Detailed Action
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This Office action is in response to Applicant’s amendment filed on March 10, 2026.
Claims 1-21 are pending in the application.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on July 13, 2026 has been entered.
Response to Arguments/Remarks
Claim Rejections - 35 USC § 112
Claims 5-6 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim subject matter.
The amendments to the claims have addressed the rejection. Accordingly, the rejection has been withdrawn.
Claim Rejections - 35 USC § 102/103
Claims 1-4, 10-12, and 15 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Jacquin et al. US Patent Publication No. 2017/0230245 (“Jacquin”).
Claims 16-19 are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin et al. US Patent Publication No. 2017/0230245 in view of Smith et al. US Patent Publication No. 2017/0346640.
Applicant argued that Jacquin does not teach the limitation, “the evidence for the self-attestation, the evidence for the self-attestation being tunneled via at least one transport protocol and transported by respective network management messages of the managed network deployment.” Applicant’s arguments and corresponding amendments have overcome the prior rejection. Therefore, the rejection has been withdrawn. New grounds of rejection are presented in this Office action.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 21 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding claim 21, the claim recites “The at least one processor of claim 1, wherein a first device of the set at a first level of a network topology of the managed network deployment is to transmit the evidence for the self-attestation of the first device to a second device of the set at a higher level of the network topology, the second device to verify trust in the first device.” The claim defines function of a first device, “a first device… is to transmit the evidence for the self-attestation of the first device to a second device,” and a function of a second device, “the second device to verify trust in the first device.” Claim 1 is directed to a processor comprising hardware circuitry to perform functions, presumably the managing device since the claim expressly states, “verify, by a managing device.” The cited limitations of claim 21 do not further define the processor by structure or function. The scope of the invention is not clear. It is suggested that claim 1 be amended to a “system” claim comprising the managing device, first device, and the second device.
Claim Rejections - 35 USC § 103
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
Claims 1-4, 10-12, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin et al. US Patent Publication No. 2017/0230245 (“Jacquin”) in view of Kumar et al. US Patent Publication No. 2025/0265337 (“Kumar”) and Hunsaker et al. US Patent Publication No. 2019/0228160 (“Hunsaker”).
Regarding claim 1, Jacquin teaches at least one processor comprising hardware circuitry to:
determine that attestation is to be performed for a set of devices to be included in a managed network deployment (para. [0031] attestation request 212 includes back-end network configuration requirements. back-end network configuration requirements may include a request for attestation of isolation of each network element.);
cause individual devices of the set to perform self-attestation and transmit, in respective network management messages, evidence for the self-attestation (para. [0033] provides each network element included in the back-end network 250 with a request 214 for attestation of a network element configuration of the network element. para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216); and
verify, by a managing device of the managed network deployment, trust in one or more of the devices of the managed network deployment at least a portion of the evidence for the self-attestation received in one or more of the network management messages (para. [0035] trust engine 230 verifies that the response data 216 meets the back-end network configuration requirements included in the request for attestation of the back-end network 250. verify that network communications through the back-end networks of the clients are isolated. trust engine 230 verifies software requirements, such as software version numbers, software compatibility, and software security).
Jacquin does not teach the evidence for the self-attestation, the evidence for the self-attestation being tunneled via at least one transport protocol and transported by respective network management messages of the managed network deployment.
Kumar teaches evidence for self-attestation, the evidence for the self-attestation being sent via at least one transport protocol and transported by respective network management messages of a managed network deployment (para. [0046] RoT 115 and BMC 113 may communicate with each other according to the Management Component Transport Protocol (MCTP). para. [0086] BMC 113 may provide signed attestation report received back from RoTs 115 to the token provisioning system 140 (e.g., in response to the attestation report solicitation request). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin with Kumar’s disclosure of transmitting evidence for self-attestation via the transport protocol and by messages of MCTP. One of ordinary skill in the in the art would have been motivated to do so for benefits of providing a protocol to support different management functions (para. [0046]).
Hunsaker teaches tunneling messages via at least one transport protocol (para. [0011] eSPI 20 tunnels communications (e.g., data collection traffic in the form of, for example, Management Component Transport Protocol/MCTP messages and/or embedded packets). para. [0019] tunneled communications include data collection traffic. additionally, the communications may include MCTP messages and/or embedded packets). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin and Kumar with Hunsaker’s disclosure of tunneling messages via a transport protocol. One of ordinary skill in the in the art would have been motivated to do so for benefits of secured communications (para. [0020]).
Regarding claim 10, Jacquin teaches a system, comprising:
one or more processors, each processor comprising hardware circuitry to:
determine that attestation is to be performed for a set of devices to be included in a managed network deployment (para. [0031] attestation request 212 includes back-end network configuration requirements. back-end network configuration requirements may include a request for attestation of isolation of each network element.);
cause individual devices of the set to perform self-attestation and transmit, in respective network management messages, evidence for the self-attestation (para. [0033] provides each network element included in the back-end network 250 with a request 214 for attestation of a network element configuration of the network element. para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216); and
verify, by a managing device of the managed network deployment receiving the respective network management messages, trust in one or more of the devices of the managed network deployment based in part on at least a portion of the evidence for the self-attestation (para. [0035] trust engine 230 verifies that the response data 216 meets the back-end network configuration requirements included in the request for attestation of the back-end network 250. verify that network communications through the back-end networks of the clients are isolated. In some implementations, the trust engine 230 verifies software requirements, such as software version numbers, software compatibility, and software security).
Jacquin does not teach the evidence for the self-attestation, the evidence for the self-attestation being tunneled via at least one transport protocol and transported by respective network management messages of the managed network deployment.
Kumar teaches evidence for self-attestation, the evidence for the self-attestation being sent via at least one transport protocol and transported by respective network management messages of a managed network deployment (para. [0046] RoT 115 and BMC 113 may communicate with each other according to the Management Component Transport Protocol (MCTP). para. [0086] BMC 113 may provide signed attestation report received back from RoTs 115 to the token provisioning system 140 (e.g., in response to the attestation report solicitation request). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin with Kumar’s disclosure of transmitting evidence for self-attestation via the transport protocol and by messages of MCTP. One of ordinary skill in the in the art would have been motivated to do so for benefits of providing a protocol to support different management functions (para. [0046]).
Hunsaker teaches tunneling messages via at least one transport protocol (para. [0011] eSPI 20 tunnels communications (e.g., data collection traffic in the form of, for example, Management Component Transport Protocol/MCTP messages and/or embedded packets). para. [0019] tunneled communications include data collection traffic. additionally, the communications may include MCTP messages and/or embedded packets). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin and Kumar with Hunsaker’s disclosure of tunneling messages via a transport protocol. One of ordinary skill in the in the art would have been motivated to do so for benefits of secured communications (para. [0020]).
Regarding claim 2, Jacquin in view of Kumar and Hunsaker teach the at least one processor of claim 1, wherein the devices of the managed network deployment include at least one of servers, processors, network interface cards, routers, load balancers, network switches, or core switches (Jacquin: para. [0018] network element, such as a server computer, a network switch, a network router).
Regarding claim 3, Jacquin in view of Kumar and Hunsaker teach the at least one processor of claim 1, wherein the hardware circuitry are further to cause a first set of devices of the managed network deployment to send the evidence for the self-attestation in network management messages to one or more second devices of the managed network deployment for verification, wherein the managing device receives network management messages from at most the one or more second devices (Jacquin: para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216. para. [0036] trust engine 230 provides the client device 210 with data 218 verifying that the back-end network 250).
Regarding claim 4, Jacquin in view of Kumar and Hunsaker teach the at least one processor of claim 1, wherein the hardware circuitry are further to determine to perform the attestation for the set of devices to be included in the managed network deployment corresponding to an initial network configuration, a periodic reverification, or a connection of a new network device (Jacquin: para. [0043] dynamic reconfiguration may result in changes to the back-end network 250, and the trust engine 230 can periodically monitor the back-end network 250 for changes. when changes are detected, the trust engine 230 may verify the changed portion, or re-verify the entire back-end network 250, and provide the client device 210 with updated verification data. para. [0044] assign a new network element, such as network element Z 260, to take the place of network element E 255. As network element Z 260 was not verified during the initial verification of the back-end network 250, the trust engine 230 may send network element Z 260 an attestation request).
Regarding claim 11, Jacquin in view of Kumar and Hunsaker teach the system of claim 10, wherein the one or more processors are further to cause a first set of devices of the managed network deployment to send the evidence for the self-attestation in network management messages to one or more second devices of the managed network deployment for verification, wherein the managing device receives network management messages from at most the one or more second devices (Jacquin: para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216. para. [0036] trust engine 230 provides the client device 210 with data 218 verifying that the back-end network 250).
Regarding claim 12, Jacquin in view of Kumar and Hunsaker teach the system of claim 10, wherein the evidence for the self-attestation includes one or more values representative of a state of the individual devices (Jacquin: para. [0034] network element configuration includes data specifying links between the corresponding network element and other network elements. response data 216 may include, for example, the port forwarding rules of each respective network element and/or software measurements).
Regarding claim 15, Jacquin in view of Kumar and Hunsaker teach the system of claim 10, wherein the system is at least one of:
a system for performing simulation operations;
a system for performing simulation operations to test or validate autonomous machine applications;
a system for performing digital twin operations;
a system for performing light transport simulation;
a system for rendering graphical output;
a system for performing deep learning operations;
a system for performing generative AI operations using a large language model (LLM);
a system implemented using an edge device;
a system for generating or presenting virtual reality (VR) content;
a system for generating or presenting augmented reality (AR) content;
a system for generating or presenting mixed reality (MR) content;
a system incorporating one or more Virtual Machines (VMs);
a system implemented at least partially in a data center;
a system for performing hardware testing using simulation;
a system for performing generative operations using a language model (LM);
a system for synthetic data generation;
a collaborative content creation platform for 3D assets; or
a system implemented at least partially using cloud computing resources (Jacquin: para. [0043] cloud network 220).
Claims 5-6 are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Kumar, Hunsaker, and Jacquin et al. US Patent Publication No. 2017/0222878 (“Jacquin ‘878”).
Regarding claim 5, Jacquin does not teach the at least one processor of claim 1, wherein the hardware circuitry is further cause transmission of the respective network management messages to a network controller of the managed network deployment.
Jacquin ‘878 teaches hardware circuitry cause transmission of respective network management messages to a network controller of the managed network deployment (para. [0009] SDN controller… dynamically change configurations. reconfigure a subset of network elements. para. [0021] verifier 140 may be any device in communication with the computing device 100, such as… SDN controller. para. [0035] SDN controller and network elements are included in an SDN managed by the SDN controller 270… para. [0036] verifier 210 provides the network element 220 with a request 212 for attestation. para. [0044] receives the response data 254 from the trusted component 250. verify both the network configuration and software measurements. para. [0046] request is received, at a network element and from a verifier, for attestation of i) software measurements for the network element). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Jacquin ‘878’s disclosure of causing transmission of the respective network management messages to a network controller of the managed network deployment. One of ordinary skill in the art would have been motivated to do so in order to have ensured correct configuration by similarly providing capability for a network controller to verify network configuration of devices.
Regarding claim 6, Jacquin teaches the at least one processor of claim 5, wherein the hardware circuitry is further to verify the trust in the one or more devices before the managed network deployment is configured (para. [0035] trust engine 230 verifies that the response data 216 meets the back-end network configuration requirements included in the request for attestation of the back-end network 250). Jacquin does not teach the hardware circuitry configured to receive, from the network controller, at least one request of an attestation report, and.
Jacquin ‘878 teaches hardware circuitry is to receive, from a network controller, at least one request of an attestation report (para. [0021] verifier 140 may be any device in communication with the computing device 100, such as… SDN controller, para. [0035] SDN controller and network elements are included in an SDN managed by the SDN controller 270… para. [0046] request is received, at a network element and from a verifier, for attestation of i) software measurements for the network element). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Jacquin ‘878’s disclosure of receiving, from a network controller, a request for an attestation report. One of ordinary skill in the art would have been motivated to do so in order to have ensured correct configuration by similarly providing capability for a network controller to verify network configuration of devices.
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Kumar, Hunsaker, and Schroeder et al. US Patent No. 11,165,778 (“Schroeder”).
Regarding claim 7, Jacquin does not teach the at least one processor of claim 1, wherein hardware circuitry are to assign trusted devices to a first subnet and untrusted devices to a second subnet of the managed network deployment.
Schroeder suggests hardware circuitry are to assign trusted devices to a first subnet and untrusted devices to a second subnet of a managed network deployment (col. 3, line 64-col. 4, line 2; col. 7, line 1-7. highly trustworthy computing devices are assigned to an operating network with more privileges (e.g., a trusted network segment) than less trustworthy computing devices. less trustworthy computing devices are assigned to an operating network segment). While Schroeder does not expressly disclose untrusted devices, it would have been obvious to one of ordinary skill in the art to include untrusted devices with less trustworthy devices and/or restrict privileges for untrusted devices based on Schroder’s disclosure. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have applied Schroeder’s disclosure of assigning devices based on trust such that devices are assigned to subnets based on trust associated with devices. One of ordinary skill in the art would have been motivated to do so in order to have improved network security.
Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Kumar, Hunsaker, Gavrilov et al. US Patent Publication No. 2021/0349794 (“Gavrilov”) and Bhandari et al. US Patent Publication No. 2020/0322075 (“Bhandrai”).
Regarding claim 8, Jacquin does not teach the at least one processor of claim 1, wherein the network management messages correspond to management datagrams (MADs) of an InfiniBand deployment, and wherein the MAD headers are extended to include the evidence for the self-attestation.
Gavrilov teaches network management messages corresponding to management datagrams (MADs) of an InfiniBand deployment (para. [0088] in Infiniband fabric, the first management query may include an SMP (Subnet Management Protocol) MAD. para. [0166] Infiniband environment, management datagrams (MADs) are used to discover and configure the fabric and to execute remote hardware or software commands). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Gavrilov’s disclosure of utilizing messages corresponding to MADs of an InfiniBand deployment. One of ordinary skill in the art would have been motivated to do so for benefits of providing management functions including discovery and configuration (para. [0166]-[0167]).
Bhandari teaches extending headers to include evidence for self-attestation (para. [0121] attestation information can be included as a separate field or as extensions to exiting fields. para. [0132] attestation information can include Proof of Integrity). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin and Gavrilov with Bhandari’s disclosure such the datagrams are extended to include evidence for self-attestation. One of ordinary skill in the art would have been motivated to do so in order to have utilized existing messages, using extensions, to communicate additional information.
Claims 9 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Kumar, Hunsaker, and M et al. US Patent Publication No. 2022/0104100 (“M”).
Regarding claim 9, Jacquin does not teach the at least one processor of claim 1, wherein hardware circuitry are further to identify at least one trusted path through the managed network deployment corresponding to devices of the set where the self-attestation is verified.
M teaches hardware circuitry are to identify at least one trusted path through a managed network deployment corresponding to devices of a set where the self-attestation is verified (para. [0023] MR uses the attestation information to verify whether the neighbor MR is trustworthy. para. [0032] verifier verifies the evidence to select trustworthiness levels for the features. para. [0050] destination node determines which of the accumulated paths are trusted paths based on the trust indicators for the mesh routers along the accumulated paths. para. [0061] RREQ packet carries attestation information, so that the next MR in the path to the destination MR can validate to verify the proof of integrity of the MR). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have applied M’s disclosure of identifying a trusted path based on verifying attestation of devices. One of ordinary skill in the art would have been motivated to do so for improved security by determining a path among trusted paths (para. [0012]).
Regarding claim 14, Jacquin does not teach the system of claim 10, wherein the one or more processors are further to identify at least one trusted path through the managed network deployment corresponding to devices of the set where the self-attestation is verified, and wherein trusted data is to be propagated using only the at least one trusted path through the managed network deployment.
M teaches identify at least one trusted path through a managed network deployment corresponding to devices of a set where the self-attestation is verified, and wherein trusted data is to be propagated using only the at least one trusted path through the managed network deployment. (para. [0023] MR uses the attestation information to verify whether the neighbor MR is trustworthy. para. [0032] verifier verifies the evidence to select trustworthiness levels for the features. para. [0050] destination node determines which of the accumulated paths are trusted paths based on the trust indicators for the mesh routers along the accumulated paths. para. [0061] RREQ packet carries attestation information, so that the next MR in the path to the destination MR can validate to verify the proof of integrity of the MR). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have applied M’s disclosure of identifying a trusted path based on verifying attestation of devices. One of ordinary skill in the art would have been motivated to do so for improved security by determining a path among trusted paths (para. [0012]).
Claim 13 is are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Kumar, Hunsaker, and Cabre et al. US Patent Publication No. 2022/0303123 (“Cabre”).
Regarding claim 13, Jacquin does not teach the system of claim 12, wherein the evidence is signed using an endorsement from respective manufacturers of the individual devices.
Cabre teaches evidence signed using an endorsement from respective manufacturers of the individual devices (para. [0105] obtain attestation evidence associated with the subject device. attestation evidence is provided by the device platform, and the attestation evidence is signed by a certificate produced using a manufacturer-embedded key). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Cabre’s disclosure of signing evidence using an endorsement from respective manufacturers of the individual devices. One of ordinary skill in the art would have been motivated to do so in order to have improved security and verification of evidence of the attestation.
Claims 16-19 are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin et al. US Patent Publication No. 2017/0230245 (“Jacquin”) in view of Smith et al. US Patent Publication No. 2017/0346640 (“Smith), Kumar et al. US Patent Publication No. 2025/0265337 (“Kumar”), and Hunsaker et al. US Patent Publication No. 2019/0228160 (“Hunsaker”).
Regarding claim 16, Jacquin teaches a subnet manager, comprising:
one or more processing units, each processing unit implemented in hardware circuitry and configured to:
transmit a request for attestation that is to be performed by devices in a managed subnet to be included in a managed network deployment (para. [0031] attestation request 212 includes back-end network configuration requirements. back-end network configuration requirements may include a request for attestation of isolation of each network element.);
receive, from the devices of the managed subnet, respective network management messages including self-attestation evidence for the devices (para. [0033] provides each network element included in the back-end network 250 with a request 214 for attestation of a network element configuration of the network element. para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216); and
verify trust in one or more of the devices of the managed subnet based in part on at least a portion of the evidence for the self-attestation received in one or more of the network management messages (para. [0035] trust engine 230 verifies that the response data 216 meets the back-end network configuration requirements included in the request for attestation of the back-end network 250. verify that network communications through the back-end networks of the clients are isolated. In some implementations, the trust engine 230 verifies software requirements, such as software version numbers, software compatibility, and software security).
Jacquin teaches transmitting a request for attestation but does not expressly teach broadcast the request for attestation.
Jacquin does not teach the evidence for the self-attestation, the evidence for the self-attestation being tunneled via at least one transport protocol and transported by respective network management messages of the managed network deployment.
Smith teaches broadcasting a request for attestation (para. [0063] computing device 102 may send the request for attestation to one or more members of the particular subsystem, for example by broadcasting a request to all computing devices 102 in the subsystem). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Smith’s disclosure of broadcasting a request for attestation. One of ordinary skill in the art would have been motivated to do so in order to have similarly ensured that all required devices in a subsystem receive and respond to the request for attestation.
Kumar teaches evidence for self-attestation, the evidence for the self-attestation being sent via at least one transport protocol and transported by respective network management messages of a managed network deployment (para. [0046] RoT 115 and BMC 113 may communicate with each other according to the Management Component Transport Protocol (MCTP). para. [0086] BMC 113 may provide signed attestation report received back from RoTs 115 to the token provisioning system 140 (e.g., in response to the attestation report solicitation request). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin with Kumar’s disclosure of transmitting evidence for self-attestation via the transport protocol and by messages of MCTP. One of ordinary skill in the in the art would have been motivated to do so for benefits of providing a protocol to support different management functions (para. [0046]).
Hunsaker teaches tunneling messages via at least one transport protocol (para. [0011] eSPI 20 tunnels communications (e.g., data collection traffic in the form of, for example, Management Component Transport Protocol/MCTP messages and/or embedded packets). para. [0019] tunneled communications include data collection traffic. additionally, the communications may include MCTP messages and/or embedded packets). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin and Kumar with Hunsaker’s disclosure of tunneling messages via a transport protocol. One of ordinary skill in the in the art would have been motivated to do so for benefits of secured communications (para. [0020]).
Regarding claim 17, Jacquin in view of Smith, Kumar, and Hunsaker teach the subnet manager of claim 16, wherein the one or more processing units are further to cause a first set of devices of the managed subnet to send the evidence for the self-attestation in network management messages to one or more second devices of the managed subnet for verification, wherein the subnet manager receives the network management messages from at most the one or more second devices (Jacquin: para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216. para. [0036] trust engine 230 provides the client device 210 with data 218 verifying that the back-end network 250).
Regarding claim 18, Jacquin in view of Smith, Kumar, and Hunsaker teach the subnet manager of claim 16, wherein the one or more processing units are further to determine to perform the attestation for the set of devices to be included in the managed subnet corresponding to an initial network configuration, a periodic reverification, or a connection of a new network device (Jacquin: para. [0043] dynamic reconfiguration may result in changes to the back-end network 250, and the trust engine 230 can periodically monitor the back-end network 250 for changes. when changes are detected, the trust engine 230 may verify the changed portion, or re-verify the entire back-end network 250, and provide the client device 210 with updated verification data. para. [0044] assign a new network element, such as network element Z 260, to take the place of network element E 255. As network element Z 260 was not verified during the initial verification of the back-end network 250, the trust engine 230 may send network element Z 260 an attestation request).
Regarding claim 19, Jacquin in view of Smith, Kumar, and Hunsaker teach the subnet manager of claim 16, wherein the evidence for the self-attestation includes one or more values representative of a state of the individual devices (Jacquin: para. [0034] network element configuration includes data specifying links between the corresponding network element and other network elements. response data 216 may include, for example, the port forwarding rules of each respective network element and/or software measurements).
Claim 20 is are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Smith, Kumar, Hunsaker, and Cabre et al. US Patent Publication No. 2022/0303123 (“Cabre”).
Regarding claim 20, Jacquin does not teach the subnet manager of claim 19, wherein the evidence is signed using an endorsement from respective manufacturers of the individual devices.
Cabre teaches evidence signed using an endorsement from respective manufacturers of the individual devices (para. [0105] obtain attestation evidence associated with the subject device. attestation evidence is provided by the device platform, and the attestation evidence is signed by a certificate produced using a manufacturer-embedded key). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Cabre’s disclosure of signing evidence using an endorsement from respective manufacturers of the individual devices. One of ordinary skill in the art would have been motivated to do so in order to have improved security and verification of evidence of the attestation.
Examiner’s Note
The following prior art made of record and not relied upon is considered pertinent to applicant’s disclosure.
Moyer et al. US Patent Publication No. 2025/0211619 (para. [0031] after establishing the communication session 22, the first computing device 10a receives, via the communication session 22, an attestation request 172 (e.g., using an HTTP request or an HTTPS tunnel. Para. [0033] attestation report may include a variety of information)
Kim et al. US Patent Publication No. 2024/0168675 (para. [0046] host 200 and the CXL devices 220 and 240 may perform device attestation. host 200 and the CXL devices 220 and 240 may conform to the Security Protocol and Data Model (SPDM) over Management Component Transport Protocol (MCTP) architecture/protocol
Conclusion
A shortened statutory period for reply to this Office action is set to expire THREE MONTHS from the mailing date of this action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Joshua Joo whose telephone number is (571)272-3966. The examiner can normally be reached Monday-Friday 7am-3pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar Louie can be reached at 571-270-1684. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JOSHUA JOO/Primary Examiner, Art Unit 2445