Prosecution Insights
Last updated: August 18, 2026
Application No. 18/396,401

SECURE EXECUTION OF CONTAINERS

Non-Final OA §101§103
Filed
Dec 26, 2023
Examiner
XU, ZUJIA
Art Unit
2195
Tech Center
2100 — Computer Architecture & Software
Assignee
Dell Products L.P.
OA Round
1 (Non-Final)
69%
Grant Probability
Favorable
1-2
OA Rounds
9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 69% — above average
69%
Career Allowance Rate
126 granted / 183 resolved
+13.9% vs TC avg
Strong +82% interview lift
Without
With
+81.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
17 currently pending
Career history
206
Total Applications
across all art units

Statute-Specific Performance

§101
14.3%
-25.7% vs TC avg
§103
47.3%
+7.3% vs TC avg
§102
2.5%
-37.5% vs TC avg
§112
31.7%
-8.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 183 resolved cases

Office Action

§101 §103
CTNF 18/396,401 CTNF 94032 DETAILED ACTION 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. Claims 1-20 are pending for examination. Claim Rejections - 35 USC § 101 07-04-01 AIA 07-04 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 1 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Step 1, Statutory Category : Yes , the claim 1 is a computer-implemented method that recites a series of steps and therefore falls in the statutory category of a process. Step 2A- Prong 1: Judicial Exception Recited : Yes , the claim recites: “performing the following steps in response to a request to start a container in a container-based environment: generating a set of data corresponding to a sequence of components to be used to start the container in the container-based environment; comparing the generated set of data to a set of trusted data for the sequence of components; and automatically controlling a start of the container based at least in part on a result of the comparing”. As drafted, the claim as a whole recites a method including steps that could be performed in the human mind, but for the recitation of generic computing components. The human mind can easily creating/generating/establishing data corresponding to a sequence of components to be used to start the container in the container-based environment, comparing/determining the generated set of data to a set of trusted data for the sequence of components, and automatically controlling/scheduling/planning a start of the container based at least in part on a result of the comparing. Therefore, but for the recitation of generic computing components, these steps may be a Mental Processes that can be performed in the human mind (including an observation, evaluation, judgment, opinion). Therefore, yes, the claims do recite judicial exceptions. Step 2A- Prong 2: Integrated into a practical Application: No , this judicial exception is not integrated into a practical application. In particular, the claim recites an additional limitations that “wherein the request initiates an execution of a container startup process in a kernel space of an operating system” and “wherein the method is performed by at least one processing device comprising a processor coupled to a memory.” which are directed to Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a generic computer as a tool to perform an abstract idea (see MPEP 2106.05(f)). Accordingly, even in combination, these additional elements do not integrate the abstract idea into a practical application because they not impose any meaningful limits on practicing the abstract idea. Therefore, the claim is directed to the abstract idea. Step 2B: Claim provides an Inventive Concept: No. The additional element “wherein the request initiates an execution of a container startup process in a kernel space of an operating system” and “wherein the method is performed by at least one processing device comprising a processor coupled to a memory.” which are directed to Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a generic computer as a tool to perform an abstract idea (see MPEP 2106.05(f)). These additional elements and combination of the elements does not amount to significant more than the exception itself or provide an inventive concept in Step 2B. For these reasons, there is no inventive concept in the claim, and thus the claim is ineligible . Independent claims 9 and 15 are rejected for the same reason as claim 1 above. Claim 9 further recites “A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device:”. Claim 15 further recites “An apparatus comprising: at least one processing device comprising a processor coupled to a memory”. These additional elements are directed to generic computing components/functions merely applying the abstract idea (MPEP § 2106.05(f)). With respect to the dependent claim 2, the claim elaborates that wherein the container startup process comprises a dynamic module loader (these limitations are directed to Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a generic computer as a tool to perform an abstract idea (see MPEP 2106.05(f))). With respect to the dependent claim 3, the claim elaborates that intercepting the request from the dynamic module loader based at least in part on a software mechanism that injects code into the kernel space from a user space of the operating system (“intercepting the request” which are directed to Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a generic computer as a tool to perform an abstract idea (see MPEP 2106.05(f))). With respect to the dependent claim 4, the claim elaborates that wherein the sequence of components comprises two or more of: the container startup process; a container object management component; a container lifecycle management component; a bridge component between the container-based environment and the container lifecycle management component that decouples containers running in the container-based environment from the container lifecycle management component; a container runtime component; and at least one software image associated with the container (these limitations are attempt to generally link the use of the judicial exception to a particular technological environment or field of use (MPEP 2106.05(h))). With respect to the dependent claim 5, the claim elaborates that wherein: the set of data comprises a first set of hash codes computed for the sequence of components; and the trusted set of data comprises a second set of hash codes previously computed for the sequence of components (these limitations are directed to Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a generic computer as a tool to perform an abstract idea (see MPEP 2106.05(f))). With respect to the dependent claim 6, the claim elaborates that wherein the set of trusted data is stored in a secure hardware component of a host device of the operating system (“stored” which is insignificant extra-solution activity and merely data storing (see MPEP § 2106.05(g)). With respect to the dependent claim 7, the claim elaborates that wherein the automatically controlling comprises: preventing the container from starting in response to determining that the set of data is different than the trusted set of data (“preventing the container from starting” are being treated as part of abstract idea and is analogous to Mental processes, such that concept can be performed in the human mind. In addition, the claim as a whole is a Mental Processes that can be performed in the human mind (including an observation, evaluation, judgment, opinion)). With respect to the dependent claim 8, the claim elaborates that wherein the set of data corresponding to the sequence of components is generated in response to determining that a list of registered containers maintained in the kernel space comprises the container (“generated in response to determining” are being treated as part of abstract idea and is analogous to Mental processes, such that concept can be performed in the human mind. In addition, the claim as a whole is a Mental Processes that can be performed in the human mind (including an observation, evaluation, judgment, opinion)). Dependent claims 10-14 recite the same features as applied to claims 2-6 respectively above, therefore they are also rejected under the same rationale. Dependent claims 16-20 recite the same features as applied to claims 2-6 respectively above, therefore they are also rejected under the same rationale. Claim Rejections - 35 USC § 103 07-20-fti The following is a quotation of pre-AIA 35 U.S.C. 103(a) which forms the basis for all obviousness rejections set forth in this Office action: (a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in section 102, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim s 1-2, 4, 6-7, 9-10, 12, 14-16, 18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Feist et al. (US Pub. 2023/0161867 A1) in view of AMBICHL et al. (US Pub. 2018/0357068 A1) . As per claim 1, Feist teaches the invention substantially as claimed including A computer-implemented method comprising: performing the following steps in response to a start a container in a container-based environment, wherein initiates an execution of a container startup process in a kernel space of an operating system (Feist, [0009] lines 1-5, For virtualization methods such as containers, it is particularly critical that different container instances executed in isolation share the same operating system kernel . For use in a security-critical setting, there is therefore a need for improved monitoring, in particular when starting a container instance ; [0061] lines 1-5, Besides the execution limitations, the runtime environments (e.g. existing devices, hardware, host, kernel versions, configuration of security-critical environment parameters (e.g. sysctls, etc.)) may also be concurrently taken into consideration when forming, or determining, the rights signature FP): generating a set of data corresponding to a sequence of components to be used to start the container in the container-based environment (Feist, [0020] lines 1-3, The steps may also be in the form of phases, or stages, for preparing the required execution limitation or multiple execution limitations; [0023] lines 1-3, A respective hash value may be determined and logged for each execution limitation ; [0024] All the determined hash values may be combined with one another in each such step to form a total value, and the total value and the change therein that arises with each step may be logged; [0025] a hash value may be formed from a file of the log in a first step. Each file change may result in a subsequent step… each step results in a further value being added to the sum of the values. The type of combination (e.g. running hash value) of all the hash values with one another may result in a sequence of the aforementioned steps for preparing the at least one execution limitation; [0026] The total value may be representable or may be represented by a fingerprint) ; comparing the generated set of data to a set of trusted data for the sequence of components (Feist, [0027] The total value may be compared with the corresponding configured permissibility criterion (as a set of trusted data). It is accordingly ascertained whether the permissibility criterion is satisfied ; [0040] ] c) wherein the checking unit compares each logged step with a permissibility criterion configured in the check function) ; and automatically controlling a start of the container based at least in part on a result of the comparing (Feist, [0041] d) a startup unit designed to complete the startup and if necessary the execution of the container instance if the at least one permissibility criterion is satisfied; also see claim 1, a) providing a configurable check function that is performed before and/or while starting up the container instance; b) logging each step for preparing at least one execution limitation required for starting up and/or executing the container instance; checking each logged step using at least one permissibility criterion configured in the check function; and d ) completing a startup and if necessary the execution of the container instance if the at least one permissibility criterion is satisfied , or e) initiating an alerting measure or a measure that counteracts the startup if at least one of the possible permissibility criteria is not satisfied ) ; wherein the method is performed by at least one processing device comprising a processor coupled to a memory (Feist, claim 10, A computer program product, comprising a computer readable hardware storage device having computer readable program code stored therein, said program code executable by a processor of a computer system to implement a method as claimed in claim 1) . Feist fails to explicitly teach when start a container, it is in response to a request to start a container in a container-based environment , wherein the request initiates an execution of a container startup process. However, AMBICHL teaches when start a container, it is in response to a request to start a container in a container-based environment , wherein the request initiates an execution of a container startup process (AMBICHL, Claim 24, The method of claim 22 further comprises receiving , by a kernel of the operating system, a container start request for the given container; starting , by the kernel of the operating system, the given container in response to receiving the container start request and in accordance with the modified parameter in the container configuration data for the given container; detecting, by an injection procedure, start of a given container process). It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to have combined the teaching of Feist with AMBICHL because AMBICHL’s teaching of starting a container based on the received container start request would have provided Feist’s system with the advantage and capability to allow the system to instructing the kernel of the OS for starting the container in order to improving the system performance and efficiency. As per claim 2, Feist and AMBICHL teach the invention according to claim 1 above. AMBICHL further teaches wherein the container startup process comprises a dynamic module loader (AMBICHL, [0076] The process starts with step 601 when the container manager process agent detects that a received trace event indicates preparations to create the file system view of a new container (e.g. step 504 of process depicted in FIG. 5 detected that a received trace event reports the execution of a system call that is only used by a container manager process to set the root file system for a new container). Subsequent step 602 switches the container manager agent process to the context of the starting process. This allows the container manager agent process to examine the resources that will be available for the subsequently started container. More specifically and for a Linux/Docker based environment, step 602 may switch to the mount namespace of the starting container to view the portions of the host file system that will be available for the starting container. Following step 603 checks if the starting container has access to basic functionality required for the automated loading of in-process agents. An example of such basic functionality is the functionality to dynamically load libraries to processes during runtime. For Linux/Docker environments, this may contain checking if the starting container has access to a variant of the library “/lib/Id-linux.so”, as this library provides the functionality to dynamically load libraries . In case decision step 604 determines that access to this basic functionality is not available, the process ends with step 608). As per claim 4, Feist and AMBICHL teach the invention according to claim 1 above. Feist further teaches wherein the sequence of components comprises two or more of : the container startup process; a container object management component; a container lifecycle management component; a bridge component between the container-based environment and the container lifecycle management component that decouples containers running in the container-based environment from the container lifecycle management component; a container runtime component; and at least one software image associated with the container (Feist, [0020] The steps may also be in the form of phases, or stages, for preparing the required execution limitation or multiple execution limitations; [0025] a hash value may be formed from a file of the log in a first step. Each file change may result in a subsequent step comprising the hash value being formed in this way by virtue of the previously formed hash value being concatenated with the hash value of the changed file and then hashed. This may also be referred to as a running hash value. In the case of a hex addition, each step results in a further value being added to the sum of the values. The type of combination (e.g. running hash value) of all the hash values with one another may result in a sequence of the aforementioned steps for preparing the at least one execution limitation; [0021] loads the container images and provides resources for the container instances; [0061] Besides the execution limitations, the runtime environments ( e.g. existing devices, hardware, host, kernel versions, configuration of security-critical environment parameters (e.g. sysctls, etc.)) may also be concurrently taken into consideration when forming, or determining, the rights signature FP). As per claim 6, Feist and AMBICHL teach the invention according to claim 1 above. Feist further teaches wherein the set of trusted data is stored in a secure hardware component of a host device of the operating system (Feist, [0059] a container instance itself is able to check whether it has been started correctly. Container instances may thus e.g. also check whether other container instances with which they interchange data, for example, have been started properly or also run on the execution environment provided for them. Furthermore, the setup of the execution environment of started container instances may also be recorded in so-called platform configuration registers (PCRs) as part of a measured-boot process using a TPM ( trusted platform module ) (as a secure hardware component). The value recorded in said registers may be provided as part of a remote attestation process . As such, e.g. devices on which only permissible execution environments have been set up may be allowed to access a remote service; also see [0060]). As per claim 7, Feist and AMBICHL teach the invention according to claim 1 above. Feist further teaches wherein the automatically controlling comprises: preventing the container from starting in response to determining that the set of data is different than the trusted set of data (Feist, [0060] If the determined rights signature FP is recognized as diverging from the expected rights signature, it is possible to react with different measures. Besides the above-described embodiment in which the container init process is prevented from starting, the event may also be logged, a switching signal may be set, or e.g. the device state may be changed. The measure may also turn out differently, e.g. be purely alerting, depending on the container image or image origin. If a container instance recognizes for example that its execution environment has not been prepared as expected, i.e. is impermissible, it may e.g. refuse execution , or take one of the above measures; also see claim 1). As per claims 9-10, 12 and 14, they are non-transitory processor-readable storage medium claims of claims 1-2, 4 and 6 respectively above. Therefore, they are rejected for the same reasons as claims 1-2, 4 and 6 respectively above. As per claims 15-16, 18 and 20, they are apparatus claims of claims 1-2, 4 and 6 respectively above. Therefore, they are rejected for the same reasons as claims 1-2, 4 and 6 respectively above . 07-22-aia AIA Claim s 3, 11 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Feist and AMBICHL , as applied to claim s 2, 10 and 16 respectively above, and further in view of Park (US Patent. 8,769,672 B2) and Vidrine et al. (US Pub. 2016/0092675 A1) . As per claim 3, Feist and AMBICHL teach the invention according to claim 2 above. Feist and AMBICHL fail to specifically teach intercepting the request from the dynamic module loader based at least in part on a software mechanism that injects code into the kernel space from a user space of the operating system. However, Park teaches intercepting the request based at least in part on a software mechanism that injects code into the kernel space from a user space of the operating system (Park, Col 5 line 63- Col 6, line 2, any suspicious attempt to write to one or more processes using kernel mode OS system calls, where a process is not simply writing to itself, is intercepted and blocked. The memory space used by a process running in the system can be kept free from code injection by user mode malware that could otherwise avoid user mode security programs (for example security program 240 in FIG. 2); Col 2, lines 47-50, A kernel driver is a specific type of software running in kernel mode, typically developed to control software and hardware devices or to provide security both for user mode application programs and the operating system; Claim 4, code programmed to establish a hook to intercept requests for a kernel mode operating system (OS) system call, wherein hooking the kernel mode OS system call comprises replacing a function pointer corresponding to the request). It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to have combined the teaching of Feist and AMBICHL with Park because Park’s teaching of suspicious attempt to write to one or more processes using kernel mode OS system calls, where a process is not simply writing to itself, is intercepted and blocked would have provided Feist and AMBICHL’s system with the advantage and capability to allow the system to control software and hardware devices or to provide security both for user mode application programs and the operating system in order to improving the system performance (see Park, Col 5 line 63- Col 6, line 2). Feist, AMBICHL and Park fail to specifically teach the request from the dynamic module loader. However, Vidrine teaches the request from the dynamic module loader (Vidrine, Fig. 10, 1040, 1042 system call from dynamic linker; [0069] FIG. 11 is a block diagram of indirect access to functions in shuffled virtual memory using a JIT compiled function 1144, according to an embodiment. In one embodiment, in response to a request to resolve a symbol for a shared library, the dynamic linker 1140 can allocate a region of protected virtual memory 1121 in process virtual memory 1020. The dynamic linker 1140 can then load a set of instructions in the protected virtual memory 1121 and cause those instructions to be dynamically compiled just-in-time for execution. The JIT compiled function can then algorithmically derive a function address and return a pointer to the function in the shuffled library clump 1022. In one embodiment, the dynamic linker 1140 can then configure an indirect call 1146 to a shared library function via the compiled JIT function 1144, such that instructions in the shuffled code section clump 1026 can make calls to shared library functions in the shuffled library clump 1022 without direct knowledge of the shuffled function start address; [0074] the dynamic loader can configure an indirect call to the function to enable the requesting process to perform function calls to the requested function). It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to have combined the teaching of Feist, AMBICHL and Park with Vidrine because Vidrine’s teaching of the dynamic loader can configure an indirect call to the function to enable the requesting process to perform function calls would have provided Feist, AMBICHL and Park’s system with the advantage and capability to allow kernel to facilitate an indirect call into the shuffled library clump to access the shared library function without exposing the location of the function in order to improving the system performance and efficiency. As per claim 11, it is a non-transitory processor-readable storage medium claim of claim 3 above. Therefore, it is rejected for the same reasons as claim 3 above. As per claim 17, it is an apparatus claim of claim 3 above. Therefore, it is rejected for the same reasons as claim 3 above . 07-22-aia AIA Claim s 5, 13 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Feist and AMBICHL , as applied to claim s 1, 9 and 15 respectively above, and further in view of Martin (US Pub. 2014/0237255 A1) . As per claim 5, Feist and AMBICHL teach the invention according to claim 1 above. Feist further teaches wherein: the set of data comprises a first set of hash codes computed for the sequence of components (Feist, [0023] A respective hash value may be determined and logged for each execution limitation; [0025] By way of example, a hash value may be formed from a file of the log in a first step. Each file change may result in a subsequent step comprising the hash value being formed in this way by virtue of the previously formed hash value being concatenated with the hash value of the changed file and then hashed. This may also be referred to as a running hash value. In the case of a hex addition, each step results in a further value being added to the sum of the values. The type of combination (e.g. running hash value) of all the hash values with one another may result in a sequence of the aforementioned steps for preparing the at least one execution limitation). Feist and AMBICHL fail to specifically teach the trusted set of data comprises a second set of hash codes previously computed for the sequence of components. However, Martin teaches the trusted set of data comprises a second set of hash codes previously computed for the sequence of components (Martin, [0043] the second decrypted application data as generated at step 514 is used to validate the integrity. The validation of the integrity ensures there has been no tampering of the second encrypted application data in the memory. Step 516, by way of example, computes a hash value by using a cryptographic hash function. Specifically, the second decrypted application data is used to compute a hash value to validate its integrity by using a checksum program, checksum function, cryptographic hash function, or other type of integrity check function. In one embodiment of step 516, includes computing a data value and then comparing it against other previously computed hash values on the computing device or on the trusted source. Comparing this computed data value to other previously computed hash values determines whether there is a corresponding hash value in order to validate the integrity of the application data; please note: sequence of components was taught by Feist). It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to have combined the teaching of Feist and AMBICHL with Martin because Martin’s teaching of comparing the computed hash value with previous hash values would have provided Feist and AMBICHL’s system with the advantage and capability to allow the system to prevent unauthorized use of application and provide a mechanism for security to applications and users of computing devices by reducing malicious tampering with application software (see Martin [0049]). As per claim 13, it is a non-transitory processor-readable storage medium claim of claim 5 above. Therefore, it is rejected for the same reasons as claim 5 above. As per claim 19, it is an apparatus claim of claim 5 above. Therefore, it is rejected for the same reasons as claim 5 above . 07-22-aia AIA Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Feist and AMBICHL , as applied to claim 1 above, and further in view of Fong et al. (US Pub. 2021/0240671 A1) . As per claim 8, Feist and AMBICHL teach the invention according to claim 1 above. Feist further teaches wherein the set of data corresponding to the sequence of components is generated (Feist, [0020] lines 1-3, The steps may also be in the form of phases, or stages, for preparing the required execution limitation or multiple execution limitations; [0023] lines 1-3, A respective hash value may be determined and logged for each execution limitation ; [0024] All the determined hash values may be combined with one another in each such step to form a total value, and the total value and the change therein that arises with each step may be logged; [0025] a hash value may be formed from a file of the log in a first step. Each file change may result in a subsequent step… each step results in a further value being added to the sum of the values. The type of combination (e.g. running hash value) of all the hash values with one another may result in a sequence of the aforementioned steps for preparing the at least one execution limitation; [0026] The total value may be representable or may be represented by a fingerprint) . Feist and AMBICHL fail to specifically teach when generating, it is in response to determining that a list of registered containers maintained in the kernel space comprises the container. However, Fong teaches when generating, it is in response to determining that a list of registered containers maintained in the kernel space comprises the container (Fong, [0049] the container client 214 (or the controller 266) is an example of an executable that may be installed on each host machine 220. The container client 214 may also include a file system that may be registered to the kernel of each of the container host machines. When a request to start a container is made, the container client 214 determines if the container image is already cached on the hose machine 220 (e.g., by examining the local file system or image folder 206). If present, the container orchestration system is ready to execute the container and may be directed to execute the container). It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to have combined the teaching of Feist and AMBICHL with Fong because Fong’s teaching of before processing the startup the container, ensuring the container images is registered would have provided Feist and AMBICHL’s system with the advantage and capability to allow the system to ensuring the required necessary information before starting the container in order to prevent potential system failure and improving the system efficiency. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZUJIA XU whose telephone number is (571)272-0954. The examiner can normally be reached M-F 9:30-5:30 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Aimee J Li can be reached at (571) 272-4169. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ZUJIA XU/Examiner, Art Unit 2195 Application/Control Number: 18/396,401 Page 2 Art Unit: 2195 Application/Control Number: 18/396,401 Page 3 Art Unit: 2195 Application/Control Number: 18/396,401 Page 4 Art Unit: 2195 Application/Control Number: 18/396,401 Page 5 Art Unit: 2195 Application/Control Number: 18/396,401 Page 7 Art Unit: 2195 Application/Control Number: 18/396,401 Page 8 Art Unit: 2195 Application/Control Number: 18/396,401 Page 9 Art Unit: 2195 Application/Control Number: 18/396,401 Page 10 Art Unit: 2195 Application/Control Number: 18/396,401 Page 11 Art Unit: 2195 Application/Control Number: 18/396,401 Page 12 Art Unit: 2195 Application/Control Number: 18/396,401 Page 13 Art Unit: 2195 Application/Control Number: 18/396,401 Page 14 Art Unit: 2195 Application/Control Number: 18/396,401 Page 15 Art Unit: 2195
Read full office action

Prosecution Timeline

Dec 26, 2023
Application Filed
May 18, 2026
Non-Final Rejection mailed — §101, §103
Aug 17, 2026
Examiner Interview Summary
Aug 17, 2026
Applicant Interview (Telephonic)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12625722
Semantic-Aware Workflow Creation and Execution
4y 3m to grant Granted May 12, 2026
Patent 12602249
Hardware Resource Allocation System for Allocating Resources to Threads
4y 11m to grant Granted Apr 14, 2026
Patent 12541397
THREAD MANAGEMENT
3y 11m to grant Granted Feb 03, 2026
Patent 12504983
SUPERVISORY DEVICE WITH DEPLOYED INDEPENDENT APPLICATION CONTAINERS FOR AUTOMATION CONTROL PROGRAMS
4y 0m to grant Granted Dec 23, 2025
Patent 12498971
COMPUTING TASK SCHEDULING METHOD AND APPARATUS, ELECTRONIC DEVICE, AND READABLE STORAGE MEDIUM
1y 5m to grant Granted Dec 16, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
69%
Grant Probability
99%
With Interview (+81.6%)
3y 4m (~9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 183 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month