Detailed Action
1. This Office Action is responsive to the Amendment filed 07/16/2026. Claims 1-20 are presented for examination. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
2. The information disclosure statement (IDS) submitted on 07/07/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 102
3. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
4. Claims 1, 6-11 and 16-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by DEL OJO ELLIAS et al. (WO 2013/079113 A1), hereinafter “ELLIAS”.
5. As to claim 1, ELLIAS discloses a method performed by at least one processor, said method comprising:
receiving a request for a remote browsing session, the request received from a first browser running on a client device ([0052] and [0122]: the user introduces in his pre-installed local (first) browser the URL of a web site … In response to the client device is prompted to formally request an instance of a container in a Secure Browsing Server, which creates a Secure (remote) Browsing Instance);
retrieving user profile information associated with the first browser ([0125]: The Client Access Tool is prepared for the session, and all the data required for establishing the connection between the (local browser of) the user device and the container (session ID and encryption keys) is embedded in the binary code before signing the software; and [0127]: the web site initially sends a login form so that the user can respond by introducing his credentials (user profile information) using the Local Browser);
based on the request, allocating a remote browsing server ([0096]: when receiving the mentioned request, the Connection Manager chooses one of the Secure Browsing Servers to host the new environment and instructs it to create a new Secure Browsing Instance), the remote browsing server comprising a remote browsing connector and a second browser ([0052]: the request is routed to the Access Manager, which will deliver a Client Access Tool 220, being customized for one specific session, to the user’s device 110. At the same time, the Secure Browsing Server 320 hosted in the Secure Server System 210 creates one Secure Browsing Instance 330 (comprising a Secure Remote Browser 335) assigned to the user as a browsing environment for the session and interacts with its corresponding Client Access Tool 220); and
causing the first browser to connect to the second browser via the remote browsing connector such that a video stream of renderings of the second browser are displayed on the first browser, and user input from the first browser is transmitted to the second browser are based on permissions associated with the user profile information ([0052]: A Secure Remote Browser 335, executed inside the Secure Browsing Instance 330, fetches, retrieves and renders, the contents of the destination web site following the usual process, as if it were hosted in the end user’s computing device 110. Once rendered, the web page contents are sent to the Client Access Tool 220 as images, for display on the user’s device display; and [0132]: Keyboard and mouse events are transmitted to the Secure Remote Browser to process them and update the display).
6. As to claims 6-7, ELLIAS teaches the method of claim 1, wherein the allocating the remote browsing server comprises: wherein the allocating the remote browsing server comprises: instantiating the remote browsing server, wherein the remote browsing server is a virtual machine ([0096]: when receiving the mentioned request, the Connection Manager requests the Monitoring Manager 313 information on the Secure Browsing Servers’ load information. Based on this, the Connection Manager chooses one of the Secure Browsing Servers to host the new environment and instructs it to create a new Secure Browsing Instance).
7. As to claim 8, ELLIAS-Hill teaches the method of claim 1, wherein the remote browsing server is instantiated after receiving the request ([0096]: when receiving the mentioned request, the Connection Manager requests the Monitoring Manager 313 information on the Secure Browsing Servers’ load information. Based on this, the Connection Manager chooses one of the Secure Browsing Servers to host the new environment and instructs it to create a new Secure Browsing Instance).
8. As to claim 9, ELLIAS-Hill teaches the method of claim 1, wherein the remote browsing server is instantiated prior to receiving the request ([0096]: the Connection Manager chooses one of the [already initiated] Secure Browsing Servers to host the new environment and instructs it to create a new Secure Browsing Instance).
9. As to claim 10, Simon teaches the method of claim 1, wherein the allocating comprises selecting the remote browsing server from a plurality of remote browsing servers ([0096]: based on the Secure Browsing Servers’ load information the Connection Manager chooses one of the Secure Browsing Servers to host the new environment and instructs it to create a new Secure Browsing Instance).
10. As to claims 11 and 16-20, claims 11 and 16-20 are corresponding administrator device claims that recite similar limitations as of method claims 1 and 6-10; therefore, they are rejected under the same rationale.
Claim Rejections - 35 USC § 103
11. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
12. Claims 2-5 and 12-15 are rejected under 35 U.S.C. 103 as being unpatentable over ELLIAS, in view of Hill et al. (US 9,208,316 B1), hereinafter “Hill”.
13. As to claim 2, ELLIAS teaches the method of claim 1, but does not explicitly disclose “based on the permissions, one or more types of user input are disabled”.
In an analogous art, Hill discloses “based on the permissions, one or more types of user input are disabled” (Fig. 7E and col. 17, lines 1-7: when the phishing web site may be known and present in the blacklist 186, the input controls provided for entry of the user’s credit card number and expiration data has been disabled).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of ELLIAS and Hill to achieve the claimed invention to allow the system to detect and disable potentially harmful items that are embedded within or referenced by retrievable network resources such as web pages and other types of documents (Hill, col. 2, lines 29-32).
14. As to claim 3, ELLIAS-Hill teaches the method of claim 1, wherein based on the permissions, one or more webpages or types of content are not accessible (Hill, Fig 7E and col. 17, lines 1-58: the input controls for entry of the user’s credit card number and expiration data have been disabled and replaced with clickable images to navigate to a web page which contains information about the potential phishing attack).
15. As to claim 4, ELLIAS-Hill teaches the method of claim 1, wherein based on the permissions, a first webpage or type of content is opened by the first browser, and a second webpage or different type of content is opened by the second browser, and a video stream of renderings of the second webpage is displayed on the first browser (Hill, col. 17, lines 40-50: if a web page is included in a blacklist, or if there are multiple potentially harmful portions of the web page, the NCC POP can render the web page in the browser 182 and create a snapshot of the web page. The NCC POP can then transmit the image to the client computing device for display in the browser 190).
16. As to claim 5, ELLIAS-Hill teaches the method of claim 4, wherein the second webpage or the different type of content is from a trusted domain, internet protocol address, or range of internet protocol addresses (Hill, col. 17, lines 40-50: if a web page is included in a blacklist, or if there are multiple potentially harmful portions of the web page, the NCC POP can render the web page in the browser 182 and create a snapshot of the web page. The NCC POP can then transmit the image to the client computing device for display in the browser 190, i.e., the snapshot of the web page is from the NCC POP, a trusted domain, IP address).
17. As to claims 12-15, claims 12-15 are corresponding administrator device claims that recite similar limitations as of method claims 2-5; therefore, they are rejected under the same rationale.
Response to Arguments
18. Applicant’s arguments as well as request for reconsideration filed on 04/24/2008 have been fully considered but they are moot in view of the new ground(s) of rejection.
19. Further references of interest are cited on Form PTO-892, which is an attachment to this Office Action.
20. A shortened statutory period for reply to this action is set to expire THREE (3) months from the mailing date of this communication. See 37 CFR 1.134.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to QUANG N. NGUYEN whose telephone number is (571) 272-3886.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s SPE, KAMAL B. DIVECHA, can be reached at (571) 272-5863. The fax phone number for the organization is (571) 273-8300.
Information regarding the status of published or unpublished applications may be obtained from the Patent Center. Status information for unpublished applications is available to registered users. To file and manage patent submissions in Patent Center, visit https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/QUANG N NGUYEN/
Primary Examiner, Art Unit 2441