DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Double Patenting
The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on non-statutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-20 are rejected on the ground of non-statutory double patenting as being unpatentable over claims 1-11 and 15 of U.S. Patent No. 10,462,219. Although the claims at issue are not identical, they are not patentably distinct from each other because the examined application claims are anticipated by the reference claims.
Claims 1, 16 and 20 are anticipated by claim 1 of the ‘219 Patent.
Claims 2 and 17 are anticipated by claim 2 of the ‘219 Patent.
Claims 3 and 18 are anticipated by claim 3 of the ‘219 Patent.
Claim 4 is anticipated by claim 15 of the ‘219 Patent.
Claim 5 is anticipated by claim 4 of the ‘219 Patent.
Claim 6 is anticipated by claim 5 of the ‘219 Patent.
Claim 7 is anticipated by claim 5 of the ‘219 Patent.
Claim 8 is anticipated by claim 7 of the ‘219 Patent.
Claim 9 is anticipated by claim 6 of the ‘219 Patent.
Claim 10 is anticipated by claim 7 of the ‘219 Patent.
Claim 11 is anticipated by claim 8 of the ‘219 Patent.
Claim 12 is anticipated by claim 1 of the’219 Patent.
Claim 13 is anticipated by claim 9 of the ‘219 Patent.
Claim 14 is anticipated by claim 10 of the ‘219 Patent.
Claim 15 is anticipated by claim 11 of the ‘219 Patent.
Claim 19 is anticipated by claim 1 of the ‘219 Patent.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-3, 5-11, 14, 16-18 and 20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by U.S. Patent Application Publication 2017/0111446 to Rivera et al.
As concerns claim 1, a computer-implemented method executed by one or more processors comprising:
assigning a first node (Fig. 5; Fig. 7, 770-assign one of unassigned servers to tenant) in a distributed network to a first customer (Fig. 5, 510-first tenant), the first node selected from a set of unassigned nodes that are not assigned to any customer (Fig. 6, 630-unassigned servers);
assigning a second node (Fig. 5; Fig. 7, 770-assign one of unassigned servers to tenant) in the distributed network to a second customer (Fig. 5, 520-second tenant), the second node selected from the set of unassigned nodes, wherein the second node is different than the first node and the second customer is different than the first customer (Fig. 5);
configuring the assigned first node to process network traffic only from the first customer (0005-isolation across tenants; 0024-isolation; 0061-private);
configuring the assigned second node to process network traffic only from the second customer (0005-isolation across tenants; 0024-isolation; 0061-private);
processing, by the assigned first node, network traffic associated with the first customer, wherein the network traffic of the first customer is isolated from the network traffic of the second customer (0005-isolation across tenants; 0007; 0024-isolation; 0061-private); and
processing, by the assigned second node, network traffic associated with the second customer, wherein the network traffic of the second customer is isolated from the network traffic of the first customer (0005-isolation across tenants; 0007; 0024-isolation; 0061-private).
Claim 16 is rejected under the same rationale as claim 1 above.
As concerns claim 20, a system comprising: non-transitory memory (Fig. 1-3) for storing data; and one or more processors (Fig. 1-3) and rejected under the same rational as claim 1 above.
As concerns claim 2, the method of claim 1, further comprising determining that the first customer requires additional processing resources, wherein assigning the first node to the first customer is performed in response to the determination (0062-request from user to create virtual machines within the cloud; provide with computation resources; 0064-allocate specified resources to create virtual machine).
As concerns claim 3, the method of claim 2, further comprising: after assigning the first node to the first customer, determining that the first customer no longer requires the first node; and de-assigning the first node from the first customer including deleting data associated with the first customer from the first node (0062-create, modify or destroy vm/node), and returning the first node to the set of unassigned nodes (Fig. 8, 850, 0011).
As concerns claim 5, the method of claim 1, wherein the first node is a virtual machine instance (Fig. 3; 0035; 0043) executed by a physical computing device (Fig. 5, 515; 0069).
As concerns claim 6, the method of claim 1, wherein the first node is a physical computing device (Fig. 5, 515; 0069).
As concerns claim 7, the method of claim 6, wherein the physical computing device is located on a local network controlled by the first customer (0028; 0037; tenant is using/employing device thus it is located on its network and “controlling” it).
As concerns claim 8, the method of claim 7, further comprising assigning an additional node to the first customer, wherein the additional node is a virtual machine (0064) executed by a physical computing device located on a different network than the first node (0064).
As concerns claim 9, the method of claim 1, wherein the first node is of a particular node type, wherein the particular node type is one of an administrative node (0042; 0051), a web security node, a reporting node, a sandbox node, an uptime node, or a risk assessment node.
As concerns claim 10, the method of claim 9, wherein the first node is of a first node type, and an additional node assigned to the first customer is of a node type different than the first node type (0046-different “type” of operating system platform).
As concerns claim 11, the method of claim 9, wherein the first node is of a first node type, and an additional node assigned to the first customer is also of the first node type (0046-one or more servers of a first “type”).
As concerns claim 14, the method of claim 1, further comprising determining that the first customer requires additional processing resources in a particular geographic location based on at least one request associated with the first customer received from the particular geographic location, wherein assigning the first node to the first customer includes selecting the first node from the set of unassigned nodes based on a proximity of the location of a physical computing device associated with the first node to the particular geographic location (0064-allocated to specific zone).
As concerns claim 17, the non-transitory, computer-readable medium of claim 16, the operations further comprising determining that the first customer requires additional processing resources, wherein assigning the first node to the first customer is performed in response to the determination (0062-request from user to create virtual machines within the cloud; provide with computation resources; 0064-allocate specified resources to create virtual machine).
As concerns claim 18, the non-transitory, computer-readable medium of claim 17, the operations further comprising: after assigning the first node to the first customer, determining that the first customer no longer requires the first node; and de-assigning the first node from the first customer including deleting data associated with the first customer from the first node (0062-create, modify or destroy vm/node), and returning the first node to set of the unassigned nodes (Fig. 8, 850, 0011).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 4, 12, 13, 15 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Patent Application Publication 2017/0111446 to Rivera et al. in view of U.S. Patent No. 8,307,362 to Gong et al.
Rivera et al. ‘446 do not disclose:
As concerns claim 4, the method of claim 1, wherein configuring the assigned first node includes receiving, by the assigned first node, configuration information specific to the first customer only from one or more other nodes assigned to the first customer.
As concerns claim 12, the method of claim 9, wherein the first node is a web security node, and processing the network traffic associated with the first customer includes applying a network policy to the network traffic.
As concerns claim 13, the method of claim 9, wherein the first node is a reporting node, and processing the network traffic associated with the first customer includes storing data associated with the network traffic of the first customer.
As concerns claim 15, the method of claim 1, further comprising: receiving, from a client associated with the first customer, a request to access a multi-tenant user interface; authenticating the client to the multi-tenant user interface using credentials associated with the first customer; receiving a request to access data associated with the first customer from the client via the multi-tenant user interface; and in response to receiving the request from the client via the multi-tenant user interface, generating a request to the first node assigned to the first customer.
As concerns claim 19, the non-transitory, computer-readable medium of claim 16, wherein configuring the assigned first node includes receiving, by the assigned first node, configuration information specific to the first customer only from one or more other nodes assigned to the first customer.
Gong et al. ‘362 teach:
As concerns claims 4 and 19, the invention of claims 1 and 16, wherein configuring the assigned first node includes receiving, by the assigned first node, configuration information specific to the first customer only from one or more other nodes assigned to the first customer (col. 8, line 66-clone vm’s; col. 9, line 41-migrating; col. 8, lines 16-21-customer data center…configuring and deploying virtual machines is known in the field of computer science; cloning will provide “configuration” information to a node within the customer data center, thus node is assigned to customer; see also col. 6, lines 1-3-cloning service provided, lines 25-30-service provided in cloud environment for virtual resources; col. 7, lines 29-38-exchanging data via mirroring between servers; col. 8, lines 20-25- USPN 7,577,722 (col. 9, lines 1-8-cloning, migration) which is incorporated by reference into Gong et al. '262).
As concerns claim 12, the method of claim 9, wherein the first node is a web security node, and processing the network traffic associated with the first customer includes applying a network policy to the network traffic (col. 9, lines 35-39-SLA is an applied network policy).
As concerns claim 13, the method of claim 9, wherein the first node is a reporting node, and processing the network traffic associated with the first customer includes storing data associated with the network traffic of the first customer (col. 8, line 53-col. 9, line 10-tools storing traffic metrics that are tracked and viewed).
As concerns claim 15, the method of claim 1, further comprising: receiving, from a client associated with the first customer, a request to access a multi-tenant user interface (col. 13, lines 13-20);
authenticating the client to the multi-tenant user interface using credentials associated with the first customer (col. 13, lines 20-22-authenticaiton filter-authenticate subscribing users);
receiving a request to access data associated with the first customer from the client via the multi-tenant user interface (col. 13, lines 20-22-authenticaiton filter-authenticate subscribing users); and
in response to receiving the request from the client via the multi-tenant user interface, generating a request to the first node assigned to the first customer (col. 13, lines 20-22-authenticaiton filter-authenticate subscribing users).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to provide the system of Rivera et al. ‘446 with authenticating, network policy and data storage as taught by Gong et al. ‘362, in order to provide data management and network security.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. U.S. Patent Application Publication 2016/0218991 disclose virtual private clouds.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOHN B WALSH whose telephone number is (571)272-7063. The examiner can normally be reached 7:30-3:30 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Christopher L Parry can be reached at 571-272-8328. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JOHN B WALSH/Primary Examiner, Art Unit 2451