DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statements (IDSs) were submitted on 05/27/2025, 12/16/2025 and 06/03/2026. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-15 of U.S. Patent No. 12,255,768. Although the claims at issue are not identical, they are not patentably distinct from each other because claims 1-15 of U.S. Patent No. 12,255,768 teaches on each and every limitation of claims 1-20 of the Instant Application.
Instant Application
US Patent No. 12,255,768
1. A system comprising: memory; and one or more processors having access to the memory, wherein the memory stores instructions that, when executed, cause the one or more processors to:
determine, based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
determine, based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes,
wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults;
and output an indication of the one or more candidate root cause faults.
14. A system comprising: memory; one or more processors having access to the memory; and wherein the memory stores instructions that, when executed, cause the one or more processors to:
determine, a causality map for the plurality of network devices according to an intent, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with the plurality of network devices, a second plurality of nodes that each represent a respective symptom provided, at least in part, by the plurality of network devices, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
receive an indication of a network service impact;
determine, based on the network service impact, a relevant portion of the causality map that is less than the entire causality map;
determine, based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes, wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults; and
output an indication of the one or more candidate root cause faults.
2. The system of claim 1, wherein the instructions further cause the one or more processors to: determine a mapping of a serial number for a networking device of the plurality of network devices to a unique model identifier for the causality map, wherein the instructions cause the one or more processors to determine the causality map further based on the mapping of the serial number to the unique model identifier.
2. The method of claim 1, further comprising:
determining, by the one or more processors, a mapping of a serial number for a networking device of the plurality of network devices to a unique model identifier for the causality graph; and
wherein determining the causality map is further based on the mapping of the serial number to the unique model identifier.
3. The system of claim 1, wherein the instructions to determine the relevant portion of the causality map cause the one or more processors to match the network service impact to one of the nodes in the third set of nodes and identify at least one node in the first set of nodes using the one or more first edges and the one or more second edges.
3. The method of claim 1,
wherein determining the relevant portion of the causality map comprises matching the network service impact to one of the nodes in the third set of nodes and identifying at least one node in the first set of nodes using the one or more first edges and the one or more second edges.
4. The system of claim 1, wherein the instructions further cause the one or more processors to suppress a set of alerts using the one or more candidate root cause faults.
4. The method of claim 1, further comprising suppressing, by the one or more processors, a set of alerts using the one or more candidate root cause faults.
5. The system of claim 1, wherein the instructions to determine the one or more candidate root cause faults cause the one or more processors to determine whether the one or more candidate root cause faults are within the relevant portion of the causality map.
5. The method of claim 1, wherein determining the one or more candidate root cause faults comprises determining that the one or more candidate root cause faults are within the relevant portion of the causality map.
6. The system of claim 1, wherein the instructions to output the indication of the one or more candidate root cause faults cause the one or more processors to output an alert to a network administrator.
6. The method of claim 1, wherein outputting the indication of the one or more candidate root cause faults comprises outputting an alert to a network administrator.
7. The system of claim 1, wherein the instructions to receive the indication of the network service impact cause the one or more processors to receive a support ticket for a customer.
7. The method of claim 1, wherein receiving the indication of the network service impact comprises receiving a support ticket for a customer.
8. The system of The system of wherein the plurality of network devices are arranged in a topology comprising one or more of a 3-stage Clos network topology, a 5-stage Clos network topology, or a spine and leaf topology, and wherein the instructions cause the one or more processors to determine the causality map based on the topology.
8. The method of claim 1, wherein the plurality of network devices are arranged in a topology comprising one or more of a 3-stage Clos network topology, a 5-stage Clos network topology, or a spine and leaf topology; and
wherein determining the causality map is based on the topology, a role assigned to each network device of the plurality of devices, and the intent.
9. The system of claim 1, wherein the instructions further cause the one or more processors to: receive an intent as a data structure; and determine the causality map based on the intent.
8.
wherein determining the causality map is based on the topology, a role assigned to each network device of the plurality of devices, and the intent.
10. The system of claim 9, wherein the data structure comprises a graph model.
10. The method of claim 9, wherein the data structure comprises a graph model.
11. The system of claim 1, wherein the first plurality of nodes comprises a first node corresponding to a Border Gateway Protocol (BGP) session for an external router being misconfigured, wherein the second plurality of nodes comprises a second set of nodes corresponding to one or more of BGP session operational status of the external router being down or the external router missing a non-default route to an external Ethernet Virtual Private Network (EVPN) gateway, and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of missing routes in an EVPN flood list routes for the external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted.
11. The method of claim 9,
wherein the first plurality of nodes comprises a first node corresponding to a Border Gateway Protocol (BGP) session for an external router being misconfigured;
wherein the second plurality of nodes comprises a second set of nodes corresponding to one or more of BGP session operational status of the external router being down or the external router missing a non-default route to an external Ethernet Virtual Private Network (EVPN) gateway; and
wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of missing routes in an EVPN flood list routes for the external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted.
12. The system of claim 1, wherein the first plurality of nodes comprises a first node corresponding to a border leaf Border Gateway Protocol (BGP) routing policy being misconfigured,
wherein the second plurality of nodes comprises a second set of nodes corresponding to a border leaf BGP of a leaf running a configuration that prevents learning of a non-default state,
and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of a BGP session operational status of the leaf being down, missing non-default routes, missing routes in an Ethernet Virtual Private Network (EVPN) flood list routes for an external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted.
12. The method of claim 1,
wherein the first plurality of nodes comprises a first node corresponding to a border leaf Border Gateway Protocol (BGP) routing policy being misconfigured;
wherein the second plurality of nodes comprises a second set of nodes corresponding to a border leaf BGP of a leaf running a configuration that prevents learning of a non-default state; and
wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of a BGP session operational status of the leaf being down, missing non-default routes, missing routes in an Ethernet Virtual Private Network (EVPN) flood list routes for the external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted.
13. The system of claim 1, wherein the first plurality of nodes comprises a first node corresponding to a broken path to external Ethernet Virtual Private Network (EVPN) gateway for a Border Gateway Protocol (BGP) session,
wherein the second plurality of nodes comprises a second set of nodes corresponding to one or more of a BGP session state for the BGP session changing only between a connect state, an active state, and an idle state, or a Transmission Control Protocol (TCP) socked state for peer devices of the BGP session corresponding to waiting for an acknowledgement to a connection request,
and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of missing routes in an EVPN flood list routes for an external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted.
13. The method of claim 1,
wherein the first plurality of nodes comprises a first node corresponding to a broken path to external Ethernet Virtual Private Network (EVPN) gateway for a Border Gateway Protocol (BGP) session;
wherein the second plurality of nodes comprises a second set of nodes corresponding to one or more of a BGP session state for the BGP peer session changing only between a connect state, an active state, and an idle state, or a Transmission Control Protocol (TCP) socked state for peer devices of the BGP session corresponding to waiting for an acknowledgement to a connection request; and
wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of missing routes in an EVPN flood list routes for an external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted.
14. A method comprising:
determining, by one or more processors and based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
determining, by the one or more processors and based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes,
wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults;
and outputting, by the one or more processors, an indication of the one or more candidate root cause faults.
1. A method for managing a plurality of network devices of a network, the method comprising:
determining, by one or more processors, a causality map for the plurality of network devices according to an intent, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with the plurality of network devices, a second plurality of nodes that each represent a respective symptom provided, at least in part, by the plurality of network devices, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
receiving, by the one or more processors, an indication of a network service impact;
determining, by the one or more processors and based on the network service impact, a relevant portion of the causality map that is less than the entire causality map;
determining, by the one or more processors and based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes, wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults; and
outputting, by the one or more processors, an indication of the one or more candidate root cause faults.
15. The method of claim 14, further comprising: determining, by the one or more processors, a mapping of a serial number for a networking device of the plurality of network devices to a unique model identifier for the causality map, and wherein determining the causality map is further based on the mapping of the serial number to the unique model identifier.
2. The method of claim 1, further comprising:
determining, by the one or more processors, a mapping of a serial number for a networking device of the plurality of network devices to a unique model identifier for the causality graph; and
wherein determining the causality map is further based on the mapping of the serial number to the unique model identifier.
16. The method of claim 14, wherein determining the relevant portion of the causality map comprises matching the network service impact to one of the nodes in the third set of nodes and identifying at least one node in the first set of nodes using the one or more first edges and the one or more second edges.
3. The method of claim 1,
wherein determining the relevant portion of the causality map comprises matching the network service impact to one of the nodes in the third set of nodes and identifying at least one node in the first set of nodes using the one or more first edges and the one or more second edges.
17. The method of claim 14, further comprising suppressing, by the one or more processors, a set of alerts using the one or more candidate root cause faults.
4. The method of claim 1, further comprising suppressing, by the one or more processors, a set of alerts using the one or more candidate root cause faults.
18. The method of claim 14, wherein determining the one or more candidate root cause faults comprises determining that the one or more candidate root cause faults are within the relevant portion of the causality map.
5. The method of claim 1, wherein determining the one or more candidate root cause faults comprises determining that the one or more candidate root cause faults are within the relevant portion of the causality map.
19. The method of claim 14, wherein outputting the indication of the one or more candidate root cause faults comprises outputting an alert to a network administrator.
6. The method of claim 1, wherein outputting the indication of the one or more candidate root cause faults comprises outputting an alert to a network administrator.
20. Non-transitory computer-readable storage media having stored thereon instructions that, when executed, cause one or more processors to:
determine, based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
determine, based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes,
wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults;
and output an indication of the one or more candidate root cause faults.
15. Non-transitory computer-readable storage media having stored thereon instructions that, when executed, cause one or more processors of a system that manages a plurality of network devices to:
determine, a causality map for the plurality of network devices according to an intent, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with the plurality of network devices, a second plurality of nodes that each represent a respective symptom provided, at least in part, by the plurality of network devices, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
receive an indication of a network service impact;
determine, based on the network service impact, a relevant portion of the causality map that is less than the entire causality map;
determine, based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes, wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults; and
output an indication of the one or more candidate root cause faults.
Claims 1, 14, 20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 4-6, 9, 12-14, 20 of U.S. Patent No. 12,445,345 in view of provisional 63/269,807 of US 2023/0095270 A1 (Garapati) priority date 08/20/2021.
U.S. Patent No. 12,445,345 teaches on all the limitations of Claims 1, 14, 20 except for “wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults”.
Garapati teaches wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults. (FIGS 15-16, 20 [00221] [00226]-[00227])
It would have been obvious to a person having ordinary skill in the art before the effective filing date, to modify U.S. Patent No. 12,445,345 per Garapati as it would allow the modified system to provide a more targeted root cause, allowing for quicker remediation of faults.
Instant Application
US Patent No. 12,445,345
1. A system comprising: memory; and one or more processors having access to the memory, wherein the memory stores instructions that, when executed, cause the one or more processors to: determine, based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
determine, based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes,
and output an indication of the one or more candidate root cause faults.
12. The network management system of claim 9, wherein the one or more metrics comprises one or more of: root cause data indicating for each root cause fault of a plurality of root cause faults, a respective set of one or more symptoms and one or more impacts; or an indication of one or more candidate root cause faults.
13. The network management system of claim 9, wherein the one or more metrics comprise an indication of one or more candidate root cause faults and wherein, to generate the one or more metrics, the instructions cause the processing circuitry to: determine a causality map for a plurality of network devices of the network and for the time range using the selected intent graph, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with the plurality of network devices, a second plurality of nodes that each represent a respective symptom provided, at least in part, by the plurality of network devices, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices.
14. determine a relevant portion of the causality map based on a network service indicated by the query; and
determine the one or more candidate root cause faults based on the relevant portion of the causality map,
wherein, to output the one or more metrics, the instructions cause the processing circuitry to output an indication of the one or more candidate root cause faults.
14. A method comprising:
determining, by one or more processors and based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
determining, by the one or more processors and based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes,
and outputting, by the one or more processors, an indication of the one or more candidate root cause faults.
4. The method of claim 1,
wherein the one or more metrics comprise one or more of: root cause data indicating for each root cause fault of a plurality of root cause faults, a respective set of one or more symptoms and one or more impacts; or
an indication of one or more candidate root cause faults.
5. The method of claim 1, wherein the one or more metrics comprise an indication of one or more candidate root cause faults and wherein generating the one or more metrics comprises:
determining a causality map for a plurality of network devices of the network and for the time range using the selected intent graph, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with the plurality of network devices, a second plurality of nodes that each represent a respective symptom provided, at least in part, by the plurality of network devices, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices.
6. determining a relevant portion of the causality map based on a network service indicated by the query; and
determining the one or more candidate root cause faults based on the relevant portion of the causality map,
wherein outputting the one or more metrics comprises outputting an indication of the one or more candidate root cause faults.
20. Non-transitory computer-readable storage media having stored thereon instructions that, when executed, cause one or more processors to: determine, based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
determine, based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes,
and output an indication of the one or more candidate root cause faults.
20. The non-transitory computer-readable storage media of claim 17, wherein the one or more metrics comprises one or more of:
root cause data indicating for each root cause fault of a plurality of root cause faults, a respective set of one or more symptoms and one or more impacts; or
an indication of one or more candidate root cause faults.
13. The network management system of claim 9, wherein the one or more metrics comprise an indication of one or more candidate root cause faults and wherein, to generate the one or more metrics, the instructions cause the processing circuitry to:
determine a causality map for a plurality of network devices of the network and for the time range using the selected intent graph, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with the plurality of network devices, a second plurality of nodes that each represent a respective symptom provided, at least in part, by the plurality of network devices, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices.
14. determine a relevant portion of the causality map based on a network service indicated by the query; and
determine the one or more candidate root cause faults based on the relevant portion of the causality map,
wherein, to output the one or more metrics, the instructions cause the processing circuitry to output an indication of the one or more candidate root cause faults.
Claims 1, 3, 5, 9-10, 14, 20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 11, 13, 20 of U.S. Patent No. 12,199,813 in view of provisional 63/269,807 of US 2023/0095270 A1 (Garapati) priority date 08/20/2021.
U.S. Patent No. 12,199,813 teaches on all the limitations of Claims 1, 14, 20 except for “wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults”.
Garapati teaches wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults. (FIGS 15-16, 20 [00221] [00226]-[00227])
It would have been obvious to a person having ordinary skill in the art before the effective filing date, to modify U.S. Patent No. 12,199,813 per Garapati as it would allow the modified system to provide a more targeted root cause, allowing for quicker remediation of faults.
Instant Application
US Patent No. 12,199,813
1. A system comprising: memory; and one or more processors having access to the memory, wherein the memory stores instructions that, when executed, cause the one or more processors to:
determine, based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes; determine, based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes,
11. A computing system comprising:
a memory configured to store time series data comprising measurements of one or more performance indicators received from devices of a network system; and
processing circuitry configured to execute an analysis framework system, the analysis framework system configured to:
determine, based on the time series data, one or more anomalies in a performance of the network system;
create, based on the time series data, a knowledge graph comprising first nodes in the network system referenced in the time series, the first nodes representing elements residing at one or more of a plurality of network service layers associated with the network system;
determine, in response to detecting the one or more anomalies, and based on the knowledge graph and a machine learning (ML) model trained with previous time series data, a causality graph, wherein the causality graph includes second nodes associated with the performance indicators, wherein edges between the first nodes and the second nodes indicate relationships between the first nodes and the second nodes, and wherein the knowledge graph and the causality graph each includes edges between one or more of the first nodes and one or more of the second nodes that are associated with elements residing at different network service layers of the plurality of network service layers;
determine a weighting for each of the edges in the causality graph;
determine, based on the edges in the causality graph, one or more candidate root causes associated with the one or more anomalies;
determine a ranking of the one or more candidate root causes based on the weighting of the edges in the causality graph; and
output at least a portion of the ranking.
3. The system of claim 1, wherein the instructions to determine the relevant portion of the causality map cause the one or more processors to match the network service impact to one of the nodes in the third set of nodes and identify at least one node in the first set of nodes using the one or more first edges and the one or more second edges.
13. The computing system of claim 11,
wherein the processing circuitry is further configured to, in response to determining the one or more anomalies and prior to determining the causality graph, prune the knowledge graph to remove first nodes that are more than a threshold distance away from the first nodes of the knowledge graph that are associated with the one or more anomalies, and wherein the processing circuitry is configured to determine the causality graph based on the pruned knowledge graph.
5. The system of claim 1,
wherein the instructions to determine the one or more candidate root cause faults cause the one or more processors to determine whether the one or more candidate root cause faults are within the relevant portion of the causality map.
13. The computing system of claim 11,
wherein the processing circuitry is further configured to, in response to determining the one or more anomalies and prior to determining the causality graph, prune the knowledge graph to remove first nodes that are more than a threshold distance away from the first nodes of the knowledge graph that are associated with the one or more anomalies, and wherein the processing circuitry is configured to determine the causality graph based on the pruned knowledge graph.
9. The system of claim 1, wherein the instructions further cause the one or more processors to: receive an intent as a data structure; and determine the causality map based on the intent.
11. determining, by the analysis framework system in response to detecting the one or more anomalies, and based on the knowledge graph and a machine learning (ML) model trained with previous time series data, a causality graph,
10. The system of claim 9, wherein the data structure comprises a graph model.
11. determining, by the analysis framework system in response to detecting the one or more anomalies, and based on the knowledge graph and a machine learning (ML) model trained with previous time series data, a causality graph,
14. A method comprising:
determining, by one or more processors and based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
determining, by the one or more processors and based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes,
and outputting, by the one or more processors, an indication of the one or more candidate root cause faults.
1. A method comprising:
receiving, by an analysis framework system from devices of a network system, time series data comprising measurements of one or more performance indicators;
determining, by the analysis framework system and based on the time series data, one or more anomalies in a performance of the network system;
creating, based on the time series data, a knowledge graph comprising first nodes in the network system referenced in the time series, the first nodes representing elements residing at one or more of a plurality of network service layers associated with the network system;
determining, by the analysis framework system in response to detecting the one or more anomalies, and based on the knowledge graph and a machine learning (ML) model trained with previous time series data, a causality graph, wherein the causality graph includes second nodes associated with the performance indicators, wherein edges between the first nodes and the second nodes indicate relationships between the first nodes and the second nodes, and wherein the knowledge graph and the causality graph each includes edges between one or more of the first nodes and one or more of the second nodes that are associated with elements residing at different network service layers of the plurality of network service layers;
determining a weighting for each of the edges in the causality graph;
determining, based on the edges in the causality graph, one or more candidate root causes associated with the one or more anomalies;
determining a ranking of the one or more candidate root causes based on the weighting of the edges in the causality graph;
and outputting at least a portion of the ranking.
20. Non-transitory computer-readable storage media having stored thereon instructions that, when executed, cause one or more processors to:
determine, based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes;
determine, based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes,
20. Non-transitory computer-readable storage media having instructions stored thereon that, when executed, cause one or more processors to execute a framework analysis system, wherein the framework analysis system is configured to:
receive, from one or more devices of a network system, time series data comprising measurements of one or more performance indicators;
determine, based on the time series data, one or more anomalies in a performance of the network system;
create, based on the time series data, a knowledge graph comprising first nodes in the network system referenced in the time series, the first nodes representing elements residing at one or more of a plurality of network service layers associated with the network system;
determine, in response to detecting the one or more anomalies, and based on the knowledge graph and a machine learning (ML) model trained with previous time series data, a causality graph, wherein the causality graph includes second nodes associated with the performance indicators, wherein edges between the first nodes and the second nodes indicate relationships between the first nodes and the second nodes, and wherein the knowledge graph and the causality graph each includes edges between one or more of the first nodes and one or more of the second nodes that are associated with elements residing at different network service layers of the plurality of network service layers;
determine a weighting for each of the edges in the causality graph;
determine, based on the edges in the causality graph, one or more candidate root causes associated with the one or more anomalies;
determine a ranking of the one or more candidate root causes based on the weighting of the edges in the causality graph;
and output at least a portion of the ranking.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 3-10, 14, 16-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over US PGPub 2017/0230229 Al (Sasturkar) in view of provisional 63/269,807 of US 2023/0095270 A1 (Garapati) priority date 08/20/2021.
Regarding Claim 1:
Sasturkar teaches A system ([0061] A system including Assembly Engine 105, Detection Engine 135, Correlation Engine 112) comprising: memory; and one or more processors having access to the memory, ([0061] a system including memory and one or more processors operable to execute instructions, stored in the memory, to perform any of the methods described above.) wherein the memory stores instructions that, when executed, cause the one or more processors to:
determine, based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, (Fig 3A, Anomaly Impact Graph. [0062]-[0064] Anomaly impact graph 300 shows a progression over time of the cascading failures for the connected node pairs to identify one or more root causes of the cascading failures. [0174]-[0177] At action 910, performance data is assembled for a multiplicity of metrics across a multiplicity of resources on a network. At action 920, the anomalous instance data are grouped into an anomaly cluster including anomaly nodes that represent detected anomalies that compromise respective resources and represent probability weighted directed edges connecting correlated anomaly nodes. At action 940, the scoring is repeated for a plurality of anomaly clusters.)
and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes; ([0064] FIGS. 3A-3D show an anomaly impact graph interface 300 that depicts a cluster of operation anomalies that are interrelated as cascading failures. The cluster of operation anomalies that are interrelated as cascading failures are depicted as nodes 302, and anomaly impact graph 300 shows a progression over time of the cascading failures for the connected node pairs to identify one or more root causes of the cascading failures.)
determine, based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes, ([0132]-[0134] Action 620, a map of active network communication paths that carry communications among resources subject to anomalous performances is constructed. Also, the active network communication paths are represented as edges between nodes representing anomalous instance data for the resources. [0136] Action 640, human feedback is received from one or more users on the calculated impact rankings for the nodes representing anomalous instance data for the resources. New impact rankings are calculated for the nodes based on the received human feedback.)
and output an indication of the one or more candidate root cause faults. ([0063] FIGS. 3A-3D illustrate one implementation of an anomaly impact graph 300 that depicts a map of active network communication paths that carry communications among resources subject to anomalous performances. In particular, FIGS. 3A-3D show an anomaly impact graph interface 300 that depicts a cluster of operation anomalies that are interrelated as cascading failures. Anomaly impact graph interface 300 can be used to illustrate to a network administrator causes of system failure.)
Sasturkar teaches determining root causes ([0063]). However, Sasturkar is silent on wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults.
Garapati teaches, in the same field of endeavor, on techniques used to enable automated remediation efforts once a root cause event is identified, Abstract.
Garapati teaches wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults. (FIGS 15-16, 20 [00221] a maximum number of causal relationships (connections, edges) Cx may be set. Candidate causal relationships CC and final causal relationships FC may be defined. [00226] Then, candidate causal relationships CC in lower layers, from Le to Lo, may be determined by searching a number Mx of closest causal events. These candidate causal relationships may be pruned by removing farther/weaker relationships as closer/stronger relationships are found, so that Cx is maintained for each event (2010). [00227] Final causal relationships FC may be determined from the candidate causal relationships CC, by selecting longer-range, higher-layer edges over any redundant, subsumed shorter-range, lower-layer edges (2012).) By selecting higher-layer, the final casual relationships are less than the candidate casual relationships.
It would have been obvious to a person having ordinary skill in the art before the effective filing date, to modify Sasturkar per Garapati to include wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults. This would have been advantageous as discussed above, as it would allow the modified system to provide a more targeted root cause, allowing for quicker remediation of faults.
Regarding Claim 14:
Sasturkar teaches A method comprising:
determining, by one or more processors ([0061] a system including memory and one or more processors operable to execute instructions, stored in the memory, to perform any of the methods described above.) and based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, (Fig 3A, Anomaly Impact Graph. [0062]-[0064] Anomaly impact graph 300 shows a progression over time of the cascading failures for the connected node pairs to identify one or more root causes of the cascading failures. [0174]-[0177] At action 910, performance data is assembled for a multiplicity of metrics across a multiplicity of resources on a network. At action 920, the anomalous instance data are grouped into an anomaly cluster including anomaly nodes that represent detected anomalies that compromise respective resources and represent probability weighted directed edges connecting correlated anomaly nodes. At action 940, the scoring is repeated for a plurality of anomaly clusters.)
and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes; ([0132]-[0134] Action 620, a map of active network communication paths that carry communications among resources subject to anomalous performances is constructed. Also, the active network communication paths are represented as edges between nodes representing anomalous instance data for the resources. [0136] Action 640, human feedback is received from one or more users on the calculated impact rankings for the nodes representing anomalous instance data for the resources. New impact rankings are calculated for the nodes based on the received human feedback.)
determining, by the one or more processors and based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes, ([0132]-[0134] Action 620, a map of active network communication paths that carry communications among resources subject to anomalous performances is constructed. Also, the active network communication paths are represented as edges between nodes representing anomalous instance data for the resources. [0136] Action 640, human feedback is received from one or more users on the calculated impact rankings for the nodes representing anomalous instance data for the resources. New impact rankings are calculated for the nodes based on the received human feedback.)
and outputting, by the one or more processors, an indication of the one or more candidate root cause faults. ([0063] FIGS. 3A-3D illustrate one implementation of an anomaly impact graph 300 that depicts a map of active network communication paths that carry communications among resources subject to anomalous performances. In particular, FIGS. 3A-3D show an anomaly impact graph interface 300 that depicts a cluster of operation anomalies that are interrelated as cascading failures. Anomaly impact graph interface 300 can be used to illustrate to a network administrator causes of system failure.)
Sasturkar teaches determining root causes ([0063]). However, Sasturkar is silent on wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults.
Garapati teaches, in the same field of endeavor, on techniques used to enable automated remediation efforts once a root cause event is identified, Abstract.
Garapati teaches wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults. (FIGS 15-16, 20 [00221] a maximum number of causal relationships (connections, edges) Cx may be set. Candidate causal relationships CC and final causal relationships FC may be defined. [00226] Then, candidate causal relationships CC in lower layers, from Le to Lo, may be determined by searching a number Mx of closest causal events. These candidate causal relationships may be pruned by removing farther/weaker relationships as closer/stronger relationships are found, so that Cx is maintained for each event (2010). [00227] Final causal relationships FC may be determined from the candidate causal relationships CC, by selecting longer-range, higher-layer edges over any redundant, subsumed shorter-range, lower-layer edges (2012).) By selecting higher-layer, the final casual relationships are less than the candidate casual relationships.
It would have been obvious to a person having ordinary skill in the art before the effective filing date, to modify Sasturkar per Garapati to include wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults. This would have been advantageous as discussed above, as it would allow the modified system to provide a more targeted root cause, allowing for quicker remediation of faults.
Regarding Claim 20:
Sasturkar teaches on a Non-transitory computer-readable storage media having stored thereon instructions that, when executed, cause one or more processors ([0061] a system including memory and one or more processors operable to execute instructions, stored in the memory, to perform any of the methods described above.) to:
determine, based on a network service impact, a relevant portion of a causality map that is less than the causality map, wherein the causality map comprises a first plurality of nodes that each represent a respective root cause fault associated with a plurality of network devices, a second plurality of nodes that each represent a respective symptom, and a third plurality of nodes that each represent a respective network service impact associated with the plurality of network devices, (Fig 3A, Anomaly Impact Graph. [0062]-[0064] Anomaly impact graph 300 shows a progression over time of the cascading failures for the connected node pairs to identify one or more root causes of the cascading failures. [0174]-[0177] At action 910, performance data is assembled for a multiplicity of metrics across a multiplicity of resources on a network. At action 920, the anomalous instance data are grouped into an anomaly cluster including anomaly nodes that represent detected anomalies that compromise respective resources and represent probability weighted directed edges connecting correlated anomaly nodes. At action 940, the scoring is repeated for a plurality of anomaly clusters.)
and wherein each node of the third plurality of nodes comprises one or more first edges to one or more nodes in the second plurality of nodes, and each node of the second plurality of nodes comprises one or more second edges to one or more nodes of the first plurality of nodes; ([0132]-[0134] Action 620, a map of active network communication paths that carry communications among resources subject to anomalous performances is constructed. Also, the active network communication paths are represented as edges between nodes representing anomalous instance data for the resources. [0136] Action 640, human feedback is received from one or more users on the calculated impact rankings for the nodes representing anomalous instance data for the resources. New impact rankings are calculated for the nodes based on the received human feedback.)
determine, based on the relevant portion of the causality map, one or more candidate root cause faults from a plurality of root cause faults represented by the first plurality of nodes, ([0132]-[0134] Action 620, a map of active network communication paths that carry communications among resources subject to anomalous performances is constructed. Also, the active network communication paths are represented as edges between nodes representing anomalous instance data for the resources. [0136] Action 640, human feedback is received from one or more users on the calculated impact rankings for the nodes representing anomalous instance data for the resources. New impact rankings are calculated for the nodes based on the received human feedback.)
and output an indication of the one or more candidate root cause faults. ([0063] FIGS. 3A-3D illustrate one implementation of an anomaly impact graph 300 that depicts a map of active network communication paths that carry communications among resources subject to anomalous performances. In particular, FIGS. 3A-3D show an anomaly impact graph interface 300 that depicts a cluster of operation anomalies that are interrelated as cascading failures. Anomaly impact graph interface 300 can be used to illustrate to a network administrator causes of system failure.)
Sasturkar teaches determining root causes ([0063]). However, Sasturkar is silent on wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults.
Garapati teaches, in the same field of endeavor, on techniques used to enable automated remediation efforts once a root cause event is identified, Abstract.
Garapati teaches wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults. (FIGS 15-16, 20 [00221] a maximum number of causal relationships (connections, edges) Cx may be set. Candidate causal relationships CC and final causal relationships FC may be defined. [00226] Then, candidate causal relationships CC in lower layers, from Le to Lo, may be determined by searching a number Mx of closest causal events. These candidate causal relationships may be pruned by removing farther/weaker relationships as closer/stronger relationships are found, so that Cx is maintained for each event (2010). [00227] Final causal relationships FC may be determined from the candidate causal relationships CC, by selecting longer-range, higher-layer edges over any redundant, subsumed shorter-range, lower-layer edges (2012).) By selecting higher-layer, the final casual relationships are less than the candidate casual relationships.
It would have been obvious to a person having ordinary skill in the art before the effective filing date, to modify Sasturkar per Garapati to include wherein the plurality of root cause faults comprises at least one root cause fault not included in the one or more candidate root cause faults. This would have been advantageous as discussed above, as it would allow the modified system to provide a more targeted root cause, allowing for quicker remediation of faults.
Regarding Claims 3, 16:
Sasturkar (as modified by Garapati) teaches the inventions of claims 1, 14 as described.
Sasturkar teaches wherein the instructions to determine the relevant portion of the causality map cause the one or more processors to match the network service impact to one of the nodes in the third set of nodes and identify at least one node in the first set of nodes using the one or more first edges and the one or more second edges. ([0064] FIGS. 3A-3D show an anomaly impact graph interface 300 that depicts a cluster of operation anomalies that are interrelated as cascading failures. A user can select one or more edges that the user desires to inspect. In such an implementation, inspected edges can be brighten, highlighted, or bolded like edges 304n while unselected edges are dimmed or greyed like edges 306n.)
Regarding Claims 4, 17:
Sasturkar (as modified by Garapati) teaches the inventions of claims 1, 14 as described.
Sasturkar teaches wherein the instructions further cause the one or more processors to suppress a set of alerts using the one or more candidate root cause faults. ([0024] The technology disclosed allows for ranking of detected anomalies or anomaly clusters that enables network operators to focus on most critical true positives and not be distracted by false alarms. Using the technology disclosed, the large number of alerts raised in large data centers can be efficiently ranked to help the network operators and monitoring tools to filter out false positives and direct management resources to the most critical problems in the network.)
Regarding Claims 5, 18:
Sasturkar (as modified by Garapati) teaches the inventions of claims 1, 14 as described.
Sasturkar teaches wherein the instructions to determine the one or more candidate root cause faults cause the one or more processors to determine whether the one or more candidate root cause faults are within the relevant portion of the causality map. ([0050] Some other implementations include graphics engine 125 generating for display a "heat map" that illustrates anomaly-intensity at the impacted resources and the directionality of anomalous performances from source resources to target resources. [0064] Fig 3A-D, The cluster of operation anomalies that are interrelated as cascading failures are depicted as nodes 302, and anomaly impact graph 300 shows a progression over time of the cascading failures for the connected node pairs to identify one or more root causes of the cascading failures.)
Regarding Claims 6, 19:
Sasturkar (as modified by Garapati) teaches the inventions of claims 1, 14 as described.
Sasturkar teaches wherein the instructions to output the indication of the one or more candidate root cause faults cause the one or more processors to output an alert to a network administrator. ([0026] Proactive notification of potential bottlenecks in the network. Timely and accurate bottleneck anomaly detection along with effective notification can lead to quicker resolution of network faults. [0200] Portal 1000 depicting a notification summary 1004 of the detected anomaly clusters and an overall status of the system or the network 1002.)
Regarding Claim 7:
Sasturkar (as modified by Garapati) teaches the invention of claim 1 as described.
Sasturkar teaches wherein the instructions to receive the indication of the network service impact cause the one or more processors to receive a support ticket for a customer. ([0044] Some other implementations include correlation engine 112 identifying anomaly dependency data based on at least explicit and/or implicit user feedback on whether anomalies are correlated and/or user behavior observations, which are stored in user feedback data store 122.)
Regarding Claim 8:
Sasturkar (as modified by Garapati) teaches the invention of claim 1 as described.
Sasturkar teaches wherein the plurality of network devices are arranged in a topology comprising one or more of a 3-stage Clos network topology, a 5-stage Clos network topology, or a spine and leaf topology, and wherein the instructions cause the one or more processors to determine the causality map based on the topology. ([0040] Correlation engine 112 organizes anomalies in anomaly clusters into anomaly dependency data. Correlation engine 112 correlates anomalies based on physical and/or logical topology of resources (wireless devices, switches, routers, firewalls, servers, databases) in the network. Logical topology represents active communication paths of data flow among the resources in the network. Logical network topologies include point-to-point, bus, ring, star, tree, mesh, daisy chain, or hybrid.)
Regarding Claim 9:
Sasturkar (as modified by Garapati) teaches the invention of claim 1 as described.
Sasturkar teaches wherein the instructions further cause the one or more processors to: receive an intent as a data structure; and determine the causality map based on the intent. ([0064] nodes 302n are proximate in time and connected by edges 304n that represent cascading failure result links. In yet another implementation, a user can select one or more edges that the user desires to inspect. Inspected edges can be brighten, highlighted, or bolded like edges 304n while unselected edges are dimmed or greyed like edges 306n. [0178] implementations such as cluster ranking environment, cluster prioritizing algorithms, user feedback interface, or anomaly data structures.)
Regarding Claim 10:
Sasturkar (as modified by Garapati) teaches the invention of claim 9 as described.
Sasturkar teaches wherein the data structure comprises a graph model. (Fig 3A, Anomaly Impact Graph. [0062]-[0064] Anomaly impact graph 300 shows a progression over time of the cascading failures for the connected node pairs to identify one or more root causes of the cascading failures. [0178] implementations such as cluster ranking environment, cluster prioritizing algorithms, user feedback interface, or anomaly data structures.)
Claim(s) 2, 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over US PGPub 2017/0230229 Al (Sasturkar) in view of provisional 63/269,807 of US 2023/0095270 A1 (Garapati) priority date 08/20/2021 further in view of EP 2666088 B1 (Haines).
Regarding Claims 2, 15:
Sasturkar (as modified by Garapati) teaches the inventions of claims 1, 14 as described.
Sasturkar teaches on a correlation engine using the network topology information to identify the spatial relationship among the HTTP servers, the on-demand databases, and the HTTP request distributors ([0041]). However, Sasturkar (as modified by Garapati) is silent on wherein the instructions further cause the one or more processors to: determine a mapping of a serial number for a networking device of the plurality of network devices to a unique model identifier for the causality map, wherein the instructions cause the one or more processors to determine the causality map further based on the mapping of the serial number to the unique model identifier.
Haines teaches, in the same field of endeavor, methods for utilizing software that interacts with hardware for reporting errors encountered by the hardware, [0001].
Haines also teaches wherein the instructions further cause the one or more processors to: determine a mapping of a serial number for a networking device of the plurality of network devices to a unique model identifier for the causality map, ([0034] Errors often result in a related chain of errors. To facilitate association of errors within the same chain, some embodiments utilize an error model where each error includes multiple attributes. A first attribute can include a unique serial number associated with this particular error. A second attribute can include the serial number that identifies a parent error.)
wherein the instructions cause the one or more processors to determine the causality map further based on the mapping of the serial number to the unique model identifier. ([0037] FIG. 1 B shows an exemplary error 125, including the attributes used to identify the current instance ID 127, which refers to the unique serial number of "homing failed" error 125, and the parent instance ID 117, which refers to the instance ID of the "in motion mismatch" error 115. Parent instance ID 117 could include a pointer to the in motion mismatch error 115 object or a serial number identifying that error.)
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, to modify Sasturkar (as modified by Garapati) by modifying Sasturkar per Haines to include wherein the instructions further cause the one or more processors to: determine a mapping of a serial number for a networking device of the plurality of network devices to a unique model identifier for the causality map, wherein the instructions cause the one or more processors to determine the causality map further based on the mapping of the serial number to the unique model identifier. This would have been advantageous as discussed above, as it would allow the combined system to more easily associate multiple errors with a common cause and propagate information between related errors, see Haines, [0031].
Claim(s) 11-13 is/are rejected under 35 U.S.C. 103 as being unpatentable over US PGPub 2017/0230229 Al (Sasturkar) in view of provisional 63/269,807 of US 2023/0095270 A1 (Garapati) priority date 08/20/2021 further in view of US PGPub 2019/0229937 A1 (Nagarajan).
Regarding Claim 11:
Sasturkar (as modified by Garapati) teaches the invention of claim 1 as described.
Sasturkar teaches on plurality of nodes of different levels relating to behaviors of network devices ([0064]). However, Sasturkar (as modified by Garapati) is silent on wherein the first plurality of nodes comprises a first node corresponding to a Border Gateway Protocol (BGP) session for an external router being misconfigured; wherein the second plurality of nodes comprises a second set of nodes corresponding to one or more of BGP session operational status of the external router being down or the external router missing a non-default route to an external Ethernet Virtual Private Network (EVPN) gateway; and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of missing routes in an EVPN flood list routes for the external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted.
Nagarajan teaches, in the same field of endeavor, on connectivity of nodes in a EVPN environment, Abstract.
Nagarajan also teaches wherein the first plurality of nodes comprises a first node corresponding to a Border Gateway Protocol (BGP) session for an external router being misconfigured; ([0086] In the event of a network failure such as a PE device 100 to CE 8 link 15B failure; a failure of any of the PE devices; or an MPLS-reachability or other type of tunneling failure between any of the PE devices; EVPN module 148 coordinates with the other PE devices to ensure that the PE devices continue to operate in an active-active redundancy mode)
wherein the second plurality of nodes comprises a second set of nodes corresponding to one or more of BGP session operational status of the external router being down or the external router missing a non-default route to an external Ethernet Virtual Private Network (EVPN) gateway; ([0086] EVPN module 148 coordinates with the other PE devices to ensure that the PE devices continue to operate in an active-active redundancy mode, and rapidly converge to a state of having the same topological information about the network in which the PEs operate (i.e., network convergence).)
and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of missing routes in an EVPN flood list routes for the external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted. ([0086] EVPN module 148 additionally manages the EVPN multi-homing mode of operation for PE device 100. That is, EVPN module 148 operates to maintain EVPN service and traffic forwarding to and from CEs multi-homed to PE device 100 and one or more other PE devices. For example, in the event of a network failure such as a PE device 100 to CE 8 link 15B failure.)
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, to modify Sasturkar (as modified by Garapati) by modifying Sasturkar per Nagarajan to include wherein the first plurality of nodes comprises a first node corresponding to a Border Gateway Protocol (BGP) session for an external router being misconfigured; wherein the second plurality of nodes comprises a second set of nodes corresponding to one or more of BGP session operational status of the external router being down or the external router missing a non-default route to an external Ethernet Virtual Private Network (EVPN) gateway; and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of missing routes in an EVPN flood list routes for the external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted. This would have been advantageous as discussed above, as it would allow the combined system to provide a hierarchical method of determining root cause which allows for quick recovery of connectivity in case of PE and/or link failure.
Regarding Claim 12:
Sasturkar (as modified by Garapati) teaches the invention of claim 1 as described.
Sasturkar teaches on plurality of nodes of different levels relating to behaviors of network devices ([0064]). However, Sasturkar (as modified by Garapati) is silent on wherein the first plurality of nodes comprises a first node corresponding to a border leaf Border Gateway Protocol (BGP) routing policy being misconfigured; wherein the second plurality of nodes comprises a second set of nodes corresponding to a border leaf BGP of a leaf running a configuration that prevents learning of a non-default state; and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of a BGP session operational status of the leaf being down, missing non-default routes, missing routes in an Ethernet Virtual Private Network (EVPN) flood list routes for the external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted.
Nagarajan teaches wherein the first plurality of nodes comprises a first node corresponding to a border leaf Border Gateway Protocol (BGP) routing policy being misconfigured; ([0091][0092] The configuration data may further specify an interface-level policy directing the PE device 100 to accept a PIM Join message received on the interface only if the source of the PIM Join message is one of the list of acceptable sources. [0086] MPLS-reachability or other type of tunneling failure between any of the PE devices.)
wherein the second plurality of nodes comprises a second set of nodes corresponding to a border leaf BGP of a leaf running a configuration that prevents learning of a non-default state; ([0092] PE device 100 may consequently avoid accepting Join messages from other PE devices 10 participating in the EVI 3 or other non-specified routers on the L2 network, e.g., VLAN 11A.)
and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of a BGP session operational status of the leaf being down, missing non-default routes, missing routes in an Ethernet Virtual Private Network (EVPN) flood list routes for the external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted. ([0086] EVPN module 148 additionally manages the EVPN multi-homing mode of operation for PE device 100. That is, EVPN module 148 operates to maintain EVPN service and traffic forwarding to and from CEs multi-homed to PE device 100 and one or more other PE devices. For example, in the event of a network failure such as a PE device 100 to CE 8 link 15B failure.)
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, to modify Sasturkar (as modified by Garapati) by modifying Sasturkar per Nagarajan to include wherein the first plurality of nodes comprises a first node corresponding to a border leaf Border Gateway Protocol (BGP) routing policy being misconfigured; wherein the second plurality of nodes comprises a second set of nodes corresponding to a border leaf BGP of a leaf running a configuration that prevents learning of a non-default state; and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of a BGP session operational status of the leaf being down, missing non-default routes, missing routes in an Ethernet Virtual Private Network (EVPN) flood list routes for the external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted. This would have been advantageous as discussed above, as it would allow the combined system to provide a hierarchical method of determining root cause which allows for quick recovery of connectivity in case of PE and/or link failure.
Regarding Claim 13:
Sasturkar (as modified by Garapati) teaches the invention of claim 1 as described.
Sasturkar teaches on plurality of nodes of different levels relating to behaviors of network devices ([0064]). However, Sasturkar (as modified by Garapati) is silent on wherein the first plurality of nodes comprises a first node corresponding to a broken path to external Ethernet Virtual Private Network (EVPN) gateway for a Border Gateway Protocol (BGP) session; wherein the second plurality of nodes comprises a second set of nodes corresponding to one or more of a BGP session state for the BGP peer session changing only between a connect state, an active state, and an active state, or a Transmission Control Protocol (TCP) socked state for peer devices of the BGP session corresponding to waiting for an acknowledgement to a connection request; and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of missing routes in an EVPN flood list routes for an external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted.
Nagarajan teaches wherein the first plurality of nodes comprises a first node corresponding to a broken path to external Ethernet Virtual Private Network (EVPN) gateway for a Border Gateway Protocol (BGP) session; ([0091][0092] The configuration data may further specify an interface-level policy directing the PE device 100 to accept a PIM Join message received on the interface only if the source of the PIM Join message is one of the list of acceptable sources. [0086] MPLS-reachability or other type of tunneling failure between any of the PE devices.)
wherein the second plurality of nodes comprises a second set of nodes corresponding to one or more of a BGP session state for the BGP peer session changing only between a connect state, an active state, and an active state, or a Transmission Control Protocol (TCP) socked state for peer devices of the BGP session corresponding to waiting for an acknowledgement to a connection request; ([0086] EVPN module 148 coordinates with the other PE devices to ensure that the PE devices continue to operate in an active-active redundancy mode, and rapidly converge to a state of having the same topological information about the network in which the PEs operate (i.e., network convergence).)
and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of missing routes in an EVPN flood list routes for an external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted. ([0086] EVPN module 148 additionally manages the EVPN multi-homing mode of operation for PE device 100. That is, EVPN module 148 operates to maintain EVPN service and traffic forwarding to and from CEs multi-homed to PE device 100 and one or more other PE devices. For example, in the event of a network failure such as a PE device 100 to CE 8 link 15B failure.)
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, to modify Sasturkar (as modified by Garapati) by modifying Sasturkar per Nagarajan to include wherein the first plurality of nodes comprises a first node corresponding to a broken path to external Ethernet Virtual Private Network (EVPN) gateway for a Border Gateway Protocol (BGP) session; wherein the second plurality of nodes comprises a second set of nodes corresponding to one or more of a BGP session state for the BGP peer session changing only between a connect state, an active state, and an active state, or a Transmission Control Protocol (TCP) socked state for peer devices of the BGP session corresponding to waiting for an acknowledgement to a connection request; and wherein the third plurality of nodes comprises a third set of nodes corresponding to one or more of missing routes in an EVPN flood list routes for an external router, missing routes in EVPN prefix routes for the external router, switched traffic for the external router being disrupted, or routed traffic for the external router being disrupted. This would have been advantageous as discussed above, as it would allow the combined system to provide quick recovery of connectivity in case of PE and/or link failure by providing for changing between states of the PE devices as required.
Conclusion & Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to RACHEL J HACKENBERG whose telephone number is (571)272-5417. The examiner can normally be reached 9am-5pm M-F.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Glenton B Burgess can be reached at (571)272-3949. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/RACHEL J HACKENBERG/Primary Examiner, Art Unit 2454