Prosecution Insights
Last updated: October 02, 2026
Application No. 18/438,644

VERIFYING TRUSTWORTHINESS OF WORKER NODES OF CLUSTER ENVIRONMENTS DURING WORKLOAD SCHEDULING

Non-Final OA §103
Filed
Feb 12, 2024
Priority
Aug 11, 2023 — provisional 63/532,162
Examiner
TRUONG, DANIEL NHU
Art Unit
4100
Tech Center
4100
Assignee
NVIDIA Corporation
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-60.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
7 currently pending
Career history
7
Total Applications
across all art units
This examiner has no resolved cases yet (career too new); statute-level performance unavailable. The Grant Probability card shows Tech Center averages instead.

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to claims filed on 02/12/2024. Claims 1-20 are pending. Priority Applicant’s claim for priority from application no. 63/532,162 filed 08/11/2023 is acknowledged. Claim Objections Claim 12 objected to because of the following informalities: States "further comprising obtaining, the at least one processing device", which is missing the word "by" before "the at least one processing device". Appropriate correction is required. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-3, 7-10, and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Huang et al. (JP 2024083208 A; English translation provided by IP.COM; filed May 11, 2023; hereinafter referred to as Huang), in view of Nainar et al. (20220078015; published March 10, 2022; hereinafter referred to as Nainar) and in further view of Wentz (11379263; filed March 6, 2020; hereinafter referred to as Wentz). As per claim 1, Huang teaches: A system comprising: a memory; and a processing device, operatively coupled to the memory (e.g. Huang: [0027] discloses the cloud resource allocation apparatus 100A is realized by using an electronic device with computing function and networking function, and the hardware architecture thereof includes at least a processor 110 and a storage 120.), to perform operation comprising: Receiving a workload (e.g. Huang: [0008] discloses parse a job profile of a job request obtained from the waiting queue through the job scheduler. Please note the job profile corresponds to Applicant’s workload.); Selecting, from a set of worker nodes of a cluster environment, a worker node for scheduling of the workload (e.g. Huang: [0008] discloses the orchestrator is configured to: find a first worker node having an available resource matching the job profile through the job scheduler among the worker nodes; dispatch the job to be handled to the first worker node through the resource manager.); Huang does not teach determining whether the worker node is valid, including determining whether the worker node is trusted; and in response to determining that the worker node is valid, scheduling the workload with the worker node. However, Nainar does teach: determining whether the worker node is valid, including determining whether the worker node is trusted (e.g. Nainar: [0013] discloses the master node (e.g., API-server) may validate the worker node by sending a locally generated nonce and request for an attestation token based on the nonce.). Huang and Nainar are in the same field of endeavor in terms of secure computing therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang to incorporate the teachings of Nainar for the reason of teach determining whether the worker node is valid, including determining whether the worker node is trusted. This improves the security of the cluster by validating the nodes that attempt to join the cluster and makes it less likely for malicious parties to be able to slip in. Huang-Nainar does not teach and in response to determining that the worker node is valid, scheduling the workload with the worker node. However, Wentz does teach and in response to determining that the worker node is valid, scheduling the workload with the worker node (e.g. Wentz: [0004] discloses receiving a first authorization token including a secure proof of an attestation conferring a first credential on the at least a remote device, evaluating the first authorization token, and selecting the at least a remote device based on the evaluation of the first authorization token. The method includes assigning, by the selection device, the computing task to the at least a remote device. Please note evaluating the authorization token conferring credentials onto the remote device corresponds to Applicant's determining that the worker node is valid. This is because if the token is deemed trusted then the remote device can be trusted and assigned a workload). Huang-Nainar and Wentz are in the same field of endeavor in terms of secure computing therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang-Nainar to incorporate the teachings of Wentz for the reason of in response to determining that the worker node is valid, scheduling the workload with the worker node. This improves the security of the cluster by only allowing validated nodes to perform work for the cluster and lowering the chances of an attack from a malicious party. As per claim 2, Huang-Nainar-Wentz teaches claim 1 as applied above. Huang further teaches wherein selecting the worker node comprises identifying the worker node by using load balancing based on an analysis of available computing resources (e.g. Huang: [0008] discloses decide to execute a direct resource allocation or an indirect resource allocation for a job to be handled requested by the job request based on the node resource information and the job profile. In response to deciding to execute the direct resource allocation, the orchestrator is configured to: find a first worker node having an available resource matching the job profile through the job scheduler among the worker nodes. Please note the orchestrator finds a worker node based on the plurality of node resource information it possesses which corresponds to Applicant's node identification using load balancing.). As per claim 3, Huang-Nainar-Wentz teaches claim 1 as applied above. Nainar further teaches wherein determining whether the worker node is trusted comprises determining whether an attestation lease associated with a trust agent of the worker node is valid (e.g. Nainar: [0029] discloses the kubelet 110a may compute or generate the attestation token 230 based on the received new nonce 228. The kubelet 110a may reply to the API-server 108 with the attestation token 230. [0065] discloses the file definition indicates that attestation tokens are to be used (attestation-token=true) and that attestation tokens are valid for 500 ms. Please note the kubelet corresponds to Applicant's trust agent of the worker node because, similar to trust agent 136 in Figure 1b of Applicant’s specification, it resides on the worker node and communicates with the master node. [0031] of Applicant's specification states “Attestation lease valid can indicate a trusted state of node 132” and [0032] states “The PoA can include a set of data that indicates the trustworthiness of the node 132 is validated for the amount of time (e.g., attestation lease start time and attestation lease end time)”. Please note the attestation token corresponds to Applicant's attestation lease because the attestation token indicates trustworthiness and for how long.). As per claim 7, Huang-Nainar-Wentz teaches claim 7 as applied above. Nainar further teaches wherein the operations further comprise, in response to determining that the worker node is invalid, causing at least one remedial action to be performed to address the worker node (e.g. Nainar: [0022] discloses if there are consecutive failures in consecutive validation intervals, then such a worker node may be classified as a compromised worker node and the worker node may be quarantined, e.g., taken out of service. Please note being quarantined corresponds to Applicant’s remedial action.). As per claim 8, Huang teaches: by at least one processing device (e.g. Huang: [0027] discloses the hardware architecture thereof includes at least a processor 110.), receiving a workload (e.g. Huang: [0008] discloses parse a job profile of a job request obtained from the waiting queue through the job scheduler. Please note the job profile corresponds to Applicant’s workload.); selecting, by the at least one processing device from a set of worker nodes of a cluster environment, a worker node for scheduling of the workload (e.g. Huang: [0008] discloses the orchestrator is configured to: find a first worker node having an available resource matching the job profile through the job scheduler among the worker nodes; dispatch the job to be handled to the first worker node through the resource manager.); Huang does not teach determining, by the at least one processing device, whether the worker node is valid, including determining whether the worker node is trusted; and in response to determining that the worker node is valid, scheduling, by the at least one processing device, the workload with the worker node. However, Nainar does teach determining, by the at least one processing device, whether the worker node is valid, including determining whether the worker node is trusted (e.g. Nainar: [0013] discloses the master node (e.g., API-server) may validate the worker node by sending a locally generated nonce and request for an attestation token based on the nonce.); Huang and Nainar are in the same field of endeavor in terms of secure computing therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang to incorporate the teachings of Nainar for the reason of teach determining, by the at least one processing device, whether the worker node is valid, including determining whether the worker node is trusted. This improves the security of the cluster by validating the nodes that attempt to join the cluster and makes it less likely for malicious parties to be able to slip in. Huang-Nainar does not teach and in response to determining that the worker node is valid, scheduling, by the at least one processing device, the workload with the worker node. However, Wentz does teach and in response to determining that the worker node is valid, scheduling, by the at least one processing device, the workload with the worker node (e.g. Wentz: [0004] discloses receiving a first authorization token including a secure proof of an attestation conferring a first credential on the at least a remote device, evaluating the first authorization token, and selecting the at least a remote device based on the evaluation of the first authorization token. The method includes assigning, by the selection device, the computing task to the at least a remote device. Please note evaluating the authorization token conferring credentials onto the remote device corresponds to Applicant's determining that the worker node is valid. This is because if the token is deemed trusted then the remote device can be trusted and assigned a workload). Huang-Nainar and Wentz are in the same field of endeavor in terms of secure computing therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang-Nainar to incorporate the teachings of Wentz for the reason of and in response to determining that the worker node is valid, scheduling, by the at least one processing device, the workload with the worker node. This improves the security of the cluster by only allowing validated nodes to perform work for the cluster and lowering the chances of an attack from a malicious party. As per claim 9, Huang-Nainar-Wentz teaches claim 8 as applied above. Huang further teaches wherein selecting the worker node comprises identifying the worker node using load balancing based on an analysis of available computing resources (e.g. Huang: [0008] discloses decide to execute a direct resource allocation or an indirect resource allocation for a job to be handled requested by the job request based on the node resource information and the job profile. In response to deciding to execute the direct resource allocation, the orchestrator is configured to: find a first worker node having an available resource matching the job profile through the job scheduler among the worker nodes. Please note the orchestrator finds a worker node based on the plurality of node resource information it possesses which corresponds to Applicant's node identification using load balancing.). As per claim 10, Huang-Nainar-Wentz teaches claim 8 as applied above. Nainar further teaches wherein determining whether the worker node is trusted comprises determining whether an attestation lease associated with a trust agent of the worker node is valid (e.g. Nainar: [0029] discloses the kubelet 110a may compute or generate the attestation token 230 based on the received new nonce 228. The kubelet 110a may reply to the API-server 108 with the attestation token 230. [0065] discloses the file definition indicates that attestation tokens are to be used (attestation-token=true) and that attestation tokens are valid for 500 ms. Please note the kubelet corresponds to Applicant's trust agent of the worker node because, similar to trust agent 136 in Figure 1b of Applicant’s specification, it resides on the worker node and communicates with the master node. [0031] of Applicant's specification states “Attestation lease valid can indicate a trusted state of node 132” and [0032] states “The PoA can include a set of data that indicates the trustworthiness of the node 132 is validated for the amount of time (e.g., attestation lease start time and attestation lease end time)”. Please note the attestation token corresponds to Applicant's attestation lease because the attestation token indicates trustworthiness and for how long.). As per claim 14, Huang-Nainar-Wentz teaches claim 8 as applied above. Nainar further teaches in response to determining that the worker node is invalid, causing, by the at least one processing device, at least one remedial action to be performed to address the worker node (e.g. Nainar discloses if there are consecutive failures in consecutive validation intervals, then such a worker node may be classified as a compromised worker node and the worker node may be quarantined, e.g., taken out of service. Please note being quarantined corresponds to Applicant’s remedial action.). Claims 4 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Huang-Nainar-Wentz, in view of SPIFFE (Spire Concepts; published March 5, 2021; hereinafter referred to as SPIFFE). As per claim 4, Huang-Nainar-Wentz teaches claim 1 as applied above. But Huang-Nainar-Wentz does not teach wherein the operations further comprise: obtaining workload identity data corresponding to the workload; and validating the workload using the workload identity data. However, SPIFFE teaches wherein the operations further comprise: obtaining workload identity data corresponding to the workload; and validating the workload using the workload identity data (e.g. SPIFFE: [Page 4; Under Summary of Steps: Workload Attestation; Paragraph 0002] discloses the agent interrogates the node’s kernel to identify the process ID of the caller. [Page 4; Under Summary of Steps: Workload Attestation; Paragraph 0003] discloses workload attestors use the process ID to discover additional information about the workload. The attestors return the discovered information to agent in the form of selectors. The agent determines the workload’s identity by comparing discovered selectors to registration entries. Please note the workload process ID corresponds to Applicant's workload identity data. As said in [0039] of the Applicant's specification, "the workload identity data can be used to prove that the workload schedule to be executed by node 132 is valid", which is what the process ID is being used for. The workload attestors using the process ID to return selectors to validate against existing registration entries corresponds to Applicant's workload validation using the workload identity data.). Huang-Nainar-Wentz and SPIFFE are in the same field of endeavor in terms of secure computing therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang-Nainar-Wentz to incorporate the teachings of SPIFFE for the reason obtaining workload identity data corresponding to the workload; and validating the workload using the workload identity data. This ensures the workloads have not been tampered with and are safe before allowing them to run on the nodes. The bolsters security and prevents malicious actors from spoofing legitimate workloads. As per claim 11, Huang-Nainar-Wentz teaches claim 8 as applied above. But Huang-Nainar-Wentz does not teach obtaining, by the at least one processing device, workload identity data corresponding to the workload; and validating, by the at least one processing device, the workload using the workload identity data. However, SPIFFE teaches obtaining, by the at least one processing device, workload identity data corresponding to the workload; and validating, by the at least one processing device, the workload using the workload identity data (e.g. SPIFFE: [Page 4 Under Summary of Steps: Workload Attestation] discloses the agent interrogates the node’s kernel to identify the process ID of the caller. [Page 4; Under Summary of Steps: Workload Attestation; Paragraph 0003] discloses workload attestors use the process ID to discover additional information about the workload. The attestors return the discovered information to agent in the form of selectors. The agent determines the workload’s identity by comparing discovered selectors to registration entries. Please note the workload process ID corresponds to Applicant's workload identity data. As said in [0039] of the Applicant's specification, "the workload identity data can be used to prove that the workload schedule to be executed by node 132 is valid", which is what the process ID is being used for. The workload attestors using the process ID to return selectors to validate against existing registration entries corresponds to Applicant's workload validation using the workload identity data.). Huang-Nainar-Wentz and SPIFFE are in the same field of endeavor in terms of secure computing therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang-Nainar-Wentz to incorporate the teachings of SPIFFE for the reason of obtaining, by the at least one processing device, workload identity data corresponding to the workload; and validating, by the at least one processing device, the workload using the workload identity data. This ensures the workloads have not been tampered with and are safe before allowing them to run on the nodes. The bolsters security and prevents malicious actors from spoofing legitimate workloads. Claim 5 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Huang-Nainar-Wentz-SPIFFE in view of Srivastava et al. (20220191025; published June 16, 2022; hereinafter referred to as Srivastava), and in further view of Sabath et al. (11652631; filed June 27, 2019; hereinafter referred to as Sabath). As per claim 5, Huang-Nainar-Wentz-SPIFFE teaches claim 4 as applied above. Huang-Nainar-Wentz-SPIFFE does not teach wherein the operations further comprise obtaining a proof of attestation corresponding to the worker node, and wherein the workload identity data is generated based on the proof of attestation. However, Srivastava teaches wherein the operations further comprise obtaining a proof of attestation corresponding to the worker node (e.g. Srivastava: [0028] discloses trust authority 202 can carry out hardware-based attestation with respect to each worker VM 116 that is created for the purpose of running the workload components of the workload and can securely transmit a digital certificate to the worker VM upon attestation completion.). Huang-Nainar-Wentz-SPIFFE and Srivastava are in the same field of endeavor in terms of secure computing and therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang-Nainar-Wentz-SPIFFE to incorporate the teachings of Srivastava for the reason of wherein the operations further comprise obtaining a proof of attestation corresponding to the worker node. This creates a more secure environment by making sure the worker node is safe and trustworthy to use. Huang-Nainar-Wentz-SPIFFE-Srivastava does not teach wherein the workload identity data is generated based on the proof of attestation. However, Sabath does teach wherein the workload identity data is generated based on the proof of attestation (e.g. Sabath: [0023] discloses the autonomous generation of one or more digital identity tokens that can be bound to a computer application process and/or signed by a chain of trust originating from one or more hardware devices. Please note that having to be signed by the chain of trust as part of the process of creating the digital identity tokens is similar to the workload identity being generated on a proof of attestation. As such the digital identity token signed by a chain of trust originating from one or more hardware devices corresponds to Applicant's workload identity data generated based on proof of attestation.). Huang-Nainar-Wentz-SPIFFE-Srivastava and Sabath are in the same field of endeavor in terms of secure computing therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang-Nainar-Wentz-SPIFFE-Srivastava to incorporate the teachings of Sabath for the reason of wherein the workload identity data is generated based on the proof of attestation. This eliminates the need for hard-coded credentials by using cryptographic proof of the system’s integrity. It creates secure, short-lived identities that expire if the machine or system is tampered with creating a safer system. As per claim 12 Huang-Nainar-Wentz-SPIFFE teaches claim 11 as applied above. Huang-Nainar-Wentz-SPIFFE does not teach wherein the operations further comprise obtaining a proof of attestation corresponding to the worker node, and wherein the workload identity data is generated based on the proof of attestation. However, Srivastava teaches wherein the operations further comprise obtaining a proof of attestation corresponding to the worker node (e.g. Srivastava: [0028] discloses trust authority 202 can carry out hardware-based attestation with respect to each worker VM 116 that is created for the purpose of running the workload components of the workload and can securely transmit a digital certificate to the worker VM upon attestation completion.). Huang-Nainar-Wentz-SPIFFE and Srivastava are in the same field of endeavor in terms of secure computing and therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang-Nainar-Wentz-SPIFFE to incorporate the teachings of Srivastava for the reason of wherein the operations further comprise obtaining a proof of attestation corresponding to the worker node. This creates a more secure environment by making sure the worker node is safe and trustworthy to use. Huang-Nainar-Wentz-SPIFFE-Srivastava does not teach wherein the workload identity data is generated based on the proof of attestation. However, Sabath does teach wherein the workload identity data is generated based on the proof of attestation (e.g. Sabath: [0023] discloses the autonomous generation of one or more digital identity tokens that can be bound to a computer application process and/or signed by a chain of trust originating from one or more hardware devices. Please note that having to be signed by the chain of trust as part of the process of creating the digital identity tokens is similar to the workload identity being generated on a proof of attestation. As such the digital identity token signed by a chain of trust originating from one or more hardware devices corresponds to Applicant's workload identity data generated based on proof of attestation.). Huang-Nainar-Wentz-SPIFFE-Srivastava and Sabath are in the same field of endeavor in terms of secure computing therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang-Nainar-Wentz-SPIFFE-Srivastava to incorporate the teachings of Sabath for the reason of wherein the workload identity data is generated based on the proof of attestation. This eliminates the need for hard-coded credentials by using cryptographic proof of the system’s integrity. It creates secure, short-lived identities that expire if the machine or system is tampered with creating a safer system. Claim(s) 6 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Huang-Nainar-Wentz, in view of Yang et al. (20240320324; foreign priority August 10, 2023; hereinafter referred to as Yang). As per claim 6, Huang-Nainar-Wentz teaches claim 1 as applied above. But Huang-Nainar-Wentz does not teach wherein the operations further comprise, in response to determining that the worker node is invalid, selecting a second worker node of the set of worker nodes for scheduling of the workload. However, Yang does teach wherein the operations further comprise, in response to determining that the worker node is invalid, selecting a second worker node of the set of worker nodes for scheduling of the workload (e.g. Yang discloses the scheduler may reschedule the application deployment unit for execution on a second compatible worker node of the plurality of worker nodes when the security resource data no longer satisfies the security requirement. This may provide a mechanism for rescheduling applications if the security resources on a node change, ensuring continuous compliance with security requirements.). Huang-Nainar-Wentz and Yang are in the same field of endeavor in terms of secure computing therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang-Nainar-Wentz to incorporate the teachings of Yang for the reason of wherein the operations further comprise, in response to determining that the worker node is invalid, selecting a second worker node of the set of worker nodes for scheduling of the workload. This speeds up the cluster and prevents vulnerabilities by making the cluster move on to another node instead of waiting on an invalid and possibly unsafe node. As per claim 13, Huang-Nainar-Wentz teaches claim 8 as applied above. But Huang-Nainar-Wentz does not teach in response to determining that the worker node is invalid, selecting, by the at least one processing device, a second worker node of the set of worker nodes for scheduling of the workload. However, Yang does teach in response to determining that the worker node is invalid, selecting, by the at least one processing device, a second worker node of the set of worker nodes for scheduling of the workload (e.g. Yang discloses the scheduler may reschedule the application deployment unit for execution on a second compatible worker node of the plurality of worker nodes when the security resource data no longer satisfies the security requirement. This may provide a mechanism for rescheduling applications if the security resources on a node change, ensuring continuous compliance with security requirements.). Huang-Nainar-Wentz and Yang are in the same field of endeavor in terms of secure computing therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Huang-Nainar-Wentz to incorporate the teachings of Yang for the reason of in response to determining that the worker node is invalid, selecting, by the at least one processing device, a second worker node of the set of worker nodes for scheduling of the workload. This speeds up the cluster and prevents vulnerabilities by making the cluster move on to another node instead of waiting on an invalid and possibly unsafe node. Claim(s) 15 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Nainar, in view of Okuda et al. (WO2024252681A1; English translation provided by IP.COM; filed June 9, 2023; hereinafter referred to as Okuda), and in further view of Doshi et al. (20240264874; domestic priority March 31, 2023; hereinafter referred to as Doshi). As per claim 15, Nainar teaches: a control plane comprising a processing device, operatively coupled to a memory (e.g. Nainar: [0092] discloses the chipset 606 provides an interface between the CPUs 604 and the remainder of the components and devices on the baseboard 602. The chipset 606 can provide an interface to a RAM 608, used as the main memory in the computer 600.), to perform operations comprising: determining whether the worker node is valid by performing an attestation of the worker node based on the trust measurement data (e.g. Nainar: [0019] discloses the worker node computes or generates the attestation token based on the received nonce. The worker node replies back to the master node with the attestation token. The master node validates the attestation token with the CA server to ensure that the integrity of the worker node is not compromised. Please note the generation of the attestation token corresponds to Applicant’s performing an attestation based on trust measurement data.); Nainar does not teach receiving, from a trust agent of a worker node of a cluster environment, attestation verification data for comprising trust measurement data defining a configuration state of the worker node; and in response to determining that the worker node is valid, sending a proof of attestation to the worker node However, Okuda teaches receiving, from a trust agent of a worker node of a cluster environment, attestation verification data for comprising trust measurement data defining a configuration state of the worker node (e.g. Okuda: [Page 5 Paragraph 0005] discloses the worker node 220 has an agent function unit 221 and an attestation report issuing unit 222. [Page 5 Paragraph 0007] discloses the attestation report issuing unit 222 issues an attestation report using the TEE. At this time, the attestation report issuing unit 222 issues an attestation report that includes its own (the worker node 220's) node-specific information. Please note the attestation report corresponds to Applicant’s trust measurement data. Please note node-specific information corresponds to Applicant’s configuration state of the worker node.). Nainar and Okuda are in the same field of endeavor in terms of secure computing and therefore it would be obvious to one of ordinary skill in the art before the effective filing date of the invention to have modified the teachings of Nainar to incorporate the teachings of Okuda for receiving, from a trust agent of a worker node of a cluster environment, attestation verification data for comprising trust measurement data defining a configuration state of the worker node. This process is a core part of attestation-based identity. This allows the trust agent to cryptographically prove the current configuration of its node has not been tampered with. And it lets the system trust the cryptographic proof of the node’s environment instead of some hard-coded key, creating a more secure system. Nainar-Okuda does not teach and in response to determining that the worker node is valid, sending a proof of attestation to the worker node. However, Doshi does teach and in response to determining that the worker node is valid, sending a proof of attestation to the worker node (e.g. Doshi: [0159] discloses an attestation result in the form of an attestation token (shown in operation 2) may utilize industry standard token structures such as CBOR Web Token, JSON Web Token, Concise Evidence, W3C DID/VC, X.509 certificates, Trusted Platform Module etc. or proprietary formats such as Intel® SGX attestation block, etc. The attestation token may be returned to the IPU 3320 upon successful verification and appraisal. Please note in [0033] of Applicant's specification, proof of attestation examples is given as possibly digital certificates or tokens.). Nainar-Okuda and Doshi are in the same field of endeavor in terms of secure computing and therefore it would be obvious to one of ordinary skill in the art before the effective filing date of the invention to have modified the teachings of Nainar-Okuda to incorporate the teachings of Doshi for in response to determining that the worker node is valid, sending a proof of attestation to the worker node. This improves the security of the cluster by allowing the network to securely schedule workloads, grant access to sensitive data, and distribute tasks without relying on easily spoofed static credentials. As per claim 16, Nainar-Okuda-Doshi teach claim 15 as applied above. Nainar further teaches wherein determining whether the worker node is valid comprises determining whether the trust measurement data matches reference trust measurement data (e.g. Nainar: [0019] discloses the master node validates the attestation token with the CA server to ensure that the integrity of the worker node is not compromised. Please note that when the worker node generates an attestation token it includes cryptographic measurements of its systems. As a result, when the CA server validates the token, it compares these measurements against known good baselines which corresponds to Applicant’s comparing trust measurement data against reference trust measurement data.). Claim(s) 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Nainar-Okuda-Doshi, in view of SPIFFE (Spire Concepts; published March 5, 2021;), and in further view of Kostiainen (US. Pat. Pub 20150281219; published October 1, 2015; hereinafter referred to as Kostiainen). As per claim 17, Nainar-Okuda-Doshi teaches claim 15 as applied above. Nainar further teaches receiving, from the worker node, a get nonce request to initiate an attestation process of the worker node (e.g. Nainar: [0012] discloses the worker node may then send its authentication credentials to the master node. The master node may then locally generate a nonce and forward the nonce to the worker node. Please note sending the authentication credentials prompted the master node to then send a nonce to the worker node. As such sending the authentication credentials functionally works as a get nonce request and corresponds to Applicant’s get nonce request to initiate an attestation process of the worker node.); determining, based on the node state of the worker node, whether to continue with the attestation process (e.g. Nainar: [0066] discloses if there are consecutive failures in consecutive validation intervals, then the worker node 106a may be classified as a compromised worker node and the worker node 106a may be quarantined, e.g., taken out of service. Please note consecutive validation intervals corresponds to Applicant’s attestation process, so if the worker node is compromised it can no longer continue the attestation process.); in response to determining to continue with the attestation process, (e.g. Nainar: [0013] discloses the worker node may be periodically validated by the master node using locally generated nonces and attestation tokens. Additionally, or alternatively, discloses the master node may validate the worker node using locally generated nonces and attestation tokens in response to an event. Please note Nainar teaches that in response to an event the master node may choose to go through with the validation/attestation of the worker node and will generate a random nonce to do so.); sending, to the worker node, a get nonce response (e.g. Nainar: [0019] discloses the master node (e.g., API-server) may validate the worker node by sending a locally generated nonce and request for an attestation token based on the nonce.); and after sending the get nonce response, receiving the attestation verification data from the trust agent of the worker node (e.g. Nainar: [0019] discloses the worker node computes or generates the attestation token based on the received nonce. The worker node replies back to the master node with the attestation token.). Nainar-Okuda-Doshi does not teach identifying, using a node state store, a node state of the worker node related to an attestation lease; However, SPIFFE does teach identifying, using a node state store, a node state of the worker node related to an attestation lease (e.g. SPIFFE: [Page 3; Under Node Attestation; Paragraph 0002] discloses the result of a successful node attestation is that the agent receives a unique SPIFFE ID. [Page 4; Under Summary of Steps: Node Attestation; Paragraph 0003] discloses the node attestor also creates a SPIFFE ID for the agent, and passes this back to the server process. Please note upon the broadest reasonable interpretation, the node state store holding data of a node state of the worker node related to an attestation lease means that the node state store holds data on whether a node can be trusted or not. In SPIFFE, a successful node attestation results in a SPIFFE ID that is then passed and held by the server process. As such the server process corresponds to Applicant’s node state store.). Nainar-Okuda-Doshi and SPIFFE are in the same field of endeavor in terms of secure computing and therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Nainar-Okuda-Doshi to incorporate the teachings of SPIFFE for the reason of identifying, using a node state store, a node state of the worker node related to an attestation lease. This speeds up processing time and efficiency because by remembering which nodes are trusted the cluster will not have to attest its individual nodes each time it wants to assign them a workload. Nainar-Okuda-Doshi-SPIFFE does not teach However, Kostiainen does teach (e.g. Kostiainen: [0123] discloses the picked random nonce n is saved for later verification and sent 315 to the application 104, which is to be attested. Please note, previously above Nainar taught that in response to an event the master node may choose to go through with the validation/attestation of the worker node and will generate a random nonce to do so. From that, Kostiainen then teaches to store that randomly generated nonce for later verification.). Nainar-Okuda-Doshi-SPIFFE and Kostiainen are in the same field of endeavor in terms of secure computing and therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Nainar-Okuda-Doshi-SPIFFE to incorporate the teachings of Kostiainen for the reason of Storing nonce data is essential for proving freshness, validating transaction contexts, and prevent replay attacks. It allows the master node to compare the returned attestation data with the original nonce, thereby guaranteeing security. Claim(s) 18 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Nainar-Okuda-Doshi, in view of Ogbuachi et al. (WO2023046279; English translation provided by IP.COM; published March 30, 2023), and in further in view of Wattiau et al. (20240305634; filed March 8, 2023; hereinafter referred to as Wattiau). As per claim 18, Nainar-Okuda-Doshi teach claim 15 as applied above. But Nainar-Okuda-Doshi does not teach receiving, from the worker node, a registration request to register the worker node with the control plane; and in response to receiving the registration request, initiating a registration phase of an enrollment process to register the worker node with the control plane. However, Ogbuachi does teach receiving, from the worker node, a registration request to register the worker node with the control plane (e.g. Ogbuachi: [Page 42 Paragraph 2] discloses as illustrated by arrow 832 of Figure 9, in some embodiments, the wireless device 30 may transmit a request to join the cluster towards the master node 10.). Nainar-Okuda-Doshi and Ogbuachi are in the same field of endeavor in terms of computer systems and therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Nainar-Okuda-Doshi to incorporate the teachings of Ogbuachi for the reason of receiving, from the worker node, a registration request to register the worker node with the control plane. This allows nodes to request to join the cluster giving another option for nodes to enter as opposed to the cluster itself seeking new nodes. This gives the cluster more processing power and resources. Nainar-Okuda-Doshi-Ogbuachi does not teach in response to receiving the registration request, initiating a registration phase of an enrollment process to register the worker node with the control plane. However, Wattiau does teach in response to receiving the registration request, initiating a registration phase of an enrollment process to register the worker node with the control plane (e.g. Wattiau: [0006] discloses the target device may initiate an authentication process with an enrollment authority, such as a cluster enrollment system, on the network to request access to a cluster. The enrollment authority may then determine an enrollment policy that is usable to determine whether the target device should be joined to the cluster. Please note determining an enrollment policy for the target device to join the cluster corresponds to Applicant's initiating a registration phase of an enrollment process to register the worker node with the control plane). Nainar-Okuda-Doshi-Ogbuachi and Wattiau are in the same field of endeavor in terms of secure computing and therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Nainar-Okuda-Doshi-Ogbuachi to incorporate the teachings of Wattiau for the reason of initiating a registration phase of an enrollment process to register the worker node with the control plane. This improves security because registration of the node is the first step before attesting it to make sure it is safe to communicate with. As per claim 19, Nainar-Okuda-Doshi-Ogbuachi-Wattiau teaches claim 18 as applied above. Wattiau further teaches determining whether the registration phase is successful; and in response to determining that the registration phase is successful, initiating an enrollment phase of the enrollment process (e.g. Wattiau: [0006] discloses in response to satisfaction of an enrollment policy, which may include one or more enrollment criteria, the target device may be provided with a key that allows the target device to join the cluster and engage in communication with other devices in the cluster and/or other devices outside of the cluster.). Claim(s) 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Nainar-Okuda-Doshi-Ogbuachi-Wattiau in view of Piras (TPM 2.0-based Attestation of a Kubernetes Cluster; published 2022; hereinafter referred to as Piras). As per claim 20, Nainar-Okuda-Doshi-Ogbuachi-Wattiau teaches claim 19 as applied above. But Nainar-Okuda-Doshi-Ogbuachi-Wattiau does not teach determining whether the enrollment phase is successful; and in response to determining that the enrollment phase is successful, initiating the attestation of the worker node. However, Piras teaches determining whether the enrollment phase is successful; and in response to determining that the enrollment phase is successful, initiating the attestation of the worker node (e.g. Piras: [Page 42; Paragraph 0001] discloses after the delivery and the decryption of the encrypted payload, the services start on the node and the remote attestation process can begin. Please note the delivery and decryption of the encrypted payload corresponds to Applicant's enrollment phase because after the step finishes, attestation of the worker node can begin.). Nainar-Okuda-Doshi-Ogbuachi-Wattiau and Piras are in the same field of endeavor in terms of secure computing and therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Nainar-Okuda-Doshi-Ogbuachi-Wattiau to incorporate the teachings of Piras for the reason of determining whether the enrollment phase is successful; and in response to determining that the enrollment phase is successful, initiating the attestation of the worker node. This improves security because attesting the node makes sure it is safe to communicate with. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. (KR-102726547-B1; published January 6, 2022; Inventor Rodriguez) Rodriguez teaches Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANIEL N TRUONG whose telephone number is (571)270-0856. The examiner can normally be reached Monday-Thursday 9:00AM-6:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, April Blair can be reached at (571) 270-1014. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DANIEL NHU TRUONG/Examiner, Art Unit 2196 /APRIL Y BLAIR/Supervisory Patent Examiner, Art Unit 2196
Read full office action

Prosecution Timeline

Feb 12, 2024
Application Filed
Aug 13, 2026
Non-Final Rejection mailed — §103
Sep 29, 2026
Interview Requested

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month