Prosecution Insights
Last updated: October 02, 2026
Application No. 18/901,515

DEVICE ATTESTATION IN MANAGED NETWORKS

Non-Final OA §102§103§112
Filed
Sep 30, 2024
Examiner
JOO, JOSHUA
Art Unit
2445
Tech Center
2400 — Computer Networks
Assignee
Mellanox Technologies Ltd.
OA Round
3 (Non-Final)
78%
Grant Probability
Favorable
3-4
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
782 granted / 997 resolved
+20.4% vs TC avg
Strong +23% interview lift
Without
With
+23.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
27 currently pending
Career history
1023
Total Applications
across all art units

Statute-Specific Performance

§101
10.5%
-29.5% vs TC avg
§103
40.5%
+0.5% vs TC avg
§102
11.0%
-29.0% vs TC avg
§112
30.2%
-9.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 997 resolved cases

Office Action

§102 §103 §112
Detailed Action The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office action is in response to Applicant’s amendment filed on March 10, 2026. Claims 1-21 are pending in the application. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on July 13, 2026 has been entered. Response to Arguments/Remarks Claim Rejections - 35 USC § 112 Claims 5-6 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim subject matter. The amendments to the claims have addressed the rejection. Accordingly, the rejection has been withdrawn. Claim Rejections - 35 USC § 102/103 Claims 1-4, 10-12, and 15 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Jacquin et al. US Patent Publication No. 2017/0230245 (“Jacquin”). Claims 16-19 are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin et al. US Patent Publication No. 2017/0230245 in view of Smith et al. US Patent Publication No. 2017/0346640. Applicant argued that Jacquin does not teach the limitation, “the evidence for the self-attestation, the evidence for the self-attestation being tunneled via at least one transport protocol and transported by respective network management messages of the managed network deployment.” Applicant’s arguments and corresponding amendments have overcome the prior rejection. Therefore, the rejection has been withdrawn. New grounds of rejection are presented in this Office action. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 21 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Regarding claim 21, the claim recites “The at least one processor of claim 1, wherein a first device of the set at a first level of a network topology of the managed network deployment is to transmit the evidence for the self-attestation of the first device to a second device of the set at a higher level of the network topology, the second device to verify trust in the first device.” The claim defines function of a first device, “a first device… is to transmit the evidence for the self-attestation of the first device to a second device,” and a function of a second device, “the second device to verify trust in the first device.” Claim 1 is directed to a processor comprising hardware circuitry to perform functions, presumably the managing device since the claim expressly states, “verify, by a managing device.” The cited limitations of claim 21 do not further define the processor by structure or function. The scope of the invention is not clear. It is suggested that claim 1 be amended to a “system” claim comprising the managing device, first device, and the second device. Claim Rejections - 35 USC § 103 The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action. Claims 1-4, 10-12, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin et al. US Patent Publication No. 2017/0230245 (“Jacquin”) in view of Kumar et al. US Patent Publication No. 2025/0265337 (“Kumar”) and Hunsaker et al. US Patent Publication No. 2019/0228160 (“Hunsaker”). Regarding claim 1, Jacquin teaches at least one processor comprising hardware circuitry to: determine that attestation is to be performed for a set of devices to be included in a managed network deployment (para. [0031] attestation request 212 includes back-end network configuration requirements. back-end network configuration requirements may include a request for attestation of isolation of each network element.); cause individual devices of the set to perform self-attestation and transmit, in respective network management messages, evidence for the self-attestation (para. [0033] provides each network element included in the back-end network 250 with a request 214 for attestation of a network element configuration of the network element. para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216); and verify, by a managing device of the managed network deployment, trust in one or more of the devices of the managed network deployment at least a portion of the evidence for the self-attestation received in one or more of the network management messages (para. [0035] trust engine 230 verifies that the response data 216 meets the back-end network configuration requirements included in the request for attestation of the back-end network 250. verify that network communications through the back-end networks of the clients are isolated. trust engine 230 verifies software requirements, such as software version numbers, software compatibility, and software security). Jacquin does not teach the evidence for the self-attestation, the evidence for the self-attestation being tunneled via at least one transport protocol and transported by respective network management messages of the managed network deployment. Kumar teaches evidence for self-attestation, the evidence for the self-attestation being sent via at least one transport protocol and transported by respective network management messages of a managed network deployment (para. [0046] RoT 115 and BMC 113 may communicate with each other according to the Management Component Transport Protocol (MCTP). para. [0086] BMC 113 may provide signed attestation report received back from RoTs 115 to the token provisioning system 140 (e.g., in response to the attestation report solicitation request). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin with Kumar’s disclosure of transmitting evidence for self-attestation via the transport protocol and by messages of MCTP. One of ordinary skill in the in the art would have been motivated to do so for benefits of providing a protocol to support different management functions (para. [0046]). Hunsaker teaches tunneling messages via at least one transport protocol (para. [0011] eSPI 20 tunnels communications (e.g., data collection traffic in the form of, for example, Management Component Transport Protocol/MCTP messages and/or embedded packets). para. [0019] tunneled communications include data collection traffic. additionally, the communications may include MCTP messages and/or embedded packets). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin and Kumar with Hunsaker’s disclosure of tunneling messages via a transport protocol. One of ordinary skill in the in the art would have been motivated to do so for benefits of secured communications (para. [0020]). Regarding claim 10, Jacquin teaches a system, comprising: one or more processors, each processor comprising hardware circuitry to: determine that attestation is to be performed for a set of devices to be included in a managed network deployment (para. [0031] attestation request 212 includes back-end network configuration requirements. back-end network configuration requirements may include a request for attestation of isolation of each network element.); cause individual devices of the set to perform self-attestation and transmit, in respective network management messages, evidence for the self-attestation (para. [0033] provides each network element included in the back-end network 250 with a request 214 for attestation of a network element configuration of the network element. para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216); and verify, by a managing device of the managed network deployment receiving the respective network management messages, trust in one or more of the devices of the managed network deployment based in part on at least a portion of the evidence for the self-attestation (para. [0035] trust engine 230 verifies that the response data 216 meets the back-end network configuration requirements included in the request for attestation of the back-end network 250. verify that network communications through the back-end networks of the clients are isolated. In some implementations, the trust engine 230 verifies software requirements, such as software version numbers, software compatibility, and software security). Jacquin does not teach the evidence for the self-attestation, the evidence for the self-attestation being tunneled via at least one transport protocol and transported by respective network management messages of the managed network deployment. Kumar teaches evidence for self-attestation, the evidence for the self-attestation being sent via at least one transport protocol and transported by respective network management messages of a managed network deployment (para. [0046] RoT 115 and BMC 113 may communicate with each other according to the Management Component Transport Protocol (MCTP). para. [0086] BMC 113 may provide signed attestation report received back from RoTs 115 to the token provisioning system 140 (e.g., in response to the attestation report solicitation request). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin with Kumar’s disclosure of transmitting evidence for self-attestation via the transport protocol and by messages of MCTP. One of ordinary skill in the in the art would have been motivated to do so for benefits of providing a protocol to support different management functions (para. [0046]). Hunsaker teaches tunneling messages via at least one transport protocol (para. [0011] eSPI 20 tunnels communications (e.g., data collection traffic in the form of, for example, Management Component Transport Protocol/MCTP messages and/or embedded packets). para. [0019] tunneled communications include data collection traffic. additionally, the communications may include MCTP messages and/or embedded packets). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin and Kumar with Hunsaker’s disclosure of tunneling messages via a transport protocol. One of ordinary skill in the in the art would have been motivated to do so for benefits of secured communications (para. [0020]). Regarding claim 2, Jacquin in view of Kumar and Hunsaker teach the at least one processor of claim 1, wherein the devices of the managed network deployment include at least one of servers, processors, network interface cards, routers, load balancers, network switches, or core switches (Jacquin: para. [0018] network element, such as a server computer, a network switch, a network router). Regarding claim 3, Jacquin in view of Kumar and Hunsaker teach the at least one processor of claim 1, wherein the hardware circuitry are further to cause a first set of devices of the managed network deployment to send the evidence for the self-attestation in network management messages to one or more second devices of the managed network deployment for verification, wherein the managing device receives network management messages from at most the one or more second devices (Jacquin: para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216. para. [0036] trust engine 230 provides the client device 210 with data 218 verifying that the back-end network 250). Regarding claim 4, Jacquin in view of Kumar and Hunsaker teach the at least one processor of claim 1, wherein the hardware circuitry are further to determine to perform the attestation for the set of devices to be included in the managed network deployment corresponding to an initial network configuration, a periodic reverification, or a connection of a new network device (Jacquin: para. [0043] dynamic reconfiguration may result in changes to the back-end network 250, and the trust engine 230 can periodically monitor the back-end network 250 for changes. when changes are detected, the trust engine 230 may verify the changed portion, or re-verify the entire back-end network 250, and provide the client device 210 with updated verification data. para. [0044] assign a new network element, such as network element Z 260, to take the place of network element E 255. As network element Z 260 was not verified during the initial verification of the back-end network 250, the trust engine 230 may send network element Z 260 an attestation request). Regarding claim 11, Jacquin in view of Kumar and Hunsaker teach the system of claim 10, wherein the one or more processors are further to cause a first set of devices of the managed network deployment to send the evidence for the self-attestation in network management messages to one or more second devices of the managed network deployment for verification, wherein the managing device receives network management messages from at most the one or more second devices (Jacquin: para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216. para. [0036] trust engine 230 provides the client device 210 with data 218 verifying that the back-end network 250). Regarding claim 12, Jacquin in view of Kumar and Hunsaker teach the system of claim 10, wherein the evidence for the self-attestation includes one or more values representative of a state of the individual devices (Jacquin: para. [0034] network element configuration includes data specifying links between the corresponding network element and other network elements. response data 216 may include, for example, the port forwarding rules of each respective network element and/or software measurements). Regarding claim 15, Jacquin in view of Kumar and Hunsaker teach the system of claim 10, wherein the system is at least one of: a system for performing simulation operations; a system for performing simulation operations to test or validate autonomous machine applications; a system for performing digital twin operations; a system for performing light transport simulation; a system for rendering graphical output; a system for performing deep learning operations; a system for performing generative AI operations using a large language model (LLM); a system implemented using an edge device; a system for generating or presenting virtual reality (VR) content; a system for generating or presenting augmented reality (AR) content; a system for generating or presenting mixed reality (MR) content; a system incorporating one or more Virtual Machines (VMs); a system implemented at least partially in a data center; a system for performing hardware testing using simulation; a system for performing generative operations using a language model (LM); a system for synthetic data generation; a collaborative content creation platform for 3D assets; or a system implemented at least partially using cloud computing resources (Jacquin: para. [0043] cloud network 220). Claims 5-6 are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Kumar, Hunsaker, and Jacquin et al. US Patent Publication No. 2017/0222878 (“Jacquin ‘878”). Regarding claim 5, Jacquin does not teach the at least one processor of claim 1, wherein the hardware circuitry is further cause transmission of the respective network management messages to a network controller of the managed network deployment. Jacquin ‘878 teaches hardware circuitry cause transmission of respective network management messages to a network controller of the managed network deployment (para. [0009] SDN controller… dynamically change configurations. reconfigure a subset of network elements. para. [0021] verifier 140 may be any device in communication with the computing device 100, such as… SDN controller. para. [0035] SDN controller and network elements are included in an SDN managed by the SDN controller 270… para. [0036] verifier 210 provides the network element 220 with a request 212 for attestation. para. [0044] receives the response data 254 from the trusted component 250. verify both the network configuration and software measurements. para. [0046] request is received, at a network element and from a verifier, for attestation of i) software measurements for the network element). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Jacquin ‘878’s disclosure of causing transmission of the respective network management messages to a network controller of the managed network deployment. One of ordinary skill in the art would have been motivated to do so in order to have ensured correct configuration by similarly providing capability for a network controller to verify network configuration of devices. Regarding claim 6, Jacquin teaches the at least one processor of claim 5, wherein the hardware circuitry is further to verify the trust in the one or more devices before the managed network deployment is configured (para. [0035] trust engine 230 verifies that the response data 216 meets the back-end network configuration requirements included in the request for attestation of the back-end network 250). Jacquin does not teach the hardware circuitry configured to receive, from the network controller, at least one request of an attestation report, and. Jacquin ‘878 teaches hardware circuitry is to receive, from a network controller, at least one request of an attestation report (para. [0021] verifier 140 may be any device in communication with the computing device 100, such as… SDN controller, para. [0035] SDN controller and network elements are included in an SDN managed by the SDN controller 270… para. [0046] request is received, at a network element and from a verifier, for attestation of i) software measurements for the network element). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Jacquin ‘878’s disclosure of receiving, from a network controller, a request for an attestation report. One of ordinary skill in the art would have been motivated to do so in order to have ensured correct configuration by similarly providing capability for a network controller to verify network configuration of devices. Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Kumar, Hunsaker, and Schroeder et al. US Patent No. 11,165,778 (“Schroeder”). Regarding claim 7, Jacquin does not teach the at least one processor of claim 1, wherein hardware circuitry are to assign trusted devices to a first subnet and untrusted devices to a second subnet of the managed network deployment. Schroeder suggests hardware circuitry are to assign trusted devices to a first subnet and untrusted devices to a second subnet of a managed network deployment (col. 3, line 64-col. 4, line 2; col. 7, line 1-7. highly trustworthy computing devices are assigned to an operating network with more privileges (e.g., a trusted network segment) than less trustworthy computing devices. less trustworthy computing devices are assigned to an operating network segment). While Schroeder does not expressly disclose untrusted devices, it would have been obvious to one of ordinary skill in the art to include untrusted devices with less trustworthy devices and/or restrict privileges for untrusted devices based on Schroder’s disclosure. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have applied Schroeder’s disclosure of assigning devices based on trust such that devices are assigned to subnets based on trust associated with devices. One of ordinary skill in the art would have been motivated to do so in order to have improved network security. Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Kumar, Hunsaker, Gavrilov et al. US Patent Publication No. 2021/0349794 (“Gavrilov”) and Bhandari et al. US Patent Publication No. 2020/0322075 (“Bhandrai”). Regarding claim 8, Jacquin does not teach the at least one processor of claim 1, wherein the network management messages correspond to management datagrams (MADs) of an InfiniBand deployment, and wherein the MAD headers are extended to include the evidence for the self-attestation. Gavrilov teaches network management messages corresponding to management datagrams (MADs) of an InfiniBand deployment (para. [0088] in Infiniband fabric, the first management query may include an SMP (Subnet Management Protocol) MAD. para. [0166] Infiniband environment, management datagrams (MADs) are used to discover and configure the fabric and to execute remote hardware or software commands). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Gavrilov’s disclosure of utilizing messages corresponding to MADs of an InfiniBand deployment. One of ordinary skill in the art would have been motivated to do so for benefits of providing management functions including discovery and configuration (para. [0166]-[0167]). Bhandari teaches extending headers to include evidence for self-attestation (para. [0121] attestation information can be included as a separate field or as extensions to exiting fields. para. [0132] attestation information can include Proof of Integrity). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin and Gavrilov with Bhandari’s disclosure such the datagrams are extended to include evidence for self-attestation. One of ordinary skill in the art would have been motivated to do so in order to have utilized existing messages, using extensions, to communicate additional information. Claims 9 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Kumar, Hunsaker, and M et al. US Patent Publication No. 2022/0104100 (“M”). Regarding claim 9, Jacquin does not teach the at least one processor of claim 1, wherein hardware circuitry are further to identify at least one trusted path through the managed network deployment corresponding to devices of the set where the self-attestation is verified. M teaches hardware circuitry are to identify at least one trusted path through a managed network deployment corresponding to devices of a set where the self-attestation is verified (para. [0023] MR uses the attestation information to verify whether the neighbor MR is trustworthy. para. [0032] verifier verifies the evidence to select trustworthiness levels for the features. para. [0050] destination node determines which of the accumulated paths are trusted paths based on the trust indicators for the mesh routers along the accumulated paths. para. [0061] RREQ packet carries attestation information, so that the next MR in the path to the destination MR can validate to verify the proof of integrity of the MR). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have applied M’s disclosure of identifying a trusted path based on verifying attestation of devices. One of ordinary skill in the art would have been motivated to do so for improved security by determining a path among trusted paths (para. [0012]). Regarding claim 14, Jacquin does not teach the system of claim 10, wherein the one or more processors are further to identify at least one trusted path through the managed network deployment corresponding to devices of the set where the self-attestation is verified, and wherein trusted data is to be propagated using only the at least one trusted path through the managed network deployment. M teaches identify at least one trusted path through a managed network deployment corresponding to devices of a set where the self-attestation is verified, and wherein trusted data is to be propagated using only the at least one trusted path through the managed network deployment. (para. [0023] MR uses the attestation information to verify whether the neighbor MR is trustworthy. para. [0032] verifier verifies the evidence to select trustworthiness levels for the features. para. [0050] destination node determines which of the accumulated paths are trusted paths based on the trust indicators for the mesh routers along the accumulated paths. para. [0061] RREQ packet carries attestation information, so that the next MR in the path to the destination MR can validate to verify the proof of integrity of the MR). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have applied M’s disclosure of identifying a trusted path based on verifying attestation of devices. One of ordinary skill in the art would have been motivated to do so for improved security by determining a path among trusted paths (para. [0012]). Claim 13 is are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Kumar, Hunsaker, and Cabre et al. US Patent Publication No. 2022/0303123 (“Cabre”). Regarding claim 13, Jacquin does not teach the system of claim 12, wherein the evidence is signed using an endorsement from respective manufacturers of the individual devices. Cabre teaches evidence signed using an endorsement from respective manufacturers of the individual devices (para. [0105] obtain attestation evidence associated with the subject device. attestation evidence is provided by the device platform, and the attestation evidence is signed by a certificate produced using a manufacturer-embedded key). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Cabre’s disclosure of signing evidence using an endorsement from respective manufacturers of the individual devices. One of ordinary skill in the art would have been motivated to do so in order to have improved security and verification of evidence of the attestation. Claims 16-19 are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin et al. US Patent Publication No. 2017/0230245 (“Jacquin”) in view of Smith et al. US Patent Publication No. 2017/0346640 (“Smith), Kumar et al. US Patent Publication No. 2025/0265337 (“Kumar”), and Hunsaker et al. US Patent Publication No. 2019/0228160 (“Hunsaker”). Regarding claim 16, Jacquin teaches a subnet manager, comprising: one or more processing units, each processing unit implemented in hardware circuitry and configured to: transmit a request for attestation that is to be performed by devices in a managed subnet to be included in a managed network deployment (para. [0031] attestation request 212 includes back-end network configuration requirements. back-end network configuration requirements may include a request for attestation of isolation of each network element.); receive, from the devices of the managed subnet, respective network management messages including self-attestation evidence for the devices (para. [0033] provides each network element included in the back-end network 250 with a request 214 for attestation of a network element configuration of the network element. para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216); and verify trust in one or more of the devices of the managed subnet based in part on at least a portion of the evidence for the self-attestation received in one or more of the network management messages (para. [0035] trust engine 230 verifies that the response data 216 meets the back-end network configuration requirements included in the request for attestation of the back-end network 250. verify that network communications through the back-end networks of the clients are isolated. In some implementations, the trust engine 230 verifies software requirements, such as software version numbers, software compatibility, and software security). Jacquin teaches transmitting a request for attestation but does not expressly teach broadcast the request for attestation. Jacquin does not teach the evidence for the self-attestation, the evidence for the self-attestation being tunneled via at least one transport protocol and transported by respective network management messages of the managed network deployment. Smith teaches broadcasting a request for attestation (para. [0063] computing device 102 may send the request for attestation to one or more members of the particular subsystem, for example by broadcasting a request to all computing devices 102 in the subsystem). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Smith’s disclosure of broadcasting a request for attestation. One of ordinary skill in the art would have been motivated to do so in order to have similarly ensured that all required devices in a subsystem receive and respond to the request for attestation. Kumar teaches evidence for self-attestation, the evidence for the self-attestation being sent via at least one transport protocol and transported by respective network management messages of a managed network deployment (para. [0046] RoT 115 and BMC 113 may communicate with each other according to the Management Component Transport Protocol (MCTP). para. [0086] BMC 113 may provide signed attestation report received back from RoTs 115 to the token provisioning system 140 (e.g., in response to the attestation report solicitation request). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin with Kumar’s disclosure of transmitting evidence for self-attestation via the transport protocol and by messages of MCTP. One of ordinary skill in the in the art would have been motivated to do so for benefits of providing a protocol to support different management functions (para. [0046]). Hunsaker teaches tunneling messages via at least one transport protocol (para. [0011] eSPI 20 tunnels communications (e.g., data collection traffic in the form of, for example, Management Component Transport Protocol/MCTP messages and/or embedded packets). para. [0019] tunneled communications include data collection traffic. additionally, the communications may include MCTP messages and/or embedded packets). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified have modified Jacquin and Kumar with Hunsaker’s disclosure of tunneling messages via a transport protocol. One of ordinary skill in the in the art would have been motivated to do so for benefits of secured communications (para. [0020]). Regarding claim 17, Jacquin in view of Smith, Kumar, and Hunsaker teach the subnet manager of claim 16, wherein the one or more processing units are further to cause a first set of devices of the managed subnet to send the evidence for the self-attestation in network management messages to one or more second devices of the managed subnet for verification, wherein the subnet manager receives the network management messages from at most the one or more second devices (Jacquin: para. [0034] trust engine 230 receives, from each network element included in the back-end network 250, response data 216. para. [0036] trust engine 230 provides the client device 210 with data 218 verifying that the back-end network 250). Regarding claim 18, Jacquin in view of Smith, Kumar, and Hunsaker teach the subnet manager of claim 16, wherein the one or more processing units are further to determine to perform the attestation for the set of devices to be included in the managed subnet corresponding to an initial network configuration, a periodic reverification, or a connection of a new network device (Jacquin: para. [0043] dynamic reconfiguration may result in changes to the back-end network 250, and the trust engine 230 can periodically monitor the back-end network 250 for changes. when changes are detected, the trust engine 230 may verify the changed portion, or re-verify the entire back-end network 250, and provide the client device 210 with updated verification data. para. [0044] assign a new network element, such as network element Z 260, to take the place of network element E 255. As network element Z 260 was not verified during the initial verification of the back-end network 250, the trust engine 230 may send network element Z 260 an attestation request). Regarding claim 19, Jacquin in view of Smith, Kumar, and Hunsaker teach the subnet manager of claim 16, wherein the evidence for the self-attestation includes one or more values representative of a state of the individual devices (Jacquin: para. [0034] network element configuration includes data specifying links between the corresponding network element and other network elements. response data 216 may include, for example, the port forwarding rules of each respective network element and/or software measurements). Claim 20 is are rejected under 35 U.S.C. 103 as being unpatentable over Jacquin in view of Smith, Kumar, Hunsaker, and Cabre et al. US Patent Publication No. 2022/0303123 (“Cabre”). Regarding claim 20, Jacquin does not teach the subnet manager of claim 19, wherein the evidence is signed using an endorsement from respective manufacturers of the individual devices. Cabre teaches evidence signed using an endorsement from respective manufacturers of the individual devices (para. [0105] obtain attestation evidence associated with the subject device. attestation evidence is provided by the device platform, and the attestation evidence is signed by a certificate produced using a manufacturer-embedded key). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jacquin with Cabre’s disclosure of signing evidence using an endorsement from respective manufacturers of the individual devices. One of ordinary skill in the art would have been motivated to do so in order to have improved security and verification of evidence of the attestation. Examiner’s Note The following prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. Moyer et al. US Patent Publication No. 2025/0211619 (para. [0031] after establishing the communication session 22, the first computing device 10a receives, via the communication session 22, an attestation request 172 (e.g., using an HTTP request or an HTTPS tunnel. Para. [0033] attestation report may include a variety of information) Kim et al. US Patent Publication No. 2024/0168675 (para. [0046] host 200 and the CXL devices 220 and 240 may perform device attestation. host 200 and the CXL devices 220 and 240 may conform to the Security Protocol and Data Model (SPDM) over Management Component Transport Protocol (MCTP) architecture/protocol Conclusion A shortened statutory period for reply to this Office action is set to expire THREE MONTHS from the mailing date of this action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Joshua Joo whose telephone number is (571)272-3966. The examiner can normally be reached Monday-Friday 7am-3pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar Louie can be reached at 571-270-1684. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JOSHUA JOO/Primary Examiner, Art Unit 2445
Read full office action

Prosecution Timeline

Show 1 earlier event
Dec 19, 2025
Non-Final Rejection mailed — §102, §103, §112
Feb 26, 2026
Applicant Interview (Telephonic)
Mar 05, 2026
Examiner Interview Summary
Mar 10, 2026
Response Filed
Apr 21, 2026
Final Rejection mailed — §102, §103, §112
Jul 13, 2026
Request for Continued Examination
Jul 24, 2026
Response after Non-Final Action
Aug 11, 2026
Non-Final Rejection mailed — §102, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12726494
DETECTING MICROSERVICE SECURITY ATTACKS BASED ON METRIC SENSITIVE DEPENDENCIES
3y 4m to grant Granted Sep 01, 2026
Patent 12719738
DETERMINING CRITICAL LOGS FOR NETWORK APPLICATIONS
2y 8m to grant Granted Aug 25, 2026
Patent 12712937
AGENT-BASED REMOTE DESKTOP PROTOCOL SESSION CONTROL
2y 1m to grant Granted Aug 18, 2026
Patent 12695719
METHOD, DEVICE, AND SYSTEM FOR MANAGING DOMAIN NAME RESOLUTION
1y 11m to grant Granted Jul 28, 2026
Patent 12688318
MANAGEMENT OF SHARED AUTHORIZATION KEYS IN A HYBRID SOFTWARE DEPLOYMENT
2y 5m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+23.1%)
3y 1m (~1y 1m remaining)
Median Time to Grant
High
PTA Risk
Based on 997 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month