CTNF 19/079,100 CTNF 97891 DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-30-03-h AIA Claim Interpretation 07-30-03 AIA The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. 07-30-05 The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: “an interface device configured to receive…”; (Claim 1) “an interface device further configured to transmit…”; (Claim 2) “an interface device to connect to an intranet”; and “an interface device is further configured to transmit…”;(Claim 5) “an interface device configure to transmit…” and “an interface device configure to receive…”; (Claim 7). Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 112 07-30-02 AIA The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1, 5 and 7 are additionally rejected under this title because the claim limitation “an interface device” invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph and for failing to disclose the corresponding structure. The written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. It was unclear from the specification which particular hardware element or software algorithm detailed the functioning of the “an interface device”. Mere reference to a general purpose computer with appropriate programming without providing an explanation of the appropriate programming, or simply reciting "software" without providing detail about the means to accomplish a specific software function, would not be an adequate disclosure of the corresponding structure to satisfy the requirements of 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. Aristocrat, 521 F.3d at 1334, 86 USPQ2d at 1239; Finisar, 523 F.3d at 1340-41, 86 USPQ2d at 1623. In addition, merely referencing a specialized computer (e.g., a "bank computer"), some undefined component of a computer system (e.g., "access control manager"), "logic," "code," or elements that are essentially a black box designed to perform the recited function, will not be sufficient because there must be some explanation of how the computer or the computer component performs the claimed function. Blackboard, Inc. v. Desire2Learn, Inc., 574 F.3d 1371, 1383-85, 91 USPQ2d 1481, 1491-93 (Fed. Cir. 2009); Net MoneyIN, Inc. v. VeriSign, Inc., 545 F.3d 1359, 1366-67, 88 USPQ2d 1751, 1756-57 (Fed. Cir. 2008); Ex parte Rodriguez, 92 USPQ2d 1395, 1405-06 (Bd. Pat. App. & Inter. 2009). Therefore, the claim is indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. 07-34-23 Applicant may: (a) Amend the claim so that the claim limitation will no longer be interpreted as a limitation under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph; (b) Amend the written description of the specification such that it expressly recites what structure, material, or acts perform the entire claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (c) Amend the written description of the specification such that it clearly links the structure, material, or acts disclosed therein to the function recited in the claim, without introducing any new matter (35 U.S.C. 132(a)). If applicant is of the opinion that the written description of the specification already implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function, applicant should clarify the record by either: (a) Amending the written description of the specification such that it expressly recites the corresponding structure, material, or acts for performing the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (b) Stating on the record what the corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function. For more information, see 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181. Claims 2-4 and 6 are rejected, in addition to the rejections mentioned above for the individual claims, also in light of their dependency on claim 1 and claim 5 respectively and for not overcoming the grounds of rejection applied to claim 1 and claim 5. 07-30-01 AIA The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. 07-31-01 Claims 1, 5 and 7 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claims 2-4 and 6 are rejected, in addition to the rejections mentioned above for the individual claims, also in light of their dependency on claim 1 and claim 5 respectively and for not overcoming the grounds of rejection applied to claim 1 and claim 5. The “an interface device” in claims 1, 5 and 7 invokes 112(f), however the specification does not disclose adequate structure (or material or acts) for performing the recited function of the claimed “an interface device”. Thus, the specification fails to meet the description requirement of 112(a). Furthermore, Claim 4 is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claim 4 recites “the information processing apparatus to notify…the communication terminal of the presence or absence of the root certificate”. However, specification fails to provide explanation/description for how the information processing apparatus is notifying to the communication terminal? Specification fails to describing. How to notify…the communication terminal. It is unclear whether “a notify” means “a message”, “pop-up” or “error-page” or displaying window of “redirection error”. Additionally claim 4 recites “the interface device receives a notification of checking…from the communication terminal”. However, specification fails to explain how this notification id being received from the communication terminal. What is the form for notification to indicate that root certificate is present of absent. It is unclear whether “a notification” is “message”, “pop-up” or “error-page” or displaying window of “redirection error”. How a notification is received to check presence or absent of root certificate is need to be clear. Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim (s) 1-2, 5 and 7 are rejected under 35 U.S.C. 103 as being unpatentable over Krishna et al. (U. S. 2011/0320818 A1) (hereinafter “Krishna”) and further in view of Rakshit (U. S. Pat. No. 9,077,546 B1) (hereinafter “Rakshit”) . Regarding Claim 1, Krishna teaches: An information processing apparatus that provides a rendering result of a web page (Krishna: [0031] A user 501 starts the interaction by indicating to the browser 203 that the user desires to access a web page or to interact in some fashion with a webpage on the remote server 505, step 351) based on a request from a communication terminal connected to an intranet (Krishna: In response to the user's request, the browser 203 issues an http request message onto the remote web server 505), when the web page of the website on the intranet is rendered (Krishna: [0031] A user 501 starts the interaction by indicating to the browser 203 that the user desires to access a web page or to interact in some fashion with a webpage on the remote server 505, step 351. In response to the user's request, the browser 203 issues an http request message onto the remote web server 505, step 353. For the scenario contemplated herein, a web application is loaded into the browser 203. [0036], the URL of the web page being accessed), Krishna does not explicitly disclose: the information processing apparatus comprising: an interface device configured to receive a root certificate for a website on the intranet from the communication terminal; and a memory storing a program and a processor configured to, when executing the program, cause the information processing apparatus to perform, when the web page of the website on the intranet is rendered, verification of reliability of the website on the intranet with the root certificate. perform … verification of reliability of the website on the intranet with the root certificate However, in an analogous art, Rakshit disclose: the information processing apparatus comprising (Rakshit: [Col 1,lines 46-47], (7) Methods and apparatuses for authenticating a secure sockets layer certificate (SSL) certificate are described herein): an interface device configured to receive a root certificate for a website on the intranet from the communication terminal (Rakshit: [Col 3, lines 67 – Col 4, lines 1-4], The web browser 114 also receives site certificates, such as SSL certificates. The web browser 114 typically maintains or has access to a root certificate store that includes stored root certificates which identify known signers for particular certificates, [Col 7, lines 4-7], The processing logic then, at block 406, identifies the root certificate associated with the SSL certificate of the validation request); and a memory storing a program (Rakshit: [Col 8, lines 51-56], The instructions 526 may also reside, completely or at least partially, within the main memory 504 and/or within the processing device 502 during execution thereof by the computer system 500, the main memory 504 and the processing device 502 also constituting machine-readable storage media) and a processor configured to, when executing the program, cause the information processing apparatus to (Rakshit: [Col 8, lines 30-36], Processing device 502 may also be one or more special-purpose processing devices such as an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP), network processor, or the like. Processing device 502 is configured to execute the instructions 526 for performing the operations and steps discussed herein) perform … verification of reliability of the website on the intranet with the root certificate (Rakshit: [Col 6, lines 25-28], If the true root certificate authority matches the root certificate of the SSL certificate, then the SSL certificate is valid and the processing logic, at block 316, trusts the website). It would be obvious to a person having ordinary skill in the art, before the effective filing date of the invention, to modify Krishan’s method of starts the interaction by indicating to the browser 203 that the user desires to access a web page by sending http request message to the remote server by applying Rakshit’s method of comparing root certificate, in order to validate SSL certificate and determine that the requested site is trusted web site. The motivation is to prevent attacker from intercepting every detail of the communication and manipulate the data of the communication. This attack is often referred to as a "man-in-the-middle" attack [Col 1, lines 40-43]). Regarding Claim 2 , Krishna in view of Rakshit teaches: The information apparatus of claim 1 (see rejection of claim 1 above), with an error occurrence in the verification of the reliability of the web site when the web page of the website on the intranet is rendered (Rakshit: [Col 6, lines 46-55], In one embodiment, the processing logic notifies the user by presenting an alarm (=error occurrence). The alarm may be a visual pop-up or an audible alarm) , the interface device further configured to transmit…information about the error and a Uniform Resource Locator (URL) of the website with the error occurrence to the communication terminal (Rakshit: [Col 6, lines 46-55], (31) The processing logic, in one embodiment, transmits information including, but not limited to, website name, invalid intermediate or root certificate name, IP address of client device (for determining geolocation), IP address of the malicious website, etc. The security manager, as will be discussed below, may utilize this information to analyze the malicious attack. At block 314, the processing logic notifies a user of the malicious website….[Col 3, lines 7-11], the web browser presents an alarm (=error occurrence) to the user and sends details of such communication to the trusted certificate authority, the website owner, and the compromised certificate authority of the malicious certificate). It would be obvious to a person having ordinary skill in the art, before the effective filing date of the invention, to modify Krishan’s method of starts the interaction by indicating to the browser 203 that the user desires to access a web page by sending http request message to the remote server by applying Rakshit’s method of presenting an alarm to notifies a user of malicious website, in order prevent unsecure communication/connection. The motivation is to prevent attacker from intercepting every detail of the communication and manipulate the data of the communication. This attack is often referred to as a "man-in-the-middle" attack [Col 1, lines 40-43]). Regarding Claim 5, Krishna teaches: A communication terminal that requests an information processing apparatus for a rendering result of a web page the communication terminal comprising (Krishna: [0031] A user 501 starts the interaction by indicating to the browser 203 that the user desires to access a web page or to interact in some fashion with a webpage on the remote server 505, step 351) when the web page of the website on the intranet is rendered (Krishna: [0031] A user 501 starts the interaction by indicating to the browser 203 that the user desires to access a web page or to interact in some fashion with a webpage on the remote server 505, step 351. In response to the user's request, the browser 203 issues an http request message onto the remote web server 505, step 353. For the scenario contemplated herein, a web application is loaded into the browser 203) perform… acquire a Uniform Resource Locator (URL) for accessing the web page (Krishna: [0036], the URL of the web page being accessed,) Krishna does not explicitly disclose: an interface device configured to connect to an intranet; and a memory storing a program and a processor configured to, when executing the program, cause the communication terminal: acquire a Uniform Resource Locator (URL) for accessing the web page, and analyze, in a case where the URL is acquired, whether the URL is a URL of a website on an intranet and whether a dedicated root certificate is to be used for accessing the website, wherein the interface device is further configured to transmit the dedicated root certificate to the information processing apparatus in a case where the dedicated root certificate is used as a result of the analysis. However, Rakshit disclose: an interface device configured to connect to an intranet (Rakshit: [Col 6, lines 63-67], (33) Referring to FIG. 4, processing logic begins method 400 by receiving a validation request at block 402. In one embodiment, the processing logic receives a validation request by receiving a cryptographically signed validation request from a client device. In particular, the credential manager 106, via the web browser 114, may send a signed validation request. [Col 1, lines 50-51], transmitting, to a security manager, a validation request with the SSL certificate and a certificate in the chain of trust) ; and a memory storing a program (Rakshit: [Col 8, lines 51-56], The instructions 526 may also reside, completely or at least partially, within the main memory 504 and/or within the processing device 502 during execution thereof by the computer system 500, the main memory 504 and the processing device 502 also constituting machine-readable storage media) and a processor configured to, when executing the program, cause the communication terminal: to (Rakshit: [Col 8, lines 30-36], Processing device 502 may also be one or more special-purpose processing devices such as an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP), network processor, or the like. Processing device 502 is configured to execute the instructions 526 for performing the operations and steps discussed herein) and analyze, in a case where the URL is acquired, whether the URL is a URL of a website on an intranet (Rakshit: [Col 4, lines 64-67], (23) To combat this scenario, and other similar situations, the credential manager 106 is configured to verify the signing authority of a particular website. Using the example of above, the credential manager 106, before trusting an SSL certificate of BankXYZ.com, may communicate with a security manager 150) and whether a dedicated root certificate is to be used for accessing the website (Rakshit: [Col 5, lines 2-4], The security manager 150 interfaces with the CA database 142 to identify the legitimate certificate authority for any particular website (=dedicated root certificate for each website. [Col 6, lines 34-38], If the processing logic, after comparing certificate details with the details retrieved from the CA Database, finds that retrieved domain/website's exclusive identifier 208 is "Y" for the CA 140a (i.e., an indication that this website exclusively uses certificate from the trusted CA 140a) wherein the interface device is further configured to transmit the dedicated root certificate to the information processing apparatus in a case where the dedicated root certificate is used as a result of the analysis (Rakshit: [Col 6, lines 16-23], (29) At block 308, the processing logic receives a validation response from the security manager 150 of the trusted certificate authority 140….The processing logic determines (=analysis), at decision block 310, whether the SSL certificate is valid (=having dedicated root certificate) based on the response from the security manager 150. In one embodiment, the response from the security manager 150 contains an indication of the authentic or true root certificate authority for the SSL certificate. If the true root certificate authority matches the root certificate of the SSL certificate, then the SSL certificate is valid and the processing logic, at block 316, trusts the website. (Examiner’s Note: Validation response is getting transmitted to the processing logic wherein validation response contains authentic/true root certificate authority for SSL certificate In other words, it proves that if SSL certificate is valid it means that the website has its dedicated root certificate therefore the website is trusted a website) Regarding Claim 7, Krishna teaches: provide a rendering result of a web page (Krishna: [0031] A user 501 starts the interaction by indicating to the browser 203 that the user desires to access a web page or to interact in some fashion with a webpage on the remote server 505, step 351) based on a request from the communication terminal, wherein the communication terminal includes (Krishna: In response to the user's request, the browser 203 issues an http request message onto the remote web server 505): provides the communication terminal with a rendering result of the web page on the website on the intranet (Krishna: [0031] A user 501 starts the interaction by indicating to the browser 203 that the user desires to access a web page or to interact in some fashion with a webpage on the remote server 505, step 351). Krishna does not explicitly disclose: An information processing system comprising: a communication terminal connected to an intranet; and an information processing apparatus configured to a memory storing a program and a processor configured to, when executing the program, cause the information processing apparatus to perform, when the web page on the web site on the intranet is rendered, verification of reliability of the website on the intranet with the root certificate, and wherein the information processing apparatus accesses the website on the intranet in which the communication terminal is located However, in an analogous art, Rakshit teaches: An information processing system comprising (Rakshit: [Col 8, lines 12-13], (39) The exemplary computer system 500 includes a processing device 502): a communication terminal connected to an intranet (Rakshit: (38) FIG. 5 illustrates a diagrammatic representation of a machine in the exemplary form of a computing system 500 within which a set of instructions, for causing the machine to perform any one or more of the methodologies discussed herein, may be executed. Within the computer system 500 is a set of instructions for causing the machine to perform any one or more of the methodologies discussed herein. In alternative embodiments, the machine may be connected (e.g., networked) to other machines in a LAN, an intranet, an extranet, or the Internet) and an information processing apparatus configured to (Rakshit: [Col 8, lines 12, 21], (39) The exemplary computer system 500 includes a processing device 502, a main memory 504 (e.g., read-only memory (ROM), flash memory, dynamic random access memory (DRAM) such as synchronous DRAM (SDRAM) or DRAM (RDRAM), etc.), a static memory 506 (e.g., flash memory, static random access memory (SRAM), etc.), and a secondary memory 518 (e.g., a data storage device in the form of a drive unit, which may include fixed or removable computer-readable storage medium), which communicate with each other via a bus 530) and a memory storing a program (Rakshit: [Col 8, lines 51-56], The instructions 526 may also reside, completely or at least partially, within the main memory 504 and/or within the processing device 502 during execution thereof by the computer system 500, the main memory 504 and the processing device 502 also constituting machine-readable storage media) and a processor configured to, when executing the program, cause the communication terminal to (Rakshit: [Col 8, lines 30-36], Processing device 502 may also be one or more special-purpose processing devices such as an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP), network processor, or the like. Processing device 502 is configured to execute the instructions 526 for performing the operations and steps discussed herein) analyze , in a case where a Uniform Resource Location (URL) for accessing the web page is entered , whether the URL is the URL of a website on the intranet (Rakshit: [Col 4, lines 64-67], (23) To combat this scenario, and other similar situations, the credential manager 106 is configured to verify the signing authority of a particular website. Using the example of above, the credential manager 106, before trusting an SSL certificate of BankXYZ.com (=URL), may communicate with a security manager 150) and whether a dedicated root certificate is to be used for accessing the websites (Rakshit: [Col 5, lines 2-4], The security manager 150 interfaces with the CA database 142 to identify the legitimate certificate authority for any particular website (=dedicated root certificate for each website. [Col 6, lines 34-38], If the processing logic, after comparing certificate details with the details retrieved from the CA Database, finds that retrieved domain/website's exclusive identifier 208 is "Y" for the CA 140a (i.e., an indication that this website exclusively uses certificate from the trusted CA 140a) and an interface device configured to transmit the dedicated root certificate to the information processing apparatus in a case where the dedicated root certificate is used as a result of the analysis, wherein the information processing apparatus includes (Rakshit: (Rakshit: [Col 6, lines 16-23], (29) At block 308, the processing logic receives a validation response from the security manager 150 of the trusted certificate authority 140….The processing logic determines (=analysis), at decision block 310, whether the SSL certificate is valid (=having dedicated root certificate) based on the response from the security manager 150. In one embodiment, the response from the security manager 150 contains an indication of the authentic or true root certificate authority for the SSL certificate. If the true root certificate authority matches the root certificate of the SSL certificate, then the SSL certificate is valid and the processing logic, at block 316, trusts the website. (Examiner’s Note: Validation response is getting transmitted to the processing logic wherein validation response contains authentic/true root certificate authority for SSL certificate In other words, it proves that if SSL certificate is valid it means the website has its dedicated root certificate therefore the website is trusted a website) an interface device configured to receive a root certificate for the website on the intranet from the communication terminal (Rakshit: [Col 3, lines 67 – Col 4, lines 1-4], The web browser 114 also receives site certificates, such as SSL certificates. The web browser 114 typically maintains or has access to a root certificate store that includes stored root certificates which identify known signers for particular certificates, [Col 7, lines 4-7], The processing logic then, at block 406, identifies the root certificate associated with the SSL certificate of the validation request) , and a memory storing a program (Rakshit: [Col 8, lines 51-56], The instructions 526 may also reside, completely or at least partially, within the main memory 504 and/or within the processing device 502 during execution thereof by the computer system 500, the main memory 504 and the processing device 502 also constituting machine-readable storage media) and a processor configured to, when executing the program, cause the information processing apparatus to (Rakshit: [Col 8, lines 30-36], Processing device 502 may also be one or more special-purpose processing devices such as an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP), network processor, or the like. Processing device 502 is configured to execute the instructions 526 for performing the operations and steps discussed herein) when the web page of the website on the intranet is rendered (Krishna: [0031] A user 501 starts the interaction by indicating to the browser 203 that the user desires to access a web page or to interact in some fashion with a webpage on the remote server 505, step 351. In response to the user's request, the browser 203 issues an http request message onto the remote web server 505, step 353. For the scenario contemplated herein, a web application is loaded into the browser 203) Perform…verification of reliability of the website on the intranet with the root certificate (Rakshit: [Col 6, lines 25-28], If the true root certificate authority matches the root certificate of the SSL certificate, then the SSL certificate is valid and the processing logic, at block 316, trusts the website). and wherein the information processing apparatus accesses the website on the intranet (Rakshit: [Col 3, lines 61-61], (27) Referring to FIG. 3, processing logic begins method 300 by accessing, at block 302, a website and receiving an SSL certificate associated with that website) in which the communication terminal is located (Rakshit: [Col 7, lines 61-65], the machine may be connected (e.g., networked) to other machines in a LAN, an intranet, an extranet, or the Internet. The machine can be a host (=located) in a cloud, a cloud provider system, a cloud controller or any other machine) It would be obvious to a person having ordinary skill in the art, before the effective filing date of the invention, to modify Krishan’s method of starts the interaction by indicating to the browser 203 that the user desires to access a web page by sending http request message to the remote server by applying Rakshit’s method of comparing root certificate, in order to validate SSL certificate and determine that the requested site is trusted web site. The motivation is to prevent attacker from intercepting every detail of the communication and manipulate the data of the communication. This attack is often referred to as a "man-in-the-middle" attack [Col 1, lines 40-43]) . 07-21-aia AIA Claim (s) 3 is rejected under 35 U.S.C. 103 as being unpatentable over Krishna et al. (U. S. 2011/0320818 A1) (hereinafter “Krishna”) and further in view of Rakshit (U. S. Pat. No. 9,077,546 B1) (hereinafter “Rakshit”); and in further view of PAO et al. (U. S. 2013/0061281 A1) (hereinafter “Pao”) . Regarding Claim 3, Krishna in view of Rakshit teaches: The information apparatus of claim 1 (see rejection of claim 1 above), Krishna in view of Rakshit does not explicitly disclose: the processor is further configured to cause the information processing apparatus to delete the root certificate; However, in an analogous art, Pao teaches: the processor is further configured to cause the information processing apparatus to delete the root certificate (Pao: [Abstract], Proactive remediation is enabled to delete or disable root certificates in trusted operating system root certificate stores or in trusted browser root certificate stores by a web security agent installed at distributed endpoints. [0030] When the web security agent determines that a certificate authority is no longer acceptable to the custom policy store it deletes or disables the root certificate for that certificate authority wherever it has permission or requests permission from the operator administrator to "clean" the certificate store). A person having ordinary skill in the art, before the effective filing date of the invention, would have found it obvious to modify Krishna in view of Rakshit by applying the well-known technique as disclosed by Pao of deleting of disabling root certificates order to removes the need for additional hardware or synchronous remote access over the protected endpoints. Motivation is to prevent performing phishing attacks, or perform man-in-the-middle attacks against end users using a fraudulent certificate may be used to spoof Web content.(Pao: [0008]) . 07-21-aia AIA Claim (s) 4 and 6 are rejected under 35 U.S.C. 103 as being unpatentable over Krishna et al. (U. S. 2011/0320818 A1) (hereinafter “Krishna”) and further in view of Rakshit (U. S. Pat. No. 9,077,546 B1) (hereinafter “Rakshit”); and in further view of Vogel et al. (U. S. Pat. No.6,816,900 B1) (hereinafter “Vogel”) . Regarding Claim 4, Krishna in view of Rakshit teaches: The information apparatus of claim 2 (see rejection of claim 2 above), Krishna in view of Rakshit does not explicitly disclose: the processor is further configured to cause the information processing apparatus to notify, in a case where the interface device receives a notification of checking whether the root certificate for the website on the intranet is present or absent from the communication terminal, the communication terminal of the presence or absence of the root certificate. However, in an analogous art, Vogel teaches: the processor is further configured to cause the information processing apparatus to notify, in a case where the interface device receives a notification of (Vogel: [Col 7, lines 45-50], (25) Certificate trust list 214 includes a subject usage indication 218 (=notification), one or more hash values 220..Subject sage indication 218 indicates the default usage restrictions for the root certificates in certificate trust list 214. For example, subject usage indication 218 may contain client authentication and server authentication usage restrictions) checking whether the root certificate for the website on the intranet is present or absent from the communication terminal, the communication terminal of the presence or absence of the root certificate (Vogel: [Col 11, lines 21-28], A check can then be made as to whether any of the usage restrictions on the root certificates should be changed, and the appropriate changes made… a request may be sent by an additional control hosted on the web page for whether a particular root certificate exists (or is still valid) in root store 112, and the root certificate removed if it is present (or still valid). A person having ordinary skill in the art, before the effective filing date of the invention, would have found it obvious to modify Krishna in view of Rakshit by applying the well-known technique as disclosed by Vogel of checking whether a particular root certificate exist in the root store in order to verify chain of trust. The motivation is to provide a solution to the problem of adding new root certificates to an application that has already been distributed to consumers can be a difficult and cumbersome process (Vogel: [Col 1, lines 51-53]). Regarding Claim 6, Krishna in view of Rakshit teaches: The communication terminal according to claim 5 (see rejection of claim 5 above), Krishna in view of Rakshit does not explicitly disclose: the processor is further configured to cause the communication terminal to check the information processing apparatus for whether the dedicated root certificate is present or absent in a case where the dedicated root certificate is used as a result of the analysis However, in an analogous art, Vogel teaches: the processor is further configured to cause the communication terminal to check the information processing apparatus for whether the dedicated root certificate is present or absent in a case where the dedicated root certificate is used as a result of the analysis (Vogel: [Col 11, lines 21-28], A check can then be made as to whether any of the usage restrictions on the root certificates should be changed, and the appropriate changes made… a request may be sent by an additional control hosted on the web page for whether a particular root certificate exists (or is still valid) in root store 112, and the root certificate removed if it is present (or still valid) . A person having ordinary skill in the art, before the effective filing date of the invention, would have found it obvious to modify Krishna in view of Rakshit by applying the well-known technique as disclosed by Vogel of checking whether a particular root certificate exist in the root store in order to verify chain of trust. The motivation is to provide a solution to the problem of adding new root certificates to an application that has already been distributed to consumers can be a difficult and cumbersome process (Vogel: [Col 1, lines 51-53]). Conclusion The prior art made of record and not relied upon is considered pertinent to a disclosure. Refer to PTO-892, Notice of References Cited for a listing of analogous art. Verma et al. (U. S Pat. No. 12,069,042 B2): The techniques disclosed herein enable improved security as well as more scalable and reliable job execution by utilizing granular security boundaries and certificate-based authentication for all communication within cloud-based platforms. To manage a cloud-based platform, a system receives a plurality of jobs and associated certificates at a first security boundary that are to be executed at various resource units within a second security boundary. The system then authenticates each certificate before transmitting each job to its respective resource unit for execution. In addition, the system is further configured to monitor active certificates for compromise and accordingly isolate various security boundaries in the event of a security breach. By isolating portions of the cloud-based platform within security boundaries, the system can mitigate the impact of security breaches. Furthermore, certificate-based authentication addresses performance constraints to enable more efficient and scalable job execution. SATOH (U. S. PGPub. No. 2014/0244999A1): A network system includes a management apparatus and multiple apparatuses. The management apparatus includes a preparation instruction unit to transmit an instruction to prepare a certificate request to the apparatuses; a collection unit to collect the certificate requests; a request unit to request issuance of certificates to a certificate authority; a resetting instruction unit to transmit the issued certificates to the apparatuses and to instruct resetting of certificates. The apparatus includes a storing unit including an operation area for storing a first certificate and a provisional operation area; a provisionally operating unit to transfer the first certificate to the provisional operation area, and to generate a certificate request, and to transmit the certificate request to the management apparatus; a setting unit to store a second certificate, issued by the certificate authority, in the operation area, and to instruct a communication unit to conduct the communication by switching a certificate. Any inquiry concerning this communication or earlier communications from the examiner should be directed to RUPALI DHAKAD whose telephone number is (571)270-3743. The examiner can normally be reached M-F 8:30-5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at 5712705143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /R.D./Examiner, Art Unit 2437 /ALI S ABYANEH/Primary Examiner, Art Unit 2437 Application/Control Number: 19/079,100 Page 2 Art Unit: 2437 Application/Control Number: 19/079,100 Page 3 Art Unit: 2437 Application/Control Number: 19/079,100 Page 4 Art Unit: 2437 Application/Control Number: 19/079,100 Page 5 Art Unit: 2437 Application/Control Number: 19/079,100 Page 6 Art Unit: 2437 Application/Control Number: 19/079,100 Page 7 Art Unit: 2437 Application/Control Number: 19/079,100 Page 8 Art Unit: 2437 Application/Control Number: 19/079,100 Page 9 Art Unit: 2437 Application/Control Number: 19/079,100 Page 10 Art Unit: 2437 Application/Control Number: 19/079,100 Page 11 Art Unit: 2437 Application/Control Number: 19/079,100 Page 12 Art Unit: 2437 Application/Control Number: 19/079,100 Page 13 Art Unit: 2437 Application/Control Number: 19/079,100 Page 14 Art Unit: 2437 Application/Control Number: 19/079,100 Page 15 Art Unit: 2437 Application/Control Number: 19/079,100 Page 16 Art Unit: 2437 Application/Control Number: 19/079,100 Page 17 Art Unit: 2437 Application/Control Number: 19/079,100 Page 18 Art Unit: 2437 Application/Control Number: 19/079,100 Page 19 Art Unit: 2437 Application/Control Number: 19/079,100 Page 20 Art Unit: 2437 Application/Control Number: 19/079,100 Page 21 Art Unit: 2437 Application/Control Number: 19/079,100 Page 22 Art Unit: 2437 Application/Control Number: 19/079,100 Page 23 Art Unit: 2437 Application/Control Number: 19/079,100 Page 24 Art Unit: 2437 Application/Control Number: 19/079,100 Page 25 Art Unit: 2437 Application/Control Number: 19/079,100 Page 26 Art Unit: 2437