Prosecution Insights
Last updated: August 17, 2026
Application No. 19/012,233

ZERO TRUST TAGGING OF CLOUD OBJECTS

Non-Final OA §103
Filed
Jan 07, 2025
Examiner
RONI, SYED A
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
1 (Non-Final)
82%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
546 granted / 666 resolved
+24.0% vs TC avg
Strong +22% interview lift
Without
With
+22.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
18 currently pending
Career history
687
Total Applications
across all art units

Statute-Specific Performance

§101
15.6%
-24.4% vs TC avg
§103
35.8%
-4.2% vs TC avg
§102
28.8%
-11.2% vs TC avg
§112
11.1%
-28.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 666 resolved cases

Office Action

§103
DETAILED ACTION Authorization for Internet Communications The examiner encourages Applicant to submit an authorization to communicate with the examiner via the Internet by making the following statement (from MPEP 502.03): “Recognizing that Internet communications are not secure, I hereby authorize the USPTO to communicate with the undersigned and practitioners in accordance with 37 CFR 1.33 and 37 CFR 1.34 concerning any subject matter of this application by video conferencing, instant messaging, or electronic mail. I understand that a copy of these communications will be made of record in the application file.” Please note that the above statement can only be submitted via Central Fax (not Examiner's Fax), Regular postal mail, or EFS Web using PTO/SB/439. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 01/07/2025 and 05/07/2026 are being considered by the examiner. Specification The abstract of the disclosure is objected to because of the following; The abstract refers to purported merits or speculative applications of the invention and compares the invention with the prior art. Correction is required. See MPEP § 608.01(b). Claim Objections Claims 8, and 17 are objected to because of the following informalities: Regarding claims 8 and 17; the limitation “the input” lacks proper antecedent basis because there are multiple citations earlier in the claims i.e., “input” in claim 1 and “second input” in claim 7. Claim 18 is a dependent claim and thus also objected. Appropriate correction is required. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1 – 4, 7 – 13, and 16 – 20 are rejected under 35 U.S.C. 103 as being unpatentable over the prior art of record, Foskett et al., (US 2017/0063720 A1) (hereinafter “Foskett”) (submitted by the applicant via IDS filed 05/07/2026) in view of Thakore et al., (US 11,968,269 B1) (hereinafter “Thakore”). Regarding claim 1, Foskett discloses; a method of providing zero trust tagging of cloud objects in a multi-cloud network (MCN) [i.e., (para 30), (see figures 1 and 2) multi-cloud network proxy with centralized resource tagging control. The MNP 112 controls and facilitates normalization of the metadata tag identifies and metadata tag content attached to the technical components hosted in the various target hosting platforms by the service providers. The MNP 112 performs this role regardless of whether any particular target hosting platform natively supports metadata tagging. In that regard, the MNP 112 maintains the proxy metadata tagging repository 232 as a centralized source of metadata tagging information], comprising: receiving input associated with a tag of a cloud object in the MCN, the cloud object being associated with a cloud account [i.e., (para 32 – 33 and 42) the MNP 112 may…transmit discovery request messages 308, 310, 312 to the target virtual hosting platforms 312, 316, and 318 of the service providers 102, 106, and 108 respectively (402). The discovery messages specify a request for the target hosting platform to return identifiers of each resource deployed in the target virtual hosting platform…the MNP 112 receives discovery responses 320, 322, and 324 enumerating the resource as a result of transmitting the discovery request messages 308, 310, 312 (404). The discovery may include obtaining access credentials 326, e.g., logon username/password from an account owner at the resource requester 150…Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]; determining, based in part on the input, that the input associated with the tag is valid [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]; Foskett does not disclose; determining, based on the tag, one or more mappings between the tag and one of a tunnel or a classless inter domain routing (CIDR) group; determining, based on the one or more mappings, one or more virtual points of presence (vPoPs) within the MCN; and sending, to the one or more vPoPs, the one or more mappings. However, Thakore discloses; determining, based on a tag, one or more mappings [i.e., a mapping between tags and tunnels (see table 2 in col 8, lines 1 – 15)] between the tag and one of a tunnel [i.e., assigning tags to VPN gateway endpoints based on a tag policy (col. 3, lines 22 – 23) i.e., using those tags, including prioritized tags and tag relationships to determine connectivity and routing policy between endpoints (col. 8, lines 24 – 38)]; determining, based on the one or more mappings [i.e., a mapping between tags and tunnels (see table 2 in col 8, lines 1 – 15)], one or more virtual points of presence (vPoPs) within the MCN [i.e., A SASE gateway (virtual hub) 500 in the cloud control plane controls 102 controls the implementation of the tags (see ref. 500 of figure 5), (col. 8, lines 57 - 60) i.e., assigning tags to VPN gateway endpoints based on a tag policy (col. 3, lines 22 – 23)]; and sending, to the one or more vPoPs, the one or more mappings [i.e., establishing the network connection between the client endpoint and the service endpoint via the secure tunnel using the routes between the plurality of gateway endpoints (col. 5, lines 48 – 51) Note; the gateway endpoint to apply the correct tunnel, it is necessarily receiving or is provisioned with the tag policy]. Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Foskett by adapting the teachings of Thakore to provide establishment of direct tunnels between gateway endpoints (See Thakore; col. 1, lines 40 – 42). Regarding claim 2, Foskett discloses; the method of claim 1 [i.e., (see claim 1 above)]. Foskett does not disclose; receiving, by a vPoP, a request to form a new tunnel or a new CIDR with the cloud object, the request comprising the tag; determining, by the vPoP, that the tag is mapped to the new tunnel or the new CIDR; and forming, by the vPoP, a secure connection with the cloud object. However, Thakore discloses; receiving, by a vPoP, a request to form a new tunnel or a new CIDR with the cloud object, the request comprising the tag [i.e., receiving a request to establish a network connection between a client endpoint and a cloud service endpoint (col. 8, lines 24 – 38) i.e., figure 11 depicts that block 1102 states receive request for connection. The requested connection may be a VPN connection between client endpoint 406 and service endpoint 214 (see figure 11), (col. 16, lines 15 - 20)]; determining, by the vPoP, that the tag is mapped to the new tunnel [i.e., specifying connectivity between tags using tunnels based on tag policies at block 1108. The tunnel sector 622 identifies a secure tunnel from multiple tunnels based on tags and routing information (see figure 11), (col. 16, lines 44 – 51)]; and forming, by the vPoP, a secure connection with the cloud object [i.e., establishing the network connection between the client endpoint and the service endpoint via the secure tunnel using the routes between the plurality of gateway endpoints (col. 5, lines 48 – 51)]. Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Foskett by adapting the teachings of Thakore to provide establishment of direct tunnels between gateway endpoints (See Thakore; col. 1, lines 40 – 42). Regarding claim 3, Foskett discloses; the method of claim 1, wherein the cloud object comprises one of a subnet associated with the cloud account [i.e., (para 32 – 33 and 42) the MNP 112 may…transmit discovery request messages 308, 310, 312 to the target virtual hosting platforms 312, 316, and 318 of the service providers 102, 106, and 108 respectively (402). The discovery messages specify a request for the target hosting platform to return identifiers of each resource deployed in the target virtual hosting platform…the MNP 112 receives discovery responses 320, 322, and 324 enumerating the resource as a result of transmitting the discovery request messages 308, 310, 312 (404). The discovery may include obtaining access credentials 326, e.g., logon username/password from an account owner at the resource requester 150…Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]. Regarding claim 4, Foskett discloses; the method of claim 1, wherein the tag comprises one or more fields including a tag name [i.e., Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]. Regarding claim 7, Foskett discloses; the method of claim 1, further comprising: receiving second input comprising an instruction to edit the tag and generate an updated tag associated with the cloud object [i.e., (para 32 – 33 and 42) the MNP 112 may…transmit discovery request messages 308, 310, 312 to the target virtual hosting platforms 312, 316, and 318 of the service providers 102, 106, and 108 respectively (402). The discovery messages specify a request for the target hosting platform to return identifiers of each resource deployed in the target virtual hosting platform…the MNP 112 receives discovery responses 320, 322, and 324 enumerating the resource as a result of transmitting the discovery request messages 308, 310, 312 (404). The discovery may include obtaining access credentials 326, e.g., logon username/password from an account owner at the resource requester 150…Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]; determining, based on the second input, that the updated tag is invalid [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]. Foskett does not disclose; refraining from distributing the updated tag to the one or more vPoPs; and enabling traffic flow between the cloud object and the MCN using the tag. However, Thakore discloses; refraining from distributing the updated tag to the one or more vPoPs [i.e., assigning tags to VPN gateway endpoints based on a tag policy (col. 3, lines 22 – 23) i.e., using those tags, including prioritized tags and tag relationships to determine connectivity and routing policy between endpoints (col. 8, lines 24 – 38)]; and enabling traffic flow between the cloud object and the MCN using the tag [i.e., establishing the network connection between the client endpoint and the service endpoint via the secure tunnel using the routes between the plurality of gateway endpoints (col. 5, lines 48 – 51) Note; the gateway endpoint to apply the correct tunnel, it is necessarily receiving or is provisioned with the tag policy]. Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Foskett by adapting the teachings of Thakore to provide establishment of direct tunnels between gateway endpoints (See Thakore; col. 1, lines 40 – 42). Regarding claim 8, Foskett discloses; the method of claim 7, wherein determining the updated tag is invalid is based on or more of: a violation of a security policy associated with the value of the updated tag or the role of the user [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]. Regarding claim 9, Foskett discloses; the method of claim 7, further comprising: generating an alert associated with the updated tag, the alert indicating the updated tag is invalid [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]; and sending the alert to a user device for display [i.e., (para 30), (see figures 1 and 2) multi-cloud network proxy with centralized resource tagging control. The MNP 112 controls and facilitates normalization of the metadata tag identifies and metadata tag content attached to the technical components hosted in the various target hosting platforms by the service providers. The MNP 112 performs this role regardless of whether any particular target hosting platform natively supports metadata tagging. In that regard, the MNP 112 maintains the proxy metadata tagging repository 232 as a centralized source of metadata tagging information]. Regarding claim 10, Foskett discloses; the method of claim 1, wherein the input is received from an application on a user device, and wherein determining the input is valid comprises: reading, by a network management system (NMS) of the MCN and from the cloud account, a signature of the tag [i.e., (para 30), (see figures 1 and 2) multi-cloud network proxy with centralized resource tagging control. The MNP 112 controls and facilitates normalization of the metadata tag identifies and metadata tag content attached to the technical components hosted in the various target hosting platforms by the service providers. The MNP 112 performs this role regardless of whether any particular target hosting platform natively supports metadata tagging. In that regard, the MNP 112 maintains the proxy metadata tagging repository 232 as a centralized source of metadata tagging information]; validating, based on accessing a verification system, the signature of the tag as being generated by the application [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]; and based on validating the signature, storing an indication that the application is a trusted application in association with the tag [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]. Regarding claim 11, Foskett discloses; a system [i.e., (see figure 2), (page 2, para 0024] comprising: one or more processors [i.e., processors (see ref. 218 of figure 2), (page 2, para 0026)]; and one or more computer-readable media storing instructions [i.e., memories (see ref. 220 of figure 2), (page 2, para 0026)] that, when executed by the one or more processors, cause the one or more processors to perform operations comprising [i.e., (page 2, para 0026), (see figure 2)]: receiving input associated with a tag of a cloud object in a multi-cloud network (MCN), the cloud object being associated with a cloud account [i.e., (para 32 – 33 and 42) the MNP 112 may…transmit discovery request messages 308, 310, 312 to the target virtual hosting platforms 312, 316, and 318 of the service providers 102, 106, and 108 respectively (402). The discovery messages specify a request for the target hosting platform to return identifiers of each resource deployed in the target virtual hosting platform…the MNP 112 receives discovery responses 320, 322, and 324 enumerating the resource as a result of transmitting the discovery request messages 308, 310, 312 (404). The discovery may include obtaining access credentials 326, e.g., logon username/password from an account owner at the resource requester 150…Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]; determining, based in part on the input, that the input associated with the tag is valid [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]; Foskett does not disclose; determining, based on the tag, one or more mappings between the tag and one of a tunnel or a classless inter domain routing (CIDR) group; determining, based on the one or more mappings, one or more virtual points of presence (vPoPs) within the MCN; and sending, to the one or more vPoPs, the one or more mappings. However, Thakore discloses; determining, based on a tag, one or more mappings [i.e., a mapping between tags and tunnels (see table 2 in col 8, lines 1 – 15)] between the tag and one of a tunnel [i.e., assigning tags to VPN gateway endpoints based on a tag policy (col. 3, lines 22 – 23) i.e., using those tags, including prioritized tags and tag relationships to determine connectivity and routing policy between endpoints (col. 8, lines 24 – 38)]; determining, based on the one or more mappings [i.e., a mapping between tags and tunnels (see table 2 in col 8, lines 1 – 15)], one or more virtual points of presence (vPoPs) within the MCN [i.e., A SASE gateway (virtual hub) 500 in the cloud control plane controls 102 controls the implementation of the tags (see ref. 500 of figure 5), (col. 8, lines 57 - 60) i.e., assigning tags to VPN gateway endpoints based on a tag policy (col. 3, lines 22 – 23)]; and sending, to the one or more vPoPs, the one or more mappings [i.e., establishing the network connection between the client endpoint and the service endpoint via the secure tunnel using the routes between the plurality of gateway endpoints (col. 5, lines 48 – 51) Note; the gateway endpoint to apply the correct tunnel, it is necessarily receiving or is provisioned with the tag policy]. Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Foskett by adapting the teachings of Thakore to provide establishment of direct tunnels between gateway endpoints (See Thakore; col. 1, lines 40 – 42). Regarding claim 12, Foskett discloses; the system of claim 11, wherein the cloud object comprises one of a subnet associated with the cloud account [i.e., (para 32 – 33 and 42) the MNP 112 may…transmit discovery request messages 308, 310, 312 to the target virtual hosting platforms 312, 316, and 318 of the service providers 102, 106, and 108 respectively (402). The discovery messages specify a request for the target hosting platform to return identifiers of each resource deployed in the target virtual hosting platform…the MNP 112 receives discovery responses 320, 322, and 324 enumerating the resource as a result of transmitting the discovery request messages 308, 310, 312 (404). The discovery may include obtaining access credentials 326, e.g., logon username/password from an account owner at the resource requester 150…Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]. Regarding claim 13, Foskett discloses; the system of claim 11, wherein the tag comprises one or more fields including a tag name [i.e., Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]. Regarding claim 16, Foskett discloses; the system of claim 11, the operations further comprising: receiving second input comprising an instruction to edit the tag and generate an updated tag associated with the cloud object [i.e., (para 32 – 33 and 42) the MNP 112 may…transmit discovery request messages 308, 310, 312 to the target virtual hosting platforms 312, 316, and 318 of the service providers 102, 106, and 108 respectively (402). The discovery messages specify a request for the target hosting platform to return identifiers of each resource deployed in the target virtual hosting platform…the MNP 112 receives discovery responses 320, 322, and 324 enumerating the resource as a result of transmitting the discovery request messages 308, 310, 312 (404). The discovery may include obtaining access credentials 326, e.g., logon username/password from an account owner at the resource requester 150…Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]; determining, based on the second input, that the updated tag is invalid [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]. Foskett does not disclose; refraining from distributing the updated tag to the one or more vPoPs; and enabling traffic flow between the cloud object and the MCN using the tag. However, Thakore discloses; refraining from distributing the updated tag to the one or more vPoPs [i.e., assigning tags to VPN gateway endpoints based on a tag policy (col. 3, lines 22 – 23) i.e., using those tags, including prioritized tags and tag relationships to determine connectivity and routing policy between endpoints (col. 8, lines 24 – 38)]; and enabling traffic flow between the cloud object and the MCN using the tag [i.e., establishing the network connection between the client endpoint and the service endpoint via the secure tunnel using the routes between the plurality of gateway endpoints (col. 5, lines 48 – 51) Note; the gateway endpoint to apply the correct tunnel, it is necessarily receiving or is provisioned with the tag policy]. Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Foskett by adapting the teachings of Thakore to provide establishment of direct tunnels between gateway endpoints (See Thakore; col. 1, lines 40 – 42).. Regarding claim 17, Foskett discloses; the system of claim 16, wherein determining the updated tag is invalid is based on or more of: a violation of a security policy associated with the value of the updated tag or the role of the user [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]. Regarding claim 18, Foskett discloses; the system of claim 17, the operations further comprising: generating an alert associated with the updated tag, the alert indicating the updated tag is invalid [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]; and sending the alert to a user device for display [i.e., (para 30), (see figures 1 and 2) multi-cloud network proxy with centralized resource tagging control. The MNP 112 controls and facilitates normalization of the metadata tag identifies and metadata tag content attached to the technical components hosted in the various target hosting platforms by the service providers. The MNP 112 performs this role regardless of whether any particular target hosting platform natively supports metadata tagging. In that regard, the MNP 112 maintains the proxy metadata tagging repository 232 as a centralized source of metadata tagging information]. Regarding claim 19, Foskett discloses; one or more non-transitory computer-readable media maintaining instructions [i.e., memories (see ref. 220 of figure 2), (page 2, para 0026)] that, when executed by one or more processors, program the one or more processors to perform operations comprising [i.e., (page 2, para 0026), (see figure 2)]: receiving input associated with a tag of a cloud object in a multi-cloud network (MCN), the cloud object being associated with a cloud account [i.e., (para 32 – 33 and 42) the MNP 112 may…transmit discovery request messages 308, 310, 312 to the target virtual hosting platforms 312, 316, and 318 of the service providers 102, 106, and 108 respectively (402). The discovery messages specify a request for the target hosting platform to return identifiers of each resource deployed in the target virtual hosting platform…the MNP 112 receives discovery responses 320, 322, and 324 enumerating the resource as a result of transmitting the discovery request messages 308, 310, 312 (404). The discovery may include obtaining access credentials 326, e.g., logon username/password from an account owner at the resource requester 150…Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]; determining, based in part on the input, that the input associated with the tag is valid [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]; Foskett does not disclose; determining, based on the tag, one or more mappings between the tag and one of a tunnel or a classless inter domain routing (CIDR) group; determining, based on the one or more mappings, one or more virtual points of presence (vPoPs) within the MCN; and sending, to the one or more vPoPs, the one or more mappings. However, Thakore discloses; determining, based on a tag, one or more mappings [i.e., a mapping between tags and tunnels (see table 2 in col 8, lines 1 – 15)] between the tag and one of a tunnel [i.e., assigning tags to VPN gateway endpoints based on a tag policy (col. 3, lines 22 – 23) i.e., using those tags, including prioritized tags and tag relationships to determine connectivity and routing policy between endpoints (col. 8, lines 24 – 38)]; determining, based on the one or more mappings [i.e., a mapping between tags and tunnels (see table 2 in col 8, lines 1 – 15)], one or more virtual points of presence (vPoPs) within the MCN [i.e., A SASE gateway (virtual hub) 500 in the cloud control plane controls 102 controls the implementation of the tags (see ref. 500 of figure 5), (col. 8, lines 57 - 60) i.e., assigning tags to VPN gateway endpoints based on a tag policy (col. 3, lines 22 – 23)]; and sending, to the one or more vPoPs, the one or more mappings [i.e., establishing the network connection between the client endpoint and the service endpoint via the secure tunnel using the routes between the plurality of gateway endpoints (col. 5, lines 48 – 51) Note; the gateway endpoint to apply the correct tunnel, it is necessarily receiving or is provisioned with the tag policy]. Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Foskett by adapting the teachings of Thakore to provide establishment of direct tunnels between gateway endpoints (See Thakore; col. 1, lines 40 – 42).. Regarding claim 20, Foskett discloses; the one or more non-transitory computer-readable media of claim 19, wherein the input is received from an application on a user device, and wherein determining the input is valid comprises: reading, by a network management system (NMS) of the MCN and from the cloud account, a signature of the tag [i.e., (para 30), (see figures 1 and 2) multi-cloud network proxy with centralized resource tagging control. The MNP 112 controls and facilitates normalization of the metadata tag identifies and metadata tag content attached to the technical components hosted in the various target hosting platforms by the service providers. The MNP 112 performs this role regardless of whether any particular target hosting platform natively supports metadata tagging. In that regard, the MNP 112 maintains the proxy metadata tagging repository 232 as a centralized source of metadata tagging information]; validating, based on accessing a verification system, the signature of the tag as being generated by the application [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]; and based on validating the signature, storing an indication that the application is a trusted application in association with the tag [i.e., (para 44, 47 and 51) the MNP 112 may implement tag renaming in different ways. For instance, the MNP 112 may retain a base reference to the tag, e.g., with a specific tag identifier such as globally unique identifier (GUID) known to the server provider and MNP 112, which may be used for synchronization…turning ahead to fig. 12, that figure shows an example of a metadata type definition 1200. The example type definition 1200 applies to the Environmental metadata tag 1201. The type definition 1200 includes, e.g., constraint definitions 1202 and validation definitions 1250 in the type definition 1200 may be enforced across all customers, the type definition may indicate that the content field is mandatory and must have a value. When the tag content validates, the MNP 112 saves the new metadata tag content in the proxy metadata tagging repository 232 (826)…]. Claim(s) 5 – 6, and 14 - 15 are rejected under 35 U.S.C. 103 as being unpatentable over Foskett in view of Thakore as applied to claims 4 and 13 above, and further in view of Diorio et al., (US 9,111,283 B1) (hereinafter “Diorio”). Regarding claim 5, Foskett discloses; the method of claim 4, wherein the tag is generated and signed by an application associated with a cloud service provider of the cloud account, wherein generating the tag comprises: receiving second input via the application comprising values associated with the one or more fields [i.e., (para 32 – 33 and 42) the MNP 112 may…transmit discovery request messages 308, 310, 312 to the target virtual hosting platforms 312, 316, and 318 of the service providers 102, 106, and 108 respectively (402). The discovery messages specify a request for the target hosting platform to return identifiers of each resource deployed in the target virtual hosting platform…the MNP 112 receives discovery responses 320, 322, and 324 enumerating the resource as a result of transmitting the discovery request messages 308, 310, 312 (404). The discovery may include obtaining access credentials 326, e.g., logon username/password from an account owner at the resource requester 150…Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]. Foskett and Thakore do not disclose; signing, by the application, the one or more fields of the tag to generate a cryptographical signature. However, Diorio discloses; signing, by an application, one or more fields of a tag to generate a cryptographical signature [i.e., the signing authority generates a tag-specific electronic signature by signing at least the tag public key with the master private key (col. 2, lines 27 – 30)]. Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Foskett and Thakore by adapting the teachings of Diorio to securely managing and distributing passwords or keys among global trading partners (See Diorio; col. 2, lines 3 – 4). Regarding claim 6, Foskett discloses; the method of claim 5 [i.e., (see claim 5 above)]. Foskett and Thakore do not disclose; wherein the cryptographical signature is based on hashing the tag name, cloud object identifier, and an identifier of an entity. However, Diorio discloses; wherein the cryptographical signature is based on hashing the tag name [i.e., a hash value (), (see ref. 603 of figure 6A), (col. 11, lines 49 – 54), i.e., the signing authority generates a tag-specific electronic signature by signing at least the tag public key with the master private key (col. 2, lines 27 – 30)]. Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Foskett and Thakore by adapting the teachings of Diorio to securely managing and distributing passwords or keys among global trading partners (See Diorio; col. 2, lines 3 – 4). Regarding claim 14, Foskett discloses; the system of claim 13, wherein the tag is generated and signed by an application associated with a cloud service provider of the cloud account, wherein generating the tag comprises: receiving second input via the application comprising values associated with the one or more fields [i.e., (para 32 – 33 and 42) the MNP 112 may…transmit discovery request messages 308, 310, 312 to the target virtual hosting platforms 312, 316, and 318 of the service providers 102, 106, and 108 respectively (402). The discovery messages specify a request for the target hosting platform to return identifiers of each resource deployed in the target virtual hosting platform…the MNP 112 receives discovery responses 320, 322, and 324 enumerating the resource as a result of transmitting the discovery request messages 308, 310, 312 (404). The discovery may include obtaining access credentials 326, e.g., logon username/password from an account owner at the resource requester 150…Fig. 5 shows a metadata tagging control interface (“control interface”) 500. In particular, the MNP 112 generates the control interface 500 (802) to facilitate adding, deleting and renaming new metadata tags, and to facilitate synchronizing metadata tags to target hosting platform…”]. Foskett and Thakore do not disclose; signing, by the application, the one or more fields of the tag to generate a cryptographical signature. However, Diorio discloses; signing, by an application, one or more fields of a tag to generate a cryptographical signature [i.e., the signing authority generates a tag-specific electronic signature by signing at least the tag public key with the master private key (col. 2, lines 27 – 30)]. Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Foskett and Thakore by adapting the teachings of Diorio to securely managing and distributing passwords or keys among global trading partners (See Diorio; col. 2, lines 3 – 4). Regarding claim 15, Foskett discloses; the system of claim 14 [i.e., (see claim 5 above)]. Foskett and Thakore do not disclose; wherein the cryptographical signature is based on hashing the tag name, cloud object identifier, and an identifier of an entity. However, Diorio discloses; wherein the cryptographical signature is based on hashing the tag name [i.e., a hash value (), (see ref. 603 of figure 6A), (col. 11, lines 49 – 54), i.e., the signing authority generates a tag-specific electronic signature by signing at least the tag public key with the master private key (col. 2, lines 27 – 30)]. Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Foskett and Thakore by adapting the teachings of Diorio to securely managing and distributing passwords or keys among global trading partners (See Diorio; col. 2, lines 3 – 4). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Townsley (US 2026/0197297 A1) discloses receiving input associated with a first tag of a first network element in the MCN, the first network element being associated with a cloud account of the MCN; determining, based on the first tag, a tag mapping between the first tag and one of a tunnel or classless interdomain routing (CIDR) group; determining, based on the tag mapping, one or more routes associated with the first network element that enable traffic flow to a second network element via the MCN; determining, based on the tag mapping, a virtual point of presence (vPoP) associated with the first network element; and sending the one or more routes to the vPoP. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SYED A RONI whose telephone number is (571)270-7806. The examiner can normally be reached M-F 9:00-5:00 pm (EST). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SYED A RONI/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Jan 07, 2025
Application Filed
Jul 28, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12695768
MONITORING A SOFTWARE DEVELOPMENT PIPELINE
4y 1m to grant Granted Jul 28, 2026
Patent 12693914
MULTI-AGENT RING-BUFFER
2y 6m to grant Granted Jul 28, 2026
Patent 12694103
MULTI-ACCESS EDGE COMPUTING FOR REMOTE LOCATIONS
2y 1m to grant Granted Jul 28, 2026
Patent 12688279
SYSTEMS AND METHODS FOR EVENT-BASED APPLICATION CONTROL
2y 3m to grant Granted Jul 21, 2026
Patent 12675609
ENERGY STORAGE SYSTEM AND OPERATING METHOD THEREOF
2y 5m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
82%
Grant Probability
99%
With Interview (+22.3%)
2y 9m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 666 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month