Prosecution Insights
Last updated: August 07, 2026
Application No. 18/861,872

SYSTEM AND METHOD FOR APPLICATION-BASED MICRO-SEGMENTATION

Final Rejection §101§103
Filed
Oct 30, 2024
Priority
Apr 30, 2022 — provisional 63/337,055 +1 more
Examiner
MALINOWSKI, WALTER J
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Aviatrix Systems Inc.
OA Round
2 (Final)
70%
Grant Probability
Favorable
3-4
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 70% — above average
70%
Career Allowance Rate
237 granted / 341 resolved
+11.5% vs TC avg
Strong +53% interview lift
Without
With
+52.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
14 currently pending
Career history
361
Total Applications
across all art units

Statute-Specific Performance

§101
13.5%
-26.5% vs TC avg
§103
65.6%
+25.6% vs TC avg
§102
3.0%
-37.0% vs TC avg
§112
8.7%
-31.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 341 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This Office Action is in response to the amendment filed 6/2/2026 for application 18/861,872. Claims 1-19 and 21 are currently pending; claims 4, 5, 11, 14, 15, and 19 have been amended; claim 20 has been canceled; claim 21 has been added; claims 1, 11, and 18 are independent claims; claims 1-20 have been examined. This Action is made FINAL. Response to Arguments Applicants’ arguments in the instant Amendment, filed on 6/2/2026, with respect to limitations listed below, have been fully considered but they are not persuasive. Applicant argues as follows: Applicant respectfully submits that claims 1-20 are not directed to mental processes, but instead go beyond mental processes to novel and practical applications for network-security. Withdrawal of the rejection of claims 1-20 is respectfully requested. Examiner respectfully disagrees. Regarding claim 11, the claim recites the limitations “recovering information…”generating a first subset of rules,” “generating a second subset of rules” Broadly interpreted, the aforementioned steps are directed to mental processes as said steps could be performed in the human mind. Therefore, the claims recite an abstract idea. Said abstract idea and/or judicial exception is not integrated into a practical application as the claim does not recite any other active steps that could be considered that the abstract idea is being integrated into a practical application. It’s noted that the claim recites the operations “‘determining a virtual region” and “using micro-segmentation” However, said operations are not sufficient to consider that the abstract idea is being interpreted into a practical application. Said operations are recited at a high level of generality in gathering/processing/storing information, which are a form of insignificant extra-solution activity. It’s also noted that the claims recite additional limitation/elements (i.e., cloud service provider, overlay network, underlay network etc.,). However, said additional elements are recited at a high-level of generality (i.e., as a generic computing device performing a generic computer functions) such that it amounts no more than mere instructions to apply the exception or abstract idea using generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims do not include additional elements/limitations/embodiments that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As mentioned above, although the claims recite additional elements, said elements taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic computer content distributing functions routinely used in information technology field. As discussed above, the additional elements recited at a high-level of generality such that they amount no more than mere instructions to apply the exception using a generic computer component. Therefore, the claim is directed to non-statutory subject matter. Regarding claims 1-10 and 12-20, claims 1-10 and 12-20 are also rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter for the same reasons addressed above as the claims recite an abstract idea and the claims do not positively recite any other operations that could be considered as the abstract idea is being integrated into a practical application or significantly more. Applicant argues as follows: II. Rejections under 35 U.S.C. § 103 Claims 1-4, 6-8, 11-14, 16, and 18-20 stand rejected under 35 U.S.C. § 103 as being unpatentable over U.S. Patent Pub. No. 2022/0103471 to Kulkarni ("Kulkarni") in view of U.S. Pat. Pub. No. 2013/0170490 to Kreeger ("Kreeger"). Applicant respectfully traverses the rejection. Independent claim 1 is directed to a controller whose storage medium includes classification logic that determines, based on recovered information associated with a newly discovered endpoint, the virtual region in which that endpoint resides, and rule generation logic that conditionally generates different rule subsets depending on whether the source and destination reside within the same virtual region or different virtual regions. Kulkarni's cited disclosure concerns a multi-region SD-WAN in which enterprise regions may be configured based on geography, business objectives, or divisions of network appliances, and in which regional business policies may vary. Applicant respectfully submits that Kulkarni's SD-WAN regions do not disclose the claimed virtual regions determined for a newly discovered endpoint based on recovered endpoint information. Examiner respectfully submits that claim 1 has been properly rejected by the combination of Kulkarni and Kreeger. Regarding claim 1, Kulkarni discloses, paragraph 0059, controller comprising: a processor by disclosing software, processor, storage, RAM memory; a non-transitory storage medium communicatively coupled to the processor, the non-transitory storage medium includes by disclosing software, processor, storage, RAM memory; paragraph 0064, 0035, (i) classification logic that, based on recovered information associated with an endpoint, determines a virtual region in which the endpoint resides by disclosing policies configured based on application classification techniques; define applicable business policies region by region, business policies can be customized on a regional basis; paragraph 0035, 0159, 0077, 0052, (ii) rule generation logic configured to (a) generate a first subset of rules for controlling a flow of messages between a destination and a source via native cloud constructs associated with a cloud service provider (CSP) underlay network when the destination and source reside within a first virtual region by disclosing define applicable business policies region by region, local cloud security service provider in a region; security and networking policies customized on a regional basis; network traffic may traverse between each appliance in a region (intra-region); underlay network; paragraph 0035, 0036, 0052, (b) generate a second subset of rules for controlling a flow of messages between the destination and the source via an overlay network providing communications between the first virtual region and a second virtual region when the destination and the source reside within different virtual regions by disclosing communication network divided into regions, applicable business polices can be defined region by region; each region can have different combinations of transport links with different link qualities and link bandwidths; overlay network; paragraph 0159 and 0038, use micro-segmentation to set and manage security policies by disclosing polices may be configured on a regional basis; segmentation , security policies. Kulkarni discloses (i) classification logic that, based on recovered information associated with an endpoint, determines a virtual region in which the endpoint resides, but does not explicitly disclose (i) classification logic that, based on recovered information associated with a newly discovered endpoint, determines a virtual region in which the newly discovered endpoint resides. Kreeger discloses, paragraph 0012, 0031, 0042, i) classification logic that, based on recovered information associated with a newly discovered endpoint, determines a virtual region in which the newly discovered endpoint resides by disclosing discovering endpoints in an overlayer environment for subsequent troubleshooting of network issues, discovering endpoints to troubleshoot connectivity; discover endpoints. Applicant discloses as follows: In addition, Kulkarni does not disclose generating a first subset of rules via CSP-native cloud constructs when the source and destination reside within a first virtual region and generating a second subset of rules via an overlay network when the source and destination reside within different virtual regions. Kreeger does not cure these deficiencies because Kreeger's discovery packets are used to discover VEMs or VXLAN endpoints in an overlay network for troubleshooting multicast connectivity, not to classify a newly discovered endpoint into a virtual region or generate micro-segmentation rule subsets. The proposed combination of Kulkarni and Kreeger therefore at most discloses endpoint discovery for troubleshooting; the combination does not teach or suggest the claimed controller logic that uses recovered endpoint information to determine endpoint virtual-region residence and then conditionally generates different rule subsets for same-region and different-region source-destination message flows. Examiner respectfully submits that Kulkarni discloses, in paragraph 0035, 0159, 0077, 0052, (ii) rule generation logic configured to (a) generate a first subset of rules for controlling a flow of messages between a destination and a source via native cloud constructs associated with a cloud service provider (CSP) underlay network when the destination and source reside within a first virtual region by disclosing define applicable business policies region by region, local cloud security service provider in a region; security and networking policies customized on a regional basis; network traffic may traverse between each appliance in a region (intra-region); underlay network. Kulkarni discloses, paragraph 0035, 0036, 0052, (b) generate a second subset of rules for controlling a flow of messages between the destination and the source via an overlay network providing communications between the first virtual region and a second virtual region when the destination and the source reside within different virtual regions by disclosing communication network divided into regions, applicable business polices can be defined region by region; each region can have different combinations of transport links with different link qualities and link bandwidths; overlay network. The Examiner respectfully suggests that the claim be further amended and details in the specification be incorporated to distinguish the claimed invention over prior art of record. Should the Applicant desire an interview to further clarify the claim interpretation/rejections, please contact the Examiner at (571) 272-5368 to schedule an interview. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-19 and 21 are rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter as being directed to an abstract idea without being integrated into a practical application or significantly more. Regarding claim 11, the claim recites the limitations “recovering information…”generating a first subset of rules,” “generating a second subset of rules” Broadly interpreted, the aforementioned steps are directed to mental processes as said steps could be performed in the human mind. Therefore, the claims recite an abstract idea. Said abstract idea and/or judicial exception is not integrated into a practical application as the claim does not recite any other active steps that could be considered that the abstract idea is being integrated into a practical application. It’s noted that the claim recites the operations “‘determining a virtual region” and “using micro-segmentation” However, said operations are not sufficient to consider that the abstract idea is being interpreted into a practical application. Said operations are recited at a high level of generality in gathering/processing/storing information, which are a form of insignificant extra-solution activity. It’s also noted that the claims recite additional limitation/elements (i.e., cloud service provider, overlay network, underlay network, controller comprising classification logic and rule generation logic etc.,). However, said additional elements are recited at a high-level of generality (i.e., as a generic computing device performing a generic computer functions) such that it amounts no more than mere instructions to apply the exception or abstract idea using generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims do not include additional elements/limitations/embodiments that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As mentioned above, although the claims recite additional elements, said elements taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic computer content distributing functions routinely used in information technology field. As discussed above, the additional elements recited at a high-level of generality such that they amount no more than mere instructions to apply the exception using a generic computer component. Therefore, the claim is directed to non-statutory subject matter. Regarding claims 1-10, 12-19, and 21, claims 1-10, 12-19, and 21 are also rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter for the same reasons addressed above as the claims recite an abstract idea and the claims do not positively recite any other operations that could be considered as the abstract idea is being integrated into a practical application or significantly more. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically discloses as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-4. 6-8, 11-14, 16, 18, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Kulkarni (US20220103471), filed August 4, 2021, in view of Kreeger (US20130170490), filed December 30, 2011. Regarding claim 1, Kulkarni discloses controller comprising: a processor (Kulkarni, paragraph 0059, software, processor, storage, RAM memory). a non-transitory storage medium communicatively coupled to the processor, the non-transitory storage medium includes (Kulkarni, paragraph 0059, software, processor, storage, RAM memory). (i) classification logic that, based on recovered information associated with an endpoint, determines a virtual region in which the endpoint resides (Kulkarni, paragraph 0064, policies configured based on application classification techniques; paragraph 0035, define applicable business policies region by region, business policies can be customized on a regional basis) (ii) rule generation logic configured to (a) generate a first subset of rules for controlling a flow of messages between a destination and a source via native cloud constructs associated with a cloud service provider (CSP) underlay network when the destination and source reside within a first virtual region (Kulkarni, paragraph 0035, define applicable business policies region by region, local cloud security service provider in a region; paragraph 0159, security and networking policies customized on a regional basis; paragraph 0077, network traffic may traverse between each appliance in a region (intra-region); paragraph 0052, underlay network) (b) generate a second subset of rules for controlling a flow of messages between the destination and the source via an overlay network providing communications between the first virtual region and a second virtual region when the destination and the source reside within different virtual regions (Kulkarni, paragraph 0035, communication network divided into regions, applicable business polices can be defined region by region; paragraph 0036, each region can have different combinations of transport links with different link qualities and link bandwidths; paragraph 0052, overlay network). use micro-segmentation to set and manage security policies (Kulkarni, paragraph 0159, polices may be configured on a regional basis; paragraph 0038, segmentation , security policies). Kulkarni discloses (i) classification logic that, based on recovered information associated with an endpoint, determines a virtual region in which the endpoint resides, but does not explicitly disclose (i) classification logic that, based on recovered information associated with a newly discovered endpoint, determines a virtual region in which the newly discovered endpoint resides. However, in an analogous art, Kreeger discloses i) classification logic that, based on recovered information associated with a newly discovered endpoint, determines a virtual region in which the newly discovered endpoint resides (Kreeger, paragraph 0012, discovering endpoints in an overlayer environment for subsequent troubleshooting of network issues, paragraph 0031, discovering endpoints to troubleshoot connectivity; paragraph 0042, discover endpoints). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Kreeger with the controller/ method/ nontransitory storage medium of Kulkarni to include i) classification logic that, based on recovered information associated with a newly discovered endpoint, determines a virtual region in which the newly discovered endpoint resides to provide users with the benefits of discovering multipoint endpoints in a network environment (Kreeger: paragraph 0001). Regarding claim 2, Kulkarni and Kreeger disclose the controller of claim 1. Kulkarni and Kreeger discloses wherein the first virtual region corresponds to a first virtual private cloud network (VPC) and the second virtual region corresponds to a second VPC (Kulkarni, paragraph 0048, first location 110, second location 120, private network; paragraph 0055 private cloud network). Regarding claim 3, Kulkarni and Kreeger disclose the controller of claim 2. Kulkarni and Kreeger discloses wherein the first VPC resides within a first public cloud network and a second VPC resides within a second public cloud network different than the first public cloud network (Kulkarni, paragraph 0056, first locations, second locations, different web services (locations)). Regarding claim 4, Kulkarni and Kreeger disclose the controller of claim 2. Kulkarni and Kreeger discloses wherein the second subset of rules include filtering rules that formulate one or more policies that influence a propagation of inter-VPC network traffic over the overlay network establishing a communication path between the first VPC and the second VPC (Kulkarni, paragraph 0038, policies, local configuration, global aspects; paragraph 0093, routing). Regarding claim 6, Kulkarni and Kreeger disclose the controller of claim 1. Kulkarni and Kreeger disclose wherein the non-transitory storage medium further comprises endpoint discovery logic configured to identify newly added, modified, or deleted endpoints within one or more public cloud networks including the first virtual region and the second virtual region (Kulkarni, paragraph 0156, appliance reassigned from first region to second region; paragraph 0005, public cloud) (Kreeger, paragraph 0012, discovering endpoints in an overlayer environment for subsequent troubleshooting of network issues, paragraph 0031, discovering endpoints to troubleshoot connectivity; paragraph 0042, discover endpoints). Regarding claim 7, Kulkarni and Kreeger disclose the controller of claim 6. Kulkarni and Kreeger disclose wherein the recovered information associated with the newly discovered endpoint includes an identifier of the endpoint and an identifier of the virtual region (Kreeger, paragraph 0036, endpoint identifier, paragraph 0012, discovering endpoints in an overlayer environment for subsequent troubleshooting of network issues, paragraph 0031, discovering endpoints to troubleshoot connectivity; paragraph 0042, discover endpoints). Regarding claim 8, Kulkarni and Kreeger disclose the controller of claim 7. Kulkarni and Kreeger disclose wherein the identifier of the virtual region includes a virtual private cloud network (VPC) identifier upon which the newly discovered endpoint resides (Kreeger, paragraph 0036, endpoint identifier, paragraph 0012, discovering endpoints in an overlayer environment for subsequent troubleshooting of network issues, paragraph 0031, discovering endpoints to troubleshoot connectivity; paragraph 0042, discover endpoints).. Regarding claim 11, Kulkarni discloses a method for controlling network traffic flow separation between inter-VPC communications and intra-VPC communications via a controller comprising classification logic and rule generation logic, the method: (Kulkarni, paragraph 0051, VPC); recovering, via the controller, information that identifies newly added, modified, or deleted endpoints within one or more public cloud networks (Kulkarni, paragraph 0005, public cloud, performing functions; paragraph 0059, processor to create, modify, and retrieve); based on recovered information associated with a newly discovered endpoint, determining, via the classification logic of the controller, a virtual region in which the newly discovered endpoint resides (Kulkarni, paragraph 0064, policies configured based on application classification techniques; paragraph 0035, define applicable business policies region by region, business policies can be customized on a regional basis; paragraph 0059, processor to create, modify, and retrieve); generating , via the rule generation logic of the controller, a first subset of rules for controlling a flow of messages sourced by or destined to the endpoint via native cloud constructs associated with a cloud service provider (CSP) underlay network when the endpoint and another endpoint in communication with and operating as a destination and a source of the flow of messages with the endpoint reside within a first virtual region (Kulkarni, paragraph 0035, define applicable business policies region by region, local cloud security service provider in a region; paragraph 0159, security and networking policies customized on a regional basis; paragraph 0077, network traffic may traverse between each appliance in a region (intra-region); paragraph 0052, underlay network; paragraph 0059, processor to create, modify, and retrieve); generating, via the rule generation logic of the controller, a second subset of rules for controlling a flow of messages sourced by or destined to the endpoint via an overlay network providing communications between the first virtual region and a second virtual region when the endpoint and another endpoint reside within different virtual regions (Kulkarni, paragraph 0035, communication network divided into regions, applicable business polices can be defined region by region; paragraph 0036, each region can have different combinations of transport links with different link qualities and link bandwidths; paragraph 0052, overlay network; paragraph 0059, processor to create, modify, and retrieve); using, via the rule generation logic of the controller, micro-segmentation to set and manage security policies (Kulkarni, paragraph 0159, polices may be configured on a regional basis; paragraph 0038, segmentation , security policies; paragraph 0059, processor to create, modify, and retrieve). Kulkarni discloses generating, via the rule generation logic of the controller, a first subset of rules for controlling a flow of messages sourced by or destined to the endpoint via native cloud constructs associated with a cloud service provider (CSP) underlay network when the endpoint and another endpoint in communication with and operating as a destination and a source of the flow of messages with the endpoint reside within a first virtual region; generating, via the rule generation logic of the controller, a second subset of rules for controlling a flow of messages sourced by or destined to the endpoint via an overlay network providing communications between the first virtual region and a second virtual region when the endpoint and another endpoint reside within different virtual regions; but does not explicitly disclose generating, via the rule generation logic of the controller, a first subset of rules for controlling a flow of messages sourced by or destined to the newly discovered endpoint via native cloud constructs associated with a cloud service provider (CSP) underlay network when the newly discovered endpoint and another endpoint in communication with and operating as a destination and a source of the flow of messages with the newly discovered endpoint reside within a first virtual region; generating, via the rule generation logic of the controller, a second subset of rules for controlling a flow of messages sourced by or destined to the newly discovered endpoint via an overlay network providing communications between the first virtual region and a second virtual region when the newly discovered endpoint and another endpoint reside within different virtual regions. However, in an analogous art, Kreeger discloses generating, via the rule generation logic of the controller, a first subset of rules for controlling a flow of messages sourced by or destined to the newly discovered endpoint via native cloud constructs associated with a cloud service provider (CSP) underlay network when the newly discovered endpoint and another endpoint in communication with and operating as a destination and a source of the flow of messages with the newly discovered endpoint reside within a first virtual region (Kreeger, paragraph 0012, discovering endpoints in an overlayer environment for subsequent troubleshooting of network issues, paragraph 0031, discovering endpoints to troubleshoot connectivity; paragraph 0042, discover endpoints); generating, via the rule generation logic of the controller, a second subset of rules for controlling a flow of messages sourced by or destined to the newly discovered endpoint via an overlay network providing communications between the first virtual region and a second virtual region when the newly discovered endpoint and another endpoint reside within different virtual regions (Kreeger, paragraph 0012, discovering endpoints in an overlayer environment for subsequent troubleshooting of network issues, paragraph 0031, discovering endpoints to troubleshoot connectivity; paragraph 0042, discover endpoints). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Kreeger with the controller/ method/ nontransitory storage medium of Kulkarni to include newly discovered endpoints to provide users with the benefits of discovering multipoint endpoints in a network environment (Kreeger: paragraph 0001). Regarding claim 12, Kulkarni and Kreeger disclose the method of claim 11. Kulkarni and Kreeger discloses wherein the first virtual region corresponds to a first virtual private cloud network (VPC) and the second virtual region corresponds to a second VPC (Kulkarni, paragraph 0048, first location 110, second location 120, private network; paragraph 0055 private cloud network). Regarding claim 13, Kulkarni and Kreeger disclose the method of claim 12. Kulkarni and Kreeger discloses wherein the first VPC resides within a first public cloud network and a second VPC resides within a second public cloud network different than the first public cloud network (Kulkarni, paragraph 0056, first locations, second locations, different web services (locations)). Regarding claim 14, Kulkarni and Kreeger disclose the method of claim 12. Kulkarni and Kreeger discloses wherein the second subset of rules include filtering rules that formulate one or more policies that influence a propagation of inter-VPC network traffic over the overlay network establishing a communication path between the first VPC and the second VPC (Kulkarni, paragraph 0038, policies, local configuration, global aspects; paragraph 0093, routing). Regarding claim 16, Kulkarni and Kreeger disclose the method of claim 11. Kulkarni and Kreeger disclose wherein the recovered information associated with the newly discovered endpoint includes an identifier of the endpoint and an identifier of the first virtual region (Kreeger, paragraph 0036, endpoint identifier, paragraph 0012, discovering endpoints in an overlayer environment for subsequent troubleshooting of network issues, paragraph 0031, discovering endpoints to troubleshoot connectivity; paragraph 0042, discover endpoints). Regarding claim 18, Kulkarni discloses a non-transitory storage medium including logic that, upon execution, controls flow separation for inter-VPC communications and intra-VPC communications, comprising: (Kulkarni, paragraph 0051, VPC, paragraph 0059, software, processor, storage, RAM memory); endpoint discovery logic configured to identify newly added, modified, or deleted endpoints within a plurality of public cloud networks (Kulkarni, paragraph 0005, public cloud, performing functions); classification logic configured, based on recovered information associated with an endpoint, to determine a virtual region in which the endpoint resides (Kulkarni, paragraph 0064, policies configured based on application classification techniques; paragraph 0035, define applicable business policies region by region, business policies can be customized on a regional basis); rule generation logic configured to (i) generate a first subset of rules for controlling a flow of messages between a destination and a source via native cloud constructs associated with a cloud service provider (CSP) underlay network when the destination and source reside within a first virtual region (Kulkarni, paragraph 0035, define applicable business policies region by region, local cloud security service provider in a region; paragraph 0159, security and networking policies customized on a regional basis; paragraph 0077, network traffic may traverse between each appliance in a region (intra-region); paragraph 0052, underlay network); (ii) generate a second subset of rules for controlling a flow of messages between the destination and the source via an overlay network providing communications between the first virtual region and a second virtual region when the destination and the source reside within different virtual regions (Kulkarni, paragraph 0035, communication network divided into regions, applicable business polices can be defined region by region; paragraph 0036, each region can have different combinations of transport links with different link qualities and link bandwidths; paragraph 0052, overlay network); use micro-segmentation to set and manage security policies (Kulkarni, paragraph 0159, polices may be configured on a regional basis; paragraph 0038, segmentation , security policies). Kulkarni discloses classification logic configured, based on recovered information associated with an endpoint, to determine a virtual region in which the endpoint resides; but does not explicitly disclose classification logic configured, based on recovered information associated with a newly discovered endpoint, to determine a virtual region in which the newly discovered endpoint resides. However, in an analogous art, Kreeger discloses based on recovered information associated with a newly discovered endpoint, determining a virtual region in which the newly discovered endpoint resides (Kreeger, paragraph 0012, discovering endpoints in an overlayer environment for subsequent troubleshooting of network issues, paragraph 0031, discovering endpoints to troubleshoot connectivity; paragraph 0042, discover endpoints). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Kreeger with the controller/ method/ nontransitory storage medium of Kulkarni to include classification logic configured, based on recovered information associated with a newly discovered endpoint, to determine a virtual region in which the newly discovered endpoint resides to provide users with the benefits of discovering multipoint endpoints in a network environment (Kreeger: paragraph 0001). Regarding claim 19, Kulkarni and Kreeger disclose the non-transitory storage medium of claim 18. Kulkarni and Kreeger disclose wherein the second subset of rules includes a rule that controls and filters the messages over the overlay network when the source resides in the first virtual region included in the first public cloud network and the destination resides in the second virtual region included in the second public cloud network, to be enforced by native cloud constructs to propagate messages perform intra-VPC network traffic controls for messaging between and a second subset of rules to be enforced by one or more spoke gateways to perform inter-VPC network traffic controls (Kulkarni, paragraph 0035, define policies region by region, paragraph 0036, different links per region; paragraph 0038 policies; paragraph 0093, filtering). Claims 5, 9, 15, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Kulkarni (US20220103471), filed August 4, 2021, in view of Kreeger (US20130170490), filed December 30, 2011, and further in view of Janakiraman (US20200059492), filed August 20, 2018. Regarding claim 5, Kulkarni and Kreeger disclose the controller of claim 4. Kulkarni and Kreeger disclose an underlay network (Kulkarni, paragraph 0035, define applicable business policies region by region, local cloud security service provider in a region; paragraph 0159, security and networking policies customized on a regional basis; paragraph 0077, network traffic may traverse between each appliance in a region (intra-region); paragraph 0052, underlay network), but do not explicitly disclose wherein the first set of rules include filtering rules that formulate one or more policies that influence a propagation of intra-VPC network traffic over the underlay network. However, in an analogous art, Janakiraman discloses wherein the first set of rules include filtering rules that formulate one or more policies that influence a propagation of intra-VPC network traffic over the underlay network. However, in an analogous art, Janakiraman discloses wherein the first set of rules include filtering rules that formulate one or more policies that influence a propagation of intra-VPC network traffic over the underlay network (Janakiraman, paragraph 0091, rules for intra-VPC traffic, paragraph 0036, filters). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Janakiraman with the controller/ method/ nontransitory storage medium of Kulkarni and Kreeger to include wherein the first set of rules include filtering rules that formulate one or more policies that influence a propagation of intra-VPC network traffic over the underlay network to provide users with the benefits of multi-cloud policy scaling and integration (Janakiraman: paragraph 0001). Regarding claim 9, Kulkarni and Kreeger disclose the controller of claim 8. Kulkarni and Kreeger do not explicitly disclose wherein the non-transitory storage medium further comprises logic to create and maintain an endpoint-to-VPC identifier mapping for use in determining whether or not security group orchestration is needed to support intra-VPC communications between the source and the destination. However, in an analogous art, Janakiraman discloses wherein the non-transitory storage medium further comprises logic to create and maintain an endpoint-to-VPC identifier mapping for use in determining whether or not security group orchestration is needed to support intra-VPC communications between the source and the destination (Janakiraman: paragraph 0091, intra-VPC traffic; paragraph 0080, endpoints, VPC, mapped, mapping endpoints; paragraph 0081, distributing security policies, mapped, endpoints, VPC). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Janakiraman with the controller/ method/ nontransitory storage medium of Kulkarni and Kreeger to include wherein the non-transitory storage medium further comprises logic to create and maintain an endpoint-to-VPC identifier mapping for use in determining whether or not security group orchestration is needed to support intra-VPC communications between the source and the destination to provide users with the benefits of multi-cloud policy scaling and integration (Janakiraman: paragraph 0001). Regarding claim 15, Kulkarni and Kreeger disclose the method of claim 14. Kulkarni and Kreeger disclose an underlay network (Kulkarni, paragraph 0035, define applicable business policies region by region, local cloud security service provider in a region; paragraph 0159, security and networking policies customized on a regional basis; paragraph 0077, network traffic may traverse between each appliance in a region (intra-region); paragraph 0052, underlay network), but do not explicitly disclose wherein the first subset of rules include filtering rules that formulate one or more policies that influence a propagation of intra-VPC network traffic over the underlay network. However, in an analogous art, Janakiraman discloses wherein the first subset of rules include filtering rules that formulate one or more policies that influence a propagation of intra-VPC network traffic over the underlay network. However, in an analogous art, Janakiraman discloses wherein the first subset of rules include filtering rules that formulate one or more policies that influence a propagation of intra-VPC network traffic over the underlay network (Janakiraman, paragraph 0091, rules for intra-VPC traffic, paragraph 0036, filters). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Janakiraman with the controller/ method/ nontransitory storage medium of Kulkarni and Kreeger to include wherein the first subset of rules include filtering rules that formulate one or more policies that influence a propagation of intra-VPC network traffic over the underlay network to provide users with the benefits of multi-cloud policy scaling and integration (Janakiraman: paragraph 0001). Regarding claim 17, Kulkarni and Kreeger disclose the method of claim 11. Kulkarni and Kreeger do not explicitly disclose further comprising: creating and maintaining an endpoint-to-VPC identifier mapping for use in determining whether or not security group orchestration is needed to support intra-VPC communications between the newly discovered endpoint and another endpoint. However, in an analogous art, Janakiraman discloses further comprising: creating and maintaining an endpoint-to-VPC identifier mapping for use in determining whether or not security group orchestration is needed to support intra-VPC communications between the newly discovered endpoint and another endpoint (Janakiraman: paragraph 0091, intra-VPC traffic; paragraph 0080, endpoints, VPC, mapped, mapping endpoints; paragraph 0081, distributing security policies, mapped, endpoints, VPC). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Janakiraman with the controller/ method/ nontransitory storage medium of Kulkarni and Kreeger to include further comprising: creating and maintaining an endpoint-to-VPC identifier mapping for use in determining whether or not security group orchestration is needed to support intra-VPC communications between the newly discovered endpoint and another endpoint to provide users with the benefits of multi-cloud policy scaling and integration (Janakiraman: paragraph 0001). Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Kulkarni (US20220103471), filed August 4, 2021, in view of Kreeger (US20130170490), filed December 30, 2011, and further in view of Shevade (US20220311744), filed March 29 2021. Regarding claim 10, Kulkarni and Kreeger disclose the controller of claim 6. Kulkarni and Kreeger do not explicitly disclose wherein the non-transitory storage medium further comprises security group generation logic configured to generate one or more network security groups, each network security group operating as a virtual firewall that is associated with an identified endpoint. However, in an analogous art, Shevade discloses wherein the non-transitory storage medium further comprises security group generation logic configured to generate one or more network security groups, each network security group operating as a virtual firewall that is associated with an identified endpoint (Shevade, paragraph 0015, network security groups, virtual firewall). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Shevade with the controller/ method/ nontransitory storage medium of Kulkarni and Kreeger to include wherein the non-transitory storage medium further comprises security group generation logic configured to generate one or more network security groups, each network security group operating as a virtual firewall that is associated with an identified endpoint to provide users with the benefits of extending cloud-based virtual private networks to radio-based networks (Shevade: abstract). Claim 21 is rejected under 35 U.S.C. 103 as being unpatentable over Kulkarni (US20220103471), filed August 4, 2021, in view of Kreeger (US20130170490), filed December 30, 2011, and further in view of Aharon (US20220029881), filed July 29, 2021. Regarding claim 21, Kulkarni and Kreeger disclose the controller of claim 1. Kulkarni and Kreeger do not explicitly disclose wherein the non-transitory storage medium further comprises management logic configured to issue resource discovery messages through CSP- provided APIs to native cloud components and receive discovery response messages containing network addresses and attributes for resources within a virtual private cloud network. However, in an analogous art, Aharon discloses wherein the non-transitory storage medium further comprises management logic configured to issue resource discovery messages through CSP- provided APIs to native cloud components and receive discovery response messages containing network addresses and attributes for resources within a virtual private cloud network (Aharon, paragraph 0266, network address, discovery of resources, API, virtual, cloud; paragraph 0311, discovery of resources, cloud service, API, network address; paragraph 0395, network address, discovery of resources, API). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Aharon with the controller/ method/ nontransitory storage medium of Kulkarni and Kreeger to include wherein the non-transitory storage medium further comprises management logic configured to issue resource discovery messages through CSP- provided APIs to native cloud components and receive discovery response messages containing network addresses and attributes for resources within a virtual private cloud network to provide users with the benefits of network load balancing (Aharon: abstract). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to WALTER J MALINOWSKI whose telephone number is (571)272-5368. The examiner can normally be reached 8-6:30 MTWH. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, LUU PHAM can be reached at 5712705002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /W.J.M/Examiner, Art Unit 2439 /LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Oct 30, 2024
Application Filed
May 07, 2026
Non-Final Rejection mailed — §101, §103
Jun 02, 2026
Response Filed
Jun 23, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699798
METHOD AND SYSTEM TO IMPLEMENT PRIVACY-PRESERVING COLLABORATIVE SEMANTIC MAPPING
1y 4m to grant Granted Aug 04, 2026
Patent 12688472
SYSTEMS AND METHODS FOR MANAGING SUBORDINATE WORKSPACES
3y 6m to grant Granted Jul 21, 2026
Patent 12682123
LINE ENCRYPTION OVER ETHERNET CABLE
3y 6m to grant Granted Jul 14, 2026
Patent 12657320
SECURE CONTACT TRACING BETWEEN COMPUTING DEVICES
2y 10m to grant Granted Jun 16, 2026
Patent 12639463
SYSTEMS AND METHODS FOR STORING AND RETRIEVING PUBLIC DATA
2y 5m to grant Granted May 26, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
70%
Grant Probability
99%
With Interview (+52.8%)
3y 0m (~1y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 341 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month