Detailed Action
The office action is in response to the communication dated on February 14, 2025.
Claims 1-20 are submitted for examination.
Claims 1-20 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Oath/Declaration
Applicant’s oath/declaration filed on February 14, 2025 has been reviewed by the examiner and is found to conform to the requirements prescribed in 37 C.F.R. 1.63.
Drawings
The drawings submitted on February 14, 2025 with the instant application are acceptable for examination purposes.
Specification
The specification submitted on February 14, 2025 with the instant application are acceptable for examination purposes.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-6, 8-13, and 15-20 are rejected under 35 U.S.C. 103 as being unpatentable over Beckwith (US 7474618 B2) in view of Castinado (US 20230199027 A1).
Regarding Claim 1:
Beckwith teaches a system comprising (Beckwith – [Col. 5, lines 39-41]: FIG. 1 shows a block diagram of an exemplary system that advantageously uses the PCS. The system comprises a node 1, which communicates with node 2 across a network):
a processing device (Beckwith – [Col. 5, lines 65-67 – Col. 6, line 1]: Each node 1 or 2 in FIG. 1 includes a processor hardware base (not shown), such as one or more CPUs, microprocessors, embedded controllers, digital signal processors, etc, for executing codes, programs, and/or applications); and
a memory device including instructions that are executable by the processing device for causing the processing device to perform operations comprising (Beckwith – [Col. 5, lines 65-67 – Col. 6, line 1]: Each node 1 or 2 in FIG. 1 includes a processor hardware base (not shown), such as one or more CPUs, microprocessors, embedded controllers, digital signal processors, etc, for executing codes, programs, and/or applications; [Col. 6, lines 11-25]: Each node uses a load procedure to convert the software implementation and/or configuration data of a node into a useable form. The initial load function can take different forms, including: placement of the implementation or configuration information onto suitable media (e.g., CD, ROM or flash memory); or compilation of configuration data as part of the implementation … Initialization includes the boot function that brings each node's implementation code and data into its execution domain, for example, by reading it from disk, from ROM, or from flash memory into a memory space allocated for node functions and data):
determining, by the access control system, a risk profile related to the communication channel of the client device, the risk profile indicating a level of trustworthiness of the communication channel (Beckwith – [Col. 7, lines 21-33]: The SK uses a set of configuration data to establish partition definitions and allocation of resources to partitions. The SK configuration data provides the control information used by the node during initialization to define the secure initial state and its behavior during runtime; [Col. 9, lines 26-31]: Once the SK is initialized, a PCS control partition loads PCS configuration data, including the channel connectivity policy, the resource management policy, and the network description. The PCS ensure that violations of the channel connectivity policy or resource management policy do not occur due to detectable failures; [Col. 8, lines 14-27]: The channel connectivity policy describes the allowable connections between subjects. Essentially, this policy is an access control policy limiting which subjects may directly communicate via channels provided by the PCS. The resource management policy describes how the shared communications resources used to implement channels are to be allocated between channels and the extent to which channels may influence each other; [Col. 9, lines 43-56]: Before communicating data between subjects on separate nodes, the PCS ensures that the nodes participating in the communication have consistent configuration data … By verifying that all nodes have compatible configuration data before performing inter-node communications, inadvertent or malicious modification to the PCS configuration data is prevented; Examiner’s Note: the configuration data of the SK and the PCS’s teaches the claimed risk profile for ensuring the configuration of the communication channel is trustworthy),
providing, by the access control system, access by the client device to an isolated environment comprising the requested computing resource, the isolated environment configured based on the risk profile (Beckwith – [Col. 7, lines 21-33]: The SK uses a set of configuration data to establish partition definitions and allocation of resources to partitions. [Col. 7, lines 3-5]: The SK achieves isolation of subjects in different partitions such that each partition encompasses a resource set that appears to be entirely its own. This is known as virtualization; [Col. 9, lines 36-42]: The PCS domain comprises a number of partitions implementing the connectivity via channel endpoint (CE) partitions or subjects. A PCS configuration code and data partition is responsible for managing configuration data and bindings. The PCS configuration data defines bindings to CEs at either the subject or partition level, as supported by the underlying SK; [Col. 10, lines 7-8]: The SK also enables the PCS to control when a resource under its control is made available to subjects).
Beckwith does not expressly teach receiving, by an access control system, an access request from a client device via a communication channel of the client device, the access request indicating a requested computing resource to which the client device is requesting access.
However, Castinado teaches receiving, by an access control system, an access request from a client device via a communication channel of the client device, the access request indicating a requested computing resource to which the client device is requesting access (Castinado – Paragraph [0054]: As shown in block 202, the process flow includes receiving, from a first user input device, a request to access resources via a first communication channel; Paragraph [0044]: Any communication between the system 130 and the user input device 140 (or any other computing devices) may be subject to an authentication protocol allowing the system 130 to maintain security by permitting only authenticated users (or processes) to access the protected resources of the system 130).
It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to modify Beckwith, further incorporating Castinado to arrive at the claimed invention. One would be motivated to incorporate Castinado’s teachings into Beckwith’s invention to determine what configuration parameters are associated with various types of a communication channels and effectively choose the best mode to transfer sensitive data; see Castinado Paragraphs [0001-0005].
Regarding Claim 2:
The combination of Beckwith and Castinado teaches the system of claim 1.
Castinado further teaches wherein the operations further comprise:
detecting a change in the communication channel of the client device (Castinado – Paragraph [0029]: When a user input device attempts to access resources via a specific communication channel, the present invention initiates a network device configuration monitoring engine to determine whether the device configuration parameters of the user input device meets the configuration requirements of the communication channel to be authorized to access the resources. In instances where the requirements are not met, the present invention provides the functional benefit of triggering a channel switch engine to toggle between multiple available communication channels to determine particular communication channels whose configuration requirements are met by the user input device), wherein the change in the communication channel affects [the risk profile] of the communication channel (Castinado – Paragraph [0056]: the configuration requirements associated with the first communication channel further comprises at least one or more preset requirements (e.g., a status level) for one or more security controls—safeguards or countermeasures to avoid, detect, counteract, or minimize security exposure to the technology infrastructure associated with the first communication channel; Paragraph [0057]: in block 208, the process flow includes determining that the device configuration parameters associated with the first user input device does not meet the configuration requirements associated with the first communication channel; Paragraph [0059]: the process flow includes determining, using the channel switch engine, that the device configuration parameters associated with the first user input device meets configuration parameters associated with a second communication channel; Paragraph [0060]: the process flow includes authorizing the first user input device to access the resources via the second communication channel); and
modifying [the isolated environment] to adjust access by the client device to the requested computing resource (Castinado – Paragraph [0005]: receive, from a first user input device, a request to access resources via a first communication channel; determine, using a network device configuration monitoring engine, device configuration parameters associated with the first user input device; determine configuration requirements associated with the first communication channel; determine that the device configuration parameters associated with the first user input device does not meet the configuration requirements associated with the first communication channel; trigger a channel switch engine, in response to determining that the device configuration parameters associated with the first user input device does not meet the configuration requirements associated with the first communication channel; determine, using the channel switch engine, that the device configuration parameters associated with the first user input device meets configuration parameters associated with a second communication channel; and authorize the first user input device to access the resources via the second communication channel).
Beckwith further teaches … the risk profile … (Beckwith – [Col. 8, lines 39-59]: a PCS security policy (SP) that includes a channel connectivity policy and a resource management policy as set forth in a PCS configuration data … the security policy SP allows subject to communicate over a one-way PCS channel in resource group 1 with subject A and subject B. Likewise, the security policy allows subject A to communicate over a one-way PCS channel in resource group 2 with subject C and subject D … The use of resource groups enforces complete separation of communications resources from channels belonging to different groups. The PCS configuration data may also place restrictions on the interactions within the resource groups; [Col. 13, lines 7-9]: the PCS mediates use of shared resources to prevent resources used to implement one channel from influencing resources used to implement another channel; [Col. 7, lines 29-33]: The SK configuration data consists of SK flow policy configuration data and supporting policy configuration data, which define the information flow control and partition flow control policies for communication between and within partitions; [Col. 12, lines 6-9]: information flow control policy requires confidentiality of transmissions between nodes by cryptography or encryption to eliminates illicit information flows due to eavesdropping of message content by an agent; [Col. 9, lines 59-61]: For every channel, a sending CE performs mutual authentication with every receiving CE, and establishes a shared secret key with those endpoints; Examiner’s Note: The teaching from Beckwith, when in combination with Castinado, teaches “the change in the communication channel affects the risk profile of the communication channel” as Beckwith discloses that each channel is configured based on the SK and PCS’s configuration data such that one channel’s configuration does not influence another’s. Additionally, when Castinado’s second communication channel is used in place of the first communication channel, the risk profile governing the client device’s access to the requested resource changes from the first communication channel’s configuration data to the second communication channel’s configuration data); and
… isolated environment … (Beckwith – [Col. 7, lines 3-5]: The SK achieves isolation of subjects in different partitions such that each partition encompasses a resource set that appears to be entirely its own. This is known as virtualization; [Col. 9, lines 36-40]: The PCS domain comprises a number of partitions implementing the connectivity via channel endpoint (CE) partitions or subjects. A PCS configuration code and data partition is responsible for managing configuration data and bindings; [Col. 10, lines 7-8]: The SK also enables the PCS to control when a resource under its control is made available to subjects; [Col. 8, lines 44-57]: the security policy SP allows subject to communicate over a one-way PCS channel in resource group 1 with subject A and subject B. Likewise, the security policy allows subject A to communicate over a one-way PCS channel in resource group 2 with subject C and subject D … The use of resource groups enforces complete separation of communications resources from channels belonging to different groups; Examiner’s Note: The combination of Beckwith and Castinado teaches “modifying the isolated environment to adjust access by the client device to the requested computing resources” because Beckwith teaches partitioning resources and controlling access to the resources through allowed communication channels. When the channel switching occurs in Castinado, the switch modifies which partitioned resource the client is allowed to access based on the configuration parameters associated with each communication channel).
The motivation to combine the arts are the same as that in claim 1.
Regarding Claim 3:
The combination of Beckwith and Castinado teaches the system of claim 2.
Castinado further teaches wherein the change in the communication channel comprises switching from a first type of communication channel to a second type of communication channel having a different [risk profile] than the first type of communication channel (Castinado – Paragraph [0057]: in block 208, the process flow includes determining that the device configuration parameters associated with the first user input device does not meet the configuration requirements associated with the first communication channel; Paragraph [0059]: the process flow includes determining, using the channel switch engine, that the device configuration parameters associated with the first user input device meets configuration parameters associated with a second communication channel; Paragraph [0045]: Communication interface 158 may provide for communications under various modes or protocols, such as GSM voice calls, SMS, EMS, or MMS messaging, CDMA, TDMA, PDC, WCDMA, CDMA2000, or GPRS, among others. Such communication may occur, for example, through radio-frequency transceiver 160. In addition, short-range communication may occur, such as using a Bluetooth, Wi-Fi, or other such transceiver (not shown).).
Beckwith further teaches … risk profile … (Beckwith – [Col. 8, lines 39-57]: a PCS security policy (SP) that includes a channel connectivity policy and a resource management policy as set forth in a PCS configuration data … the security policy SP allows subject to communicate over a one-way PCS channel in resource group 1 with subject A and subject B. Likewise, the security policy allows subject A to communicate over a one-way PCS channel in resource group 2 with subject C and subject D … The use of resource groups enforces complete separation of communications resources from channels belonging to different groups; [Col. 13, lines 7-9]: the PCS mediates use of shared resources to prevent resources used to implement one channel from influencing resources used to implement another channel; [Col. 7, lines 29-33]: The SK configuration data consists of SK flow policy configuration data and supporting policy configuration data, which define the information flow control and partition flow control policies for communication between and within partitions; [Col. 12, lines 6-9]: information flow control policy requires confidentiality of transmissions between nodes by cryptography or encryption to eliminates illicit information flows due to eavesdropping of message content by an agent; [Col. 9, lines 59-61]: For every channel, a sending CE performs mutual authentication with every receiving CE, and establishes a shared secret key with those endpoints).
The motivation to combine the arts are the same as that in claim 2.
Regarding Claim 4:
The combination of Beckwith and Castinado teaches the system of claim 1.
Beckwith further teaches wherein the isolated environment comprises one or more nested environments that each comprise a respective set of computing resources (Beckwith – [Col. 7, lines 44-57]: FIG. 2 illustrates an exemplary embodiment of a node operating under the control of the SK … each node runs its own SK which protects resources unique to that node. As stated above, the SK divides all resources under its control into partitions such that the actions of an active entity, such as a subject, in one partition are isolated from and cannot be detected by or communicated to an active entity in another partition; [Col. 7, lines 63-66]: As shown, Partition A includes subjects 1 and 2 and resources 4-5, Partition B includes subject 3 and resources 6-7 and Partition C includes resources 9 and 10 and no subjects).
The motivation to combine the arts are the same as that in claim 1.
Regarding Claim 5:
The combination of Beckwith and Castinado teaches the system of claim 4.
Beckwith further teaches wherein the operations further comprise:
selecting, by the access control system and based on the risk profile of the communication channel, a particular nested environment of the one or more nested environments comprising the requested computing resource (Beckwith – [Col. 9, lines 36-42]: The PCS domain comprises a number of partitions implementing the connectivity via channel endpoint (CE) partitions or subjects. A PCS configuration code and data partition is responsible for managing configuration data and bindings. The PCS configuration data defines bindings to CEs at either the subject or partition level, as supported by the underlying SK; [Col. 9, lines 43-51]: Before communicating data between subjects on separate nodes, the PCS ensures that the nodes participating in the communication have consistent configuration data … All is needed on each node is a subset of the PCS configuration data that is sufficient for the node to determine that its configuration is consistent with the configurations of other nodes it is authorized to communicate with; [Col. 7, lines 64-67 – Col. 8, line 1]: Partition A includes subjects 1 and 2 and resources 4-5, Partition B includes subject 3 and resources 6-7 and Partition C includes resources 9 and 10 and no subjects. The arrows depict the SK flow policy for the node which is implemented by the SK configuration data; Examiner’s Note: As shown by the arrows in Fig. 2, Subject 2 can access resource 6 in Partition B indicating the claimed “particular nested environment”); and
providing, by the access control system and to the client device, access to the particular nested environment (Beckwith – [Col. 9, lines 43-45]: Before communicating data between subjects on separate nodes, the PCS ensures that the nodes participating in the communication have consistent configuration data; [Col. 7, lines 64-67 – Col. 8, line 1]: Partition A includes subjects 1 and 2 and resources 4-5, Partition B includes subject 3 and resources 6-7 and Partition C includes resources 9 and 10 and no subjects. The arrows depict the SK flow policy for the node which is implemented by the SK configuration data; [Col. 10, lines 7-8]: The SK also enables the PCS to control when a resource under its control is made available to subjects).
The motivation to combine the arts are the same as that in claim 4.
Regarding Claim 6:
The combination of Beckwith and Castinado teaches the system of claim 1.
Beckwith further teaches wherein the operations further comprise:
determining that the risk profile of the communication channel is compatible with a security requirement associated with the requested computing resource (Beckwith – [Col. 7, lines 21-22]: The SK uses a set of configuration data to establish partition definitions and allocation of resources to partitions; [Col. 9, lines 38-42]: A PCS configuration code and data partition is responsible for managing configuration data and bindings. The PCS configuration data defines bindings to CEs at either the subject or partition level, as supported by the underlying SK; [Col. 8, lines 39-59]: a PCS security policy (SP) that includes a channel connectivity policy and a resource management policy as set forth in a PCS configuration data … the security policy SP allows subject to communicate over a one-way PCS channel in resource group 1 with subject A and subject B. Likewise, the security policy allows subject A to communicate over a one-way PCS channel in resource group 2 with subject C and subject D … The use of resource groups enforces complete separation of communications resources from channels belonging to different groups. The PCS configuration data may also place restrictions on the interactions within the resource groups); and
in response to determining that the risk profile of the communication channel is compatible with the security requirement, providing access by the client device to the isolated environment comprising the requested computing resource (Beckwith – [Col. 9, lines 43-56]: Before communicating data between subjects on separate nodes, the PCS ensures that the nodes participating in the communication have consistent configuration data … By verifying that all nodes have compatible configuration data before performing inter-node communications, inadvertent or malicious modification to the PCS configuration data is prevented; [Col. 10, lines 7-8]: The SK also enables the PCS to control when a resource under its control is made available to subjects; [Col. 7, lines 3-4]: The SK achieves isolation of subjects in different partitions such that each partition encompasses a resource set that appears to be entirely its own).
The motivation to combine the arts are the same as that in claim 1.
Regarding Claim 8:
Claim 8 is a method claim that recites features that are similar to those of the system claim 1. Therefore, claim 8 is rejected with the same rationale and motivation as applied against claim 1 above.
Regarding Claim 9:
Rejection of claim 8 is incorporated. In addition, claim 9 recites features that are similar to those of claim 2. Therefore, claim 9 is rejected with the same rationale and motivation as applied against claim 2 above.
Regarding Claim 10:
Rejection of claim 8 is incorporated. In addition, claim 10 recites features that are similar to those of claim 3. Therefore, claim 10 is rejected with the same rationale and motivation as applied against claim 3 above.
Regarding Claim 11:
Rejection of claim 8 is incorporated. In addition, claim 11 recites features that are similar to those of claim 4. Therefore, claim 11 is rejected with the same rationale and motivation as applied against claim 4 above.
Regarding Claim 12:
Rejection of claim 8 is incorporated. In addition, claim 12 recites features that are similar to those of claim 5. Therefore, claim 12 is rejected with the same rationale and motivation as applied against claim 5 above.
Regarding Claim 13:
Rejection of claim 8 is incorporated. In addition, claim 13 recites features that are similar to those of claim 6. Therefore, claim 13 is rejected with the same rationale and motivation as applied against claim 6 above.
Regarding Claim 15:
Claim 15 is a non-transitory computer-readable medium claim that recites features that are similar to those of the system claim 1. Therefore, claim 15 is rejected with the same rationale and motivation as applied against claim 1 above. In addition, Castinado teaches a non-transitory computer-readable medium comprising program code executable by a processing device for causing the processing device to perform operations comprising (Castinado – Paragraph [0012]: a computer program product for dynamic communication channel switching based on preconfigured network security protocols, the computer program product comprising a non-transitory computer-readable medium comprising code causing a first apparatus to: …).
Regarding Claim 16:
Rejection of claim 15 is incorporated. In addition, claim 16 recites features that are similar to those of claim 2. Therefore, claim 16 is rejected with the same rationale and motivation as applied against claim 2 above.
Regarding Claim 17:
Rejection of claim 16 is incorporated. In addition, claim 17 recites features that are similar to those of claim 3. Therefore, claim 17 is rejected with the same rationale and motivation as applied against claim 3 above.
Regarding Claim 18:
Rejection of claim 15 is incorporated. In addition, claim 18 recites features that are similar to those of claim 4. Therefore, claim 18 is rejected with the same rationale and motivation as applied against claim 4 above.
Regarding Claim 19:
Rejection of claim 18 is incorporated. In addition, claim 19 recites features that are similar to those of claim 5. Therefore, claim 19 is rejected with the same rationale and motivation as applied against claim 5 above.
Regarding Claim 20:
Rejection of claim 15 is incorporated. In addition, claim 20 recites features that are similar to those of claim 6. Therefore, claim 20 is rejected with the same rationale and motivation as applied against claim 6 above.
Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Beckwith (US 7474618 B2) in view of Castinado (US 20230199027 A1), and in further view of Redcentric “VIRTUAL PRIVATE CLOUD: WHAT IS IT AND HOW DOES IT WORK?,” published December 8, 2022 hereby regarded to as Redcentric.
Regarding Claim 7:
The combination of Beckwith and Castinado teaches the system of claim 1.
Castinado further … the access control system (Castinado – Paragraph [0052]: the user input device 130 makes a service request to the system 130, the system 130 accepts the service request, processes the service request, and returns the requested information to the user input device 140; Paragraph [0036]: the system 130 may implement dynamic allocation and de-allocation of local memory resources among multiple computing devices in a parallel or distributed system).
The combination of Beckwith and Castinado do not teach wherein [the access control system] is part of a virtual private cloud.
However, Redcentric teaches wherein the access control system is part of a virtual private cloud (Redcentric – [Page 2, Section: “What are the benefits of a Virtual Private Cloud?”]: Since the virtual private cloud is an isolated network, user data and applications have exclusive access to resources … With an isolated cloud, a customer or organisation can completely control access to, and the use of, resources).
It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to modify the combination of Beckwith and Castinado, further incorporating Redcentric to arrive at the claimed invention. One would be motivated to incorporate Redcentric’s teachings into the combination of Beckwith and Castinado’s invention to improve security by using a virtual private cloud that provides an isolated network and controls which users may access computing resources; see Redcentric [Page 2-3, Section: “What are the benefits of a Virtual Private Cloud?”].
Regarding Claim 14:
Rejection of claim 8 is incorporated. In addition, claim 14 recites features that are similar to those of claim 7. Therefore, claim 14 is rejected with the same rationale and motivation as applied against claim 7 above.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure:
Lietz (US 20150128204 A1) teaches a system that analyzes data security policy data for determining which communication channel is the best mode to transfer sensitive information.
Bansal (US 20240146689 A1) teaches a system that derives a risk profile for a mobile device based network flow attributes
Patel (US 20250069013 A1) teaches a system that monitors communications over communication channels and uses an AI/ML scoring engine to generate a communication-specific risk score.
Wang (US 20200065498 A1) teaches a method for determining a channel risk value for deciding whether or not to transfer classified files.
Koganti (US 20170329966 A1) teaches a method monitoring for threats and determining, based on security policies, a trust score of the communication channel.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to NATHANIEL C SKIRVIN whose telephone number is (571)272-9798. The examiner can normally be reached Monday-Friday 8-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin Chin Shaw can be reached at (571) 272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/NATHANIEL CHRISTIAN SKIRVIN/Examiner, Art Unit 2498
/YIN CHEN SHAW/Supervisory Patent Examiner, Art Unit 2498