Prosecution Insights
Last updated: October 02, 2026
Application No. 18/902,098

AUTOMATED VIRTUAL PRIVATE NETWORK SESSION ROUTING

Final Rejection §103
Filed
Sep 30, 2024
Examiner
DOAN, TRANG T
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Fmr LLC
OA Round
2 (Final)
83%
Grant Probability
Favorable
3-4
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
526 granted / 634 resolved
+25.0% vs TC avg
Strong +17% interview lift
Without
With
+16.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
16 currently pending
Career history
658
Total Applications
across all art units

Statute-Specific Performance

§101
15.2%
-24.8% vs TC avg
§103
35.6%
-4.4% vs TC avg
§102
19.7%
-20.3% vs TC avg
§112
19.7%
-20.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 634 resolved cases

Office Action

§103
DETAILED ACTION In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This Office Action is in response to the communication filed on 4/16/2026. Claims 2 and 12 have been canceled. Claims 1 and 11 have been amended. Claims 1, 3-11 and 13-20 are pending for consideration. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments filed on 4/16/2026 have been fully considered but they are not persuasive. Applicant argues on pages 6-7 of the Remark that Saluja does not detail a VPN connections failover process wherein external interface of affected VPN appliances is disabled to force large scale reconnection of all connected endpoint devices. In response to applicant's argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., “to force large scale reconnection of all connected endpoint devices”) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). In response to the argument regarding the VPN connections failover process wherein external interface of affected VPN appliances is disabled, Examiner respectfully disagrees. The combination of the cited arts discloses that upon a failover from Tunnel 10, a forwarding plane is instructed to use a standby MPLS tunnel instead a main MPLS tunnel associated with Tunnel 10(Saluja: paragraph 22, “VPN traffic received for VPN-A will thus be output over Tunnel 10 unless the control plane receives notification that Tunnel 10 is down. Upon failover from Tunnel 10, the forwarding plane will be instructed to use the standby MPLS tunnel for VPN-A, and traffic for VPN-A will automatically be forwarded over standby Tunnel 23”). Examiner broadly interprets the VPN failover process of Saluja as the VPN connections failover process recited in the claims. As disclosed in paragraphs 22-25 of Saluja, when the failover is notified, the VPN traffic is no longer routed to the main MPLS tunnel but to the standby MPLS tunnel. Those citations further state that the standby MPLS tunnel would become a new main MPLS tunnel for VPN-A. Examiner broadly interprets when the traffic is no longer routed to the main MPLS tunnel means the external interface of affected VPN appliances is disabled. Therefore, the combination does teach the disputed limitation. Applicant argues on page 7 of the Remark that Saluja does not teach directing endpoint devices to connect to an entirely different VPN appliance upon detection of an unhealthy MPLS link. In response to applicant's argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., “directing endpoint devices to connect to an entirely different VPN appliance upon detection of an unhealthy MPLS link” and “by disabling the external interface of any VPN appliance having an unhealthy MPLS link detected”) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 3-7, 9-11, 13-17 and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over An (US 20240340234) (hereinafter An) in view of Saluja (US 8493845) (hereinafter Saluja). Regarding claim 1, An discloses a computerized method for routing virtual private network (VPN) sessions (An: paragraphs 0042 and 0077, “routing traffic to facilitate the communication of that traffic from a source compute node to a destination compute node are referred to as router nodes. Examples of router nodes include routers, forwarders, virtual networking entities such as different types of gateways,”), the method comprising: providing a computer network data center comprising a plurality of zones, each zone comprising a VPN connections optimization tool and one or more VPN appliances operable to securely connect a VPN client to the data center (AN: paragraphs 0077, 0081 and 0164, “The cloud infrastructure or CSPI is physically hosted in one or more data centers in one or more regions around the world”… “Each region may provide a set of core infrastructure services and resources, such as, compute resources…; … networking resources (e.g., virtual cloud networks (VCNs), load balancing resources, connections to on-premise networks), database resources; edge networking resources (e.g., DNS); and access management and monitoring resources, and other”…“Clos network is a particular type of network topology designed to provide connection redundancy while maintaining high bisection bandwidth and maximum resource utilization. A Clos network is a type of non-blocking, multistage or multi-tiered switching network”), wherein each zone is connected to one or more remote resources by a multiprotocol label switching (MPLS) link (An: paragraphs 0164-0166, “each resource within CSPI is assigned a unique identifier called a Cloud Identifier (CID). This identifier is included as part of the resource's information and can be used to manage the resource, for example, via a Console or through APIs. An example syntax for a CID is: [0167] ocid1.<RESOURCE TYPE>.<REALM>. [REGION][.FUTURE USE].<UNIQUE ID> where, [0168] ocid1: The literal string indicating the version of the CID; [0169] resource type: The type of resource (for example, instance, volume, VCN, subnet, user, group, and so on); [0170] realm: The realm the resource is in. Example values are “c1” for the commercial realm, “c2” for the Government Cloud realm, or “c3” for the Federal Government Cloud realm, etc. Each realm may have its own domain name; [0171] region: The region the resource is in. If the region is not applicable to the resource, this part might be blank; [0172] future use: Reserved for future use. [0173] unique ID: The unique portion of the ID. The format may vary depending on the type of resource or service.”); wherein the VPN connections optimization tool at a first zone is operable to perform the steps of: periodically polling availability of a first zone’s MPLS link (An: paragraphs 0249-0250, “the NPAS 620 may perform periodic monitoring of all network segments or generate a map of the network, or a representation thereof, based upon the various nodes and segments determine”); receiving a threshold number of consecutive network down responses in response to the periodic polling (An: paragraphs, 0257-0259, “the computer system or software component may be configured to provide a visual, audible, or electronic notification in the event certain network errors or failures are detected. Network errors or failures may be detected, for instance, by assigning a threshold value to the calculated metrics. Network latency, for instance, may have a maximum value above which certain notifications can be triggered. Likewise, packet loss may have a maximum threshold value and jitter may have a maximum threshold value. Other actions may also be triggered based upon the value of the metric computed in 1920. For example, if the metric measure network latency and is calculated to be over a threshold, automatic corrective actions may be triggered or initiated to reduce the network latency.”). An does not explicitly disclose the following limitation which is disclosed by, subsequently initiating a VPN connections failover process (Saluja: paragraphs 22-25, “By enabling VPN connection information associated with redundant MPLS tunnels to be stored in the forwarding plane, such as main MPLS tunnel information and standby MPLS tunnel information, fast failover from a main MPLS tunnel to a standby MPLS tunnel may be achieved... Additionally, by enabling this selection to be passed to the forwarding plane and maintained in the forwarding plane, reprogramming of the forwarding plane may take place without transmitting the new information to the forwarding plane from the control plane. This further accelerates failover recovery, especially where multiple VPN connections are affected by a given failure.”… “VPN traffic received for VPN-A will thus be output over Tunnel 10 unless the control plane receives notification that Tunnel 10 is down. Upon failover from Tunnel 10, the forwarding plane will be instructed to use the standby MPLS tunnel for VPN-A, and traffic for VPN-A will automatically be forwarded over standby Tunnel 23”) comprising logging into the one or more VPN appliances at the first zone and disabling an external interface thereof using the VPN connections optimization tool at the first zone (Saluja: paragraphs 10 and 23-25, “such that upon failure of the main MPLS tunnel, traffic may be switched quickly to the standby MPLS tunnel without requiring the control plane to reprogram that information into the forwarding plane. This enables failover between MPLS tunnels to be accomplished in a very rapid manner to enable the tunnels to carry time sensitive VPN traffic such as voice transmissions and video transmissions.”… “Upon failover to the standby MPLS tunnel, the previous standby MPLS tunnel will become the new main MPLS tunnel for that VPN and the standby MPLS tunnel will be set to null until reprogrammed by the control plane. Thus, for example in the example illustrated in FIG. 3, upon failover from Tunnel 10 to Tunnel 23, Tunnel 23 would become the new main MPLS tunnel for VPN-A”). An and Saluja are analogous art because they are from the same field of endeavor, data processing. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of An and Saluja before him or her, to modify the system of An to include subsequently initiating a VPN connections failover process of Saluja. The suggestion/motivation for doing so would have been to thereby provide fast notification of a failed link or card (Saluja: paragraph 12). Regarding claim 11, the claim 11 discloses a system claim that is substantially equivalent to the method of claim 1. Therefore, the arguments set forth above with respect to claim 1 are equally applicable to claim 11 and rejected for the same reasons. Regarding claims 3 and 13, An as modified discloses wherein the disabling step triggers the VPN clients connected to the one or more VPN appliances at the first zone to reconnect to a second VPN appliance connected to the one or more remote resources via an internet connection (Saluja: paragraphs 23-27, “Since the standby MPLS tunnels have already been determined, the control plane does not need to select a new MPLS tunnel for each VPN affected by the failure. Additionally, since this information has been passed to the forwarding plane, it is not necessary to repopulate the forwarding plane tables with the new MPLS tunnel information. Thus, a very fast failover may be achieved in the forwarding plane.”). The same motivation to modify An in view of Saluja, as applied in claim 1 above, applies here. Regarding claims 4 and 14, An as modified discloses wherein the second VPN appliance is in a second zone in the computer network data center (An: paragraphs 0164-0166, “each resource within CSPI is assigned a unique identifier called a Cloud Identifier (CID). This identifier is included as part of the resource's information and can be used to manage the resource, for example, via a Console or through APIs. An example syntax for a CID is: [0167] ocid1.<RESOURCE TYPE>.<REALM>. [REGION][.FUTURE USE].<UNIQUE ID> where, [0168] ocid1: The literal string indicating the version of the CID; [0169] resource type: The type of resource (for example, instance, volume, VCN, subnet, user, group, and so on); [0170] realm: The realm the resource is in. Example values are “c1” for the commercial realm, “c2” for the Government Cloud realm, or “c3” for the Federal Government Cloud realm, etc. Each realm may have its own domain name; [0171] region: The region the resource is in. If the region is not applicable to the resource, this part might be blank; [0172] future use: Reserved for future use. [0173] unique ID: The unique portion of the ID. The format may vary depending on the type of resource or service.”). Regarding claims 5 and 15, An as modified discloses wherein the one or more VPN appliances at the first zone connect to the second VPN appliance in the second zone via an MPLS connection (An: paragraphs 0053 and 0164-0166, “In certain implementations, Multiprotocol Label Switching (MPLS) labels may be used. MPLS is a packet routing technology that causes routers to forward packets across a physical link according to a specified label.”…each resource within CSPI is assigned a unique identifier called a Cloud Identifier (CID). This identifier is included as part of the resource's information and can be used to manage the resource, for example, via a Console or through APIs. An example syntax for a CID is: [0167] ocid1.<RESOURCE TYPE>.<REALM>. [REGION][.FUTURE USE].<UNIQUE ID> where, [0168] ocid1: The literal string indicating the version of the CID; [0169] resource type: The type of resource (for example, instance, volume, VCN, subnet, user, group, and so on); [0170] realm: The realm the resource is in. Example values are “c1” for the commercial realm, “c2” for the Government Cloud realm, or “c3” for the Federal Government Cloud realm, etc. Each realm may have its own domain name; [0171] region: The region the resource is in. If the region is not applicable to the resource, this part might be blank; [0172] future use: Reserved for future use. [0173] unique ID: The unique portion of the ID. The format may vary depending on the type of resource or service.”). Regarding claims 6 and 16, An as modified discloses wherein the second VPN appliance is in a zone in a second computer network data center (An: paragraphs 0053 and 0164-0166, “In certain implementations, Multiprotocol Label Switching (MPLS) labels may be used. MPLS is a packet routing technology that causes routers to forward packets across a physical link according to a specified label.”…each resource within CSPI is assigned a unique identifier called a Cloud Identifier (CID). This identifier is included as part of the resource's information and can be used to manage the resource, for example, via a Console or through APIs. An example syntax for a CID is: [0167] ocid1.<RESOURCE TYPE>.<REALM>. [REGION][.FUTURE USE].<UNIQUE ID> where, [0168] ocid1: The literal string indicating the version of the CID; [0169] resource type: The type of resource (for example, instance, volume, VCN, subnet, user, group, and so on); [0170] realm: The realm the resource is in. Example values are “c1” for the commercial realm, “c2” for the Government Cloud realm, or “c3” for the Federal Government Cloud realm, etc. Each realm may have its own domain name; [0171] region: The region the resource is in. If the region is not applicable to the resource, this part might be blank; [0172] future use: Reserved for future use. [0173] unique ID: The unique portion of the ID. The format may vary depending on the type of resource or service.”). Regarding claims 7 and 17, An as modified discloses wherein the one or more VPN appliances at the first zone connect to the second VPN appliance in the zone in the second computer network data center via an internet connection (An: paragraphs 0053 and 0164-0166, “In certain implementations, Multiprotocol Label Switching (MPLS) labels may be used. MPLS is a packet routing technology that causes routers to forward packets across a physical link according to a specified label.”…each resource within CSPI is assigned a unique identifier called a Cloud Identifier (CID). This identifier is included as part of the resource's information and can be used to manage the resource, for example, via a Console or through APIs. An example syntax for a CID is: [0167] ocid1.<RESOURCE TYPE>.<REALM>. [REGION][.FUTURE USE].<UNIQUE ID> where, [0168] ocid1: The literal string indicating the version of the CID; [0169] resource type: The type of resource (for example, instance, volume, VCN, subnet, user, group, and so on); [0170] realm: The realm the resource is in. Example values are “c1” for the commercial realm, “c2” for the Government Cloud realm, or “c3” for the Federal Government Cloud realm, etc. Each realm may have its own domain name; [0171] region: The region the resource is in. If the region is not applicable to the resource, this part might be blank; [0172] future use: Reserved for future use. [0173] unique ID: The unique portion of the ID. The format may vary depending on the type of resource or service.”). Regarding claims 9 and 19, An as modified discloses wherein the threshold number of consecutive network down responses comprises at least 6 (Saluja: paragraphs 22-25, “For example, a network operator may choose to specify the implementation and designation of a standby MPLS tunnel only for particular classes of VPN connections, such as where the VPN customer has specified the use of fast failover protection in its Service Level Agreement (SLA). Additionally, a less than fully populated table may occur where a failover has just occurred for the VPN and the control plane is in the process of generating new standby MPLS tunnel information to be downloaded to the forwarding plane. Numerous other reasons may cause the forwarding table to be less than fully populated and the invention is not limited to these two particular examples.”). The same motivation to modify An in view of Saluja, as applied in claim 1 above, applies here. Regarding claims 10 and 20, An as modified discloses wherein the computer network data center is one of a plurality of computer network data centers located at a plurality of geographically distributed sites (An: paragraphs 0040, 0077 and 0175, “cloud services provider (CSP) may offer one or more cloud services to subscribing customers on demand (e.g., via a subscription model) using infrastructure provided by the CSP. The CSP-provided infrastructure is sometimes referred to as cloud infrastructure or cloud services provider infrastructure (CSPI). The CSPI provided by a CSP typically includes one or more data centers communicatively coupled with each other via a communication network (also sometimes referred to as a backbone network). The data centers are generally located in different geographical locations, where one data center can be separated from another data center by vast geographical distances. The communication network enables communication of network traffic between the data centers, where the network traffic can comprise data packets. Various communication protocols may be used to facilitate communications between the data centers over the communication network.”). Claim(s) 8 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over An in view of Saluja, and further in view of JHA (US 20230206755) (hereinafter JHA). Regarding claims 8 and 18, An as modified by An does not explicitly disclose the following limitation which is disclosed by JHA, wherein the periodically polling step occurs every 15 seconds or less (JHA: paragraphs, “To observe environmental conditions, the AI agents is/are configurable or operable to receive, or monitor for, … Monitoring may include polling (e.g., periodic polling, sequential (roll call) polling, and/or the like) …sensor data and/or one or more DCUs 1574 for CSD for a specified/selected period of time”). An as modified by Saluja and JHA are analogous art because they are from the same field of endeavor, data processing. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of An as modified by Saluja and JHA before him or her, to modify the system of An in view of Saluja to include periodically polling step occurs every 15 seconds or less of JHA. The suggestion/motivation for doing so would have been to enable an increase in traffic safety and efficiency (JHA: paragraph 0003). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TRANG T DOAN whose telephone number is (571)272-0740. The examiner can normally be reached Monday-Friday 7-4 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D Feild can be reached on (571)272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TRANG T DOAN/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Sep 30, 2024
Application Filed
Dec 16, 2025
Non-Final Rejection (signed) — §103
Jan 16, 2026
Non-Final Rejection mailed — §103
Apr 16, 2026
Response Filed
Jul 01, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12726827
METHOD FOR EXTERNAL AUTHENTICATION AND AUTHORIZATION
3y 2m to grant Granted Sep 01, 2026
Patent 12726277
SINGLE-PHOTON TRANSMISSION DETERMINATION
2y 2m to grant Granted Sep 01, 2026
Patent 12719884
System and Method for Intrusion Detection of Malware Traffic based on Feature Information
4y 8m to grant Granted Aug 25, 2026
Patent 12712714
Transmission of a message by quantum communication with eavesdropping detection
2y 6m to grant Granted Aug 18, 2026
Patent 12711261
SOVEREIGN DATA CENTER STAGING AREA
2y 3m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+16.8%)
3y 4m (~1y 4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 634 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month