DETAILED ACTION
This communication is in response to the application filed on 03/05/2024 in which claims 1-20 are pending in the application. Claims 1, 14, and 20 are in independent form.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 04/12/2024 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 6 and 19 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 6 recites “wherein the virtual agent interacts with containers that are executing at different locations, within the virtual node, than the virtual agent,” the language renders the claim vague and indefinite. Although the claim recites an awkward middle-placement of the prepositional phrase, moving it to the end clarifies that the phrase modifies the entire preceding relational context rather than awkwardly splitting the comparison "than the virtual agent." Examiner suggest changing the language to “wherein the virtual agent interacts with containers that are executing at different locations than the virtual agent within the virtual node”. Appropriate correction is required. Claim 19 depends on claim 6 is similarly rejected.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-4, 14-17, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kalley (US 20230359508 A1) and in further view of Wennerström (US 20220158926 A1).
As per claim 1, Kalley discloses one or more non transitory computer readable media comprising instructions that, when executed by one or more hardware processors, cause performance of operations comprising: [¶ [0008], a non transitory computer readable medium storing specific computer-executable instructions that, when executed by a processor, cause a computer system to perform operations comprising]
executing a virtual agent in a first service tenancy of a cloud network manager [¶ [0141], the source agent is deployed in a source service tenancy of the source cloud environment],
executing a container orchestration API server in a second service tenancy of the cloud network manager [¶ [0039], in the execution cloud environment 231, the execution-side RFI service tenancy 233 includes a control plane 235 hosting the RFI invocation service] (Examiner Note: Control plane in this context acts similarly to an “API server”); and
routing a request from the container orchestration API server to the virtual agent through a customer tenancy of a customer of the cloud network manager [¶ [0052], the RFI control plane 303 submits a request to the forwarder agent 307 included in the notification cloud environment 201], [¶ [0038], the notification-side RFI service tenancy 203 includes a forwarder agent 205 and a metadata database 215 associated with the forwarder agent 205. The notification cloud environment 201 further includes a customer tenancy 209 and an identity management service 216. The customer tenancy 209 includes one or more cloud resources 211 that utilize one or more services provided in the notification cloud environment 201].
Kalley discloses the claimed invention as detailed above but does not explicitly teach the virtual agent being executed on a virtual node of a container orchestration system.
However, Wennerström discloses the virtual agent being executed on a virtual node of a container orchestration system [¶ [0506], The command that was used to verify that the Helm command had indeed created an Agent at every node in the Kubernetes cluster] (Examiner Note: Specification refer Kubernetes cluster as container orchestration system [¶ [12]).
Kalley and Wennerström are in the same field of endeavor as they are both in distributed cloud-management systems and, therefore, are combinable/modifiable.
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to modify the system of Kalley to include with the virtual agent running on a virtual node inside a container orchestration system as taught by Wennerström because putting the agent on virtual node to improve manageability.
Modification would improve cluster resource management and deployment efficiency by executing an agent on a node as taught by Wennerström [¶ 0506].
As per claim 2, the combination of Kalley and Wennerström discloses the claimed invention as detailed above for claim 1. Kalley discloses the non-transitory media of Claim 1, wherein, the second service tenancy and the customer tenancy are implemented within a same cloud environment [¶ [0038], an RFI service tenancy is included in each of the notification cloud environment 201 and the execution cloud environment 231. For example, as shown in FIG. 2, the notification cloud environment 201 includes an RFI service tenancy 203 that is referred to herein as a notification-side RFI service tenancy, and the execution cloud environment 231 includes an RFI service tenancy 233 that is referred to herein as an execution-side RFI service tenancy. In the notification cloud environment 201, the notification-side RFI service tenancy 203 includes a forwarder agent 205 and a metadata database 215 associated with the forwarder agent 205], [¶ [0028], according to some embodiments, the RFI service framework provides a user interface and command line interface (CLI) that provisions users of a cloud environment to configure an RFI instance in a customer's tenancy included in the cloud environment] and
configured to execute operations corresponding to a data set associated with the customer [¶ [0046], the listener agent 236 is disposed in a data plane of the RFI service in the execution-side RFI service tenancy 233. According to one embodiment, the listener agent 236 upon receiving the notification, performs a lookup operation to identify a function (and a corresponding customer tenancy that hosts the function)], [[¶ [0102], the customer of the IaaS provider may grant temporary network access to the IaaS provider and request a function to be attached to the data plane tier app 846. Code to run the function may be executed in the VMs 866(1)-(N), and the code may not be configured to run anywhere else on the data plane VCN 818. Each VM 866(1)-(N) may be connected to one customer tenancy 870].
As per claim 3, the combination of Kalley and Wennerström discloses the claimed invention as detailed above for claim 1. Kalley discloses the non-transitory media of Claim 1, wherein the first service tenancy, the second service tenancy and the customer tenancy are implemented within a same cloud environment [¶ [0047], the execution policy 245 defines whether a service e.g., the listener agent 236 deployed in the execution side service tenancy is permitted to access the function(s) deployed in the customer tenancy 243 of the execution cloud environment 231. Upon a successful check being performed, the serverless function service 241 launches the function 242 in the customer tenancy 243] and
configured to execute operations corresponding to a data set associated with the customer [¶ [0102], the containers 871(1)-(N) may be communicatively coupled to the customer tenancy 870 and may be configured to transmit or receive data from the customer tenancy 870].
As per claim 4, the combination of Kalley and Wennerström discloses the claimed invention as detailed above for claim 1. Kalley discloses the non-transitory media of Claim 1, wherein routing the request through the customer tenancy comprises addressing the request to a service virtual network interface controller (VNIC) in the customer tenancy that sends the request to the virtual agent [¶ [0042], upon receiving the request from the forwarder agent 205 to register as the target with respect to notifications, the cloud resources 211 (deployed in the customer tenancy 209 of the notification cloud environment 201) communicates with the identity management service 216 to validate the request from the forwarder 205], [¶ [0099], VNICs 864(1)-(N) that can be communicatively coupled to tenant virtual machines (VMs) 866(1)-(N). Each tenant VM 866(1)-(N) can be communicatively coupled to a respective app subnet 867(1)-(N) that can be contained in respective container egress VCNs 868(1)-(N) that can be contained in respective customer tenancies 870(1)-(N)].
As per claim 14, the claim is rejected using the same rationale as noted above for claim 1.
As per claim 15, the claim is rejected using the same rationale as noted above for claim 2.
As per claim 16, the claim is rejected using the same rationale as noted above for claim 3.
As per claim 17, the claim is rejected using the same rationale as noted above for claim 4.
As per claim 20, the claim is rejected using the same rationale as noted above for claim 1.
Claim(s) 5, 6, 10, 12, 13, 18, and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kalley (US 20230359508 A1) and Wennerström (US 20220158926 A1) and further in view of Seshandri (US 11436035 B2).
As per claim 5, the combination of Kalley and Wennerström discloses the claimed invention as detailed above for claim 1 but does not explicitly teach the non transitory media of Claim 1, wherein the virtual agent includes a first virtual agent replica executed by a first host and a second virtual agent replica executed by a second host, wherein the second virtual agent replica operates even when the first virtual agent replica fails.
However, Seshandri discloses wherein the virtual agent includes a first virtual agent replica executed by a first host and a second virtual agent replica executed by a second host [Col. 14:1-3, instantiating at least one virtual agent in each of the virtual appliances, wherein each virtual agent performs a remote access function in the cloud architecture], [Col. 3 4:65-67, 1-11, the private cloud computing environment 102 of the hybrid cloud system 100 includes one or more virtual appliances VA-1, VA-2, . . . , VA-N, where N is a positive integer, in which proxy services 110-1, 110-2, . . . , 110-N and virtual agents 112 reside. As used herein, the term “virtual appliance” refers to any software processing entity that can run on a computer system, such as a software application, a software process, a virtual machine (VM), e.g., a VM supported by virtualization products of VMware, Inc., and a software “container”, e.g., a Docker container. In some instances, the virtual computing instances will be described as being virtual machines, although embodiments of the invention described herein are not limited to virtual machines]
wherein the second virtual agent replica operates even when the first virtual agent replica fails [Col. 13:50-51, generating a new container image for a first virtual agent in a first virtual appliance of the virtual appliances].
Kalley, Wennerström, and Seshadri are in the same field of endeavor and they are all directed to distributed, multi-tenant cloud-management systems, and therefore are combinable/modifiable.
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to modify the system of Kalley and Wennerström to include where the virtual agent has two replicas running on different hosts as taught by Seshandri in order to have the second agent keep working even if the first one fails.
Modification would improve system reliability and by maintain continuous service availability through redundant execution, as taught by Seshandri [Col. 14].
As per claim 6, Seshandri discloses the non-transitory media of Claim 1, wherein the virtual agent interacts with containers that are executing at different locations, within the virtual node, than the virtual agent [Col. 12:52-54, instantiating at least one virtual agent in each of the virtual appliances, wherein each virtual agent performs a remote access function in the cloud architecture].
As per claim 10, the combination of Kalley and Wennerström discloses the claimed invention as detailed above for claim 1. Kalley discloses the non-transitory media of Claim 1, wherein the customer tenancy includes a customer network, and the virtual agent is attached to the customer network [¶ [0031], further, the notification cloud environment 101 includes a customer tenancy 102 and the execution cloud environment includes a customer tenancy 113][ ¶ [0006], the source agent being deployed in a source cloud environment that is different than the target cloud environment; determining, by the target agent, a function that is to be invoked based on the notification; verifying whether the target agent is permitted to invoke the function that is deployed in a target customer tenancy of the target cloud environment; and responsive to a successful verification, invoking by the target agent the function in the target customer tenancy of the target cloud environment].
The combination discloses the claimed invention as detailed above for claim 1 but does not explicitly teach with a service virtual network interface controller (VNIC) with a single address for a first virtual agent replica and a second virtual agent replica executing on different hosts.
However, Seshandri discloses with a service virtual network interface controller (VNIC) with a single address for a first virtual agent replica and a second virtual agent replica executing on different hosts [Col. 14:1-3, instantiating at least one virtual agent in each of the virtual appliances, wherein each virtual agent performs a remote access function in the cloud architecture], [Col. 3-4:65-67, 1-11, the private cloud computing environment 102 of the hybrid cloud system 100 includes one or more virtual appliances VA-1, VA-2, . . . , VA-N, where N is a positive integer, in which proxy services 110-1, 110-2, . . . , 110-N and virtual agents 112 reside. As used herein, the term “virtual appliance” refers to any software processing entity that can run on a computer system, such as a software application, a software process, a virtual machine (VM), e.g., a VM supported by virtualization products of VMware, Inc., and a software “container”, e.g., a Docker container. In some instances, the virtual computing instances will be described as being virtual machines, although embodiments of the invention described herein are not limited to virtual machines].
Kalley, Wennerström, and Seshadri are in the same field of endeavor and they are all directed to distributed, multi-tenant cloud-management systems, and therefore are combinable/modifiable.
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to modify the system of Kalley and Wennerström to include a service virtual network interface controller that provides one shared address for two virtual agent replicas running on different host as taught by Seshandri because to simplify how the virtual agent connects to the customer network.
Modification would improve high availability and load distribution by deploying replicas across separate hosts while maintaining a single service VNIC address on the customer network as taught by Seshandri [Col. 3-4].
As per claim 12, the combination of Kalley and Wennerström discloses the claimed invention as detailed above for claim 1. Kalley discloses the first service tenancy under control of the cloud network manager without requiring a request from the customer [¶ [0047], upon identifying the function (and the corresponding customer tenancy in the execution cloud environment hosting the function), the listener agent 236 obtains a credential e.g., a token, from the identity management service 239 of the execution cloud environment 231. Further, the listener agent 236 forwards the token to the serverless function service 241 in order to use the serverless function service 241 to invoke the function 242 in the customer tenancy 243].
The combination discloses the claimed invention as detailed above for claim 1 but does not explicitly teach patching a version of the virtual agent in the first service tenancy.
However, Seshandri discloses patching a version of the virtual agent in the first service tenancy [Col. 13:49-54, generating a new container image for a first virtual agent in a first virtual appliance of the virtual appliances; registering a new version of the first virtual agent that corresponds to the new container image; and updating the first virtual agent to the new version based on the new container image].
Kalley, Wennerström, and Seshadri are in the same field of endeavor and they are all directed to distributed, multi-tenant cloud-management systems, and therefore are combinable/modifiable.
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to modify the system of Kalley and Wennerström to include automatically updating the virtual agent in the first service tenancy under the cloud manager’s control without the customer having to request it as taught by Seshandri because to keep the system updated without needing the customer to do anything.
Modification would patch the virtual agent version in the first service tenancy under cloud network manager control proactively, boosting system stability and performance without customer delay as taught by Seshandri [Col. 13].
As per claim 13, Seshandri discloses the non-transitory media of Claim 1, wherein the virtual agent in the first service tenancy is protected using cloud network security for the first service tenancy [Col. 12:57 59, controlling the at least one virtual agent in each of the virtual appliances based on communications with the cloud framework], [Col. 7:31-36, a virtual appliance is deployed with the secret key and a security certificate. The security certificate may be automatically generated in the virtual appliance or provided to the virtual appliance during virtual application deployment process].
As per claim 18, the claim is rejected using the same rationale as noted above for claim 5.
As per claim 19, the claim is rejected using the same rationale as noted above for claim 6.
Claim(s) 7-9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kalley (US 20230359508 A1) and Wennerström (US 20220158926 A1) and further in view of Lee (US 20240080277 A1).
As per claim 7, the combination of Kalley and Wennerström discloses the claimed invention as detailed above for claim 1. Kalley discloses wherein the container orchestration API server sends the request through the customer tenancy [¶ [0042], receiving the request from the forwarder agent 205 to register as the target with respect to notifications, the cloud resources 211 (deployed in the customer tenancy 209 of the notification cloud environment 201) communicates with the identity management service 216 to validate the request from the forwarder 205] and
wherein the request is rerouted to the virtual agent in the first service tenancy [¶ [0042], receiving the request from the forwarder agent 205 to register as the target with respect to notifications, the cloud resources 211 (deployed in the customer tenancy 209 of the notification cloud environment 201) communicates with the identity management service 216 to validate the request from the forwarder 205. In one implementation, in validating the request, an authentication process is performed based on a subscription policy 213 defined by a user. The subscription policy 213 defines whether the forwarder agent 205 (i.e., in the RFI service account/tenancy 203)].
The combination discloses the claimed invention as detailed above for claim 1 but does not explicitly teach the non-transitory media of Claim 1, wherein the request is to create, update or destroy containers for the virtual node.
However, Lee discloses the non-transitory media of Claim 1, wherein the request is to create, update or destroy containers for the virtual node [¶ [0254], the container runtime 1502 (e.g., in response to the request at step 4) may execute operations to create container(s) 1504].
Kalley, Wennerström, and Lee are in the same field of endeavor as they all focus on cloud computing, resource management, and virtualized infrastructure and, therefore, are combinable/modifiable.
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to modify the system of Kalley and Wennerström to include where the request is simply to create, update, or delete containers for the virtual node as taught by Lee in order to add a way to manage a virtual node.
Modification would improve security and tenant isolation by routing container requests securely through the customer tenancy to the virtual agent by Lee [¶ [0254]].
As per claim 8, Lee discloses the non-transitory media of Claim 1, wherein the virtual agent instructs a container instance control plane to create, update, or destroy container instances containing container orchestration pods [¶ [0152], kubelet 606 may execute instructions to pull images (e.g., contained in containers 220, 222, and 224) and start the containers of the new pod (e.g., pod 234)], [¶ [0147], at step 10, kubelet 606 may execute any suitable operations that stop containers (e.g., containers 220, 222, and 224) of the pod (e.g., pod 234) and delete the pod from the node], [¶ [0181], the ODO operator 912 may call the API server 928 (part of the Kubernetes control plane 604 of FIG. 6) in the SMC cluster to create pods (or workload objects, containers, etc.), and then waits for their successful creation as described above in connection with FIG. 6].
As per claim 9, Lee discloses the non-transitory media of Claim 7, wherein the virtual agent, the container orchestration API server and container orchestration pods in container instances are part of a Kubernetes cluster and the container instances contain a kube-proxy [¶ [0110-0111], In some embodiments, the Kubelets (e.g., Kubelets 312 and 314) may be individually configured to ensure that containers are running in a pod. The Kubelets may obtain pod specifications that are provided through various mechanisms to ensure that the containers described in those pod specifications are running and healthy. Kube proxy 316 and Kube proxy 318 may be network proxies that run on each node (e.g., node 313 and 315, respectively) and maintain network rules on each node. These network rules allow network communication to these pods from network sessions inside or outside the cluster (e.g., a cluster of nodes including the nodes 313 and 315)], [¶ [0181], the ODO operator 912 may call the API server 928 (part of the Kubernetes control plane 604 of FIG. 6) in the SMC cluster to create pods (or workload objects, containers, etc.)].
Claim 11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kalley (US 20230359508 A1) and Wennerström (US 20220158926 A1) and further in view of Fischman (US 7647329 B1).
As per claim 11, the combination of Kalley and Wennerström discloses the claimed invention as detailed above for claim 1 but does not explicitly teach the non-transitory media of Claim 10, wherein messages are load balanced by the Service VNIC between the first virtual agent replica and the second virtual agent replica.
However, Fischman discloses wherein messages are load balanced by the Service VNIC between the first virtual agent replica and the second virtual agent replica [Col. 11:26-34, web services platform 100 may be configured as a number of distinct systems (e.g., in a cluster topology) implementing load balancing and other request management features configured to dynamically manage large-scale web services request processing loads].
Both Kalley, Wennerström, and Fischman are in the same field of endeavor and they are all in distributed cloud-management systems, and therefore are combinable/modifiable.
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to modify the system of Kalley and Wennerström to include where the service virtual network interface controller spreads the message across both virtual agent replicas to balance the load as taught by Fischman because this provide a way to spread the work and keep the system running smoothly.
Modification would be to keep the system running smoothly by spreading message traffic across both replicas so no single replica gets overloaded, improving performance and reliability as taught by Fischman [Col. 11].
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Kearney (US 20230067904 A1) teaches “when a customer subscribes to or registers for a service provided by a CSP, a tenancy or an account is created for that customer. The customer can then, via this account, access the subscribed-to one or more cloud resources associated with the account” [¶ [0042]].
Levy (US 9509553 B2) teaches “a method of executing an original agent application as a virtual agent, the method comprising encapsulating an original agent in a container file to produce a virtual agent; providing the virtual agent to an endpoint machine; and executing the virtual agent” [Abstract].
Examiner has cited particular columns/paragraphs/sections and line numbers in the references applied and not relied upon to the claims above for the convenience of the applicant. Although the specified citations are representative of the teachings of the art and are applied to specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested from the applicant in preparing responses, to fully consider the references in entirety as potentially Page 14 Application/Control Number: 18/582,274 Art Unit: 2198 teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior art or disclosed by the Examiner.
When responding to the Office action, applicant is advised to clearly point out the patentable novelty the claims present in view of the state of the art disclosed by the reference(s) cited or the objections made. A showing of how the amendments avoid such references or objections must also be present. See 37 C.F.R. 1.111(c).
When responding to this Office action, applicant is advised to provide the line and page numbers in the application and/or reference(s) cited to assist in locating the appropriate paragraphs.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Tien Tram whose telephone number is (571) 270-3050. The examiner can normally be reached Mon-Fri, 8:00a-4:00p. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Pierre M. Vital can be reached at (571)272-4215. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/TIEN THANH TRAM/Examiner, Art Unit 2198
/PIERRE VITAL/Supervisory Patent Examiner, Art Unit 2198