Prosecution Insights
Last updated: October 01, 2026
Application No. 18/884,681

EMBEDDING SECURITY REQUIREMENTS IN CONTAINER IMAGES

Final Rejection §DP
Filed
Sep 13, 2024
Priority
Oct 23, 2020 — continuation of 12/124,561
Examiner
JEUDY, JOSNEL
Art Unit
2438
Tech Center
2400 — Computer Networks
Assignee
Red Hat Inc.
OA Round
2 (Final)
84%
Grant Probability
Favorable
3-4
OA Rounds
8m
Est. Remaining
68%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
674 granted / 804 resolved
+25.8% vs TC avg
Minimal -16% lift
Without
With
+-16.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
16 currently pending
Career history
817
Total Applications
across all art units

Statute-Specific Performance

§101
19.2%
-20.8% vs TC avg
§103
49.9%
+9.9% vs TC avg
§102
7.2%
-32.8% vs TC avg
§112
9.2%
-30.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 804 resolved cases

Office Action

§DP
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 1.This is a Final Office Action in response to applicant’s arguments filed on May 18, 2026. At this time, no claim has been amended, added or cancelled. Therefore, claims 1-20 are pending and addressed below. Response to Arguments Applicant’s Terminal Disclaimer is disapproved. See Terminal Disclaimer review decision. Therefore, the Double patenting rejection is maintained. See the rejection below. Double patenting 2. The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the "right to exclude" granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Omum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b). Claims 1, 3, 5-7, 8-10, 12, 14, 16, and 18-20 are rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over claims 1-11, 13-14 and 16-20 of US Patent number 12124561. The conflicting claims are not identical, they are not patentably distinct from each other because the current application contains claims that are broader in scope than the claims of the patent number 12124561 and are anticipated by the claims 1-11, 13-14 and 16-20. This is a Non-provisional double patenting rejection. Claims Comparison Table Application Number 18/884,681 Patent Application Number 12124561 1. A system comprising: a memory; and a processing device operatively coupled to the memory, the processing device to: trace, using a trace tool, system calls made by an application to determine a system call that is necessary for the application to operate, wherein the system call corresponds to a minimum level of security for the application; and embed, based on the system call, a custom security setting into a container image corresponding to the application. 1. A system comprising: a memory; and a processing device operatively coupled to the memory, the processing device to: trace, using a trace tool, system calls made by an application to determine a set of system calls that are necessary for the application to operate, wherein the set of system calls that are necessary for the application to operate correspond to a minimum level of security for the application; define custom security settings based on the set of system calls that are necessary for the application to operate, wherein the custom security settings indicate the set of system calls that are necessary for the application to operate as authorized system calls for a system call filter; and embed the custom security settings into a container image corresponding to the application. 9. The non-transitory computer-readable medium of claim 8, wherein the custom security setting comprises a custom seccomp profile. 2. The system of claim 1, wherein the custom security settings comprise a custom seccomp profile. 3. The system of claim 1, wherein to embed the custom security settings into the container image, the processing device is to include the custom security settings as part of image metadata of the container image. 3. The system of claim 1, wherein to embed the custom security settings into the container image, the processing device is to: include the custom security settings as part of image metadata of the container image. 5. The system of claim 1, wherein to embed the custom security setting into the container image, the processing device is to include the custom security setting into a layer of the container image as a file system object. 4. The system of claim 1, wherein to embed the custom security settings into the container image, the processing device is to: include the custom security settings into a layer of the container image as a file system object. 6. The system of claim 1, wherein to trace the system calls made by the application, the processing device is to: utilize the trace tool to trace the system calls made by the application during a pre-start phase of a container in which the application is running, wherein during the pre-start phase an initialization process of the container is created but not yet started. 5. The system of claim 1, wherein to trace the system calls made by the application, the processing device is to: utilize the trace tool to trace the system calls made by the application during a pre-start phase of a container in which the application is running, wherein during the pre-start phase an initialization process of the container is created but not yet started. 7. The system of claim 5, wherein the processing device implements the trace tool as a run time hook. 6. The system of claim 5, wherein the processing device implements the trace tool as a run time hook. 20. The method of claim 14, wherein a container building tool is used to embed the custom security settings into the container image corresponding to the application. 7. The system of claim 1, further comprising: compiling the custom security settings into the system call filter prior to embedding the custom security settings into the container image corresponding to the application. 8. A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processing device, cause the processing device to: trace, using a trace tool executed by the processing device, system calls made by an application to determine a system call that are necessary for the application to operate, wherein the system call that is necessary for the application to operate correspond to a minimum level of security for the application; and embed, based on the system call, a custom security setting into a container image corresponding to the application. 8. A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processing device, cause the processing device to: trace, using a trace tool, system calls made by an application to determine a set of system calls that are necessary for the application to operate, wherein the set of system calls that are necessary for the application to operate correspond to a minimum level of security for the application; define custom security settings based on the set of system calls that are necessary for the application to operate, wherein the custom security settings indicate the set of system calls that are necessary for the application to operate as authorized system calls for a system call filter; and embed, by the processing device, the custom security settings into a container image corresponding to the application. 9. The non-transitory computer-readable medium of claim 8, wherein the custom security setting comprises a custom seccomp profile. 9. The non-transitory computer-readable medium of claim 8, wherein the custom security settings comprise a custom seccomp profile. 10. The non-transitory computer-readable medium of claim 8, wherein to embed the custom security setting into the container image, the processing device is to include the custom security settings as part of image metadata of the container image. 10. The non-transitory computer-readable medium of claim 8, wherein to embed the custom security settings into the container image, the processing device is to: include the custom security settings as part of image metadata of the container image. 5. The system of claim 1, wherein to embed the custom security setting into the container image, the processing device is to include the custom security setting into a layer of the container image as a file system object. 11. The non-transitory computer-readable medium of claim 8, wherein to embed the custom security settings into the container image, the processing device is to: include the custom security settings into a layer of the container image as a file system object. 6. The system of claim 1, wherein to trace the system calls made by the application, the processing device is to: utilize the trace tool to trace the system calls made by the application during a pre-start phase of a container in which the application is running, wherein during the pre-start phase an initialization process of the container is created but not yet started. 12. The non-transitory computer-readable medium of claim 8, wherein to trace the system calls made by the application, the processing device is to: utilize the trace tool to trace the system calls made by the application during a pre-start phase of a container in which the application is running, wherein during the pre-start phase an initialization process of the container is created but not yet started. 7. The system of claim 5, wherein the processing device implements the trace tool as a run time hook. 13. The non-transitory computer-readable medium of claim 8, wherein the processing device implements the trace tool as a run time hook. 14. A method comprising: tracing, using a privilege tracing tool, privileges used by an application to determine a privilege that is necessary for the application to operate, wherein the privilege that is necessary for the application to operate correspond to a minimum level of security for the application; embedding, based on the privilege, a custom security setting into a container image corresponding to the application. 14. A method comprising: tracing, using a tracing tool, system calls used by an application to determine a set of system calls that are necessary for the application to operate, wherein the set of system calls that are necessary for the application to operate correspond to a minimum level of security for the application; defining custom security settings based on the set of system calls that are necessary for the application to operate; and embedding the custom security settings into a container image corresponding to the application. 16. The method of claim 14, wherein embedding the custom security setting into the container image comprises including the custom security settings as part of image metadata of the container image. 16. The method of claim 14, wherein embedding the custom security settings into the container image comprises: including the custom security settings as part of image metadata of the container image. 5. The system of claim 1, wherein to embed the custom security setting into the container image, the processing device is to include the custom security setting into a layer of the container image as a file system object. 17. The method of claim 14, wherein embedding the custom security settings into the container image comprises: including the custom security settings into a layer of the container image as a file system object. 18. The method of claim 14, wherein tracing the privileges used by the application comprises: utilizing the privilege tracing tool to trace privileges used by the application during a pre-start phase of a container in which the application is running, wherein during the pre-start phase an initialization process of the container is created but not yet started. 18. The method of claim 14, wherein tracing the system calls used by the application comprises: utilizing the tracing tool to trace system calls used by the application during a pre-start phase of a container in which the application is running, wherein during the pre-start phase an initialization process of the container is created but not yet started. 19. The method of claim 15, wherein each of the one or more labels comprise a set of key/value pairs that are not visible to the application. 19. The method of claim 15, wherein each of the one or more labels comprise a set of key/value pairs that are not visible to the application. 20. The method of claim 14, wherein a container building tool is used to embed the custom security settings into the container image corresponding to the application. 20. The method of claim 14, wherein a container building tool is used to embed the custom security settings into the container image corresponding to the application. Allowable Subject Matter The following is a statement of reasons for the indication of allowable subject matter: Kim (US 20200285733) discloses a memory; and a processing device operatively coupled to the memory, the processing device to: trace, using a trace tool, system calls made by an application to determine a system call that is necessary for the application to operate, wherein the system call corresponds to a minimum level of security for the application; The prior art does not disclose and embed, based on the system call, a custom security setting into a container image corresponding to the application. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Mishra Gupta, US 20240080342 A1, title “ GENERATION OF SECURITY POLICIES FOR CONTAINER EXECUTION.“ THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOSNEL JEUDY whose telephone number is (571)270-7476. The examiner can normally be reached M-F 10:00-8:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Arani T Taghi can be reached at (571)272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. Date: 08/11/2026 /JOSNEL JEUDY/ Primary Examiner, Art Unit 2438
Read full office action

Prosecution Timeline

Sep 13, 2024
Application Filed
Feb 19, 2026
Non-Final Rejection mailed — §DP
May 18, 2026
Response Filed
Aug 13, 2026
Final Rejection mailed — §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737477
TRIGGERING A SECURITY ACTION BASED ON AN AI-GENERATED CODE PACKAGE RECOMMENDATION
2y 5m to grant Granted Sep 15, 2026
Patent 12724878
GENERATING INSTRUMENTATION FOR DATA INTEGRITY OF FUNCTION CALLS
2y 9m to grant Granted Sep 01, 2026
Patent 12711230
RANSOMWARE DISCOVERY BY DETECTION OF TRANSMIT/OVERWRITE PROCESSES
3y 4m to grant Granted Aug 18, 2026
Patent 12705615
SYSTEMS, METHODS AND APPARATUS FOR PAYMENT TERMINAL MANAGEMENT
3y 3m to grant Granted Aug 11, 2026
Patent 12694101
VIRTUAL CANARY FILES TO MITIGATE RANSOMWARE ATTACKS
2y 8m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
84%
Grant Probability
68%
With Interview (-16.1%)
2y 9m (~8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 804 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month