Prosecution Insights
Last updated: October 01, 2026
Application No. 18/659,589

MANAGING A SERVICE OFFERED BY A FIRST CLOUD SERVICE PROVIDER VIA A CLOUD ENVIRONMENT OF A SECOND CLOUD SERVICE PROVIDER

Non-Final OA §103
Filed
May 09, 2024
Priority
Nov 15, 2023 — provisional 63/599,183
Examiner
KIM, SISLEY NAHYUN
Art Unit
Tech Center
Assignee
ORACLE INTERNATIONAL Corporation
OA Round
1 (Non-Final)
89%
Grant Probability
Favorable
1-2
OA Rounds
3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 89% — above average
89%
Career Allowance Rate
614 granted / 693 resolved
+28.6% vs TC avg
Strong +17% interview lift
Without
With
+16.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
21 currently pending
Career history
715
Total Applications
across all art units

Statute-Specific Performance

§101
9.7%
-30.3% vs TC avg
§103
51.1%
+11.1% vs TC avg
§102
24.3%
-15.7% vs TC avg
§112
7.3%
-32.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 693 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Objections Claim 4 is objected to because of the following informalities: Claim 4 discloses “hosted on by the physical resource” (emphasis added). It is recommended to amend the phrase to read “hosted on the physical resource” by removing “by” (or alternatively, to read “hosted by the physical resource” by removing “on”). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made Claims 1-17, 19, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Hernandez Serrano (US 2023/0251908, hereinafter Serrano) in view of “Microsoft expands partnership with Oracle to bring customers’ mission-critical database workloads to Azure,” published on 14 September 2023, hereafter Sanders). Regarding claim 1, Serrano discloses A computer-implemented method comprising: receiving, by a service of a first cloud environment (FIG. 9 routing proxy 915 / database adaptor 925), a request to configure a virtual resource (paragraph ¶ [0200]: the user may utilize the multi-cloud console 905 to issue commands to access, create, or update a resource in the tenancy of the user in the first cloud infrastructure … there is described a scenario of the user utilizing the multi-cloud console to issue a request to create an Exa-database resource), wherein: the first cloud environment is implemented on a first cloud infrastructure of a first cloud service provider (paragraph [0168]: the high-level architecture 700 includes a first cloud environment provided by a first cloud services provider (e.g., OCI) 720), the request is received from a second cloud environment upon input of a customer of a second cloud service provider … (paragraph [0168]: the high-level architecture 700 includes a first cloud environment provided by a first cloud services provider (e.g., OCI) 720 and a second cloud environment provided by a second cloud services provider 710 (i.e., Azure); paragraph [0201]: the user accesses the multi-cloud console 905 and provides login information e.g., credentials of the user in the second cloud infrastructure), the input indicates at least one parameter of the request (paragraph [0203]: the request may be comprehended as one being of creating an Exa-database and thus the request is forwarded to the database adaptor 925 … the routing proxy module 915 may analyze information included in the REST call such as a provider ID, resource type requested, etc.), and the second cloud environment is implemented on a second cloud infrastructure of the second cloud service provider (paragraph [0168]: a second cloud environment provided by a second cloud services provider 710 (i.e., Azure)); and causing, by the service, a control plane of the first cloud environment to configure the virtual resource on a physical resource of the first cloud service provider (paragraph [0173]: the DBaaS control plane included in the control plane 724 is configured to instantiate Exa-database resources in the customer tenancy 726 of the first cloud environment; paragraph [0184]: Exa-database is a pre-configured combination of hardware and software that provides an infrastructure for executing databases. By some embodiments, Exa-database comprises a stack of resources: (a) Exadata infrastructure (i.e., hardware), (b) VM cloud cluster …). Serrano does not disclose the request is received … upon input … at a portal of the second cloud environment; wherein the physical resource is installed at a location within the second cloud infrastructure. Sanders discloses the request is received … upon input … at a portal of the second cloud environment (page 2: The tight integration also ensures that Azure customers can use existing skills to build and operate Oracle databases from within the Azure Portal and APIs); wherein the physical resource is installed at a location within the second cloud infrastructure (page 2: To make this seamless, our engineering teams worked closely to colocate Oracle database services on OCI, such as Exadata and related OCI hardware, into Microsoft datacenters). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the multi-cloud control plane and provisioning method of Serrano to physically install the first cloud provider’s hardware within the second cloud provider’s datacenters, and to route the configuration requests directly through the second cloud provider’s native portal, as taught by Sanders. The motivation would have been to enhance security by keeping apps and data on a single network, gain optimal performance with the same fully managed Exadata Database Service that runs in OCI, and then innovate with the comprehensive services offered in the Microsoft cloud (Sanders page 2). Regarding claim 2, Chen discloses further comprising: sending, by the service, a response to the request … that the virtual resource is provided by the first cloud service provider (paragraph [0208]: the MCCP 900 may notify the user regarding a successful completion of the request; paragraph [0276]: the graphical user interface 1655 depicts metadata information 1656 related to a status of creation of the database … the status is depicted as ‘provisioning’, along with information for both cloud environments e.g., the first cloud environment (such as Oracle's OCI) and the first external cloud environment (e.g., Microsoft's Azure cloud environment); FIG 16A: showing the GUI indicates “Services For First External Cloud Environment” and lists Oracle-specific resources like “Autonomous Database” and “Exadata”)). Serrano does not disclose sending the response such that the portal of the second cloud environment presents an indication that the virtual resource is provided by the first cloud service provider and is hosted in the second cloud environment. Sanders discloses the virtual resource provided by the first cloud service provider is physically hosted in the second cloud environment and managed via the second cloud environment’s portal (page 2: To make this seamless, our engineering teams worked closely to colocate Oracle database services on OCI, such as Exadata and related OCI hardware, into Microsoft datacenters … The tight integration also ensures that Azure customers can use existing skills to build and operate Oracle databases from within the Azure Portal and APIs). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the response and graphical user interface notification of Serrano to indicate that the resource is hosted in the second cloud environment, as taught by Sanders. The motivation would have been to provide this specific indication in the portal would be to accurately reflect the physical deployment location of the database to the user, thereby allowing the user to verify that their deployment satisfies strict data residency, security, and compliance requirements. Sanders explicitly identifies “enhancing security and compliance on their transactions” as a primary benefit of this colocated architecture (Sanders, pg. 2). Furthermore, presenting this hosting indication confirms to the user that the deployment successfully achieved the optimal performance and single-network security intended by the integration (Sanders page. 2). Regarding claim 3, Chen discloses further comprising: determining, by the service from the request, a first resource identifier assigned by the second cloud service provider to the virtual resource (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) and a first identifier (associated with the tenancy of the user in the first cloud infrastructure) to enable operations going through the multi-cloud control plane 722 to map to the appropriate underlying resource in the first cloud infrastructure); and determining, by the service a second resource identifier assigned by the first cloud service provider and associated with the first resource identifier, wherein the virtual resource is configured based on the second resource identifier (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) and a first identifier (associated with the tenancy of the user in the first cloud infrastructure) to enable operations going through the multi-cloud control plane 722 to map to the appropriate underlying resource in the first cloud infrastructure; paragraph [0204]: the routing proxy module 915 communicates with the cloud-link adaptor 920 to obtain mapping information of the user's account in the second cloud infrastructure to the tenancy of the user in the first cloud infrastructure. If the mapping information exists, then the routing proxy module 915 obtains the information pertaining to the tenancy of the user in the first cloud infrastructure and passes the information to the database adaptor 925. In this manner, the database adaptor 925 is aware of the tenancy of the user in the first cloud infrastructure where the resource is to be created/deployed). Regarding claim 4, Chen discloses wherein causing the control plane to configure the virtual resource comprises (paragraph [0173]: the DBaaS control plane included in the control plane 724 is configured to instantiate Exa-database resources in the customer tenancy 726 of the first cloud environment): sending, by the service to the control plane, the second resource identifier (paragraph [0173]: the DBaaS control plane included in the control plane 724 is configured to instantiate Exa-database resources in the customer tenancy 726 of the first cloud environment; paragraphs [0230]: The cloud-link adaptor 1030 can then identify (based on the token), the appropriate tenancy 1022 that is associated with token e.g., the customer identity, user identity, etc.; paragraph [0231]: the database adaptor 1037 transmits a request to the corresponding downstream service offered by the first cloud environment (e.g., DBaaS 1060). The request pertains to the creation of a resource (e.g., database) in the tenancy associated with the user in the first cloud environment; Note: the service (e.g., the database adaptor) sends the mapped identifier associated with the first cloud infrastructure (the claimed second resource identifier) to the native control plane/downstream services of the first cloud environment to configure the resource), wherein the virtual resource is configured as a data plane hosted on by the physical resource (paragraph [0016]: A key value proposition to MCCP is that customers will be able to experience the full data plane capabilities of the services in external clouds). Regarding claim 5, Chen discloses further comprising: determining, by the service, a network configuration to use in association with the virtual resource hosting a compute instance, the network configuration associated with a first private cloud of the customer hosted in the second cloud environment (paragraph [0169]: It is noted that the customer subscription may also be referred to as a virtual network (VNET) where customer applications are deployed and executed; paragraph [0178]: The network link module (also referred to as a network adaptor) 722F is responsible for creating a network link between the customer subscription 715 (in the second cloud infrastructure) and the corresponding customer tenancy/account (in the first cloud infrastructure) 726; paragraph [0206]: the database adaptor 925 may communicate with (or instruct) the network adaptor 930 to create a network link between the user's account in the second cloud infrastructure and the tenancy of the user in the first cloud infrastructure; Note: the service (e.g., network link module / network adaptor 722F or 930) determines a network configuration/link to use in association with the virtual resource (e.g., Exa-database resource), where the network configuration is associated with a customer subscription in the second cloud environment, which is explicitly defined as a virtual private network (VNET) where customer applications are deployed); and causing, by the service, a second private cloud of the customer hosted in the first cloud environment to be configured with the network configuration (paragraph [0068]: the customer networks that are hosted in the cloud by the CSPI are referred to as virtual cloud networks (VCNs) … A VCN is a virtual or software defined private network; paragraph [0206]: the network adaptor 930 may … create: (1) a first peering relationship (in the first cloud environment) between a data plane of the MCCP and the tenancy of the user in the first cloud infrastructure, and (2) a second peering relationship (in the second cloud environment) between the user's account and a subscription of the first cloud provider included in the second cloud infrastructure); and causing, by the service, a network connection between the first private cloud and the second private cloud (paragraph [0068]: the customer networks that are hosted in the cloud by the CSPI are referred to as virtual cloud networks (VCNs) … A VCN is a virtual or software defined private network; paragraph [0206]: the network adaptor 930 may … create: (1) a first peering relationship (in the first cloud environment) between a data plane of the MCCP and the tenancy of the user in the first cloud infrastructure, and (2) a second peering relationship (in the second cloud environment) between the user's account and a subscription of the first cloud provider included in the second cloud infrastructure). Regarding claim 6, Chen discloses wherein the network configuration includes a subnet address space, and … (paragraph [0071]: when a VCN is created, it is associated with a private overlay Classless Inter-Domain Routing (CIDR) address space, which is a range of private overlay IP addresses that are assigned to the VCN (e.g., 10.0/16). A VCN includes associated subnets, route tables, and gateway; paragraph [0072]: A VCN can be subdivided into one or more sub-networks such as one or more subnets. A subnet is thus a unit of configuration or a subdivision that can be created within a VCN. A VCN can have one or multiple subnets. Each subnet within a VCN is associated with a contiguous range of overlay IP addresses (e.g., 10.0.0.0/24 and 10.0.1.0/24) that do not overlap with other subnets in that VCN, and which represent an address space subset within the address space of the VCN). Serrano does not disclose wherein the first private cloud and the second private cloud use the same subnet address space. Sanders discloses physically colocating the first cloud provider’s hardware directly into the second cloud provider’s datacenters to keep the applications and databases on a single network (page 2: To make this seamless, our engineering teams worked closely to colocate Oracle database services on OCI, such as Exadata and related OCI hardware, into Microsoft datacenters … The tight integration also ensures that Azure customers can use existing skills to build and operate Oracle databases from within the Azure Portal and APIs). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the network configuration of Hernandez Serrano to utilize the same subnet address space for the first and second private clouds, as taught by the “single network” colocated architecture of Sanders. Because Sanders physically installs the first cloud provider’s hardware (e.g., Exadata) directly inside the second cloud provider’s datacenters (e.g., Azure), it would be a matter of obvious design and logical implementation to provision those colocated resources directly into the same subnet address space as the customer’s existing virtual network (e.g., via a delegated subnet). The motivation would have been to use the same subnet address space would be to successfully implement the single network. Furthermore, utilizing the same subnet address space eliminates the need for complex Layer-3 routing and NAT translation across separate network boundaries, thereby reducing network hops to achieve the optimal performance and strict security compliance intended by the Sanders integration (Sanders page. 2). Regarding claim 7, Chen discloses further comprising: causing, by the service, the control plane to configure the compute instance (paragraph [0173]: the DBaaS control plane included in the control plane 724 is configured to instantiate Exa-database resources in the customer tenancy 726 of the first cloud environment; paragraph [0208]: the downstream services included in the first cloud infrastructure 940 utilizes the identity i.e., resource principal obtained from the MCCP platform 935 to create/deploy the required resources e.g., Exa-database in the tenancy of the user in the first cloud infrastructure) by at least sending the network configuration or a portion of the network configuration to the control plane (paragraph [0208]: the downstream services … to create/deploy the required resources e.g., Exa-database in the tenancy of the user in the first cloud infrastructure; paragraphs [0273]-[0274] and FIG. 16E: the graphical user interface captures “networking information of the autonomous database … such as secure access from anywhere … or a secure access from allowed IP addresses). Regarding claim 8, Chen discloses wherein causing the second private cloud to be configured comprises: sending, by the service to a networking service (paragraph [0082]: the creation of VCNs and subnets are handled by a VCN Control Plane (CP); paragraph [0206]: the network adaptor 930 may obtain from the native services in the second cloud infrastructure module 945, a token associated with the user and create: (1) a first peering relationship (in the first cloud environment) between a data plane of the MCCP and the tenancy of the user in the first cloud infrastructure; Note: the service (e.g., the multi-cloud infrastructure / network adaptor) causes the second private cloud (e.g., the VCN in the first cloud environment) to be configured by sending requests/information to the native networking services (e.g., the VCN Control Plane) to establish the network components and peering relationships), information that indicates the first private cloud (paragraph [0206]: the network adaptor 930 may obtain from the native services in the second cloud infrastructure module 945, a token associated with the user and create: (1) a first peering relationship (in the first cloud environment) between a data plane of the MCCP and the tenancy of the user in the first cloud infrastructure; paragraph [0272]: the control plane of the multi-cloud infrastructure queries both, the control plane of the first external cloud environment as well as the control plane of the first cloud environment (e.g., at the same time) to provide information related to the constructs 1632A of the first external cloud environment (such as a subscription ID, resource group ID, etc.), as well information related to the constructs 1632B of the first cloud environment (such as a name of the user, a region of deployment, etc.)), a subnet address space (paragraph [0071]: when a VCN is created, it is associated with a private overlay Classless Inter-Domain Routing (CIDR) address space, which is a range of private overlay IP addresses that are assigned to the VCN (e.g., 10.0/16). A VCN includes associated subnets, route tables, and gateway; paragraph [0072]: A VCN can be subdivided into one or more sub-networks such as one or more subnets. A subnet is thus a unit of configuration or a subdivision that can be created within a VCN. A VCN can have one or multiple subnets. Each subnet within a VCN is associated with a contiguous range of overlay IP addresses (e.g., 10.0.0.0/24 and 10.0.1.0/24) that do not overlap with other subnets in that VCN, and which represent an address space subset within the address space of the VCN; paragraph [0274]: the networking related parameters for the database may include … a secure access from allowed IP addresses (e.g., public ingress to the DB, which may restrict certain IP addresses)), and an identifier of a tenancy of the customer in the first cloud environment (paragraph [0204]: the routing proxy module 915 communicates with the cloud-link adaptor 920 to obtain mapping information of the user's account in the second cloud infrastructure to the tenancy of the user in the first cloud infrastructure. If the mapping information exists, then the routing proxy module 915 obtains the information pertaining to the tenancy of the user in the first cloud infrastructure and passes the information to the database adaptor 925. In this manner, the database adaptor 925 is aware of the tenancy of the user in the first cloud infrastructure where the resource is to be created/deployed). Regarding claim 9, Chen discloses further comprising: determining, by the service, information about the compute instance and the virtual resource (paragraph [0276]: the graphical user interface 1655 depicts metadata information 1656 related to a status of creation of the database … the metadata information includes an autoscaling feature, which corresponds to the number of CPUs to be allocated to the database resource that is being created); and sending, by the service, the information (paragraph [0276]: the graphical user interface 1655 of FIG. 161 is provided to the user … the graphical user interface 1655 depicts metadata information 1656 related to a status of creation of the database), a subscription identifier assigned by the second cloud service provider (paragraph [0272]: the control plane of the multi-cloud infrastructure queries both, the control plane of the first external cloud environment as well as the control plane of the first cloud environment (e.g., at the same time) to provide information related to the constructs 1632A of the first external cloud environment (such as a subscription ID), a first resource identifier assigned by the second cloud service provider (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) … ; paragraph [0239]: a second identifier of a second customer tenancy of the second cloud environment; paragraph [0272]: resource group ID), and a second resource identifier assigned by the first cloud service provider (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) and a first identifier (associated with the tenancy of the user in the first cloud infrastructure) to enable operations going through the multi-cloud control plane 722 to map to the appropriate underlying resource in the first cloud infrastructure; paragraph [0239]: a first identifier of the resource deployed in the first cloud environment; paragraph [0272]: The graphical user interface 1630 also includes a project detail section 1632 that provides details related to … constructs 1632B). Regarding claim 10, Chen discloses further comprising: storing, by the service, a first mapping between a first resource identifier assigned by the first cloud service provider and a second resource identifier assigned by the second cloud service provider (paragraph [0176]: the cloud-link adaptor 722D generates a mapping of a first identifier associated with the tenancy of the user in the first cloud infrastructure to a second identifier associated with the account of the user in the second cloud infrastructure; paragraph [0211]: The cloud-link resource object 1010 includes a mapping of a first identifier associated with the tenancy of the user in the first cloud infrastructure (e.g., tenancy name in the first cloud environment) to a second identifier associated with the account of the user in the second cloud infrastructure (e.g., tenancy ID and associated subscription in the second cloud environment)); and sending, by the service to the second cloud environment, information about the virtual resource based on the first mapping (paragraph [0245] the observability framework is setup for collecting, in the first cloud environment, observability data associated with execution of the service in the first cloud environment for the customer of the second cloud environment, and communicating the observability data collected from the first cloud environment to the second cloud environment (e.g., via a high bandwidth network link) to enable a user associated with the customer of the second cloud environment to access the observability data via the second cloud environment; paragraph [0251]: In step 4, the multi-cloud service control plane 1305 retrieves, for each resource identifier, the corresponding observability instance (OI) data object that is stored in the data store 1307 of the multi-cloud infrastructure. In step 6, upon obtaining the OI data object for each identifier in step 5, the multi-cloud service control plane 1305 forwards the retrieved information (of step 5) to the metrics processor 1303. Upon verifying that a particular resource is a multi-cloud resource (based on the observability instance data object of the resource), the metrics processor in step 7 transmits a request to the multi-cloud service control plane 1305 to obtain a token that is usable in the second cloud environment). Regarding claim 11, Chen discloses further comprising: storing, by the service, a second mapping between a first subscription identifier assigned by the first cloud service provider and a second subscription identifier assigned by the second cloud service provider (paragraph [0176]: the cloud-link adaptor 722D generates a mapping of a first identifier associated with the tenancy of the user in the first cloud infrastructure to a second identifier associated with the account of the user in the second cloud infrastructure; paragraph [0177]: The cloud-link adaptor 722D may store the data object; paragraph [0211]: The cloud-link resource object 1010 includes a mapping of a first identifier associated with the tenancy of the user in the first cloud infrastructure (e.g., tenancy name in the first cloud environment) to a second identifier associated with the account of the user in the second cloud infrastructure (e.g., tenancy ID and associated subscription in the second cloud environment)), wherein the information is sent further based on the second mapping (paragraph [0239]: a first identifier of the resource deployed in the first cloud environment; paragraph [0272]: The graphical user interface 1630 also includes a project detail section 1632 that provides details related to … constructs 1632B; paragraph [0251]: In step 4, the multi-cloud service control plane 1305 retrieves, for each resource identifier, the corresponding observability instance (OI) data object that is stored in the data store 1307 of the multi-cloud infrastructure. In step 6, upon obtaining the OI data object for each identifier in step 5, the multi-cloud service control plane 1305 forwards the retrieved information (of step 5) to the metrics processor 1303. Upon verifying that a particular resource is a multi-cloud resource (based on the observability instance data object of the resource), the metrics processor in step 7 transmits a request to the multi-cloud service control plane 1305 to obtain a token that is usable in the second cloud environment). Regarding claim 12, Chen discloses further comprising: receiving, by the service from the second cloud environment, another request to perform an operation on the virtual resource, wherein the other request indicates the second resource identifier (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) … ; paragraph [0201]: The multi-cloud console 905 provides a plurality of options e.g., create a resource, access a resource, update a resource etc.; paragraph [0255]: Customers interact with the multi-cloud console to perform control plane operations on their multi-cloud resources. For example, customers may perform operations such as create a database, list existing databases, or delete a database, etc.); determining, by the service based on the first mapping, the first resource identifier (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) and a first identifier (associated with the tenancy of the user in the first cloud infrastructure) to enable operations going through the multi-cloud control plane 722 to map to the appropriate underlying resource in the first cloud infrastructure; paragraph [0204]: the routing proxy module 915 communicates with the cloud-link adaptor 920 to obtain mapping information of the user's account in the second cloud infrastructure to the tenancy of the user in the first cloud infrastructure. If the mapping information exists, then the routing proxy module 915 obtains the information pertaining to the tenancy of the user in the first cloud infrastructure and passes the information to the database adaptor 925); and causing, by the service, the control plane to perform the operation based on the first resource identifier (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) and a first identifier (associated with the tenancy of the user in the first cloud infrastructure) to enable operations going through the multi-cloud control plane 722 to map to the appropriate underlying resource in the first cloud infrastructure; paragraph [0231]: the database adaptor 1037 transmits a request to the corresponding downstream service offered by the first cloud environment (e.g., DBaaS 1060). The request pertains to the creation of a resource (e.g., database) in the tenancy associated with the user in the first cloud environment). Regarding claim 13, Chen discloses further comprising: validating, by the service, the other request based on a token received with the other request (paragraph [0174]: [0174] The incoming request received by the multi-cloud infrastructure 720B is processed by the authority module 722A for performing authentication and access control. Each request includes a token associated with the account of the user in the second cloud infrastructure. The authority module extracts the token and validates the token in conjunction with the active directory 712 (i.e., the identity provider system of the second cloud infrastructure 710A) and a determination that a multi-cloud identity object is configured for the customer (paragraph [0204]: the routing proxy module 915 communicates with the cloud-link adaptor 920 to obtain mapping information of the user's account in the second cloud infrastructure to the tenancy of the user in the first cloud infrastructure. If the mapping information exists, then the routing proxy module 915 obtains the information pertaining to the tenancy of the user in the first cloud infrastructure and passes the information to the database adaptor 925. In this manner, the database adaptor 925 is aware of the tenancy of the user in the first cloud infrastructure where the resource is to be created/deployed. However, if the cloud-link adaptor 920 determines that no mapping information exists, then the routing proxy module 915 may simply issue, as a response to the request to create the database resource, an ‘unauthorized-access’ message that is transmitted back to the user). Regarding claim 14, Chen discloses wherein the multi-cloud identity object associates the first resource identifier with the second resource identifier (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) and a first identifier (associated with the tenancy of the user in the first cloud infrastructure) to enable operations going through the multi-cloud control plane 722 to map to the appropriate underlying resource in the first cloud infrastructure) and a first subscription identifier assigned by the first cloud service provider with a second subscription identifier assigned by the second cloud service provider (paragraph [0176]: the cloud-link adaptor 722D generates a mapping of a first identifier associated with the tenancy of the user in the first cloud infrastructure to a second identifier associated with the account of the user in the second cloud infrastructure; paragraph [0211]: The cloud-link resource object 1010 includes a mapping of a first identifier associated with the tenancy of the user in the first cloud infrastructure (e.g., tenancy name in the first cloud environment) to a second identifier associated with the account of the user in the second cloud infrastructure (e.g., tenancy ID and associated subscription in the second cloud environment)). Regarding claim 15, Chen discloses further comprising: causing, by the service, the control plane to lock the virtual resource such that an operation on the virtual resource is only authorized upon a determination that the operation is requested from the portal via the service (¶ [0190]: As part of creating the new account, a native user may be created and associated with the newly created account. However, note that this native user's credentials are not used. Rather, the user's identity in the second cloud infrastructure is used for managing the account and its resources (from the second cloud infrastructure) in the first cloud infrastructure; paragraph [0224]: When a user transmits (from the second cloud environment), a request to the multi-cloud infrastructure … the cloud-link adaptor 1030 creates the resource-principal … which is utilized by a downstream service of the first cloud environment to execute the request; paragraph [0231]: The DBaaS service 1060 can then determine, based on the resource-principal (i.e., based on policies associated with the resource-principal), whether creation of a database… is permitted; Note: the multi-cloud service configures (i.e., locks) the resource in the native control plane such that operations are authorized exclusively via the multi-cloud service pathway (using the second cloud’s portal and identity). Under the BRI, “locking” a virtual resource encompasses configuring access policies such that only a specific identity or pathway is granted authorization). Regarding claim 16, Chen discloses further comprising: requesting, by the service from the control plane, status information about configuring the virtual resource while the control plane is configuring the virtual resource (paragraph [0208]: Upon the user issuing the request to create the Exa-database, the user may intermittently poll the MCCP 900 to obtain a status of the request); and sending, by the service, the status information to the second cloud environment (paragraph [0271]: Metadata associated with each database may also be displayed. It is appreciated that the metadata may include information related to a name of the database, a subscription of the user, a resource group to which the resource belongs to, locality information of the resource, and a current status of the resource). Regarding claim 17, Chen discloses further comprising: determining, by the service, a first subscription identifier assigned by the first cloud service provider, a second subscription identifier assigned by the second cloud service provider (paragraph [0176]: the cloud-link adaptor 722D generates a mapping of a first identifier associated with the tenancy of the user in the first cloud infrastructure to a second identifier associated with the account of the user in the second cloud infrastructure; paragraph [0211]: The cloud-link resource object 1010 includes a mapping of a first identifier associated with the tenancy of the user in the first cloud infrastructure (e.g., tenancy name in the first cloud environment) to a second identifier associated with the account of the user in the second cloud infrastructure (e.g., tenancy ID and associated subscription in the second cloud environment)), and a first resource identifier assigned by the second cloud service provider (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) and a first identifier (associated with the tenancy of the user in the first cloud infrastructure) to enable operations going through the multi-cloud control plane 722 to map to the appropriate underlying resource in the first cloud infrastructure)), wherein the virtual resource is configured based on the first subscription identifier, the second subscription identifier, and the first resource identifier (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) and a first identifier (associated with the tenancy of the user in the first cloud infrastructure) to enable operations going through the multi-cloud control plane 722 to map to the appropriate underlying resource in the first cloud infrastructure; paragraph [0230]: The database adaptor 1037 in turn queries the cloud-link adaptor 1030 (in step 4) to obtain mapping information of the user accounts in the two cloud environments; paragraph [0231]: the database adaptor 1037 transmits a request to the corresponding downstream service offered by the first cloud environment (e.g., DBaaS 1060) … The DBaaS service 1060 can then determine, based on the resource-principal (i.e., based on policies associated with the resource-principal), whether creation of a database… is permitted; paragraph [0239]: the observability instance data object configured for the resource includes the identifiers for both cloud environments and the cloud-link object linking the tenancies; Note: the virtual resource (e.g., the database) is configured/created based on these determined identifiers. Specifically, the multi-cloud infrastructure uses the mapping of the first cloud tenancy, the second cloud subscription, and the external resource identifiers to authorize the request, generate the appropriate resource-principal, and instruct the downstream native control plane to configure the resource in the correct location). Regarding claim 19, Chen discloses further comprising: causing, by the service, an observability service to send metrics about usage of the virtual resource to the second cloud environment (paragraph [0239]: During the creation of a multi-cloud resource (e.g., database)—after a customer creates a multi-cloud database instance, a database adaptor performs two functions: (1) provisions the database with metrics being emitted into a monitoring service of the first cloud environment (i.e., so metrics from the database are produced into the monitoring service); paragraph [0242]: the workflow is initiated to collect, observability data associated with the execution of a service (e.g., the database instance) in the first cloud environment 1101 for the customer of the second cloud environment 1102; paragraph [0245]: the observability framework is setup for collecting, in the first cloud environment, observability data associated with execution of the service in the first cloud environment for the customer of the second cloud environment, and communicating the observability data collected from the first cloud environment to the second cloud environment (e.g., via a high bandwidth network link) to enable a user associated with the customer of the second cloud environment to access the observability data via the second cloud environment). Regarding claim 20, Chen discloses wherein causing the service to send the metrics comprises: sending, by the service to the observability service while the virtual resource is being configured (paragraph [0239]: after a customer creates a multi-cloud database instance, a database adaptor performs two functions: (1) provisions the database with metrics being emitted into a monitoring service of the first cloud environment (i.e., so metrics from the database are produced into the monitoring service), and (2) calls a multi-cloud platform control plane that creates an observability instance data object), a subscription identifier assigned by the second cloud service provider (paragraph [0272]: the control plane of the multi-cloud infrastructure queries both, the control plane of the first external cloud environment as well as the control plane of the first cloud environment (e.g., at the same time) to provide information related to the constructs 1632A of the first external cloud environment (such as a subscription ID), a first resource identifier assigned by the first cloud service provider (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) … ; paragraph [0239]: a second identifier of a second customer tenancy of the second cloud environment; paragraph [0272]: resource group ID), and a second resource identifier assigned by the second cloud service provider (paragraph [0177]: the cloud-link adaptor 722D performs translation between external cloud identifiers (e.g., second identifier associated with the account of the user in the second cloud infrastructure) and a first identifier (associated with the tenancy of the user in the first cloud infrastructure) to enable operations going through the multi-cloud control plane 722 to map to the appropriate underlying resource in the first cloud infrastructure; paragraph [0239]: a first identifier of the resource deployed in the first cloud environment; paragraph [0272]: The graphical user interface 1630 also includes a project detail section 1632 that provides details related to … constructs 1632B). Allowable Subject Matter Claim 18 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. Kondratiev et al. (US 2023/0247088) discloses “The MCCP enables users of a second cloud infrastructure (e.g., Azure users) to make use of resources (e.g., database resources) provided by a first cloud infrastructure (e.g., OCI) in a way that is transparent to the user” (paragraph [0042]). Any inquiry concerning this communication or earlier communications from the examiner should be directed to SISLEY N. KIM whose telephone number is (571)270-7832. The examiner can normally be reached M-F 11:30AM -7:30PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, April Y. Blair can be reached on (571)270-1014. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SISLEY N KIM/Primary Examiner, Art Unit 2196 8/31/2026
Read full office action

Prosecution Timeline

May 09, 2024
Application Filed
Sep 03, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743323
LIVE MIGRATION OF RUNNING APPLICATIONS BETWEEN COMPUTER SYSTEMS
3y 5m to grant Granted Sep 22, 2026
Patent 12730668
LOAD LATENCY AMELIORATION USING BUNCH BUFFERS
3y 11m to grant Granted Sep 08, 2026
Patent 12730661
SECURE SIDECAR CONTAINER
3y 5m to grant Granted Sep 08, 2026
Patent 12730559
SHARED MEMORY WITH PRIORITY-BASED NOTIFICATIONS
3y 0m to grant Granted Sep 08, 2026
Patent 12717643
DATA LOCALITY FOR BIG DATA ON KUBERNETES
4y 7m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
89%
Grant Probability
99%
With Interview (+16.6%)
2y 7m (~3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 693 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month