DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 10/09/2025, 11/10/2025, 4/22/2026, and 6/25/2026 was filed. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Pub.No.: US 2010/0057485 A1 to Luft in view of Patent No.: US 7,890,612 B2 to Todd et al(hereafter referenced to Todd).
Regarding claim 21, Luft discloses “a method of monitoring a connected device for abnormal behavior within a software defined networking (SDN)-enabled local network (monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity. [par.0083]), “comprising: assigning the connected device to a first micronet of the local network based on an initial status of the connected device”( the terms “network” and “bearer network” refer generally to any type of data, telecommunications or other network including, without limitation, data networks (including MANs, PANs, WANs, LANs, WLANs, micronets, piconets, internets, and intranets), hybrid fiber coax (HFC) networks, satellite networks, cellular networks, and telco networks. [par.0080]), “and reassigning, based on the detected abnormal behavior condition, the connected device to a second micronet different from the first micronet.”(evaluate user category [Fig.2/item 208], apply rules or category [Fig.2/item 210]).
Luft does not explicitly disclose “monitoring an operation of the connected device over time; detecting, from the monitoring, an abnormal behavior condition of the connected device; and reassigning, based on the detected abnormal behavior condition, the connected device to a second micronet different from the first micronet.”
However, Todd in an analogous art discloses “monitoring an operation of the connected device over time”(electronic monitoring may be accomplished by fitting a network security device an alarm mechanism (not shown) which would warn of a disconnected cable, so that disconnecting the cable from the communication port 2 or network port 4 would set off an audible or visible alarm, or send a message to a security Supervisor Todd[Col.12/lines 16-21]) ; “detecting, from the monitoring, an abnormal behavior condition of the connected device”(one of the primary methods IE7 uses to detect a malicious website is a client-side whitelist of “safe' websites which is transmitted incrementally from the central Microsoft server Todd[Col.5/lines 1-3]).
Therefore, it would have been obvious to one of ordinary skill in the art at the time the invention was filed to modify Luft’s machine to machine communication services comprising a detection process with Todd’s process to monitor data flow in order to provide additional security. One of ordinary skill in the art would have been motivated to combine because Luft discloses monitoring of M2M client behavior to detect and notify the network operator of abnormal, fraudulent, or malicious activity, Todd discloses a process to monitor data flow, and both are from the same field of endeavor.
Regarding claim 22 in view of claim 21, the references combined disclose “wherein the initial status of the connected device includes strong device credentials” (The user is able to update the URL database 31 and the sensitive information database 32 at any time Todd[Col.11/lines 33-34]).
Regarding claim 23 in view of claim 22, the references combined disclose “wherein the first micronet includes at least one of a new and an existing trust domain of the local network”(the secure server 19 upon notification may optionally inform the holder of the domain name that attempts are being made to redirect traffic that is destined for their site to a malicious site Todd[Col.27/line 14-17]).
Regarding claim 24 in view of claim 22, the references combined disclose “wherein the strong device credentials include at least one certificate” (Record IP, Certificate DNS info Todd[Fig.16/item 172]).
Regarding claim 25 in view of claim 21, the references combined disclose “wherein monitoring the operation of the connected device is executed adaptively over time” (monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity Luft[par.0083]),
Regarding claim 26 in view of claim 25, the references combined disclose “wherein monitoring the operation of the connected device includes fingerprinting” (Complete Site Fingerprinting Todd[Fig.16/item 173]).
Regarding claim 27 in view of claim 25, the references combined disclose “wherein the fingerprinting includes adaptive identification of the connected device for at least one of a device purpose and a device function ”(fingerprint match Todd[Fig.16/item 176]).
Regarding claim 28 in view of claim 21, the references combined disclose “wherein the initial status of the connected device provides a baseline defining normal device behavior, and wherein the detected abnormal behavior condition represents a deviation from the baseline” (monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity. [par.0083]).
Regarding claim 29 in view of claim 21, the references combined disclose “wherein monitoring the operation of the connected device includes analyzing readily visible attributes and patterns of network traffic of the connected device” (monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity. [par.0083]),
Regarding claim 30 in view of claim 21, the references combined disclose “wherein the abnormal behavior condition is detected based on at least one rule or policy of a micronets platform of the local network” (monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity. [par.0083]).
Regarding claim 31 in view of claim 21, the references combined disclose “wherein the abnormal behavior condition includes a missing or obsolete security update”(the more com prehensive firewalls would recognize abnormal traffic pat terns and either block them, or at least inform the user Todd[Col.4/lines 52-54]).
Regarding claim 32 in view of claim 31, the references combined disclose “further comprising reassigning the connected device back to the first micronet upon performance of an up-to-date security update” (monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity. [par.0083]),
Regarding claim 33 in view of claim 21, the references combined disclose “wherein the abnormal behavior condition indicates that the second connected device is (i) compromised, and/or (ii) infected with malware”(the network security device can be employed to continually search for malware such as viruses, spyware or malicious traffic using a combination of virus signatures (similar to those written by security companies) and heuristic analysis Todd[Col.29/lines 45-49]).
Regarding claim 34 in view of claim 21, the references combined disclose “further comprising notifying a separate user device of the detected abnormal behavior condition.” (monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity. [par.0083]),
Regarding claim 35, Luft discloses “a method of organizing first and second connected devices within a software defined networking (SDN)-enabled local network(monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity. [par.0083]), “comprising: assigning the first and second connected devices to a first micronet of the local network representing a first trust domain of the local network( the terms “network” and “bearer network” refer generally to any type of data, telecommunications or other network including, without limitation, data networks (including MANs, PANs, WANs, LANs, WLANs, micronets, piconets, internets, and intranets), hybrid fiber coax (HFC) networks, satellite networks, cellular networks, and telco networks. [par.0080]) and reassigning the compromised second connected device to the segregated second micronet, which enables further operation of the second connected device within local network while preventing the second connected device from compromising the first connected device within the first micronet” (evaluate user category [Fig.2/item 208], apply rules or category [Fig.2/item 210]).
Luft does not explicitly disclose “monitoring operations of the first and second connected devices over time; detecting, from the monitoring, that the operation of the second connected device has been compromised; and generating a segregated second micronet representing a second trust domain of the local network that is isolated from the first trust domain”
However, Todd in an analogous art discloses “monitoring operations of the first and second connected devices over time”(electronic monitoring may be accomplished by fitting a network security device an alarm mechanism (not shown) which would warn of a disconnected cable, so that disconnecting the cable from the communication port 2 or network port 4 would set off an audible or visible alarm, or send a message to a security Supervisor Todd[Col.12/lines 16-21]) ; “detecting, from the monitoring, that the operation of the second connected device has been compromised; and generating a segregated second micronet representing a second trust domain of the local network that is isolated from the first trust domain”(one of the primary methods IE7 uses to detect a malicious website is a client-side whitelist of “safe' websites which is transmitted incrementally from the central Microsoft server Todd[Col.5/lines 1-3]).
Therefore, it would have been obvious to one of ordinary skill in the art at the time the invention was filed to modify Luft’s machine to machine communication services comprising a detection process with Todd’s process to monitor data flow in order to provide additional security. One of ordinary skill in the art would have been motivated to combine because Luft discloses monitoring of M2M client behavior to detect and notify the network operator of abnormal, fraudulent, or malicious activity, Todd discloses a process to monitor data flow, and both are from the same field of endeavor.
Regarding claim 36 in view of claim 35, the references combined disclose “further comprising notifying a separate user device of the compromised second connected device.”(notify secure server Todd[Fig.5/item 55]).
Regarding claim 37 in view of claim 35, the references combined disclose “further comprising analyzing readily visible attributes and patterns of network traffic of the second connected device” (monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity. Luft[par.0083]),
Regarding claim 38 in view of claim 37, the references combined disclose “wherein the abnormal behavior condition is detected based on at least one rule or policy of a micronets platform of the local network” (policy module Tod[Fig.7/item 79]).
Regarding claim 39 in view of claim 35, the references combined disclose “wherein reassigning the compromised second connected device is one of (i) temporary, and (ii) permanent” (monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity. [par.0083]),
Regarding claim 40, Luft discloses “a method of organizing first and second connected devices within a software defined networking (SDN)-enabled local network(monitoring of M2M client behavior can be used to detect and notify the network operator of abnormal, potentially malicious activity. [par.0083]), “comprising: the local network into a first micronet corresponding to a first trust domain and a second micronet corresponding to a second trust domain different from the first trust domain( the terms “network” and “bearer network” refer generally to any type of data, telecommunications or other network including, without limitation, data networks (including MANs, PANs, WANs, LANs, WLANs, micronets, piconets, internets, and intranets), hybrid fiber coax (HFC) networks, satellite networks, cellular networks, and telco networks. [par.0080]), and assigning the first connected device to the first micronet and the second connected device to the second micronet. (evaluate user category [Fig.2/item 208], apply rules or category [Fig.2/item 210]).
Luft does not explicitly disclose orchestrating micronet service delivery within the local network; segmenting, based on the orchestrating.
However, Todd in an analogous art discloses “orchestrating micronet service delivery within the local network; segmenting, based on the orchestrating” (one of the primary methods IE7 uses to detect a malicious website is a client-side whitelist of “safe' websites which is transmitted incrementally from the central Microsoft server Todd[Col.5/lines 1-3]).
Therefore, it would have been obvious to one of ordinary skill in the art at the time the invention was filed to modify Luft’s machine to machine communication services comprising a detection process with Todd’s process to monitor data flow in order to provide additional security. One of ordinary skill in the art would have been motivated to combine because Luft discloses monitoring of M2M client behavior to detect and notify the network operator of abnormal, fraudulent, or malicious activity, Todd discloses a process to monitor data flow, and both are from the same field of endeavor.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL D ANDERSON whose telephone number is (571)270-5159. The examiner can normally be reached Mon-Fri 9am-6pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached at (571) 272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MICHAEL D ANDERSON/ Examiner, Art Unit 2433
/JEFFREY C PWU/ Supervisory Patent Examiner, Art Unit 2433