Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor
to file provisions of the AIA .
Detailed Action
2. Claims 1-20 are pending in Instant Application.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 01/10/2025 is in compliance with the
provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-11, 15, 18, and 20-33 are rejected under 35 U.S.C. 103 as being unpatentable over US
11,841,952 issued to Gitelman et al. (Gitelman) in view of US 20200104509 issued to Furuichi et al. (Furuichi).
As per claim 1, Gitelman teaches a method for determining device risk for a plurality of wireless devices based on one or more determined vulnerabilities (Gitelman: Col. 7, ll. (4-7) - the exploitable vulnerability detector 150 may be further configured to detect devices 110 that do not belong to the organization which may perform malicious activity, and thus may pose a risk to devices and networks in the environment), the method comprising: receiving, by one or more processors, wireless signal data from a plurality of devices, wherein the received wireless signal data were detected by a plurality of wireless signal sensors (Gitelman: Fig. 1, Col. 4, ll. (24-31) - a plurality of sensors 140-1 through 140-p (hereinafter referred to individually as a sensor 140 and collectively as sensors 140, merely for simplicity purposes) are deployed in the network 100. Each sensor 140 is deployed as an out-of-band device and is configured to monitor and control the wireless traffic transmitted by the devices 110 in proximity of where the sensor 140 is deployed.); classifying each of the plurality of devices based on the wireless signal data; determining one or more vulnerabilities associated with each of the plurality of devices based on the classification of each of the plurality of devices (Gitelman: Fig. 1, Col. 6, ll. 63 to Col. 7, ll. 1 - the exploitable vulnerability detector 150 is configured to determine device attributes meaning the exploitable vulnerability detector 150 is configured to navigate a classifier hierarchy in order to determine each device attribute, for example, a device attribute of one of the devices 110);
Gitelman however does not explicitly teach determining at least one device risk for each of the plurality of devices based on the one or more device vulnerabilities.
Furuichi however explicitly teaches determining at least one device risk for each of the plurality of devices based on the one or more device vulnerabilities (Furuichi: ¶ 0020 - the IoT Application 130 can determine which vulnerabilities affect the particular device meaning the vulnerability information also includes a category for each vulnerability (e.g., what type of vulnerability it is), a risk level associated with the vulnerability, and the like).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Gitelman in view of Furuichi to teach determining at least one device risk for each of the plurality of devices based on the one or more device vulnerabilities. One would be motivated to do so as the IoT application can determine which vulnerabilities affect the particular device meaning the vulnerability information also includes a category for each vulnerability (e.g., what type of vulnerability it is), a risk level associated with the vulnerability, and the like (Furuichi: ¶ 0020).
As per claim 2, the modified teaching of Gitelman teaches the method of claim 1, comprising determining a risk to a facility based at least in part on the at least one device risk (Furuichi: ¶ 0053, Fig. 6 - the IoT Application determines the number of devices present in the group and determines a risk level of the devices of the selected group).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Gitelman in view of Furuichi to teach determining a risk to a facility based at least in part on the at least one device risks. One would be motivated to do so as the IoT Application determines the number of devices present in the group and determines a risk level of the devices of the selected group (Furuichi: ¶ 0053, Fig. 6).
As per claim 3, the modified teaching of Gitelman teaches the method of claim 1, comprising: displaying an indication of the at least one device risk (Furuichi: ¶ 0048 - the vulnerability measure includes an indication as to which vulnerabilities, if any, the device is affected by).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Gitelman in view of Furuichi to teach displaying an indication of the at least one device risk. One would be motivated to do so as the vulnerability measure includes an indication as to which vulnerabilities, if any, the device is affected by (Furuichi: ¶ 0048).
As per claim 4, the modified teaching of Gitelman teaches the method of claim 1, comprising: generating a recommended mitigation for at least one of the one or more vulnerabilities (Gitelman: Col. 3, ll. (48-49) - Mitigation actions may be performed to avoid exploitation of the detected exploitable vulnerabilities).
As per claim 5, the modified teaching of Gitelman teaches the method of claim 4, comprising: executing the recommended mitigation for at least one of the one or more vulnerabilities, wherein the recommended mitigation comprises any one or more of: patching a device, blocking a transmission from a device, deactivating a device, reconfiguring a device, segmenting off a portion of a network, and isolating a portion of a network (Gitelman: Col. 5, ll. (53-57) - the sensors are configured to perform mitigation actions under the control of the exploitable vulnerability detector. For example, the sensor can terminate a wireless connection with a device determined to be vulnerable).
As per claim 6, the modified teaching of Gitelman teaches the method of claim 1, comprising: determining at least one of a weakness associated with one or more devices of the plurality of devices and a threat associated with one or more devices of the plurality of devices (Gitelman: Col. 8, ll. (63-66) - identifying potential exploits (weakness) based on device attributes defined in the device profile allows for more accurately detecting exploitable vulnerabilities).
As per claim 7, the modified teaching of Gitelman teaches the method of claim 6, comprising: generating a recommended mitigation for the weakness or the threat (Gitelman: Col. 5, ll. (57-60) - the exploitable vulnerability detector may be configured to perform the mitigation actions or to cause the sensors to perform the mitigation actions).
As per claim 8, the modified teaching of Gitelman teaches the method of claim 7, comprising: executing the recommended mitigation, wherein the recommended mitigation comprises any one or more of: patching a device, blocking a transmission from a device, deactivating a device, reconfiguring a device, segmenting off a portion of a network, and isolating a portion of a network (Gitelman: Col. 5, ll. (53-57) - the sensors are configured to perform mitigation actions under the control of the exploitable vulnerability detector. For example, the sensor can terminate a wireless connection with a device determined to be vulnerable).
As per claim 9, the modified teaching of Gitelman teaches the method of claim 6, wherein the weakness comprises any one or more of: an unencrypted wireless access point, a hidden access point, a rogue access point, a rogue hotspot access point, one or more inconsistent access point vendors, an Evil Twin access point, an unencrypted ad-hoc network, an unauthorized ad-hoc network, an always-discoverable device, an unencrypted communication, a weakly-encrypted communication, a use of compromised encryption keys, a use of vendor default encryption keys, and a 2G base station (Gitelman: Col. 7, ll. (11-14) - the exploitable vulnerability detector 150 may be configured to profile each device 110 discovered in the environment 100 using device attributes (an always-discoverable device)).
As per claim 10, the modified teaching of Gitelman teaches the method of claim 6, wherein the threat comprises any one or more of a spoofed device, an Evil Twin access point, and a 2G base station (Gitelman: Col. 8, ll. (59-61) - the vulnerabilities database includes device attributes associated with exploitable vulnerabilities (attributes making the device a spoofed device) and corresponding known exploits).
As per claim 11, the modified teaching of Gitelman teaches the method of claim 1, wherein each of the plurality of wireless signal sensors is configured to detect wireless signals of a respective wireless signal protocol of a plurality of wireless signal protocols (Gitelman: Col. 4, ll. (20-23) - the devices may communicate directly with each other or with other systems directly using communication protocols such as, but not limited to, Bluetooth®, Bluetooth low energy (BLE), and the like).
As per claim 15, the modified teaching of Gitelman teaches the method of claim 1, wherein classifying the plurality of devices comprises determining any one or more of a vendor name, a product name, or a device code (Gitelman: Col. 5, ll. (36-37) - determination of a device's vendor based on the MAC address may be performed by the sensors).
As per claim 18, the modified teaching of Gitelman teaches the method of claim 1, wherein classifying the plurality of devices comprises: determining a device vendor based on a MAC address associated with the plurality of wireless signals (Gitelman: Col. 5, ll. (36-37) - determination of a device's vendor based on the MAC address may be performed by the sensors).
As per claim 20, the modified teaching of Gitelman teaches the method of claim 1, wherein determining the plurality of device risks for the plurality of devices based on the one or more device vulnerabilities comprises comparing the one or more device vulnerabilities to a list of predetermined device risks associated with the one or more device vulnerabilities (Gitelman: Col. 13, ll. (15-22) - the device attribute may be used, for example, as part of a device profile, which in tum may be used to identify abnormal activity of devices which may require mitigation. Thus, the device attribute identification described herein may be utilized to accurately profile the device, which in turn allows for more accurately identifying abnormalities in device behavior by comparison to devices having the same device attributes or combinations of device attributes).
As per claim 21, the modified teaching of Gitelman teaches the method of claim 1, comprising: determining a number of devices associated with one or more wireless communication protocols based on the wireless signal data (Gitelman: Col. 4, ll. (27-30); ll. (35-37) - each sensor is deployed as an out-of-band device and is configured to monitor and control the wireless traffic transmitted by the devices while each sensor may be configured to process the monitored traffic based on a corresponding wireless communication protocol).
As per claim 22, the modified teaching of Gitelman teaches the method of claim 21, further comprising: displaying a graphical user interface comprising a plurality of dashboards, wherein a first dashboard comprises an indication of the number of devices associated at least one of the one or more wireless protocols (Gitelman: Col. 5, ll. (21-26); Col. 6, ll. (5-7) - the sensor 140 identifies a new wireless connection, data associated with the new wireless connection (device associated with wireless protocol) is sent to the exploitable vulnerability detector while the exploitable vulnerability detector 150 is configured to interface (display the data on dashboard) with one or more external systems).
As per claim 23, the modified teaching of Gitelman teaches the method of claim 22, wherein the first dashboard comprises a user configurable geospatial view, wherein the geospatial view depicts an indication of a location of the plurality of devices (Gitelman: Col. 7, ll. (40-41) - a list of previously discovered devices can be managed in a centralized location).
As per claim 24, the modified teaching of Gitelman teaches the method of claim 22, wherein the first dashboard comprises an indication of one or more of vendors associated with the plurality of devices (Gitelman: Col. 5, ll. (36-38) - determination of a device's vendor based on the MAC address may be performed by the sensors or by the exploitable vulnerability detector; wherein Col. 6, ll. (5-7) - teaches he exploitable vulnerability detector is configured to interface (display the data on dashboard) with one or more external systems).
As per claim 25, the modified teaching of Gitelman teaches the method of claim 22, wherein a second dashboard comprises a list of the plurality of devices, wherein the list comprises a device identifier associated with a device of the plurality of devices, a wireless protocol associated with the device, a vendor associated with the device, and the device risk associated with the device (Gitelman: Col. 5, ll. (21-26); Col. 6, ll. (5-7) - the sensor 140 identifies a new wireless connection, data associated with the new wireless connection (device associated with wireless protocol) is sent to the exploitable vulnerability detector while the exploitable vulnerability detector 150 is configured to interface (display the data on dashboard) with one or more external systems; wherein Col. 5, ll. (36-38) - teaches determination of a device's vendor based on the MAC address may be performed by the sensors or by the exploitable vulnerability detector; and Col. 6, ll. (5-7) - teaches he exploitable vulnerability detector is configured to interface (display the data on dashboard) with one or more external systems).
As per claim 26, the modified teaching of Gitelman teaches the method of claim 22, wherein a third dashboard comprises an indication of one or more weaknesses and one or more threats associated with the one or more wireless devices (Gitelman: Col. 6, ll. (5-7); ll. (15-18) - teaches he exploitable vulnerability detector is configured to interface (display the data on dashboard) with one or more external systems while such external systems may provide vulnerabilities databases identifying known vulnerabilities that are device type-specific and defining known exploits for those vulnerabilities).
As per claim 27, the modified teaching of Gitelman teaches the method of claim 1, further comprising: determining a relationship between a first device and a second device of the plurality of devices based on a communication between the first device and the second device (Gitelman: Col. 3, ll. (49-55) - a plurality of coexisting networks 120-1 through 120-n (hereinafter referred to individually as a network 120 and collectively as networks 120, merely for simplicity purposes), thereby allowing communication between and among the devices).
As per claim 28, the modified teaching of Gitelman teaches the method of claim 27, comprising: generating a network map comprising a first node associated with the first device and a second node associated with the second device, wherein the network map depicts the relationship between the first device and the second device based on the communication between the first device and the second device (Gitelman: Col. 3, ll. (49-55) - a plurality of coexisting networks 120-1 through 120-n (hereinafter referred to individually as a network 120 and collectively as networks 120, merely for simplicity purposes), thereby allowing communication between and among the devices in the environment of an internal network of an organization).
As per claim 29, the modified teaching of Gitelman teaches the method of claim 1, comprising: determining one or more device subcomponents associated with a device of the plurality of devices based on the wireless signal data (Gitelman: claim 10 - sequentially apply a plurality of sub-models of a hierarchy to a plurality of features extracted from device activity data, wherein the sequential application ends with applying a last sub-model of the plurality of sub-models, wherein each sub-model includes a plurality of classifiers, wherein each sub-model outputs a class when applied to at least a portion of the plurality of features,).
As per claim 30, the modified teaching of Gitelman teaches the method of claim 26, comprising: determining one or more subcomponent vulnerabilities associated with a device subcomponent of the one or more device subcomponents (Gitelman: Col. 6, ll. 65 to Col. 7, ll. 3 - the exploitable vulnerability detector 150 is configured to navigate a classifier hierarchy in order to determine each device attribute, for example, a device attribute of one of the devices 110. The exploitable vulnerability detector 150 may be further configured to train sub-models of the hierarchy).
As per claim 31, the claim resembles claim 1 and is rejected under the same rationale while Gitelman also teaches a non-transitory computer readable storage medium storing instructions (Gitelman: Claim 9 - a non-transitory computer readable medium having stored thereon instructions).
As per claim 32, the claim resembles claim 1 and is rejected under the same rationale.
As per claim 33, the claim resembles claim 1 and is rejected under the same rationale.
Claims 12-14 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over US
11,841,952 issued to Gitelman et al. (Gitelman) in view of US 20200104509 issued to Furuichi et al. (Furuichi) and further in view of US 20190044737 issued to Singhi et al. (Singhi).
As per claim 12, the modified teaching of Gitelman teaches the method of claim 1 however does not explicitly teach wherein the plurality of devices are classified using at least one of: one or more passive inference techniques and one or more active interrogation techniques.
Singhi however explicitly teaches wherein the plurality of devices are classified using at least one of: one or more passive inference techniques and one or more active interrogation techniques (Singhi: ¶ 0003, ¶ 0019 - a modified WLAN probe and beacon technique (inference technique as per ¶ 0026 of specification) replaces traditional IoT device configuration to access the network; wherein a variety of security techniques for WLAN networks have been developed, such as the Wi-Fi protected setup (WPS) family of standards (WPS is also classified as inference technique based on ¶ 0026 of the specification)).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the modified teaching of Gitelman in view of Singhi to teach wherein the plurality of devices are classified using at least one of: one or more passive inference techniques and one or more active interrogation techniques. One would be motivated to do so as a modified WLAN probe and beacon technique (inference technique) replaces traditional IoT device configuration to access the network; wherein a variety of security techniques for WLAN networks have been developed, such as the Wi-Fi protected setup (WPS) family of standards (WPS is also classified as inference technique) (Singhi: ¶ 0003, ¶ 0019).
As per claim 13, the modified teaching of Gitelman in view of Singhi teaches the method of claim 12, wherein the one or more passive inference techniques comprise any one or more of: a Wi-Fi probe-request frame taxonomy, a Wi-Fi beacon frame taxonomy, a Wi-Fi protected setup taxonomy, a passive Bluetooth taxonomy, OUI vendor matching, WPS vendor matching, WPS product matching, and Bluetooth Low Energy Generic Attribute Profile Blueprinting (Singhi: ¶ 0003, ¶ 0019 - a modified WLAN probe and beacon technique (inference technique as per ¶ 0026 of specification) replaces traditional IoT device configuration to access the network; wherein a variety of security techniques for WLAN networks have been developed, such as the Wi-Fi protected setup (WPS) family of standards (WPS is also classified as inference technique based on ¶ 0026 of the specification)).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the modified teaching of Gitelman in view of Singhi to teach wherein the one or more passive inference techniques comprise any one or more of: a Wi-Fi probe-request frame taxonomy, a Wi-Fi beacon frame taxonomy, a Wi-Fi protected setup taxonomy, a passive Bluetooth taxonomy, OUI vendor matching, WPS vendor matching, WPS product matching, and Bluetooth Low Energy Generic Attribute Profile Blueprinting. One would be motivated to do so as a modified WLAN probe and beacon technique (inference technique) replaces traditional IoT device configuration to access the network; wherein a variety of security techniques for WLAN networks have been developed, such as the Wi-Fi protected setup (WPS) family of standards (WPS is also classified as inference technique) (Singhi: ¶ 0003, ¶ 0019).
As per claim 14, the modified teaching of Gitelman in view of Singhi teaches the method of claim 12, wherein the one or more active interrogation techniques comprise any one or more of: active Bluetooth interrogation, active Z-Wave interrogation, and active 802.15.4 interrogation (Singhi: ¶ 0071 - the mesh transceiver may use any number of frequencies and protocols, such as 2.4 Gigahertz (GHz) transmissions under the IEEE 802.15.4 standard).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the modified teaching of Gitelman in view of Singhi to teach wherein the one or more active interrogation techniques comprise any one or more of: active Bluetooth interrogation, active Z-Wave interrogation, and active 802.15.4 interrogation. One would be motivated to do so as the mesh transceiver may use any number of frequencies and protocols, such as 2.4 Gigahertz (GHz) transmissions under the IEEE 802.15.4 standard (Singhi: ¶ 0071).
As per claim 19, the modified teaching of Gitelman teaches the method of claim 1 however does not explicitly teach wherein at least one of the plurality of devices is classified based on a combination of a plurality of classification techniques.
Singhi however explicitly teaches wherein at least one of the plurality of devices is classified based on a combination of a plurality of classification techniques (Singhi: ¶ 0066 - components that may be present in an IoT device implements the techniques for example the IoT device may include any combinations of the components that may be implemented as ICs, portions thereof, discrete electronic devices, or other modules, logic, hardware, software, firmware, or a combination thereof adapted in the IoT device).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the modified teaching of Gitelman in view of Singhi to teach wherein at least one of the plurality of devices is classified based on a combination of a plurality of classification techniques. One would be motivated to do so as components that may be present in an IoT device implements the techniques for example the IoT device may include any combinations of the components that may be implemented as ICs, portions thereof, discrete electronic devices, or other modules, logic, hardware, software, firmware, or a combination thereof adapted in the IoT device (Singhi: ¶ 0066).
Claim 16 is rejected under 35 U.S.C. 103 as being unpatentable over US 11,841,952
issued to Gitelman et al. (Gitelman) in view of US 20200104509 issued to Furuichi et al. (Furuichi) and further in view of US 20230205892 issued to Wareus et al. (Wareus).
As per claim 16, the modified teaching of Gitelman teaches the method of claim 15 however does not explicitly teach wherein the device code is a common platform enumerator (CPE), and wherein determining the one or more device vulnerabilities comprises determining a device vulnerability identifier based on the device code, wherein the device vulnerability identifier comprises a common vulnerability and exposure (CVE) number.
Wareus however explicitly teaches wherein the device code is a common platform enumerator (CPE) (Wareus: ¶ 0106 - CPE (common platform enumerations) may provide a standardized string (code) for defining which product and versions are affected by the vulnerability), and wherein determining the one or more device vulnerabilities comprises determining a device vulnerability identifier based on the device code, wherein the device vulnerability identifier comprises a common vulnerability and exposure (CVE) number (Wareus: ¶ 0019, ¶ 0020 - the dependency CPE and vulnerability CPE should be interpreted as an identifier and the vulnerability database should be interpreted as a database comprising vulnerabilities, wherein each vulnerability has been assigned a common vulnerability enumeration, CVE while any number of vulnerability CPEs may be linked to each CVE of the vulnerability database).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the modified teaching of Gitelman in view of Wareus to teach wherein the device code is a common platform enumerator (CPE), and wherein determining the one or more device vulnerabilities comprises determining a device vulnerability identifier based on the device code, wherein the device vulnerability identifier comprises a common vulnerability and exposure (CVE) number. One would be motivated to do so as CPE (common platform enumerations) may provide a standardized string (code) for defining which product and versions are affected by the vulnerability wherein he dependency CPE and vulnerability CPE should be interpreted as an identifier and the vulnerability database should be interpreted as a database comprising vulnerabilities, wherein each vulnerability has been assigned a common vulnerability enumeration, CVE while any number of vulnerability CPEs may be linked to each CVE of the vulnerability database (Wareus: ¶ 0019, ¶ 0020, ¶ 0106).
Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over US 11,841,952
issued to Gitelman et al. (Gitelman) in view of US 20200104509 issued to Furuichi et al. (Furuichi) and further in view of US 20170255776 issued to Zhang et al. (Zhang).
As per claim 17, the modified teaching of Gitelman teaches the method of claim 1 however does not explicitly teach wherein classifying the plurality of devices comprises: generating a string based on the wireless signal data; hashing the string to generate a signature associated with a device of the plurality of devices; and classifying a respective device of the plurality of devices based on the signature.
Zhang however explicitly teaches wherein classifying the plurality of devices comprises: generating a string based on the wireless signal data; hashing the string to generate a signature associated with a device of the plurality of devices (Zhang: ¶ 0075 - determining a string sample of data, determining a hash of the string sample of data, automatically clustering the hash with other hashes from other string samples of data, and automatically creating a string hash signature for the string sample of data); and classifying a respective device of the plurality of devices based on the signature (Zhang: ¶ 0080 - string hash signature is communicated to an electronic device for use in the detection of the malware).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the modified teaching of Gitelman in view of Zhang to teach wherein classifying the plurality of devices comprises: generating a string based on the wireless signal data; hashing the string to generate a signature associated with a device of the plurality of devices; and classifying a respective device of the plurality of devices based on the signature. One would be motivated to do so as a string of sample of data is created, determine a hash of the string sample of data. Automatically clustering the hash with other hashes from other string samples of data, and automatically creating a string hash signature for the string sample of data and string hash signature is communicated to an electronic device for use in the detection of the malware (Zhang: ¶ 0075, ¶ 0080).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SM AZIZUR RAHMAN whose telephone number is (571) 270-7360. The examiner can normally be reached on M-F Telework;
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached on 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only.
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SM A RAHMAN/Primary Examiner, Art Unit 2434