DETAILED ACTION
Claims 1-20 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 03/05/2024 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
The following claim limitation is unclear:
As per claims 1, 8 and 15, they recite “processing data associated with the first tenant using the first set of resources”, “processing data associated with the second tenant using the second set of resources”, and “a data privacy and compliance component configured to receive data regarding a state of data in the system”. It is unclear from the context of the claims whether the state of the data in the system correspond to the processed data or other data. For examination purposes, examiner interprets the limitation as audit logs of tenant telemetry data.
Claims 2-7, 9-14 and 16-20 are dependent on claims 1, 8 and 15 and fail to cure the deficiency set forth above for claim 1. Therefore, they are rejected under the same rationale above.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 2, 3, 7, 9, 10, 14 are rejected under 35 U.S.C. 103 as being unpatentable over Dilley et al. (US 10,791,168 B1) in view of Ren et al. (US 2023/0266957 A1), in further view of Cooper et al. (US 2026/0202963 A1).
Regarding claim 1, Dilley teaches the invention substantially as claimed including a system for providing secure multi-tenancy (Col. 1, lines 14-17: computers providing a multi-tenant compute platform with resource isolation, so that tenants sharing the platform do not interfere too greatly with each other.; Col. 3, line 60 through Col. 4, line 28: The system 102 includes a placement orchestration manager 104 and a plurality of clusters 106 that are coupled to the orchestration manager 104 over a communication network 108 and that host tenant applications (e.g., A1-A4)… The manager 104 orchestrates the placement of tenant applications over the network 108 at the clusters 106, also referred herein as to as ‘edges’ or edge clusters…Edges 106 that host more than one tenant application maintain isolation of tenant applications from one another.) comprising:
a plurality of edge nodes, each edge node including at least one processor and a memory and being in communication with at least one other edge node via a communications network, wherein each edge node is configured to perform operations (Fig. 1, plurality of edge nodes 106; Col. 8, lines 44-50: FIG. 3 is an illustrative drawing representing hardware and software module layers of an edge node 122 of FIG. 2. The example edge node 122 includes a hardware layer 302 that includes a server system with one or more processors, storage memory, both dynamic (random access memory) and persistent (disk medium) storage and a network interface as explained above.) including:
receiving, from a central management system via the communications network, resource isolation instructions associated with a first tenant (Col. 5, lines 20-51: Based upon tenant-specified performance requirements, the orchestration manager 104 orchestrates placement of tenant applications at edge data centers 106 steers external endpoint requests to edges where requested tenant applications are placed, and schedules execution of tenant applications at the edges…The edges 106 maintain isolation of different tenant applications from one another. For example, tenant applications that share an example edge 106 are isolated through one or more of operating system features that limit the amount of resources they can use, for example by time slicing central processing unit (CPU) time, network bandwidth, and disk access; or providing hard limits on amount of disk or memory storage used, for example; Col. 5, line 64 through Col. 6, line 1: The orchestration manager tracks resource usage of currently existing edges, adjusts edge resource allocation as needed to meet current and expected traffic needs, determines where tenant applications should be placed; Col. 22, lines 63-67: instructing the edge message client 533 to download the tenant workload code package and a corresponding configuration specification and instructing the edge message client 533 to execute the tenant workload according to settings in the configuration specification, such as settings as to scheduling and edge resource allocation, for example);
in response to receiving the resource isolation instructions associated with the first tenant, allocating a first set of resources to the first tenant (Col. 5, lines 20-51: The edges 106 maintain isolation of different tenant applications from one another. For example, tenant applications that share an example edge 106 are isolated through one or more of operating system features that limit the amount of resources they can use, for example by time slicing central processing unit (CPU) time, network bandwidth, and disk access; or providing hard limits on amount of disk or memory storage used, for example. Col. 6, lines 20-23: An example orchestration manager 104 manages placement of tenant applications at edge data centers based at least in part upon individual tenant application owner specified performance factors…Depending at least in part upon tenant application owner preferences for different tenant application, an example orchestration manager can place instances of multiple different tenant applications at some edge data centers 106.);
receiving, from the central management system, resource isolation instructions associated with a second tenant different than the first tenant (Col. 1, lines 14-17: computers providing a multi-tenant compute platform with resource isolation, so that tenants sharing the platform do not interfere too greatly with each other; Col. 5, lines 20-51; process is the same for different tenants in the multi-tenant environment; Col. 22, lines 63-67);
in response to receiving the resource isolation instructions associated with the second tenant, allocating a second set of resources to the second tenant (Col. 1, lines 14-17: computers providing a multi-tenant compute platform with resource isolation, so that tenants sharing the platform do not interfere too greatly with each other; Col. 5, lines 20-51: Col. 6, lines 20-23) , wherein the first set of resources and the second set of resources are distinct (Col. 5, lines 27-29: Different tenant applications typically have different performance requirements.);
processing data associated with the first tenant using the first set of resources (Col. 1, lines 35-39: Examples of cloud services include online data storage and backup solutions, Web-based e-mail services, hosted office suites and document collaboration services, database processing and managed technical support services.; Col. 5, lines 5-6: Different tenant applications provide different application services to external endpoint devices 110.; Col. 23, lines 6-8: The edge workload manager 534 at each edge receives a message to run the tenant workload); processing data associated with the second tenant using the second set of resources (Col. 1, lines 35-39; Col. 5, lines 5-6; Col. 23, lines 6-8).
Dilley teaches allocating/limiting edge resources based on a configuration specification provided by the tenant and resource availability (See at least Col. 22 line 57 through Col. 23 line 6) but does not explicitly teaches a first and second set of resources, wherein the first set of resources and the second set of resources are distinct; and
a data privacy and compliance component configured to receive data regarding a state of data in the system and to generate a compliance report based on the received data.
However, Ren teaches a first and second set of resources, wherein the first set of resources and the second set of resources are distinct ([0021]; [0025] The pod controller receives instructions from an orchestrator (e.g., orchestrator 260) that instructs the controller on how best to partition physical resources and for what duration, such as by receiving key performance indicator (KPI) targets based on SLA contracts. The pod controller determines which container requires which resources and for how long in order to complete the workload and satisfy the SLA. The pod controller also manages container lifecycle operations such as: creating the container, provisioning it with resources and applications, coordinating intermediate results between multiple containers working on a distributed application together, dismantling containers when workload completes, and the like. [0029] tenant isolation may be orchestrated where the resources allocated to a tenant are distinct from resources allocated to a second tenant, but edge owners cooperate to ensure resource allocations are not shared across tenant boundaries.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Ren with the teachings of Dilley to provide separate sets of resources depending on the workload/application requested by the tenant. The modification would have been motivated by the desire of combining known methods of resource partitioning to yield predictable results of isolated execution environments in edge systems.
Dilley and Ren do not expressly teach a data privacy and compliance component configured to receive data regarding a state of data in the system and to generate a compliance report based on the received data.
However, Cooper teaches a data privacy and compliance component configured to receive data regarding a state of data in the system and to generate a compliance report based on the received data ([0250] Collectively, components illustrated in FIG. 50 enable distributed and federated compaction telemetry systems that provide comprehensive visibility and control across large-scale deployments while preserving privacy, isolation, and data locality guarantees. Through distributed collection of telemetry at endpoints via local telemetry components 5014, 5024, and 5034, aggregation via telemetry aggregator 5040, analysis via central analyzer 5050 and federated analyzer 5060, and policy distribution via policy distributor 5070, the distributed architecture enables scalable monitoring, analysis, and adaptive control of anonymized data compaction systems across diverse deployment scenarios including cloud environments, edge computing deployments, multi-tenant platforms, and geographically distributed infrastructures. This distributed approach transforms anonymized data compaction from isolated endpoint operations into collaborative, coordinated systems capable of detecting and responding to complex threats and conditions that span multiple endpoints, administrative domains, or organizational boundaries while maintaining strict privacy and isolation guarantees essential for regulatory compliance and contractual obligations.; [0260] Report generator 5170 represents a component configured to generate comprehensive reports consolidating analysis results from analytics engine 5150 and actionable insights from insight generator 5160 into customer-facing documents suitable for executive review, compliance documentation, or technical analysis. Report generator 5170 produces reports in various formats including portable document format files, hypertext markup language dashboards, comma-separated value data exports, or application programming interface responses depending on customer preferences and intended use cases. Reports generated by report generator 5170 may include executive summaries highlighting key findings and recommendations, detailed technical analyses of telemetry patterns and anomalies, trend visualizations showing temporal evolution of compaction behavior, security assessments identifying potential threats or vulnerabilities, and compliance attestations documenting adherence to regulatory requirements.; [0261] Tenant isolation layer 5180 enforces tenant-specific permissions throughout processing pipeline including telemetry processor 5140, analytics engine 5150, insight generator 5160, and report generator 5170 to prevent cross-tenant information leakage. In some embodiments, tenant isolation layer 5180 enables aggregation or comparative analysis across tenants performed only on anonymized or normalized telemetry representations that prevent inference of tenant-specific data characteristics, wherein such cross-tenant analysis may be used to establish population-level baselines or detect coordinated threats affecting multiple tenants while maintaining strict separation of customer-specific details. Tenant isolation layer 5180 maintains audit logs documenting all access to tenant-specific telemetry and analytic results to enable compliance verification and incident investigation. Such isolation enables analytics-as-a-service offerings while maintaining contractual and regulatory separation between tenants, thereby facilitating compliance with data protection regulations that mandate tenant data segregation in shared infrastructure environments.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Cooper with the teachings of Dilley and Ren to analyze logs/data to determine compliance and generate compliance verification reports. The modification would have been motivated by the desire of facilitating responsible data sharing, organizations frequently anonymize datasets prior to use in analytics, machine learning applications, or third-party transfers. (See at least [0014])
Regarding claim 2, Dilley teaches the operations performed by each edge node further including:
receiving, from the central management system, access control instructions associated with the first tenant, in response to receiving the access control instructions associated with the first tenant, controlling access by the first tenant to data associated with the edge node based on the access control instructions (Col. 5, lines 43-51: The edges 106 maintain isolation of different tenant applications from one another. For example, tenant applications that share an example edge 106 are isolated through one or more of operating system features that limit the amount of resources they can use, for example by time slicing central processing unit (CPU) time, network bandwidth, and disk access; or providing hard limits on amount of disk or memory storage used, for example.; Col. 7, lines 11-16; Col. 8, lines 58-67: In operation, each edge node 122 includes processor hardware that runs an operating system, container and cluster scheduling and management software, and tenant workloads. The container management system layer 304 manages the execution of software containers, including controlling each container's access to storage, memory, and processing resources in order to support a multi-tenant compute platform. The cluster scheduling layer 305 manages the placement of containers on nodes according to configuration settings.).
Regarding claim 3, Dilley teaches wherein controlling access to data includes preventing the first tenant from accessing data not associated with the first tenant (Col. 7, lines 11-16: The system steers requests for access to tenant applications to the most appropriate edges, such that external endpoints 110 can access the hosted applications with tenant-specified levels of performance. The system maintains isolation of tenant applications sharing an edge 106.;).
Regarding claim 7, Dilley teaches wherein controlling access to data is performed in accordance with a set of compliance requirements (Col. 5, lines 43-51: The edges 106 maintain isolation of different tenant applications from one another. For example, tenant applications that share an example edge 106 are isolated through one or more of operating system features that limit the amount of resources they can use, for example by time slicing central processing unit (CPU) time, network bandwidth, and disk access; or providing hard limits on amount of disk or memory storage used, for example).
Regarding claim 8, it is a method claim having similar limitations as claim 1 above. Therefore, it is rejected under the same rationale above.
Regarding claim 9, it is a method claim having similar limitations as claim 2 above. Therefore, it is rejected under the same rationale above.
Regarding claim 10, it is a method claim having similar limitations as claim 3 above. Therefore, it is rejected under the same rationale above.
Regarding claim 14, it is a method claim having similar limitations as claim 7 above. Therefore, it is rejected under the same rationale above.
Regarding claim 15, it is a media/product claim having similar limitations as claim 1 above. Therefore, it is rejected under the same rationale above.
Regarding claim 16, it is a media/product claim having similar limitations as claim 2 above. Therefore, it is rejected under the same rationale above.
Regarding claim 17, it is a media/product claim having similar limitations as claim 3 above. Therefore, it is rejected under the same rationale above.
Claims 4-6, 11-13 and 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over Dilley, Ren and Cooper, as applied to claim 1, in view of Guim Bernat et al. (US 2021/0014047 A1).
Regarding claim 4, Dilley, Ren nor Cooper teach the limitations of claim 4 but Guim Bernat teaches wherein controlling access to data includes encrypting data associated with the first tenant using credentials exclusive to the first tenant ([0028] Data in the edge environment can be stored in data lakes. As used herein, a data lake refers to a storage and/or repository that can store both unstructured (e.g., raw) data and structured data at any scale. A data lake region refers to a region or partition of the data lake, where each data lake can be partitioned into any number of data lake regions of varying size. The data lake regions corresponding to a data lake can be stored across one or more edge devices. Partitioning of the data lake into data lake regions increases privacy of the data stored therein, as each tenant (e.g., user, entity requesting access, etc.) can be granted access only to particular regions of the data lake. Additionally, encryption and/or decryption of data can occur at the level of an individual data lake region to avoid having to encrypt and/or decrypt an entire corresponding data lake, thereby reducing processing times.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Guim Bernat with the teachings of Dilley to encrypt data associated with a tenant with the teachings of Dilley, Ren and Cooper. The modification would have been motivated so that encryption and/or decryption of data can occur at the level of an individual data lake region to avoid having to encrypt and/or decrypt an entire corresponding data lake, thereby reducing processing times
Regarding claim 5, Guim Bernat teaches wherein encrypting data includes encrypting data stored in the memory of the edge node ([0140] The example data encryptor 1108 encrypts data in a data lake region (e.g., the data lake region A 917A and/or the data lake region B 917B). For example, in response to the service 922 writing new data to the data lake region A 917A, the data encryptor 1108 receives the RDEK corresponding to the data lake region A 917A from the key manager 1106 and encrypts the new data using the RDEK. Additionally or alternatively, the data encryptor 1108 encrypts data in the data lake region using the homomorphic encryption key from the key manager 1106.).
Regarding claim 6, Guim Bernat teaches wherein encrypting data includes encrypting data prior to transmission of the data by the edge node via the communications network ([0214] the service 922 encrypts the written data prior to sending the data to the instruction analyzer 1100.).
Regarding claim 11, it is a method claim having similar limitations as claim 4 above. Therefore, it is rejected under the same rationale above.
Regarding claim 12, it is a method claim having similar limitations as claim 5 above. Therefore, it is rejected under the same rationale above.
Regarding claim 13, it is a method claim having similar limitations as claim 6 above. Therefore, it is rejected under the same rationale above.
Regarding claim 18, it is a media/product claim having similar limitations as claim 4 above. Therefore, it is rejected under the same rationale above.
Regarding claim 19, it is a media/product claim having similar limitations as claim 5 above. Therefore, it is rejected under the same rationale above.
Regarding claim 20, it is a media/product claim having similar limitations as claim 6 above. Therefore, it is rejected under the same rationale above.
Response to Arguments
Applicant’s arguments with respect to claims 07/02/2026 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JORGE A CHU JOY-DAVILA whose telephone number is (571)270-0692. The examiner can normally be reached Monday-Friday, 6:00am-5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Aimee J Li can be reached at (571)272-4169. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JORGE A CHU JOY-DAVILA/Primary Examiner, Art Unit 2195