Remarks
Claims 1-20 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. Applicant has not complied with one or more conditions for receiving the benefit of an earlier filing date under 35 U.S.C. 120 as follows:
The later-filed application must be an application for a patent for an invention which is also disclosed in the prior application (the parent or original nonprovisional application or provisional application). The disclosure of the invention in the parent application and in the later-filed application must be sufficient to comply with the requirements of 35 U.S.C. 112(a) or the first paragraph of pre-AIA 35 U.S.C. 112, except for the best mode requirement. See Transco Products, Inc. v. Performance Contracting, Inc., 38 F.3d 551, 32 USPQ2d 1077 (Fed. Cir. 1994).
The disclosure of the prior-filed application, Application No. 16/419,017, fails to provide adequate support or enablement in the manner provided by 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph for one or more claims of this application. The parent application does not enable intervening in the authentication process such that the authentication request is denied solely in response to ascertaining that the response indicates that the authentication request is granted, as currently claimed in independent claims 1 and 12.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph, as based on a disclosure which is not enabling. The disclosure does not enable one of ordinary skill in the art to practice the invention without additional processing prior to intervening in the authentication process such that the authentication request is denied (e.g., asking for another authentication factor for MFA), which is/are critical or essential to the practice of the invention but not included in the claim(s). See In re Mayhew, 527 F.2d 1229, 188 USPQ 356 (CCPA 1976). At no point does the application as originally filed enable intervening in the authentication process such that the authentication request is denied solely in response to ascertaining that the response indicates that the authentication request was granted. Additional steps are required, such as requesting authentication via another factor of MFA and this factor not being authenticated prior to denying. In fact, the only time the application as originally filed discusses intervening in the authentication process such that authentication is denied is when the authentication fails (e.g., steps 76 and 78 of figure 4).
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being incomplete for omitting essential steps, such omission amounting to a gap between the steps. See MPEP § 2172.01. The omitted steps are: the additional processing required prior to intervening in the authentication process such that the authentication request is denied, as noted above in the 112(a) rejection.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-11 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter because claim 1 is directed to a system comprising a traffic management server and a directory server. However, servers are known in the art to include virtual/software servers. Moreover, the application states that the components in figure 5 may include any suitable combination of hardware and/or software components (last page of the specification) and that the servers may use virtual hosting and be implemented as a virtual machine (e.g., claim 6, page 19), showing that software only embodiments are within the scope of the application. In order to be statutory as a system/machine, the system/machine must distinguish itself based on physical components. None of claims 2-11 fix this issue and they are all rejected for the same reasons.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-9 and 11-19 are rejected under 35 U.S.C. 103 as being unpatentable over Agarwal (U.S. Patent Application Publication 2013/0007239) in view of Rathor (U.S. Patent 9,124,636).
Regarding Claim 1,
Agarwal discloses a system comprising:
A traffic management server (Exemplary Citations: for example, Figures 6A, 7A, 8A, and associated written description, as well as below citations describing functionality of traffic management server; cache server, parallel device, as examples); and
A directory server, configured to (Exemplary Citations: for example, Figures 6A, 7A, 8A, and associated written description, as well as below citations describing functionality of directory server; intermediary, appliance, as examples):
Run a directory application (Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 273, and associated figures; any application, such as a vServer, server application, web server application, etc., including for active directories or the like, for example); and
While running the directory application, using one or more modules that are separate from the directory application (Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 273, and associated figures; other module(s) may include any other module(s) within the appliance/intermediary, including communication modules used to transmit and receive packets, for example):
Receive an authentication request originating from a request origin device and directed to the directory application per an authentication process (Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 227-237, 252, 253, 270-280, and associated figures; receive request including name and password, for example);
Subsequently to receiving the authentication request, forward the authentication request to the traffic management server (Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 227-237, 252, 253, 270-280, and associated figures; cache redirection, redirection to parallel device, or the like, for example);
Subsequently to forwarding the authentication request, receive the authentication request from the traffic management server (Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 227-237, 252, 253, 270-280, and associated figures; receiving the message back from the parallel device or cache, for example);
In response to receiving the authentication request from the traffic management server, pass the authentication request to the directory application (Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 227-237, 252, 253, 270-280, and associated figures; sending request to the above-described application(s), for example); and
Subsequently to passing the authentication request to the directory application, receive a response to the authentication request from the directory application (Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 227-237, 252, 253, 270-280, and associated figures; receive response, for example); and
With respect to the limitation reading in response to receiving the response from the directory application, communicate the response to the traffic management server (for which the Examiner cited the following for the corresponding limitation in parent application #16/419,017: Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 227-237, 252, 253, 270-280, and associated figures; cache redirection, redirection to parallel device, or the like, for example), the PTAB stated, in the response dated 7/17/2024 of the parent application #16/419,017, that, although the PTAB did not believe that the Examiner had cited sufficient evidence to demonstrate that Agarwal necessarily routes the response through the TMS (equated to the parallel device 108), “Agarwal identifies the redirector comprises the functionality to direct both request and response messages through the parallel processing device 810, which would have the claimed flow of the response. We find that Agarwal teaches that the parallel processing device 810 may perform services such as encrypting or decrypting. Agarwal ¶283. Thus, Agarwal suggests that one of the communication links either between the client 102 and intermediary 200, or between the intermediary 200 and the server 106, carries encrypted data. Thus, for example, if the link from the client to the intermediary carried encrypted data, one skilled in the art would find it obvious to use the redirector such that upon receiving an encrypted request from the client (item 106), the redirector in the intermediary (item 800, 200) would forward the request to the parallel processing device 810 (to decrypt the request), which would then return the decrypted request, the parallel processing device would then forward the decrypted request to the server, the response from the server would then be forwarded back through the intermediary and parallel processing device for encryption before sending it back to the client (i.e. the return leg uses the data flow depicted in Fig 8B, with the response substituted for the request, and the server 10 substituted for the client). Thus, we consider the skilled artisan would find it obvious to make use of the parallel processing device for both the request and response to the request to maintain security by encrypting the data.” Thus, it would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to forward responses as well as requests to the parallel devices within Agarwal in order to allow for encrypted communications, to maintain security in encrypted communications, and/or to increase security by allowing for such encrypted communications. The PTAB also stated, in the denial of reconsideration dated 9/17/2024 in parent application #16/419,017, that the decision cited above “demonstrated that Agarwal suggests using an intermediary for communications in both directions and that use of encrypted communications would be one reason the skilled artisan would use an intermediary for communications in both directions.” Thus, the PTAB has already effectively affirmed its own motivation statement, cited above and incorporated into the 103 motivation statement above.
But does not explicitly disclose the traffic management server being configured to: ascertain that the response indicates that the authentication request was granted, and in response to ascertaining that the response indicates that the authentication request was granted, intervene in the authentication process such that the authentication request is denied.
Rathor, however, discloses that the traffic management server being configured to:
Ascertain that the response indicates that the authentication request was granted (Exemplary Citations: for example, Abstract, Column 6, lines 17-39; Column 7, lines 25-47; Column 10, lines 13-26; Column 15, line 53 to Column 16, line 40; and associated figures; authentication successful, for example); and
In response to ascertaining that the response indicates that the authentication request was granted, intervene in the authentication process such that the authentication request is denied (Exemplary Citations: for example, Abstract, Column 6, line 40 to Column 7, line 63; Column 9, line 16 to Column 11, line 26; Column 12, line 18 to Column 13, line 41; Column 18, line 20 to Column 19, line 25; Column 20, line28 to Column 21, line 27; Column 22, line 36 to Column 23, line 43; Column 24, line 44 to Column 25, line 49; Column 26, lines 28-58; and associated figures; denying devices that have been compromised or considered compromised based on common characteristics or the like, for example. These policies are checked in response to successful authentication, as noted in the cited sections). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the compromise detection and response techniques of Rathor into the redirection system of Agarwal in order to proactively prevent the spread of malicious network traffic and resulting infection throughout a network, to stop attacking devices from performing attacks, and/or to increase security in the system.
Regarding Claim 12,
Claim 12 is a method claim that corresponds to system claim 1 and is rejected for the same reasons.
Regarding Claim 2,
Agarwal as modified by Rathor discloses the system of claim 1, in addition, Agarwal as modified by Rathor discloses that the traffic management server is configured to intervene in the authentication process by modifying the response to indicate that the authentication request was denied, and wherein the directory server is further configured to (Rathor: Exemplary Citations: for example, Abstract, Column 6, line 40 to Column 7, line 63; Column 9, line 16 to Column 11, line 26; Column 12, line 18 to Column 13, line 41; Column 18, line 20 to Column 19, line 25; Column 20, line28 to Column 21, line 27; Column 22, line 36 to Column 23, line 43; Column 24, line 44 to Column 25, line 49; Column 26, lines 28-58; and associated figures; change of authorization response, denial response, changing of VLAN to deny access, etc., as examples):
Receive the modified response from the traffic management server (Agarwal: Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 227-237, 252, 253, 270-280, and associated figures; receiving the message back from the parallel device or cache, for example; please also see the above citations to the PTAB documents, as well as the documents themselves that show that communicating responses through the parallel device and intermediary is obvious. Rathor: Exemplary Citations: for example, Abstract, Column 6, line 40 to Column 7, line 63; Column 9, line 16 to Column 11, line 26; Column 12, line 18 to Column 13, line 41; Column 18, line 20 to Column 19, line 25; Column 20, line28 to Column 21, line 27; Column 22, line 36 to Column 23, line 43; Column 24, line 44 to Column 25, line 49; Column 26, lines 28-58; and associated figures; modified response being received by an entity from another entity, such as by a switch from UAC, from a UAC from another UAC (e.g., as in Figure 5, Column 26, line 59 to Column 27, line 27), for example); and
In response to receiving the modified response from the traffic management server, communicate the modified response to the request origin device (Agarwal: Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 227-237, 252, 253, 270-280, 284, and associated figures; forwarding to the a destination, such as client or server, for example; again, the PTAB already explained this quite well. Rathor: Exemplary Citations: for example, Abstract, Column 6, line 40 to Column 7, line 63; Column 9, line 16 to Column 11, line 26; Column 12, line 18 to Column 13, line 41; Column 18, line 20 to Column 19, line 25; Column 20, line28 to Column 21, line 27; Column 22, line 36 to Column 23, line 43; Column 24, line 44 to Column 25, line 49; Column 26, lines 28-58; and associated figures; sending the modified response to user device or the like, for example).
Regarding Claim 13,
Claim 13 is a method claim that corresponds to system claim 2 and is rejected for the same reasons.
Regarding Claim 3,
Agarwal as modified by Rathor discloses the system of claim 2, in addition, Agarwal as modified by Rathor discloses that the directory server is configured to forward the authentication request to the traffic management server over a connection, and wherein the traffic management server is configured to return the modified response to the directory server over the connection (Agarwal: Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 227-237, 252, 253, 270-280, 284, and associated figures; connections are used for communications, for example. Rathor: Exemplary Citations: for example, Abstract, Column 6, line 40 to Column 7, line 63; Column 9, line 16 to Column 11, line 26; Column 12, line 18 to Column 13, line 41; Column 18, line 20 to Column 19, line 25; Column 20, line28 to Column 21, line 27; Column 22, line 36 to Column 23, line 43; Column 24, line 44 to Column 25, line 49; Column 26, lines 28-58; and associated figures; connections are used for communications, for example).
Regarding Claim 14,
Claim 14 is a method claim that corresponds to system claim 3 and is rejected for the same reasons.
Regarding Claim 4,
Agarwal as modified by Rathor discloses the system of claim 1, in addition, Agarwal as modified by Rathor discloses that the traffic management server is configured to intervene in the authentication process by closing a connection between the traffic management server and the directory server, such that the response is not returned to the directory server (Rathor: Exemplary Citations: for example, Abstract, Column 6, line 40 to Column 7, line 63; Column 9, line 16 to Column 11, line 26; Column 12, line 18 to Column 13, line 41; Column 18, line 20 to Column 19, line 25; Column 20, line28 to Column 21, line 27; Column 22, line 36 to Column 23, line 43; Column 24, line 44 to Column 25, line 49; Column 26, lines 28-58; and associated figures; change of authorization response, denial response, changing of VLAN to deny access, etc., as examples, all close a connection, for example).
Regarding Claim 15,
Claim 15 is a method claim that corresponds to system claim 4 and is rejected for the same reasons.
Regarding Claim 5,
Agarwal as modified by Rathor discloses the system of claim 1, in addition, Agarwal as modified by Rathor discloses that the traffic management server is configured to intervene in the authentication process by refraining from returning the response to the directory server (Rathor: Exemplary Citations: for example, Abstract, Column 6, line 40 to Column 7, line 63; Column 9, line 16 to Column 11, line 26; Column 12, line 18 to Column 13, line 41; Column 18, line 20 to Column 19, line 25; Column 20, line28 to Column 21, line 27; Column 22, line 36 to Column 23, line 43; Column 24, line 44 to Column 25, line 49; Column 26, lines 28-58; and associated figures; change of authorization response or denial response being sent, for example).
Regarding Claim 16,
Claim 16 is a method claim that corresponds to system claim 5 and is rejected for the same reasons.
Regarding Claim 6,
Agarwal as modified by Rathor discloses the system of claim 1, in addition, Agarwal as modified by Rathor discloses that the directory server and the traffic management server are implemented on a single host (Agarwal: Exemplary Citations: for example, Abstract, Paragraphs 41-60, 64-74, 76-89, and associated figures; appliance/intermediary may be part of client, server, etc., for example; Rathor: Exemplary Citations: for example, Column 5, lines 14-32; Column 27, lines 43-60; and associated figures; same device or separate devices, for example).
Regarding Claim 7,
Agarwal as modified by Rathor discloses the system of claim 1, in addition, Agarwal as modified by Rathor discloses that the modules include network layer software (Agarwal: Exemplary Citations: for example, Paragraph 145 and associated figures; virtual network interfaces, for example).
Regarding Claim 17,
Claim 17 is a method claim that corresponds to system claim 7 and is rejected for the same reasons.
Regarding Claim 8,
Agarwal as modified by Rathor discloses the system of claim 1, in addition, Agarwal as modified by Rathor discloses that the traffic management server is further configured to inspect parameters of the authentication request and/or of the response, and wherein the traffic management server is configured to intervene in the authentication process in response to the parameters (Rathor: Exemplary Citations: for example, Abstract, Column 6, line 40 to Column 7, line 63; Column 9, line 16 to Column 11, line 26; Column 12, line 18 to Column 13, line 41; Column 18, line 20 to Column 19, line 25; Column 20, line28 to Column 21, line 27; Column 22, line 36 to Column 23, line 43; Column 24, line 44 to Column 25, line 49; Column 26, lines 28-58; and associated figures; inspecting parameters, such as common characteristics, health parameters, identification parameters, and the like, for example, and intervening as above based on those, for example).
Regarding Claim 18,
Claim 18 is a method claim that corresponds to system claim 8 and is rejected for the same reasons.
Regarding Claim 9,
Agarwal as modified by Rathor discloses the system of claim 8, in addition, Agarwal as modified by Rathor discloses that the traffic management server is further configured to calculate a risk measure based on the parameters, and wherein the traffic management server is configured to intervene in the authentication process in response to the risk measure exceeding a predetermined threshold (Rathor: Exemplary Citations: for example, Abstract, Column 6, line 40 to Column 7, line 63; Column 9, line 16 to Column 11, line 26; Column 12, line 18 to Column 13, line 41; Column 18, line 20 to Column 19, line 25; Column 20, line28 to Column 21, line 27; Column 22, line 36 to Column 23, line 43; Column 24, line 44 to Column 25, line 49; Column 26, lines 28-58; and associated figures; attack/compromise detected (e.g., a binary where the threshold may be “anything above 0 is considered compromised”, for example), or other thresholds, such as number of endpoint devices, time, common characteristics, etc., as examples).
Regarding Claim 19,
Claim 19 is a method claim that corresponds to system claim 9 and is rejected for the same reasons.
Regarding Claim 11,
Agarwal as modified by Rathor discloses the system of claim 1, in addition, Agarwal as modified by Rathor discloses that the traffic management server is configured to return the authentication request to the directory server using an IP address of the request origin device as a source IP address of the authentication request (Agarwal: Exemplary Citations: for example, Paragraphs 229, 244, 248-253, and associated figures; maintaining source/client IP address in packet, for example).
Claims 10 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Agarwal in view of Rathor and Sancheti (U.S. Patent Application Publication 2017/0244730).
Regarding Claim 10,
Agarwal as modified by Rathor does not appear to explicitly disclose that the traffic management server is configured to intervene in the authentication process by: requesting provision of authentication from a user who initiated the authentication request in accordance with a multi factor authentication policy, and causing the authentication request to be denied in response to not receiving the requested authentication from the user.
Sancheti, however, discloses that the traffic management server is configured to intervene in the authentication process by:
Requesting provision of authentication from a user who initiated the authentication request in accordance with a multi factor authentication policy (Exemplary Citations: for example, Paragraphs 8, 9, 43, 48-51, 56, 59, 62, 63, 70, 73-77, 80, 86-101, and associated figures; requesting authentication of user, for example); and
Causing the authentication request to be denied in response to not receiving the requested authentication from the user (Exemplary Citations: for example, Paragraphs 8, 9, 43, 48-51, 56, 59, 62, 63, 70, 73-77, 80, 86-101, and associated figures; authentication failure, for example, for example). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the network communication inspection techniques of Sancheti into the redirection system of Agarwal as modified by Rathor in order to detect and prevent attacks and unwanted activities, protect authentication based network resources, allow for use of numerous additional authentication techniques, and/or to increase security in the system.
Regarding Claim 20,
Claim 20 is a method claim that corresponds to system claim 10 and is rejected for the same reasons.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Jeffrey D Popham whose telephone number is (571)272-7215. The examiner can normally be reached Monday through Friday 9:00-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Jeffrey D. Popham/Primary Examiner, Art Unit 2432