DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-3, 6-19 are pending.
Claim Objections
Claim 2, 6, 15 and 18 are objected to because of the following informalities:
-- the first, second and third -- should be -- the first, the second and the third -- in claim 2 and claim 18.
-- herein -- should be -- wherein -- in claim 6 line 1.
-- excludes -- should be -- exclude[[s]] -- in claim 15.
Appropriate correction is required.
Specification
The title of the invention is same as the parent application name. A new title is required that is clearly indicative of the invention to which the claims are directed.
The disclosure is objected to because of the following informalities:
-- employers are currently are -- should be -- employers are currently
-- detected, of if -- should be -- detected, of or if -- in [0031].
-- excludes -- should be -- exclude -- in [0071].
-- includes for -- should be -- include -- in [0078].
Appropriate correction is required.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to
www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1, 11-12 of the instant invention are rejected on the ground of nonstatutory double patenting as being unpatentable over claim 1 of U.S. Patent No. US 12,026,531 B2 (hereafter ‘531).
Instant Invention
US Patent 12,026,531 B2 (‘531)
1. A method for emulating a secure remote application-specific workstation on a general purpose computer having volatile and non-volatile memories, and a network interface, the method comprising the steps of:
1. A method for emulating a secure remote application-specific workstation on a general purpose computer having volatile and non-volatile memories, and a network interface, the method comprising:
a. prior to booting up the general purpose computer, receiving at a data port of the general purpose computer a portable data storage device,
prior to booting up the general purpose computer, receiving at a data port of the general purpose computer a portable data storage device,
the portable data storage device having stored therein at least a software code for an operating system for emulating an application-specific workstation;
the portable data storage device having stored therein at least a software code for an operating system for emulating an application-specific workstation;
Claim 12
modifying a Basic Input/Output System (BIOS) setting of the general purpose computer such that the general purpose computer will first determine whether the software code for emulating the application-specific workstation operating system is accessible from the portable data storage device connected to the data port prior to attempting to execute any portion of the operating system stored in the non-volatile memory of the general purpose computer;
b. as part of initiating the boot up of the general purpose computer, copying the software code from the portable data storage device to the volatile memory, while not accessing or executing any portion of any software code stored in the non-volatile memory;
as part of initiating the boot up of the general purpose computer, copying the software code from the portable data storage device to the volatile memory, while not accessing or executing any portion of any software code stored in the nonvolatile memory;
c. executing by the general purpose computer, a first portion of the software code copied to the volatile memory to transmit authorization request data to a remote administrative server via the network interface;
executing by the general purpose computer, a first portion of the software code copied to the volatile memory to transmit authorization request data to the remote administrative server via the network interface;
d. executing by the general purpose computer, a second portion of the software code copied to the volatile memory to confirm that the general purpose computer is authorized to execute at least a third portion of the software code copied to the volatile memory,
executing by the general purpose computer, a second portion of the software code copied to the volatile memory to confirm that the general purpose computer is authorized to execute at least a third portion of the software code copied to the volatile memory,
wherein executing the second portion of the software code causes the general purpose computer to process received authorization response data from the remote administrative server, the response data including instructions which either permit or forbid certain actions by the general purpose computer;
wherein executing the second portion of the software code causes the general purpose computer to process received authorization response data from the remote administrative server;
e. upon confirmation of authorization based on the processed received authorization response data, executing by the general purpose computer the third portion of the software code for emulating the application-specific workstation, to prevent read and/or write access of any digital information from and/or to the non-volatile memory and to enable the execution of any portion of an operating system stored only in the volatile memory; and
upon confirmation of authorization based on the processed received authorization response data, executing by the general purpose computer the third portion of the software code for emulating the application-specific workstation and to prevent read and/or write access of any digital information from and/or to the non-volatile memory and the execution of any portion of the operating system stored in the nonvolatile memory; and
f. transmitting to and receiving from the network-connected remote administrative server via the network interface information associated with an operation of at least one specific software application of the application specific workstation.
transmitting to and receiving from the network-connected remote administrative server via the network interface information associated with an operation of at least one specific software application of the application specific workstation,
11. The method of claim 1 wherein the at least one specific software application of the application specific workstation is a specific application for emulating a Payment Card Industry Data Security Standard (PCI DSS), level 1, compliant workstation.
wherein the at least one specific software application of the application specific workstation is a specific application configured for compliance with a Payment Card Industry Data Security Standard (PCI DSS), level 1 system.
12. The method of claim 1 further comprising the step of modifying BIOS settings of the general purpose computer such that the general purpose computer will first determine whether the software code for emulating the application-specific workstation operating system is accessible from a portable data memory connected to the data port prior to executing any portion of the operating system stored in the non-volatile memory of the general purpose computer.
As illustrated in above table, claims 1, 11-12 of instant application are rejected over claim 1 of US Patent ‘531. Instant invention teaches “the response data including instructions which either permit or forbid certain actions by the general purpose computer;”, “enable the execution of any portion of an operating system stored only in the volatile memory”, which is either missing from or variation of limitations of claim 1 of the US patent ‘513. On the other hand, US patent ‘513 teaches prevent the execution of any portion of an operating system stored only in the non-volatile memory.
Although the claims at issue are not identical, they are not patentably distinct from each other because “enabling the execution of operating system stored in the volatile memory” as recited in the instant invention is variation of limitations of “preventing execution of operating system in the non-volatile memory” as recited in the US patent ‘513.
This is an obviousness-type double patenting rejection.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1-3, 6-20 are rejected under 35 U.S.C. 112 (b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or joint inventor regards as the invention.
The following terms lack proper antecedent basis:
-- the network connected -- in claim 1 step f.
-- the steps of -- in claim 1 line 3.
-- the at least one of -- in claim 3 line 2.
-- the step of controlling -- in claim 14 line 2
The following claim language is not clearly understood:
Claim 1 recites “portable storage device having stored therein a software code”, and later recites a first, second and third portion of the software code. It is unclear what decides the portions, i.e. how the portion of the code is determined to be first, second or third portions.
Claim 1 recites in step e.) that “upon confirmation of authorization…executing by the general purpose computer the third portion of the software code for emulating the application specific workstation, to prevent read and/or write access of any digital information from and/or to the non-volatile memory and to enable the execution of an operating system only in the volatile memory”. It is unclear if the authorization or the execution of the third portion of code that prevent the read/write access to the non-volatile memory and enable execution of the operating system.
Claim 3 recites “at least one of the at least one of specific software application”. It is unclear if at least one specific software or one of the specific software among the multiple specific software is being received.
Claim 13 recites “prior to performing the receiving step” without clearly reciting which receiving step i.e. receiving of the portable data storage device”, “receiving authorization response”, or “receiving of information associated with software application”.
Remaining dependent claims 2-3, 6-20 are also rejected due to deficiency inherited from the rejected independent claims.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-3, 6-7, 12-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Gschwind (US 2018/0024839 A1) in view of MCMICHAEL, IV et al (US 2016/0381031 A1, hereafter MCMICHAEL) and further in view of Fusari (US 2009/0307311 A1).
MCMICHAEL, Gschwind and Fusari were cited in the IDS filed on 11/07/2024.
As per claim 1, Gschwind teaches the invention substantially as claimed including a method for emulating on a general purpose computer having volatile and non-volatile memories, and a network interface (fig. 1 computer 10 memory 110 network interface 124 [0092] volatile memory elements e.g., RAM nonvolatile memory elements e.g. ROM [0030] computer, general purpose computer [0006] emulate a boot environment), the method comprising the steps of:
a. prior to booting up the general purpose computer, receiving at a data port of the general purpose computer a portable data storage device ([0028] computer 10 to boot from user trusted device UTD 20 i.e. connection before UTD), the portable data storage device having stored therein at least a software code for an operating system for emulating ([0031]UTD, stores a boot loader 16 [0003] OS loader typically includes a boot loader [0005] OS loader from the user trusted device [0041] OS loader 24a, stored, on the UTD 20 [0006] emulate a boot environment);
b. as part of initiating the boot up of the general purpose computer ([0001] securely booting computers, booting a computer from user trusted device), copying the software code from the portable data storage device to the volatile memory ([0018] user trusted device, connectable, computer, stores, boot loader [0010] bootloader, copy the identified boot block of executable core to a suitable address in the main memory prior to starting execution of the loaded or stored initial boot block), while not accessing or executing any portion of any software code stored in the non-volatile memory ([0049] preventing the PC 10 to be booted by the user without the user trusted device UTD 20, in order to prevent the user to accidentally boot the PC 10 on the PC's data storage device, without the user trusted device UTD 20, this initial boot block has to be removed or replaced with a different version);
c. executing by the general purpose computer, a first portion of the software code copied to the volatile memory to authorization ([0003] bootloader prompts the user for a passphrase that is used to unlock the encryption key [0010] bootloader, copy the identified boot block of executable core to a suitable address in the main memory);
d. executing by the general purpose computer, a second portion of the software code copied to the volatile memory to confirm that the general purpose computer is authorized ([0018] user trusted device, connectable, computer, stores, boot loader [0010] bootloader, copy the identified boot block of executable core to a suitable address in the main memory prior to starting execution of the loaded or stored initial boot block [0003] bootloader prompts the user for a passphrase that is used to unlock the encryption key [0041] computer is requested to authenticate to a smart card [0056] PC 10, need to authenticate itself in order to allow to copy the detected version of the OS loader 24);
e. executing by the general purpose computer the third portion of the software code, to prevent read and/or write access of any digital information from and/or to the non-volatile memory and to enable the execution of an operating system only in the volatile memory ([0049] preventing the PC 10 to be booted by the user without the UTD 20, in order to prevent the user to accidentally boot the PC 10 on the PC's data storage device, without the UTD 20, this initial boot block has to be removed or replaced with a different version [0051] execution of the loaded initial boot block of executable code to trigger execution S282 of other blocks of the transferred OS loader 24b [0052] execution of boot loader, start execution of the loaded/copied initial boot blocks, triggers the execution of the remainder of the OS loader 24b, causes the loaded or stored initial boot block [0003] OS loader typically includes a boot loader [0029] operating system services [0010] bootloader, copy the identified boot block of executable core to a suitable address in the main memory).
Gschwind doesn’t specifically teach emulating a secure remote application-specific workstation; first portion of software code to transmit authorization request data to a remote administrative server via the network interface; to confirm computer is authorized to execute at least a third portion of the software code copied to the volatile memory; wherein executing the second portion of the software code causes the general purpose computer to process received authorization response data from the remote administrative server, the response data including instructions which either permit or forbid certain actions by the general purpose computer; upon confirmation of authorization based on the processed received authorization response data, executing the third portion of the code for emulating the application-specific workstation; transmitting to and receiving from the network-connected remote administrative server via the network interface information associated with an operation of at least one specific software application of the application specific workstation.
MCMICHAEL, however, teaches the invention substantially as claimed including method for a secure remote application-specific workstation (fig. 2 client device 108 VDI client 110 remote VM desktop 165 [0019] user credentials, VM, log on), the method comprising the steps of:
c. first portion of the software code copied to the volatile memory to transmit authorization request data to a remote administrative server via the network interface ( [0011] fig. 1 client machine 108 general purpose computer network 120 connection broker 137 users, their desktop, running in one of virtual machine 157 or blade server, data center, remote from the user locations [0003] transmitting, user credentials, request, start session script, client [0004] connection broker, configured, receive user credentials fig. 2 client 108 credentials connection broker 137 domain controller 135 VM 165 remote desktop agent 204 user profiles 213);
d. executing by the general purpose computer ([0011] fig. 1 client machine 108 general purpose computer network 120 connection broker 137), to confirm that the general purpose computer is authorized to execute at least a third portion of the software code ([0024] client, accepts user credentials from a user, transmits the credentials to the connection broker, verifies the credentials via domain controller, [0025] domain controller, permitted desktop information, relays, to the client i.e. user authorized and user/client permitted to execute), wherein executing the second portion of the software code causes the general purpose computer to process received authorization response data from the remote administrative server ([0024] client, accepts user credentials from a user, transmits the credentials to connection broker 137, verifies the credentials via domain controller 135 domain controller, permitted desktop information, relays, to the client i.e. user authorized and user/client permitted to execute corresponding desktop), the response data including instructions which either permit or forbid certain actions by the general purpose computer ([0025] domain controller retrieves, permitted desktop information, transmits the permitted desktop information to connection broker, which relays the permitted desktop information back to client [0026] client machine 108, permitted desktop, user, select, desktops [0027] VM receives credentials, operating system, beginning the log on process for the user);
e. upon confirmation of authorization based on the processed received authorization response data ([0024] response to verifying the credentials, connection broker 137, looks up desktop permitted to be accessed by the user [0025] Domain controller 135 retrieves this permitted desktop information from user account information 136 and transmits the permitted desktop information to connection broker 137, which relays the permitted desktop information back to client machine 108 i.e. responding to the authorization request [0026] client machine 108, displays the permitted desktop on user interface i.e. processing the response, client machine 108, permitted desktop, user, select, desktops [0027] VM receives credentials, operating system, beginning the log on process for the user), executing by the general purpose computer the third portion of the software code ([0026] permitted desktops, user select one of the permitted desktops, [0027] VM receives credentials, operating system, beginning the log on process for the user, logon, begin a session [0028] execution of startup script); and
f. transmitting to and receiving from the network-connected remote administrative server via the network interface (fig. 1 client 108 network 120 connection broker 137 domain controller 135 fig. 2 client 108 desktop connection 165 connection broker 137 domain controller 135 client 108 [0003] transmitting, user credentials, request to execute start session script to host computer[0025] permitted desktop, transmits, to connection broker, relays to client) information associated with an operation of at least one specific software application of the application specific workstation ([0028] fig. 2 client 108 connection broker 137 script execution request VM 165 fig. 4 log user on VM 416).
It would have been obvious to one of ordinary skills in the art before the effective filing date of the invention was made to combine the teachings of Gschwind with the teachings of MCMICHAEL of client device connecting to remote desktop, sending credentials and receiving the permitted remote desktop information after verification of the credentials, selecting the desktop from the permitted desktop, causing execution of start session script, client transmitting the credentials / request for script execution, remote desktop server transmitting the permitted desktops information to improve efficiency and allow a secure remote application-specific workstation; first portion of software code to transmit authorization request data to a remote administrative server via the network interface; to confirm computer is authorized to execute at least a third portion of the software code copied to the volatile memory; wherein executing the second portion of the software code causes the general purpose computer to process received authorization response data from the remote administrative server, the response data including instructions which either permit or forbid certain actions by the general purpose computer; upon confirmation of authorization based on the processed received authorization response data, executing the third portion of the code for the application-specific workstation; transmitting to and receiving from the network-connected remote administrative server via the network interface information associated with an operation of at least one specific software application of the application specific workstation to the method of Gschwind as in the instant invention.
The combination would have been obvious because applying the known method of connecting to the remote desktop, exchanging /verifying credentials, presenting permitted desktop and running the session script, exchanging messages as taught by MCMICHAEL to the method of Gschwind to yield expected result and improved efficiency.
Gschwind and MCMICHAEL, in combination, do not specifically teach emulating the application-specific workstation.
Fusari, however, teaches emulating the application-specific workstation ([0017] receiving from the remote application server, remote application is emulated on the first client [0092] emulation, client emulates a remote desktop session executing on remote application server, session provided in the form of desktop, client may launch one or more applications).
It would have been obvious to one of ordinary skills in the art before the effective filing date of the invention was made to combine the teachings of Gschwind and MCMICHAEL with the teachings of Fusari of client emulates a remote desktop session executing on remote application server and launches one or more application to improve efficiency and allow emulating the application-specific workstation to the method of Gschwind and MCMICHAEL as in the instant invention.
The combination would have been obvious because applying the known method of emulating a remote desktop session executing applications as taught by Fusari to the method of Gschwind and MCMICHAEL of controlled booting of the general purpose computer using the boot loader obtained from a portable device as taught by Gschwind and MCMICHAEL to yield expected result with improved efficiency.
As per claim 2, Gschwind teaches wherein at least one of the first, second and third portions of the software code stored in the portable data storage device is encrypted ([0035] OS loader, boot loader, reside encrypted, UTD).
As per claim 3, Gschwind teaches wherein execution of the third portion of the software code comprises receiving from the remote administrative server ([0051] execution of the loaded initial boot block of executable code to trigger execution S282 of other blocks of the transferred OS loader 24b [0052] [0087] user device 20, third party server 30, host computer 10 [0096] transmits / receives data between the computer 10 and external system e.g. server 30 [0104] remote computer server 30).
Fusari teaches remaining claim elements of receiving at least one of the at least one of specific software application from the remote server ([0018] client further executing an emulation application that emulates that at least one remote application on the first client [0092] session provide in the form of desktop, from which emulation client, launch one or more applications).
As per claim 6, Gschwind teaches wherein the copied software code into the volatile memory includes at least one software driver the general purpose computer ([0006] transfer the OS loader by loading it into a main memory, cause to execute the at least one crypto driver and the kernel [0029] crypto driver, device driver), and wherein the method further comprises controlling with the at least one software driver at least one of a network interface controller, computer monitor, mouse, keyboard, microphone and camera connected to the general purpose computer ([0006] execute crypto driver, kernel [0029] crypto driver, device driver [0039] device drivers, user/application, PC’s hardware [0096] keyboard, mouse, microphone, display).
As per claim 7, Fusari teaches wherein the specific software application of the application specific workstation includes customer communications for at least one of customer inquiries, complaints, orders or requests ([0003] plurality of computer applications, user, patient, clinical information, patient encounter, clinical provider, observation, insurer [0004] healthcare related applications).
As per claim 12, Gschwind teaches modifying BIOS settings of the general purpose computer ([0006] modify a boot environment [0051] modify the boot environment is to load the initial boot blocks of the OS loader 24b into the same memory region as would otherwise be done by the PC's BIOS [0052] load/copy initial boot blocks of executable code from the UTD) such that the general purpose computer will first determine whether the software code for emulating the application-specific workstation operating system is accessible from a portable data memory connected to the data port (fig. 3 let boot loader be detected by firmware S23 compare OS loader on UTD to OS loader version on PC S26 OS loader version differ S261-yes/no i.e. application-specific workstation operating system is accessible or not ) prior to executing any portion of the operating system stored in the non-volatile memory of the general purpose computer ([0003] boot computer, hard disk, operating system loader, operating system subsequently started [0071] prior to execution S28 re-instate a secure version of OS loader [0049] prevent the user to accidentally boot the PC 10 on the PC's data storage device, without the user trusted device UTD 20, this initial boot block has to be removed or replaced with a different version).
As per claim 13, Gschwind teaches the downloading and executing BIOS setting altering software received via the network interface prior to performing the receiving ([0006] modify a boot environment [0051] modify the boot environment is to load the initial boot blocks of the OS loader 24b into the same memory region as would otherwise be done by the PC's BIOS [0052] load/copy initial boot blocks of executable code from the UTD [0103] program instructions, downloaded to computing/processing device).
As per claim 14, McMichael teaches the step of controlling permitted operations available to a user of the general purpose computer by at least one of executing the second portion of the software code ([0011] user, access, remote desktop, using general purpose computer [0016] user, single sign on client 110, operating system 208 [0001] remotely access virtual computing environment or desktops, workers, access, personal accounts at different locations), and instructions received from the network-connected remote administrative server via the network interface ([0018] client, communication, domain controller, message exchange [0013] VDI system 100 communicate via network).
As per claim 15, Fusari teaches wherein the permitted operations excludes at least one of printing, accessing the internet, cutting, pasting or copying data, and using any data ports of the general purpose computer ([0038] prevents data communication [0076] can’t send unsolicited communication to application executing on desktop [0084] prevents, rouge application, intruding context).
As per claim 16, Fusari teaches wherein the permitted operations are based on at least predetermined responsibilities of the user of the general purpose computer ([0003] user, authorized resources, patient encounter, clinical provider, observation, insurer) and time periods when the user is scheduled to access such permitted operations ([0016] client, application, share, context, another application, period of time).
As per claim 17, McMichael teaches the received authorization response data from the remote administrative server is based on a dual authentication process (fig. 2 client 108, connection broker 137 domain controller 135 [0024] In response to verifying the credentials, connection broker 137 looks up desktops permitted to be accessed by the user associated with the credentials [0025] Domain controller 135 retrieves this permitted desktop information from user account information 136 and transmits the permitted desktop information to connection broker 137, which relays the permitted desktop information back to client machine 108 [0014] user credentials, user ID and password, user principal name on a smart card certificate and a smart card pin).
As per claim 18, McMichael teaches wherein at least one of the first, second or third portions of the software code is based on a Linux operating system ([0021] Microsoft windows, may apply to system that execute different operating systems).
As per claim 19, Fusari teaches wherein execution of the third portion of the software code executes application partitioning for updating software applications for execution in the general purpose computer without interfering with the activities of the user of the general purpose computer ([0046] desktop, executes, browser, communicates with web server, separates user interface from the corresponding application program in a manner such that updates of the application program are not automatically sent to the user interface).
As per claim 20, MCMICAHEL teaches the remote administrative server is managed by an administrator ([0016] administrator, disable, single sign on [0030] administrator, create, profile 212, desktop setup ); and
the general purpose computer only performs operations allowed by the administrator and only enables access to applications made available by the administrator, the available applications necessary for a user to perform tasks associated with the user's job ([0016] user, desktop, VDI client, user, perform single sign-on, administrator may disable the single sign on [0020] user profile, information related to the desktop environment in which the user may interact with the operating system and applications).
Claims 8-10 is/are rejected under 35 U.S.C. 103 as being unpatentable over MCMICHAEL in view of Gschwind and further in view of Fusari, as applied to above claims, and further in view of SZE et al. (US 2021/0152485 A1, hereafter SZE).
SZE was cited in the IDS filed on 11/07/2024.
As per claim 8, Fusari teaches wherein the at least one specific software application includes software applications for at least one of productivity applications ([0003] plurality of computer applications, user, patient, clinical information, patient encounter, clinical provider, observation, insurer [0004] healthcare related applications).
Gschwind, MCMICHAEL and Fusari, in combination, do not specifically teach application for at least one of quality of service monitoring, word processors, spreadsheet applications, document reader applications, key-logger.
SZE, however, teaches software application for at least one of quality of service monitoring, word processors, spreadsheet applications, document reader applications, key-logger ([0023] computer implemented method for improving performance of transmission, real-time or near real-time applications [0047] performance measurement, jitter, packet loss [0051] quality, latency [0084] real-time monitoring of the characteristics, connection).
It would have been obvious to one of ordinary skills in the art before the effective filing date of the invention was made to combine the teachings of Gschwind, MCMICHAEL, and Fusari with the teachings of SZE of real-time application for performance measurement including jitter, quality, latency to improve efficiency and allow application for at least one of quality of service monitoring, word processors, spreadsheet applications, document reader applications, key-logger to the method of Gschwind, MCMICHAEL, and Fusari as in the instant invention.
The combination would have been obvious because applying the known method of real-time application for performance measurement including jitter, quality, latency as taught by SZE to the method of Gschwind, MCMICHAEL, and Fusari to yield expected result and improved efficiency.
As per claim 9, SZE teaches wherein the software applications for the quality of service monitoring includes monitoring at least one of packet loss, jitter, latency and other indicators for the quality of the network connection ([0047] performance measurement, jitter, packet loss [0051] quality, latency [0084] real-time monitoring of the characteristics, connection).
As per claim 10, SZE teaches wherein the quality of service monitoring is based on monitoring of the at least one of packet loss, jitter, latency and indicators for the quality of the network connection ([0047] performance measurement, jitter, packet loss [0051] quality, latency [0084] real-time monitoring of the characteristics, connection [0052] minimum system latency threshold, predetermined system latency threshold).
Claims 11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Gschwind in view of MCMICHAEL and further in view of Fusari, as applied to above claims, and further in view of NEWMAN (US 2010/0050249 A1, hereafter NEWMAN).
NEWMAN was cited in the IDS filed on 11/07/2024.
As per claim 11, Fusari teaches wherein the at least one specific software application of the application specific workstation is a specific application for emulating a Payment Card Industry Data Security Standard (PCI DSS), level 1, compliant workstation ([0003] plurality of computer applications, user, patient, clinical information, patient encounter, clinical provider, observation, insurer [0004] healthcare related applications).
Gscwind, MCMICHAEL, and Fusari, in combination, do not specifically teach a Payment Card Industry Data Security Standard (PCI DSS), level 1, compliant workstation.
NEWMAN, however, teaches Payment Card Industry Data Security Standard (PCI DSS), level 1, compliant workstation ([0002] payment card industry PCI data security standard DSS [0052] virtual machine, PCI compliance).
It would have been obvious to one of ordinary skills in the art before the effective filing date of the invention was made to combine the teachings of Gschwind, MCMICHAEL, and Fusari with the teachings of NEWMAN of payment card industry data security standard virtual machine compliance to improve efficiency and allow a Payment Card Industry Data Security Standard (PCI DSS), level 1, compliant VM workstation to the method of Gschwind, MCMICHAEL, Gschwind, and Fusari as in the instant invention.
The combination would have been obvious because applying the known method of PCI compliance virtual machine as taught by NEWMAN to the method of Gschwind, MCMICHAEL, and Fusari to yield expected result and improved efficiency.
Examiners Note
Applicant is further reminded of that the cited paragraphs and in the references as applied to the claims above for the convenience of the applicant(s) and although the specified citations are representative of the teachings of the art and are applied to the specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested from the applicant in preparing responses, to fully consider all of the references in entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior art or disclosed by the examiner.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
McGravey (US 5926631 A) teaches network computer emulator systems for product for personal computer and emulator program obtaining a java desktop and java application from the server over the network.
Pouline (US 7813910 B1) teaches system for developing an application playing on a mobile device emulated on a personal computer
Authorization for Internet Communication
Applicant is encouraged to submit an authorization to communicate with the Examiner via the internet by making the following statement (MPEP 502.03)
“Recognizing that internet communications are not secure, I hereby authorize the USPTO to communicate with the undersigned and practitioners in accordance with 37 CFR 1.33 and 37 CFR 1.34 concerning any subject matter of this application by video conferencing, instant messaging, or electronic mail. I understand that a copy of these communications will be made of record in the application file.”
Please note that the above statement can only by submitted via Central Fax (not Examiner’s Fax), Regular postal mail, or EFS Web using PTO/SB/439.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABU ZAR GHAFFARI whose telephone number is (571)270-3799. The examiner can normally be reached on Monday-Thursday 9:00 - 17:00 Hrs.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Aimee Li can be reached on 571-272-4169. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ABU ZAR GHAFFARI/Primary Examiner, Art Unit 2195