Prosecution Insights
Last updated: October 02, 2026
Application No. 18/465,148

GUEST ADMIN PROTECTION FOR CONFIDENTIAL VIRTUAL MACHINES

Final Rejection §103
Filed
Sep 11, 2023
Examiner
HUARACHA, WILLY W
Art Unit
2197
Tech Center
2100 — Computer Architecture & Software
Assignee
Microsoft Technology Licensing, LLC
OA Round
2 (Final)
73%
Grant Probability
Favorable
3-4
OA Rounds
1y 0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
305 granted / 416 resolved
+18.3% vs TC avg
Strong +54% interview lift
Without
With
+54.4%
Interview Lift
resolved cases with interview
Typical timeline
4y 1m
Avg Prosecution
16 currently pending
Career history
444
Total Applications
across all art units

Statute-Specific Performance

§101
12.9%
-27.1% vs TC avg
§103
46.1%
+6.1% vs TC avg
§102
9.7%
-30.3% vs TC avg
§112
26.9%
-13.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 416 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claims 1-4, 6-11, 13-18 and 20 are currently pending and have been examined. Claim Objections Claims 1 and 16 are objected to because of the following informalities: Re-claim 1, line 9 recites “administrative rights” when it should be “administrative right” Re-claim 16, lines 6 and 11 recite “the one or more measurements” when it should be “the measurement” Appropriate correction is required. Information Disclosure Statement The information disclosure statement (IDS) submitted on 04/03/2026 has been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Form PTO-1449 is signed and attached hereto. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-4, 6, 8-11, 13 and 15-18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Narayanan et al. “Remote attestation of SEV-SNP confidential VMs using e-vTPMs” in view of Srivastava et al. (U.S. Pub. No. 20220222100 A1) in view of Tamir et al. (U.S. Pub. No. 20240086550 A1) and further in view of Song et al (U.S. Pub. No. 20130191643 A1). Narayanan, Srivastava and Tamir were cited in previous office action. As per claim 1, Narayanan teaches the invention substantially as claimed including a confidential compute system comprising: a confidential compute component configured to support a confidential virtual machine (CVM) (page 2, right column, managed by a dedicated co-processor, AMD secure processor (AMD-SP). AMD-SP takes care of the lifecycle management of the SEV VMs; page 5, right column, lines 15-17 every confidential VM has its own private vTPM that runs at a higher privilege level (i.e., VMPL0) inside each confidential VM and is encrypted by AMD-SP); provision a confidential virtual machine (CVM) within the confidential compute system (page 5, right column, lines 24-25 We use Qemu/KVM environment for running the confidential VM. Figure 2 shows how a confidential VM is launched; Fig. 2, SEV-SNP Confidential VM); capture a measurement from the CVM during a build process performed by the third party … (page 7, right column, lines 4-7, Before launching [during build process] the confidential VM, the AMD-SP hardware measures all the load-time binaries as part of the launch measurement. This includes the SVSM and our SVSM-vTPM code. By verifying these measurements that are included as part of the attestation report, we can ensure that our SVSM-vTPM binary, and anything else running in VMPL0, has not been tampered; page 7, left column, lines 46-47 an attestation report (4) that contains the launch measurements, vmpl level and the user-data); transmit an attestation report to a primary administrative party of the CVM, the attestation report including the captured measurement (page 7, left column, lines 49-50 We can retrieve the saved attestation report at any point in time (5)). Narayanan does not expressly disclose: cause the CVM to enter operational service with confidential data based on the attestation report; a processor; and a computer-readable medium storing instructions that are operative upon execution by the processor However, Srivastava teaches: cause the CVM to enter operational service with confidential data based on the attestation report; a processor; and a computer-readable medium storing instructions that are operative upon execution by the processor (par. 0020 For a Guest Owner to verify that the guest that is running authentic software and has not been tampered with, it needs to establish a secure communication channel with the PSP and obtain a measurement of the guest. A measurement includes a hash of the guest's memory contents and is not deemed to change on every boot. Note that SEV is transparent to guest applications but guest kernels need to be made SEV aware to support this capability …The Guest Owner can verify the hash provided by the PSP of the guest, and only then proceed to deliver a disk decryption key to the guest. This allows the guest to decrypt the disk and process the confidential data. The guest VM is now fully operational and protected by SEV.), and a computer-readable medium storing instructions that are operative upon execution by the processor (par. 0017 CPUs 160 are configured to execute instructions, for example, executable instructions that perform one or more operations described herein, which may be stored in RAM). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the technique of causing a VM enter operational service with the confidential data upon guest owner verifying that the guest is running authentic software of Srivastava with the system/method of Narayanan resulting in a system and method which provides for causing a confidential VM enter operational service with the confidential data upon guest owner verifying guest authentic software as in Srivastava. One or ordinary skill in the art would have been motivated to make this combination for the purpose of verifying authenticity of the various components executing in such virtualized computing systems (par. 0002). Narayanan and Srivastava do not expressly disclose: provide a third party with administrative right to the CVM, the administrative rights allowing the third party to install software on the CVM. However, Tamir teaches: provide a third party with administrative right to the CVM, the administrative rights allowing the third party to install software on the CVM (par. 0024 granting a subset of administrative rights to the cloud account operator(s) 103, the cloud account owner(s) 102 trust the cloud account operator(s) 103 to perform duties without impacting the security and confidentiality of the guest virtual machines run by the cloud account owner(s); par. 0025 the cloud account owner(s) 102 configures the vault owner 104 with administrative privileges to lock and establish the vault around a guest virtual machine; par. 0033 the cloud account owner(s) 102 allow the vault owner 104 to install applications, e.g., as application containers on the guest VM 404). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the technique of providing by a cloud account owner various levels of administrative rights/privileges to one or more of account operators, vault owner allow them to perform duties, install applications of Tamir with the system and method of Narayanan and Srivastava resulting in a system and method that provides each of operators, vault owners with different levels of administrative right/privileges as in Tamir. One or ordinary skill in the art would have been motivated to make this combination for the purpose of preventing attacks initiated remotely (e.g., via SSH, SSM, etc.) and locally (e.g., through cloning or retrieving information from the hardware hosting the guest VM) (par. 0040)). Narayanan, Srivastava and Tamir do not expressly describe: capture a measurement from the CVM during a build process performed by the third party, the build process including installation of a guest operating system and/or a user application, and the captured measurement pertaining to the guest operating system and/or the user application. However, Song teaches: capture a measurement from the CVM during a build process performed by the third party, the build process including installation of a guest operating system and/or a user application, and the captured measurement pertaining to the guest operating system and/or the user application (par. 0032 Each hypervisor may be configured to establish a chain of trust into each virtual machine 118. The chain of trust may be established into each virtual machine 118 … before instantiation [during build process] of the virtual machine; par. 0033 the boot loader may be configured to measure the operating system binary to generate an operating system measurement and may be further configured to store the operating system measurement in the sealed memory. Further, after instantiating [after installing] the operating system 120 from the operating system binary, the operating system 120 may be configured to measure each of the one or more application binaries of the virtual machine image to generate a corresponding application measurement and may be further configured to store the application measurement in the sealed memory). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the technique of generating measurements of the operating system and applications of the a virtual machine of Song with the system and method of Narayanan, Srivastava and Tamir resulting in a system which provides for generating measurements of the guest OS and applications of the a virtual machine during build process of the VM as in Song. One of ordinary skill in the art would have been motivated to make this combination for the purpose of improving performance by establishing a chain of trust into a virtual machine (par. 0072). As per claim 2, Narayanan further teaches: identify an operational software policy that identifies the captured measurement and an expected value for the captured measurement (page 1, right column, last paragraph, comparing entries in the measured boot and IMA logs with a pre-defined set of acceptable values (called an attestation policy) and exposing any measurements that do not conform to policy expectations); transmit an attestation request to an attestation agent being executed by the CVM, the attestation request identifying the captured measurement to be attested by the attestation agent (page 4, left column, lines 41-44 SVSM-vTPM establishes a chain of trust by generating an SEV-SNP attestation report by passing the 𝑑𝑖𝑔𝑒𝑠𝑡(𝐸𝐾𝑝𝑢𝑏) as the user-data along with the attestation request and thus relying only on the AMD hardware; Fig. 2, attestation request to a SVSM-vTPM; page 8, left column, last paragraph, Keylime verifier initiates the attestation protocol by sending a TPMquote request to the agent; Fig. 3 attestation request); receive an evidence message from the attestation agent of the CVM, the evidence message including a current reading of the captured measurement (page 8, left column, last paragraph, The agent sends back the requested quote signed by the TPM, using the AIK associated during the registration phase. In addition, a number of logs (e.g. measured boot log, IMA log) are sent back with the quote); and verify the current reading of the captured measurement using with respect to the expected value of the captured measurement identified in the operational software policy (page 8, left column, last paragraph, The verifier validates the TPM quote by decrypting it with the registered AIK; validates the logs by testing them against the PCRs contained in the quote; and finally checks the contents of the logs against the attestation policy to render a trustworthy/untrustworthy verdict), Shrivastava further teaches: wherein causing the CVM to enter operational service includes causing the CVM to enter operational service when the current reading is verified against the expected value (par. 0020 For a Guest Owner to verify that the guest that is running authentic software and has not been tampered with, it needs to establish a secure communication channel with the PSP and obtain a measurement of the guest. A measurement includes a hash of the guest's memory contents and is not deemed to change on every boot. Note that SEV is transparent to guest applications but guest kernels need to be made SEV aware to support this capability …The Guest Owner can verify the hash provided by the PSP of the guest, and only then proceed to deliver a disk decryption key to the guest. This allows the guest to decrypt the disk and process the confidential data. The guest VM is now fully operational and protected by SEV). As per claim 3, Narayanan further teaches: wherein the attestation request is a software-based attestation request (page 8, left column, last paragraph, Keylime verifier initiates the attestation protocol by sending a TPMquote request to the agent; Fig. 3 attestation request), Srivastava further teaches wherein the instructions are further operative to transmit a hardware-based attestation request to the at least one confidential compute component supporting the CVM prior to cause the CVM to enter operational service (par. 0015 using hardware-based secure attestation in a virtualized computing system; par. 0020 The Guest Owner can verify the hash provided by the PSP of the guest, and only then proceed to deliver a disk decryption key to the guest. This allows the guest to decrypt the disk and process the confidential data. The guest VM is now fully operational and protected by SEV). As per claim 4, Srivastava further teaches: wherein causing the CVM to enter operational service further includes transmitting an attestation decision to a key management service, thereby causing the key management service to transmit a decryption key to the CVM for use in decrypting protected data used during the operational service of the CVM (par. 0020 The Guest Owner can verify the hash provided by the PSP of the guest, and only then proceed to deliver a disk decryption key to the guest. This allows the guest to decrypt the disk and process the confidential data. The guest VM is now fully operational and protected by SEV). As per claim 6, Narayanan further teaches: wherein the captured measurement (page 7, lines 7-8 measurements that are included as part of the attestation report). Tamir further teaches information about an administrative account currently present on the CVM (par. 0025 cloud provider owner(s) 101, cloud account owner(s) 102, cloud account operator(s), vault owner 104 with administrative privileges). As per claim 8, it is a computer-implemented method having similar limitations as claim 1. Thus, claim 8 is rejected for the same rationale as applied to claim 1. As per claim 9, it is a computer-implemented method having similar limitations as claim 2. Thus, claim 9 is rejected for the same rationale as applied to claim 2. As per claim 10, it is a computer-implemented method having similar limitations as claim 3. Thus, claim 10 is rejected for the same rationale as applied to claim 3. As per claim 11, it is a computer-implemented method having similar limitations as claim 4. Thus, claim 11 is rejected for the same rationale as applied to claim 4. As per claim 13, it is a computer-implemented method having similar limitations as claim 6. Thus, claim 13 is rejected for the same rationale as applied to claim 6. 7. (Currently Amended) The confidential compute system of claim 1, wherein the captured measurement further includes a hash of a filesystem of the CVM. As per claim 15, it is a computer storage device having similar limitations as claim 1. Thus, claim 15 is rejected for the same rationale as applied to claim 1. Srivastava further teaches: a computer storage device (par. 0072 Computer readable media). As per claim 16, it is a computer storage device having similar limitations as claim 2. Thus, claim 16 is rejected for the same rationale as applied to claim 2. As per claim 17, it is a computer storage device having similar limitations as claim 3. Thus, claim 17 is rejected for the same rationale as applied to claim 3. As per claim 18, it is a computer storage device having similar limitations as claim 4. Thus, claim 18 is rejected for the same rationale as applied to claim 4. As per claim 20, it is a computer storage device having similar limitations as claim 6. Thus, claim 20 is rejected for the same rationale as applied to claim 6. Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Narayanan in view of Srivastava, Tamir and Song, and further in view of Dodeja et al. (U.S. Pub. No. 20140122897 A1). Dodeja was cited in previous office action. As per claim 7, Narayanan, Srivastava, Tamir and Song do not expressly disclose: wherein the captured measurement further includes a hash of a filesystem of the CVM. However, Dodeja teaches: wherein the captured measurement further includes a hash of a filesystem of the CVM (par. 0026 HSTC 152 includes making measurements of the components included in the scope; par. 0038 The standard application of IMA seals measured hashes of the filesystem into the TPM). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the technique of making measurements and sealing measured hashes of a file system into a TPM of Tamir with the system and method of Narayanan, Srivastava, Tamir and Song resulting in a system and method in which measurements include hashes of a file system. One or ordinary skill in the art would have been motivated to make this combination for the purpose of determining integrity of the computing device (par. 0013). As per claim 14, it is a computer-implemented method having similar limitations as claim 7. Thus, claim 14 is rejected for the same rationale as applied to claim 7. Response to Arguments Applicant's arguments with respect to claims 1, 8 and 15 have been considered but are moot in view of the new ground(s) of rejection. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. NPL Prior art “"Introduction to confidential virtual machines" CN 119377944A English Translation Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Willy W. Huaracha whose telephone number is (571) 270-5510. The examiner can normally be reached on M-F 8:30-5:00pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bradley Teets can be reached on (571) 272-3338. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /WH/ Examiner, Art Unit 2195 /BRADLEY A TEETS/ Supervisory Patent Examiner, Art Unit 2197
Read full office action

Prosecution Timeline

Sep 11, 2023
Application Filed
Apr 01, 2026
Non-Final Rejection mailed — §103
May 19, 2026
Examiner Interview Summary
May 19, 2026
Applicant Interview (Telephonic)
Jun 01, 2026
Response Filed
Aug 19, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730677
EMBEDDED SYSTEM START CONTROL METHOD AND APPARATUS, AND STORAGE MEDIUM AND ELECTRONIC DEVICE
2y 8m to grant Granted Sep 08, 2026
Patent 12710989
JOB EXECUTION WITH MANAGED COMPUTE ENVIRONMENTS
4y 5m to grant Granted Aug 18, 2026
Patent 12693892
PLATFORM FRAMEWORK COMMUNICATIONS
5y 1m to grant Granted Jul 28, 2026
Patent 12646025
DELTA BASED TASK ANALYSIS FOR CI SYSTEMS
3y 7m to grant Granted Jun 02, 2026
Patent 12625741
LCS RESOURCE DEVICE FUNCTIONALITY PROVISIONING SYSTEM
3y 10m to grant Granted May 12, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
73%
Grant Probability
99%
With Interview (+54.4%)
4y 1m (~1y 0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 416 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month