Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Applicant’s submission for RCE filed on 05/15/2026 has been entered. Applicant has amended claims 1, 5, 6, 10, 11 and 16. Currently claims 1-11 and 13-16 are pending in this application.
Response to Arguments
Applicant's arguments with respect to claims 1, 6 and 11 have been considered but are moot in view of the new ground(s) of rejection.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-3, 5-8, 10-11, 13-14 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Smith in view of Bhalotra et al. (US 10,397,255 B1), hereinafter, “Bhalotra”.
Regarding Claims 1, 6 and 11, discloses a method, corresponding computing device and computer program product for securing a tenant container, the computing device being adapted for comprising:
processing circuitry (See, Fig. 3, Numeral 310);
at least one memory (See, Fig. 3, Numeral 312) connected to the processing circuitry and storing program code that is executed by the processing circuitry to perform operations comprising:
identifying collection of information from the tenant container by an endpoint agent resident on the computing device during execution of the tenant container (See, Paragraph 0036, “TTEM 314 when executed by processor 310 may cause service provider to, in response to receiving a TTIS, send an attestation signal (AS) to client 101” and Paragraph 0038, “In instances where a TTIS includes security and/or compartmentalization context, TEM 314 may cause service provider 102n to instantiate containers/realms pertinent to such context. By way of example, if a TTIS specifies that data associated with a trusted task is subject to multi-level security policy that classifies some of the data as top secret, other data as sensitive, and still other data as unclassified, TEM 314 may cause service provider 102n to initiate containers/realms in its TEE for each of the top secret data, the sensitive data, and the unclassified data. Each container/realm may be affiliated with associated resources, e.g., storage resources, processing resources, network resources, combinations thereof, and the like. Subsequently, TEM 314 may cause service provider 102n to send an attestation signal to client 101 that includes information about the instantiated containers/realms. In some embodiments, the containers/realms are instantiated to a degree that is sufficient to allow attestation to the client of the service provider's ability to maintain such containers/realms in a TEE”) and Paragraph 0037 recites, “Prior to sending an AS to client 101, service provider 102n may initiate its TEE environment for the purpose of supporting the attestation process. More specifically, TEM 314 may cause service provider 102n to instantiate enough of its TEE environment to support attestation, i.e., to support a representation to client 101 of its TEE capabilities”);
extracting a summary of collected information (See, Paragraph 0036, “The AS may include information that may affect client 101's decision to schedule the trusted task on service provider 102n capabilities to the client. For example, the AS may include information attesting to the nature and type of TEE(s) on service provider 102n. In addition, the AS may include contextual information relevant to the trusted task. Non-limiting examples of such contextual information include the service provider's expected allocation of computing resources (processor, memory, input/output, storage, etc.), combinations thereof, and the like. Alternatively or additionally, contextual information in the AS may include context obtainable from one or more sensors, such as the location of service provider 102n (e.g., obtained using a global positioning system), the mobility of service provider 102n (e.g., from an accelerometer), power information (e.g., battery life), policies or Service Level Agreement (SLA) constraints” and Paragraph 0038 recites, “TEM 314 may cause service provider 102n to send an attestation signal to client 101 that includes information about the instantiated containers/realms”); and
signing the summary of the collected information using a signing key (See, Fig. 5, “Service Provider Attestation Module” and Paragraph 0070, “In any case, the service provider 102n may sign its attestation proof with in appropriate private key, e.g., ID-E, if it wishes to remain anonymous. Like ID-C, the nature of ID-E may vary depending on the TEE capabilities of service provider 102n. For example, where service provider 102n's TEE is configured to use secure enclave, ID-E may be the private EPID of service provider 102n. Likewise if service provider 102n is equipped to provide a TEE using virtualization (as in the case of a trusted platform module), ID-E may take the form of an AIK”),
wherein the signing key is not accessible to one or more processes that are being executed on the computing device (See, Paragraph 0070, “the service provider 102n may sign its attestation proof with in appropriate private key, e.g., ID-E, if it wishes to remain anonymous. Like ID-C, the nature of ID-E may vary depending on the TEE capabilities of service provider 102n. For example, where service provider 102n's TEE is configured to use secure enclave, ID-E may be the private EPID of service provider 102n. Likewise if service provider 102n is equipped to provide a TEE using virtualization (as in the case of a trusted platform module), ID-E may take the form of an AIK”),
wherein at least some of the information collected from the tenant container by the endpoint agent is accessible for extraction of the summary of the collected information (See, Paragraph 0051, “The method may then proceed to block 411, wherein the client analyzes the attestation proof offered by the service provider and determines whether an acceptable TEE can be instantiated on the service provider”).
Smith fails to disclose wherein the information from the tenant container comprises events or alerts related to multiple software processes.
Bhalotra discloses collecting information from tenant container wherein the information from the tenant container comprises events or alerts related to multiple software processes (See, Column 5, lines 30-44, Column 6, line 38-Column 7, line 2, Column 8, lines 14-42 and Column 10, lines 46-60).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to collect, in the system of Smith, information from tenant container wherein the information from the tenant container comprises events or alerts related to multiple software processes as taught by Bhalotra because “[T]the fingerprinting process and the resulting fingerprints uniquely identify distinct application components and configuration, reveal equivalence between identical profiles despite different container names, make it easy to determine differences between containers, provide metadata useful for machine learning, provide metadata useful for detecting corrupt states, provide metadata useful for enforcement actions, and do not modify the containers in any way. The fingerprinting process is done passively at runtime with no impact on application behavior and no additional latency.
Regarding Claims 2, 7 and 13, the rejection of claims 1, 6 and 11 is incorporated and Smith further discloses transmit the signed summary to one or more of: a tenant associated with the tenant container and a vendor associated with the tenant container (See, Paragraphs 0014 and 0038).
Regarding Claims 3, 8 and 14, the rejection of claims 1, 6 and 11 is incorporated and Smith further discloses wherein identify the collection of information related to the tenant container further comprises: determine one or more rules applied by the endpoint agent for collecting the information from the tenant container during execution of the tenant container (See, Paragraph 0044-0045).
Regarding Claims 5, 10 and 16, the rejection of claims 1, 6 and 11 is incorporated and Smith further discloses wherein the information from the tenant container comprises at least one of metadata, events, and alerts related to multiple software processes, relationships between the software processes, private data, Personal Identifiable Information (PII), operation of the computing device, and operating system configuration changes (See, Paragraph 0036 and 0069).
Claims 4, 9 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Smith in view of Bhalotra and further in view of Yu et al. (US 2020/0349252 A1), hereinafter, “Yu”.
Regarding Claims 4, 9 and 15, the rejection of claims 1, 6 and 11 is incorporated and Smith further discloses whereby execution of the program code causes the computing device to perform further operations comprising: transmitting the summary of the collected information to the tenant or the vendor of the container (See, Paragraph 0083); but does not explicitly disclose receiving a request for inspecting of the summary from a tenant or vendor of the container and receiving an indication related to verification of the authenticity of the summary from the tenant or the vendor of the container (See, Paragraphs 0053, 0087 and 0108).
Yu discloses receiving a request for inspecting of a summary from a tenant or vendor of a container and receiving an indication related to verification of the authenticity of the summary from the tenant or the vendor of the container (See, Paragraphs 0049, 0071, 0053, 0087 and 0108).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to receive, in the system of Smith and Bhalotra, a request for inspecting of a summary from a tenant or vendor of a container and receiving an indication related to verification of the authenticity of the summary from the tenant or the vendor of the container as taught by Yu in order to perform an attestation process is performed to verify (prove) that the TEE is operating as expected, and is executing the code that is expected to be executed therein (See, Yu, Paragraph 0004).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to YOGESH PALIWAL whose telephone number is (571)270-1807. The examiner can normally be reached M-F 9:00AM-5:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571)270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/YOGESH PALIWAL/Primary Examiner, Art Unit 2435