Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 6/19/2026 have been fully considered, and they are partially persuasive. The 6/25/2026 Terminal Disclaimer has been entered, as the previously made Double Patenting rejection has responsively been withdrawn. The rejections made under 35 USC 112 have also been withdrawn responsive to the presently entered claim amendments. Regarding the rejections made under 35 USC 102, Applicant’s arguments cannot be held as persuasive. On page 9, arguing the 35 USC 102 rejections made in view of Miriyala, Applicant argues that “the cited portions of Miriyala do not disclose that the ‘access policy controller’ . . . receives ‘a request . . . to create an access control policy…” and “also executes the ‘one or more functions in [the] network system”. In response, the Examiner notes that claim 1 is directed to a “network controller” claimed as comprising “a server”. This controller comprising a server is mapped to the Miriyala’s “SND controller 132 [that] includes access policy controller 23 that may generate the access control policy”, which is noted to contain/be executed by “processing circuitry of a network device such as one or more servers 12” (Miriyala, [74]). Thus the combined access policy controller and SDN controller, with the included server execution functionality, are mapped to the “network controller” of claim 1. The “execute the one o4r more functions” language is show via the creation of “the policy between one more networks”, which Miriyala notes in [42] is performed by the SDN Controller 132. Miriyala continues in [50-51] to note that “SDN controller 132 may direct components . . . to perform the functions specified” via, e.g., executing API calls. Applicant’s arguments on page 9 thus cannot be held as persuasive. Continuing on page 9, Applicant argues that Miriyala does not show a server that logs “execution of the one or more functions in an audit log”. Applicant’s argument cannot be held as persuasive. Miriyala, e.g., in [50] and [53] discusses to “determine the one or more operations performed” via generation of “records or logs”. Multiple references to log generation are provided throughout Miriyala, including [53-55] and [77-78]. Concluding on page 9 and continuing to page 10, Applicant argues that Miriyala fails to show the amended claim language directed to a “request specifying one or more functions of an interference provided by the server”. In response, the Examiner notes the claimed request is discussed in [34,39-41,48] of Miriyala, as well as, e.g., [50-51] which discusses where an reception of “one or more functions specified by an administrator”. As [50-51] notes, these functions may be achieved via execution of an API (application programming interface). [44] of Miriyala explains that the SDN controller (part of the claimed “network controller” of claim 1) implements an API server, and thus “provides” the interface as claimed. Thus, responsive to the amended claim language, the rejections made utilizing Miriyala have been updated. However, given the modified citations to Miriyala address the amended language, Applicant’s arguments cannot be held as persuasive.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1, 3, 4, 6, 10, 11, 13, 14, 16, and 20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Miriyala (US-20210306338-A1). Regarding claim 1, Miriyala shows a network controller ([74] discussing a combined SDN controller and access policy controller, which is claimed as including server functionality) comprising: processing circuitry ([74, 86-88]); and a server (Fig. 1, see items 23 and 132; as [74] notes, these two controller can be implemented as part of a single server) to process one or more requests for operations on one or more resources of a container orchestration system, wherein the server is configured for execution by the processing circuitry to ([86-88]): obtain a request ([39,48], see “send a request to access policy controller. . .”) to generate an access control policy for a role ([45], see “specify a role”) in the container orchestration system ([15] and Fig. 1 item 130), the request specifying one or more functions of an interface provided by the server ([33] discussing “API access lists”, [40] discussing “one or more operations to be performed” and [41] discussing an administrator providing input to “specify one or more functions”; note that [50-51,44] discusses implementation of the functions via API calls, where SDN controller includes an API server); execute the one or more functions ([50-51] to note that “SDN controller 132 may direct components . . . to perform the functions specified” via, e.g., executing API calls); log execution of the one or more functions in an audit log ([50] and [53] discussing to “determine the one or more operations performed” via generation of “records or logs”; further discussion provided in [53-55] and [77-78]); parse the audit log ([53-56]) to determine a resource of the container orchestration system ([15]) to be accessed from executing the one or more functions and one or more types of operations to be performed on the resource from executing the one or more functions ([50-54], e.g., see [53] reciting to “record or log the function specified by administrator 24, every object on which at least one operation is performed. . .”); and create, based at least in part on the parsed audit log ([50,53-56]), the access control policy for the role that permits access for the one or more types of operations to be performed on the resource ([40,79], see, e.g., [40] reciting to “generate an access control policy for the role that permits the associated role to perform the one or more operations on the one or more objects”).
Regarding claim 3, Miriyala further shows wherein to log the execution of the one or more functions of the audit log, the server is further configured to: record, for each function of the one or more functions in the audit log from executing the one or more functions, an event that indicates one or more resources accessed by executing the function and a respective one or more types of operations performed on each of the one or more resources by executing the function ([62]).
Regarding claim 4, Miriyala further shows the network controller of claim 1, wherein to parse the audit log, the server is further configured to: filter the audit log based at least in part ([60], see “determine the relevant . . .”) on timestamps of events recorded in the data ([56,60-62,78]).
Regarding claim 6, Miriyala further shows the network controller of claim 1, wherein to parse the audit log, the server is further configured to: determine, based on the audit log ([60-61] discussing “one or more logs”), an association between each of the one or more resources ([61-62] discussing a targeted object) of the container orchestration system ([15]) and the one or more types of operations ([62] noting the particular CRUD operation).
Regarding claim 10, Miriyala further shows the network controller of claim 1, wherein each of the respective one or more operations include one or more of create, read, update, and delete (CRUD) operations ([42,78]). Regarding claims 11 and 20, the limitations of said claims are rejected in the analysis of claim 1.
Regarding claim 13, the limitations of said claim are rejected in the analysis of claim 3.
Regarding claim 14, the limitations of said claim are rejected in the analysis of claim 4.
Regarding claim 16, the limitations of said claim are rejected in the analysis of claim 6.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary kill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 2 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Miriyala in view of Ghare (US-20200159648-A1).
Regarding claim 2, Miriyala shows the network controller of claim 1, wherein to execute the one or more functions, the server is further configured for to: perform a first respective one or more operations indicated by the one or more functions on each of a first one or more resources indicated by the one or more functions ([51-55], e.g., [55] discussing tracking indications of each of the one or more operations performed); determine, based at least in part on the first respective one or more operations to be performed on each of the first one or more resources, a second respective one or more operations to be performed on each of a second one or more resources ([51-55]); perform the second respective one or more operations on each of the second one or more resources ([62]); andlog performance of the first respective one or more operations and performance of the second respective one or more operations in the data from executing the one or more functions ([62]). Miriyala does not show monitoring operations that are not indicated by the one or more functions. Ghare shows monitoring operations that are not indicated by the one or more functions ([53], discussing monitoring performance of application execution and tracking if an unexpected action was performed).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Miriyala with the performance tracking of Ghare in order to ensure unintended and/or unexpected actions are noted and thus ensure that the evaluated policy/application execution is resulting in the intended behavior in the controlled system, thus better ensuring reliable and consistent operation.
Regarding claim 12, the limitations of said claim are rejected in the analysis of claim 2.
Claims 5 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Miriyala in view of Parthasarathy (US-11599288-B2).
Regarding claim 5, Miriyala shows filtering the audit log based at least in part on events recorded in the data ([56,60-62,78]). Miriyala does not show filtering based on namespaces. Parthasarathy shows filtering based on namespaces (col. 8 lines 5-35).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Miriyala with the namespace awareness of Parthasarathy in order to ensure strong data isolation is tracked and maintained, better ensuring the resultant system has the desired privacy and data protections.
Regarding claim 15, the limitations of said claim are rejected in the analysis of claim 5.
Claims 7 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Miriyala in view of Bhatti (US-20130326579-A1).
Regarding claim 7, Miriyala shows claim 1.
Miriyala does not show to: validate the access control policy for the role based at least in part by comparing the access control policy for the role to a pre-configured access control policy for the role. Bhatti shows to: validate the access control policy for the role based at least in part by comparing the access control policy for the role ([56]) to a pre-configured (Fig. 1) access control policy ([11,14,19,59]) for the role ([56]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Miriyala with the policy tracking and validation of Bhatti in order to ensure sufficient data protection while lowering administrative overhead (Bhatti, [4-8]).
Regarding claim 17, the limitations of said claim are rejected in the analysis of claim 7.
Claims 8 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Miriyala in view of Liu (US-20220321495-A1).
Regarding claim 8, Miriyala shows claim 1, including wherein the one or more functions include one or more requests for operations on one or more instances of resources for software-defined networking (SDN) architecture configuration ([73-75]), wherein each of the resources for SDN architecture configuration corresponds to a type of configuration object ([33]) in a SDN architecture system ([77]). Miriyala does not show consideration and evaluation of custom resources. Liu shows consideration and evaluation of custom resources ([22,27]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Miriyala with the containerized, SDN-based awareness of Liu in order to ensure data relevant to the particular implementation environment is sufficiently tracked and evaluated when the resultant role-based permission evaluations are performed.
Regarding claim 18, the limitations of said claim are rejected in the analysis of claim 8.
Claims 9 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Miriyala in view of Cao (US-20220019455-A1) and Liu.
Regarding claim 9, Miriyala shows wherein the server includes ([74]) an application programming interface (API) server to process requests for operations ([75]) on resources of the container orchestration system ([15]) and a server to process requests for operations on resources for software-defined networking (SDN) architecture configuration ([74-75]), Miriyala does not show consideration and use of a custom API server. Cao shows consideration and use of a custom API server ([47-48]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Miriyala with the API-server evaluation of Cao in order to methods and frameworks utilized in the resultant implementation environment are properly evaluated, ensuring the correct role-based policy evaluations are fully performed and analyzed. The above combination does not show consideration and evaluation of custom resources, and wherein the one or more functions include requests for operations on instances of one or more native resources of the container orchestration system. Liu shows show consideration and evaluation of custom resources ([22,27]) and wherein the one or more functions include requests for operations on instances of one or more native resources (e.g., Kubernetes resources and discussed in Figs. 3-5) of the container orchestration system (e.g., Kubernetes, see noted Figs. 3 – 5 and the discussion of intent-based request evaluation when monitoring API function invocations as discussed in [24,27-28]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the above combination in order to improve operations tracking in popular deployment environments such as Kubernetes (Liu, [2-4]).
Regarding claim 19, the limitations of said claim are rejected in the analysis of claim 9.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOHN M MACILWINEN whose telephone number is (571)272-9686. The examiner can normally be reached Monday - Friday, 9:00 - 5:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Glenton B Burgess can be reached at (571) 272 - 3949. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
JOHN MACILWINEN
Primary Examiner
Art Unit 2442
/JOHN M MACILWINEN/ Primary Examiner, Art Unit 2454