Notice of Pre-AIA or AIA Status
present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This is in response to the amendments filed 01/21/2026 . Claims 1, 8, 15 and 17-20 have been amended. Claims 1-20 are pending and have been considered below.
Priority
Acknowledgment is made of no claim of foreign priority.
Drawings
The drawings filed on 12/29/2023 are accepted.
Specification
The specification filed on 12/29/2023 is accepted.
Response to Arguments
Applicant's arguments remarks pages 6-7 with respect to “Claim Rejections - 35 USC § 101” have been fully considered but they are not persuasive because: the claims are directed to collecting information, analyzing information and generating results certain method of organizing Human activity such a mental processes category. The step amount to : data gathering (adding metadata, receiving image), data analysis (scanning and mapping), data output (assigning a remediation) such operations constitute an abstract ideas. The claims recite generic computing components(“first software”, “second software”, “host”, “cloud”, container security agent”, “container security monitor”. The claims do not improve the functionality of a computer or container technology itself. There is no specific technological improvement, no new container image structure, no new scanning technique and no unconventional architecture. Therefore the rejection has been maintained.
Applicant’s arguments remarks page 7, with respect to“ Claim Rejections - 35 USC § 112” have been fully considered and are persuasive. The rejection has been withdrawn in view of the amendments to the claims has been withdrawn.
Applicant's arguments remarks pages 7-8 with respect to “Claim Rejections - 35 USC § 103” have been fully considered but they are not persuasive because: The applicant specification teaches see paragraph 18” During container image creation or editing, container security agent 112 collects auth data for the user (e.g., username, group name, and like type identity information). Container security agent 112 stores metadata in container images that includes auth data,” and paragraph 22 further teaches “container security agent 112 adds auth data for the user as metadata to the container”(emphasis added), Levin also teaches see paragraph 23” The indexed metadata for an image layer includes at least the unique cryptographic signature, tags, and timestamps of the image layer. The indexed metadata may be stored in a database acting as a central repository. The new metadata indicates contextual information related to the addition or use of the image layer such as, but not limited to, the user that pushed an image of the image layer (e.g., a user name of the user), job name, environment, and the like.” Which meets the limitations of “embedding user-associated metadata into the container image”.
Claim Rejections - 35 USC § 101
U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20: the claims are directed to an abstract idea without significantly more. The claims recite the limitations of adding metadata associated with a user to the container image, receiving the container image; scanning the container image to identify a software vulnerability; generating a mapping between the metadata and the software vulnerability; and assigning a remediation action to remediate the container image based on the mapping”. Such mental observations or evaluations fall within the mental processes grouping of abstract ideas. This judicial exception is not integrated into a practical application. In particular, the claim only recites one additional element – using a first software or a second software to perform the adding, the receiving, the scanning, the generating and the assigning steps. The processor is recited at a high-level of generality (i.e., as a generic processor performing a generic computer function of (adding, the receiving, the scanning, the generating and the assigning) such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a first software or a second software to perform the adding, the receiving, the scanning, the generating and the assigning steps amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claim is not patent eligible.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-4, 6-11, 13-16 and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Pieczul U.S. 2023/0252157 A1 in view of Levin et al U.S. 2020/0012818 A1in further view of Gupta et al U.S. 2024/0427901 A1.
Claims 1 and 8: Pieczul teaches method of managing a container image in a computing system (par.5, 46), comprising:
a non-transitory computer readable medium comprising instructions to be executed in a computing device to cause the computing device to carry out a method a method of managing a container image in a computing system (par.5,46, non-transitory computer-readable storage media storing programs, code, or instructions executable by one or more processors), comprising
adding, by first software (container image information reader ) executing on a host, metadata (stacked software layers) par.45-46, 70, using the container image information reader subsystem 112, container images and associated metadata 102 from a memory accessible to the VAS 110 and determine information identifying the container image and metadata associated with the container image. marking the container image for scanning by the container images scanner or otherwise transmitting a signal to the container images scanner to scan the container image to generate container images scan results for the container image);
receiving, by the first software or second software (container images scanner), the container image (par. 45-46. marking the container image for scanning by the container images scanner or otherwise transmitting a signal to the container images scanner to scan the container image to generate container images scan results for the container image);
scanning, by the first software or the second software, the container image to identify a software vulnerability the container image to identify a software vulnerability (par. 45-46, the container images scanner to scan the container image to generate container images scan results for the container image, par 67-70, further teaches calculating vulnerability scores for the layers identified based upon results of container image scans. The results of container image scans are generated from the actual scanning of container images. Container images scanner is configured to scan one or more container images and generate container images scan results wherein the scan results is used by layers vulnerability scores generator subsystem to calculate vulnerability scores for the layers determined for the container image to be processed);
generating, by the first software or the second software, a mapping between the metadata and the software vulnerability (par.70, 79-80, the container images scanner inspects container images layer-by-layer for vulnerabilities specified in the collected vulnerability data and provides a notification of any detected vulnerabilities); and
assigning a remediation action to remediate the container image based on the mapping (par.129-133, 20, the report includes information identifying the various layers that make up the container image and the vulnerability scores computed for the individual layers. Par.45, further teaches the container image vulnerability scores generator subsystem can be configured to transmit the determined container image vulnerability score to the actions subsystem , par.137-138 the actions may include sending messages to one or more recipients informing them of the vulnerability score for the container image. For example, if the vulnerability score for a container image exceeds a threshold, one or more messages may be sent to members of a security team tasked with reducing container image vulnerabilities which is configured to perform one or more actions in accordance with actions configuration information) .
Pieczul fails to teach, however Levin et al in the same field of endeavor teaches
adding, by first software executing on a host, metadata associated with a user to the container image (par.23, 27, the added metadata may indicate, but is not limited to, which user pushed the image of the image layer, a job name, an environment in which the image layer is run, and the like),
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Pieczul with the additional features of Levin et al in order to provide the ability for maintaining image integrity in a containerized environment, as suggested by Levin et al abstract.
The combination fails to teach, however Gupta et al in the same field of endeavor teaches
an orchestrator executing unit in the data center or the cloud configured to provision containers in the data center or the cloud from the container image as remediated (par.34, 37, Once the related layers are identified, the security vulnerability can be addressed. For example, the layer(s) in question may be patched to remove the vulnerability. In another example, the affected container images may be flagged as vulnerable, such that alternative container images, ones without the vulnerability, may be used instead. patching the vulnerable layer and layers of the additional container images that are related to the vulnerable layer based on the relationship information)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Pieczul with the additional features of Gupta et al in order to decrease the burden of security scans wherein metadata from the scans are preserved to prevent redundant scanning, as suggested by Gupta et al par.15.
Claim 15: Pieczul teaches a computing system, comprising:
a host in a data center (par.45-46);
a container security agent executing on the host and configured to add metadata(stacked software layers) par.45-46, 70, using the container image information reader subsystem 112, container images and associated metadata from a memory accessible to the VAS and determine information identifying the container image and metadata associated with the container image. marking the container image for scanning by the container images scanner or otherwise transmitting a signal to the container images scanner to scan the container image to generate container images scan results for the container image); and
a container security monitor executing in the data center or a cloud in communication with the data center, the container security monitor configured to receive the container image, scan the container image to identify a software vulnerability (par. 45-46, the container images scanner to scan the container image to generate container images scan results for the container image, par 67-70 further teaches calculating vulnerability scores for the layers identified based upon results of container image scans. The results of container image scans are generated from the actual scanning of container images. Container images scanner is configured to scan one or more container images and generate container images scan results wherein the scan results is used by layers vulnerability scores generator subsystem to calculate vulnerability scores for the layers determined for the container image to be processed),
generate a mapping between the metadata and the software vulnerability (par.70, 79-80, the container image scanner inspects container images layer-by-layer for vulnerabilities specified in the collected vulnerability data and provides a notification of any detected vulnerabilities), and
assign a remediation action to remediate the container image based on the mapping (par.129-133, 20, the report includes information identifying the various layers that make up the container image and the vulnerability scores computed for the individual layers. Par.45, the container image vulnerability scores generator subsystem can be configured to transmit the determined container image vulnerability score to the actions subsystem, par.137-138 the actions may include sending messages to one or more recipients informing them of the vulnerability score for the container image. For example, if the vulnerability score for a container image exceeds a threshold, one or more messages may be sent to members of a security team tasked with reducing container image vulnerabilities which is configured to perform one or more actions in accordance with actions configuration information).
Pieczul fails to teach, however Levin et al in the same field of endeavor teaches
a container security agent executing on the host and configured to add metadata associated with a user to the container image (par. 23, 27, the added metadata may indicate, but is not limited to, which user pushed the image of the image layer, a job name, an environment in which the image layer is run, and the like),
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Pieczul with the additional features of Levin et al in order to provide the ability for maintaining image integrity in a containerized environment, as suggested by Levin et al abstract.
The combination fails to teach, however Gupta et al in the same field of endeavor teaches
an orchestrator executing unit in the data center or the cloud configured to provision containers in the data center or the cloud from the container image as remediated (par.34, 37, once the related layers are identified, the security vulnerability can be addressed. For example, the layer(s) in question may be patched to remove the vulnerability. In another example, the affected container images may be flagged as vulnerable, such that alternative container images, ones without the vulnerability, may be used instead. patching the vulnerable layer and layers of the additional container images that are related to the vulnerable layer based on the relationship information)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Pieczul with the additional features of Gupta et al in order to decrease the burden of security scans wherein metadata from the scans are preserved to prevent redundant scanning, as suggested by Gupta et al par.15.
Claims 2 and 9: the combination teaches
wherein the first software comprises a container security agent executing on the host in a data center, and wherein the second software comprises a container security monitor executing in a cloud in communication with the data center (Pieczul, par.45-46).
Claims 3, 10 and 16: the combination teaches
wherein the container security agent notifies the container security monitor of the container image to be scanned (Pieczul, par.45-46,70).
Claims 4 and 11: the combination teaches
wherein the first software comprises a container security monitor executing on the host in a data center (Pieczul, par.45-46,225).
Claims 6 and 13 and 19: the combination teaches
wherein the first software relates the metadata with a layer of the container image added by the user (Pieczul, par.8, 43, Levin et al par.23, 27-28, 30-33).
The same motivation to modify Pieczul in view of Levin et al applied to claims 1, 8 and 15 above applies here.
Claims 7, 14 and 20: the combination teaches
wherein the first software or the second software identifies the layer as having the software vulnerability and obtains the metadata from the container image based on the layer (Pieczul, par.8, 45-46, Levin et al, par. 24-26).
The same motivation to modify Pieczul in view of Levin et al applied to claims 6, 13 and 19 above applies here.
Claims 5, 12 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Pieczul U.S. 2023/0252157 A1 in view of Levin et al U.S. 2020/0012818 A1 in further view Gupta et al U.S. 2024/0427901 A1 and Cristofi et al U.S. 2021/0117251 A1.
Claims 5, 12 and 18: the combination fails to teach, however Cristofi et al in the same field of endeavor teaches
wherein the metadata comprises a username and a group name associated with the user, and wherein the first software obtains the metadata in cooperation with auth software (par. 497, 1056, ).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Pieczul with the additional features of Cristofi et al in order to provide the ability for maintaining image integrity in a containerized environment, as suggested by Cristofi et al abstract.
Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Pieczul U.S. 2023/0252157 A1 in view of Levin et al U.S. 2020/0012818 A1 in further view of Gupta et al U.S. 2024/0427901 A1 and Kurian et al U.S. 2021/0374767 A1.
Claim 17: the combination teaches fails to teach, however Kurian et al in the same field of endeavor teaches
wherein the first software comprises a container security monitor comprises a software-as-a-service executing in the cloud (par.37).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Pieczul with the additional features of Kurian et al in order to provide the ability or automatic remediation of non-compliance events, as suggested by Kurian et al abstract.
The following prior art are cited to further show the state of the art at the time of applicant’s invention.
Sweet et al U.S. 2018/0309747 A1
Stopel et al U.S. 2017/0116415 A1
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FATOUMATA TRAORE whose telephone number is (571)270-1685. The examiner can normally be reached 6:30-3:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, SHEWAYE GELAGAY can be reached at 5712724219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Saturday, May 2, 2026
/FATOUMATA TRAORE/Primary Examiner, Art Unit 2436