DETAILED ACTION
This action is in response to the claims filed 4/1/2025. Claims 1-20 are pending. Independent claims 1, 16 and 20, and corresponding dependent claims are directed towards a method and network devices for virtual local area network discovery and assignment for unauthenticated or sleeping endpoints.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Specification
The disclosure is objected to because of the following informalities: the first recitation of the following acronyms is not expanded: [0003] OSI and OT; [0004] IP; [0009] MAC; [0044] VLSI; [0064] EPROM. Appropriate correction is required.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 9, 12, 15-17 and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Olakangil et al. (US 2008/0137660 A1), published Jun. 12, 2008, in view of Avaya, Inc. “Configuration — Security Avaya Ethernet Routing Switch 4000 Series” published Dec. 2011, hereinafter referred to as Avaya.
As to claim 1, Olakangil substantially discloses a network device (Olakangil Fig. 1 item 100 switch; ¶6 & ¶13), comprising: a processor (Olakangil Fig. 1 item 106; ¶13, 17-20 disclosing functionality processing of ingress/forwarding logic unit); a plurality of interfaces (Olakangil Fig. 1 items 104, 108 and 110a-110n; ¶13-14 multiple ports disclosed in switch) including at least one first interface assigned to a first Virtual Local Area Network (VLAN) (Olakangil ¶13 & ¶16 receive packet 102 via port 104 for VLAN A) and one or more second interfaces assigned to a second VLAN (Olakangil ¶13 flood packet via ports 110a-n in second VLAN D), wherein a second interface of the one or more second interfaces is communicatively coupled to an endpoint (Olakangil ¶23 servers residing on multiple ports of VLAN D); a memory communicatively coupled to the processor (Olakangil Fig. 1 item 114 L2 Table and item 116 L3 Table; ¶14 used by ingress/forwarding logic unit), wherein the memory comprises a configuration logic that is configured to: detect a packet (Olakangil ¶13 & ¶16 receive packet 102 via port 104 for VLAN A to process packet); determine that the packet is associated with the first VLAN (Olakangil ¶16 packet ingresses at port 104 in VLAN A, having VLAN A tag); and flood the packet on the second VLAN based on the determination that the packet is associated with the first VLAN (Olakangil ¶17-18 change VLAN tag from VLAN A to VLAN D; ¶19-20 flood copies of packet through ports 110a-n of VLAN D), wherein based on the flooding, the packet reaches the endpoint (Olakangil ¶20 each port 110-a-110n receives copy of packet; ¶23 servers residing on multiple ports of VLAN D would receive copy). Olakangil fails to explicitly disclose the first VLAN being a host VLAN and the second VLAN being the default VLAN; and the endpoint being unauthenticated. Avaya describes security configuration for Avaya ethernet routing switch 4000 series. With this in mind, Avaya discloses the first VLAN being a host VLAN (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” if authentication succeeds port is placed on preconfigured VLAN) and the second VLAN being the default VLAN (Avaya pgs. 38-39 “Guest VLAN” unauthenticated ports are assigned to global default Guest VLAN) and the endpoint being unauthenticated (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” guest VLAN configured for non-authenticated users, port is placed in guest VLAN for awaiting authentication or failed authentication; pgs. 51-52 “802.1X authentication and Wake on Lan” client previously assigned to RADIUS-assigned VLAN reverts to “default port-based VLAN or Guest VLAN” when it enters hibernation, Wake-on-LAN (WoL) magic packet is broadcast to wake client up). It would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains to combine the RADIUS-assigned/Guest VLANs of Avaya with the cross VLAN flooding technique of Olakangil, such that packets are flooded on the guest/default VLAN in order to reach an unauthenticated endpoint, as it would advantageously allow for communication with devices that have shutdown and lost authentication status (Avaya pgs. 51-52 “802.1X authentication and Wake on Lan”).
As to claim 9, Olakangil and Avaya disclose the invention as claimed as described in claim 1, including wherein the packet corresponds to one of: a unicast packet (Olakangil ¶13 packet is a unicast packet), a broadcast packet (optional – not required), or a Wake-on-LAN (WOL) packet (optional – not required).
As to claim 12, Olakangil and Avaya disclose the invention as claimed as described in claim 1, including wherein prior to detecting, the configuration logic is further configured to receive the packet from an upstream network device (Olakangil ¶13&16 packet is externally ingressed via port 104).
As to claim 15, Olakangil and Avaya disclose the invention as claimed as described in claim 1, including wherein the host VLAN is an authenticated VLAN Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” if authentication succeeds port is placed on preconfigured VLAN) and the default VLAN is an unauthenticated VLAN (Avaya pgs. 38-39 “Guest VLAN” unauthenticated ports are assigned to global default Guest VLAN).
As to claim 16, Olakangil substantially discloses a network device (Olakangil Fig. 1 item 100 switch; ¶6 & ¶13), comprising: a processor (Olakangil Fig. 1 item 106; ¶13, 17-20 disclosing functionality processing of ingress/forwarding logic unit); a plurality of interfaces (Olakangil Fig. 1 items 104, 108 and 110a-110n; ¶13-14 multiple ports disclosed in switch) including at least one first interface assigned to a first Virtual Local Area Network (VLAN) (Olakangil ¶13 & ¶16 receive packet 102 via port 104 for VLAN A) and one or more second interfaces assigned to a second VLAN (Olakangil ¶13 flood packet via ports 110a-n in second VLAN D) and one or more second interfaces assigned to a second VLAN (Olakangil ¶13 flood packet via ports 110a-n in second VLAN D), wherein a second interface of the one or more second interfaces is communicatively coupled to an endpoint (Olakangil ¶23 servers residing on multiple ports of VLAN D); a memory communicatively coupled to the processor (Olakangil Fig. 1 item 114 L2 Table and item 116 L3 Table; ¶14 used by ingress/forwarding logic unit), wherein the memory comprises a configuration logic that is configured to: detect a packet (Olakangil ¶13 & ¶16 receive packet 102 via port 104 for VLAN A to process packet); determine that the packet is associated with the first VLAN (Olakangil ¶16 packet ingresses at port 104 in VLAN A, having VLAN A tag); and flood the packet on the second VLAN based on the determination that the packet is associated with the first VLAN (Olakangil ¶17-18 change VLAN tag from VLAN A to VLAN D; ¶19-20 flood copies of packet through ports 110a-n of VLAN D), wherein based on the flooding the packet reaches the endpoint (Olakangil ¶20 each port 110-a-110n receives copy of packet; ¶23 servers residing on multiple ports of VLAN D would receive copy). Olakangil fails to explicitly disclose the first VLAN being a host VLAN and the second VLAN being the default VLAN; and the endpoint being in a sleep mode. Avaya discloses the first VLAN being a host VLAN (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” if authentication succeeds port is placed on preconfigured VLAN) and the second VLAN being the default VLAN (Avaya pgs. 38-39 “Guest VLAN” unauthenticated ports are assigned to global default Guest VLAN) and the endpoint being in the sleep mode (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” guest VLAN configured for non-authenticated users, port is placed in guest VLAN for awaiting authentication or failed authentication; pgs. 51-52 “802.1X authentication and Wake on Lan” client previously assigned to RADIUS-assigned VLAN reverts to “default port-based VLAN or Guest VLAN” when it enters hibernation, Wake-on-LAN (WoL) magic packet is broadcast to wake client up). It would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains to combine the RADIUS-assigned/Guest VLANs of Avaya with the cross VLAN flooding technique of Olakangil, such that packets are flooded on the guest/default VLAN in order to reach an unauthenticated endpoint, as it would advantageously allow for communication with devices that have shutdown and lost authentication status (Avaya pgs. 51-52 “802.1X authentication and Wake on Lan”).
As to claim 17, Olakangil and Avaya disclose the invention as claimed as described in claim 16, including wherein the packet is configured to transition the endpoint from the sleep mode to an active mode (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” guest VLAN configured for non-authenticated users, port is placed in guest VLAN for awaiting authentication or failed authentication; pgs. 51-52 “802.1X authentication and Wake on Lan” client previously assigned to RADIUS-assigned VLAN reverts to “default port-based VLAN or Guest VLAN” when it enters hibernation, Wake-on-LAN (WoL) magic packet is broadcast to wake client up).
As to claim 19, Olakangil and Avaya disclose the invention as claimed as described in claim 16, including wherein the endpoint is an 802.1X-enabled device (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” use of EAP for authentication of client; pg. 52 “EAP (802.1X) accounting” showing 802.1X with EAP).
As to claim 20, Olakangil substantially discloses a method (Olakangil [Abstract]), comprising: detecting a packet (Olakangil ¶13 & ¶16 receive packet 102 via port 104 for VLAN A to process packet); determining that the packet is associated with a first Virtual Local Area Network (VLAN) (Olakangil ¶16 packet ingresses at port 104 in VLAN A, having VLAN A tag) to which at least one first interface of a network device is assigned (Olakangil ¶13 & ¶16 receive packet 102 via port 104 for VLAN A); and flooding the packet on a second VLAN based on the determination that the packet is associated with the first VLAN (Olakangil ¶17-18 change VLAN tag from VLAN A to VLAN D; ¶19-20 flood copies of packet through ports 110a-n of VLAN D), wherein one or more second interfaces of the network device are assigned to the second VLAN (Olakangil ¶13 flood packet via ports 110a-n in second VLAN D) and a second interface of the one or more second interfaces is communicatively coupled to an endpoint (Olakangil ¶23 servers residing on multiple ports of VLAN D), and wherein based on the flooding the packet reaches the endpoint (Olakangil ¶20 each port 110-a-110n receives copy of packet; ¶23 servers residing on multiple ports of VLAN D would receive copy). Olakangil fails to explicitly disclose the first VLAN being a host VLAN and the second VLAN being the default VLAN; and the endpoint being one of unauthenticated or in a sleep mode. Avaya discloses the first VLAN being a host VLAN (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” if authentication succeeds port is placed on preconfigured VLAN) and the second VLAN being the default VLAN (Avaya pgs. 38-39 “Guest VLAN” unauthenticated ports are assigned to global default Guest VLAN) and the endpoint being one of unauthenticated or in the sleep mode (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” guest VLAN configured for non-authenticated users, port is placed in guest VLAN for awaiting authentication or failed authentication; pgs. 51-52 “802.1X authentication and Wake on Lan” client previously assigned to RADIUS-assigned VLAN reverts to “default port-based VLAN or Guest VLAN” when it enters hibernation, Wake-on-LAN (WoL) magic packet is broadcast to wake client up). It would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains to combine the RADIUS-assigned/Guest VLANs of Avaya with the cross VLAN flooding technique of Olakangil, such that packets are flooded on the guest/default VLAN in order to reach an unauthenticated endpoint, as it would advantageously allow for communication with devices that have shutdown and lost authentication status (Avaya pgs. 51-52 “802.1X authentication and Wake on Lan”).
Claims 2-8, 10-11, 14 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Olakangil et al. (US 2008/0137660 A1), published Jun. 12, 2008, in view of Avaya, Inc. “Configuration — Security Avaya Ethernet Routing Switch 4000 Series” published Dec. 2011, hereinafter referred to as Avaya, in view of Kondalam et al. (US 2021/0344591 A1), published Nov. 4, 2021.
As to claim 2, Olakangil and Avaya substantially disclose the invention as claimed as described in claim 1, failing, however, to explicitly disclose wherein the configuration logic is further configured to receive a response from the endpoint based on the packet reaching the endpoint. Kondalam describes detecting and communicating with silent hosts in software-defined networks. With this in mind, Kondalam discloses wherein the configuration logic is further configured to receive a response from the endpoint based on the packet reaching the endpoint (Kondalam ¶34 flood packet to reach silent host, which is woken up and provides response). It would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains to combine the silent host response of Kondalam with the network device of Olakangil and Avaya, such that upon receiving a flooded packet a silent host would be woken and send a response, as it would advantageously allow the network device to learn the port of the endpoint and direct traffic to that port reducing the bandwidth required (Kondalam ¶34).
As to claim 3, Olakangil, Avaya and Kondalam disclose the invention as claimed as described in claim 2, including wherein the configuration logic is further configured to transmit an authentication request for the endpoint to an authentication server (Avaya pgs. 33-34 “EAPOL-based security” switch encapsulates user ID and forwards it to RADIUS server for authentication).
As to claim 4, Olakangil, Avaya and Kondalam disclose the invention as claimed as described in claim 3, including wherein the authentication request is based on MAC-Address Authentication Bypass (MAB) (Avaya pgs. 46-48 “Non EAP hosts on EAP-enabled ports” for a non-EAPOL endpoint use endpoint’s MAC address as credentials and forward to RADIUS server for authentication).
As to claim 5, Olakangil, Avaya and Kondalam disclose the invention as claimed as described in claim 3, including wherein the configuration logic is further configured to receive, in response to the transmitted authentication request, an authentication response from the authentication server (Avaya pgs. 33-34 “EAPOL-based security” switch encapsulates user ID and forwards it to RADIUS server for authentication, which responds with a request for user which then is processed by the RADIUS server; pgs. 292-294 EAPOL message variables including BackendAuthSuccesses and BackendAuthFails).
As to claim 6, Olakangil, Avaya and Kondalam disclose the invention as claimed as described in claim 5, including wherein the authentication response is configured to indicate one of a successful authentication of the endpoint or a failed authentication of the endpoint (Avaya pgs. 292-294 EAPOL message variables including BackendAuthSuccesses and BackendAuthFails).
As to claim 7, Olakangil, Avaya and Kondalam disclose the invention as claimed as described in claim 6, including wherein the configuration logic is further configured to assign the second interface to the host VLAN based on the authentication response indicating the successful authentication of the endpoint (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” if authentication succeeds port is placed on preconfigured VLAN).
As to claim 8, Olakangil and Avaya substantially disclose the invention as claimed as described in claim 1, failing, however, to explicitly disclose wherein the endpoint is a silent host, incapable of initiating communication until prompted by an external trigger. Kondalam discloses wherein the endpoint is a silent host, incapable of initiating communication until prompted by an external trigger (Kondalam ¶34 flood packet to reach silent host, which is woken up and provides response). It would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains to combine the silent host response of Kondalam with the network device of Olakangil and Avaya, such that upon receiving a flooded packet a silent host would be woken and send a response, as it would advantageously allow the network device to learn the port of the endpoint and direct traffic to that port reducing the bandwidth required (Kondalam ¶34).
As to claim 10, Olakangil and Avaya disclose the invention as claimed as described in claim 1, including wherein detecting the packet comprises snooping an Address Resolution Protocol (ARP)-based packet (Araya pg. 80 “Dynamic ARP inspection” switch intercepts and examines ARP packets).
As to claim 11, Olakangil and Avaya disclose the invention as claimed as described in claim 1, including wherein detecting the packet comprises snooping the packet based on an Access Control List (ACL) (Araya “Non EAP hosts on EAP-enabled ports” MAC address compared against local list of allowed MAC addresses).
As to claim 14, Olakangil and Avaya substantially disclose the invention as claimed as described in claim 1, including a host VLAN (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” if authentication succeeds port is placed on preconfigured VLAN). Olakangil and Avaya fail to explicitly disclose wherein the configuration logic is further configured to transmit the packet on the host VLAN. Kondalam discloses wherein the configuration logic is further configured to transmit the packet on all ports of a router or switch (Kondalam ¶34 packet intended for silent host maybe replicated on all ports of a router or switch). It would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains to combine the silent host response of Kondalam with the network device of Olakangil and Avaya, such that a silent host is initially communicated with by flooding packets on all ports of the switch (including the original host VLAN), as it would advantageously allow the network device to learn the port of the endpoint and direct traffic to that port reducing the bandwidth required (Kondalam ¶34).
As to claim 18, Olakangil and Avaya substantially disclose the invention as claimed as described in claim 17, including wherein the configuration logic is further configured to: assign the second interface to the host VLAN based on the response (Avaya pgs. 37-38 “Single Host with Single Authentication and Guest VLAN” if authentication succeeds port is placed on preconfigured VLAN or a RADIUS-assigned VLAN). Olakangil and Avaya fail to explicitly disclose receive a response from the endpoint that is transitioned to the active mode. Kondalam discloses wherein the configuration logic is further configured to: receive a response from the endpoint that is transitioned to the active mode (Kondalam ¶34 flood packet to reach silent host, which is woken up and provides response). It would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains to combine the silent host response of Kondalam with the network device of Olakangil and Avaya, such that upon receiving a flooded packet a silent host would be woken and send a response, as it would advantageously allow the network device to learn the port of the endpoint and direct traffic to that port reducing the bandwidth required (Kondalam ¶34).
Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Olakangil et al. (US 2008/0137660 A1), published Jun. 12, 2008, in view of Avaya, Inc. “Configuration — Security Avaya Ethernet Routing Switch 4000 Series” published Dec. 2011, hereinafter referred to as Avaya, in view of Lo et al. (US 2023/0132016 A1), published Apr. 27, 2023.
As to claim 13, Olakangil and Avaya substantially disclose the invention as claimed as described in claim 1, failing, however, to explicitly disclose wherein the detected packet is a locally generated packet at the network device. Lo describes host routing with virtual machine mobility. With this in mind, Lo discloses wherein the packet is a locally generated packet at the network device (Lo ¶52 network device generates and ARP request for virtual machine and floods on network underlay). It would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains to combine the network device MAC address discovery process of Lo with the network device of Olakangil and Kondalam, such that the network device floods a packet on the network when unable to obtain the MAC address, as it would advantageously trigger a response from an endpoint and permit the network device to learn routing information necessary to direct subsequent traffic to the endpoint (Lo ¶52).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Jabr et al. (US 8,189,600 B2) is related to IP routing when using dynamic VLANs with web-based authentication.
Nozue et al. (US 2008/0137557 A1) is related to forming spanning trees for VLANs.
Beser (US 2009/0028116 A1) is related to dynamic VLANS.
Brotherson et al. (US 2019/0296972 A1) is related to dynamic network discovery.
TP-link, Inc., “Configuration Guide For 802.1X VLAN Assignment and MAB” is related to MAB.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ERIC W SHEPPERD whose telephone number is (571)270-5654. The examiner can normally be reached Monday - Thursday, Alt. Friday, 7:30AM - 5:00PM, EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal Dharia can be reached at (571)272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Eric W Shepperd/Primary Examiner, Art Unit 2492