Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claims 1-20 are pending in Instant Application.
Information Disclosure Statement
The information disclosure statement(s) (IDS) submitted on 05/11/2026 is/are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement(s) is/are being considered if signed and initialed by the Examiner.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-6, 8-13, 15-20 are rejected under 35 U.S.C. 103 as being unpatentable over Chanak et al., “hereinafter Chanak” (U.S. Patent Application: 20230247003) in view of Lindteigen (U.S. Patent Application: 20170201382).
As per Claim 1, Chanak discloses a method implemented in a computer system that includes a processor system, comprising:
validating an identity of a first remote endpoint based on a cryptographic credential received from the first remote endpoint (Chanak, Para.06, validating credentials of the user with one or more additional sources, responsive to successful validation of the users' credentials, authenticating the user and evaluating one or more access policies for the user, and initiating a connection between the user and the application based on the one or more access policies, Para.94, These endpoints are user computing devices—such as mobile devices, laptops, tablets, etc. );
determining that the first remote endpoint is authorized to communicate with a second remote endpoint (Chanak, Para.110, The central authority 152 determines if the user 102 and the user device 300 are authorized for the enterprise file share and application 402, 404. Once authorization is determined, the central authority 152 provides information to the enforcement nodes 150A, 150B, 150C, the application 350, and the lightweight connectors 400 at the enterprise file share and application 402, 404, and the information can include the certificates 720 and other details necessary to stitch secure connections between the various devices.);
initiating an establishment of a network packet route between the first remote endpoint and the second remote endpoint (Chanak, Para.90, the user 102 connects securely to a VPN device 420 located in the cloud-based system 100 through a secure connection 422. Note, the cloud-based system 100 can include a plurality of VPN devices 420. The VPN architecture 405 dynamically routes traffic between the user 102 and the Internet 104, the SaaS/public cloud systems for the applications 402, and securely with the enterprise network 410.), based on validating the identity of the first remote endpoint, and based on determining that the first remote endpoint is authorized to communicate with the second remote endpoint (Chanak, Para.06, responsive to successful validation of the users' credentials, authenticating the user and evaluating one or more access policies for the user, and initiating a connection between the user and the application based on the one or more access policies, Para.07, the determining, validating, and authenticating are performed by the IDP, and receiving validation from the IDP indicating that the authentication is successful. The authenticating can further include utilizing one or more of contextual access policies, and Multi-factor Authentication (MFA) in order to authenticate a user.); and
subsequent to the establishment of the network packet route between the first remote endpoint and the second remote endpoint, (Chanak, Para.57, the cloud-based system 100 can dynamically create a connection through a secure tunnel between an endpoint (e.g., users 102A, 102B) that are remote and an on-premises connector 400 that is either located in cloud file shares and applications 402 and/or in an enterprise network 410 that includes enterprise file shares and applications 404, Para.132, The multiple modes of operation can include monitor-only, block mode, and redirect. The objective of the WAAP 600 is to protect the applications 402, 404 from compromised user devices 300 as well as from untrusted users 102, Para.208, performing inspection of transactions after the access using the plurality of rules including a rule for identifying the zero-day CVE (step 856); and, responsive to results of any of the plurality of rules, one or more of monitoring, allowing, blocking, and redirecting the access, via the cloud-based system (step 858).).
However Chanak does not disclose initiating a destruction of the network packet route between the first remote endpoint and the second remote endpoint.
Lindteigen discloses initiating a destruction of the network packet route between the first remote endpoint and the second remote endpoint (Lindteigen, Para.43, Revoked (e.g. as endpoint devices, or accounts are transferred, lost, stolen, expired, or removed, then the trusted identity token (e.g. certificate) needs to also be updated or removed to reflect its status and eliminate potential harm to the remaining population of endpoint devices), Para.41, an endpoint device may need to be revoked from a secure contact group. For example, the endpoint device may reach the end of its lifecycle, or it may be reassigned or repurposed, or it may be lost or stolen. This process can occur via a designated administrator with the 4000 secure network dashboard, or it can occur via API calls by using a security network API directly. The 4001 management server may create a new certificate revocation list (“CRL”), which may be encrypted by creating a key (e.g. by using ECDH and the security gateway's public key) and then using the key to seed AES-256 in CBC mode. The CRL may be sent to by the 4001 management server, or the management serer may replicate the message to the other 4001 management servers via the reliable messaging servers. The 4001 management servers may distribute the updated CRL to the affected endpoint device within a secure contact group, including the revoked endpoint device. When the revoked endpoint device attempts to connect to the 4000 secure network, it will be blocked from communicating with other endpoint devices or performing other security network functions.).
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings as in Chanak with the teachings as in Lindteigen. The motivation for doing so would have been for providing novel methods, apparatuses, and systems for securing, sending, receiving, and storing data between endpoint devices via a network. First a 1100 first endpoint device may be coupled to a 4000 secure network. Next, a 2100 second endpoint device may be coupled to the 4000 secure network. Next, the 4000 secure network is enabled to establish a secure communication tunnel directly between the 1100 first endpoint device and the 2100 second endpoint device enabling the 1100 first endpoint device to transmit and receive data directly to the 2100 second endpoint device via the secure communication tunnel. Further the 4000 secure network may include a continuum server; a 4001 management server; a 4002 database; a 4003 relay server; and a 4004 message server (Lindteigen, Para.09).
As per Claim 2, Chanak in view of Lindteigen discloses the method of claim 1, wherein the method further comprises validating a security status of the first remote endpoint (Chanak, Para.221, When a user (citizen) 102 opens a web browser via a user device 300 and sends a request for an application (for example, app.domain.tld), DNS directs the request to the cloud-based system 100. Systems forward a Security Assertion Markup Language (SAML) request to a configured IDP 122, where the IDP 122 determines if the user 102 passes the authentication requirements. If the user 102 passes, it presents the user 102 with a login page, consisting of a choice of social media services 352 that have been configured for authentication. The user 102 provides credentials, and the IDP 122 validates the credentials with the social media service 352. Responsive to the credentials being valid, the social media service 352 returns an authorization to the IDP 122. The IDP 122 returns a SAML assertion to the cloud-based system 100, validating that authentication is successful. The cloud-based system 100 then evaluates access policies for the user and initiates the connection between the user and the requested application via the app connector 400.).
As per Claim 3, Chanak in view of Lindteigen discloses the method of claim 2, wherein validating the security status of the first remote endpoint comprises: attesting the first remote endpoint; and issuing an attestation certificate to the first remote endpoint (Chanak, Para.221, When a user (citizen) 102 opens a web browser via a user device 300 and sends a request for an application (for example, app.domain.tld), DNS directs the request to the cloud-based system 100. Systems forward a Security Assertion Markup Language (SAML) request to a configured IDP 122, where the IDP 122 determines if the user 102 passes the authentication requirements. If the user 102 passes, it presents the user 102 with a login page, consisting of a choice of social media services 352 that have been configured for authentication. The user 102 provides credentials, and the IDP 122 validates the credentials with the social media service 352. Responsive to the credentials being valid, the social media service 352 returns an authorization to the IDP 122. The IDP 122 returns a SAML assertion to the cloud-based system 100, validating that authentication is successful. The cloud-based system 100 then evaluates access policies for the user and initiates the connection between the user and the requested application via the app connector 400.).
As per Claim 4, Chanak in view of Lindteigen discloses the method of claim 1, wherein: the identity is a first identity, and the cryptographic credential is a first cryptographic credential (Chanak, Para.104, The connection is established through the enforcement nodes 150, and is encrypted with a combination of the customer's client and server-side certificates.); and the method further comprises validating a second identity of the second remote endpoint based on a second cryptographic credential received from the second remote endpoint ( Chanak, Para.104, The connection is established through the enforcement nodes 150, and is encrypted with a combination of the customer's client and server-side certificates, Para.110, The central authority 152 determines if the user 102 and the user device 300 are authorized for the enterprise file share and application 402, 404. Once authorization is determined, the central authority 152 provides information to the enforcement nodes 150A, 150B, 150C, the application 350, and the lightweight connectors 400 at the enterprise file share and application 402, 404, and the information can include the certificates 720 and other details necessary to stitch secure connections between the various devices…With the connection information, the enforcement node 150A connects to the user 102, presenting a token, and the enforcement node 150C connects to the lightweight connector 400, presenting a token (step 758). Now, a connection is stitched between the user 102 to the enterprise file share and application 402, 404, through the application 350, the enforcement nodes 150A, 1506, 150C, and the lightweight connector 400.).
With respect to Claim 11 is substantially similar to Claim 4 and is rejected in the same manner, the same art and reasoning applying.
As per Claim 5, Chanak in view of Lindteigen discloses the method of claim 1, wherein: initiating the establishment of the network packet route between the first remote endpoint and the second remote endpoint comprises sending a first message to a network appliance, the first message instructing the network appliance to establish the network packet route (Chanak, Para.07, The one or more additional sources can include a social media service chosen from the one or more social media services, and the validating can include validating the users' credentials with the social media service. Responsive to receiving the request, the steps can include forwarding a Security Assertion Markup Language (SAML) request to a configured Identity Provider (IDP), wherein the determining, validating, and authenticating are performed by the IDP, and receiving validation from the IDP indicating that the authentication is successful. The authenticating can further include utilizing one or more of contextual access policies, and Multi-factor Authentication (MFA) in order to authenticate a user. The contextual access policies can include geo-location, network location, endpoint device posture, and social network, and the MFA can include soft tokens, one-time codes, push notifications, and utilization of biometric devices.); and initiating the destruction of the network packet route between the first remote endpoint and the second remote endpoint comprises sending a second message to the network appliance, the second message instructing the network appliance to destroy the network packet route (Lindteigen, Para.43, Revoked (e.g. as endpoint devices, or accounts are transferred, lost, stolen, expired, or removed, then the trusted identity token (e.g. certificate) needs to also be updated or removed to reflect its status and eliminate potential harm to the remaining population of endpoint devices), Para.41, an endpoint device may need to be revoked from a secure contact group. For example, the endpoint device may reach the end of its lifecycle, or it may be reassigned or repurposed, or it may be lost or stolen. This process can occur via a designated administrator with the 4000 secure network dashboard, or it can occur via API calls by using a security network API directly. The 4001 management server may create a new certificate revocation list (“CRL”), which may be encrypted by creating a key (e.g. by using ECDH and the security gateway's public key) and then using the key to seed AES-256 in CBC mode. The CRL may be sent to by the 4001 management server, or the management serer may replicate the message to the other 4001 management servers via the reliable messaging servers. The 4001 management servers may distribute the updated CRL to the affected endpoint device within a secure contact group, including the revoked endpoint device. When the revoked endpoint device attempts to connect to the 4000 secure network, it will be blocked from communicating with other endpoint devices or performing other security network functions.).
With respect to Claim 12 is substantially similar to Claim 5 and is rejected in the same manner, the same art and reasoning applying.
As per Claim 6, Chanak in view of Lindteigen discloses the method of claim 1, wherein the method further comprises at least one of: sending a first network address of the first remote endpoint to the second remote endpoint (Chanak, Para.57, These network architectures rely on approved IP addresses, ports, and protocols to establish access controls and validate what's trusted inside the network, generally including anybody connecting via remote access VPN. In contrast, a zero trust approach treats all traffic, even if it is already inside the perimeter, as hostile. For example, workloads are blocked from communicating until they are validated by a set of attributes, such as a fingerprint or identity. Identity-based validation policies result in stronger security that travels with the workload wherever it communicates—in a public cloud, a hybrid environment, a container, or an on-premises network architecture.); sending a second network address of the second remote endpoint to the first remote endpoint (Chanak, Para.126, The private service edge node 150P can include listen IP addresses and publish IP addresses or domains. The listen IP addresses are a set of IP addresses that the private service edge node 150P uses for accepting incoming connections, and this can be specified or all IP addresses. The publish IP addresses or domains, if specified, are required for connection to the private service edge node 150P. If these are specified, one of the entries is provided to the applications 350, e.g., randomly selected.); sending a first certificate or first key associated with the first remote endpoint to the second remote endpoint; or sending a second certificate or second key associated with the second remote endpoint to the first remote endpoint (Chanak, Para.109, The virtual private access process 750 is described with reference to both the user 102, the cloud-based system 100, and the enterprise file share and application 402, 404. First, the user 102 is executing the application 350 on the user device 300, in the background. The user 102 launches the application 350 and can be redirected to an enterprise ID provider or the like to sign on, i.e., a single sign on, without setting up new accounts. Once authenticated, Public Key Infrastructure (PKI) certificate 720 enrollment occurs, between the user 102 and the enforcement node 150A.).
With respect to Claim 13 is substantially similar to Claim 6 and is rejected in the same manner, the same art and reasoning applying.
As per Claim 8, Chanak in view of Lindteigen discloses the method of claim 1, wherein initiating the destruction of the network packet route between the first remote endpoint and the second remote endpoint is based on at least one of: a completion of a communication between the first remote endpoint and the second remote endpoint; an elapsing of a predetermined amount of time; or a change in a security status of the first remote endpoint or the second remote endpoint (Lindteigen, 43, Revoked (e.g. as endpoint devices, or accounts are transferred, lost, stolen, expired, or removed, then the trusted identity token (e.g. certificate) needs to also be updated or removed to reflect its status and eliminate potential harm to the remaining population of endpoint devices).
As per Claim 9, Chanak in view of Lindteigen discloses the method of claim 8, wherein initiating the destruction of the network packet route between the first remote endpoint and the second remote endpoint is based on the change in the security status of the first remote endpoint or the second remote endpoint, and wherein the change in the security status is a loss of attestation of the first remote endpoint or the second remote endpoint (Lindteigen, 43, Revoked (e.g. as endpoint devices, or accounts are transferred, lost, stolen, expired, or removed, then the trusted identity token (e.g. certificate) needs to also be updated or removed to reflect its status and eliminate potential harm to the remaining population of endpoint devices), Para.41, The 4001 management servers may distribute the updated CRL to the affected endpoint device within a secure contact group, including the revoked endpoint device. When the revoked endpoint device attempts to connect to the 4000 secure network, it will be blocked from communicating with other endpoint devices or performing other security network functions.). (20170201382)
With respect to Claim 15, 20 are substantially similar to Claim 9 and are rejected in the same manner, the same art and reasoning applying.
As per Claim 10, Chanak discloses a computer system, comprising: a processor system; and a computer storage medium that stores computer-executable instructions that are executable by the processor system (Chanak, Para.77, The processor 202 is a hardware device for executing software instructions. The processor 202 may be any custom made or commercially available processor, a Central Processing Unit (CPU), an auxiliary processor among several processors associated with the server 200…the processor 202 is configured to execute software stored within the memory 210, to communicate data to and from the memory 210, and to generally control operations of the server 200 pursuant to the software instructions.) to at least:
validate an identity of a first remote endpoint based on a cryptographic credential received from the first remote endpoint;
validate a security status of the first remote endpoint (Chanak, Para.06, validating credentials of the user with one or more additional sources, responsive to successful validation of the users' credentials, authenticating the user and evaluating one or more access policies for the user, and initiating a connection between the user and the application based on the one or more access policies, Para.94, These endpoints are user computing devices—such as mobile devices, laptops, tablets, etc. ), including:
attesting the first remote endpoint; and issuing an attestation certificate to the first remote endpoint (Chanak, Para.221, When a user (citizen) 102 opens a web browser via a user device 300 and sends a request for an application (for example, app.domain.tld), DNS directs the request to the cloud-based system 100. Systems forward a Security Assertion Markup Language (SAML) request to a configured IDP 122, where the IDP 122 determines if the user 102 passes the authentication requirements. If the user 102 passes, it presents the user 102 with a login page, consisting of a choice of social media services 352 that have been configured for authentication. The user 102 provides credentials, and the IDP 122 validates the credentials with the social media service 352. Responsive to the credentials being valid, the social media service 352 returns an authorization to the IDP 122. The IDP 122 returns a SAML assertion to the cloud-based system 100, validating that authentication is successful. The cloud-based system 100 then evaluates access policies for the user and initiates the connection between the user and the requested application via the app connector 400.).
determine that the first remote endpoint is authorized to communicate with a second remote endpoint (Chanak, Para.110, The central authority 152 determines if the user 102 and the user device 300 are authorized for the enterprise file share and application 402, 404. Once authorization is determined, the central authority 152 provides information to the enforcement nodes 150A, 150B, 150C, the application 350, and the lightweight connectors 400 at the enterprise file share and application 402, 404, and the information can include the certificates 720 and other details necessary to stitch secure connections between the various devices.);
initiate an establishment of a network packet route between the first remote endpoint and the second remote endpoint (Chanak, Para.90, the user 102 connects securely to a VPN device 420 located in the cloud-based system 100 through a secure connection 422. Note, the cloud-based system 100 can include a plurality of VPN devices 420. The VPN architecture 405 dynamically routes traffic between the user 102 and the Internet 104, the SaaS/public cloud systems for the applications 402, and securely with the enterprise network 410.), based on validating the identity of the first remote endpoint, and based on determining that the first remote endpoint is authorized to communicate with the second remote endpoint(Chanak, Para.06, responsive to successful validation of the users' credentials, authenticating the user and evaluating one or more access policies for the user, and initiating a connection between the user and the application based on the one or more access policies, Para.07, the determining, validating, and authenticating are performed by the IDP, and receiving validation from the IDP indicating that the authentication is successful. The authenticating can further include utilizing one or more of contextual access policies, and Multi-factor Authentication (MFA) in order to authenticate a user.); and
subsequent to the establishment of the network packet route between the first remote endpoint and the second remote endpoint(Chanak, Para.57, the cloud-based system 100 can dynamically create a connection through a secure tunnel between an endpoint (e.g., users 102A, 102B) that are remote and an on-premises connector 400 that is either located in cloud file shares and applications 402 and/or in an enterprise network 410 that includes enterprise file shares and applications 404, Para.132, The multiple modes of operation can include monitor-only, block mode, and redirect. The objective of the WAAP 600 is to protect the applications 402, 404 from compromised user devices 300 as well as from untrusted users 102, Para.208, performing inspection of transactions after the access using the plurality of rules including a rule for identifying the zero-day CVE (step 856); and, responsive to results of any of the plurality of rules, one or more of monitoring, allowing, blocking, and redirecting the access, via the cloud-based system (step 858).).
However Chanak does not disclose initiating a destruction of the network packet route between the first remote endpoint and the second remote endpoint.
Lindteigen discloses initiating a destruction of the network packet route between the first remote endpoint and the second remote endpoint (Lindteigen, Para.43, Revoked (e.g. as endpoint devices, or accounts are transferred, lost, stolen, expired, or removed, then the trusted identity token (e.g. certificate) needs to also be updated or removed to reflect its status and eliminate potential harm to the remaining population of endpoint devices), Para.41, an endpoint device may need to be revoked from a secure contact group. For example, the endpoint device may reach the end of its lifecycle, or it may be reassigned or repurposed, or it may be lost or stolen. This process can occur via a designated administrator with the 4000 secure network dashboard, or it can occur via API calls by using a security network API directly. The 4001 management server may create a new certificate revocation list (“CRL”), which may be encrypted by creating a key (e.g. by using ECDH and the security gateway's public key) and then using the key to seed AES-256 in CBC mode. The CRL may be sent to by the 4001 management server, or the management serer may replicate the message to the other 4001 management servers via the reliable messaging servers. The 4001 management servers may distribute the updated CRL to the affected endpoint device within a secure contact group, including the revoked endpoint device. When the revoked endpoint device attempts to connect to the 4000 secure network, it will be blocked from communicating with other endpoint devices or performing other security network functions.).
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings as in Chanak with the teachings as in Lindteigen. The motivation for doing so would have been for providing novel methods, apparatuses, and systems for securing, sending, receiving, and storing data between endpoint devices via a network. First a 1100 first endpoint device may be coupled to a 4000 secure network. Next, a 2100 second endpoint device may be coupled to the 4000 secure network. Next, the 4000 secure network is enabled to establish a secure communication tunnel directly between the 1100 first endpoint device and the 2100 second endpoint device enabling the 1100 first endpoint device to transmit and receive data directly to the 2100 second endpoint device via the secure communication tunnel. Further the 4000 secure network may include a continuum server; a 4001 management server; a 4002 database; a 4003 relay server; and a 4004 message server. (Lindteigen, Para.09).
As per Claim 17, Chanak discloses a computer storage medium that stores computer-executable instructions that are executable by a processor system to at least:
validate a first identity of a first remote endpoint based on a first cryptographic credential received from the first remote endpoint (Chanak, Para.06, validating credentials of the user with one or more additional sources, responsive to successful validation of the users' credentials, authenticating the user and evaluating one or more access policies for the user, and initiating a connection between the user and the application based on the one or more access policies, Para.94, These endpoints are user computing devices—such as mobile devices, laptops, tablets, etc. );
validate a second identity of a second remote endpoint based on a second cryptographic credential received from the second remote endpoint (Chanak, Para.104, When the user 102 requests an application in the file shares and applications 402, 404, the policy engine delivers connection information to the application 350 and app-side enforcement nodes 150, which includes the location of a single enforcement nodes 150 to provision the client/app connection. The connection is established through the enforcement nodes 150, and is encrypted with a combination of the customer's client and server-side certificates.);
determining that the first remote endpoint is authorized to communicate with a second remote endpoint (Chanak, Para.110, The central authority 152 determines if the user 102 and the user device 300 are authorized for the enterprise file share and application 402, 404. Once authorization is determined, the central authority 152 provides information to the enforcement nodes 150A, 150B, 150C, the application 350, and the lightweight connectors 400 at the enterprise file share and application 402, 404, and the information can include the certificates 720 and other details necessary to stitch secure connections between the various devices.);
initiating an establishment of a network packet route between the first remote endpoint and the second remote endpoint (Chanak, Para.90, the user 102 connects securely to a VPN device 420 located in the cloud-based system 100 through a secure connection 422. Note, the cloud-based system 100 can include a plurality of VPN devices 420. The VPN architecture 405 dynamically routes traffic between the user 102 and the Internet 104, the SaaS/public cloud systems for the applications 402, and securely with the enterprise network 410.), based on validating the identity of the first remote endpoint, and based on determining that the first remote endpoint is authorized to communicate with the second remote endpoint (Chanak, Para.06, responsive to successful validation of the users' credentials, authenticating the user and evaluating one or more access policies for the user, and initiating a connection between the user and the application based on the one or more access policies, Para.07, the determining, validating, and authenticating are performed by the IDP, and receiving validation from the IDP indicating that the authentication is successful. The authenticating can further include utilizing one or more of contextual access policies, and Multi-factor Authentication (MFA) in order to authenticate a user.); and
subsequent to the establishment of the network packet route between the first remote endpoint and the second remote endpoint, (Chanak, Para.57, the cloud-based system 100 can dynamically create a connection through a secure tunnel between an endpoint (e.g., users 102A, 102B) that are remote and an on-premises connector 400 that is either located in cloud file shares and applications 402 and/or in an enterprise network 410 that includes enterprise file shares and applications 404, Para.132, The multiple modes of operation can include monitor-only, block mode, and redirect. The objective of the WAAP 600 is to protect the applications 402, 404 from compromised user devices 300 as well as from untrusted users 102, Para.208, performing inspection of transactions after the access using the plurality of rules including a rule for identifying the zero-day CVE (step 856); and, responsive to results of any of the plurality of rules, one or more of monitoring, allowing, blocking, and redirecting the access, via the cloud-based system (step 858).).
However Chanak does not disclose initiating a destruction of the network packet route between the first remote endpoint and the second remote endpoint.
Lindteigen discloses initiating a destruction of the network packet route between the first remote endpoint and the second remote endpoint (Lindteigen, Para.43, Revoked (e.g. as endpoint devices, or accounts are transferred, lost, stolen, expired, or removed, then the trusted identity token (e.g. certificate) needs to also be updated or removed to reflect its status and eliminate potential harm to the remaining population of endpoint devices), Para.41, an endpoint device may need to be revoked from a secure contact group. For example, the endpoint device may reach the end of its lifecycle, or it may be reassigned or repurposed, or it may be lost or stolen. This process can occur via a designated administrator with the 4000 secure network dashboard, or it can occur via API calls by using a security network API directly. The 4001 management server may create a new certificate revocation list (“CRL”), which may be encrypted by creating a key (e.g. by using ECDH and the security gateway's public key) and then using the key to seed AES-256 in CBC mode. The CRL may be sent to by the 4001 management server, or the management serer may replicate the message to the other 4001 management servers via the reliable messaging servers. The 4001 management servers may distribute the updated CRL to the affected endpoint device within a secure contact group, including the revoked endpoint device. When the revoked endpoint device attempts to connect to the 4000 secure network, it will be blocked from communicating with other endpoint devices or performing other security network functions.).
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings as in Chanak with the teachings as in Lindteigen. The motivation for doing so would have been for providing novel methods, apparatuses, and systems for securing, sending, receiving, and storing data between endpoint devices via a network. First a 1100 first endpoint device may be coupled to a 4000 secure network. Next, a 2100 second endpoint device may be coupled to the 4000 secure network. Next, the 4000 secure network is enabled to establish a secure communication tunnel directly between the 1100 first endpoint device and the 2100 second endpoint device enabling the 1100 first endpoint device to transmit and receive data directly to the 2100 second endpoint device via the secure communication tunnel. Further the 4000 secure network may include a continuum server; a 4001 management server; a 4002 database; a 4003 relay server; and a 4004 message server. (Lindteigen, Para.09).
As per Claim 18, Chanak in view of Lindteigen discloses the computer storage medium of claim 17, wherein the computer-executable instructions are also executable by the processor system to: validate a first security status of the first remote endpoint; and validate a second security status of the second remote endpoint (Chanak, Para.104, When the user 102 requests an application in the file shares and applications 402, 404, the policy engine delivers connection information to the application 350 and app-side enforcement nodes 150, which includes the location of a single enforcement nodes 150 to provision the client/app connection. The connection is established through the enforcement nodes 150, and is encrypted with a combination of the customer's client and server-side certificates.).
As per Claim 19, Chanak in view of Lindteigen discloses the computer storage medium of claim 17, wherein the computer-executable instructions are also executable by the processor system to: issue a first attestation certificate to the first remote endpoint after attesting the first remote endpoint; issue a second attestation certificate to the second remote endpoint after attesting the second remote endpoint; send the first attestation certificate to the second remote endpoint; and send the second attestation certificate to the first remote endpoint (Chanak, Para.221, The user 102 provides credentials, and the IDP 122 validates the credentials with the social media service 352. Responsive to the credentials being valid, the social media service 352 returns an authorization to the IDP 122. The IDP 122 returns a SAML assertion to the cloud-based system 100, validating that authentication is successful. The cloud-based system 100 then evaluates access policies for the user and initiates the connection between the user and the requested application via the app connector 400, Para.104, When the user 102 requests an application in the file shares and applications 402, 404, the policy engine delivers connection information to the application 350 and app-side enforcement nodes 150, which includes the location of a single enforcement nodes 150 to provision the client/app connection. The connection is established through the enforcement nodes 150, and is encrypted with a combination of the customer's client and server-side certificates, Para.110, Once authorization is determined, the central authority 152 provides information to the enforcement nodes 150A, 150B, 150C, the application 350, and the lightweight connectors 400 at the enterprise file share and application 402, 404, and the information can include the certificates 720 and other details necessary to stitch secure connections between the various devices. Specifically, the central authority 152 can create connection information with the best enforcement nodes 150 for joint connections, from the user 102 to the enterprise file share and application 402, 404, and the unique tokens (step 756).).
Claims 7, 14 are rejected under 35 U.S.C. 103 as being unpatentable over Chanak et al., “hereinafter Chanak” (U.S. Patent Application: 20230247003) in view of Lindteigen (U.S. Patent Application: 20170201382) and further in view of ORÉ et al., “hereinafter ORÉ” (U.S. Patent Application: 20180091417).
As per Claim 7, Chanak in view of Lindteigen discloses the method of claim 1, wherein the method further comprises: after initiating the establishment of the network packet route between the first remote endpoint and the second remote endpoint, initiating an establishment of a secured network tunnel over the network packet route; initiating the destruction of the network packet route between the first remote endpoint and the second remote endpoint (Chanak, Para.53, There are various techniques to forward traffic between the users 102 at the locations 112, 114, 118, and via the devices 110, 116, and the cloud-based system 100. Typically, the locations 112, 114, 118 can use tunneling where all traffic is forward through the cloud-based system 100, Para.85, the cloud-based system 100 can dynamically create a connection through a secure tunnel between an endpoint (e.g., users 102A, 102B) that are remote and an on-premises connector 400 that is either located in cloud file shares and applications 402 and/or in an enterprise network 410 that includes enterprise file shares and applications 404.).
However Chanak in view of Lindteigen do not disclose initiating a destruction of the secured network tunnel over the network packet route.
ORÉ discloses initiating a destruction of the secured network tunnel over the network packet route (ORÉ, Para.161, When a tunnel goes down, it suddenly drops sending all traffic out of the tunnel and inboard tunnel traffic cannot find the end point of the tunnel which no longer exists and new tunnel build process has to wait for cleanup of routes and for the tunnel destruction process 16-040 of the first tunnel to complete.).
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings as in Chanak, Lindteigen with the teachings as in ORÉ. The motivation for doing so would have been for connecting devices via a virtual global network are disclosed. In one embodiment the network system may comprise an endpoint device including a tunnel manager and a first virtual interface, an access point server including at least one tunnel listener and a second virtual interface. One or more communication paths or tunnels are formed connecting the tunnel managers and tunnel listeners. The virtual interfaces provide a logical point of access to the one or more tunnels. (ORÉ, Para.08).
With respect to Claim 14 is substantially similar to Claim 7 and is rejected in the same manner, the same art and reasoning applying.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to NORMIN ABEDIN whose telephone number is (571)270-5970. The examiner can normally be reached Monday to Friday from 10 am to 6 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Vivek Srivastava can be reached at 5712727304. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/NORMIN ABEDIN/Primary Examiner, Art Unit 2449