Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This is the initial office action has been issued in response to patent application, 19/205767, filed on 12 May 2025 with a provisional date of 01 July 2020. Claims 1-20, as originally filed, are currently pending and have been considered below.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20:
With respect to claims 1, 12, 17, claims 1-20 are directed to a method/system/processor being configured to perform some functions/steps. To one of ordinary skill in the art all the functions/steps cited in claims 1, 12, 17 may be reasonably implemented as software routines. Applicants specifications state, “Various functions described herein as being performed by entities may be carried out by hardware, firmware, and/or software.” (0020), “each block of methods 300, 400, and 500 described herein, comprises a computing process that may be performed using any combination of hardware, firmware, and/or software” (0039). When interpreted broadly as software routines, claims 1, 12, 17 does not cite any claim elements for performing the functions wherein the claimed elements of the system are limited to a machine or a physical part of a device within the meaning of 35 U.S.C. 101. It appears the functions/steps do not explicitly mention hardware components doing any one of the functions/steps in the system claims. Accordingly, claims 1, 12, 17 to recite statutory subject matter as defined in 35 U.S.C. 101.
With respect to claims 2-11, 13-16, and 18-20 , claims 2-11, 13-16, and 18-20 are rejected for the same analysis above and dependent on claims 1, 12, 17.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1, 2, 4-9, 12, 13, 15-18, 20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Baliga et al. (US2016/0308837 A1, publish date 10/20/2016).
Claims 1, 12:
With respect to claims 1, 12, Baliga et al. disclose a computer-implemented method/system (communication system 100 that includes an Internet Protocol (IP) network 102 (e.g., an external packet switched network, the Internet, X.25, a WiMax network, etc.) and a wireless mobile network 104, 0025) (Figure 1) (Through the use of separate isolated VPMNs, provide enhanced security. Thus, a compromise on a first VPMN and/or a wireless mobile network cannot propagate to other VPMNs because the VPMNs are logically separate, 0023) comprising:
one or more processors (The VPMN controller 116 may also assign and/or configure specific interfaces, switches, and/or processors within the network elements 108-112 and 210-214 to host the VPMN 202, 0052, Figure 1)
(the processor platform P100 can be implemented by one or more general-purpose processors, processor cores, microcontrollers, etc, 0106, Processor P105, Figure 9) to perform operations including:
determining that one or more first network communications associated with a device use a first network communication protocol format (VPMN may include security protocols and/or security tools that are not implemented in a wireless mobile network for communications, 0022) (security rules for the wireless mobile network 104 that include security event profiles that specify security events associated with potentially problematic communications, 0039) (some client administrators may only be concerned with malicious network worms and denial of service attacks for their respective VPMNs while other client administrators are concerned with malicious applications, unsupported mobile devices, and/or unsecure mobile devices for their respective VPMNs, 0040);
based at least on determining the one or more first network communications use
the first network communication protocol format, configuring one or more security rules (To receive requests for a VPMN, the example communication system 100 of FIG. 1 includes a Mobility-as-a-Service (Maas) portal 120. The MaaS portal 120 enables clients to specify requirements (e.g., security rules) for a VPMN. 0034) to assign one or more network communication channels of the device (In response to the client administrator 122 requesting a VPMN, the MaaS portal 120, via the VPMN controller 116, establishes a VPMN through the network elements 108-112, 0036)
to one or more isolated portions of a network with respect to one or more other devices on the network (Through the use of separate isolated VPMNs, provide enhanced security. Thus, a compromise on a first VPMN and/or a wireless mobile network cannot propagate to other VPMNs because the VPMNs are logically separate, 0023) (to create a VPMN (e.g., a security VPMN) to isolate potentially problematic communications (and/or identified problematic communications) originating from, for example, the mobile device 106, 0033); and
routing, according to the one or more security rules (The IP network 102 utilizes and/or conforms to any routing and/or communication protocols, 0025),
one or more second network communications associated with the device through the one or more network communication channels assigned to the one or more isolated portions of the network (the eNodeB 108 transforms wireless communications received from the mobile device 106 into a wired communications that may be routed to the IP network 102, 0028)(the PDN gateway 112 transforms and/or converts communications originating from the mobile device 106 received via the serving gateway 110 into an appropriate packet data protocol (PDP) format (e.g., IP, X.25, etc.) for propagation through the IP network 102, 0032) (The APN enables communications from identified mobile devices to be routed through the wireless mobile network 104 via a VPMN, 0036) (the security VPMN may propagate the communications associated with the mobile device 106 through the wireless mobile network 104 to the IP network 102 separate and/or isolated from other communications from other mobile devices, 0043).
Claims 2, 13, 18:
With respect to claims 2, 13, 18, Baliga et al. disclose wherein the configuring the one or more security rules includes creating one or more access-control-list (ACL) entries that map a device identifier of the device to the one or more isolated portions of the network (The request for a VPMN may include a list of mobile devices that are to be authorized to access the VPMN, 0035) (After detecting potentially problematic communications, the VPMNs and/or the network elements 108-112 broadcast information about the security event and/or an identifier of a mobile device associated with the security event to other VPMNs, 0041) (the security event profile 602 may include a list of device identifiers and/or addresses known to be associated with the Virus XXX, 0069, Figure 6).
Claims 4, 15:
With respect to claims 4, 15, Baliga et al. disclose wherein the one or more isolated portions of the network include at least one of:
a Virtual Local Area Network (VLAN),
a subnetwork of an internal network,
a Virtual Private Network (VPN),
a micro-VPN, or
a separate processing space within a network device, the separate processing space
being configured to handle network traffic associated with the device independently from network traffic associated with the one or more other devices (VPMN controller 116 that a client accesses via the IP network 102, wireless mobile network 104 of FIG. 1 with VPMNs 202 and 204, Figure 1) (transmit a second communication through the virtual private mobile network securely isolated from other portions of the wireless network., 0010) (Through the use of separate isolated VPMNs, provide enhanced security. Thus, a compromise on a first VPMN and/or a wireless mobile network cannot propagate to other VPMNs because the VPMNs are logically separate, 0023).
Claims 5, 16:
With respect to claims 5, 16, Baliga et al. disclose wherein the configuring the one or more security rules includes assigning one or more network interfaces of the device to the one or more isolated portions of the network, the one or more network interfaces including at least one of a computer port, a network port, or a socket (interface circuit P130 may be implemented by any type of interface standard, such as an external memory interface, serial port, general-purpose input/output, etc 0109).
Claim 6:
With respect to claim 6, Baliga et al. disclose wherein the one or more security rules are configured to prevent the one or more other devices from accessing the one or more network communication channels (The security protocols and/or analysis tools analyze, diagnose, filter, block, and/or monitor potentially problematic communications and/or identified problematic communications, 0022) (the separation of the control and/or data planes of the network elements 210-214 via the VPMN 202 prevents security issues in, for example, the VPMN 202 from propagating to other portions of the network elements 108-112 and 210-214, 0054) (the security VPMN 204 may block communications from the mobile device 506 from accessing the content server 510, thereby preventing the communications from affecting the content server 510, 0067).
Claim 7:
With respect to claim 7, Baliga et al. disclose further including, based at least on associating the one or more second network communications with the one or more security rules (security rules for the wireless mobile network 104 that include security event profiles that specify security events associated with potentially problematic communications, 0039):
creating the one or more isolated portions of the network (Through the use of separate isolated VPMNs, provide enhanced security. Thus, a compromise on a first VPMN and/or a wireless mobile network cannot propagate to other VPMNs because the VPMNs are logically separate, 0023) (to create a VPMN (e.g., a security VPMN) to isolate potentially problematic communications (and/or identified problematic communications) originating from, for example, the mobile device 106, 0033); and
performing the routing using the created one or more isolated portions of the
network (the eNodeB 108 transforms wireless communications received from the mobile device 106 into a wired communications that may be routed to the IP network 102, 0028)(the PDN gateway 112 transforms and/or converts communications originating from the mobile device 106 received via the serving gateway 110 into an appropriate packet data protocol (PDP) format (e.g., IP, X.25, etc.) for propagation through the IP network 102, 0032) (The APN enables communications from identified mobile devices to be routed through the wireless mobile network 104 via a VPMN, 0036) (the security VPMN may propagate the communications associated with the mobile device 106 through the wireless mobile network 104 to the IP network 102 separate and/or isolated from other communications from other mobile devices, 0043)
Claim 8:
With respect to claim 8, Baliga et al. disclose wherein the routing the one or more second network communications comprises routing the one or more second network communications to the device based at least on the one or more second network communications being addressed to the device (serving gateway 110 receives communications from the mobile devices 502-504, determines the communications are addressed to the content server 510, and routes the communications to the local PDN gateway 508., 0067) (network manager 706 allocates a control plane by, for example, designating a portion of IP address space that is to be associated with a VPMN. The portion of the IP address space may be referenced to an assigned APN., 0079) (control plane configure 710 may configure a VPMN in a control plane of a network element by updating routing and/or forwarding tables with an IP address space and/or an APN for communications associated with a VPMN., 0085).
Claim 9:
With respect to claim 9, Baliga et al. disclose wherein the configuring the one or more security rules is based at least on identifying the first network communication protocol format in a data store including a listing of communication protocol formats associated with a corresponding security rule configuration (VPMN may include security protocols and/or security tools, 0022) (The IP network 102 utilizes and/or conforms to any routing and/or communication protocols., 0025) (the security VPMN may analyze the communications to identify the security event and determine a resolution (e.g., a defense strategy) to the security event, the security VPMN may propagate the communications associated with the mobile device 106 through the wireless mobile network 104 to the IP network 102 separate and/or isolated from other communications from other mobile devices, 0043).
Claim 17:
With respect to claim 17, Baliga et al. disclose at least one processor (The VPMN controller 116 may also assign and/or configure specific interfaces, switches, and/or processors within the network elements 108-112 and 210-214 to host the VPMN 202, 0052, Figure 1) (the processor platform P100 can be implemented by one or more general-purpose processors, processor cores, microcontrollers, etc, 0106, Processor P105, Figure 9) comprising:
one or more circuits to route, using one or more security rules (The IP network 102 utilizes and/or conforms to any routing and/or communication protocols, 0025),
one or more first network communications associated with a device through one or more network communication channels assigned to one or more isolated portions of a network with respect to one or more other devices on the network (the eNodeB 108 transforms wireless communications received from the mobile device 106 into a wired communications that may be routed to the IP network 102, 0028)(the PDN gateway 112 transforms and/or converts communications originating from the mobile device 106 received via the serving gateway 110 into an appropriate packet data protocol (PDP) format (e.g., IP, X.25, etc.) for propagation through the IP network 102, 0032) (The APN enables communications from identified mobile devices to be routed through the wireless mobile network 104 via a VPMN, 0036) (the security VPMN may propagate the communications associated with the mobile device 106 through the wireless mobile network 104 to the IP network 102 separate and/or isolated from other communications from other mobile devices, 0043) (Through the use of separate isolated VPMNs, provide enhanced security. Thus, a compromise on a first VPMN and/or a wireless mobile network cannot propagate to other VPMNs because the VPMNs are logically separate, 0023) (to create a VPMN (e.g., a security VPMN) to isolate potentially problematic communications (and/or identified problematic communications) originating from, for example, the mobile device 106, 0033), the routing being based at least on one or more second network communications associated with the device having been received in a first network communication protocol format (To receive requests for a VPMN, the example communication system 100 of FIG. 1 includes a Mobility-as-a-Service (Maas) portal 120. The MaaS portal 120 enables clients to specify requirements (e.g., security rules) for a VPMN. 0034) (VPMN may include security protocols and/or security tools that are not implemented in a wireless mobile network for communications, 0022) (security rules for the wireless mobile network 104 that include security event profiles that specify security events associated with potentially problematic communications, 0039) (some client administrators may only be concerned with malicious network worms and denial of service attacks for their respective VPMNs while other client administrators are concerned with malicious applications, unsupported mobile devices, and/or unsecure mobile devices for their respective VPMNs, 0040).
Claim 20:
With respect to claim 20, Baliga et al. disclose wherein the at least one processor is
comprised in at least one of a hub, a repeater, a bridge, a switch, a router, a gateway, or a bridge router (The IP network 102 includes any number and/or types of routers, switches, servers, etc. to enable communications (e.g., packet-based data), 0025).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 3, 10, 11, 14, 19 are rejected under 35 U.S.C. 103 as being unpatentable over Baliga et al. (US2016/0308837 A1, publish date 10/20/2016) in view of Rong et al. (US2019/0356630 A1, publish date 11/21/2019).
Claims 3, 14, 19:
With respect to claims 3, 14, 19, Baliga et al. disclose wherein the one or more isolated portions of the network include one or more first virtual local-area networks (VLANs) of the network and the one or more other devices are included in one or more second VLANs of the network (VPMN controller 116 that a client accesses via the IP network 102, wireless mobile network 104 of FIG. 1 with VPMNs 202 and 204, Figure 1).
Rong et al. teaches wherein the one or more isolated portions of the network include one or more first virtual local-area networks (VLANs) of the network and the one or more other devices are included in one or more second VLANs of the network (Transport agent 130 is an encoding value used to denote the overlay protocol type that is used for tenant isolation, e.g., VLAN, VXLAN, DOVE, NVGRE, STT, etc. 0089) (Figure 5).
Baliga et al. and Rong et al. are analogous art because they are from the same field of endeavor of Communication protocols.
It would have been obvious to one skilled in the art before the effective filing date of the claimed invention to use Rong et al. in Baliga et al. to provide the flexibility required for multi-tenant support and addresses the issue of address isolation for different tenants in a more efficient manner than current systems and issues between different encapsulation protocols for multi-tenant isolation (e.g., VLAN, VXLAN, DOVE, NVGRE, STT, etc.) is alleviated. (see Rong et al. 0006, 0012, 0106)
Claim 10:
With respect to claim 10, Baliga et al. disclose the limitations of claim 1, as addressed.
Baliga et al. disclose configuring one or more security rules:
identifying, from the one or more first network communications, a protocol version
corresponding to the first network communication protocol format; and
determining, based at least on the identifying, that the protocol version is
associated with a corresponding security rule configuration (the PDN gateway 112 transforms and/or converts communications originating from the mobile device 106 received via the serving gateway 110 into an appropriate packet data protocol (PDP) format (e.g., IP, X.25, etc.) for propagation through the IP network 102, 0032) (VPMN may include security protocols and/or security tools that are not implemented in a wireless mobile network for communications, 0022) (security rules for the wireless mobile network 104 that include security event profiles that specify security events associated with potentially problematic communications, 0039) (some client administrators may only be concerned with malicious network worms and denial of service attacks for their respective VPMNs while other client administrators are concerned with malicious applications, unsupported mobile devices, and/or unsecure mobile devices for their respective VPMNs, 0040).
Rong et al. teaches wherein the configuring the one or more security rules is
based at least on:
identifying, from the one or more first network communications, a protocol version
identifier corresponding to the first network communication protocol format; and
determining, based at least on the identifying, that the protocol version identifier is
associated with a corresponding security rule configuration (Transport agent 130 is an encoding value used to denote the overlay protocol type that is used for tenant isolation, e.g., VLAN, VXLAN, DOVE, NVGRE, STT, etc. 0089) (VAPs can be physical ports or virtual ports identified through logical interface identifiers, such as VLAN ID or internal vSwitch Interface ID connected to a virtual machine (VM). 0092).
Baliga et al. and Rong et al. are analogous art because they are from the same field of endeavor of Communication protocols.
It would have been obvious to one skilled in the art before the effective filing date of the claimed invention to use Rong et al. in Baliga et al. to provide the flexibility required for multi-tenant support and addresses the issue of address isolation for different tenants in a more efficient manner than current systems and issues between different encapsulation protocols for multi-tenant isolation (e.g., VLAN, VXLAN, DOVE, NVGRE, STT, etc.) is alleviated. (see Rong et al. 0006, 0012, 0106)
Claim 11:
With respect to claim 11, Baliga et al. disclose the limitations of claim 1, as addressed.
Baliga et al. disclose wherein the configuring the one or more security rules is based at least on determining that the first network communication protocol format (the PDN gateway 112 transforms and/or converts communications originating from the mobile device 106 received via the serving gateway 110 into an appropriate packet data protocol (PDP) format (e.g., IP, X.25, etc.) for propagation through the IP network 102, 0032) (VPMN may include security protocols and/or security tools that are not implemented in a wireless mobile network for communications, 0022) (security rules for the wireless mobile network 104 that include security event profiles that specify security events associated with potentially problematic communications, 0039) (some client administrators may only be concerned with malicious network worms and denial of service attacks for their respective VPMNs while other client administrators are concerned with malicious applications, unsupported mobile devices, and/or unsecure mobile devices for their respective VPMNs, 0040).
Rong et al. teaches wherein the configuring the one or more security rules is
based at least on determining that the first network communication protocol format is absent from a list of permitted communication protocol formats (Transport agent 130 is an encoding value used to denote the overlay protocol type that is used for tenant isolation, e.g., VLAN, VXLAN, DOVE, NVGRE, STT, etc. 0089) (VAPs can be physical ports or virtual ports identified through logical interface identifiers, such as VLAN ID or internal vSwitch Interface ID connected to a virtual machine (VM). 0092)
Baliga et al. and Rong et al. are analogous art because they are from the same field of endeavor of Communication protocols.
It would have been obvious to one skilled in the art before the effective filing date of the claimed invention to use Rong et al. in Baliga et al. to provide the flexibility required for multi-tenant support and addresses the issue of address isolation for different tenants in a more efficient manner than current systems and issues between different encapsulation protocols for multi-tenant isolation (e.g., VLAN, VXLAN, DOVE, NVGRE, STT, etc.) is alleviated. (see Rong et al. 0006, 0012, 0106)
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure, see PTO Form 892.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Helai Salehi whose telephone number is 571-270-7468. The examiner can normally be reached on Monday - Friday from 9 am to 5 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Jeff Pwu, can be reached on 571-272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HELAI SALEHI/Examiner, Art Unit 2433
/JEFFREY C PWU/Supervisory Patent Examiner, Art Unit 2433