Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the
DETAILED ACTION
Currently pending claims are 2 – 21 (Claim 1 cancelled).
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1, 9 & 16 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention because the claim language “wherein the management domain and the one or more workload domains have no direct data path” is considered to be unclear and indefinite regrading, at least, (for example) whether a physical networking router or a network switch must be included, an authentication server must be used, and etc., between the management domain and the workload domains to assure the inventive subject matter of no direct data path, as recited in the claim – As such Examiner respectfully notes the precise metes and bound of the claim, as alleged, cannot be determined. See § MPEP 2173.05(b). Any other claims not addressed are rejected by virtue of their dependency should also be corrected.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the exclaimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 2 – 6, 9 – 13 & 16 – 20 are rejected under 35 U.S.C.103 as being unpatentable over Sridhar et al. (U.S. Patent 10,891,162), in view of Nagalla et al. (U.S. Patent 10,616,339), and in view of Warwick et al. (U.S. Patent 8,239,552).
As per claim 2, 9 & 16, Sridhar teaches a system, comprising:
a plurality of hyperconverged infrastructure (HCI) nodes, each HCI node comprising compute resources, node-local storage resources, and virtualization software executing on the compute resources, wherein the virtualization software of each HCI node is configured to instantiate and execute virtual machines on the HCI node (Sridhar: FIG. 2, Col. 2 Line 14 – 21 / Line 47 – 50, Col. 9 Line 60 – 64 / Line 42 – 46, Col. 6 Line 6 – 16 & Col. 2 Line 37 – 40: (a) using hyperconverged infrastructure (HCI) to manage network resources provided in SDDC (Software Defined Data Center(s)), wherein (b) a hypervisor, as an integral part of HCI, managing each HCI host (as a SDDC manager) within an integrated virtualization platform to instantiate the virtual resource to a virtual machine, and (c) a HCI direct attached storage constitutes a part of the node-local storage resource (Col. 6 Line 6-7));
a hyperconverged storage subsystem executed by the plurality of HCI nodes and configured to aggregate the node-local storage resources of the plurality of HCI nodes into a shared storage resource (Sridhar: see above, FIG. 1 / 2, Col. 3 Line 51 – 67 & Col. 13 Line 13 – 20: (a) a HCI-based SDDC subsystem can be deployed using virtual server rack (FIG. 1 / 2), which can be configured in many different sizes, as small as 4x hosts such that the virtual server rack that includes software defined storage can be distributed across multiple hosts and thus the HCI node-local storage resources (i.e. HCI direct attached storages: see above) can be aggregated from multiple HCI nodes into a software defined storage (i.e. a shared storage resource, a recited), wherein the shared storage resource is partitioned by a software-defined storage configuration into a management storage pool and a plurality of network-specific storage pools (Sridhar: see above, FIG. 1 / 2, Col. 4 Line 45 – 51, Col. 5 Line 20 – 38 & Col. 3 Line 51 – 67: the virtual server rack (FIG. 1) can also include a software-define data storage and storage virtualization integrated into a hypervisor that manages a management domain and a set of a workload domains such that a corresponding software-define data storage can be partitioned into two entities:
(a) a plurality of network-specific storage pools (Sridhar: Col. 5 Line 24 – 38) – a cloud computing customer can request allocations of storage resources to support services required by the customers to meet the requirements w.r.t. the on-demand network access to a shared (storage) pool of configurable computing resources (e.g., a pool of hardware resources, etc.) – e.g., when a customer requests to run one or more services in the cloud computing environment, one or more corresponding workload domains may be created based on resources in the shared storage pool of configurable computing resource; and
(b) a management storage pool (Sridhar: Col. 5 Line 20 – 24) – a management domain is a group of physical machines and VM that host core cloud infrastructure (storage) components necessitated to manage a SDDC in a cloud computing environment to support customers and security services);
a management network and one or more provisioned secure networks, each network comprising a logically separate and secure virtualized network, wherein a management domain is associated with the management network (Sridhar: see above, Col. 5 Line 20 – 23, Col. 8 Line 21 – 27 / Line 15 – 21 & Col. 15 Line 30 – 35: a management domain associated with a management network comprising a group of physical machines as well as virtual machines to manage a SDDC, wherein a cluster of a server group of a plurality of server nodes with network connectivity across multiple network links logically formulates separate virtualized networks but physically connected via network switches supported with security services) and one or more workload domains are each associated with a respective one of the one or more provisioned secure networks (Sridhar: see above & Col. 17 Line 41 – 49 & Col. 15 Line 25 – 35: creating a workload domain with a needed quantity of hosts to formulate a secure network supported with security services from a software-based virtualized networks).
However, Sridhar does not disclose expressly wherein the management domain and the one or more workload domains have no direct data.
Nagalla (& Sridhar) teaches wherein the management domain and the one or more workload domains have no direct data path (Sridhar: see above) || (Nagalla: Col. 4 Line 43 – 59: a management block can provide an out-of-band (OOB) channel (instead of direct access to any data asset of the network system) when managing and controlling the operation of the system – this is also consistent with the disclosure of the instant specification (SPEC: Para [0075] Line 5 – 12: the out-of-band management may generally refer to a solution to manage connected devices without having direct access to anything related to network and user data).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification that the management domain and the one or more workload domains have no direct data path because Nagalla teaches to alternatively, effectively and securely provide an out-of-band (OOB) channel for a management block (instead of direct access to any data asset of the network system) when managing and controlling the operation of the system (see above) within the Sridhar’s system of providing a software-define data storage in a cloud computing environment and storage virtualization which is integrated into a hypervisor that manages a management domain as well as a set of a workload domains associated a plurality of network entities and various network connectivity to support customers and security services (see above).
wherein first virtual machines instantiated by the virtualization software and assigned to the management domain are configured to access the management storage pool, and second virtual machines instantiated by the virtualization software and assigned to a workload domain are configured to access the network-specific storage pool associated with that workload domain (Sridhar: see above, Col. 4 Line 45 – 51, Col. 3 Line 62 – 66, Col. 9 Line 41 – 46, Col. 5 Line 24 – 38: providing virtualized networking software to instantiate and manage the HCI hosts associated with the corresponding management domain and the workload domain); and
one or more security policies applied by the system to control an access to the shared storage resource based on the management domain and the one or more workload domains to maintain an isolation (see Warwick below) between the management domain and the one or more workload domains (Sridhar: see above, Col. 5 Line 33 – 36, Col. 15 Line 33 – 35 & Col. 17 Line 41 – 49: the cloud storage resource are shared among a group of management domain and workload domains supported with security policies).
However, Sridhar does not disclose providing an isolation between the management domain and the one or more workload domains.
Warwick (& Sridhar) teaches providing an isolation between the management domain and the one or more workload domains (Sridhar: see above: the cloud storage resource are shared among a group of management domain and workload domains supported with security policies) || (Warwick: Col. 12 Line 41 – 63: providing an iSCSI protocol such that a set of devices of a separate access group is identified and permitted (authorized) to access only within a target that identifies the set of devices so as to prevent from accessing resource assigned to a different group).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification providing an isolation between the management domain and the one or more workload domains because Warwick teaches to alternatively, effectively and securely provide an iSCSI protocol such that a set of devices of a separate access group is identified and permitted (authorized) to access only within a target that identifies the set of devices so as to prevent from accessing resource assigned to a different group (see above) within the Sridhar’s system of providing a software-define data storage in a cloud computing environment, which is integrated into a hypervisor that manages a management domain as well as a set of a workload domains associated a plurality of network entities and various network connectivity to support customers and security services (see above).
wherein the hyperconverged storage subsystem is configured to incorporate node-local storage resources of one or more additional HCI nodes into the shared storage resource upon an addition of the one or more additional HCI nodes to the plurality of HCI nodes (Sridhar: see above & Col. 24 Line 55 – Col. 25 Line 20, Col. 2 Line 14 – 21 / Line 47 – 50, Col. 9 Line 60 – 64 / Line 42 – 46, Col. 6 Line 6 – 16 & Col. 2 Line 37 – 40: a resource allocator within the hyperconverged infrastructure (HCI) virtualization platform manages network resources based on an HCI storage solution that includes the HCI hosts and corresponding HCI storage to provide a new solution requirements as needed to be satisfied when the resource allocator determines that the HCI storage solution has not been identified – e.g. a new (additional) HCI node / storage (Sridhar: Col. 24 Line 55 – Col. 25 Line 20), wherein a HCI direct attached storage constitutes a part of the node-local storage resource (Sridhar: Col. 6 Line 6-7)), and
wherein the software-defined storage configuration continues to enforce the one or more security policies for the management storage pool and each network-specific storage pool after incorporating the one or more additional HCI nodes to maintain the isolation between the management domain and the one or more workload domains as the shared storage (Sridhar || Warwick: see above).
As per claim 3, 10 & 17, Sridhar as modified teaches partitioning data associated with the shared storage resource into blocks and distribute the blocks across storage devices of the plurality of HCI nodes using erasure coding or a data protection scheme, and wherein the one or more security policies are applied to ensure that data separation between the management domain and the one or more workload domains is maintained (Sridhar: see above || Warwick: see above & Col. 12 Line 41 – 63).
As per claim 4, 11 & 18, Sridhar as modified teaches wherein the management network comprises one or more of the plurality of HCI nodes dedicated to a management plane, the management network maintaining management-specific volumes and management-specific datastores exclusively accessible by management plane computing resources (Sridhar: see above, Col. 5 Line 20 – 23, Col. 8 Line 21 – 27 / Line 15 – 21 & Col. 15 Line 30 – 35: a management domain associated with a management network comprising a group of physical machines as well as virtual machines to manage a SDDC, wherein a cluster of a server group of a plurality of server nodes with network connectivity via multiple network links of to formulate logically separate virtualized network but physically connected via network switches support with security services) || (Warwick: see above & Col. 12 Line 41 – 63: providing an iSCSI protocol such that a set of devices of a separate access group is identified and permitted (authorized) to access only within a target that identifies the set of devices so as to prevent from accessing resource assigned to a different group).
As per claim 5 – 6, 12 – 13 & 19 – 20, Sridhar as modified teaches wherein the shared storage resource is accessible via an Internet small computer systems interface (iSCSI) protocol, and wherein the one or more security policies are enforced to control iSCSI-based access to the shared storage resource based on the management domain and the one or more workload domains (Sridhar: see above) || (Warwick: see above & Col. 12 Line 41 – 63: providing an iSCSI protocol such that a set of devices of a separate access group is identified and permitted (authorized) to access only within a target that identifies the set of devices so as to prevent from accessing resource assigned to a different group).
Claims 7 – 8, 14, 15 & 21 are rejected under 35 U.S.C.103 as being unpatentable over Sridhar et al. (U.S. Patent 10,891,162), in view of Nagalla et al. (U.S. Patent 10,616,339), and in view of Warwick et al. (U.S. Patent 8,239,552), and in view of Kisel et al. (EP 215-0019 @ 3-2-2010).
As per claim 7 – 8, 14, 15 & 21, Kisel (& Sridhar as modified) teaches (a) wherein the authentication credential comprises a bidirectional challenge handshake authentication protocol (CHAP) secret, and wherein each host access group is configured with a different bidirectional CHAP secret to authenticate iSCSI connections and to enforce separation between the management domain and the one or more workload domains, wherein (b) the authentication credentials (of a separate domain) are applied to iSCSI initiators (Sridhar: see above, Col. 5 Line 20 – 23, Col. 8 Line 21 – 27 / Line 15 – 21 & Col. 15 Line 30 – 35: a management domain associated with a management network comprising a group of physical machines as well as virtual machines to manage a SDDC) || (Warwick: see above) ||
(Kisel: Para [0016] / [0015] & Para [0032] Line 9 – 12: providing an iSCSI / CHAP challenge- response authentication protocol along with a CHAP secret (i.e. credential), which is used in accessing resource restricted to only the member of a particular group that holds the specific CHAP secret (i.e. credential) for authentication).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification providing the authentication credential comprising a bidirectional challenge handshake authentication protocol (CHAP) secret because Kisel teaches to alternatively, effectively and securely provide a iSCSI / CHAP challenge- response authentication protocol along with a CHAP secret (i.e. credential), which is used in accessing resource restricted to only the member of a particular group that holds the specific CHAP secret (i.e. credential) for authentication (see above) within the Sridhar’s system of providing a software-define data storage in a cloud computing environment, which is integrated into a hypervisor that manages a management domain as well as a set of a workload domains associated a plurality of network entities and various network connectivity to support customers and security services (see above).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LONGBIT CHAI whose telephone number is (571)272-3788. The examiner can normally be reached Monday - Friday 9:00am-5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D. Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
---------------------------------------------------
/Longbit Chai/
Longbit Chai E.E. Ph.D.
Primary Examiner, Art Unit 2431
No. #2565 – 2026 ---------------------------------------------------