Prosecution Insights
Last updated: October 02, 2026
Application No. 19/190,679

OPTIMIZED DEEP PACKET INSPECTION FOR ROLE-BASED POLICIES

Non-Final OA §103
Filed
Apr 27, 2025
Priority
Feb 07, 2025 — IN 202541010849
Examiner
PREM, SAIPRATAP
Art Unit
2494
Tech Center
2400 — Computer Networks
Assignee
Hewlett Packard Enterprise Development L.P.
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-58.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
4 currently pending
Career history
4
Total Applications
across all art units
This examiner has no resolved cases yet (career too new); statute-level performance unavailable. The Grant Probability card shows Tech Center averages instead.

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-5, 13, 14, 15, 16, 18, 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Hu (US 8331229 B1, published Dec. 11, 2012) in view of Manuguri (US 20140226478 A1 published Aug.14 2014). As per claim 1 Hu discloses, A network device, configured to: receive, at the network device, a data packet for transmission to a destination ([Hu, col 5, lines 58-62], “The DPI component 104 is illustrated as being tapped into the Gi interface to monitor data traffic, although this is not necessarily the case. Alternatively, the DPI component 104 could be positioned in-line with the GGSN 116 and the Internet 212. “); identify, via the network device, that the data packet is associated with a policy comprising data packet inspection (DPI)-identified criteria ([ Hu, col 5, lines 62-65], “The DPI component 104 receives policy conditions, via the P4 interface, to enable the DPI component 104 to monitor data while taking into account policies provided by the PMF 102. “); in response to identifying that the data packet is associated with the policy comprising the DPI-identified criteria: selectively enable DPI on the data packet, by providing, via the network device, ([Hu, col 6, lines 11-14 ], “Accordingly, the present invention separates the traffic detection element (DPI component 104) and the traffic enforcement element (PCEF 115) to increase performance and efficiency.“); receive, via the network device, from the DPI processor, a DPI-identified characteristic associated with the data packet ([Hu, col 2, lines 22-24 ], “The traffic analyzer can be further configured for sending a trigger to the PMF, if at least one of the policy conditions is at least substantially met. “); identify, via the network device, whether the DPI-identified characteristic matches the DPI-identified criteria of the policy ([Hu, col 6, lines 21-26],” At block 306, the traffic analyzer 118 monitors the data traffic. The traffic analyzer 118 is additionally made aware of any pre-existing policy conditions or rules that are to be applied to the monitored traffic. At block 308, if the traffic analyzer 118 detects that one or more of the policy conditions or rules have been met, “); and implement, via the network device, an action of the policy when the DPI- identified characteristic matches the DPI-identified criteria ([Hu, col 1, lines 28-31],” Accordingly, actions can be taken to properly enforce these policies. Actions can include, for example, allowing, blocking, destroying, rate limiting, and flagging a suspect packet or packet stream. “). Hu does not disclose, but Manuguri discloses a copy of the data packet to a DPI processor configured to perform DPI [Manuguri, par 0017 “In one embodiment, overlapping portions of the packet stream are copied. For example, consecutive sequences of the first 10 packets, first 50 packets, and first 100 packets of a packet stream may be copied to provide varying levels of context for the data within the packet flow. In one embodiment, entire packets are copied. Alternatively, only a portion of each the packets is copied. “]; and send the data packet to the destination [Manuguri, par 0011, “While or after the one or more packets are forwarded to the destination”]. Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that the network device is configured to receive a data packet for transmission to a destination, identify that the data packet is associated with a policy comprising dpi identified criteria. Next, the response to identifying that the data packet is associated with the policy comprising the DPI-identified criteria: selectively enable DPI on the data packet, by providing, via the network device, a copy of the data packet to a DPI processor configured to perform DPI, receive, identify the DPI-identified characteristic associated with the data packet and implement the action of the policy when the DPI- identified characteristic matches the DPI-identified criteria. Additionally, the copy of the data packet to a DPI processor is configured to perform DPI along with sending the packet to the destination as taught by Manuguri. One would have been motivated to do so because doing so would allow the system to perform deep packet inspection on suspicious data flows while maintaining low latency for regular packet forwarding. As per claim 18, the limitations of claims 18 correspond to the features of claim 1 is/are rejected for the same reasons. As per claim 2, the rejection of claim 1 is incorporated herein. Hu does not disclose, but Manuguri discloses configured to: receive, at the network device, a second data packet; identify, via the network device, that the second data packet is not associated with any policy comprising any DPI-identified criteria; and in response to identifying that the second data packet is not associated with any policy comprising any DPI-identified criteria, bypass DPI on the second data packet by refraining from generating and providing a copy of the second data packet to the DPI processor [Manuguri, par 0025, “In one embodiment, the switch 355 and/or virtual machines 345 may be tailored to selectively subject packets associated with particular virtual machines 345 to DPI. For example, if a host 305 includes two virtual machines 345, one virtual machine 345 may have packets subjected to DPI while packets corresponding to the other virtual machine bypass the DPI module 340 and are not subjected to DPI. Bypassing the DPI module 340 eliminates transmission latency associated with copying packets and enables an administrator to fine-tune a network to the specific needs of each virtual machine 345. “], [Manuguri, claim 7, “wherein packets from a second virtual machine within the first host computer are transmitted without being copied and compared against the policy. “]. Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that the network device identifies that the second data packet is not associated with any policy comprising any DPI identified criteria and in response to refraining from generating and providing a copy of the second data packet to the DPI processor. One would have been motivated to do so in order to optimize network performance and reduce latency for data packets that do not require policy enforcement. As per claim 3, the rejection of claim 1 is incorporated herein. Hu discloses configured to: in response to identifying that the data packet is associated with the policy comprising the DPI-identified criteria ([ Hu, col 5, lines 62-65], “The DPI component 104 receives policy conditions, via the P4 interface, to enable the DPI component 104 to monitor data while taking into account policies provided by the PMF 102. “): setting a flag, indicating that the DPI on the data packet is to be performed, in metadata associated with the data packet ([Hu, col 4, lines 32-36], “The P4 interface allows policy conditions and rules to be shared between the DPI component 104 and the PMF 102. In addition, when certain policy conditions or rules are met with regard to a monitored traffic flow, a trigger is sent “). Hu does not disclose, but Manuguri discloses and in response to the flag being set in the metadata, generating and providing the copy of the data packet to the DPI processor [Manuguri, par 0011, “make a copy of one or more packets of a packet flow between a source and a destination. “]. Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that the data packet is associated with the policy comprising the DPI-identified criteria where the flag is set to indicated the performance of the DPI on the packet and the metadata associated with the packet. Additionally, in response to the flag being set in the metadata, generating and providing a copy of the data packet to the DPI processor as taught by Manuguri. One would have been motivated to do so improve deep packet inspection for specific policy rules. As per claim 4, the rejection of claim 3 is incorporated herein. Hu does not disclose, but Manuguri discloses, configured to: in response to the flag being set: perform an Internet Protocol (IP) flow lookup to identify whether the data packet is associated with existing packets under DPI [Manuguri, par 0016,” In one embodiment, the packets are copied according to a stateful inspection by tracking one or more of Internet Protocol (IP) addresses, port numbers, packet sequence numbers, etc. associated with packets. As such, a consecutive sequence of 10, 50, 100, and/or another number of packets is copied. “]; [Manuguri, par 0018, “In an alternate embodiment, packets are stored and not forwarded until the determination if the copied packet(s) trigger a policy response. “] and when the data packet is associated with a set of existing packets under DPI, aggregate DPI of the data packet with DPI of the set of existing packets under DPI to receive the DPI-identified characteristic of the data packet [Manuguri, par 0017, “For example, consecutive sequences of the first 10 packets, first 50 packets, and first 100 packets of a packet stream may be copied to provide varying levels of context for the data within the packet flow. In one embodiment, entire packets are copied. Alternatively, only a portion of each the packets is copied “]. Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that the response to the flag being set included performing an IP flow lookup to identify whether the data packets are associated with existing packets under DPI and when the data packet is associated with a set of existing packets under DPI, the data is aggregated to receive the DPI characteristic of the data packets as taught by Manuguri. One would have been motivated to do so in order to provide multiple levels of traffic analysis accuracy. As per claim 5, the rejection of claim 1 is incorporated herein. Hu discloses comprising the DPI processor, wherein the network device is configured to: perform, via the DPI processor, the DPI on the data packet. ([Hu, col 3, lines 26-31], “FIG. 1 illustrates a policy-enabled deep packet inspection (DPI) system 100, according to the present invention. The illustrated policy-enabled DPI system 100 includes two main components; namely, a policy management framework 102 and a DPI component 104. “). As per claim 14, the rejection of claim 1 is incorporated herein. Hu discloses, wherein the action of the policy comprises at least one of: logging an indication of the data packet or performing an intrusion detection system (IDS) inspection ([Hu, col 1, lines 30-31], “flagging a suspect packet or packet stream. “). Claim(s) 6-8,10,12,15,16 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Hu (US 8331229 B1, published Dec. 11, 2012) in view of Manuguri (US 20140226478 A1 published Aug.14 2014), further in view of Liu (US 12513022 B2 published Dec. 30, 2025). As per claim 6, the rejection of claim 1 is incorporated herein. Hu discloses and identifying whether any policies having criteria matching the first characteristic of the data packet include the DPI-identified criteria ([Hu, col 6, lines 21-26],” At block 306, the traffic analyzer 118 monitors the data traffic. The traffic analyzer 118 is additionally made aware of any pre-existing policy conditions or rules that are to be applied to the monitored traffic. At block 308, if the traffic analyzer 118 detects that one or more of the policy conditions or rules have been met, “). Hu does not disclose, but Liu discloses configured to: identify whether the data packet is associated with a policy that includes DPI- identified criteria, by: performing at least one of a Layer 2 (L2) lookup or a Layer 3 (L3) lookup on the data packet to identify a first characteristic of the data packet; ([Liu, col 19, lines 47-56], “ For example, the first network device queries the correspondence between the IP address and the EPG information based on the source IP address of the original packet, to obtain the first EPG information corresponding to the source IP address. For another example, the first network device queries the correspondence between the IP address and the EPG information based on the destination IP address included in the original packet, to obtain the second EPG information corresponding to the destination IP address. “), ([Liu, col 21, lines 7-16], “The first network device determines the EPG information based on an interface through which the original packet is received. For example, the first network device stores a correspondence between an interface name and EPG information. After receiving the original packet through an interface, the first network device queries the correspondence between the interface name and the EPG information based on an interface name of the interface, to obtain the EPG information. “). Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so the data packet identified is associated with a policy that includes the DPI identified criteria performing a Layer 2 lookup or a Layer 3 lookup to identify a first characteristic of the data packet as taught by Liu. One would have been motivated to do so in order to improve network traffic management and enhanced packet processing. As per claim 7, the rejection of claim 6 is incorporated herein. Hu does not disclose, but Liu discloses wherein the first characteristic of the data packet comprises a role associated with a source of the data packet. ([Liu, col 2, lines 19-23], “The first EPG information identifies an EPG to which a first computing device belongs, and a source Internet Protocol IP address of the original packet includes an IP address of the first computing device. “). Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that the first characteristic of the data packet comprises a role associated with a source of the data packet as taught by Liu. One would have been motivated to do so in order to improve source tracking, access control, and network security verification. As per claim 8, the rejection of claim 6 is incorporated herein. Hu does not disclose, but Liu discloses configured to: provide, via the network device, to a second network device coupled to the destination, via a virtual extensible local area network (VxLAN) tunnel, metadata associated with the data packet, the metadata indicating the first characteristic of the data packet, enabling the second network device to evaluate whether policy criteria of the second network device is met using the first characteristic of the data packet ([Liu, col 1, lines 37-47], “the source VTEP includes EPG information of the source endpoint device in a virtual extensible local area network (VXLAN) header, and encapsulates the original packet into the VXLAN header to obtain a VXLAN packet. The source VTEP sends the VXLAN packet to a destination VTEP. After receiving the VXLAN packet, the destination VTEP device decapsulates the VXLAN header to obtain the EPG information of the source endpoint device. The destination VTEP executes a group-based policy based on the EPG information of the source endpoint device and EPG information of a destination end. “). Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that a second device is provided and sent a destination via VxLAN tunnel along with the metadata associated with the data packet. Next, the metadata indicating the first characteristic of the data packet, enabling the second network device to evaluate whether policy criteria of the second network device is met using the first characteristic of the data packet as taught by Liu. One would have been motivated to do so in order to improve source tracking, access control, and network security verification. As per claim 15, Hu discloses A network device-implemented method, comprising: receiving, at a network device, a data packet ([Hu, col 5, lines 58-62], “The DPI component 104 is illustrated as being tapped into the Gi interface to monitor data traffic, although this is not necessarily the case. Alternatively, the DPI component 104 could be positioned in-line with the GGSN 116 and the Internet “); the role-to-role policy comprising a DPI component ([Hu, col, 7, lines 56-57], “communicating the policy condition from the policy management framework to a deep packet inspection “). Hu does not disclose, but Liu discloses identifying, via the network device, that deep packet inspection (DPI) conditions are met by the data packet, the DPI conditions comprising: the data packet being associated with a role-to-role policy providing a source role criteria and a destination role criteria ([Liu, col 11, Table 1], “ TABLE 1 Matching condition (rule) EPG information of a EPG information of a source endpoint device destination endpoint device Group based policy “); and DPI of the data packet not being performed elsewhere ([Liu, col 27, lines 36-39 ], “Alternatively, if the bit is not set, it indicates that the IPv6 packet has not been processed according to the group based policy. Optionally, the identifier field is referred to as an “A” bit. “); Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that the deep packet inspection conditions are met by the data packet, with the conditions comprising a data packet being associated with a role-to-role policy providing a source and destination role criteria. The device checks that the DPI is not performed anywhere else as taught by Lui. One would have been motivated do so by ensuring deep packet inspection occurs only at a single, designated point in the network architecture. Hu and Liu do not disclose, but Manuguri discloses in response to identifying that the DPI conditions are met, selectively triggering DPI of the data packet [Manuguri, par 0011, “In particular, embodiments receive a copy of or make a copy of one or more packets of a packet flow between a source and a destination. While or after the one or more packets are forwarded to the destination, the content of the one or more copied packets is compared to a policy to determine if the packet flow triggers a policy response. “]; and sending, via the network device, the data packet to a destination of the data packet [Manuguri, par 0011, “While or after the one or more packets are forwarded to the destination”]. It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu in view of Lui so that the DPI conditions are met selectively triggering Dpi of the data packet and sending the data packet to the destination as taught by Manuguri. One would have been motivated to do so to improve network performance and security by optimizing data inspection with set DPI policies. As per claim 16, the rejection of claim 15 is incorporated herein. Hu does not disclose, but Liu discloses, comprising identifying that the data packet is associated with the role-to-role policy by: identifying a source role associated with a source of the data packet from a header of the data packet ([Liu, col 20, lines 47-50], “For example, the first network device queries the correspondence between the IP address and the EPG information based on the source IP address of the original packet, “); identifying a destination role associated with the destination of the data packet ([Liu, col 20, lines 44-47 ], “the first network device queries the correspondence between the IP address and the EPG information based on an IP address included in the original packet, to obtain the EPG information corresponding to the IP address. “); and determining that the source role criteria is met by the source role and the destination role criteria is met by the destination role ([Liu, col 11, Table 1], “Matching condition (rule) EPG information of an EPG information of a source endpoint device destination endpoint device Group based policy EPG 1 EPG 2 Deny (Deny) EPG 2 EPG 1 Allow (Allow) EPG 3 * Allow (Allow) EPG 4 EPG 5 Redirect (redirect) * EPG 6 Allow (Allow) “). Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that identifying a source and destination role associated with a source and destination of the data packet and the source and destination role criteria is met by the source and destination role as taught by Liu. One would have been motivated to do so in order to improve the routing of the packets and network efficiency. As per claim 19, the rejection of claim 18 is incorporated herein. Hu does not disclose, but Liu discloses wherein the network device is configured to: in response to the DPI being selectively enabled on the data packet, encode, in a header of the data packet, an indication that the DPI is being performed by the DPI processor ([Liu, col 27, lines 61-65], “if an upstream node has executed the group-based policy, the upstream node may identify, by using the identifier field, that the group-based policy has been executed, so that a downstream node does not need to re-execute the group-based policy. “). Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that in response to the DPI being selectively enabled on a data packet, the indication of DPI being performed by the processor is encoded in the header of the packet as taught by Liu. One would have been motivated to do in order to improve network security by thoroughly inspecting packets. Claim(s) 9, 11, 17 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Hu (US 8331229 B1, published Dec. 11, 2012) in view of Manuguri (US 20140226478 A1 published Aug.14 2014) further in view of Zhou (US 9497089 B2 published Nov.15, 2016). As per claim 9 the rejection of claim 1 is incorporated herein, Hu discloses configured to: in response to identifying that the data packet is associated with the policy comprising the DPI-identified criteria ([Hu, col 6, lines 21-26],” At block 306, the traffic analyzer 118 monitors the data traffic. The traffic analyzer 118 is additionally made aware of any pre-existing policy conditions or rules that are to be applied to the monitored traffic. At block 308, if the traffic analyzer 118 detects that one or more of the policy conditions or rules have been met, “). Hu does not disclose, but Zhou discloses cause return flow DPI, by generating, via the network device, a symmetric policy to the policy ([Zhou, col 5, lines 1-8], “set the second reverse identification result carrying flag to be true, where the second reverse identification result carrying flag is used for indicating whether to insert the first identification result in an extension field of a header of a next data packet “). Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu the packet is associated with the policy comprising the DPI criteria, causing return flow DPI, by generating, via the network device, a symmetric policy to the policy as taught by Zhou. One would have been motivated to do so in order to ensure that the data packets are compliant with the set policies ensuring network security. As per claim 10, the rejection of claim 1 is incorporated herein. Hu does not disclose, but Liu discloses configured to: receive, at the network device, a second data packet from a second source different than the network device ([Liu, col 1, lines 37-47], “the source VTEP includes EPG information of the source endpoint device in a virtual extensible local area network (VXLAN) header, and encapsulates the original packet into the VXLAN header to obtain a VXLAN packet. The source VTEP sends the VXLAN packet to a destination VTEP. After receiving the VXLAN packet, the destination VTEP device decapsulates the VXLAN header to obtain the EPG information of the source endpoint device. The destination VTEP executes a group-based policy based on the EPG information of the source endpoint device and EPG information of a destination end. “), the second data packet comprising metadata indicating a role of the second source; identify, via the network device, whether a source role criteria of a role-to-role policy is met based upon the role of the second source indicated by the metadata([Liu, col 11, Table 1], “EPG information of a EPG information of a source endpoint device destination “) ([Liu, col 12, lines 2-3 ], “When EPG information carried in a packet matches the matching condition, “); identify, via the network device, whether a destination role criteria of the role- to-role policy is met based upon a role of a destination of the second data packet known by the network device ([Liu, col 20, lines 44-56 ], “the first network device queries the correspondence between the IP address and the EPG information based on an IP address included in the original packet, to obtain the EPG information corresponding to the IP address. For example, the first network device queries the correspondence between the IP address and the EPG information based on the source IP address of the original packet, to obtain the first EPG information corresponding to the source IP address. For another example, the first network device queries the correspondence between the IP address and the EPG information based on the destination IP address included in the original packet, to obtain the second EPG information corresponding to the destination IP address. “); identify whether the role-to-role policy is fully-qualified based upon the source role criteria of the role-to-role policy and the destination role criteria of the role-to-role policy being met; and in response to identifying that the role-to-role policy is fully-qualified ([Liu, col 12, lines 1-5], “The matching condition is also referred to as a matching rule or a rule. When EPG information carried in a packet matches the matching condition, the network device executes a group-based policy corresponding to the EPG information.”) implement an action specified by the role-to-role policy ([Liu, col 11, Table 1], “Group based policy EPG 1 EPG 2 Deny (Deny) EPG 2 EPG 1 Allow (Allow) EPG 3 * Allow (Allow) EPG 4 EPG 5 Redirect (redirect) * EPG 6 Allow (Allow) “). Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that the second packet source is a different source than the network device along with the data indicating a role of the second source identified by the network device. The network device also identifies whether the source and destination role criteria of a role-to-role policy is satisfied based on the role of the second source indicated by the meta data and verify if the role-to-role policy is fully qualified based on the source and destination criteria. Then implement an action specified by the role-to-role policy as taught by Liu. One would have been motivated to do so in order to improve traffic filtering and policy verification processes. As per claim 11, the rejection of claim 10 is incorporated herein. Hu does not disclose, but Liu discloses configured to: identify that the role-to-role policy is fully-qualified except that the role-to-role policy includes an additional criteria identifiable through DPI ([Liu, col 11, Table 1], “ Matching condition (rule) EPG information of a EPG information of a source endpoint device destination endpoint device Group based policy EPG 1 EPG 2 Deny (Deny) EPG 2 EPG 1 Allow (Allow) EPG 3 * Allow (Allow) EPG 4 EPG 5 Redirect (redirect) * EPG 6 Allow (Allow) “); Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu to identify that the role-to-role policy is qualified except that the role-to-role policy includes an additional criterion identified through DPI as taught by Liu. One would have been motivated to do so ensure efficient secure network traffic management by applying rules based on specific packet roles. Hu and Liu do not disclose, but Zhou discloses and in response to identifying that the role-to-role policy is fully-qualified except that the role-to-role policy includes the additional criteria identifiable through DPI, program an IP flow lookup table to cause DPI for a forward flow associated with the second data packet and a reverse flow associated with the second data packet ([Zhou, col 2, lines 51-53 ], “ a first reverse identification result carrying flag is set in the local flow table and is used for indicating whether the first identification result is inserted “). ([Zhou, col 5, lines 32-38], “second reverse identification result carrying flag is used for indicating whether to insert the first identification result in an extension field of a header of a next data packet received by the identification function network element; “). It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu in view of Liu to program an IP flow lookup table to cause DPI for a forward flow associated with the second data packet and a reverse flow associated with the second data packet as taught by Zhou. One would have been motivated to do so ensure complete and accurate tracking of the flow of data packets in both directions. As per claim 12, the rejection of claim 10 is incorporated herein. Hu discloses trigger DPI on the second data packet ([Hu, col 3, lines 36-39], “a trigger is sent to the PMF 102 which determines (based upon a number of policies), an appropriate enforcement method, such as to allow or disallow certain traffic (e.g., abusive traffic) “). Hu does not disclose, but Liu discloses configured to: identify that the action specified by the role-to-role policy comprises a DPI- dependent action; and in response to identifying that the action specified by the role-to-role policy comprises a DPI-dependent action ([Liu, col 11, Table 1], “ EPG 1 EPG 2 Deny (Deny) EPG 2 EPG 1 Allow (Allow) EPG 3 * Allow (Allow) EPG 4 EPG 5 Redirect (redirect) * EPG 6 Allow (Allow) “), trigger DPI on the second data packet. Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that the action specified by the role-to-role policy comprising a DPI dependent action in response to identifying that the action specified comprises a dependent action triggering a DPI on the second data packet as taught by Liu. One would have been motivated to do so by providing deeper packet inspection for suspicious flow of traffic enhancing network security. As per claim 13, the rejection of claim 10 is incorporated herein. Hu does not disclose, but Liu discloses configured to: identify, based upon data in a header of the second data packet, whether DPI for the second data packet is being performed elsewhere ([Liu, col 27, lines 28-39], “an identifier field is carried in the IPv6 packet to indicate whether a group-based policy has been executed. Specifically, the IPv6 packet includes an identifier field, and the identifier field indicates whether the IPv6 packet has been processed according to a group-based policy corresponding to the EPG information. For example, the identifier field occupies one bit in the IPv6 packet. If the bit is set, it indicates that the IPv6 packet has been processed according to the group-based policy. Alternatively, if the bit is not set, it indicates that the IPv6 packet has not been processed according to the group-based policy. Optionally, the identifier field is referred to as an “A” bit. “); and selectively triggering DPI when identifying that DPI is not being performed elsewhere. ([Liu, col 27, lines 61-65], “if an upstream node has executed the group-based policy, the upstream node may identify, by using the identifier field, that the group-based policy has been executed, so that a downstream node does not need to re-execute the group-based policy. “). Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that based on the header of the second data packet, whether DPI for the second data packet is performed elsewhere, selectively trigging dpi when identifying the DPI is not being performed elsewhere as taught by Liu. One would have been motivated to do so in order to avoid redundant processing and optimize the DPI efficiency. As per claim 17, the rejection of claim 15 is incorporated herein. Hu does not disclose but Zhou discloses, comprising: triggering the DPI of the data packet by programming an internet protocol (IP) flow table with a DPI indication associated with a forward flow and reverse flow of the data packet ([Zhou, col 2, lines 51-53], “a first reverse identification result carrying flag is set in the local flow table and is used for indicating whether the first identification result is inserted “). ([Zhou, col 5, lines 32-38], “second reverse identification result carrying flag is used for indicating whether to insert the first identification result in an extension field of a header of a next data packet received by the identification function network element; “); and encoding a header of the data packet with an indication that DPI is being performed ([Zhou, fig 8a, The figure describes an IPV4 option field header carrying extension information for an ip header]), ([Zhou, fig 8b, The figure describes an extension header field including an IPV6 packet header also carrying extension information]). Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that the ip flow table is programmed with an DPI indication associated with a forward and reverse flow of the data packet including an encoding header of the data packet with an indication that DPI is being performed as taught by Zhou. One would have been motivated to do so ensure complete and accurate tracking of the flow of data packets in both directions. As per claim 20, the rejection of claim 19 is incorporated herein. Hu does not disclose, but Zhou discloses wherein the network device is configured to transmit a return data packet associated with the data packet to a source of the data packet ([Zhou, col 5, lines 31-34 ], “ when the fourth receiving unit receives the response packet, set the second reverse identification result carrying flag to be true “), wherein the return data packet comprises the indication that the DPI is being performed by the DPI processor ([Zhou, col 12, lines 42-44 ], “an identification first packet flag, which is used for marking the first data packet on which deep packet inspection identification is performed in the IP network traffic. “). Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Hu so that the network device is configured to transmit a return packet associated with the data packet to a source of the data packet, wherein the return data packet comprises the indication that the dpi is being performed by the DPI processor as taught by Zhou. One would have been motivated to do so by providing deeper packet inspection for suspicious flow of traffic enhancing network security. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAIPRATAP PREM whose telephone number is (571)270-0894. The examiner can normally be reached Monday - Friday 8 a.m. -4 p.m.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kim Jung can be reached at (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SAIPRATAP PREM/ Examiner, Art Unit 2494 /THEODORE C PARSONS/ Primary Examiner, Art Unit 2494
Read full office action

Prosecution Timeline

Apr 27, 2025
Application Filed
Aug 18, 2026
Non-Final Rejection mailed — §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month