Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This communication is in response to Applicant's Amendment filed 6/10/2026. Applicant has amended claim 1, 10, and 15. Currently, claims 1-20 are pending in the application.
Response to Amendments
Acknowledgement to applicant’s amendment to claims 1, 10, 15 has been noted. The claims have been reviewed, entered and found obviating to previously raised rejection under statutory double patenting rejection. Statutory double patenting rejection is hereby withdrawn.
Response to Arguments
Regarding statutory double patenting rejection over conflicting patent, US 12,250,535, the arguments filed on 6/10/2026 have been considered and are persuasive.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement.
The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp
Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b).
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of US 12,250,535. Although the claims at issue are not identical, they are not patentably distinct from each other because they are each drawn towards implementing a communication security architecture that divides communication functions.
Instant Application
US Patent 12,250,535 (Appl. No: 17505147)
Comments
10, An End Encryption Unit (ECU) implementing a communication security architecture that divides communication functions into (1) a Service Negotiation Plane for communications associated with service negotiations and (2) a data plane for communications associated with transmission of user data, the ECU comprising:
one or more encryption devices; and a trusted switch, wherein the trusted switch: connects to a local platform including one or more local networks; receives a request from a remote device that is connected to a remote platform including one or more remote networks over a data link via the Service Negotiation Plane, the request being a request for transmitting user data using one of the one or more local networks; retrieves one or more service rules associated with the one or more local networks generated by one or more local managers of the one or more local networks, wherein each of the one or more local networks has a local manager that (1) manages a plurality of communication functions of a corresponding local network among the one or more local networks and (2) establishes one or more service rules associated with the corresponding local network; based on the one or more service rules, determines whether the user data is permitted to be transmitted using any one of the one or more local networks of the local platform; and in response to determining that the user data from a remote device is permitted to be transmitted using a particular one of the one or more local networks, opens the data plane of a data link, allowing the user data to pass through the data link via the data plane; receives the user data from the remote device over the data link via the data plane; directs the user data to the one or more encryption devices for encryption the user data by the one or more encryption devices based on the one or more service rules; and transmits the encrypted user data to a particular local network of the local platform via the data plane.
10. An End Encryption Unit (ECU) implementing a communication security architecture that divides communication functions into (1) a Service Negotiation Plane for communications associated with service negotiations and (2) a data plane for communications associated with transmission of user data, wherein the Service Negotiation Plane is always open for communications associated with service negotiations, while the data plane is closed to block any user data from a remote platform unless a service negotiation is successful, the ECU comprising: one or more encryption devices; and a trusted switch configured to: connect to a local platform including one or more local networks; receive a request from a remote device that is connected to a remote platform including one or more remote networks over a data link via the Service Negotiation Plane, the request being a request for transmitting user data using one of the one or more local networks; retrieve one or more service rules associated with the one or more local networks generated by one or more local managers of the one or more local networks, wherein each of the one or more local networks has a local manager configured to (1) manage a plurality of communication functions of a corresponding local network among the one or more local networks and (2) establish one or more service rules associated with the corresponding local network; based on the one or more service rules, determine whether the user data is permitted to be transmitted using any one of the one or more local networks of the local platform; and in response to determining that the user data from the remote device is permitted to be transmitted using a particular one of the one or more local networks, open the data plane of the data link, allowing the user data to pass through the data link via the data plane; receive the user data from the remote device over the data link via the data plane; direct the user data to the one or more encryption devices, encrypting the user data by the one or more encryption devices based on the one or more service rules; and transmit the encrypted user data to a particular local network of the local platform via the data plane.
Based on the broadest reasonable interpretation, all claim limitations in current application are included in the claims of the patent, as the current application discloses a broader invention as that of the patent.
Claim 1
Claim 1
Similar as above
Allowable Subject Matter
Claims 1-20 would be allowable if rewritten to overcome the rejection above.
The prior art of record teaches the following:
*Kappler et al. (US 2010/0316029 A1) teaches an apparatus provides roaming broker functionality. The apparatus comprises a negotiation controller for negotiating a roaming agreement between an originating network and a destination network. The apparatus further comprises a rule generator generating rules according to a negotiated roaming agreement, and a configuration unit configured to implement configuration settings according to respective rules generated by the rule generator.
Lounsberry (US 2022/0261487) teaches technology for risk-based access to secrets utilizes risk metadata tailored to secrets. Secrets include passwords, security tokens, digital certificates, and other items used for identity authentication, authorization, signing, validation, and other cybersecurity processes. A secret's risk metadata may indicate which controls protect the secret, the deployment scope of the secret or the asset it secures, known exposures of the secret, whether the secret secures other secrets, the impact if the secret is misused, the secret's strength, characteristics of the asset the secret secures, the secret's risk history, and other characteristics of secrets that set them apart. Unlike secrets, typical user-generated digital assets like web pages, documents, image files, and so on have value on their own. An enhanced system distinguishes between secrets and non-secrets when modulating access, making it possible to automatically provide consistent, efficient, and effective risk-based control over access to secrets.
*GSM Association (NPL): “Guidelines for IPX Provider Networks (Previously Inter-Service Provider IP Backbone Guidelines) teaches the internet Protocol (IP) Packet eXchange (IPX) Network is an inter-Service Provider IP backbone which comprises the interconnected networks of IPX Providers and General Packet Radio Service (GPRS) Roaming exchange (GRX) Providers.
The IPX network supports multiple IPX services. The purpose of this document is to provide guidelines and technical information on how these networks are set-up and interconnect, and how Service Providers will connect to the IPX Provider networks. The services supported on IPX are out of scope for this document and are currently listed in GSMA Permanent Reference Document (PRO) AA.51. An IPX service is a service that requires the IPX network for either isolation from the Internet and/or for quality of service and experience. See GSMA PRO AA.51 for a list of IPX Services.
*Nair et al. (US 2021/0321303 A1) teaches techniques for automated management of a service level agreement between a first communication network and a second communication network are provided. For example, one of the communication networks is a visited network while the other is a home network whereby the service level agreement is a roaming agreement. In one example, a message is received at a first communication network from a second communication network, wherein at least a portion of the message relates to the service level agreement between the first communication network and the second communication network. An automated verification of information in the message is performed at the first communication network to determine compliance with the service level agreement. The message receiving step is performed by a security edge protection proxy function of the first communication network and the automated verification performing step is performed by a service level agreement management function of the first communication network.
(*) Indicates prior art provided by Applicant’s IDS.
However, none of the prior art of record teach by themselves or in any combination nor would have anticipated nor render obvious by combination the claimed invention of the present invention at or before the time it was filed. The prior art of record is silent on “A cross-network communication system comprising:a plurality of client networks and a crypto module implementing a Service Negotiation Plane through which service negotiation messages between the plurality of client networks can traverse;the Service Negotiation Plane forwards messages between the plurality of client networks via a plurality of control interfaces, each of the plurality of control interfaces being connected to one of the plurality of client networks,each of the plurality of control interfaces includes a first data guard that belongs to a corresponding client network, wherein the first data guard prevents exfiltration of classified information, wherein in response to receiving a message associated with a cross-network service negotiation request from a first data controller of a first client network among the plurality of client networks, the Service Negotiation Plane forwards the message to a second controller interface of a second client network among the plurality of client networks,in response to receiving the message associated with a cross-network service negotiation request, the first data guard of the second controller interface allows the message to pass therethrough and reach a manager of the second client network,the manager of the second client network determines whether the cross-network service negotiation request is to be granted or denied,the crypto module further comprising: one or more crypto devices,a security manager that controls a path forwarding function implemented by the crypto module, encapsulates messages via the one or more crypto devices, and encapsulates messages via the one or more crypto devices in a particular order; and a trusted switch, wherein the trusted switch:(1) directs an output of one crypto device from among the one or more crypto devices to an input of another crypto device from among the one or more crypto devices based on one or more service rules, the one or more service rules used to determine whether user data is permitted to be transmitted using any one of the one or more client networks,(2) directs an output of one crypto device from among the or more crypto devices to an input of a same crypto device based on the one or more service rules, or (3) performs a combination thereof. [claim 1] and (recited in a slightly general way in claims 10 and 15) one or more encryption devices; and a trusted switch, wherein the trusted switch :connects to a local platform including one or more local networks; retrieves one or more service rules associated with the one or more local networks generated by one or more local managers of the one or more local networks, wherein each of the one or more local networks has a local manager that (1) manages a plurality of communication functions of a corresponding local network among the one or more local networks and (2) establishes one or more service rules associated with the corresponding local network; based on the one or more service rules, determines whether the user data is permitted to be transmitted using any one of the one or more local networks of the local platform; andin response to determining that the user data from a remote device is permitted to be transmitted using a particular one of the one or more local networks, opens the data plane of a data link, allowing the user data to pass through the data link via the data plane;receives the user data from the remote device over the data link via the data plane;directs the user data to the one or more encryption devices for encryption based on the one or more service rules; and transmits the encrypted user data to a particular local network of the local platform via the data plane [claims 20, 25]”, in combination with all other claim limitations.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure.
(1) Walker et al. (US 2008/0069351 A1) teaches techniques for negotiation of security policies in wireless mesh networks.
(2) *Tyebji (US 2007/0053367 A1) teaches system and method for developing and executing a wireless application gateway.
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LIZBETH TORRES-DIAZ whose telephone number is 571-272-1787. The examiner can normally be reached on 9:00a-4:30p.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached on 571-270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/LIZBETH TORRES-DIAZ/ Primary Examiner, Art Unit 2408
July 25, 2026