Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This Office Action is in response to the Amendment filed 06/30/2026. In the instant amendment, claims 1-19 and 21 were amended; claim 20 was cancelled; claims 1, 8 and 15 are independent claims. Claims 1-19 and 20 are pending in this application.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 06/30/2026 has been entered.
Response to Arguments
The 35 U.S.C. 112(b) rejection has been withdrawn as per applicant’s amendment filed 06/30/2028.
Applicant’s arguments with respect to claims 1-19 and 21 in regard to the limitations “in response to detecting that the respective login session of at least one user device in the subset of one or more user devices has ended, determining whether any remaining user devices of the one or more user devices remain assigned to the container; and based on determining that the respective login session of each user device in the subset of the one or more user devices has ended, removing the container from the host system,” have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Applicant’s arguments filed 06/30/2026 have been fully considered but they are not persuasive.
Applicant argues that (on pages 11-13): Yelp fails to disclose the amended limitations requiring execution of a user shell associated with a container to assign a subset of one or more user devices to the container, thereby restricting access of that subset during respective login sessions to predefined resources. Applicant further argues that Yelp places each user session into an individual container and therefore does not disclose multiple user devices being assigned to a common container.
The Examiner respectfully disagrees with the applicant. This argument is not persuasive. Yelp describes dockersh as a login shell for machines having multiple interactive users. When invoked, dockersh brings up a docker container, if the container is not already running, and spawns a new interactive shell in the container’s namespace. Yelp additionally describes configuration on a per-user basis. Thus, Yelp does not require a separate container each time a new login session is established. Rather, Yelp contemplates use of an already-running container associated with the user. Accordingly, where a user initiates a login session and the associated container is already running, the shell for that login session is executed within the existing container. The container thereby restricts the user’s access to the resources established by the corresponding configuration (See Final Office Action on Pages 4-7 and Yelp, Pages 1-25).
Applicant argues that (on pages 11-13): that the amended claim necessarily requires a plurality of user devices to be assigned simultaneously to the same container.
The Examiner respectfully disagrees with the applicant. The claim recites “a subset of the one or more user devices.” A subset of a collection containing one or more devices may encompass a single user device unless the claim expressly requires that the subset include at least two user devices. The claim does not presently recite such a numerical requirement. Accordingly, Yelps disclosure of assigning a user login session to the corresponding container continues to meet the claimed assignment of the recited subset under the broadest reasonable interpretation of the claim language, (See Final Office Action on Pages 4-7 and Yelp, Pages 1-25).
Therefore, in view of the above reasons, the Examiner maintains the rejection with the cited prior art reference.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 8 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Yelp et al (“Yelp,” "Dockersh," pages 1-25, published on Aug. 28, 2014, retrieved from https://github.com/Yelp/dockersh) and further in view of Maes et al (“Maes,” US 20190222988).
Regarding claim 1, Yelp discloses a system comprising:
a processing device; (Yelp, Page 22, describes a computer which would have a processor)
and a memory device including instructions that are executable by the processing device for causing the processing device to perform operations comprising: (Yelp, Page 9 describes memory as 32M of memory; Page 22 describes a computer which would have a processor)
receiving user input from one or more user devices to initiate a respective login session to a computing environment; (Yelp discloses in Page 1 dockersh is designed to be used as a login shell on machines with multiple interactive users-it can be used as a shell in /etc/passwd or as an SSH ForceCommand, placing user sessions into their own individual Docket containers when users log in; also see pages 1-25 for further detail on the process)
in response to receiving the user input to initiate the respective login session, (Yelp discloses in Page 1 dockersh is designed to be used as a login shell on machines with multiple interactive users-it can be used as a shell in /etc/passwd or as an SSH ForceCommand, placing user sessions into their own individual Docket containers when users log in; also see pages 1-25 for further detail on the process)
dynamically deploying a container on a host system of the computing environment for use in restricting access of a subset of the one or more user devices in the computing environment during the respective login session, wherein dynamically deploying the container on the host system comprises: (Yelp discloses in Page 1 when the user invokes dockersh, it will bring up a Docker container (if not already running), and then spawn a new interactive shell in the container’s namespace; also see pages 1-25 for further detail on the process)
identifying a service file based on a parameter in the user input, (Yelp discloses on Pages 3-4, 13, dockersh reads a global config file /etc/dockershrc with a [dockersh] block and zero or more [user “foo”’ blocks, configurable per user, used to set settings globally or per user-the username %u is interpolated to identify the correct-per-user container configuration; also see pages 1-25 for further detail on the process)
wherein the service file indicates a set of predefined resources to which to restrict the subset of the one or more user devices during the respective login session; (Yelp discloses on Pages 3-6, 9-13 and 16 the config file specifies a restricted environment-a very restricted environment with only the busybox container, limited to 32M of memory, is configured in /etc/dockershrc with imagename, shell, and usercwd settings defining what resources the user can access; also see pages 1-25 for further detail on the process) and
configuring the container on the host system in accordance with the service file to restrict access of the subset of the one or more user devices during the respective login session to the set of predefined resources; (Yelp discloses on Pages 2, 9, 23, dockersh tries hard to drop all privileges as soon as possible, including disabling the suid, sgid, raw sockets and mknod capabilities of the target process, restricting the user to only what is configured in the file; also see pages 1-25 for further detail on the process)
based on dynamically deploying the container on the host system, executing a user shell associated with the container to assign the subset of the one or more user devices to the container, thereby restricting access of the subset of the one or more user devices during the respective login session to the set of predefined resources; (Yelp discloses on Pages 1, 19, 24, dockersh spawns a new interactive shell in the container’s namespace, assigning the user’s session to the container; also see pages 1-25 for further detail on the process)
Yelp fails to explicitly disclose in response to detecting that the respective login session of at least one user device in the subset of one or more user devices has ended, determining whether any remaining user devices of the one or more user devices remain assigned to the container; and based on determining that the respective login session of each user device in the subset of the one or more user devices has ended, removing the container from the host system.
However, in an analogous art, Maes discloses in response to detecting that the respective login session of at least one user device in the subset of one or more user devices has ended, (Maes, [0034]-[0035]; FIG 3 discloses that the system may scale in when a user or several users log out. Active user sessions are monitored)
determining whether any remaining user devices of the one or more user devices remain assigned to the container; and (Maes, [0034]-[0035]; 301-302, FIG 3 describes monitoring includes active user sessions. The management module determines whether the instance is idle based on active users and whether there are no users/no active user sessions; [0013] describes being assigned to a container)
based on determining that the respective login session of each user device in the subset of the one or more user devices has ended, (Maes, [0025] describes if no users are using a service suite instance, such as no more sessions exist between users and a service suite instance, the controller can retire the instance. In FIG 3, if there are no users for the instance, such as no active user sessions, the instance is considered idle)
removing the container from the host system (Maes, [0037], 303, FIG 3 describes once the instance is determined idle a container stop command or terminate command is used to terminate the containerized service suite 118a; [0028], FIG 1A describes that termination releases the infrastructure resources used by the service-suite instance based to the available resource pool. The containerized instances execute on infrastructure comprising computer, storage and network resources; [0017] describes a host)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Maes with the method/system of Yelp to include in response to detecting that the respective login session of at least one user device in the subset of one or more user devices has ended, determining whether any remaining user devices of the one or more user devices remain assigned to the container; and based on determining that the respective login session of each user device in the subset of the one or more user devices has ended, removing the container from the host system. One would have been motivated to conserve computing resources and make those resources available to other processes (Maes, [0016], [0025]-[0026]).
Regarding claim 8, claim 8 is directed to a method. Claim 8 is similar in scope to claim 1 and therefore rejected under the same rationale.
Regarding claim 15, claim 15 is directed to a non-transitory computer-readable medium. Claim 15 is similar in scope to claim 1 and therefore rejected under the same rationale.
Claims 2-3, 9-10, 16 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Yelp et al (“Yelp,” "Dockersh," pages 1-25, published on Aug. 28, 2014, retrieved from https://github.com/Yelp/dockersh) in view of Maes et al (“Maes,” US 20190222988) and further in view of Kasso et al ("Kasso," CN 116018580, See Google Patents Translation, Pages 1-24, 2023).
Regarding claim 2, Yelp and Maes disclose the system of claim 1.
Yelp and Maes fail to explicitly disclose wherein the set of predefined resources comprises write access, and wherein the operations further comprise: mapping a storage device to the container to provide persistent data storage with respect to user content received from the subset of the one or more user devices; prior to detecting that the respective login session has ended, receiving the user content generated based on the write access provided as part of the set of predefined resources; and storing the user content in the storage device, wherein the storage device enables the user device to access the user content subsequent to removing the container.
However, in an analogous art, Kasso discloses wherein the set of predefined resources comprises write access, and wherein the operations further comprise: (Kasso describes wherein the set of predefined resources (Page 4, Third Paragraph Under Detailed Description) comprises write access (Page 38, Last Paragraph),
and wherein the operations further comprise: mapping a storage device to the container to provide persistent data storage with respect to user content received from the subset of the one or more user devices; (Kasso describes (Page 7, First Paragraph) mapping a storage device (Page 7, First Paragraph) to the container (Page 4, Last Paragraph) to provide persistent data storage (Page 7, Lines 53-58) with respect to user content (Page 8, Lines 45-51) received from the user device (Page 9, Third Paragraph))
prior to detecting that the respective login session has ended receiving the user content generated based on the write access provided as part of the set of predefined resources; (Kasso describes prior to detecting that the respective login session has ended (Page 12, Last Paragraph), receiving the user content (Page 8, Lines 45-51) generated based on the write access (Page 38, Last Paragraph) provided as part of the set of predefined resources (Page 4, Third Paragraph Under Detailed Description))
and storing the user content in the storage device, wherein the storage device enables the subset of the one or more user devices to access the user content subsequent to removing the container, (Kasso describes Page 38, Lines 6-19) and storing the user content (Page 8, Lines 45-51) in the storage device (Page 7, First Paragraph), wherein the storage device enables the user device to access (Page 7, First Paragraph), the user content (Page 9, Third Paragraph) subsequent to removing the container (Page 10, Sixth Paragraph)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Kasso with the method/system of Yelp and Maes to include wherein the set of predefined resources comprises write access, and wherein the operations further comprise: mapping a storage device to the container to provide persistent data storage with respect to user content received from the subset of the one or more user devices; prior to detecting that the respective login session has ended, receiving the user content generated based on the write access provided as part of the set of predefined resources; and storing the user content in the storage device, wherein the storage device enables the the subset of the one or more user devices to access the user content subsequent to removing the container. One would have been motivated to persist data across cloud shell instances (Kasso, Page 4 Under Summary of the Invention).
Regarding claim 3, Yelp and Maes disclose the system of claim 1.
Yelp and Maes fail to explicitly disclose wherein the set of predefined resources comprises a software application installed on the host system, and wherein the operations further comprise: determining, based on the service file, that the subset of the one or more user devices is authorized to access the software application; and providing the software application in the container to allow the subset of the one or more user devices to access the software application.
However, in an analogous art, Kasso discloses wherein the set of predefined resources comprises a software application installed on the host system, and wherein the operations further comprise: (Kasso describes wherein the set of predefined resources (Page 4, Third Paragraph Under Detailed Description) comprises a software application (Page 12, Fifth Paragraph) installed on the host system (Page 25, Next to Last Paragraph; Page 26, Second Paragraph), and wherein the operations further comprise)
determining, based on the service file, that the user device is authorized to access the software application; (Kasso describes determining, based on the service file (Page 26, Third Paragraph), that the user device is authorized to access the software application (Page 12, Fifth Paragraph; Page 15, Last Paragraph)
and providing the software application in the container to allow the subset of the one or more user devices to access the software application, (Kasso describes and providing the software application in the container (Page 12, Fifth Paragraph) to allow the user device to access the software application (Page 12, Fifth Paragraph; Page 15, Last Paragraph)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Kasso with the method/system of Yelp and Maes to include wherein the set of predefined resources comprises a software application installed on the host system, and wherein the operations further comprise: determining, based on the service file, that the subset of the one or more user devices is authorized to access the software application; and providing the software application in the container to allow the subset of the one or more user devices to access the software application. One would have been motivated to persist data across cloud shell instances (Kasso, Page 4 Under Summary of the Invention).
Regarding claim 9, claim 9 is directed to the method of claim 8. Claim 9 is similar in scope to claim 2 and therefore rejected under the same rationale.
Regarding claim 10, claim 10 is directed to the method of claim 8. Claim 10 is similar in scope to claim 3 and therefore rejected under the same rationale.
Regarding claim 16, claim 16 is directed to the non-transitory computer-readable medium of claim 15. Claim 16 is similar in scope to claim 2 and therefore rejected under the same rationale.
Regarding claim 17, claim 17 is directed to the non-transitory computer-readable medium of claim 15. Claim 17 is similar in scope to claim 3 and therefore rejected under the same rationale.
Claim 4, 11 and 18 are rejected under 35 U.S.C. 103 as being unpatentable Yelp et al (“Yelp,” "Dockersh," pages 1-25, published on Aug. 28, 2014, retrieved from https://github.com/Yelp/dockersh) in view of Maes et al (“Maes,” US 20190222988) and further in view of Vigil et al (“Vigil,” US 20210382727).
Regarding claim 4, Yelp and Maes disclose the system of claim 1.
Yelp and Maes fail to explicitly disclose wherein the parameter includes a user identifier corresponding to a user of the subset of the one or more user devices, and wherein the operation of identifying the service file based on the parameter further comprises: identifying a directory location at which the service file is accessible, based on the user identifier; and identifying the service file at the directory location for use in deploying the container.
However, in an analogous art, Vigil discloses wherein the parameter includes a user identifier corresponding to a user of the subset of the one or more user devices, (Vigil discloses wherein the parameter [0023] includes a user identifier [0012] corresponding to a user [0021] of the user device [0012])
and wherein the operation of identifying the service file based on the parameter further comprises: identifying a directory location at which the service file is accessible, based on the user identifier; (Vigil, and wherein the operation of identifying [0018] the service file [0023] based on the parameter [0023] further comprises: identifying a directory location [0051], [0016] at which the service file [0023] is accessible, based on the user identifier [0012])
and identifying the service file at the directory location for use in deploying the container, (Vigil and identifying [0018] the service file [0023] at the directory location [0051], [0016] for use in deploying the container [0037])
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Vigil with the Yelp and Maes to include wherein the parameter includes a user identifier corresponding to a user of the subset of the one or more user devices, and wherein the operation of identifying the service file based on the parameter further comprises: identifying a directory location at which the service file is accessible, based on the user identifier; and identifying the service file at the directory location for use in deploying the container. One would have been motivated to provide container orchestration platforms (Vigil, [0001])
Regarding claim 11, claim 11 is directed to the method of claim 8. Claim 11 is similar in scope to claim 4 and therefore rejected under the same rationale.
Regarding claim 18, claim 18 is directed to the non-transitory computer-readable medium of claim 15. Claim 18 is similar in scope to claim 4 and therefore rejected under the same rationale.
Claims 5, 12 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Yelp et al (“Yelp,” "Dockersh," pages 1-25, published on Aug. 28, 2014, retrieved from https://github.com/Yelp/dockersh) in view of Maes et al (“Maes,” US 20190222988) and further in view of Singh et al ("Singh," US 20230254330).
Regarding claim 5, Yelp and Maes disclose the system of claim 1.
Yelp and Maes fail to explicitly disclose wherein the subset of the one or more user devices is a first user device that has initiated a first login session and has been assigned to a first container based on a first user identifier, and wherein the operations further comprise: subsequent to assigning the first user device to the first container, receiving additional user input from a second user device to initiate a second login session, wherein the additional user input comprises a second user identifier; based on the first user identifier being different than the second user identifier, generating a second container to provide access to a different set of predefined resources than the first container; and subsequent to generating the second container, assigning the second user device to the second container.
However, in an analogous art, Singh discloses wherein the subset of the one or more user devices is a first user device that has initiated a first login session and has been assigned to a first container based on a first user identifier, and wherein the operations further comprise: (Singh describes wherein the user device [0663] is a first user device [0663] that has initiated a first login session [0377] and has been assigned to a first container [0087] based on a first user identifier [0373], and wherein the operations further comprise) subsequent to assigning the first user device to the first container, receiving additional user input from a second user device to initiate a second login session, wherein the additional user input comprises a second user identifier; (Singh describes subsequent to assigning the first user device [0663] to the first container [0087], receiving additional user input [0099] from a second user device [0663] to initiate a second login session [0377], wherein the additional user input [0099] comprises a second user identifier [0373]) based on the first user identifier being different than the second user identifier, generating a second container to provide access to a different set of predefined resources than the first container; (Singh describes subsequent to assigning the first user device [0663] to the first container [0087], receiving additional user input [0099] from a second user device [0663] to initiate a second login session [0377], wherein the additional user input comprises a second user identifier [0373])
and subsequent to generating the second container, assigning the second user device to the second container, (Singh describes and subsequent to generating the second container [0087], assigning the second user device [0663] to the second container [0087])
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Singh with the method/system of Yelp and Maes to include wherein the subset of the one or more user devices is a first user device that has initiated a first login session and has been assigned to a first container based on a first user identifier, and wherein the operations further comprise: subsequent to assigning the first user device to the first container, receiving additional user input from a second user device to initiate a second login session, wherein the additional user input comprises a second user identifier; based on the first user identifier being different than the second user identifier, generating a second container to provide access to a different set of predefined resources than the first container; and subsequent to generating the second container, assigning the second user device to the second container. One would have been motivated to distinguish user-initiated activity from application-initiated activity (Singh, [0752]).
Regarding claim 12, claim 12 is directed to the method of claim 8. Claim 12 is similar in scope to claim 5 and therefore rejected under the same rationale.
Regarding claim 19, claim 19 is directed to the non-transitory computer-readable medium of claim 15. Claim 19 is similar in scope to claim 5 and therefore rejected under the same rationale.
Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Yelp et al (“Yelp,” "Dockersh," pages 1-25, published on Aug. 28, 2014, retrieved from https://github.com/Yelp/dockersh), Maes et al (“Maes,” US 20190222988) in view of Singh et al ("Singh," US 20230254330) and further in view of Barrall et al (“Barrall,” US 20160117377).
Regarding claim 6, Yelp, Maes and Singh disclose the system of claim 5.
Yelp, Maes and Singh fails to explicitly disclose wherein the user device is a first
user device that has initiated a first login session and has been assigned to the container
based on a first user identifier, and wherein the operations further comprise: subsequent
to assigning the first user device to the container, receiving additional user input to initiate
a third login session, wherein the additional user input comprises a third user identifier;
However, in an analogous art, Muddu discloses wherein the user device is a first
user device that has initiated a first login session and has been assigned to the container
based on a first user identifier, and wherein the operations further comprise: subsequent
to assigning the first user device to the container, receiving additional user input to initiate
a third login session, wherein the additional user input comprises a third user identifier;
Yelp, Maes and Singh fail to explicitly disclose determining that the first user device and a third user device corresponding to the third user identifier comprise a group-level identifier, wherein the third user device is part of the subset of the one or more user devices, and wherein the group-level identifier is indicative of shared access permissions; and based on the group-level identifier, assigning the third user device to the container such that the third user device is restricted to access the set of predefined resources.
However, in an analogous art, Barrall discloses determining that the first user device and a third user device corresponding to the third user identifier comprise a group-level identifier, (Barrall, [0180], [0199], Figures 40-42 describes users can belong to the same replication/synchronization group with at least one of each user’s storage appliances linked to the same virtual container. A group of users is designated by association with a group identifier)
wherein the third user device is part of the subset of the one or more user devices, and (Barrall, [0180], Figures 40-42 describes in the replication and/or synchronization group at least one of the each user’s storage appliances is linked to the same virtual container, and changes are propagated to all members of the group)
wherein the group-level identifier is indicative of shared access permissions; (Barrall, [0199], discloses that an owner can designate a group by making the association with the group identifier and on that basis grant access to a virtual container to all members of the container’s replication and/or synchronization group)
and based on the group-level identifier, assigning the third user device to the container such that the third user device is restricted to access the set of predefined resources, (Barrall, [0180], [0198]-[0199], discloses that group membership is used to determine access to the virtual container. The owner associates the group identifier and thereby grants access to all group members. Separately, members’ storage appliances are linked to the same virtual container. The owner selects particular folders to share. A user can access the selected folders, while all other folders remain invisible. The owner also specifies access level, e.g. read/write or read-only).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Barrall with the method/system of Yelp, Maes and Singh to include determining that the first user device and a third user device corresponding to the third user identifier comprise a group-level identifier, wherein the third user device is part of the subset of the one or more user devices, and wherein the group-level identifier is indicative of shared access permissions; and based on the group-level identifier, assigning the third user device to the container such that the third user device is restricted to access the set of predefined resources. One would have been motivated to provide group-based access technique to efficiently manage shared container access for multiple users/devices while restricting those users to authorized resources and permission levels (Barrel, [0115], [0198]-[0199]).
Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Yelp et al (“Yelp,” "Dockersh," pages 1-25, published on Aug. 28, 2014, retrieved from https://github.com/Yelp/dockersh) in view of Maes et al (“Maes,” US 20190222988) and further in view of Sandhu et al ("Sandhu," WO2011081931).
Regarding claim 7, Yelp and Maes disclose the system of claim 1.
Yelp fails to explicitly disclose wherein the set of predefined resources comprises
an operating system, and wherein the operations further comprise: based on the set of predefined resources indicated in the service file, providing the operating system via the container such that the operating system is accessible by the subset of the one or more user devices.
However, in an analogous art, Sandhu discloses wherein the set of predefined
resources comprises an operating system, and wherein the operations further comprise:
based on the set of predefined resources indicated in the service file providing the
operating system via the container such that the operating system is accessible by the subset of the one or more user devices, (Sandhu describes wherein the set of predefined resources (Page 115, Line 19) comprises an operating system (Page 81, Lines 20-22), and wherein the operations further comprise: based on the set of predefined resources (Page 115, Line 19) indicated in the service file (Page 120, Lines 20-29), providing the operating system (Page 81, Lines 20-22) via the container (Page 55, Table 2) such that the operating system (Page 81, Lines 20-22) is accessible by the user device (Page 10, Line 29, 902, FIG 9)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Sandhu with the method/system of Yelp to include wherein the set of predefined resources comprises an operating system, and wherein the operations further comprise: based on the set of predefined resources indicated in the service file, providing the operating system via the container such that the operating system is accessible by the subset of the one or more user devices. One would have been motivated to execute application programs and isolating services operating on a client machine (Sandhu, Page 2, Lines 11-14).
Regarding claim 14, claim 14 is directed to the method of claim 8. Claim 14 is similar in scope to claim 7 and therefore rejected under the same rationale.
Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Yelp et al (“Yelp,” "Dockersh," pages 1-25, published on Aug. 28, 2014, retrieved from https://github.com/Yelp/dockersh) in view of Maes et al (“Maes,” US 20190222988) and further in view of Muddu et al ("Muddu," US 20200007561).
Regarding claim 13, Yelp and Maes disclose the method of claim 8.
Yelp and Maes fail to explicitly disclose wherein the subset of the one or more user devices is a first user device that has initiated a first login session and has been assigned to the container based on a first user identifier, and wherein the method further comprises: subsequent to assigning the first user device to the container, receiving additional user input to initiate a second login session, wherein the additional user input comprises a second user identifier; and based on the first user identifier being associated with the second user identifier, assigning a second user device to the container such that the second user device is restricted to access the set of predefined resources.
However, in an analogous art, Muddu discloses wherein the subset of the one or more user devices is a first user device that has initiated a first login session and has been assigned to the container based on a first user identifier, and wherein the operations further comprise: (Muddhu describes wherein the user device is a first user device [0278] that has initiated a first login session [0250] and has been assigned to the container [0428] based on a first user identifier [0232], and wherein the operations further comprise)
subsequent to assigning the first user device to the container, receiving additional
user input to initiate a second login session, wherein the additional user input comprises a second user identifier; (Muddhu describes subsequent to assigning the first user device
[0278] to the container [0428], receiving additional user input [0439] to initiate a second login session [0250], wherein the additional user input [0439] comprises a second user identifier [0232])
and based on the first user identifier being associated with the second user identifier, assigning a second user device to the container such that the second user device is restricted to access the set of predefined resources, (Muddhu describes and based on the first user identifier [0439] being associated with the second user identifier [0232], assigning a second user device [0278] to the container [0428] such that the second user device [0278] is restricted to access the set of predefined resources [0273], [0297])
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Muddu with the method/system of Yelp and Maes to include wherein the subset of the one or more user devices is a first user device that has initiated a first login session and has been assigned to the container based on a first user identifier, and wherein the operations further comprise: subsequent to assigning the first user device to the container, receiving additional user input to initiate a second login session, wherein the additional user input comprises a second user identifier; and based on the first user identifier being associated with the second user identifier, assigning a second user device to the container such that the second user device is restricted to access the set of predefined resources. One would have been motivated to intelligence generation and activity discovery from events in a distributed data processing system (Muddu, [0003]).
Claim 21 is rejected under 35 U.S.C. 103 as being unpatentable over Yelp et al (“Yelp,” "Dockersh," pages 1-25, published on Aug. 28, 2014, retrieved from https://github.com/Yelp/dockersh) in view of Maes et al (“Maes,” US 20190222988) and further in view of Kasso et al (“Kasso,” US 20220052849).
Regarding claim 21, Yelp and Maes disclose the system of claim 1.
Yelp and Maes fail to explicitly disclose wherein the user shell is executed within the container and is configured to provide services of the container to the subset of the one or more user devices.
However, in an analogous art, Kasso discloses wherein the user shell is executed within the container and is configured to provide services of the container to the subset of the one or more user devices, (Kasso discloses wherein the user shell [0004], [0007]-[0010] is executed within the container [0010], [0029]-[0030] and is configured to provide services [0004], [0006], [0031] of the container [0010], [0029]-[0030] to the user device [0029])
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Kasso with the method/system of Yelp and Maes to include wherein the user shell is executed within the container and is configured to provide services of the container to the subset of the one or more user devices. One would have been motivated to secure cloud shells to run one or more terminals, using signed nonces in coordination with one or more additional security operations (Kasso, [0003]).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES J WILCOX whose telephone number is (571)270-3774. The examiner can normally be reached M-F: 8 A.M. to 5 P.M..
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu T. Pham can be reached at (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JAMES J WILCOX/ Examiner, Art Unit 2439
/LUU T PHAM/ Supervisory Patent Examiner, Art Unit 2439