DETAILED ACTION
Claims 1-20 are pending. This is in response to the application filed on November 12, 2024.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 13-17 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter because the computer program product, under broadest interpretation, is not one of eligible subject matter. It is read as a software claim.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 1 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 1 recites the limitation "the at least one communication device" in the second limitation. There is insufficient antecedent basis for this limitation in the claim.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 103 as being anticipated by Pub 20050071630 (hereinafter Thornton)
Regarding claim 1, Thornton discloses a system for identifying and tracking digital certificates for secure interfacing in a distributed network, the system comprising:
a memory device with computer-readable program code stored thereon; at least one processing device operatively coupled to the at least one memory device and the at least one communication device (Figs. 5-6 and par. [0138]-[0140] discloses a system to manage certificates for enterprises comprise servers, clients, etc. where the certificate manager in Fig. 6 combines all functionalities of 55-60 as illustrated in Fig. 5. It is inherent the certificate manager comprises memory, program code, processor, etc. as a standard computing device at the least), wherein executing the computer-readable code is configured to cause the at least one processing device to:
generate a certificate reader component, wherein the certificate reader component is coupled to at least one host server (the scanner is a reader and host servers S1-S4);
identify, by the certificate reader component, at least one digital certificate applied to the at least one host server (par. [0139]);
automatically collect digital certificate data for the at least one digital certificate; generate a digital certificate database comprising the collected digital certificate data for the at least one digital certificate (par. [0139]);
receive a query for the digital certificate database, wherein the query comprises at least one of a digital certificate identifier, a website identifier, an application identifier, or a host identifier (par. [0081]-[0084] discloses certificates are stored in a database, hence suggesting using queries to perform functions related to database access and par. [0165] discloses certificate id and the common name recorded in each certificate. See also Appendix A for same example related to query statements that can resulted in errors 100, 101, etc.); and
generate, based on the query, a report interface component, wherein the report interface component comprises the collected digital certificate data for at least one of the digital certificate identifier, the website identifier, the application identifier, or the host identifier (Fig. 28).
Regarding claim 2, Thornton discloses wherein the certificate reader component is coupled to a public key infrastructure component associated with the at least one host server (as known in the art, certificates represent Public key infrastructure (PKI)).
Regarding claim 3, Thornton discloses wherein the at least one digital certificate is associated with at least one application or website hosted on the at least one host server (par. [0096] and [0194] discloses servers S1-S4 can be web servers, application servers, etc.).
Regarding claim 4, Thornton discloses wherein the identification of the at least one digital certificate by the certificate reader component is identified in real-time to the application of the at least one digital certificate to the at least one host server (Fig. 5 and related text disclose certificate scanning based on IP address range and can be set to scan by interval or immediate).
Regarding claim 5, Thornton discloses identify at least one application associated with the identified at least one digital certificate; identify a plurality of host servers hosting the at least one application; and update the digital certificate database with a plurality of host server identifiers associated with the plurality of host servers (Figs. 31, 61 and related text discloses different host servers for different types of applications).
Regarding claim 6, Thornton discloses wherein the certificate reader component identifies all digital certificates hosted on the at least one host server (par. [0166] and [0173] discloses an exemplary view reporting all managed certificates).
Regarding claim 7, Thornton discloses wherein the collected digital certificate data comprises at least one of an expiration for the at least one digital certificate, at least one of an application identifier or a website identifier for the at least one digital certificate, at least one of a website public key or an application public key for the at least one digital certificate, or at least one of a live status or a dead status for the at least one digital certificate (Fig. 10 and related text discloses managing certificate based on its status).
Regarding claim 8, Thornton discloses scan, by the certificate reader component, the at least one host server, wherein the scan is a full file system scan of the at least one host server; automatically collect, based on the scan of the at least one host server, live digital certificate data and historical digital certificate data; and update the digital certificate database with the live digital certificate data and the historical digital certificate data associated with the at least one host server (Figs. 16-17 and related text discloses certificate management comprises editing, removing, historical activity. Also, par. [0105] discloses locating the server configuration file referencing the certificates on the server).
Regarding claim 9, Thornton discloses wherein the at least one host server scanned is a network comprising the at least one host server, and wherein the scan is a full file system scan of the network (par. [01015] discloses scanning certificate information to all server files).
Regarding claim 10, Thornton discloses wherein the network scanned comprises a range of networks, and wherein the range of networks is based on a range of internet protocol (IP) addresses (Fig. 25).
Regarding claim 11, Thornton discloses wherein the certificate reader component scans the network at a pre-determined interval (Fig. 25).
Regarding claim 12, Thornton discloses validate the collected digital certificate data that was previously collected by the digital certificate component by comparing the live digital certificate data and historical digital certificate data of the at least one host server (Figs. 9-10 and par. [0113], [0137] discloses certificate management for a server. Note that par. [0174] discloses comparing current certificate against past/revoked certificate in an example of a client device. One would expect the same procedure should apply to a server or any device for certificate management).
Regarding claims 13 and 18, the claims are rejected in view of claim 1 rejection.
Regarding claims 14 and 19, the claim is rejected in view of claim 2 rejection.
Regarding claim 15, the claims are rejected in view of claim 4 rejection.
Regarding claim 16, the claim is rejected in view of claim 5 rejection.
Regarding claims 17 and 20, the claims are rejected in view of claim 8 rejection.
Inquiry communication
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TRI M TRAN whose telephone number is (571)270-1994. The examiner can normally be reached Mon-Fri: 9am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached at (469)295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/TRI M TRAN/Primary Examiner, Art Unit 2432