Prosecution Insights
Last updated: August 17, 2026
Application No. 19/045,033

COMMUNICATIONS SECURITY ARCHITECTURE IMPLEMENTING A SERVICE NEGOTIATION PLANE CHANNEL

Final Rejection §DP
Filed
Feb 04, 2025
Priority
Oct 19, 2021 — continuation of 12/250,535
Examiner
TORRES-DIAZ, LIZBETH
Art Unit
Tech Center
Assignee
L3Harris Technologies Inc.
OA Round
2 (Final)
80%
Grant Probability
Favorable
3-4
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
252 granted / 314 resolved
+20.3% vs TC avg
Strong +31% interview lift
Without
With
+31.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
10 currently pending
Career history
320
Total Applications
across all art units

Statute-Specific Performance

§101
11.7%
-28.3% vs TC avg
§103
51.7%
+11.7% vs TC avg
§102
8.9%
-31.1% vs TC avg
§112
19.2%
-20.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 314 resolved cases

Office Action

§DP
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This communication is in response to Applicant's Amendment filed 6/10/2026. Applicant has amended claim 1, 10, and 15. Currently, claims 1-20 are pending in the application. Response to Amendments Acknowledgement to applicant’s amendment to claims 1, 10, 15 has been noted. The claims have been reviewed, entered and found obviating to previously raised rejection under statutory double patenting rejection. Statutory double patenting rejection is hereby withdrawn. Response to Arguments Regarding statutory double patenting rejection over conflicting patent, US 12,250,535, the arguments filed on 6/10/2026 have been considered and are persuasive. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b). Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of US 12,250,535. Although the claims at issue are not identical, they are not patentably distinct from each other because they are each drawn towards implementing a communication security architecture that divides communication functions. Instant Application US Patent 12,250,535 (Appl. No: 17505147) Comments 10, An End Encryption Unit (ECU) implementing a communication security architecture that divides communication functions into (1) a Service Negotiation Plane for communications associated with service negotiations and (2) a data plane for communications associated with transmission of user data, the ECU comprising: one or more encryption devices; and a trusted switch, wherein the trusted switch: connects to a local platform including one or more local networks; receives a request from a remote device that is connected to a remote platform including one or more remote networks over a data link via the Service Negotiation Plane, the request being a request for transmitting user data using one of the one or more local networks; retrieves one or more service rules associated with the one or more local networks generated by one or more local managers of the one or more local networks, wherein each of the one or more local networks has a local manager that (1) manages a plurality of communication functions of a corresponding local network among the one or more local networks and (2) establishes one or more service rules associated with the corresponding local network; based on the one or more service rules, determines whether the user data is permitted to be transmitted using any one of the one or more local networks of the local platform; and in response to determining that the user data from a remote device is permitted to be transmitted using a particular one of the one or more local networks, opens the data plane of a data link, allowing the user data to pass through the data link via the data plane; receives the user data from the remote device over the data link via the data plane; directs the user data to the one or more encryption devices for encryption the user data by the one or more encryption devices based on the one or more service rules; and transmits the encrypted user data to a particular local network of the local platform via the data plane. 10. An End Encryption Unit (ECU) implementing a communication security architecture that divides communication functions into (1) a Service Negotiation Plane for communications associated with service negotiations and (2) a data plane for communications associated with transmission of user data, wherein the Service Negotiation Plane is always open for communications associated with service negotiations, while the data plane is closed to block any user data from a remote platform unless a service negotiation is successful, the ECU comprising: one or more encryption devices; and a trusted switch configured to: connect to a local platform including one or more local networks; receive a request from a remote device that is connected to a remote platform including one or more remote networks over a data link via the Service Negotiation Plane, the request being a request for transmitting user data using one of the one or more local networks; retrieve one or more service rules associated with the one or more local networks generated by one or more local managers of the one or more local networks, wherein each of the one or more local networks has a local manager configured to (1) manage a plurality of communication functions of a corresponding local network among the one or more local networks and (2) establish one or more service rules associated with the corresponding local network; based on the one or more service rules, determine whether the user data is permitted to be transmitted using any one of the one or more local networks of the local platform; and in response to determining that the user data from the remote device is permitted to be transmitted using a particular one of the one or more local networks, open the data plane of the data link, allowing the user data to pass through the data link via the data plane; receive the user data from the remote device over the data link via the data plane; direct the user data to the one or more encryption devices, encrypting the user data by the one or more encryption devices based on the one or more service rules; and transmit the encrypted user data to a particular local network of the local platform via the data plane. Based on the broadest reasonable interpretation, all claim limitations in current application are included in the claims of the patent, as the current application discloses a broader invention as that of the patent. Claim 1 Claim 1 Similar as above Allowable Subject Matter Claims 1-20 would be allowable if rewritten to overcome the rejection above. The prior art of record teaches the following: *Kappler et al. (US 2010/0316029 A1) teaches an apparatus provides roaming broker functionality. The apparatus comprises a negotiation controller for negotiating a roaming agreement between an originating network and a destination network. The apparatus further comprises a rule generator generating rules according to a negotiated roaming agreement, and a configuration unit configured to implement configuration settings according to respective rules generated by the rule generator. Lounsberry (US 2022/0261487) teaches technology for risk-based access to secrets utilizes risk metadata tailored to secrets. Secrets include passwords, security tokens, digital certificates, and other items used for identity authentication, authorization, signing, validation, and other cybersecurity processes. A secret's risk metadata may indicate which controls protect the secret, the deployment scope of the secret or the asset it secures, known exposures of the secret, whether the secret secures other secrets, the impact if the secret is misused, the secret's strength, characteristics of the asset the secret secures, the secret's risk history, and other characteristics of secrets that set them apart. Unlike secrets, typical user-generated digital assets like web pages, documents, image files, and so on have value on their own. An enhanced system distinguishes between secrets and non-secrets when modulating access, making it possible to automatically provide consistent, efficient, and effective risk-based control over access to secrets. *GSM Association (NPL): “Guidelines for IPX Provider Networks (Previously Inter-Service Provider IP Backbone Guidelines) teaches the internet Protocol (IP) Packet eXchange (IPX) Network is an inter-Service Provider IP backbone which comprises the interconnected networks of IPX Providers and General Packet Radio Service (GPRS) Roaming exchange (GRX) Providers. The IPX network supports multiple IPX services. The purpose of this document is to provide guidelines and technical information on how these networks are set-up and interconnect, and how Service Providers will connect to the IPX Provider networks. The services supported on IPX are out of scope for this document and are currently listed in GSMA Permanent Reference Document (PRO) AA.51. An IPX service is a service that requires the IPX network for either isolation from the Internet and/or for quality of service and experience. See GSMA PRO AA.51 for a list of IPX Services. *Nair et al. (US 2021/0321303 A1) teaches techniques for automated management of a service level agreement between a first communication network and a second communication network are provided. For example, one of the communication networks is a visited network while the other is a home network whereby the service level agreement is a roaming agreement. In one example, a message is received at a first communication network from a second communication network, wherein at least a portion of the message relates to the service level agreement between the first communication network and the second communication network. An automated verification of information in the message is performed at the first communication network to determine compliance with the service level agreement. The message receiving step is performed by a security edge protection proxy function of the first communication network and the automated verification performing step is performed by a service level agreement management function of the first communication network. (*) Indicates prior art provided by Applicant’s IDS. However, none of the prior art of record teach by themselves or in any combination nor would have anticipated nor render obvious by combination the claimed invention of the present invention at or before the time it was filed. The prior art of record is silent on “A cross-network communication system comprising:a plurality of client networks and a crypto module implementing a Service Negotiation Plane through which service negotiation messages between the plurality of client networks can traverse;the Service Negotiation Plane forwards messages between the plurality of client networks via a plurality of control interfaces, each of the plurality of control interfaces being connected to one of the plurality of client networks,each of the plurality of control interfaces includes a first data guard that belongs to a corresponding client network, wherein the first data guard prevents exfiltration of classified information, wherein in response to receiving a message associated with a cross-network service negotiation request from a first data controller of a first client network among the plurality of client networks, the Service Negotiation Plane forwards the message to a second controller interface of a second client network among the plurality of client networks,in response to receiving the message associated with a cross-network service negotiation request, the first data guard of the second controller interface allows the message to pass therethrough and reach a manager of the second client network,the manager of the second client network determines whether the cross-network service negotiation request is to be granted or denied,the crypto module further comprising: one or more crypto devices,a security manager that controls a path forwarding function implemented by the crypto module, encapsulates messages via the one or more crypto devices, and encapsulates messages via the one or more crypto devices in a particular order; and a trusted switch, wherein the trusted switch:(1) directs an output of one crypto device from among the one or more crypto devices to an input of another crypto device from among the one or more crypto devices based on one or more service rules, the one or more service rules used to determine whether user data is permitted to be transmitted using any one of the one or more client networks,(2) directs an output of one crypto device from among the or more crypto devices to an input of a same crypto device based on the one or more service rules, or (3) performs a combination thereof. [claim 1] and (recited in a slightly general way in claims 10 and 15) one or more encryption devices; and a trusted switch, wherein the trusted switch :connects to a local platform including one or more local networks; retrieves one or more service rules associated with the one or more local networks generated by one or more local managers of the one or more local networks, wherein each of the one or more local networks has a local manager that (1) manages a plurality of communication functions of a corresponding local network among the one or more local networks and (2) establishes one or more service rules associated with the corresponding local network; based on the one or more service rules, determines whether the user data is permitted to be transmitted using any one of the one or more local networks of the local platform; andin response to determining that the user data from a remote device is permitted to be transmitted using a particular one of the one or more local networks, opens the data plane of a data link, allowing the user data to pass through the data link via the data plane;receives the user data from the remote device over the data link via the data plane;directs the user data to the one or more encryption devices for encryption based on the one or more service rules; and transmits the encrypted user data to a particular local network of the local platform via the data plane [claims 20, 25]”, in combination with all other claim limitations. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. (1) Walker et al. (US 2008/0069351 A1) teaches techniques for negotiation of security policies in wireless mesh networks. (2) *Tyebji (US 2007/0053367 A1) teaches system and method for developing and executing a wireless application gateway. A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to LIZBETH TORRES-DIAZ whose telephone number is 571-272-1787. The examiner can normally be reached on 9:00a-4:30p. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached on 571-270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /LIZBETH TORRES-DIAZ/ Primary Examiner, Art Unit 2408 July 25, 2026
Read full office action

Prosecution Timeline

Feb 04, 2025
Application Filed
Jun 09, 2026
Non-Final Rejection mailed — §DP
Jun 10, 2026
Response Filed
Jul 29, 2026
Final Rejection mailed — §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12689898
METHODS FOR HANDLING SECURITY OF EARLY MOBILE-TERMINATED DATA TRANSMISSIONS
4y 9m to grant Granted Jul 21, 2026
Patent 12683937
COMMUNICATION NETWORK NODES, METHODS FOR PROVIDING COMMUNICATION NETWORK NODES, TERMINAL DEVICE, METHOD FOR OPERATING A TERMINAL DEVICE, METHODS FOR COMMUNICATION NETWORKS
2y 11m to grant Granted Jul 14, 2026
Patent 12682036
VERIFICATION METHOD, VERIFICATION DEVICE, AND PROGRAM
2y 5m to grant Granted Jul 14, 2026
Patent 12677142
MULTI-ORBIT, MULTI-SAT, MULTI-BAND SATELLITE COMMUNICATION AND SECURE COMMUNICATION VIA SPATIAL FIREWALL FROM SPACE
2y 10m to grant Granted Jul 07, 2026
Patent 12664320
PROCESSING SYSTEM, INTEGRATED CIRCUIT, DEVICE, AND METHOD FOR DATA TRANSFER FOR SECURE PROCESSING
2y 12m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+31.3%)
2y 11m (~1y 4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 314 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month