Detailed Action
1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is the initial office action based on the application filed on September 10th, 2024, which claims 1-20 have been presented for examination.
Status of Claims
2. Claims 1-20 are pending in the application, of which claims 1, 11 and 20 are in independent form and these claims (1-20) are subject to following rejection(s) and/or objection(s) set forth in the following Office Action below.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
3. Per claim 20, even though claim 20 recites “A non-transient computer readable medium having stored thereon instructions that cause a processor to execute a method”, which appears to be a subject matters eligible claim; however, a non-transient media does not exclude electro-magnetic signal; for an example, a continuous radio transmission can be described as a non-transient electromagnetic signal as it continuous for extended period of time. Accordingly, a medium that persists in electromagnetic signal or wave does not qualify for patent protection. On the other hands, a “non-transitory” computer readable media designed to exclude signals and/or electromagnetic wave. Products such as a computer-readable medium which contains transitory propagating signals per se are non-statutory. As such, the claimed "computer readable medium" falls outside the four statutory categories of invention. Accordingly, this claim is ineligible for patent protection under 35 U.S.C. § 101. See MPEP § 2106. Appropriate modification or amendment to the subjected claim is anticipated.
ALLOWABLE DEPENDENT CLAIMS
4. Claims 4 and 14 are objected to as being dependent upon respective rejected base claims but would be allowable if rewritten in independent form including all of the limitations of the base claims and any intervening claim(s). However, if the claims 4 and 14 are amended; unless necessitated by the other rejections or objections provided in this office action; and/or, any of the currently pending claims are shortened or broaden, and if any new claim(s) are added the office may have right to withdraw the indication of this Allowability provided herewith by this office action.
Claim Rejections – 35 USC §103
5. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
6. Claims 1-3, 5-13 and 15-20 are rejected under 35 U.S.C. 103 as being unpatentable over Das et al. (US 2025/0030719 A1 herein after Das) in view of Bharti et al. (US 2018/0285080 A1 herein after Bharti), and further in view of Simone Nicolo (US 9,280,442 B1 here in after Nicolo).
Per claim 1:
Das discloses:
A system (At least see At least see FIG. 1, a system for automated maintenance of SMOM) comprising:
a microprocessor (At least see FIG. 7[Wingdings font/0xE0]701 with associated text); and
a computer readable medium, coupled with the microprocessor and comprising microprocessor readable and executable instructions that, when executed by the microprocessor At least see FIG. 7[Wingdings font/0xE0]707[Wingdings font/0xE0]701 with associated text), cause the microprocessor to:
determine that a software application is one of being installed in an installation environment or executed in an execution environment (At least see [0013] Proliferation of software components installed on devices poses a logistical challenge for maintaining security due to frequent installations and version updates of software components);
in response to determining that the software application is one of being installed in the installation environment or executed in the execution environment, retrieve a Tested Software Bill-of-Materials (TSBOM) of the software application (At least see [0021] -generate SBOM files for one or more devices, the SBOM file generator 107 queries the device database 112 for entries of each device corresponding to each designated SBOM file), wherein the TSBOM of the software application is a list of tested software components (At least see [0067] -query can comprise a regular expression that indicates one or more lists of software component identifiers in the filtered identifiers and one or more ranges of software component versions including software component versions indicated in the filtered identifiers).
Das sufficiently discloses the system as set forth above, but Das does not explicitly disclose: wherein a tested software component is executed during testing of the software application;
determine that software components in the installation environment or in the execution environment matches the list of tested software components; and in response to determining that at least one of the software components in the installation environment or in the execution environment does not match the tested software components in the list of tested software components, generate a notification indicating that the at least one of the software components in the installation environment or in the execution environment does not match the installation environment or the execution environment.
However, Bharti discloses:
wherein a tested software component is executed during testing of the software application (At least see Abstract: -code is executed and a resulting a list of validated software applications is generated; also see [0003] - short listed software applications have been verified via a sampling software test determined by feature translation learning code associated with each the required feature being executed);
determine that software components in the installation environment or in the execution environment matches the list of tested software components (At least see [0003] - a list of currently available software applications of the set of pre-tested software applications).
It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to incorporate Bharti into Das’s invention because Bharti’s teaching would provide Das to generate executable code associated with the software operational solution in order to validate the software application with respect to improving an efficiency and accuracy of the validated software application as well allow to generate sampling software code enabling the hardware device to execute self-learning software code with respect to a plurality of database systems based on software based solutions (please see [0020]).
Das modified by Bharti sufficiently discloses the system as set forth above, but Das modified by Bharti does not explicitly disclose: in response to determining that at least one of the software components in the installation environment or in the execution environment does not match the tested software components in the list of tested software components, generate a notification indicating that the at least one of the software components in the installation environment or in the execution environment does not match the installation environment or the execution environment.
However, Nicolo discloses:
in response to determining that at least one of the software components in the installation environment or in the execution environment does not match the tested software components in the list of tested software components, generate a notification indicating that the at least one of the software components in the installation environment or in the execution environment does not match the installation environment or the execution environment (At least see Col. 2:35-42 - a unit test generator module may be configured to read the plurality comments sections, to parse the plurality of comments sections, and extract an identification of each source code unit from the plurality of comments sections. Also, a report module may be configured to compare the identification to a list of tested source code units and add the comparison to a unit test coverage report).
It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to incorporate Nicolo into Das modified by Bharti’s invention because each source code unit corresponds to one of a plurality of comments sections, and processor to parse the plurality of comments sections and extract an identification of each source code unit from the plurality of comments sections, while comments section includes text that is ignored by source code compilers and interpreters, but may provide useful information to developers who edit, optimize, or use the source code; therefore, information in the comments portions may make the source code easier to understand for developers to write other code that is compatible with the source code (please see Col. 3:49-67 through Col. 4:1-7).
Per claim 2:
Das also discloses:
wherein the software application is being installed in the installation environment (At least see [0013] - automated tracking of software components installed on IoT devices ).
Per claim 3:
Nicolo discloses:
wherein the software application is being executed in the execution environment (At least see Col. 8:6-8 - TestUp module 114 may generally provide an environment in which all units of the source code 104 are properly tested).
It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to incorporate Nicolo into Das modified by Bharti’s invention because each source code unit corresponds to one of a plurality of comments sections, and processor to parse the plurality of comments sections and extract an identification of each source code unit from the plurality of comments sections, while comments section includes text that is ignored by source code compilers and interpreters, but may provide useful information to developers who edit, optimize, or use the source code; therefore, information in the comments portions may make the source code easier to understand for developers to write other code that is compatible with the source code (please see Col. 3:49-67 through Col. 4:1-7).
Per claim 5:
Das also discloses:
wherein the TSBOM comprises a first tested software component that comprises multiple tested versions of the first tested software component (At least see [0023] - vulnerability database 110 can comprise the CVE database and each query can comprise a regular expression specifying ranges of software components and software component versions for software components indicated the device software component data).
Per claim 6:
Das also discloses:
wherein retrieving the TSBOM comprises retrieving the TSBOM from a library of TSBOMs on a network and wherein the TSBOM in the library of TSBMOs is updated when one or more of the tested software components have been tested with a new version of the one or more tested software components (At least see [0070] At block 607, the system updates entry in a SBOM database and/or a device database for the current device with indications of the vulnerability (ies) returned for the current device. An “entry” as used in reference to the SBOM database refers to an SBOM file for the current device. The system can update the entry in the device and/or SBOM database with identifiers of the one or more returned vulnerabilities as well as indicators of associated risk level (e.g., low, medium high), malicious attack types, threat stages, etc).
Per claim 7:
Das also discloses:
wherein an installer, loader, linker, or interpreter gets the TSBOM from the library of TSBOMs on the network when determining that the software application is being executed in the execution environment (At least see [0013] Proliferation of software components installed on devices poses a logistical challenge for maintaining security due to frequent installations and version updates of software components. This challenge is amplified for Internet of Things (IoT) devices that often act as black boxes with little outgoing data regarding executing software components and without security agents to monitor security natively).
Per claim 8:
Das also discloses:
wherein the TSBOM is stored in a blockchain for the library of TSBOMs (At least see [0059}-one or more devices for which SBOM files will be generated. In other instances, the trigger indicates to generate/update SBOM files for each device for which filtered identifiers have been stored in the device database over a previous time period (e.g., according to a daily schedule). If there is a trigger detected for updating the SBOM database, operational flow proceeds to block).
Per claim 9:
Das also discloses:
wherein a block is added to the blockchain when the TSBOM is updated with the new version of the one or more tested software components (At least see [0067] - updating software vulnerabilities for software components of devices based on filtered identifiers. At block 601, the system queries a vulnerability database for indications of vulnerabilities based on filtered identifiers).
Per claim 10:
Das also discloses:
wherein the notification indicating that the at least one of the tested software components does not match the installation environment or the execution environment is at least one of: displayed in a user interface, used to block installation of the software application, and used to block execution of the of the software application (At least see [0013] - Internet of Things (IoT) devices that often act as black boxes with little outgoing data regarding executing software components and without security agents to monitor security natively. Systems monitoring security on IoT devices may not receive current software component/component version data to populate SBOM files because this data is sometimes not provided by device vendors).
Per claim 11:
Limitations in this independent claim are as similar as claim 1 above; and therefore, rejected based on same rational.
Per claim 12:
Limitations in this dependent claim are as similar as claim 2 above; and therefore, rejected based on same rational.
Per claim 13:
Limitations in this dependent claim are as similar as claim 3 above; and therefore, rejected based on same rational.
Per claim 15:
Limitations in this dependent claim are as similar as claim 5 above; and therefore, rejected based on same rational.
Per claim 16:
Limitations in this dependent claim are as similar as claim 6 above; and therefore, rejected based on same rational.
Per claim 17:
Limitations in this dependent claim are as similar as claim 7 above; and therefore, rejected based on same rational.
Per claim 18:
Limitations in this dependent claim are as similar as claim 8 above; and therefore, rejected based on same rational.
Per claim 19:
Limitations in this dependent claim are as similar as claim 10 above; and therefore, rejected based on same rational.
Per claim 20:
Limitations in this independent claim are as similar as claim 1 above; and therefore, rejected based on same rational.
CONCLUSION
7. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZIAUL A. CHOWDHURY whose telephone number is (571)270-7750. The examiner can normally be reached on 9:30PM 6:30PM Monday -Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Hyung S. Sough can be reached on 571-272-6799. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Status information for published applications may be obtained from Patent Public Search tool (for all users) – A link to the Patent Public Search Tool is available at www. Uspto.gov/PatentPublicSearch. To find a U.S. patent or U.S. patent application publication, open the Patent Public Search tool by selecting “Start search”. Type the U.S. patent or U.S. patent application publication number in the “Search” panel without any punctuation and followed by an”.pn.”.
Should you have questions on access to the system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ZIAUL A CHOWDHURY/ Primary Examiner, Art Unit 2192