Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claims 1-20 are pending in this office action.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on April 9, 2025, is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Specification
The disclosure is objected to because of the following informalities: the CROSS-REFERENCE TO RELATED APPLICATIONS section needs updated to reflect applications that have matured into patents. Appropriate correction is required.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Bannister et al. (U.S. Patent No. 11,805,107) in view of Wyatt et al. (U.S. Patent Pub. No. 2017/0346853).
Regarding claims 1 and 20, Bannister et al. teaches a method for man-in-the-middle (MITM) inspection of encrypted traffic in a cloud-based security system, the method comprising: receiving, at a node within the cloud-based security system, a request from a user device to access encrypted traffic from a server (fig. 6, ref. num 610); and inspecting encrypted traffic communicated between the user device and the server (col. 17, line 52 through col. 18, line 6).
Bannister et al. does not teach obtaining a domain certificate corresponding to the server; or establishing a first encrypted tunnel between the node and the user device and a second encrypted tunnel between the node and the server using the domain certificate.
Wyatt et al. teaches obtaining a domain certificate corresponding to the server (paragraph 0214); and establishing a first encrypted tunnel between the node and the user device and a second encrypted tunnel between the node and the server using the domain certificate (paragraph 0221).
It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine two separate encrypted tunnels, as taught by Wyatt et al., with the method of Bannister et al. It would have been obvious for such modifications because the two tunnels essentially perform an SSL proxy or MITM operation in order to ensure greater overall security for communications from computing device (see paragraph 0221 of Wyatt et al.)
Regarding claim 2, Bannister et al. teaches wherein the domain certificate is generated using a cloud-based Hardware Security Module (HSM) (col. 3, lines 36-50).
Regarding claim 3, Bannister et al. as modified by Wyatt et al. teaches wherein the domain certificate is generated by: generating a certificate signing request (CSR) and a key pair; requesting asymmetric signing of the CSR from the cloud-based HSM; receiving a digital signature from the cloud-based HSM; and merging the digital signature with the CSR to form the domain certificate (see paragraph 0183 of Wyatt et al.).
Regarding claim 4, Bannister et al. as modified by Wyatt et al. teaches wherein a private key associated with an intermediate Certificate Authority (CA) used to sign the domain certificate is stored exclusively in the cloud-based HSM (see paragraph 0190 of Wyatt et al.).
Regarding claim 5, Bannister et al. as modified by Wyatt et al. teaches further comprising caching the domain certificate locally at the node for subsequent use (see paragraph 0178 of Wyatt et al.).
Regarding claim 6, Bannister et al. as modified by Wyatt et al. teaches further comprising synchronizing cached domain certificates between multiple nodes within the cloud-based security system (see paragraph 0178 of Wyatt et al.).
Regarding claim 7, Bannister et al. as modified by Wyatt et al. teaches wherein the inspecting encrypted traffic comprises performing security functions including threat prevention, data loss prevention (DLP), intrusion detection, malware detection, or web content filtering (see paragraph 0131 of Wyatt et al.).
Regarding claim 8, Bannister et al. as modified by Wyatt et al. teaches further comprising enrolling the node with a customer Certificate Authority (CA) through a cloud-based Hardware Security Module (HSM) prior to obtaining the domain certificate (see paragraph 0003 of Wyatt et al.).
Regarding claim 9, Bannister et al. as modified by Wyatt et al.teaches wherein the obtaining the domain certificate comprises retrieving the domain certificate from a memory cache if previously generated and cached (see paragraph 0178 of Wyatt et al.).
Regarding claim 10, Bannister et al. as modified by Wyatt et al. teaches further comprising blocking or allowing encrypted traffic based on results of the inspecting (see paragraph 0054 of Wyatt et al.).
Regarding claim 11, Bannister et al. teaches wherein the establishing the first and second encrypted tunnels comprises negotiating Secure Sockets Layer (SSL) or Transport Layer Security (TLS) sessions (col. 7, line 50 through col. 8, line 14).
Regarding claim 12, Bannister et al. teaches wherein the inspecting encrypted traffic includes decrypting the traffic using session keys obtained through the SSL or TLS negotiation (col. 7, line 50 through col. 8, line 14).
Regarding claim 13, Bannister et al. teaches wherein the node operates as an inline proxy configured between the user device and the server (col. 16, lines 15-41).
Regarding claim 14, Bannister et al. as modified by Wyatt et al. teaches wherein the node is configured to transparently intercept the request from the user device without explicit proxy configuration at the user device (see paragraph 0256 of Wyatt et al.).
Regarding claim 15, Bannister et al. teaches wherein the cloud-based security system comprises multiple geographically distributed nodes, each configured to perform MITM inspection (fig. 2).
Regarding claim 16, Bannister et al. as modified by Wyatt et al. teaches further comprising: detecting failure conditions where encrypted traffic cannot be decrypted; and responsive to the detecting, blocking the encrypted traffic (see paragraph 0054 of Wyatt et al.).
Regarding claim 17, Bannister et al. as modified by Wyatt et al. teaches wherein the domain certificate is an intermediate certificate signed by a customer-specific root Certificate Authority (CA) (see paragraph 0190 of Wyatt et al.).
Regarding claim 18, Bannister et al. as modified by Wyatt et al. teaches wherein the request from the user device includes Server Name Indication (SNI) information identifying the server (see paragraph 0265 of Wyatt et al.).
Regarding claim 19, Bannister et al. teaches wherein inspecting encrypted traffic further comprises enforcing granular policies based on user identity, URL category, or application type (col. 17, line 52 through col. 18, line 6).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRANDON HOFFMAN whose telephone number is (571)272-3863. The examiner can normally be reached Monday-Friday 8:30AM-5:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached at (571)272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BRANDON HOFFMAN/Primary Examiner, Art Unit 2433