Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Response to Arguments
Applicant’s arguments with respect to claim(s) have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC §103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim/s 1-5, 7-12, 14-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vajravel (Pub. No. US 2024/0264891) in view of Silakov (Pat. No. US 12,019,504) in further view of Zhao (Pub. No. US 2022/0214902).
Claim 1, 8, 15 Vajravel teaches “a computer-implemented method, executed on a computing device, comprising: collecting data concerning interruptions associated with a plurality of virtual machines ([0024] CPU/memory [0015] Management server 200 can maintain or provide access to a database 202 in which can be stored crash-related information pertaining to secure workspaces on user computing devices that management server 200 manages. [0013] User computing device 100 is shown as having a hypervisor 110 which can allow secure workspaces in the form of virtual machines to be deployed on user computing device 100.; see also [0020]); collecting hardware information concerning one or more nodes hosting the plurality of virtual machines at a time generally contemporaneous with the interruptions of the … virtual machines ([0018] Turning to FIG. 2C, it is now assumed that secure workspace 130 is performing its intended functionality on user computing device 100 such as hosting app 132. Then, at some point and as represented in step 3a, a component running in secure workspace 130 initiates a crash. For example, a kernel-mode component could detect an unrecoverable error and could invoke the KeBugCheckEx API to allow operating system 131 to bring secure workspace 130 down in a controlled manner. However, in step 3b, EPT handler 110a is invoked before operating system 131 handles the crash (e.g., before the KeBugCheckEx functionality is implemented to bring secure workspace 130 down in a controlled manner). [0019] Turning to FIG. 2D, at this point, operating system 131 has stalled secure workspace 130 (e.g., because KeBugCheckEx has been invoked). In step 4 and while secure workspace 130 is in this pre-crash state, EPT handler 110a can gather crash-related information. For example, EPT handler 110a could obtain a memory snapshot of secure workspace 130's memory, could read the state of secure workspace 130's virtual CPU(s), and/or could read the state of user computing device 100's CPU(s). As further examples, EPT handle 110a could also or alternatively capture secure workspace 130's virtual machine control structure (VMCS) region in hypervisor 110, could determine nested virtualization information for hypervisor 110 (e.g., whether hypervisor 110 is running on physical hardware, within a virtual machine, etc.), and/or could capture a disk/memory overlay that hypervisor 110 has created on user computing device 100 for secure workspace 130.); and generating a correlation between interruptions of at least a subset of the plurality of virtual machines and one or more hardware component attributes of the one or more nodes ([0020] Turning to FIG. 2E, in step 5a, EPT handler 110a can send the crash-related information it collected to host agent 160. For example, EPT handler 110a could use IOCTLs to convey this crash-related information to host agent 160. Notably, this crash-related information that EPT handler 110a collects is “pre-crash,” meaning that operating system 131 has not yet implemented its crash handling to bring secure workspace 130 down. In step 5b, host agent 160 can relay the crash-related information it receives from EPT handler 110a to management service 201 which in turn can store the crash-related information in database 202. Although not shown, EPT handler 110a and/or host agent 160 can include information to associate the crash-related information with secure workspace 130 (e.g., one or more identifiers of user computing device 100, secure workspace 130, app 132, etc.).)”.
However, Vajravel may not explicitly teach that the interruptions are of the plurality of virtual machines.
Silakov teaches collecting crash information relating to a plurality of virtual machines such that teaches “the interruptions of the plurality of virtual machines ([Col. 4, Lines 25-41] (12) First, monitoring services are started under the host Operating System of a computer (e.g., computing device 20 shown in FIG. 5) in a cluster, to detect different kinds of problems, for example, at least one of: crashes of binary applications caused by incorrect work with memory; crashes of applications written in interpreted languages; crashes of OS kernel; hardware problems detected and reported by CPU (“Machine Check Exception, MCE”); incorrect requests to graphical subsystem (X11 errors); crashes of processes inside virtual environments (virtual machines and containers); errors in reading or writing data from/to a distributed storage. (13) Once a problem is detected, information is collected, which is required for problem analysis) [Col. 2, Lines 30-39] (12) First, monitoring services are started under the host Operating System of a computer (e.g., computing device 20 shown in FIG. 5) in a cluster, to detect different kinds of problems, for example, at least one of: crashes of binary applications caused by incorrect work with memory; crashes of applications written in interpreted languages; crashes of OS kernel; hardware problems detected and reported by CPU (“Machine Check Exception, MCE”); incorrect requests to graphical subsystem (X11 errors); crashes of processes inside virtual environments (virtual machines and containers); errors in reading or writing data from/to a distributed storage. (13) Once a problem is detected, information is collected, which is required for problem analysis”.)”.
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to apply the teachings of Silakov with the teachings of Vajravel in order to provide a system that teaches interruptions of a plurality of VMs. The motivation for applying Silakov teaching with Vajravel teaching is to provide a system that allows for analysis of additional information pertaining to crashes. Vajravel, Silakov are analogous art directed towards analyzing interruptions. Together Vajravel, Silakov teach every limitation of the claimed invention. Since the teachings were analogous art known at the filing time of invention, one of ordinary skill could have applied the teachings of Silakov with the teachings of Vajravel by known methods and gained expected results.
However, the combination may not explicitly teach the newly added limitations.
Zhao teaches “wherein the correlation indicates an increased interruption rate for virtual machines hosted by a first node of the one or more nodes; and offloading, based on the correlation and the one or more hardware component attributes, one or more virtual machines of the plurality of virtual machines hosted by the first node to a second node of the one or more nodes to mitigate interruption risk ([0105] In operation 704, it can be determined whether a count of a type of exception or fault has exceeded a threshold amount. There can be a different threshold for different types of faults. For example, a count of processor exceptions (i.e. hardware component attributes) may be very low, and count of network faults may be—by comparison to processor faults—much higher before an automatic migration is triggered based upon fault counts. In an embodiment, instead of automatically initiating a migration of the VM based on automatically detected conditions, a notification may be sent to an administrator advising that the VM be migrated based upon detected faults. If any type of fault or exception occurs more times that a threshold value associated with that fault or exception type, then method 700 continues at operation 705 otherwise method 700 ends.).”
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to apply the teachings of Zhao with the teachings of Vajravel, Silakov in order to provide a system that teaches additional details of crash information. The motivation for applying Zhao teaching with Vajravel, Silakov teaching is to provide a system that allows for maintaining execution of a VM. Vajravel, Silakov, Zhao are analogous art directed towards analyzing interruptions. Together Vajravel, Silakov, Zhao teach every limitation of the claimed invention. Since the teachings were analogous art known at the filing time of invention, one of ordinary skill could have applied the teachings of Zhao with the teachings of Vajravel, Silakov by known methods and gained expected results.
Claim 2, 9, 16 the combination teaches the claim, wherein Silakov teaches “The computer-implemented method according to claim 1, wherein collecting data concerning interruptions associated with a plurality of virtual machines includes one or more of: collecting log data associated with each of the plurality of virtual machines following a failure of each respective virtual machine; and collecting crash dump data associated with the interruption of each of the plurality of virtual machines following a failure of each respective virtual machine ([Col. 2, Lines 14-40] (10) Optionally, the logs from the virtual environments include a list of applications, a list of processes and information about crashes. Optionally, the logs on the machine include crashed application logs, general system information and cluster services logs. Optionally, the knowledge base is hosted on a report server. Optionally, the automatic recovery procedure also includes any of removal of damaged files that can prevent correct application work; reboot of host OS or guest OS of a Virtual Machine; intrusion into guest OS; adding new software; removing dangerous files; migration of a virtual environment to another machine in the cluster; and applying a “live” patch for a running process. Optionally, the crash is caused by a management subsystem that manages distributed data chunk storage, and wherein logs are collected for all management subsystems for all nodes of the cluster before applying the automatic recovery procedure. Optionally, the detecting steps detects any of crashes of binary applications caused by incorrect work with memory; crashes of applications written in interpreted languages; crashes of host OS kernel; crashes of Guest OS kernel; hardware problems detected and reported by CPU MCE (Machine Check Exception); incorrect requests to graphical subsystem; crashes of processes inside virtual machines; crashes of processes inside containers; errors in reading or writing data from/to distributed storage.)”.
Rationale to claim 1 is applied here.
Claim 3, 10, 17 the combination teaches the claim, wherein Silakov teaches “the computer-implemented method according to claim 1, wherein the data concerning interruptions associated with the plurality of virtual machines includes one or more of: virtual machine type; virtual machine size; and virtual machine configuration ([Col. 2, Lines 30-40] Optionally, the detecting steps detects any of crashes of binary applications caused by incorrect work with memory; crashes of applications written in interpreted languages; crashes of host OS kernel; crashes of Guest OS kernel; hardware problems detected and reported by CPU MCE (Machine Check Exception); incorrect requests to graphical subsystem; crashes of processes inside virtual machines; crashes of processes inside containers; errors in reading or writing data from/to distributed storage.)”.
Rationale to claim 1 is applied here.
Claim 4, 11, 18 the combination teaches the claim, wherein Vajravel teaches “the computer-implemented method according to claim 1, wherein the hardware information concerning one or more nodes hosting the plurality of virtual machines includes one or more of: an indication of a failure of at least one hardware component; and a state of at least one hardware component ([0019] Turning to FIG. 2D, at this point, operating system 131 has stalled secure workspace 130 (e.g., because KeBugCheckEx has been invoked). In step 4 and while secure workspace 130 is in this pre-crash state, EPT handler 110a can gather crash-related information. For example, EPT handler 110a could obtain a memory snapshot of secure workspace 130's memory, could read the state of secure workspace 130's virtual CPU(s), and/or could read the state of user computing device 100's CPU(s). As further examples, EPT handle 110a could also or alternatively capture secure workspace 130's virtual machine control structure (VMCS) region in hypervisor 110, could determine nested virtualization information for hypervisor 110 (e.g., whether hypervisor 110 is running on physical hardware, within a virtual machine, etc.), and/or could capture a disk/memory overlay that hypervisor 110 has created on user computing device 100 for secure workspace 130.)”.
Claim 5, 12, 19 the combination teaches the claim, wherein Vajravel teaches “The computer-implemented method according to claim 4, wherein the at least one hardware component includes one or more of a processor ([0019] Turning to FIG. 2D, at this point, operating system 131 has stalled secure workspace 130 (e.g., because KeBugCheckEx has been invoked). In step 4 and while secure workspace 130 is in this pre-crash state, EPT handler 110a can gather crash-related information. For example, EPT handler 110a could obtain a memory snapshot of secure workspace 130's memory, could read the state of secure workspace 130's virtual CPU(s), and/or could read the state of user computing device 100's CPU(s). As further examples, EPT handle 110a could also or alternatively capture secure workspace 130's virtual machine control structure (VMCS) region in hypervisor 110, could determine nested virtualization information for hypervisor 110 (e.g., whether hypervisor 110 is running on physical hardware, within a virtual machine, etc.), and/or could capture a disk/memory overlay that hypervisor 110 has created on user computing device 100 for secure workspace 130.), a memory, a storage device, a field programmable gate array (FPGA), a network interface card (NIC), a system-on-chip (SOC), a power supply, a PCIe component, and a graphics processor”.
Claim 7, 14, 20 the combination teaches the claim, wherein Vajravel teaches “the computer-implemented method according to claim 2, wherein generating the correlation between interruptions of at least a subset of the plurality of virtual machines and one or more hardware component attributes includes identifying a correlation between a virtual machine interruption and a specific hardware component failure ([0020] Turning to FIG. 2E, in step 5a, EPT handler 110a can send the crash-related information it collected to host agent 160. For example, EPT handler 110a could use IOCTLs to convey this crash-related information to host agent 160. Notably, this crash-related information that EPT handler 110a collects is “pre-crash,” meaning that operating system 131 has not yet implemented its crash handling to bring secure workspace 130 down. In step 5b, host agent 160 can relay the crash-related information it receives from EPT handler 110a to management service 201 which in turn can store the crash-related information in database 202. Although not shown, EPT handler 110a and/or host agent 160 can include information to associate the crash-related information with secure workspace 130 (e.g., one or more identifiers of user computing device 100, secure workspace 130, app 132, etc.).)”.
Claim/s 6, 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vajravel, Silakov, Zhao in view of Dudai (Pub. No. US 2014/0281664).
Claims 6, 13 the combination may not explicitly teach the limitation.
Dudai teaches “the computer-implemented method according to claim 1, wherein the one or more hardware component attributes includes one or more of a manufacturer of a hardware component ([0026] The information collected by the app error handling module 116 may include the device manufacturer and model, other apps or software running, the operating system version, the error exception the occurred, device settings at the time of crash, and the like.), a model of a hardware component, a generation of a hardware component, and a stock keeping unit (SKU) of a hardware component”.
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to apply the teachings of Dudai with the teachings of Vajravel, Silakov, Zhao in order to provide a system that teaches additional details of crash information. The motivation for applying Dudai teaching with Vajravel, Silakov, Zhao teaching is to provide a system that allows for analysis of additional information for the purposes of design choice. Vajravel, Silakov, Zhao, Dudai are analogous art directed towards analyzing interruptions. Together Vajravel, Silakov, Zhao, Dudai teach every limitation of the claimed invention. Since the teachings were analogous art known at the filing time of invention, one of ordinary skill could have applied the teachings of Dudai with the teachings of Vajravel, Silakov, Zhao by known methods and gained expected results.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to WYNUEL S AQUINO whose telephone number is (571)272-7478. The examiner can normally be reached 9AM-5PM EST M-F.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lewis Bullock can be reached at 571-272-3759. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/WYNUEL S AQUINO/Primary Examiner, Art Unit 2199