DETAILED ACTION
This action is responsive to RCE filed on April 16th, 2026.
Claims 1~20 are examined.
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 04/16/26 has been entered.
Response to Arguments
Applicant’s arguments with respect to claim(s) 1~20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
In response to Applicant’s arguments (Pgs. 8~12), that the claims are not directed to a judicially recognized exception of an abstract idea for the reasons of amended claim 1 now reciting, “identifying, by the certificate service, a public key…”; specifying, by the certificate service, data for a principal certificate; generating, by the certificate service, a digital signature; issuing…the principal certificate to the substrate instance”. Examiner respectfully point out that although a digital certificate is a functional application of cryptography, when used in the claim, is still directed to an abstract idea. The claim recites the steps of how a conventional principal certificate is generated for nodes such as substrate instances by applying a known practice, such as signing or verifying a document to prove identity, onto a generic computer system obtains an identifier of a substrate instance in order to issue the principal certificate. There are no differences between a certificate generated for a substrate instance and a certificate generated for nodes in the cloud. The claims recite only the idea of a solution or outcome devoid of how a solution to a problem is accomplished.
None of the claim limitations improve the functioning of a computer or technology; are not applied with any particular machine; do not effect a transformation of a particular article to a different state; and are not applied in any meaningful way beyond generally linking the use of the judicial exception to a particular technological environment. These limitations automate the process of receiving a certificate after determining an identifier of a substrate instance. The amended claims do not improve the functioning of a computer or technology; are not applied with any particular machine; does not use a unique, specific cryptographic method; and are not applied in any meaningful way beyond generally linking the use of the judicial exception to a particular technological environment. The claims, as currently constructed, are thus ineligible nor patentable in view of the rejections set forth below.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1~20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter.
Step 2A Prong One: Claims 1 and 11 recite:
Claims 1, 15, and 19: “performing, by a certificate service of a cloud environment, a first fetch to obtain one or more of: (i) an identifier of a compartment that includes the substrate instance, or (ii) an identifier of the substrate instance; performing, by the certificate service, a second fetch to obtain an identifier of a tenancy that includes the substrate instance, based at least in part on one or more of: (i) the identifier of the compartment identified from the first fetch, or (ii) the identifier of the substrate instance identified from the first fetch; identifying, by the certificate service, a public key of a key pair corresponding to the substrate instance; specifying, by the certificate service, data for a principal certificate to be issued to the substrate instance, wherein the data comprises: (i) the identifier of the substrate instance from the first fetch, (ii) the identifier of the tenancy obtained from the second fetch, and (iii) the public key, generating, by the certificate service, a digital signature for the principal certificate, wherein the data specified in the principal certificate becomes verifiable based on the digital signature; and issuing, by the certificate service to the substrate instance, the principal certificate with the digital signature”
The limitation, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, other than reciting “cloud environment”, “one or more processors”, and “computer-readable storage medium”, nothing in the claim elements preclude the steps from practically being performed in the mind. For example, but for the reciting “cloud environment”, “one or more processors”, and “computer-readable storage medium”, “performing…”, “performing…”, “identifying…”, “specifying…”, “generating…” and “issuing” in the context of these claims encompasses concepts relating to organizing or analyzing information that can be performed mentally and concepts relating to performing mathematical calculations. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claims recite an abstract idea.
Step 2A Prong Two: This judicial exception is not integrated into a practical application because:
1. The claims recite additional elements reciting, “cloud environment”, “one or more processors”, and “computer-readable storage medium”, which are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
2. The claims recite additional element of “performing…a first fetch…”, “performing…a second fetch…”, and “issuing a principal certificate…”, which taken individually amounts to adding insignificant extra solution activity to the judicial exception. Accordingly, this additional element does not integrate the abstract idea into a practical application because claims 1, 15, and 19 as a whole is silent regarding specific limitations directed to improving a computer system, processor, memory, network, database, or the Internet, nor do Applicants direct any attention to such specific limitations.
Accordingly, claims 1, 15, and 19 are directed to an abstract idea.
Step 2B: Claims 1, 15, and 19 do not include additional elements that are sufficient to amount to significantly more than the judicial exception.
As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of “cloud environment”, “one or more processors”, and “computer-readable storage medium”, amount to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept.
Further, the insignificant extra solution activity performing…a first fetch…”, “performing…a second fetch…”, and “issuing…”, simply appends well-understood, routine and conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception. The courts recognize receiving or transmitting data over a network and storing and retrieving information in memory (see MPEP 2106.05(d)(II)).
Thus, taken alone, the additional elements do not amount to significantly more than a judicial exception. Looking at the limitations as an ordered combination adds nothing that is not already present when looking at the elements taken individually. There is no indication that the combination of elements improves the functioning of a computer or improves any other technology. The claims when read as an ordered combination is not significantly more than a judicial exception. For these reasons, claims 1 and 11 are not patent eligible.
Regarding dependent claims 2~14, 16~18 and 20
Claims 2~14, 16~18 and 20 recite elements/limitations that also fall within the “mental processes” grouping of abstract ideas, as identified above.
Looking at the limitations as an ordered combination adds nothing that is not already present when looking at the elements taken individually. There is no indication that the combination of elements improves the functioning of a computer or improves any other technology. The claims when read as an ordered combination is not significantly more than a judicial exception. For these reasons, claims 2~14, 16~18 and 20 are not patent eligible.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1~3, 10, 12~17, 19, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over A. et al. hereinafter A. (U.S 2023/0198975) in view of Knotwell et al. hereinafter Knotwell (U.S 2021/0058388).
Regarding Claim 1,
A. taught a method for issuing one or more certificates to a substrate instance of a cloud environment, the method comprising:
performing, by a certificate service of a cloud environment, a first fetch to obtain one or more of: (i) an identifier of a compartment that includes the instance [¶13, NMS provides a certificate to an endpoint device of a tenant that includes identification information associated with the endpoint device (e.g., an identifier associated with the endpoint device)], or (ii) an identifier of the substrate instance;
performing, by the certificate service, a second fetch to obtain an identifier of a tenancy that includes the instance, based at least in part on one or more of: (i) the identifier of the compartment identified from the first fetch [¶13, NMS provides a certificate to an endpoint device of a tenant that includes identification information associated with the endpoint device (e.g., an identifier associated with the endpoint device and the tenant (e.g., one or more identifiers associated with the tenant and/or a hierarchical structure of the tenant)); ¶17, ], or (ii) the identifier of the substrate instance identified from the first fetch;
issuing, by the certificate service to the instance, the principal certificate with the digital signature [¶18, generate a certificate that includes the identification information associated with the endpoint device and the tenant].
A. did not specifically teach identifying, by the certificate service, a public key of a key pair corresponding to the substrate instance; specifying, by the certificate service, data for a principal certificate to be issued to the substrate instance, wherein the data comprises: (i) the identifier of the substrate instance from the first fetch, (ii) the identifier of the tenancy obtained from the second fetch, and (iii) the public key and generating, by the certificate service, a digital signature for the principal certificate, wherein the data specified in the principal certificate becomes verifiable based on the digital signature; and a substrate instance.
Knotwell taught identifying, by the certificate service, a public key of a key pair corresponding to the substrate instance [¶25, a customized public key infrastructure certificate service (PKI service) is used to create digital certificates that include piggybacked virtual network identifiers associated with a computing cluster];
specifying, by the certificate service, data for a principal certificate to be issued to the instance, wherein the data comprises: (i) the identifier of the instance from the first fetch, (ii) the identifier of the tenancy obtained from the second fetch, and (iii) the public key [¶207, the host sends a message to PKI service 1185 requesting an instance principal certificate and including the unique cluster network identifier of the cluster network to which the host is assigned. PKI service 1185 retrieves the virtual network identifier associated with the unique cluster network identifier included in the request for the instance principal certificate in the list of all existing cluster networks. PKI service 1185 then generates an instance principal certificate];
generating, by the certificate service, a digital signature for the principal certificate, wherein the data specified in the principal certificate becomes verifiable based on the digital signature [¶121, PKI certificate agent generates a private key and request a digital certificate from a PKI service. PKI service retrieves the piggybacked virtual network identifier, includes it in the digital certificate, and signs it]; and
a substrate instance [¶141, cluster networking (CN) allowing a user to create a pool of bare metal machines (individual machines may also be referred to as nodes or hosts) that have been configured and launched identically. For example, each node in the cluster network is given a public key infrastructure digital certificate by the cloud infrastructure's identity service].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention was made, to combine, Knotwell’s teaching of limitations with the teachings of A., because the combination would allow isolation of the cluster without any host-side functionality, avoiding the need for a hypervisor or smart network interface to be involved in the process or even being present on the host [¶28].
Regarding Claim 2,
A.-Knotwell taught wherein the first fetch is performed by the certificate service from a substrate control plane for the cloud environment, and the second fetch is performed by the certificate service from an identity service for the cloud environment [¶25, a customized public key infrastructure certificate service (PKI service) is used to create digital certificates; ¶112; ¶141]. The rationale to combine as discussed in claim 1, applies here as well.
Regarding Claim 3,
A. taught wherein the substrate control plane is configured to provision compute capacity in the substrate instance [¶112, compute control plane service creates an instance pool for the new cluster. The instance pool is made up of the set of hosts assigned to the cluster and configured to operate in the cluster], and the identity service is configured to issue and/or maintain identities of a plurality of cloud resources within the cloud environment [¶85; ¶141]. The rationale to combine as discussed in claim 1, applies here as well.
Regarding Claim 10,
A.-Knotwell taught further comprising: subsequent to transmitting the information identifying the one or more certificates to be issued to the substrate instance, receiving a third request for the principal certificate, wherein the second fetch is performed responsive at least to receiving the third request [¶207, supplicant 1065 of the host sends a message to PKI service 1185 requesting an instance principal certificate and including the unique cluster network identifier of the cluster network to which the host is assigned]. The rationale to combine as discussed in claim 1, applies here as well.
Regarding Claim 12,
A.-Knotwell taught wherein the principal certificate has a field specifying a time duration for which the principal certificate is valid [¶210, validation includes determining that the instance principal certificate is (i) currently active and has not expired]. The rationale to combine as discussed in claim 1, applies here as well.
Regarding Claim 13,
A.-Knotwell taught wherein the time duration for which the principal certificate is valid is within a range of 1 hour and 7 days [¶224, instance principal certificates expire after a certain amount of time (for example, after 2 hours)]. The rationale to combine as discussed in claim 1, applies here as well.
Regarding Claim 14,
A.-Knotwell taught wherein the principal certificate is issued to a public key infrastructure (PKI) agent operating within the substrate instance [¶124, PKI service returns the signed digital certificate to the PKI agent, which stores the digital certificate]. The rationale to combine as discussed in claim 1, applies here as well.
Regarding Claim 15~17, 19, and 20, the claims are similar in scope to claim(s) 1~3 and therefore, rejected under the same rationale.
Claims 4, 6, and 7 are rejected under 35 U.S.C. 103 as being unpatentable over A. and Knotwell in view of Elmenshawy et al. hereinafter Elmenshawy (U.S 2021/0409345).
Regarding Claim 4,
A.-Knotwell-Elmenshawy taught wherein the substrate instance uses the principal certificate for code signing [¶59, ephemeral tokens are issued for resource principals configured to access resources for a brief period of time. For example, testing platform 210 may be configured to, as part of providing a function service under an FaaS model, execute a client-supplied software function one time or periodically (e.g., on a weekly basis or in response to an event trigger), where the function accesses one or more of the compute instances 236-A to 236C and runs for 30 seconds each time before terminating].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention was made, to combine, Elmenshawy’s teaching of limitations with the teachings of A.-Knotwell, because the combination reduces the number of credentials and special relationships to be maintained for the resources [¶57].
Regarding Claim 6,
A.-Knotwell-Elmenshawy taught wherein: the principal certificate is a substrate instance principal certificate issued to the substrate instance; an overlay instance principal certificate is issued to an overlay instance that runs on the substrate instance; and the overlay instance principal certificate is recognized by the authentication authority for mTLS authentication between the overlay instance and another entity different from the overlay instance [¶51, load balancer 220 may use the stacked identifier 310 to issue a signed request for a digital certificate used to authenticate with another resource (e.g., mTLS authentication with compute instance 236-A)]. The rationale to combine as discussed in claim 4, applies here as well.
Regarding Claim 7,
A.-Knotwell-Elmenshawy taught wherein the first fetch is performed, based at least in part on an Internet Protocol (IP) address associated with the substrate instance [¶115, the compute control plane service may also create a layer 3 virtual network identifier for the cluster]. The rationale to combine as discussed in claim 4, applies here as well.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HEE SOO KIM whose telephone number is (571)270-3229. The examiner can normally be reached M-F 9AM-5PM.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas Taylor can be reached on (571) 272-3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/H.K/Primary Examiner, Art Unit 2443
/HEE SOO KIM/Primary Examiner, Art Unit 2443