DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 12/04/2025 & 02/03/2025 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-6 are rejected under 35 U.S.C 103 as being unpatentable over Sivaswamy et al. (US 2023/0188531), hereon referred to as Siv, in view of Miriyala et al. (US 2023/0104568), and hereon referred to as Miri.
In regards to claims 13, 20 & 23, Siv discloses acquiring an access permission policy of a first cluster; the access permission policy including access permission information between the first cluster and one or more second clusters associated therewith (The first dependency chain matrix 250 may be a dependency chain matrix which compiles, converges, aggregates or otherwise puts together the service matrices provided to the first ingress computer system 16 for the first cluster; Paragraphs 0025-0030); managing the access permission between the first cluster and the second cluster associated therewith by using the updated access permission policy (looking up, by the one or more processors of the computer system, in the inter cluster label matrix in response to an inter cluster service request received that requests a service in the different cluster, and a step 460 of validating, by the one or more processors of the computer system, an inter cluster authorization for the inter cluster service request based on the inter cluster label matrix; Paragraphs 0040-0045).
However, Siv does not disclose updating, in a case where it is monitored that resources of any of the associated second clusters have changed, the access permission information corresponding to the second cluster that is included in the access permission policy in accordance with a change result of the resources of the second cluster. In an analogous art Miri discloses updating, in a case where it is monitored that resources of any of the associated second clusters have changed, the access permission information corresponding to the second cluster that is included in the access permission policy in accordance with a change result of the resources of the second cluster ( SDN controller manager 303-1 watches API server 300-1 of workload cluster 930-1 for changes on native resources of the orchestration platform for workload cluster 930-1. SDN controller manager 303-1 also watches custom API server 301 for central cluster 902. This is known as a “double watch”; Paragraphs 0280-0290).
At the time before the effective filing date of the invention, it would have been obvious to the one with ordinary skill in the art to combine the teachings disclosed by Siv, with the teachings disclosed by Miri regarding updating, in a case where it is monitored that resources of any of the associated second clusters have changed, the access permission information corresponding to the second cluster that is included in the access permission policy in accordance with a change result of the resources of the second cluster. The suggestion/motivation of the combination would have been to provide additional security in cloud native networking (Miri; Paragraph 0002).
In regards to claims 14 & 21, Siv discloses updating, in a case where it is monitored that resources of the first cluster have changed, the access permission information corresponding to the first cluster that is included in the access permission policy in accordance with a change result of the resources of the first cluster; managing the access permission between the first cluster and the second cluster associated therewith by using the updated access permission policy (the receiving module 61 may be configured to receive an updated dependency chain matrix from service endpoints based on triggering events; an updated dependency chain matrix from one of the plurality of service end points when a triggering event occurs. For example, the triggering event may be that the one of the plurality of service end points restarts, or that there is a change in service end points hosted by the one of the plurality of service end points; Paragraphs 0034-0042).
In regards to claim 15, Miri discloses adding an annotation including a cluster identifier of the second cluster to the access permission information corresponding to the second cluster; indicating a case where the resources of the second cluster have changed by means of the cluster identifier included in the annotation, so as to limit the access permission of the first cluster to access the second cluster by combining the access permission policy with the annotation in a case where the first cluster accesses the second cluster (Custom resources may have namespace scope for different clusters. Custom resources that are associated with one of workload clusters 930 will have a corresponding namespace created in central cluster 902 along with a cluster identifier (e.g., cluster name or a unique identifier), with custom resources created under this namespace; SDN controller managers 303 validate and allow users or agents to only use custom resources for SDN architecture configuration that belong to a namespace that is associated with the workload cluster; Paragraphs 0199; 0285-0290).
In regards to claim 16, Miri discloses acquiring configuration information of the first cluster; determining cluster information of the one or more second clusters associated with the first cluster in accordance with the configuration information; acquiring preset access permission information between the first cluster and the one or more second clusters, and generating the access permission policy of the first cluster based on the preset access permission information ( LCM will pick up the custom resource name for the corresponding SDN controller manager 303 as the cluster name for a workload cluster; Paragraphs 0287-0308).
In regards to claim 17, Miri discloses parsing the preset access permission information from a preset configuration file, and/or parsing the preset access permission information from custom permission data included in the first cluster, wherein the custom permission data is obtained based on extension of native permission data of the cluster (configuration resources also include custom resources, which are used to extend the Kubernetes platform by defining an application program interface (API) that may not be available in a default installation of the Kubernetes platform; Paragraphs 0101; 0323).
In regards to claim 18, Siv discloses performing the steps of acquiring the access permission policy of the first cluster and updating the access permission policy by using the permission controller (the ingress computer system 16 may include a module structure 60 that includes a receiving module 61, a converging module 62, and a sharing module 63, a validating module 64, and a label generating module 65; Paragraphs 0030-0035).
In regards to claim 19, Miri discloses starting a first controller and a second controller for the first cluster to which the permission controller belongs by using the permission controller; monitoring a resource change of the first cluster by using the first controller; monitoring a resource change of the one or more second clusters associated with the first cluster by using the second controller (SDN controller manager 303-1 watches API server 300-1 of workload cluster 930-1 for changes on native resources of the orchestration platform for workload cluster 930-1. SDN controller manager 303-1 also watches custom API server 301 for central cluster 902. This is known as a “double watch”.; Paragraphs 0280-0230).
In regards to claim 22, Siv discloses a plurality of communicatively connected clusters; wherein the apparatus is configured in the plurality of communicatively connected clusters (The ingress computer system 16 is shown connected via the network(s) 50 to the external user 26 and the external service 28, as well as other clusters; Paragraphs 0031).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHARIF E ULLAH whose telephone number is (571)272-5453. The examiner can normally be reached Mon-Fri 7:00-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHARIF E ULLAH/Primary Examiner, Art Unit 2495