DETAILED ACTION
Applicant’s preliminary amendment filed 7/17/2025 has been fully considered.
Claims 1-20 have been examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 2, 4, 6, 12, 14, and 16, it is indefinite what the intended metes and bounds of the claims is. The claims recite “wherein in the …address, and the …information are located after”, it changes the context and makes it indefinite, the address and the location/host information/identifier are located after the prefix/ location/ identifier when the location/host information/identifier are part of the address.
This is not intended to be a complete list of such indefiniteness issues.
The dependent claims included in the statement of rejection but not specifically addressed in the body of the rejection have inherited the deficiencies of their parent claim and have not resolved the deficiencies. Therefore, they are rejected based on the same rationale as applied to their parent claims above.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Suzuki (20140310822), and further in view of Pohja (20070271453).
Regarding claim 1, Suzuki teaches
An access control system, comprising: a first host comprising; a first processor; and a first memory configured to store an instruction, and the first processor is configured to execute the instruction in the first memory to: deploy and start a first service; and send, to a second host, a packet for the first service to access a second service (par.38-44, fig.1, devices accessing services in network according to communication control apparatus and certificate issuance),
wherein a source address of the packet is a first internet protocol version 6 (IPv6) address and a destination port is a first port on the second host, the first IPv6 address comprises a prefix, location information, and host information, the prefix is used to define a type of the first IPv6 address, the location information is used to route the packet, and the host information comprises an identifier of the first host and an identifier of the first service (par.63-76, 176-181, ip addresses comprising different fields for different purposes, routing, identity, use port number to identify service).
Suzuki does not expressly disclose, however, Pohja teaches
the second host comprising; a second processor; and a second memory configured to store an instruction, and the second processor is configured to execute the instruction in the second memory to: deploy and start the second service; control the second service to monitor the first port; receive the packet from the first host; determine that the identifier of the first service comprised in the first IPv6 address matches a security rule of the second service; and transfer the packet to the first port, wherein the security rule of the second service comprises an identifier indicating that access to the second service is allowed (par.60-67, 100-108, 124-136, receive packets address to address/port/service, determine rule).
Therefore, one of ordinary skill in the art would have found it obvious before the effective filing date of the claimed invention to modify Suzuki to use additional access control mechanisms as taught by Pohja.
One of ordinary skill in the art would have been motivated to perform such a modification to further manage efficient access to resources (Pohja, par.1-21, 69-78).
Regarding claims 11 and 20, Suzuki teaches
An access control method, comprising: / A non-transitory computer-readable storage medium, comprising computer program instructions, wherein when the computer program instructions are executed by a computing device cluster, the computing device cluster is enabled to (par.38-44, fig.1, devices accessing services in network according to communication control apparatus and certificate issuance):
receiving, by the second host, a packet from a first host for a first service to access the second service, wherein a source address of the packet is a first internet protocol version 6 (IPv6) address and a destination port is the first port, the first IPv6 address comprises a prefix, location information, and first host information, the prefix is used to define a type of the first IPv6 address, the location information is used to route the packet, and the first host information comprises an identifier of the first host and an identifier of the first service (par.63-76, 176-181, ip addresses comprising different fields for different purposes, routing, identity, use port number to identify service);
Suzuki does not expressly disclose, however, Pohja teaches
deploying and starting, by a second host, a second service; controlling the second service to monitor a first port; receiving, by the second host, a packet from a first host for a first service to access the second service, determining, by the second host, that the identifier of the first service comprised in the first IPv6 address matches a security rule of the second service; and transferring the packet to the first port, wherein the security rule of the second service comprises an identifier indicating that access to the second service is allowed (par.60-67, 100-108, 124-136, receive packets address to address/port/service, determine rule).
Therefore, one of ordinary skill in the art would have found it obvious before the effective filing date of the claimed invention to modify Suzuki to use additional access control mechanisms as taught by Pohja.
One of ordinary skill in the art would have been motivated to perform such a modification to further manage efficient access to resources (Pohja, par.1-21, 69-78).
Regarding claim 2 and 12, Suzuki/Pohja teaches wherein in the first IPv6 address, and the location information are located after the prefix (Suzuki, 72-85, figs.7-10).
Regarding claim 3 and 13, Suzuki/Pohja teaches wherein the location information is from a 37th bit to an 80thbit (Suzuki, 72-85, figs.7-10).
Regarding claim 4 and 14, Suzuki/Pohja teaches wherein in the first IPv6 address, and the host information are located after the location information (Suzuki, 72-85, figs.7-10).
Regarding claim 5 and 15, Suzuki/Pohja teaches wherein the host information is from an 81st bit to a 128thbit (Suzuki, 72-85, figs.7-10).
Regarding claim 6 and 16, Suzuki/Pohja teaches wherein in the host information, and the identifier of the first service are located after the identifier of the first host (Suzuki, 72-85, figs.7-10).
Regarding claim 7 and 17, Suzuki/Pohja teaches wherein the identifier of the first host is from an 81st bit to a 104th bit, and the identifier of the first service is from a 105th bit to a 120thbit (Suzuki, 72-85, figs.7-10).
Regarding claim 8, Suzuki/Pohja teaches wherein the first processor is further configured to: before deploying and starting the first service, receive the identifier of the first service and a security rule of the first service from a network controller, wherein the network controller is configured to manage a service deployed on the first host and a service deployed on the second host, and the security rule of the first service comprises an identifier indicating that access to the first service is allowed (Pohja, 60-67, 100-108).
Regarding claims 9 and 18, Suzuki/Pohja teaches wherein the second processor is further configured to: before deploying and starting the second service, receive an identifier of the second service and the security rule of the second service from a network controller, wherein the network controller is configured to manage a service deployed on the first host and a service deployed on the second host (Pohja, 60-67, 100-108).
Regarding claim 10, Suzuki/Pohja teaches wherein the first processor is configured to: send, to the second host, the packet for the first service to access the second service, wherein the first processor is further configured to: control the first service to set the first IPv6 address as the source address of the packet; control the first service to monitor a second port; and send the packet to the second host through the second port (Suzuki, 63-76, Pohja, 48-65).
Regarding claim 19, Suzuki/Pohja teaches wherein after deploying and starting the second service, the method further comprising: controlling, by the second host, the second service to set a second IPv6 address as a source address of a packet for the second service to access another service, wherein the second IPv6 address comprises a prefix, location information, and second host information, and the second host information comprises an identifier of the second host and the identifier of the second service (Suzuki, 63-76, Pohja, 48-65).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: the remaining references put forth on the PTO-892 form are directed to control access to resources based on IPv6 addressing and grouping, Gage (20160142321), Qian (20120102213), Joshi (11838263), Du (20240007441), Bashandy (20190020583), Townsley (20170302576), Graham-Cumming (9584328), Graham-Cumming (20170171232), Goode (20130343391), Walker (20150207772).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to David García Cervetti whose telephone number is (571)272-5861. The examiner can normally be reached Monday-Friday 8AM-5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, HADI S ARMOUCHE can be reached at (571)270-3618. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/David Garcia Cervetti/Primary Examiner, Art Unit 2409