Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
The present office action is responsive to communications received on 07/05/2024.
Status of Claims
Claims 1-28 are pending.
Claim Objections
Claim 9 objected to because of the following informalities: the claim recites “connexion” and “connexions” instead of “connection” and “connections”, other claims have the same issue. Appropriate correction is required.
Claim 10 objected to because of the following informalities: the claim ends in comma, other claims might have similar issue. Appropriate correction is required.
Claim 18 objected to because of the following informalities: the claim recites “personal identifiable dana”. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 28 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as failing to set forth the subject matter which the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the applicant regards as the invention.
Claim 28 recites the limitation "the classifier". There is insufficient antecedent basis for this limitation in the claim. The claim is most likely, should have been dependent on claim 27 not claim 22.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-18 are rejected under 35 U.S.C. 101 for reciting software per se.
With respect to independent claims 1 and 14 the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter because the recited components and upon review of the application there is no definition for recited component(s) and based on broadest reasonable interpretation they could be software, therefore failing step 1 of the 2025 Revised Patent Subject Matter Eligibility Guidance (“2025 PEG”).
With respect to dependent claims 2-13 and 15-18 do not cure the deficiencies of independent claims 1 and 14 and are directed to non-statutory subject matter and are rejected under 35 U.S.C. 101.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1, 3-6, 8-10, 12-15, 19, and 21-25 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Yadav et al. (US 20230066058 A1) hereinafter referred to as Yadav.
With respect to claim 1, Yadav discloses: A software container or a virtual machine for integrated software development, accessible over a network by an authenticated software developer, (Yadav ¶96 teaches an author [authenticated developer] accessing over a network a virtual browser to be generated. Wherein ¶26 teaches comprises programming language development environment).
the software container or virtual machine being associated to a credentials management unit having access to a database of credentials that are not known to the software developer, (Fig. 3 illustrates access gateway 372 [credential management unit], also orchestrator 136 in fig. 1, in communication with remote access store 374 [database] in association with containers and virtual machines illustrated. The database is on the network environment 300 and not on the “author/instructor” [developer] side thus interpreted as not known).
the credentials management unit being configured to monitor network traffic, detect an authentication process to an external resource in the network traffic, present to the external resource a corresponding credential selected from the database. (Yadav ¶120 teaches orchestrator using proxy to monitor and wire access material to a learner [external resource] using a detected authentication process and exchanging credentials. The entire paragraph copied herein and relevant portions underlined “The cloud workspace orchestrator 136 may then wire access for the learner, based on the information from the container orchestrator 114 (514), and using a remote access proxy 515 (as an example implementation of the graphical remote access gateway 372 of FIG. 3), which store the credentials in the remote access store 374. That is, the cloud workspace orchestrator 136 may prepare the remote access proxy 515 to establish a connection between the virtual browser cloud workspace (VBCW7 328) and the learner 304. After receiving the appropriate connection identifier and credentials from the remote access proxy 515 (516), the cloud workspace orchestrator 136 may forward the connection identifier and credentials from the remote access proxy 515 to the learner (518). The learner 304 may then use the credentials to connect to the virtual browser cloud workspace 328 via the remote access proxy 515 (520). The remote access proxy 515 then validates the previously-stored credentials using the remote access store 374 (522), thereby enabling bi-directional communication between the learner 304 and the virtual browser cloud workspace (524).”).
With respect to claim 3, Yadav discloses: The software container or virtual machine of claim 1 equipped with a mechanism to manage the digital identities for each user to authenticate with the various network services via their specific protocols such as HTTPS, Git, or any TCP/UDP based protocol using the credential management unit. (Yadav ¶139 teaches using known internet protocols for communication mechanism as taught by the prior art which comprises the credentials mapped before).
With respect to claim 4, Yadav discloses: The software container or virtual machine of claim 1 equipped with a mechanism to store digital identities to use across various services and users, and as well user-centric digital identities, e.g. assigned to particular users, where identities are either auto-generated or provided by users to authenticate to services as explained in claim 3. (Yadav ¶89 teaches storage for credentials which is a process conducted “automatically and dynamically”).
With respect to claim 5, Yadav discloses: The software container or virtual machine of claim 1 equipped with a mechanism to define any network services, e.g. Git applications, Git repositories, HTTP, SSH and TCP-based services, container registries, or any authenticated services connected to the platform whose authentication mechanism uses the credential management unit. (Yadav ¶139 teaches the prior art, which comprises the credential management unit as established in the independent claim, defines different types of mechanisms and protocols used).
With respect to claim 6, Yadav discloses: The software container or virtual machine of claim 1 equipped with a mechanism to specify allowed network traffic consisting of a list of reachable services specified as domain names, IP addresses. (Yadav ¶88 and ¶149 teach using “whitelists” for reachable services on a DNS [domain names aka comprises IP addresses]).
With respect to claim 8, Yadav discloses: The software container or virtual machine of claim 7, hosting a web-based interactive development environment with whom the developer can interact through the developer's HTTPS connection. (Yadav Fig. 6 teaches author [developer] in communication using a browser to interact thought network data hosted on a virtual machine/container. Wherein the communication comprises secure HTTP as taught by Yadav ¶139).
With respect to claim 9, Yadav discloses: The software container or virtual machine of claim 7, wherein the applications include a secure web browser configured to establish secure HTTPS connexions with internet-based services, (Yadav ¶93 teaches establishing a virtual secure browser connection).
render a secure HTTPS connexion to a local monitor of the software developer and allow the developer to interact with a server at a remote end of the secure HTTPS connexion using his local mouse and keyboard, through the developer's HTTPS connexion. (Yadav Fig. 3 illustrates the browser 306 is at author/instructor end where they can interact with it locally as can be understood, at least from, Yadav ¶93).
Claims 14, 19, 21-22 and 24 recite a platform and method claims. While the claims might have slight variation in language they recite similar matter to claim 9 in view of claim 7 in view of claim 1 and therefore rejected based on the same rationale.
With respect to claim 10, Yadav discloses: The software container or virtual machine of claim 9, wherein the secure browser is configured to forbid download operations in general, or to forbid download operation from selected blacklisted URIs, or to allow download operation from selected whitelisted URIs exclusively, (Yadav ¶144 teaches using whitelisted DNS domains to allow access or block access).
Claim 23 recites a method claim. While the claim might have slight variation in language it recites similar matter to claim 10 and therefore rejected based on the same rationale.
With respect to claim 12, Yadav discloses: Network-based platform for the development of software products, configured to host a plurality of the software containers or virtual machines of claim 1. (Yadav Fig. 3 illustrates author [developer] hosted software data on VM/container interacting with browser data that is also on a VMs/Containers on network 300).
Claims 15 and 25 recite a platform and method claims. While the claims might have slight variation in language, they recite similar matter to claim 12 and therefore rejected based on the same rationale.
With respect to claim 13, Yadav discloses: The network-based platform of claim 12, wherein the credentials management is hosted by the platform and oversees to the secure HTTPS connection of a plurality of software containers. (Yadav Fig. 3 illustrates 372 is hosted by the network environment 300 to oversee connection between learner or author and the VMs/container).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 2 is/are rejected under 35 U.S.C. 103 as being unpatentable over Yadav as applied to claims 1, 3-6, 8-10, 12-15, 19, and 21-25 above, and further in view of Ylonen (US 20130117554 A1) hereinafter referred to as Ylonen.
With respect to claim 2, Yadav discloses: The software container or virtual machine of claim 1
Yadav does not explicitly disclose: public-private key pairs
However, Ylonen in an analogous art discloses: equipped with a mechanism to manage user-centric digital identities based on any authentication method, e.g. public-private key pairs, such that the user can authenticate to any service supporting the authentication method via the credential management unit. (Ylonen ¶116 teaches user public/private keys stored in virtual machine for authentication from the management system).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the virtual machine/container disclosed by Yadav to be equipped with a mechanism to manage user-centric digital identities based on any authentication method, e.g. public-private key pairs, such that the user can authenticate to any service supporting the authentication method via the credential management unit as disclosed by Ylonen to authorize certain accounts on other machines to log into the virtual machine (see Ylonen ¶116).
Claim(s) 7 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Yadav as applied to claims 1, 3-6, 8-10, 12-15, 19, and 21-25 above, and further in view of Clark et al. (US 20190109820 A1) hereinafter referred to as Clark.
With respect to claim 7, Yadav discloses: The software container or virtual machine of claim 1, configured to run applications capable of accessing the internet on ,, comprising a unit configured to intercept internet traffic and detect. (Yadav Fig. 3 (see Yadav ¶141-142) illustrates the VMs/Containers running applications comprising container orchestrator in communication with traffic analyzer 138 intercepting communication from and to the VMs/Containers).
Yadav does not explicitly disclose: predetermined TCP port.
However, Clark in an analogous art discloses: configured to run applications capable of accessing the internet on predetermined TCP ports,, comprising a unit configured to intercept internet traffic and detect and prevent exfiltration of sensitive data. (Clark ¶679 teaches virtual router and virtual machine communicating over particular source port and predetermined destination port which intercepts data flow as shown in Fig. 4 which is used in verification process for securing data such as recited in ¶673.)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the virtual machine/container disclosed by Yadav with configured to run applications capable of accessing the internet on predetermined TCP ports,, comprising a unit configured to intercept internet traffic and detect and prevent exfiltration of sensitive data as disclosed by Clark to securely transfer data on a pre-determined port (see Clark ¶679).
Claim 20 recites a method claim. While the claim might have slight variation in language it recites similar matter to claim 7 and therefore rejected based on the same rationale.
Claim(s) 11, 16 and 26 is/are rejected under 35 U.S.C. 103 as being unpatentable over Yadav as applied to claims 1, 3-6, 8-10, 12-15, 19, and 21-25 above, and further in view of Chong et al. (US 20020184610 A1) hereinafter referred to as Chong.
With respect to claim 11, Yadav discloses: The software container or virtual machine of claim 9,
Yadav does not explicitly disclose: wherein the secure browser controls the clipboard content and prevents, or conditionally prevents, pasting of data outside of the scope of the IDE, terminal or secure apps.
However, Chong in an analogous art discloses: wherein the secure browser controls the clipboard content and prevents, or conditionally prevents, pasting of data outside of the scope of the IDE, terminal or secure apps. (Chong ¶282 “The IDE 500 will receive the selection event, and will update the property sheet to show the settings for the selected object in step 1008, update the mini workflow diagram to show the selected object in a controller viewer that displays the entire diagram in steps 1010 and 1014, and update the displayed IDE buttons such as the "cut" and "copy" buttons to allow developers to delete or make copies of the selected object in step 1012.”)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the virtual machine/container disclosed by Yadav wherein the secure browser controls the clipboard content and prevents, or conditionally prevents, pasting of data outside of the scope of the IDE, terminal or secure apps as disclosed by Chong to allow secure IDE copy and paste only for allowed items (see Chong ¶282).
Claims 16 and 26 recite a platform and method claims. While the claims might have slight variation in language they recite similar matter to claim 11 and therefore rejected based on the same rationale.
Claim(s) 17-18 and 27-28 is/are rejected under 35 U.S.C. 103 as being unpatentable over Yadav as applied to claims 1, 3-6, 8-10, 12-15, 19, and 21-25 above, and further in view of Hufsmith et al. (US 20200097662 A1) hereinafter referred to as Hufsmith.
With respect to claim 17, Yadav discloses: The network-based platform of claim 14,
Yadav does not explicitly disclose the rest of the claim.
However, Hufsmith in an analogous art discloses: comprising a classifier configured to analyse the content of the clipboard and determine whether the content of the clipboard includes licensed code, access credentials, or sensitive information based on a semantic analysis, wherein the secure browser is configured to control the clipboard content and prevents pasting of data outside of the scope of the IDE, terminal and secure apps unless the clipboard content is submitted by the developer to the classifier and the classifier determines that they do not include sensitive information. (Hufsmith ¶160 “injection into the IDE via plugin to allow monitoring of Dockerfiles; parsing Dockerfiles for key words that would indicate something is being create or added to the image (from, add, copy [copying/pasting content of clipboard], etc. . . . ); performing a lookup [classifying] on existing vulnerability information [sensitive information] in CVE and CWE databases based to create annotations in the Dockerfile around potential exposures; and providing additional informational links in the annotations that allow the developer to get additional details on the exposure along with possible remediations [prevents pasting].”).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Yadav with comprising a classifier configured to analyse the content of the clipboard and determine whether the content of the clipboard includes licensed code, access credentials, or sensitive information based on a semantic analysis, wherein the secure browser is configured to control the clipboard content and prevents pasting of data outside of the scope of the IDE, terminal and secure apps unless the clipboard content is submitted by the developer to the classifier and the classifier determines that they do not include sensitive information as disclosed by Hufsmith to prevent copying/pasting of sensitive data (see Hufsmith ¶160 and 180).
With respect to claim 18, Yadav and Hufsmith disclose: The network-based platform of claim 17, wherein the classifier is configured to detect semantically significant data and reserved data including one or more of: code development information, data science, business data, source code, open-source code, personally identifiable dana, malware, access credentials, information stored in a database of sensitive information. (Hufsmith ¶160 teaches keywords classifier to detect potential exposure of different types of vulnerabilities which are mentioned in multiple paragraphs in the prior art).
Claims 27-28 recite a method claim. While the claims might have slight variation in language they recite similar matter to claim 17-18 and therefore rejected based on the same rationale.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Trabelsi et al. (US 20190372983 A1) ¶134 “the networking VM is configured to capture any attempt to access a URL, e.g., via any browser or similar application. It should be noted that in some embodiments, such attempts are captured without need for integration within a specific browser. The networking VM is further configured to check if the request is allowed on the security zone requesting to access the URL. The check may be performed against a URL whitelist or blacklist and/or based on integration with a third-party proxy.”
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HANY S GADALLA whose telephone number is (571)272-2322. The examiner can normally be reached Mon to Fri 8:00AM - 4:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at (571) 272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HANY S. GADALLA/Primary Examiner, Art Unit 2493