Prosecution Insights
Last updated: October 02, 2026
Application No. 19/174,342

Cloud-Based Man-in-the-Middle Inspection of Encrypted Traffic

Non-Final OA §103
Filed
Apr 09, 2025
Priority
Apr 30, 2020 — continuation of 11/394,563 +2 more
Examiner
HOFFMAN, BRANDON S
Art Unit
Tech Center
Assignee
Zscaler Inc.
OA Round
1 (Non-Final)
90%
Grant Probability
Favorable
1-2
OA Rounds
1y 0m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 90% — above average
90%
Career Allowance Rate
1153 granted / 1274 resolved
+30.5% vs TC avg
Moderate +6% lift
Without
With
+6.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
16 currently pending
Career history
1282
Total Applications
across all art units

Statute-Specific Performance

§101
8.6%
-31.4% vs TC avg
§103
35.3%
-4.7% vs TC avg
§102
33.4%
-6.6% vs TC avg
§112
5.0%
-35.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1274 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claims 1-20 are pending in this office action. Information Disclosure Statement The information disclosure statement (IDS) submitted on April 9, 2025, is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Specification The disclosure is objected to because of the following informalities: the CROSS-REFERENCE TO RELATED APPLICATIONS section needs updated to reflect applications that have matured into patents. Appropriate correction is required. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Bannister et al. (U.S. Patent No. 11,805,107) in view of Wyatt et al. (U.S. Patent Pub. No. 2017/0346853). Regarding claims 1 and 20, Bannister et al. teaches a method for man-in-the-middle (MITM) inspection of encrypted traffic in a cloud-based security system, the method comprising: receiving, at a node within the cloud-based security system, a request from a user device to access encrypted traffic from a server (fig. 6, ref. num 610); and inspecting encrypted traffic communicated between the user device and the server (col. 17, line 52 through col. 18, line 6). Bannister et al. does not teach obtaining a domain certificate corresponding to the server; or establishing a first encrypted tunnel between the node and the user device and a second encrypted tunnel between the node and the server using the domain certificate. Wyatt et al. teaches obtaining a domain certificate corresponding to the server (paragraph 0214); and establishing a first encrypted tunnel between the node and the user device and a second encrypted tunnel between the node and the server using the domain certificate (paragraph 0221). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine two separate encrypted tunnels, as taught by Wyatt et al., with the method of Bannister et al. It would have been obvious for such modifications because the two tunnels essentially perform an SSL proxy or MITM operation in order to ensure greater overall security for communications from computing device (see paragraph 0221 of Wyatt et al.) Regarding claim 2, Bannister et al. teaches wherein the domain certificate is generated using a cloud-based Hardware Security Module (HSM) (col. 3, lines 36-50). Regarding claim 3, Bannister et al. as modified by Wyatt et al. teaches wherein the domain certificate is generated by: generating a certificate signing request (CSR) and a key pair; requesting asymmetric signing of the CSR from the cloud-based HSM; receiving a digital signature from the cloud-based HSM; and merging the digital signature with the CSR to form the domain certificate (see paragraph 0183 of Wyatt et al.). Regarding claim 4, Bannister et al. as modified by Wyatt et al. teaches wherein a private key associated with an intermediate Certificate Authority (CA) used to sign the domain certificate is stored exclusively in the cloud-based HSM (see paragraph 0190 of Wyatt et al.). Regarding claim 5, Bannister et al. as modified by Wyatt et al. teaches further comprising caching the domain certificate locally at the node for subsequent use (see paragraph 0178 of Wyatt et al.). Regarding claim 6, Bannister et al. as modified by Wyatt et al. teaches further comprising synchronizing cached domain certificates between multiple nodes within the cloud-based security system (see paragraph 0178 of Wyatt et al.). Regarding claim 7, Bannister et al. as modified by Wyatt et al. teaches wherein the inspecting encrypted traffic comprises performing security functions including threat prevention, data loss prevention (DLP), intrusion detection, malware detection, or web content filtering (see paragraph 0131 of Wyatt et al.). Regarding claim 8, Bannister et al. as modified by Wyatt et al. teaches further comprising enrolling the node with a customer Certificate Authority (CA) through a cloud-based Hardware Security Module (HSM) prior to obtaining the domain certificate (see paragraph 0003 of Wyatt et al.). Regarding claim 9, Bannister et al. as modified by Wyatt et al.teaches wherein the obtaining the domain certificate comprises retrieving the domain certificate from a memory cache if previously generated and cached (see paragraph 0178 of Wyatt et al.). Regarding claim 10, Bannister et al. as modified by Wyatt et al. teaches further comprising blocking or allowing encrypted traffic based on results of the inspecting (see paragraph 0054 of Wyatt et al.). Regarding claim 11, Bannister et al. teaches wherein the establishing the first and second encrypted tunnels comprises negotiating Secure Sockets Layer (SSL) or Transport Layer Security (TLS) sessions (col. 7, line 50 through col. 8, line 14). Regarding claim 12, Bannister et al. teaches wherein the inspecting encrypted traffic includes decrypting the traffic using session keys obtained through the SSL or TLS negotiation (col. 7, line 50 through col. 8, line 14). Regarding claim 13, Bannister et al. teaches wherein the node operates as an inline proxy configured between the user device and the server (col. 16, lines 15-41). Regarding claim 14, Bannister et al. as modified by Wyatt et al. teaches wherein the node is configured to transparently intercept the request from the user device without explicit proxy configuration at the user device (see paragraph 0256 of Wyatt et al.). Regarding claim 15, Bannister et al. teaches wherein the cloud-based security system comprises multiple geographically distributed nodes, each configured to perform MITM inspection (fig. 2). Regarding claim 16, Bannister et al. as modified by Wyatt et al. teaches further comprising: detecting failure conditions where encrypted traffic cannot be decrypted; and responsive to the detecting, blocking the encrypted traffic (see paragraph 0054 of Wyatt et al.). Regarding claim 17, Bannister et al. as modified by Wyatt et al. teaches wherein the domain certificate is an intermediate certificate signed by a customer-specific root Certificate Authority (CA) (see paragraph 0190 of Wyatt et al.). Regarding claim 18, Bannister et al. as modified by Wyatt et al. teaches wherein the request from the user device includes Server Name Indication (SNI) information identifying the server (see paragraph 0265 of Wyatt et al.). Regarding claim 19, Bannister et al. teaches wherein inspecting encrypted traffic further comprises enforcing granular policies based on user identity, URL category, or application type (col. 17, line 52 through col. 18, line 6). Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRANDON HOFFMAN whose telephone number is (571)272-3863. The examiner can normally be reached Monday-Friday 8:30AM-5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached at (571)272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRANDON HOFFMAN/Primary Examiner, Art Unit 2433
Read full office action

Prosecution Timeline

Apr 09, 2025
Application Filed
Aug 19, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743535
Enforcing Compliance with Data Use Policies
2y 8m to grant Granted Sep 22, 2026
Patent 12732487
METHODS AND SYSTEMS FOR SECURING CONTAINERIZED APPLICATIONS
2y 5m to grant Granted Sep 08, 2026
Patent 12730918
APPARATUS AND METHOD FOR AUTONOMOUSLY OPERATING A SERVICE ENVIRONMENT
2y 4m to grant Granted Sep 08, 2026
Patent 12719849
AUTHENTICATION SERVICE AND CERTIFICATE EXCHANGE PROTOCOL IN WIRELESS AD HOC NETWORKS
10y 7m to grant Granted Aug 25, 2026
Patent 12717956
SYSTEMS AND METHODS USING EMULATION FOR END TO END ENCRYPTION
2y 4m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
90%
Grant Probability
97%
With Interview (+6.4%)
2y 6m (~1y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 1274 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month