Prosecution Insights
Last updated: August 17, 2026
Application No. 18/827,078

TAINTS AND FADING TAINTS

Non-Final OA §101§103§112
Filed
Sep 06, 2024
Priority
Sep 08, 2023 — provisional 63/581,481 +4 more
Examiner
CHANG, KENNETH W
Art Unit
2438
Tech Center
2400 — Computer Networks
Assignee
ORACLE INTERNATIONAL Corporation
OA Round
1 (Non-Final)
86%
Grant Probability
Favorable
1-2
OA Rounds
6m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
543 granted / 628 resolved
+28.5% vs TC avg
Minimal +1% lift
Without
With
+1.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
12 currently pending
Career history
639
Total Applications
across all art units

Statute-Specific Performance

§101
16.1%
-23.9% vs TC avg
§103
41.9%
+1.9% vs TC avg
§102
15.1%
-24.9% vs TC avg
§112
18.5%
-21.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 628 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION This first non-final action is in response to applicant’s original filing on 09/06/2024. Claims 1-20 are currently pending and have been considered as follows. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Drawings The drawings filed on 09/06/2024 are accepted. Information Disclosure Statement The information disclosure statement (IDS) submitted on 01/06/2025 has been placed in the application file, and the information referred therein has been considered as to the merits. Claim Objections Claims 1, 8, 10, 15, and 17 are objected to because of the following informalities: Claim 1 line 5 recites “based at least in the one or more taints” which should be corrected as “based on the one or more taints”; Claim 8 lines 3-4 recite “the least a portion of the data” which should be corrected as “the at least a portion of the data”; Claim 10 line 2 recites “based a strength of taint” which should be corrected as “based on a strength of taint”; Claim 15 lines 4-5 recite “the least a portion of the data” which should be corrected as “the at least a portion of the data”; Claim 17 line 2 recites “based a strength of taint” which should be corrected as “based on a strength of taint”; Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 6 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 6 recites “wherein the first taint associated with the first enforcement point is a strong taint and the first taint associated with a second enforcement point is a weaker taint compared to the strong taint” which is unclear and indefinite as to how “the first taint” can be simultaneously “a strong taint” AND “a weaker taint compared to the strong taint”. The term “first taint” refers to a singular taint as understood by one of ordinary skill in the art which cannot be a strong taint and a weaker taint at the same instance. Furthermore, The terms “strong” and “weaker” in Claim 6 are relative terms which render the claim indefinite. The terms “strong” and “weaker” are not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 18-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claims do not fall within at least one of the four categories of patent eligible subject matter because independent Claim 18 is directed to “A computer-readable medium comprising instructions…”, but applicant’s Specification has not exclusively limited the definition of “computer-readable medium” to purely statutory embodiments (e.g. Specification para. [0243] “Computer-readable storage media 1722 can include any appropriate media known or used in the art, including storage media and communication media…”). Pending claims are interpreted as broadly as their terms reasonably allow (See In re Zletz, 893 F.2d 3 19 (Fed. Cir. 1989)). The broadest reasonable interpretation of a claim drawn to a computer-readable medium typically covers forms of non-transitory tangible media and transitory propagating signals in view of the ordinary and customary meaning of computer-readable medium (See MPEP 2111.01). When the broadest reasonable interpretation of a claim covers a signal per se, the claim must be rejected under 35 U.S.C. §101 as covering non-statutory subject matter (See In re Nuijten, 500 F.3d 1346, 1356-57 (Fed. Cir. 2007) “A transitory, propagating signal … is not a ‘process, machine, manufacture, or composition of matter.’ Those four categories define the explicit scope and reach of subject matter patentable under 35 U.S.C. 101; thus, such a signal cannot be patentable subject matter”). Therefore, because the full scope of Claim 18 as read in light of the specification encompasses non-statutory subject matter, Claim 18 is rejected under 35 U.S.C. 101 for reciting non-patentable subject matter. Claims 19-20 which depend upon Claim 18 do not recite additional limitations that would bring them in statutory conformance under 35 U.S.C. 101 as patentable subject matter. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-4, 7, 8, 10-13, 15, and 17-20 are rejected under 35 U.S.C. 103 as being unpatentable over RAMACHANDRAN et al. (US 20120137375 A1, IDS submitted 01/06/2025, hereinafter Ramachandran) in view of Smith et al. (US 20190319964 A1, hereinafter Smith). As to Claim 1: Ramachandran discloses a method (e.g. Ramachandran “security systems and methods that reduce or prevent data leaks in enterprise networks” [0002]; [0005]) comprising: associating data with one or more taints, wherein the one or more taints include a first taint (e.g. Ramachandran “Through the labeling system 120, the security system 100 can track and control the propagation of labels. Users of the security system 100 can apply labels to one or a plurality of resources in the enterprise network 10. Each resource to which a label is applied can be, for example, a file or a process within the network 10” [0028]; “each label can comprise one or more taints 210” [0034]; “An enterprise user 410 may use an enterprise host 50 to create and apply a taint 210 to a file F 435” [0057]; “File F is a secret file (i.e., is labeled with a taint having a set secrecy characteristic)” [0067]; “Sensitive data that is to be protected from leaks can be associated with a taint 210, T. The user that applies the taint T to the sensitive data may ensure that none but a trusted set of enterprise users are granted the s+ capability on the taint T”[0069]); accessing one or more assertions that specify constraints on the data that affect how the data flows through one or more networks based at least in the one or more taints, wherein enforcement points within the one or more networks enforce the assertions (e.g. Ramachandran “The enforcement system can then control information flows between resources based on the labels and their associated policies” [0006]; “The network enforcer 118 can control the propagation of information from inside the network 10 to outside the network 10. In this case, the permissibility of information flow can be based on the sender's label and on network flow attributes. For example, the network enforcer 118 can prevent traffic flows that may contain secret information, as indicated the by the traffic's label, from reaching insecure networks (e.g., an open wireless network, or the outside Internet)” [0033]; “The enforcement system 110 can comprise a network enforcer 118 and, in some embodiments, a plurality of host enforcers 115” [0032]; “a host enforcer 115 of a sending host 50 can designate traffic destined to the Internet as having a particular immutable taint 210. When a network enforcer 118 sees a new data flow, it can extract the resource identification and version number from the packet header and retrieve the sender's label 200 from the label repository 128. The network enforcer 118 can then perform information flow control checks to ensure that the attempted information flow is permitted. When the network enforcer 118 sees the immutable taint 210 related to Internet traffic, it can determine whether the sending process had any secrecy taints 210” [0107]); But Ramachandran does not specifically disclose: determining, based at least in part on the one or more taints and the one or more assertions, that a first enforcement point is authorized to access at least a portion of the data; allowing the first enforcement point to access the at least the portion of the data; and responsive to the first enforcement point accessing the at least the portion of the data, associating the first enforcement point with the one or more taints. However, the analogous art Smith does disclose determining, based at least in part on the one or more taints and the one or more assertions, that a first enforcement point is authorized to access at least a portion of the data; allowing the first enforcement point to access the at least the portion of the data; and responsive to the first enforcement point accessing the at least the portion of the data, associating the first enforcement point with the one or more taints (e.g. Smith “Because a security policy is applied by routing nodes, they become the most trusted enforcement points for the system. Routing nodes may require authorization at the full range of security labels. However, it is possible for routing nodes to be authorized to operate on a subset of security labels. In this scenario, if the router is not authorized to process the interest request but another router is, the first router may supply a redirection message instructing the node how to select the other router. For example, a redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]; “routers with stronger security capabilities (e.g., equipped with a Trusted Exec. Environment) should be assigned to a higher access level” [0042]; “The data item (or fragment) that exists at a particular security level may be countersigned by the EPID key corresponding to that level. This approach removes the need for identifying nodes explicitly using a node key that contains node authorizations. Routing nodes only need to use EPID keys to enforce the security policy effectively” [0043]; [0054]; “Routers may be authorized to handle a range (but not a full range) of classification labels” [0023]; “Routing nodes have the ability to consume the labels, verify their signatures, and apply an appropriate routing policy that aligns with the security policy” [0025]). Ramachandran and Smith are analogous art because they are from the same field of endeavor in security labeling of data. It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art, having the teachings of Ramachandran and Smith before him or her, to modify the disclosure of Ramachandran with the teachings of Smith to include determining, based at least in part on the one or more taints and the one or more assertions, that a first enforcement point is authorized to access at least a portion of the data; allowing the first enforcement point to access the at least the portion of the data; and responsive to the first enforcement point accessing the at least the portion of the data, associating the first enforcement point with the one or more taints as claimed. The suggestion/motivation for doing so would have been to provide routing policies that enforce security models for protecting sensitive information (Smith [0022]). Therefore, it would have been obvious to combine Ramachandran and Smith to obtain the invention as specified in the instant claim(s). As to Claim 2: Ramachandran in view of Smith discloses the method of claim 1 further comprising: determining that a second enforcement point has communicated with the first enforcement point; and responsive to determining that the second enforcement point has communicated with the first enforcement point, associating the second enforcement point with the first taint (e.g. Ramachandran “If the network enforcer 118 allows the information flow to reach the second host 50, the labeler 125 of the second host 50 can retrieve P's label 200 from the label repository 128. From this point forward, the security system's operations can be the same or similar to those that would occur from an information flow attempt isolated to a single host 50. The second host's labeler 125 can invoke its host enforcer 115 to perform the information flow check using the respective labels 200 of P and Q. The host enforce 115 can complete this check after retrieving the appropriate user capabilities from the capability database 430” [0068]; see also Smith “For example, a redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]). The Examiner supplies the same rationale for the combination of references Ramachandran and Smith as in Claim 1. As to Claim 3: Ramachandran in view of Smith discloses the method of claim 2, associating a first taint strength with the first enforcement point and a second taint strength with the second enforcement point (e.g. Ramachandran “Router R1 320 is acting as a registration authority, but any node could serve this role. The registration authority defines the security label (e.g., levels, categories, etc.) according to the application context. This example shows three levels of sensitivity and three categories” [0038]; “Routing nodes may require authorization at the full range of security labels. However, it is possible for routing nodes to be authorized to operate on a subset of security labels… redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]; “The authorization/access level of each router is assigned by the system administrator. In an example embodiment, routers with stronger security capabilities (e.g., equipped with a Trusted Exec. Environment) should be assigned to a higher access level” [0042]). As to Claim 4: Ramachandran in view of Smith discloses the method of claim 1 further comprising: determining that other enforcement points have communicated with the first enforcement point; and responsive to determining that the other enforcement points have communicated with the first enforcement point, associating individual ones of the other enforcement point with the first taint (e.g. Ramachandran “If the network enforcer 118 allows the information flow to reach the second host 50, the labeler 125 of the second host 50 can retrieve P's label 200 from the label repository 128. From this point forward, the security system's operations can be the same or similar to those that would occur from an information flow attempt isolated to a single host 50. The second host's labeler 125 can invoke its host enforcer 115 to perform the information flow check using the respective labels 200 of P and Q. The host enforce 115 can complete this check after retrieving the appropriate user capabilities from the capability database 430” [0068]; see also Smith “For example, a redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]). The Examiner supplies the same rationale for the combination of references Ramachandran and Smith as in Claim 1. As to Claim 7: Ramachandran in view of Smith discloses the method of claim 1, further comprising associating the data with a second taint (e.g. Ramachandran “Through the labeling system 120, the security system 100 can track and control the propagation of labels. Users of the security system 100 can apply labels to one or a plurality of resources in the enterprise network 10. Each resource to which a label is applied can be, for example, a file or a process within the network 10” [0028]; “each label can comprise one or more taints 210” [0034]; “denotes the set of taints in the label 200 of a resource P for which the secrecy characteristic 220 is set” [0039]; [0114]). As to Claim 8: Ramachandran in view of Smith discloses the method of claim 1, further comprising: creating a data zone that indicates a boundary for where the data can flow within the one or more networks (e.g. Ramachandran “The network enforcer 118 can typically reside at boundaries between networks of different trust levels, such as at the edge of the enterprise network 10 leading to the Internet, or between wired and wireless network boundaries within the enterprise” [0107]); and wherein determining that the first enforcement point is authorized to access the least a portion of the data is based, at least in part, on a determination that the first enforcement point is located within the data zone (e.g. Ramachandran “A labeler module on each host within the network can use the label to determine what communication can take place between labeled resources on the host. When a first resource (e.g., a process) attempts to communicate across the network with a second resource on a different host, the security system can track the flow of information over the network using labels associated with network traffic. The labels can be used to enforce information flow policies, such as on an intermediate network device (e.g., a network enforcer) or on the host that is the intended recipient of the traffic” [0020]; “within the enterprise network perimeter protected by the security system 100, users can access sensitive resources as normal, using various programs of their choice, with information flow tracking being transparent to them and their applications” [0081]). As to Claim 10: Ramachandran in view of Smith discloses the method of claim 1, further comprising restricting what enforcement points can access the data based a strength of taint associated with the enforcement points (e.g. Ramachandran “Router R1 320 is acting as a registration authority, but any node could serve this role. The registration authority defines the security label (e.g., levels, categories, etc.) according to the application context. This example shows three levels of sensitivity and three categories” [0038]; “Routing nodes may require authorization at the full range of security labels. However, it is possible for routing nodes to be authorized to operate on a subset of security labels… redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]; “The authorization/access level of each router is assigned by the system administrator. In an example embodiment, routers with stronger security capabilities (e.g., equipped with a Trusted Exec. Environment) should be assigned to a higher access level” [0042]). As to Claim 11: Ramachandran discloses a system (e.g. Ramachandran “security systems and methods that reduce or prevent data leaks in enterprise networks” [0002]; [0005]), comprising: one or more networks that includes enforcement points (e.g. Ramachandran “The enforcement system can then control information flows between resources based on the labels and their associated policies” [0006]; “The network enforcer 118 can control the propagation of information from inside the network 10 to outside the network 10” [0033]; “The enforcement system 110 can comprise a network enforcer 118 and, in some embodiments, a plurality of host enforcers 115” [0032]); a policy that specifies how traffic flows through the one or more networks, wherein policy statements reference tags associated with resources of the one or more networks (e.g. Ramachandran “Labels have policies (known as capabilities) associated with them that restrict the flow of information from labeled resources. The enforcement system can then control information flows between resources based on the labels and their associated policies” [0006]), one or more processors (e.g. Ramachandran microprocessor [0085]; a computer processing unit [0086]); and non-transitory computer-readable medium storing a set of instructions, the set of instructions when executed by the one or more processors (e.g. Ramachandran “computer-executable instructions, such as one or more applications or program modules, stored on a computer-readable medium and executed by a computer processing unit” [0086]) cause processing to be performed comprising: associating data with one or more taints, wherein the one or more taints include a first taint (e.g. Ramachandran “Through the labeling system 120, the security system 100 can track and control the propagation of labels. Users of the security system 100 can apply labels to one or a plurality of resources in the enterprise network 10. Each resource to which a label is applied can be, for example, a file or a process within the network 10” [0028]; “each label can comprise one or more taints 210” [0034]; “An enterprise user 410 may use an enterprise host 50 to create and apply a taint 210 to a file F 435” [0057]; “File F is a secret file (i.e., is labeled with a taint having a set secrecy characteristic)” [0067]; “Sensitive data that is to be protected from leaks can be associated with a taint 210, T. The user that applies the taint T to the sensitive data may ensure that none but a trusted set of enterprise users are granted the s+ capability on the taint T”[0069]); accessing one or more assertions that specify constraints on the data that affect how the data flows through one or more networks based on the one or more taints, wherein the enforcement points within the one or more networks enforce the assertions (e.g. Ramachandran “The enforcement system can then control information flows between resources based on the labels and their associated policies” [0006]; “The network enforcer 118 can control the propagation of information from inside the network 10 to outside the network 10. In this case, the permissibility of information flow can be based on the sender's label and on network flow attributes. For example, the network enforcer 118 can prevent traffic flows that may contain secret information, as indicated the by the traffic's label, from reaching insecure networks (e.g., an open wireless network, or the outside Internet)” [0033]; “The enforcement system 110 can comprise a network enforcer 118 and, in some embodiments, a plurality of host enforcers 115” [0032]; “a host enforcer 115 of a sending host 50 can designate traffic destined to the Internet as having a particular immutable taint 210. When a network enforcer 118 sees a new data flow, it can extract the resource identification and version number from the packet header and retrieve the sender's label 200 from the label repository 128. The network enforcer 118 can then perform information flow control checks to ensure that the attempted information flow is permitted. When the network enforcer 118 sees the immutable taint 210 related to Internet traffic, it can determine whether the sending process had any secrecy taints 210” [0107]); But Ramachandran does not specifically disclose: determining, based at least in part on the one or more taints and the one or more assertions, that a first enforcement point is authorized to access at least a portion of the data; allowing the first enforcement point to access the at least the portion of the data; and responsive to the first enforcement point accessing the at least the portion of the data, associating the first enforcement point with the one or more taints. However, the analogous art Smith does disclose determining, based at least in part on the one or more taints and the one or more assertions, that a first enforcement point is authorized to access at least a portion of the data; allowing the first enforcement point to access the at least the portion of the data; and responsive to the first enforcement point accessing the at least the portion of the data, associating the first enforcement point with the one or more taints (e.g. Smith “Because a security policy is applied by routing nodes, they become the most trusted enforcement points for the system. Routing nodes may require authorization at the full range of security labels. However, it is possible for routing nodes to be authorized to operate on a subset of security labels. In this scenario, if the router is not authorized to process the interest request but another router is, the first router may supply a redirection message instructing the node how to select the other router. For example, a redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]; “routers with stronger security capabilities (e.g., equipped with a Trusted Exec. Environment) should be assigned to a higher access level” [0042]; “The data item (or fragment) that exists at a particular security level may be countersigned by the EPID key corresponding to that level. This approach removes the need for identifying nodes explicitly using a node key that contains node authorizations. Routing nodes only need to use EPID keys to enforce the security policy effectively” [0043]; [0054]; “Routers may be authorized to handle a range (but not a full range) of classification labels” [0023]; “Routing nodes have the ability to consume the labels, verify their signatures, and apply an appropriate routing policy that aligns with the security policy” [0025]). Ramachandran and Smith are analogous art because they are from the same field of endeavor in security labeling of data. It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art, having the teachings of Ramachandran and Smith before him or her, to modify the disclosure of Ramachandran with the teachings of Smith to include determining, based at least in part on the one or more taints and the one or more assertions, that a first enforcement point is authorized to access at least a portion of the data; allowing the first enforcement point to access the at least the portion of the data; and responsive to the first enforcement point accessing the at least the portion of the data, associating the first enforcement point with the one or more taints as claimed. The suggestion/motivation for doing so would have been to provide routing policies that enforce security models for protecting sensitive information (Smith [0022]). Therefore, it would have been obvious to combine Ramachandran and Smith to obtain the invention as specified in the instant claim(s). As to Claim 12: Ramachandran in view of Smith discloses the system of claim 11, further comprising: determining that a second enforcement point has communicated with the first enforcement point; responsive to determining that the second enforcement point has communicated with the first enforcement point, associating the second enforcement point with the first taint (e.g. Ramachandran “If the network enforcer 118 allows the information flow to reach the second host 50, the labeler 125 of the second host 50 can retrieve P's label 200 from the label repository 128. From this point forward, the security system's operations can be the same or similar to those that would occur from an information flow attempt isolated to a single host 50. The second host's labeler 125 can invoke its host enforcer 115 to perform the information flow check using the respective labels 200 of P and Q. The host enforce 115 can complete this check after retrieving the appropriate user capabilities from the capability database 430” [0068]; see also Smith “For example, a redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]); associating a first taint strength with the first enforcement point; and associating a second taint strength with the second enforcement point (e.g. Ramachandran “Router R1 320 is acting as a registration authority, but any node could serve this role. The registration authority defines the security label (e.g., levels, categories, etc.) according to the application context. This example shows three levels of sensitivity and three categories” [0038]; “Routing nodes may require authorization at the full range of security labels. However, it is possible for routing nodes to be authorized to operate on a subset of security labels… redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]; “The authorization/access level of each router is assigned by the system administrator. In an example embodiment, routers with stronger security capabilities (e.g., equipped with a Trusted Exec. Environment) should be assigned to a higher access level” [0042]). The Examiner supplies the same rationale for the combination of references Ramachandran and Smith as in Claim 11. As to Claim 13: Ramachandran in view of Smith discloses the system of claim 11, further comprising: determining that other enforcement points have communicated with the first enforcement point; and responsive to determining that the other enforcement points have communicated with the first enforcement point, associating individual ones of the other enforcement point with the first taint (e.g. Ramachandran “If the network enforcer 118 allows the information flow to reach the second host 50, the labeler 125 of the second host 50 can retrieve P's label 200 from the label repository 128. From this point forward, the security system's operations can be the same or similar to those that would occur from an information flow attempt isolated to a single host 50. The second host's labeler 125 can invoke its host enforcer 115 to perform the information flow check using the respective labels 200 of P and Q. The host enforce 115 can complete this check after retrieving the appropriate user capabilities from the capability database 430” [0068]; see also Smith “For example, a redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]). The Examiner supplies the same rationale for the combination of references Ramachandran and Smith as in Claim 11. As to Claim 15: Ramachandran in view of Smith discloses the system of claim 11, further comprising: creating a data zone that indicates a boundary for where the data can flow within the one or more networks (e.g. Ramachandran “The network enforcer 118 can typically reside at boundaries between networks of different trust levels, such as at the edge of the enterprise network 10 leading to the Internet, or between wired and wireless network boundaries within the enterprise” [0107]); and wherein determining that the first enforcement point is authorized to access the least a portion of the data is based, at least in part, on a determination that the first enforcement point is located within the data zone (e.g. Ramachandran “A labeler module on each host within the network can use the label to determine what communication can take place between labeled resources on the host. When a first resource (e.g., a process) attempts to communicate across the network with a second resource on a different host, the security system can track the flow of information over the network using labels associated with network traffic. The labels can be used to enforce information flow policies, such as on an intermediate network device (e.g., a network enforcer) or on the host that is the intended recipient of the traffic” [0020]; “within the enterprise network perimeter protected by the security system 100, users can access sensitive resources as normal, using various programs of their choice, with information flow tracking being transparent to them and their applications” [0081]). As to Claim 17: Ramachandran in view of Smith discloses the system of claim 11, further comprising restricting what enforcement points can access the data based a strength of taint associated with the enforcement point (e.g. Ramachandran “Router R1 320 is acting as a registration authority, but any node could serve this role. The registration authority defines the security label (e.g., levels, categories, etc.) according to the application context. This example shows three levels of sensitivity and three categories” [0038]; “Routing nodes may require authorization at the full range of security labels. However, it is possible for routing nodes to be authorized to operate on a subset of security labels… redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]; “The authorization/access level of each router is assigned by the system administrator. In an example embodiment, routers with stronger security capabilities (e.g., equipped with a Trusted Exec. Environment) should be assigned to a higher access level” [0042]). As to Claim 18: Ramachandran discloses a computer-readable medium comprising instructions that when executed, cause one or more processors (e.g. Ramachandran “computer-executable instructions, such as one or more applications or program modules, stored on a computer-readable medium and executed by a computer processing unit” [0086]) to perform operations including: associating data with one or more taints, wherein the one or more taints include a first taint (e.g. Ramachandran “Through the labeling system 120, the security system 100 can track and control the propagation of labels. Users of the security system 100 can apply labels to one or a plurality of resources in the enterprise network 10. Each resource to which a label is applied can be, for example, a file or a process within the network 10” [0028]; “each label can comprise one or more taints 210” [0034]; “An enterprise user 410 may use an enterprise host 50 to create and apply a taint 210 to a file F 435” [0057]; “File F is a secret file (i.e., is labeled with a taint having a set secrecy characteristic)” [0067]; “Sensitive data that is to be protected from leaks can be associated with a taint 210, T. The user that applies the taint T to the sensitive data may ensure that none but a trusted set of enterprise users are granted the s+ capability on the taint T”[0069]); accessing one or more assertions that specify constraints on the data that affect how the data flows through one or more networks based on the one or more taints, wherein enforcement points within the one or more networks enforce the assertions (e.g. Ramachandran “The enforcement system can then control information flows between resources based on the labels and their associated policies” [0006]; “The network enforcer 118 can control the propagation of information from inside the network 10 to outside the network 10. In this case, the permissibility of information flow can be based on the sender's label and on network flow attributes. For example, the network enforcer 118 can prevent traffic flows that may contain secret information, as indicated the by the traffic's label, from reaching insecure networks (e.g., an open wireless network, or the outside Internet)” [0033]; “The enforcement system 110 can comprise a network enforcer 118 and, in some embodiments, a plurality of host enforcers 115” [0032]; “a host enforcer 115 of a sending host 50 can designate traffic destined to the Internet as having a particular immutable taint 210. When a network enforcer 118 sees a new data flow, it can extract the resource identification and version number from the packet header and retrieve the sender's label 200 from the label repository 128. The network enforcer 118 can then perform information flow control checks to ensure that the attempted information flow is permitted. When the network enforcer 118 sees the immutable taint 210 related to Internet traffic, it can determine whether the sending process had any secrecy taints 210” [0107]); But Ramachandran does not specifically disclose: determining, based at least in part on the one or more taints and the one or more assertions, that a first enforcement point is authorized to access at least a portion of the data; allowing the first enforcement point to access the at least the portion of the data; and responsive to the first enforcement point accessing the at least the portion of the data, associating the first enforcement point with the one or more taints. However, the analogous art Smith does disclose determining, based at least in part on the one or more taints and the one or more assertions, that a first enforcement point is authorized to access at least a portion of the data; allowing the first enforcement point to access the at least the portion of the data; and responsive to the first enforcement point accessing the at least the portion of the data, associating the first enforcement point with the one or more taints (e.g. Smith “Because a security policy is applied by routing nodes, they become the most trusted enforcement points for the system. Routing nodes may require authorization at the full range of security labels. However, it is possible for routing nodes to be authorized to operate on a subset of security labels. In this scenario, if the router is not authorized to process the interest request but another router is, the first router may supply a redirection message instructing the node how to select the other router. For example, a redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]; “routers with stronger security capabilities (e.g., equipped with a Trusted Exec. Environment) should be assigned to a higher access level” [0042]; “The data item (or fragment) that exists at a particular security level may be countersigned by the EPID key corresponding to that level. This approach removes the need for identifying nodes explicitly using a node key that contains node authorizations. Routing nodes only need to use EPID keys to enforce the security policy effectively” [0043]; [0054]; “Routers may be authorized to handle a range (but not a full range) of classification labels” [0023]; “Routing nodes have the ability to consume the labels, verify their signatures, and apply an appropriate routing policy that aligns with the security policy” [0025]). Ramachandran and Smith are analogous art because they are from the same field of endeavor in security labeling of data. It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art, having the teachings of Ramachandran and Smith before him or her, to modify the disclosure of Ramachandran with the teachings of Smith to include determining, based at least in part on the one or more taints and the one or more assertions, that a first enforcement point is authorized to access at least a portion of the data; allowing the first enforcement point to access the at least the portion of the data; and responsive to the first enforcement point accessing the at least the portion of the data, associating the first enforcement point with the one or more taints as claimed. The suggestion/motivation for doing so would have been to provide routing policies that enforce security models for protecting sensitive information (Smith [0022]). Therefore, it would have been obvious to combine Ramachandran and Smith to obtain the invention as specified in the instant claim(s). As to Claim 19: Ramachandran in view of Smith discloses the computer-readable medium of claim 18, further comprising: determining that a second enforcement point has communicated with the first enforcement point; responsive to determining that the second enforcement point has communicated with the first enforcement point, associating the second enforcement point with the first taint (e.g. Ramachandran “If the network enforcer 118 allows the information flow to reach the second host 50, the labeler 125 of the second host 50 can retrieve P's label 200 from the label repository 128. From this point forward, the security system's operations can be the same or similar to those that would occur from an information flow attempt isolated to a single host 50. The second host's labeler 125 can invoke its host enforcer 115 to perform the information flow check using the respective labels 200 of P and Q. The host enforce 115 can complete this check after retrieving the appropriate user capabilities from the capability database 430” [0068]; see also Smith “For example, a redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]); associating a first taint strength with the first enforcement point; and associating a second taint strength with the second enforcement point (e.g. Ramachandran “Router R1 320 is acting as a registration authority, but any node could serve this role. The registration authority defines the security label (e.g., levels, categories, etc.) according to the application context. This example shows three levels of sensitivity and three categories” [0038]; “Routing nodes may require authorization at the full range of security labels. However, it is possible for routing nodes to be authorized to operate on a subset of security labels… redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]; “The authorization/access level of each router is assigned by the system administrator. In an example embodiment, routers with stronger security capabilities (e.g., equipped with a Trusted Exec. Environment) should be assigned to a higher access level” [0042]). The Examiner supplies the same rationale for the combination of references Ramachandran and Smith as in Claim 18. As to Claim 20: Ramachandran in view of Smith discloses the computer-readable medium of claim 18, further comprising: determining that other enforcement points have communicated with the first enforcement point; and responsive to determining that the other enforcement points have communicated with the first enforcement point, associating individual ones of the other enforcement point with the first taint (e.g. Ramachandran “If the network enforcer 118 allows the information flow to reach the second host 50, the labeler 125 of the second host 50 can retrieve P's label 200 from the label repository 128. From this point forward, the security system's operations can be the same or similar to those that would occur from an information flow attempt isolated to a single host 50. The second host's labeler 125 can invoke its host enforcer 115 to perform the information flow check using the respective labels 200 of P and Q. The host enforce 115 can complete this check after retrieving the appropriate user capabilities from the capability database 430” [0068]; see also Smith “For example, a redirection message may contain the security label range the target router is authorized for and the node may change its current security level to one that overlaps the range of the other router” [0041]). The Examiner supplies the same rationale for the combination of references Ramachandran and Smith as in Claim 1. Claims 9 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Ramachandran in view of Smith as applied to Claims 1 and 11, and further in view of Brar et al. (US 20210377166 A1, hereinafter Brar). As to Claim 9: Ramachandran in view of Smith discloses the method of claim 1, but does not specifically disclose: network virtualization devices (NVDs) that include smartNICs and virtual interfaces that include gateways. However, the analogous art Brar does disclose network virtualization devices (NVDs) that include smartNICs and virtual interfaces that include gateways (e.g. Brar “virtual networks are implemented using software virtualization technologies (e.g., hypervisors, functions performed by network virtualization devices (NVDs) (e.g., smartNICs)” [0041]; “A gateway is a virtual interface that is configured for a VCN and enables communication of traffic to and from the VCN to one or more endpoints outside the VCN. One or more different types of gateways may be configured for a VCN to enable communication to and from different types of endpoints” [0058]). Ramachandran, Smith, and Brar are analogous art because they are from the same field of endeavor in network security policy enforcement. It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art, having the teachings of Ramachandran, Smith, and Brar before him or her, to modify the combination of Ramachandran and Smith with the teachings of Brar to include network virtualization devices (NVDs) that include smartNICs and virtual interfaces that include gateways as claimed. The suggestion/motivation for doing so would have been to provide a virtualized distributed environment and enable communication of traffic to and from the virtual cloud network (VCN) to one or more endpoints outside the VCN (Brar [0041]; [0058]). Therefore, it would have been obvious to combine Ramachandran, Smith, and Brar to obtain the invention as specified in the instant claim(s). As to Claim 16: Ramachandran in view of Smith discloses the system of claim 11, but does not specifically disclose: network virtualization devices (NVDs) that include smartNICs and virtual interfaces that include gateways. However, the analogous art Brar does disclose network virtualization devices (NVDs) that include smartNICs and virtual interfaces that include gateways (e.g. Brar “virtual networks are implemented using software virtualization technologies (e.g., hypervisors, functions performed by network virtualization devices (NVDs) (e.g., smartNICs)” [0041]; “A gateway is a virtual interface that is configured for a VCN and enables communication of traffic to and from the VCN to one or more endpoints outside the VCN. One or more different types of gateways may be configured for a VCN to enable communication to and from different types of endpoints” [0058]). Ramachandran, Smith, and Brar are analogous art because they are from the same field of endeavor in network security policy enforcement. It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art, having the teachings of Ramachandran, Smith, and Brar before him or her, to modify the combination of Ramachandran and Smith with the teachings of Brar to include network virtualization devices (NVDs) that include smartNICs and virtual interfaces that include gateways as claimed. The suggestion/motivation for doing so would have been to provide a virtualized distributed environment and enable communication of traffic to and from the virtual cloud network (VCN) to one or more endpoints outside the VCN (Brar [0041]; [0058]). Therefore, it would have been obvious to combine Ramachandran, Smith, and Brar to obtain the invention as specified in the instant claim(s). Allowable Subject Matter Claims 5 and 14 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. Arlein et al. (US 20020133500 A1) Krishnamurthy et al. (US 20090300751 A1) Barile et al. (US 8356357 B1) Any inquiry concerning this communication or earlier communications from the examiner should be directed to Kenneth Chang whose telephone number is (571)270-7530. The examiner can normally be reached Monday - Friday 9:30am-5:30pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Taghi Arani can be reached at 571-272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KENNETH W CHANG/Primary Examiner, Art Unit 2438 PNG media_image1.png 35 280 media_image1.png Greyscale 04.29.2026
Read full office action

Prosecution Timeline

Sep 06, 2024
Application Filed
May 07, 2026
Non-Final Rejection mailed — §101, §103, §112
Jul 31, 2026
Examiner Interview Summary
Jul 31, 2026
Applicant Interview (Telephonic)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706942
SYSTEMS AND METHODS FOR DEPLOYING AGENTLESS COUNTERMEASURES IN A NETWORK ENVIRONMENT
2y 11m to grant Granted Aug 11, 2026
Patent 12706905
REDUCING FALSE POSITIVES IN ENTITY MATCHING BASED ON IMAGE-LINKING GRAPHS
1y 10m to grant Granted Aug 11, 2026
Patent 12671677
BIDIRECTIONAL DATA OBFUSCATION AND ATOMIZATION WITHIN UNSECURED FRAGMENTED RUNTIME ENVIRONMENTS
2y 11m to grant Granted Jun 30, 2026
Patent 12659355
ADAPTIVE POLICY GENERATION IN DISTRIBUTED SECURITY FABRICS
1y 11m to grant Granted Jun 16, 2026
Patent 12647778
REFERENCE SIGNAL SECURITY TO COMBAT EAVESDROPPING AND DIRECTIONAL DENIAL OF SERVICE ATTACKS
2y 4m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
86%
Grant Probability
88%
With Interview (+1.4%)
2y 5m (~6m remaining)
Median Time to Grant
Low
PTA Risk
Based on 628 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month