DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) - 706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1-20 are rejected on the ground of nonstatutory Obviousness-Type double patenting as being unpatentable over claims 1-20 of Patent No. 10,419,494. Although the claims at issue are not identical, they are not patentably distinct from each other because the subject matter claimed in the claim(s) of the instant application is fully disclosed and covered by the (co-pending) Application 17/147941.
“A later patent claim is not patentably distinct from an earlier patent claim if the later claim is obvious over, or anticipated by, the earlier claim. In re Longi, 759 F.2d at 896, 225 USPQ at 651 (affirming a holding of obviousness-type double patenting because the claims at issue were obvious over claims in four prior art patents); In re Berg, 140 F.3d at 1437, 46 USPQ2d at 1233 (Fed. Cir. 1998) (affirming a holding of obviousness-type double patenting where a patent application claim to a genus is anticipated by a patent claim to a species within that genus). “ELI LILLY AND COMPANY v BARR LABORATORIES, INC., United States Court of Appeals for the Federal Circuit, ON PETITION FOR REHEARING EN BANC (DECIDED: May 30, 2001).
18,883,856
18/430355 (12,099,615)
1. A system for container image deduplication in asset management, the system comprising:
at least one memory configured to store instructions; and
at least one processor configured to execute the instructions to perform operations, wherein the operations include:
obtain source data from at least one source, wherein the source data includes a plurality of assets;
extract data bits for each asset from the source data;
determine a first asset concerns a first container image based on the data bits for the first asset;
in response to determining the first asset concerns the first container image, obtain a container image dataset,
wherein the container image dataset includes a plurality of sets of values for identification fields,
each of the plurality of sets of values respectively correspond to a container image assets of a plurality of container image assets, and
the identification fields include, at least, a repository identifier field and a hash field;
determine whether the data bits match any of the plurality of sets of values;
based on a match result, generate or update records for the first container image;
based on the generated or updated records for the first container image, determine a status from a first time period to a second time period; and
cause a management graphical user interface to be displayed to a user, wherein the management graphical user interface displays the status from the first time period to the second time period.
1. A system for container image deduplication in asset and vulnerability management, the system comprising:
at least one memory configured to store instructions; and
at least one processor configured to execute the instructions to perform operations, wherein the operations include:
obtain source data from at least one source, wherein the source data includes a plurality of assets and/or findings;
extract data bits for each asset or finding from the source data;
determine a first asset or finding concerns a first container image based on the data bits for the first asset or finding;
in response to determining the first asset or finding concerns the first container image, obtain a container image dataset,
wherein the container image dataset includes a plurality of sets of values for identification fields,
each of the plurality of sets of values respectively correspond to a container image assets of a plurality of container image assets, and
the identification fields include, at least, a repository identifier field and a hash field;
determine whether the data bits match any of the plurality of sets of values;
based on a match result, generate or update records for the first container image;
based on the generated or updated records for the first container image, determine a vulnerability status from a first time period to a second time period; and
cause a management graphical user interface to be displayed to a user, wherein the management graphical user interface displays the vulnerability status from the first time period to the second time period.
2. The system of claim 1, wherein, to extract the data bits for each asset from the source data, the operations further include: determine a type of source; determine a source model based on the type of source; extract, for each asset, the data bits for the asset using the source model; and map the extracted data bits in a defined format for recall.
2. The system of claim 1, wherein, to extract the data bits for each asset or finding from the source data, the operations further include: determine a type of source; determine a source model based on the type of source; extract, for each asset or finding, the data bits for the finding using the source model; and map the extracted data bits in a defined format for recall.
3. The system of claim 1, wherein the hash field stores a container image digest or a container image id.
3. The system of claim 1, wherein the hash field stores a container image digest or a container image id.
4. The system of claim 3, wherein the container image digest is a hash of a manifest file for the first container image.
4. The system of claim 3, wherein the container image digest is a hash of a manifest file for the first container image.
5. The system of claim 3, wherein the container image id is a hash of a configuration file for the first container image.
5. The system of claim 3, wherein the container image id is a hash of a configuration file for the first container image.
6. The system of claim 1, wherein the hash field is a first hash field, and the identification fields further includes a second hash field.
6. The system of claim 1, wherein the hash field is a first hash field, and the identification fields further includes a second hash field.
7. The system of claim 6, wherein the first hash field stores a container image digest, and the second hash field stores a container image id.
7. The system of claim 6, wherein the first hash field stores a container image digest, and the second hash field stores a container image id.
8. The system of claim 6, wherein, to determine whether the data bits match any of the plurality of sets of values, the operations further include: determine whether the data bits include a repository identifier value, and at least one of: a first hash value for the first hash field or a second hash value for the second hash field.
8. The system of claim 6, wherein, to determine whether the data bits match any of the plurality of sets of values, the operations further include: determine whether the data bits include a repository identifier value, and at least one of: a first hash value for the first hash field or a second hash value for the second hash field.
9. The system of claim 8, wherein the operations further include, in response to determining the data bits do include the repository identifier value and at least one of the first hash value or the second hash value, determine whether a first match condition is satisfied.
9. The system of claim 8, wherein the operations further include, in response to determining the data bits do include the repository identifier value and at least one of the first hash value or the second hash value, determine whether a first match condition is satisfied.
10. The system of claim 9, wherein the first match condition is satisfied when a set of values, of the plurality of sets of values for identification fields, match (a) the repository identifier value and the first hash value, (b) the repository identifier value and the second hash value, or (c) the repository identifier value, the first hash value, and the second hash value.
10. The system of claim 9, wherein the first match condition is satisfied when a set of values, of the plurality of sets of values for identification fields, match (a) the repository identifier value and the first hash value, (b) the repository identifier value and the second hash value, or (c) the repository identifier value, the first hash value, and the second hash value.
11. The system of claim 10, wherein, in a case that (a) or (b) is matched, the operations further include: update an asset record for the first container image with an omitted value using the first hash value or the second hash value.
11. The system of claim 10, wherein, in a case that (a) or (b) is matched, the operations further include: update an asset record for the first container image with an omitted value using the first hash value or the second hash value.
12. The system of claim 10, wherein, in a case that a container image digest value matches but a container image id does not match, the operations further include: overwrite the container image id in an asset record for the first container image.
12. The system of claim 10, wherein, in a case that a container image digest value matches but a container image id does not match, the operations further include: overwrite the container image id in an asset record for the first container image.
13. The system of claim 8, wherein the operations further include, in response to determining the data bits (1) do include the repository identifier value and (2) do not include at least one of the first hash value or the second hash value, determine whether a second match condition is satisfied.
13. The system of claim 8, wherein the operations further include, in response to determining the data bits (1) do include the repository identifier value and (2) do not include at least one of the first hash value or the second hash value, determine whether a second match condition is satisfied.
14. The system of claim 13, wherein the identification fields further include one or combinations of: a tag field, and/or platform data fields.
14. The system of claim 13, wherein the identification fields further include one or combinations of: a tag field, and/or platform data fields.
15. The system of claim 14, wherein the second match condition is satisfied when a set of values match: (a) the repository identifier value and a tag value for the tag field, or (b) the repository identifier value, the tag value, and platform data value(s) of the platform data fields.
15. The system of claim 14, wherein the second match condition is satisfied when a set of values match: (a) the repository identifier value and a tag value for the tag field, or (b) the repository identifier value, the tag value, and platform data value(s) of the platform data fields.
16. The system of claim 15, wherein, in a case that (a) is matched and (b) is not matched, the operations further include: generate a new asset record for the first container image, so that platform variation is tracked as a different asset.
16. The system of claim 15, wherein, in a case that (a) is matched and (b) is not matched, the operations further include: generate a new asset record for the first container image, so that platform variation is tracked as a different asset.
17. A computer-implemented method for container image deduplication in asset detection and management, the computer-implemented method comprising:
obtaining source data from at least one source, wherein the source data includes a plurality of assets;
extracting data bits for each asset from the source data;
determining a first asset concerns a first container image based on the data bits for the first asset;
in response to determining the first asset concerns the first container image, obtaining a container image dataset,
wherein the container image dataset includes a plurality of sets of values for identification fields,
each of the plurality of sets of values respectively correspond to a container image assets of a plurality of container image assets, and
the identification fields include, at least, a repository identifier field and a hash field;
determining whether the data bits match any of the plurality of sets of values;
based on a match result, generating or updating records for the first container image;
based on the generated or updated records for the first container image, determining a status from a first time period to a second time period; and
causing a management graphical user interface to be displayed to a user, wherein the management graphical user interface displays the status from the first time period to the second time period.
17. A computer-implemented method for container image deduplication in vulnerability detection and management, the computer-implemented method comprising:
obtaining source data from at least one source, wherein the source data includes a plurality of assets and/or findings;
extracting data bits for each asset or finding from the source data;
determining a first asset or finding concerns a first container image based on the data bits for the first asset or finding;
in response to determining the first asset or finding concerns the first container image, obtaining a container image dataset,
wherein the container image dataset includes a plurality of sets of values for identification fields,
each of the plurality of sets of values respectively correspond to a container image assets of a plurality of container image assets, and
the identification fields include, at least, a repository identifier field and a hash field;
determining whether the data bits match any of the plurality of sets of values;
based on a match result, generating or updating records for the first container image;
based on the generated or updated records for the first container image, determining a vulnerability status from a first time period to a second time period; and
causing a management graphical user interface to be displayed to a user, wherein the management graphical user interface displays the vulnerability status from the first time period to the second time period.
18. The computer-implemented method of claim 17, wherein the hash field stores a container image digest or a container image id.
18. The computer-implemented method of claim 17, wherein the hash field stores a container image digest or a container image id.
19. The computer-implemented method of claim 18, wherein the container image digest is a hash of a manifest file for the first container image, and the container image id is a hash of a configuration file for the first container image.
19. The computer-implemented method of claim 18, wherein the container image digest is a hash of a manifest file for the first container image, and the container image id is a hash of a configuration file for the first container image.
20. The computer-implemented method of claim 17, wherein the hash field is a first hash field, and the identification fields further includes a second hash field.
6. The system of claim 1, wherein the hash field is a first hash field, and the identification fields further includes a second hash field.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Applying the subject matter eligibility test, as outlined in MPEP 2106:
Step 1: Statutory Category
The claims fall within a statutory category. Claims 1-16 are considered “machines” based claims and claims 17-20 are considered “processes”. Both machines and processes are members of the statutory categories. Thus, the analysis moves towards step 2A, prong one of the subject matter eligibility test.
Step 2A, Prong One: Judicial Exception
The claims recite a judicial exception, specifically an abstract idea. For example, claims 1 and 17 obtain source data (data collecting), extract data bits for each asset from the source data; determine a first asset concerns a first container image based on the data bits (analyzing data) and obtain a container image dataset (data retrieving), determine whether the data bits match any of the plurality of sets of values (comparison) and generate or update records for the first container image; based on the generated or updated records for the first container image, determine a status from a first time period to a second time period (generating or updating records and determining a result based on the comarison). Such processes are akin to a mental process, which have been recognized as abstract ideas. Thus, the analysis moves towards step 2A, prong two.
Step 2A, Prong Two: Integration into a Practical Application
The claims do not integrate the abstract idea into a practical application. The additional elements, such as memory and processor and user graphic interface to display status to a user do not impose any meaningful limits of on the abstract idea. Accordingly, the claim does not integrate the recited mental process into a practical application under the 2019 PEG and Oct. 2019 Update. Thus, the analysis moves towards step 2B. Thus, the analysis moves towards step 2B.
Step 2B: Inventive concept
Finally, the claims do not recite an inventive concept that transforms the abstract idea into a patent-eligible application. The use of memory and processor and user graphic interface in a generic manner, without specifying a novel algorithm or improvement to the generic computer, fails to add significantly more to the abstract idea. These additional elements are well-understood, routine, and conventional (WURC) implementations. In Berkheimer, 224 F.Supp.3d at 647-48 (quoting Content Extraction, 776 F.3d at 1348), claims that “describe "steps that employ only `well-understood, routine, and conventional' computer functions" and are claimed "at a relatively high level of generality.”” were held ineligible.
The claim is “directed to” an abstract idea.
Claim 2 added additional limitation for how to extract the data bits from claim 1. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claims 3 and 18 added hash field stores a container image digest or a container image id. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claims 4 and 19 added the container image digest is a hash of a manifest file for the first container image. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claims 5 and 19 added the container image id is a hash of a configuration file for the first container image. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claims 6 and 20 added the hash field is a first hash field, and the identification fields further includes a second hash field. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claim 7 added the first hash field stores a container image digest, and the second hash field stores a container image id from claim 6. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claim 8 added determine whether the data bits include a repository identifier value, and at least one of: a first hash value for the first hash field or a second hash value for the second hash field from claim 1. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claim 9 added in response to determining the data bits do include the repository identifier value and at least one of the first hash value or the second hash value, determine whether a first match condition is satisfied from claim 8. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claims 10-12 added how the match condition is satisfied and different method to update record based on match condition from claim 9. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claim 13 added in response to determining the data bits (1) do include the repository identifier value and (2) do not include at least one of the first hash value or the second hash value, determine whether a second match condition is satisfied from claim 8. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claim 14 added one or combinations of: a tag field, and/or platform data fields from claim 13. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claim 15 added the second match condition is satisfied when a set of values match: (a) the repository identifier value and a tag value for the tag field, or (b) the repository identifier value, the tag value, and platform data value(s) of the platform data fields from claim 14. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claim 16 added in a case that (a) is matched and (b) is not matched, the operations further include: generate a new asset record for the first container image, so that platform variation is tracked as a different asset from claim 15. The additional step doesn’t change the patent eligibility analysis discussed in claim 1.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claim 11 is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Specifically, while the claim recites “an omitted value”, the specification lacks a detailed description of any details and how update is accomplished. As a result, the disclosure does not appear to show possession of the full breadth of the claimed updating function with an omitted value.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing
out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the
invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly
claiming the subject matter which the applicant regards as his invention.
Claim 11 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
The claims recite limitation “an omitted value” without providing sufficient detail to inform, with reasonable certainty, those skilled in the art about the scope of the invention. Specifically, the claim language lacks clarity regarding the omitted value to perform updating.
As established in Nautilus, Inc. v. Biosig Instruments, Inc., 572 U.S. 898, 901, 910, 110 USPQ2d 1688, 1693 (2014), a claim is indefinite if, when read in light of the specification and the prosecution history, it fails to inform, with reasonable certainty, those skilled in the art about the scope of the invention. Additionally, MPEP § 2173.02 emphasizes that claims must be clear and precise to delineate the metes and bounds of the subject matter to be protected.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-3 and 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Pabon (Pub. No.: US 2023/0229354) in view of White et al. (Pub. No.: US 2022/0300330, hereinafter White) and Alam et al. (Pub. No.: US 2024/0176889, hereinafter Alam).
Regarding claims 1 and 17: Pabon teaches: A system for container image deduplication in asset management, the system comprising:
at least one memory configured to store instructions; and at least one processor (Pabon - [0041]: Storage array controller 101 may include one or more processing devices 104 and random access memory (‘RAM’) 111. Processing device 104 (or controller 101) represents one or more general-purpose processing devices such as a microprocessor, central processing unit) configured to execute the instructions to perform operations, wherein the operations include:
determine a first asset concerns a first container image based on the data bits for the first asset; in response to determining the first asset concerns the first container image, obtain a container image dataset (Pabon - [0331]: to access the volume 1204, the container runtime 1302 may send a request 1308-1 to the storage system 1306 for the volume 1204. The request 1308-1 may indicate an identifier of the container image 1210. In response to the request 1308-1, the storage system 1306 may provide volume data 1310-1, where the volume data 1310-1 is associated with the volume 1204),
wherein the container image dataset includes a plurality of sets of values for identification fields,
each of the plurality of sets of values respectively correspond to a container image assets of a plurality of container image assets (Pabon - [0331]: volume data may be a network path or a network location and credentials, such as a username and/or password to an account associated with one or more storage resources), and
the identification fields include, at least, a repository identifier field (Pabon - [0131]: Storage systems in accordance with some embodiments of the present disclosure may utilize object storage, where data is managed as objects. Each object may include the data itself, a variable amount of metadata, and a globally unique identifier) and a hash field (Pabon - [0086]: In order to locate a particular piece of data, embodiments calculate a hash value for a data segment or apply an inode number or a data segment number);
determine whether the data bits match any of the plurality of sets of values (Pabon - [0086]: If there is a change in where a particular segment of data is located, e.g., during a data move or a data reconstruction, the authority 168 for that data segment should be consulted, at that non-volatile solid state storage 152 or storage node 150 having that authority 168. In order to locate a particular piece of data, embodiments calculate a hash value for a data segment or apply an inode number or a data segment number. The output of this operation points to a non-volatile solid state storage 152 having the authority 168 for that particular piece of data. In some embodiments there are two stages to this operation. The first stage maps an entity identifier (ID), e.g., a segment number, inode number, or directory number to an authority identifier. This mapping may include a calculation such as a hash or a bit mask. The second stage is mapping the authority identifier to a particular non-volatile solid state storage 152, which may be done through an explicit mapping);
based on a match result, generate or update records for the first container image (Pabon - [0223]: The fleet management modules may perform tasks such as monitoring the health of each storage system in the fleet, initiating updates or upgrades on one or more storage systems in the fleet);
based on the generated or updated records for the first container image, determine a status from a first time period to a second time period (Pabon - [0225]: In checkpoint-based replication (also referred to as ‘nearly synchronous replication’), a set of updates to a dataset (e.g., one or more write operations directed to the dataset) may occur between different checkpoints, such that a dataset has been updated to a specific checkpoint only if all updates to the dataset prior to the specific checkpoint have been completed);
However, Pabon doesn’t explicitly teach, but White discloses:
obtain source data from at least one source, wherein the source data includes a plurality of assets (White - [0028]: TPRS 170 may obtain a container image's Common Vulnerabilities and Exposure (CVE) data from a plurality of upstream sources);
extract data bits for each asset from the source data (White - [0028]: then parse, correlate, and consolidate the CVE data);
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Pabon with White so that data source is obtaine and parsed for further analysis. The modification would have allowed the system to further process parsed data.
However, the combination of Pabon and White doesn’t explicitly teach, but Alam discloses:
cause a management graphical user interface to be displayed to a user, wherein the management graphical user interface displays the status from the first time period to the second time period (Alam - [0065]: The user interface 500 can include a first field 502a displaying the risk indicator change over a time period).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Pabon with White and Alam so that changes over the time period is displayed. The modification would have allowed the system to be more user friendly.
Regarding claim 2: Pabon as modified teaches: wherein, to extract the data bits for each asset from the source data, the operations further include:
determine a type of source; determine a source model based on the type of source (White - [0028]: TPRS 170 may obtain a container image's Common Vulnerabilities and Exposure (CVE) data from a plurality of upstream sources);
extract, for each asset, the data bits for the asset using the source model (White - [0028]: parse, correlate, and consolidate the CVE data); and
map the extracted data bits in a defined format for recall (White - [0028]: TPRS 170 provides the trustworthiness in any suitable format, such as a numerical score or a categorization (red/yellow/green trustworthiness, high/medium/low risk, etc.)).
The reason to combine is in the same rational as claim 1.
Regarding claims 3 and 18: Pabon as modified teaches: wherein the hash field stores a container image digest or a container image id (Pabon - [0086]: The first stage maps an entity identifier (ID), e.g., a segment number, inode number, or directory number to an authority identifier. This mapping may include a calculation such as a hash or a bit mask).
Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Pabon (Pub. No.: US 2023/0229354) in view of White et al. (Pub. No.: US 2022/0300330, hereinafter White) and Alam et al. (Pub. No.: US 2024/0176889, hereinafter Alam) and Raduchel et al. (US 20170161439, hereinafter Raduchel).
Regarding claim 4: Pabon as modified doesn’t explicitly teach but Raduchel teaches: wherein the container image digest is a hash of a manifest file for the first container image (Raduchel - [0364]: signing the container can be accomplished via a hash of the container's image manifest digest).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Pabon with White and Alam with Raduchel so that container's image manifest digest is hashed. The modification would have allowed the system to be more secure.
Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Pabon (Pub. No.: US 2023/0229354) in view of White et al. (Pub. No.: US 2022/0300330, hereinafter White) and Alam et al. (Pub. No.: US 2024/0176889, hereinafter Alam) and Hotinger et al. (US 11,966,769, hereinafter Hotinger).
Regarding claim 5: Pabon as modified doesn’t explicitly teach but Hotinger teaches: wherein the container image id is a hash of a configuration file for the first container image (Hotinger - [Col. 12, Line 27-31]: to pull a copy of a container image from a registry or repository to another location 504 request for a layer mount 410 506 an identification of a layer; also referred to as “layer identifier”; may be, e.g., a hash of the layer's content).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Pabon with White and Alam with Hotinger so that image layer identification is a hash of layer content or configuration. The modification would have allowed the system to create a content image ID.
Claims 6-10 and 20 is rejected under 35 U.S.C. 103 as being unpatentable over Pabon (Pub. No.: US 2023/0229354) in view of White et al. (Pub. No.: US 2022/0300330, hereinafter White) and Alam et al. (Pub. No.: US 2024/0176889, hereinafter Alam) and MacLachlan et al. (US 11786647) hereinafter MacLachlan).
Regarding claim 6: Pabon as modified doesn’t explicitly teach but MacLachlan teaches: wherein the hash field is a first hash field, and the identification fields further includes a second hash field (MacLachlan - [Col. 30, Line 59-64]: a third memory bank storing a rover type datum corresponding to the medical waste collection device, a first hash digest generated based on the rover type datum, use history data for the manifold, and a second hash digest generated based on the use history data for the manifold).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Pabon with White and Alam with MacLachlan so that there are plural hash field in the storage. The modification would have allowed the system to be more flexible.
Regarding claim 7: Pabon as modified teaches: wherein the first hash field stores a container image digest, and the second hash field stores a container image id (MacLachlan - [Col. 30, Line 59-64]: a first hash digest generated based on the rover type datum, use history data for the manifold, and a second hash digest generated based on the use history data for the manifold)).
The reason to combine is in the same rational as claim 6
Regarding claim 8: Pabon as modified teaches: wherein, to determine whether the data bits match any of the plurality of sets of values, the operations further include: determine whether the data bits include a repository identifier value, and at least one of: a first hash value for the first hash field or a second hash value for the second hash field (Pabon - [0131]: Storage systems in accordance with some embodiments of the present disclosure may utilize object storage, where data is managed as objects. Each object may include the data itself, a variable amount of metadata, and a globally unique identifier. [0086]: In order to locate a particular piece of data, embodiments calculate a hash value for a data segment or apply an inode number or a data segment number);.
Regarding claim 9: Pabon as modified teaches: wherein the operations further include, in response to determining the data bits do include the repository identifier value and at least one of the first hash value or the second hash value, determine whether a first match condition is satisfied (White - [0059]: RCP logic 125 determines the container ID that maps to the process ID of the request based on knowledge of how container manager application 140 assigns process IDs. RCP logic 125 determines whether the request associated with the particular container ID triggers an exception).
The reason to combine is in the same rational as claim 1.
Regarding claim 10: Pabon as modified teaches: wherein the first match condition is satisfied when a set of values, of the plurality of sets of values for identification fields, match (a) the repository identifier value and the first hash value, (b) the repository identifier value and the second hash value, or (c) the repository identifier value, the first hash value, and the second hash value (Pabon - [0086]: The first stage maps an entity identifier (ID), e.g., a segment number, inode number, or directory number to an authority identifier. This mapping may include a calculation such as a hash or a bit mask. The second stage is mapping the authority identifier to a particular non-volatile solid state storage 152, which may be done through an explicit mapping).
Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over Pabon (Pub. No.: US 2023/0229354) in view of White et al. (Pub. No.: US 2022/0300330, hereinafter White) and Alam et al. (Pub. No.: US 2024/0176889, hereinafter Alam) and Raduchel et al. (US 20170161439, hereinafter Raduchel) and Hotinger et al. (US 11,966,769, hereinafter Hotinger).
Regarding claim 19: Pabon as modified doesn’t explicitly teach but Raduchel teaches:
wherein the container image digest is a hash of a manifest file for the first container image (Raduchel - [0364]: signing the container can be accomplished via a hash of the container's image manifest digest).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Pabon with White and Alam with Raduchel so that container's image manifest digest is hashed. The modification would have allowed the system to be more secure.
However, Pabon as modified doesn’t explicitly teach but Hotinger teaches: and wherein the container image id is a hash of a configuration file for the first container image (Hotinger - [Col. 12, Line 27-31]: to pull a copy of a container image from a registry or repository to another location 504 request for a layer mount 410 506 an identification of a layer; also referred to as “layer identifier”; may be, e.g., a hash of the layer's content).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Pabon with White and Alam with Raduchel and Hotinger so that image layer identification is a hash of layer content or configuration. The modification would have allowed the system to create a content image ID.
Allowable Subject Matter
Claims 11-16 would be allowable if the 101 and 112b rejection, set forth in this Office action, are overcome and if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Weizman et al. (Pub. No.: US 2023/0376604) - Determination of mitigation priority values of vulnerabilities in container images
Sahar-Kaneti et al. (Pub. No.: US 2024/0176888) - Method of detecting vulnerabilities of container images at runtime
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MENG LI whose telephone number is (571)272-8729. The examiner can normally be reached M-F 8:30-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MENG LI/
Primary Examiner, Art Unit 2437