Prosecution Insights
Last updated: October 02, 2026
Application No. 18/139,078

EXECUTION OF CONTAINER IMAGES IN A TRUSTED EXECUTION ENVIRONMENT

Final Rejection §103
Filed
Apr 25, 2023
Priority
Dec 14, 2022 — CN PCT/CN2022/138952
Examiner
COYER, RYAN D
Art Unit
2191
Tech Center
2100 — Computer Architecture & Software
Assignee
Intel Corporation
OA Round
2 (Final)
79%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
559 granted / 706 resolved
+24.2% vs TC avg
Strong +20% interview lift
Without
With
+19.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
12 currently pending
Career history
718
Total Applications
across all art units

Statute-Specific Performance

§101
15.0%
-25.0% vs TC avg
§103
37.5%
-2.5% vs TC avg
§102
28.5%
-11.5% vs TC avg
§112
9.6%
-30.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 706 resolved cases

Office Action

§103
DETAILED ACTION This action is in response to an amendment to application 18/139078, filed on 6/18/2026. Claims 1-18 are pending. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-6, 8-10, 12-16, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Arnautov et al., “SCONE: Secure Linux Containers with Intel SGX,” hereinafter “Arnautov,” and USPGPUB 2021/0109775, hereinafter “Shen.” Regarding claim 1, Arnautov discloses “A non-transitory computer-readable medium including instructions that, when executed on a processor, cause the processor to perform operations comprising: retrieving an application image; (see, e.g., Arnautov, pg. 696; “Images are created in a trusted environment (see Figure 7).”) generating a bundle for the application image by mounting an overlay onto the application image, the overlay including library functionality for operating in a trusted execution environment (TEE); (see, e.g., Arnautov, pg. 696; “To create a secure container image, the image creator first builds a SCONE executable of the application. They statically compile the application with its library dependencies and the SCONE library.”; “Next, the image creator uses the SCONE client to create the metadata necessary to protect the file system. The client encrypts specified files and creates a file system (FS) protection file, which contains the message authentication codes (MACs) for file chunks and the keys used for encryption. The FS protection file itself is encrypted and added to the image.”) and providing the bundle for execution in the TEE.” (see, e.g., Arnautov, pg. 696; “After that, the secure image is published using standard Docker mechanisms. SCONE does not need to trust the Docker registry, because the security-relevant parts are protected by the FS protection file.”). Arnautov does not appear to disclose the further limitations “wherein: the bundle comprises integrated library operating system specific artifacts; and the integrated library operating system specific artifacts comprise one or more containers.” However, Shen discloses (at fig. 3 & associated text; para. 36-45) library operating system (“X-LibOS”) containers (“X-Containers”) comprising ‘library operating system specific artifacts’ as claimed. Shen and Arnautov are directed toward secure/trusted computing and therefore are analogous art. On or before the effective filing date of the instant application, one of ordinary skill in the art would have deemed it obvious to try to combine the “X-LibOS” and “X-Containers” of Shen with the trusted execution environment of Arnautov, thereby obtaining the invention of the instant claim. A clear and predictable benefit of so combining would have appeared as the ability to improve the security of software containers. (Shen, para. 4-9). Accordingly, the instant claim is unpatentable over the combination of Arnautov and Shen. Regarding claim 2, the combination of Arnautov and Shen renders obvious “The non-transitory computer-readable medium of claim 1, wherein the operations include determining whether to execute the bundle within a confidential container or a non-confidential container based on configuration settings corresponding to the application image.” (see, e.g., Arnautov, pg. 696; “If the image creator wants to support the composition of a secure Docker image [42], they only sign the FS protection file with their public key, but do not encrypt it. In this way, only its integrity is ensured, permitting additional customization. The confidentiality of the files is assured only after finishing the customization process.”) Regarding claim 3, the combination of Arnautov and Shen renders obvious “The non-transitory computer-readable medium of claim 1, wherein the operations include providing runtime environment-agnostic images to a container registry.” (see, e.g., Arnautov, pg. 696; “We chose to integrate SCONE with Docker because it is the most popular and widely used container platform.” “With SCONE, a secure container consists of a single Linux process that is protected by an enclave, but otherwise it is indistinguishable from a regular Docker container, e.g., relying on the shared host OS kernel for the execution of system calls.”). Regarding claim 4, the combination of Arnautov and Shen renders obvious “The non-transitory computer-readable medium of claim 1, wherein generating the bundle includes performing image service operations.” (see, e.g., Arnautov, pg. 696; fig. 7; “push image” “pull image”). Regarding claim 5, the combination of Arnautov and Shen renders obvious “The non-transitory computer-readable medium of claim 4, wherein the image service operations include at least one of an image pulling operation, a decryption operation, an unpacking operation, and a bundling operation.” (see, e.g., Arnautov, pg. 696; fig. 7; “pull image”). Regarding claim 6, the combination of Arnautov and Shen renders obvious “The non-transitory computer-readable medium of claim 1, wherein the operations further include parsing an application configuration and generating artifacts specific to a program execution environment operating in the TEE.” (see, e.g., Arnautov, pg. 696; “the image creator uses the SCONE client to create the metadata necessary to protect the file system.”). Regarding claim 8, the combination of Arnautov and Shen renders obvious “The non-transitory computer-readable medium of claim 1, wherein the application image is in an open container initiative (OCI) format.” (see, e.g., Arnautov, pg. 696; “A future version of SCONE may use the open container platform [28]”). Regarding claims 9, 12-15, and 18, the instant claims are equivalents of claims 1-3 and 5-6, differing only by statutory class. Accordingly, the rejection of claim 1 applies, mutatis mutandis, to claims 9 and 15; the rejection of claim 2 applies, mutatis mutandis, to claim 18; the rejection of claim 3 applies, mutatis mutandis, to claim 12; the rejection of claim 5 applies, mutatis mutandis, to claim 13; and the rejection of claim 6 applies, mutatis mutandis, to claim 14. Regarding claim 10, the combination of Arnautov and Shen renders obvious “The method of claim 9, wherein the TEE comprises a process-based TEE and wherein the TEE is launched outside of a virtual machine (VM) environment.” (see, e.g., Arnautov, pg. 690; “When executing secure containers, SCONE requires only an SGX-capable Intel CPU, an SGX kernel driver and an optional kernel module for asynchronous system call support.”; “Containers use OS-level virtualization [35] and have become increasingly popular for packaging, deploying and managing services such as key/value stores [46, 23] and web servers [47, 25]. Unlike VMs, they do not require hypervisors or a dedicated OS kernel.”). Regarding claim 16, the combination of Arnautov and Shen renders obvious “The computing node of claim 15, wherein the TEE comprises a process-based TEE and wherein the TEE is launched outside of a virtual machine (VM) environment.” (see, e.g., Arnautov, pg. 690; “When executing secure containers, SCONE requires only an SGX-capable Intel CPU, an SGX kernel driver and an optional kernel module for asynchronous system call support.”; “Containers use OS-level virtualization [35] and have become increasingly popular for packaging, deploying and managing services such as key/value stores [46, 23] and web servers [47, 25]. Unlike VMs, they do not require hypervisors or a dedicated OS kernel.”). Claims 7, 11, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Arnautov and Shen and USPGPUB 2015/0089502, hereinafter “Horovitz.” Regarding claim 7, the combination of Arnautov and Shen renders obvious “The computer-readable medium of claim 1,” but does not appear to disclose the further limitation “wherein the operations are executed inside a virtual machine (VM) environment.” However, Horovitz discloses (at para. 12) “a software-based method to secure the execution of a virtual machine, leveraging processor features that offer strong hardware guarantees regarding memory integrity and confidentiality” which “allows applications within a VM to utilize the same processor features to create protected regions isolated from the guest OS; providing such a capability preserves the isolation of secure applications from all privileged software, consistent with the original motivation for Intel SGX.” Horovitz further discloses (at para. 25) a method wherein an emulator “may emulate the execution of Intel SGX instructions that create or manipulate guest enclaves within the VM.” Horovitz and Arnautov and Shen are directed toward secure/trusted computing and therefore are analogous art. On or before the effective filing date of the instant application, one of ordinary skill in the art would have deemed it obvious to try to combine the VM SGX of Horovitz with the trusted execution environment of Arnautov and Shen, thereby obtaining the invention of the instant claim. A clear and predictable benefit of so combining would have appeared as the ability to run secure containers within a VM, which “allows applications within a VM to utilize the same processor features to create protected regions isolated from the guest OS; providing such a capability preserves the isolation of secure applications from all privileged software, consistent with the original motivation for Intel SGX.” (Horovitz, para. 12). Accordingly, the instant claim is unpatentable over the combination of Horovitz and Arnautov and Shen. Regarding claim 7, the combination of Arnautov and Shen renders obvious “The method of claim 9, wherein the TEE comprises a process-based TEE” (see, e.g., Arnautov, pg. 690; “When executing secure containers, SCONE requires only an SGX-capable Intel CPU, an SGX kernel driver and an optional kernel module for asynchronous system call support.”) but does not appear to disclose the further limitation “and wherein the TEE is launched inside of a virtual machine (VM) environment.” However, Horovitz discloses (at para. 12) “a software-based method to secure the execution of a virtual machine, leveraging processor features that offer strong hardware guarantees regarding memory integrity and confidentiality” which “allows applications within a VM to utilize the same processor features to create protected regions isolated from the guest OS; providing such a capability preserves the isolation of secure applications from all privileged software, consistent with the original motivation for Intel SGX.” Horovitz further discloses (at para. 25) a method wherein an emulator “may emulate the execution of Intel SGX instructions that create or manipulate guest enclaves within the VM.” Horovitz and Arnautov and Shen are directed toward secure/trusted computing and therefore are analogous art. On or before the effective filing date of the instant application, one of ordinary skill in the art would have deemed it obvious to try to combine the VM SGX of Horovitz with the trusted execution environment of Arnautov and Shen, thereby obtaining the invention of the instant claim. A clear and predictable benefit of so combining would have appeared as the ability to run secure containers within a VM, which “allows applications within a VM to utilize the same processor features to create protected regions isolated from the guest OS; providing such a capability preserves the isolation of secure applications from all privileged software, consistent with the original motivation for Intel SGX.” (Horovitz, para. 12). Accordingly, the instant claim is unpatentable over the combination of Horovitz and Arnautov and Shen. Regarding claim 17, the combination of Arnautov and Shen renders obvious “The method of claim 15, wherein the TEE comprises a process-based TEE” (see, e.g., Arnautov, pg. 690; “When executing secure containers, SCONE requires only an SGX-capable Intel CPU, an SGX kernel driver and an optional kernel module for asynchronous system call support.”) but does not appear to disclose the further limitation “and wherein the TEE is launched inside of a virtual machine (VM) environment.” However, Horovitz discloses (at para. 12) “a software-based method to secure the execution of a virtual machine, leveraging processor features that offer strong hardware guarantees regarding memory integrity and confidentiality” which “allows applications within a VM to utilize the same processor features to create protected regions isolated from the guest OS; providing such a capability preserves the isolation of secure applications from all privileged software, consistent with the original motivation for Intel SGX.” Horovitz further discloses (at para. 25) a method wherein an emulator “may emulate the execution of Intel SGX instructions that create or manipulate guest enclaves within the VM.” Horovitz and Arnautov and Shen are directed toward secure/trusted computing and therefore are analogous art. On or before the effective filing date of the instant application, one of ordinary skill in the art would have deemed it obvious to try to combine the VM SGX of Horovitz with the trusted execution environment of Arnautov and Shen, thereby obtaining the invention of the instant claim. A clear and predictable benefit of so combining would have appeared as the ability to run secure containers within a VM, which “allows applications within a VM to utilize the same processor features to create protected regions isolated from the guest OS; providing such a capability preserves the isolation of secure applications from all privileged software, consistent with the original motivation for Intel SGX.” (Horovitz, para. 12). Accordingly, the instant claim is unpatentable over the combination of Horovitz and Arnautov and Shen. Response to Arguments Applicant’s amendments required new grounds of rejection and the previous grounds of rejection are withdrawn. Accordingly, Applicant’s arguments in traversal of the previous grounds of rejection are moot in view of the foregoing new grounds of rejection. Conclusion Applicant's amendment necessitated the new grounds of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to RYAN D. COYER whose telephone number is (571) 270-5306 and whose fax number is (571) 270-6306. The examiner normally can be reached via phone on Monday-Friday 12pm-10pm Eastern Time. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Wei Mui, can be reached on 571-272-3708. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Ryan D. Coyer/Primary Examiner, Art Unit 2191
Read full office action

Prosecution Timeline

Apr 25, 2023
Application Filed
Jun 14, 2023
Response after Non-Final Action
Mar 30, 2026
Non-Final Rejection mailed — §103
Jun 18, 2026
Response Filed
Sep 02, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737164
CROSS-PLATFORM MUTUAL EXCLUSION
2y 4m to grant Granted Sep 15, 2026
Patent 12730612
GENERATION OF CODELETS FOR NETWORK FUNCTIONS BASED ON LARGE LANGUAGE MODEL
2y 3m to grant Granted Sep 08, 2026
Patent 12724589
COMPUTER LANGUAGE AND CODE FOR APPLICATION DEVELOPMENT AND ELECTRONIC AND OPTICAL COMMUNICATION
1y 7m to grant Granted Sep 01, 2026
Patent 12717704
APPLICATION SUBSCRIPTION AUTOMATION AND TEST MANAGEMENT TRACEABILITY
2y 10m to grant Granted Aug 25, 2026
Patent 12712366
COGNITIVE FRAMEWORK FOR IMPROVING RESPONSIVITY IN DEMAND RESPONSE PROGRAMS
3y 1m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
79%
Grant Probability
99%
With Interview (+19.9%)
3y 2m (~0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 706 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month