Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This Office Action is in response to the amendment filed on 04/10/2026. In the instant amendment, claims 1, 11, 12, 15, 18 and 19 were amended; claims 2-4 were cancelled; claims 21-23 are new; claims 1, 15 and 19 are independent claims. Claims 1, 5-23 are pending in this application. THIS ACTION IS MADE FINAL.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 03/12/2026 and 05/21/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Arguments
The 35 U.S.C. 101 rejection to claims 1 and 5-20 are withdrawn.
Applicant’s arguments with respect to claims 1, 5 and 19 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 5-11, 13-17 and 19-23 are rejected under 35 U.S.C. 103 as being unpatentable over Bengston et al (“Bengston,” US 20190349369) and further in view of Brandwine et al (“Brandwine,” US 11,334,661).
Regarding claim 1, Bengston discloses a non-transitory computer-readable medium including instructions that when executed by one or more processors, cause a system including the one or more processors to perform operations including:
receiving a request for a non-user principal that is an identity (i) to be assigned to a non-user entity to be used within a cloud environment upon successful authentication of the non-user entity and (ii) to be manifested as a session token granted to the non-user entity; (Bengston, [0033] when the cloud server instance performs an assume role action…associated data may be logged; [0043]-[0044] role manager evaluates the API call; if the role has permission and the token has not expired, the call may succeed; [0045] each temporary credential that issued by the STS service may be given an expiration timestamp; [0018] describes a cloud environment; [0029] further describes requests)
accessing a log that includes information associated with a receipt of the request for the non-user principal; (Bengston in [0028], these credentials may be logging in a data log 109 by logging module 108. The data log 109 may note which network address 110 and which credentials 111 were included or identified in the network service request 116; [0033] associated data may be logged in a data log including an instance identifier, an assumed role resource name, an IP address, and a TTL value; [0029] further describes requests)
determining, based at least in part on the log, originating information of the request; (Bengston in [0029], service request analyzer 112 may determine which network address 110 is associated with that server instance; [0035], the systems may then extract the instance ID and do a lookup in the table; update the table with the source IP address form the server instance; [0028]-[0033] describe a log)
detecting an anomaly associated with the originating information of the request; and in response to detecting the anomaly associated with the originating information of the request, (Bengston in [0031] detect use of a credential from an IP address that is not assigned to a given user’s or given account’s assigned resources; [0035] if the systems identify a call with a source IP address that is not this stored IP address, then the systems may have detected a credential not being used on the instance it was assigned to and may assume that those credentials have been compromised; [0028]-[0029] describe a request)
(i) causing to present, at a user interface, information indicative of the detected anomaly associated with the originating information of the request, (Bengston in [0058] the system may generate an alert that is sent to one or more administrators or other entities indicating that the credentials 111A may be compromised; claim 20 describes prevent the second server instance and/or raise an alert where the user interface is implicit)
and (ii) one or more of (a) rescinding or flagging the non-user principal granted based on the request, (Bengston in [0029], [0058], the task modification module 115 may limit the tasks that can be performed by that server instance. May be severely restricted such that the server instance is prohibited from performing any tasks at all)
(b) blocking the request, such that no non-user principal is granted based on the request, (Bengston in [0029] describes the task modification module 115 may limit the tasks that can be performed that server instance; claim 1 describes preventing the second server instance from performing one or more specified tasks within the network)
(c) flagging the non-user entity, from which the request originated, as a risk, and (Bengston in [0035] describes may have detected a credential not being used on the instance it was assigned to and may assume that those credentials have been compromised-flagging the requesting server instance as compromised)
(d) causing to undertake protective actions against the non-user entity, (Bengston in [0029] describes task restriction; [0067]-[0069] describes honeytoken null response/fictitious data and honeypot service alerting)
Bengston fails to explicitly disclose receiving a request for a non-user principal that is an identity (i) to be assigned to a non-user entity to be used within a cloud environment upon successful authentication of the non-user entity and (ii) to be manifested as a session token granted to the non-user entity; (i) causing to present, at a user interface, information indicative of the detected anomaly associated with the originating information of the request,
However, in an analogous art, Brandwine discloses receiving a request for a non-user principal that is an identity (i) to be assigned to a non-user entity to be used within a cloud environment upon successful authentication of the non-user entity and (ii) to be manifested as a session token granted to the non-user entity, (Brandwine in Column 8, Lines 27-65; Col. 10, Lines 25-44; FIG 1, Figure 2 describes software application 104/compute instance 116 obtains temporary security credentials 110. Application code may request that credentials be obtained before generating cloud-service requests; Col. 11, Lines 8-24; Col. 11, Lines 25-38; Col. 12, Lines 1-32, FIG 2 describe a role is an identity created in an IAM and associated with permissions. The role may be assumed by an application. Temporary security credentials for the role session are provided to the application/compute instance; Col. 1, Lines 5-20; Col. 8, Lines 9-26; Col. 20, Lines 33-39; FIG 6, step 608; Fig 7, step 712 describe security credentials are used by the cloud provider network to authenticate and authorize requests from users or applications. The second API request is successfully authenticated and authorized; Col. 3, Lines 35-65; Col. 4, Lines 1-18; Col. 20, Lines 28-32 describe temporary security credentials include access key identifier, secret access key, and a security token sometimes also referred to as a session token. The token encodes session information including expiration, owner identity, permissions and role; FIG 1, temporary credentials 110 and security token service 122)
(i) causing to present, at a user interface, information indicative of the detected anomaly associated with the originating information of the request, (Brandwine, Col. 14, Lines 30-36; Col. 15, Lines 29-39; FIG 3 describe a session anomaly alert 312 is generated and sent to IAM; a response message ma indicate request denied; potential security issue and credential revocation; Col. 14, Line 31 describes a user interface)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Brandwine with Bengston to include receiving a request for a non-user principal that is an identity (i) to be assigned to a non-user entity to be used within a cloud environment upon successful authentication of the non-user entity and (ii) to be manifested as a session token granted to the non-user entity; (i) causing to present, at a user interface, information indicative of the detected anomaly associated with the originating information of the request. One would have been motivated to enabling software applications to obtain security credentials used to interact with a cloud provider network
and, upon the revocation of an active set of security credentials used by an application to readily obtain new security credentials that the application can use to continue operation with minimal interruption (Brandwine, Col. 1, Lines 6-15).
Regarding claim 5, Bengston and Brandwine disclose the non-transitory computer-readable medium of claim 1.
Bengston further discloses wherein detecting the anomaly associated with the originating information of the request comprises: (Bengston in [0031] detect use of a credential from an IP address that is not assigned to a given user’s or given account’s assigned resources; [0035] if the systems identify a call with a source IP address that is not this stored IP address, then the systems may have detected a credential not being used on the instance it was assigned to and may assume that those credentials have been compromised; [0029] further describes requests)
detecting that the originating information includes an identification of an Internet Protocol (IP) address from which the request originated; (Bengston, [0028]-[0029], FIG 6, [0059] describes detecting that the originating information includes an identification of an Internet Protocol (IP) address from which the request originated; [0029] further describes requests)
mapping the IP address to outside the cloud environment; (Bengston, [0031], detect use of a credential from an IP address that is not assigned to a given user’s or a given account’s assigned resources (e.g. assigned IP block); [0048] credentials may be enforced by only allowing API calls..to succeed if they originate from a known environment; [0065] describes a cloud environment)
and in response to mapping the IP address to outside the cloud environment, (Bengston, [0031], detect use of a credential from an IP address that is not assigned to a given user’s or a given account’s assigned resources (e.g. assigned IP block); [0048] credentials may be enforced by only allowing API calls..to succeed if they originate from a known environment; [0065] & [0018] describes a cloud environment)
detecting the anomaly associated with the originating information of the request, (Bengston in [0031] detect use of a credential from an IP address that is not assigned to a given user’s or given account’s assigned resources; [0035] if the systems identify a call with a source IP address that is not this stored IP address, then the systems may have detected a credential not being used on the instance it was assigned to and may assume that those credentials have been compromised; [0028]-[0029] describe a request)
Regarding claim 6, Bengston and Brandwine disclose the non-transitory computer-readable medium of claim 1.
wherein detecting the anomaly associated with the originating information of the request comprises: (Bengston, [0011], [0091] describes wherein detecting the anomaly associated with the originating information of the request comprises; [0029] further describes requests)
detecting that the originating information includes an identification of an Internet Protocol (IP) address from which the request originated; (Bengston, [0028], FIG 6, [0059] describes detecting that the originating information includes an identification of an Internet Protocol (IP) address from which the request originated; [0029] further describes requests)
mapping the IP address to outside the cloud environment; (Bengston, [0031], detect use of a credential from an IP address that is not assigned to a given user’s or a given account’s assigned resources (e.g. assigned IP block); [0048] credentials may be enforced by only allowing API calls..to succeed if they originate from a known environment; [0065] & [0018] describes a cloud environment)
accessing a safe list of IP addresses outside the cloud environment; (Bengston in [0031] describes IP addresses; [0004], server instance may be configured to maintain a set of network addresses that are known to be valid within the network; [0048] create a managed policy that encompasses a user’s entire account across all regions…collect NAT gateway IPs, VPC identifiers, and VPC endpoint IDs to create the policy language; [0037] systems herein may build a whitelist by enumerating user agent strings..to alert when deviations from the whitelist are detected establishing the known-valid/whitelist comparison mechanism; [0035] determining the request’s IP is not he stored/known address; [0065] & [0018] describes a cloud environment)
determining that the IP address, from which the request was transmitted, is not within the safe list of IP addresses outside the cloud environment; (Bengston in [0031], IP addresses; [0004], server instance may be configured to maintain a set of network addresses that are known to be valid within the network; [0048] create a managed policy that encompasses a user’s entire account across all regions…collect NAT gateway IPs, VPC identifiers, and VPC endpoint IDs to create the policy language; [0037] systems herein may build a whitelist by enumerating user agent strings..to alert when deviations from the whitelist are detected establishing the known-valid/whitelist comparison mechanism; [0035] determining the request’s IP is not he stored/known address; [0065] & [0018] describes a cloud environment)
and in response to (i) mapping the IP address to outside the cloud environment and (ii) determining that the IP address is not within the safe list of IP addresses, (Bengston in [0031], IP addresses; [0004], server instance may be configured to maintain a set of network addresses that are known to be valid within the network; [0048] create a managed policy that encompasses a user’s entire account across all regions…collect NAT gateway IPs, VPC identifiers, and VPC endpoint IDs to create the policy language; [0037] systems herein may build a whitelist by enumerating user agent strings..to alert when deviations from the whitelist are detected establishing the known-valid/whitelist comparison mechanism; [0035] determining the request’s IP is not he stored/known address; [0065] & [0018] describes a cloud environment)
detecting the anomaly associated with the originating information of the request, (Bengston in [0031] detect use of a credential from an IP address that is not assigned to a given user’s or given account’s assigned resources; [0035] if the systems identify a call with a source IP address that is not this stored IP address, then the systems may have detected a credential not being used on the instance it was assigned to and may assume that those credentials have been compromised; [0028]-[0029] describe a request)
Regarding claim 7, Bengston and Brandwine disclose the non-transitory computer-readable medium of claim 1.
Bengston further discloses wherein the request for the non-user principal originates from a requesting non-user entity, and (Bengston, [0033] when the cloud server instance performs an assume role action…associated data may be logged; [0043]-[0044] role manager evaluates the API call; if the role has permission and the token has not expired, the call may succeed; [0045] each temporary credential that issued by the STS service may be given an expiration timestamp)
wherein detecting the anomaly associated with the originating information of the request comprises: (Bengston in [0031] detect use of a credential from an IP address that is not assigned to a given user’s or given account’s assigned resources; [0035] if the systems identify a call with a source IP address that is not this stored IP address, then the systems may have detected a credential not being used on the instance it was assigned to and may assume that those credentials have been compromised; [0028]-[0029] describe a request)
receiving, along with or as a part of the request for the non-user principal, credentials assigned to an original non-user entity; (Bengston in [0031], detect use of a credential from an IP address that is not assigned a given user’s or given account’s assigned resources (e.g. an assigned IP block); [0028], credentials 111A originally assigned to server instance/account 120A; a different server instance 120B from a different address attempting to use those credentials; [0058], server instance 120B, using credentials 111A originally assigned to instance/account 120A, is checked against known valid addreses)
detecting that the originating information includes an identification of an Internet Protocol (IP) address from which the request originated; (Bengston, [0028], FIG 6, [0059] describes detecting that the originating information includes an identification of an Internet Protocol (IP) address from which the request originated; [0029] further describes requests)
mapping the IP address to a first tenancy of the cloud environment; (Bengston, [0031], detect use of a credential from an IP address that is not assigned to a given user’s or a given account’s assigned resources (e.g. assigned IP block); [0048] credentials may be enforced by only allowing API calls..to succeed if they originate from a known environment; [0065] & [0018] describes a cloud environment; FIG 4 shows a public boot loader receiving/providing “account” [tenancy] and region information plus public IP, Elastic Ips, VPC IDs and VPC Endpoints)
and detecting the anomaly associated with the originating information of the request, (Bengston in [0031] detect use of a credential from an IP address that is not assigned to a given user’s or given account’s assigned resources; [0035] if the systems identify a call with a source IP address that is not this stored IP address, then the systems may have detected a credential not being used on the instance it was assigned to and may assume that those credentials have been compromised; [0028]-[0029] describe a request)
Bengston fails to explicitly disclose in response to determining that the original non-user entity is located within the second tenancy that is different from the first tenancy; determining that the original non-user entity, to which the credentials were assigned, is located within a second tenancy of the cloud environment that is different from the first tenancy.
However, in an analogous art, Brandwine discloses in response to determining that the original non-user entity is located within the second tenancy that is different from the first tenancy, (Brandwine in Column 8, Lines 27-65; Col. 10, Lines 25-44; FIG 1, Figure 2 describes software application 104/compute instance 116 obtains temporary security credentials 110. Application code may request that credentials be obtained before generating cloud-service requests; Col. 11, Lines 8-24; Col. 11, Lines 25-38; Col. 12, Lines 1-32, FIG 2 describe a role is an identity created in an IAM and associated with permissions. The role may be assumed by an application. Temporary security credentials for the role session are provided to the application/compute instance; Col. 1, Lines 5-20; Col. 8, Lines 9-26; Col. 20, Lines 33-39; FIG 6, step 608; Fig 7, step 712 describe security credentials are used by the cloud provider network to authenticate and authorize requests from users or applications. The second API request is successfully authenticated and authorized; Col. 3, Lines 35-65; Col. 4, Lines 1-18; Col. 20, Lines 28-32 describe temporary security credentials include access key identifier, secret access key, and a security token sometimes also referred to as a session token. The token encodes session information including expiration, owner identity, permissions and role; FIG 1, temporary credentials 110 and security token service 122; Col. 5, Lines 45-49; Col. 6, Lines 4-7 describes different accounts in a cloud environment)
determining that the original non-user entity, to which the credentials were assigned, is located within a second tenancy of the cloud environment that is different from the first tenancy, (Brandwine in Column 8, Lines 27-65; Col. 10, Lines 25-44; FIG 1, Figure 2 describes software application 104/compute instance 116 obtains temporary security credentials 110. Application code may request that credentials be obtained before generating cloud-service requests; Col. 11, Lines 8-24; Col. 11, Lines 25-38; Col. 12, Lines 1-32, FIG 2 describe a role is an identity created in an IAM and associated with permissions. The role may be assumed by an application. Temporary security credentials for the role session are provided to the application/compute instance; Col. 1, Lines 5-20; Col. 8, Lines 9-26; Col. 20, Lines 33-39; FIG 6, step 608; Fig 7, step 712 describe security credentials are used by the cloud provider network to authenticate and authorize requests from users or applications. The second API request is successfully authenticated and authorized; Col. 3, Lines 35-65; Col. 4, Lines 1-18; Col. 20, Lines 28-32 describe temporary security credentials include access key identifier, secret access key, and a security token sometimes also referred to as a session token. The token encodes session information including expiration, owner identity, permissions and role; FIG 1, temporary credentials 110 and security token service 122; Col. 5, Lines 45-49; Col. 13, Lines 20-28; Col. 14, Lines 1-8 describes credentials;; Col. 6, Lines 4-7 describes different accounts in a cloud environment)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Brandwine with Bengston to include in response to determining that the original non-user entity is located within the second tenancy that is different from the first tenancy; determining that the original non-user entity, to which the credentials were assigned, is located within a second tenancy of the cloud environment that is different from the first tenancy. One would have been motivated to enabling software applications to obtain security credentials used to interact with a cloud provider network and, upon the revocation of an active set of security credentials used by an application to readily obtain new security credentials that the application can use to continue operation with minimal interruption (Brandwine, Col. 1, Lines 6-15).
Regarding claim 8, Bengston and Brandwine disclose the non-transitory computer-readable medium of claim 7.
wherein mapping the IP address to the first tenancy of the cloud environment comprises: (Bengston, [0031], detect use of a credential from an IP address that is not assigned to a given user’s or a given account’s assigned resources (e.g. assigned IP block); [0048] credentials may be enforced by only allowing API calls..to succeed if they originate from a known environment; [0065] & [0018] describes a cloud environment)
accessing a database that identifies, for each of a plurality of tenancies of the cloud environment, a corresponding plurality of IP addresses assigned to the corresponding tenancy; and (Bengston, [0032] describes access a data table or data log of each server instances assumed role records. Each table entry may show the instance ID, assumed role, IP address of the API call, and a TTL value; [0048] describes collect NAT gateway Ips, VPC identifiers, and VPC endpoint IDs to create policy language for the managed policy encompassing a user’s entire account across all regions; [0065] & [0018] describes a cloud environment)
mapping the IP address to the first tenancy of the cloud environment, based at least in part on accessing the database, (Bengston, [0032] describes access a data table or data log of each server instances assumed role records. Each table entry may show the instance ID, assumed role, IP address of the API call, and a TTL value; [0048] describes collect NAT gateway Ips, VPC identifiers, and VPC endpoint IDs to create policy language for the managed policy encompassing a user’s entire account across all regions; [0065] & [0018] describes a cloud environment)
Regarding claim 9, Bengston and Brandwine disclose the non-transitory computer-readable medium of claim 7.
Bengston further discloses wherein the IP address is a private IP address, and wherein mapping the IP address to the first tenancy of the cloud environment comprises: mapping the private IP address to a gateway of the first tenancy of the cloud environment, (Bengston, [0046] web services 301 may observe the network address translation (NAT) gateway 303 public IP address as the source IP address, In such cases, a user’s web services instance 307 may be deployed in an internal subnet 306..web services 301 may observe the private IP address of a user’s cloud instance..and may also observe information about the VPC and/or VPC endpoint 308 the call went through; [0065] & [0018] describes a cloud environment)
Regarding claim 10, Bengston and Brandwine disclose the non-transitory computer-readable medium of claim 7.
Bengston further discloses wherein the IP address is a public IP address, and wherein mapping the IP address to the first tenancy of the cloud environment comprises: (Bengston, [0046], web services 301 may observe the network address translation (NAT) gateway 303 public IP address as the source address. In such cases, a user’s web services instance 307 may be deployed in an internal subnet 306..web services API calls may travel through the NAT gateway 303; [0047], web services 301 may observe the private IP address of a user’s cloud instance and may also observe information about the VPC and/or VPC endpoint 408 the call went through; [0065] & [0018] describes a cloud environment)
mapping the public IP address to a compute instance, or a cloud resource, or a cloud service; (Bengston, [0046], web services 301 may observe the network address translation (NAT) gateway 303 public IP address as the source address. In such cases, a user’s web services instance 307 may be deployed in an internal subnet 306..web services API calls may travel through the NAT gateway 303; [0047], web services 301 may observe the private IP address of a user’s cloud instance and may also observe information about the VPC and/or VPC endpoint 408 the call went through; [0065] & [0018] describes a cloud environment; [0039], cloud server [cloud service] and cloud resource)
determining that the compute instance, or the cloud resource, or the cloud service is within the first tenancy of the cloud environment; (Bengston, [0046], web services 301 may observe the network address translation (NAT) gateway 303 public IP address as the source address. In such cases, a user’s web services instance 307 may be deployed in an internal subnet 306..web services API calls may travel through the NAT gateway 303; [0047], web services 301 may observe the private IP address of a user’s cloud instance and may also observe information about the VPC and/or VPC endpoint 408 the call went through; [0065] & [0018] describes a cloud environment; [0039], cloud server [cloud service] and cloud resource)
and in response to determining that the compute instance, or the cloud resource, or the cloud service is within the first tenancy of the cloud environment, (Bengston, [0046], web services 301 may observe the network address translation (NAT) gateway 303 public IP address as the source address. In such cases, a user’s web services instance 307 may be deployed in an internal subnet 306..web services API calls may travel through the NAT gateway 303; [0047], web services 301 may observe the private IP address of a user’s cloud instance and may also observe information about the VPC and/or VPC endpoint 408 the call went through; [0065] & [0018] describes a cloud environment; [0039], cloud server [cloud service] and cloud resource)
mapping the IP address to the first tenancy of the cloud environment, (Bengston, [0046], web services 301 may observe the network address translation (NAT) gateway 303 public IP address as the source address. In such cases, a user’s web services instance 307 may be deployed in an internal subnet 306..web services API calls may travel through the NAT gateway 303; [0047], web services 301 may observe the private IP address of a user’s cloud instance and may also observe information about the VPC and/or VPC endpoint 408 the call went through; [0065] & [0018] describes a cloud environment; [0039], cloud server [cloud service] and cloud resource)
Regarding claim 11, Bengston and Brandwine disclose the non-transitory computer-readable medium of claim 1.
Bengston further discloses wherein detecting the anomaly associated with the originating information of the request comprises: (Bengston in [0031] detect use of a credential from an IP address that is not assigned to a given user’s or given account’s assigned resources; [0035] if the systems identify a call with a source IP address that is not this stored IP address, then the systems may have detected a credential not being used on the instance it was assigned to and may assume that those credentials have been compromised; [0029] further describes requests)
detecting that the originating information is indicative of a first tenancy from which the request originated; (Bengston, [0031], detect use of a credential from an IP address that is not assigned to a given user’s or a given account’s assigned resources (e.g. assigned IP block); [0048] credentials may be enforced by only allowing API calls..to succeed if they originate from a known environment; [0029] further describes requests)
identifying the original non-user entity of the cloud environment to whom the key or certificate was issued, (Bengston, [0058]-[0059] describes credentials are logged with the original server instance and later compared against use from another source)
and determining that the identified original non-user entity of the cloud environment is within the second tenancy of the cloud environment, (Bengston, [0058], FIG 5A, FIG 4, describes anomalous use of the same credentials from a different server instance/different network address with accounts in a cloud environment as disclosed in [0024], [0058]-[0059], Figures 1, 4 and 6)
Bengston fails to explicitly disclose determining that an original non-user entity of the cloud environment is located within a second tenancy of the cloud environment that is different from the first tenancy; and in response to determining that the original non-user entity is located within the second tenancy that is different from the first tenancy, detecting the anomaly associated with the originating information of the request, wherein determining that the original non-user entity of the cloud environment is located within the second tenancy comprises: accessing a key or a certificate accompanying the request; identifying the original non-user entity of the cloud environment to whom the key or the certificate was issued; and determining that the identified original non-user entity of the cloud environment is within the second tenancy of the cloud environment.
However, in an analogous art, Brandwine discloses determining that an original non-user entity of the cloud environment is located within a second tenancy of the cloud environment that is different from the first tenancy; (Brandwine in Column 8, Lines 27-65; Col. 10, Lines 25-44; FIG 1, Figure 2 describes software application 104/compute instance 116 obtains temporary security credentials 110. Application code may request that credentials be obtained before generating cloud-service requests; Col. 11, Lines 8-24; Col. 11, Lines 25-38; Col. 12, Lines 1-32, FIG 2 describe a role is an identity created in an IAM and associated with permissions. The role may be assumed by an application. Temporary security credentials for the role session are provided to the application/compute instance; Col. 1, Lines 5-20; Col. 8, Lines 9-26; Col. 20, Lines 33-39; FIG 6, step 608; Fig 7, step 712 describe security credentials are used by the cloud provider network to authenticate and authorize requests from users or applications. The second API request is successfully authenticated and authorized; Col. 3, Lines 35-65; Col. 4, Lines 1-18; Col. 20, Lines 28-32 describe temporary security credentials include access key identifier, secret access key, and a security token sometimes also referred to as a session token. The token encodes session information including expiration, owner identity, permissions and role; FIG 1, temporary credentials 110 and security token service 122; Col. 5, Lines 45-49; Col. 6, Lines 4-7 describes different accounts in a cloud environment)
and in response to determining that the original non-user entity is located within the second tenancy that is different from the first tenancy, (Brandwine in Column 8, Lines 27-65; Col. 10, Lines 25-44; FIG 1, Figure 2 describes software application 104/compute instance 116 obtains temporary security credentials 110. Application code may request that credentials be obtained before generating cloud-service requests; Col. 11, Lines 8-24; Col. 11, Lines 25-38; Col. 12, Lines 1-32, FIG 2 describe a role is an identity created in an IAM and associated with permissions. The role may be assumed by an application. Temporary security credentials for the role session are provided to the application/compute instance; Col. 1, Lines 5-20; Col. 8, Lines 9-26; Col. 20, Lines 33-39; FIG 6, step 608; Fig 7, step 712 describe security credentials are used by the cloud provider network to authenticate and authorize requests from users or applications. The second API request is successfully authenticated and authorized; Col. 3, Lines 35-65; Col. 4, Lines 1-18; Col. 20, Lines 28-32 describe temporary security credentials include access key identifier, secret access key, and a security token sometimes also referred to as a session token. The token encodes session information including expiration, owner identity, permissions and role; FIG 1, temporary credentials 110 and security token service 122; Col. 5, Lines 45-49; Col. 6, Lines 4-7 describes different accounts in a cloud environment)
detecting an anomaly associated with the originating information of the request, (Brandwine, Col. 13, Lines 9-36 describes detecting an anomaly associated with the originating information of the request)
wherein determining that the original non-user entity of the cloud environment is located within the second tenancy comprises: (Brandwine in Column 8, Lines 27-65; Col. 10, Lines 25-44; FIG 1, Figure 2 describes software application 104/compute instance 116 obtains temporary security credentials 110. Application code may request that credentials be obtained before generating cloud-service requests; Col. 11, Lines 8-24; Col. 11, Lines 25-38; Col. 12, Lines 1-32, FIG 2 describe a role is an identity created in an IAM and associated with permissions. The role may be assumed by an application. Temporary security credentials for the role session are provided to the application/compute instance; Col. 1, Lines 5-20; Col. 8, Lines 9-26; Col. 20, Lines 33-39; FIG 6, step 608; Fig 7, step 712 describe security credentials are used by the cloud provider network to authenticate and authorize requests from users or applications. The second API request is successfully authenticated and authorized; Col. 3, Lines 35-65; Col. 4, Lines 1-18; Col. 20, Lines 28-32 describe temporary security credentials include access key identifier, secret access key, and a security token sometimes also referred to as a session token. The token encodes session information including expiration, owner identity, permissions and role; FIG 1, temporary credentials 110 and security token service 122; Col. 5, Lines 45-49; Col. 6, Lines 4-7 describes different accounts in a cloud environment)
accessing a key or certificate accompanying the request; (Brandwine in Col. 9, Lines 1-18; Col. 13, Lines 1-19; FIG 2 describes that a software application may use an X.509 certificate or other authentication mechanism to authenticate to an identity provider, which obtains security credentials from the cloud provider on behalf of the software application. An API requests signed/authenticated using temporary security credentials)
identifying the original non-user entity of the cloud environment to whom the key or certificate was issued; (Brandwine discloses in Col. 11, Lines 8-24; Col. 12, Lines 20-49 credentials are provided to a software application/compute instance via role, instance metadata, security token service, or IDP)
and determining that the identified original non-user entity of the cloud environment is within the second tenancy of the cloud environment, (Brandwine, Col. 13, Lines 20-28; Col. 5, Lines 28-55 describes determining that the identified original non-user entity of the cloud environment is within the second account [second tenancy] of the cloud environment)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Brandwine with Bengston to include determining that an original non-user entity of the cloud environment is located within a second tenancy of the cloud environment that is different from the first tenancy; and in response to determining that the original non-user entity is located within the second tenancy that is different from the first tenancy, detecting the anomaly associated with the originating information of the request, wherein determining that the original non-user entity of the cloud environment is located within the second tenancy comprises: accessing a key or a certificate accompanying the request; identifying the original non-user entity of the cloud environment to whom the key or the certificate was issued; and determining that the identified original non-user entity of the cloud environment is within the second tenancy of the cloud environment. One would have been motivated to enabling software applications to obtain security credentials used to interact with a cloud provider network and, upon the revocation of an active set of security credentials used by an application to readily obtain new security credentials that the application can use to continue operation with minimal interruption (Col. 1, Lines 6-15).
Regarding claim 13, Bengston and Brandwine disclose the non-transitory computer-readable medium of claim 1.
Bengston further discloses wherein detecting the associated with the originating information of the request comprises: identifying an operation for which the non-user principal is to be used by a non-user entity from which the request is received; (Bengston, [0029], the task modification module 115 may limit the tasks that can be performed by that server instance. The tasks may be more moderately restricted from performing other tasks such as accessing private data; [0044], each API call may be evaluated by the IAM service to determine if the role attached to the cloud server 205 has permission to make that call; [0029] further describes requests)
determining that the operation is outside a set of operations permitted for the non-user from which the request is received; and (Bengston, [0029], the task modification module 115 may limit the tasks that can be performed by that server instance. The tasks may be more moderately restricted from performing other tasks such as accessing private data; [0044], each API call may be evaluated by the IAM service to determine if the role attached to the cloud server 205 has permission to make that call)
in response to determining that the operation is outside a set of operations permitted for the non-user entity from which the request is received, detecting the anomaly associated with the originating information of the request, (Bengston, [0029], the task modification module 115 may limit the tasks that can be performed by that server instance. The tasks may be more moderately restricted from performing other tasks such as accessing private data; [0044], each API call may be evaluated by the IAM service to determine if the role attached to the cloud server 205 has permission to make that call; [0031] detect use of a credential from an IP address that is not assigned to a given user’s or given account’s assigned resources; [0035] if the systems identify a call with a source IP address that is not this stored IP address, then the systems may have detected a credential not being used on the instance it was assigned to and may assume that those credentials have been compromised; [0028]-[0029] describe a request; [0029] further describes requests)
Regarding claim 14, Bengston and Brandwine disclose the non-transitory computer-readable medium of claim 1.
Bengston further discloses wherein the non-user principal is one of an instance principal, a resource principal, or a service principal to be assigned to a compute instance, a cloud resource, or a service, respectively, of the cloud environment, (Bengston, [0030], IAM role attached to cloud server instance though an instance profile, thus providing credentials to the underlying applications running on the server instance [service])
Regarding claim 15, claim 15 is a directed to a method. Claim 15 is similar in scope to claim 1 and is therefore rejected under the same rationale.
Regarding claim 16, claim 16 is a directed to the method of claim 15. Claim 16 is similar in scope to claim 6 and is therefore rejected under the same rationale.
Regarding claim 17, claim 17 is a directed to the method of claim 15. Claim 17 is similar in scope to claim 7 and is therefore rejected under the same rationale.
Regarding claim 19, claim 19 is a directed to a system. Claim 19 is similar in scope to claim 1 and is therefore rejected under the same rationale.
Regarding claim 20, Bengston and Brandwine disclose the system of claim 19.
Bengston further discloses wherein detecting an anomaly associated with the originating information of the request comprises:
determining that the originating information is indicative of a first attribute of a requesting entity from which the request originated; (Bengston, [0029] determine whether the identified network address and credentials..fit within a set of known valid addresses 114. If the network address does not match the known valid address, or if the credentials were known to have been used in association with a different server instance; [0035] source IP of requesting instance is the first attribute; stored/assigned IP of the instance to which the credential was originally locked is the second attribute; mismatch detection; [0029] further describes requests)
determining a second attribute of an original entity to which credentials, which accompanies the request, were assigned; (Bengston, [0029] determine whether the identified network address and credentials..fit within a set of known valid addresses 114. If the network address does not match the known valid address, or if the credentials were known to have been used in association with a different server instance; [0035] source IP of requesting instance is the first attribute; stored/assigned IP of the instance to which the credential was originally locked is the second attribute; mismatch detection; [0029] further describes requests)
determining a mismatch between the first attribute and the second attribute; and (Bengston, [0029] determine whether the identified network address and credentials..fit within a set of known valid addresses 114. If the network address does not match the known valid address, or if the credentials were known to have been used in association with a different server instance; [0035] source IP of requesting instance is the first attribute; stored/assigned IP of the instance to which the credential was originally locked is the second attribute; mismatch detection)
in response to determining the mismatch between the first attribute and the second attribute, detecting the anomaly associated with the originating information of the request, (Bengston, [0029] determine whether the identified network address and credentials..fit within a set of known valid addresses 114. If the network address does not match the known valid address, or if the credentials were known to have been used in association with a different server instance; [0035] source IP of requesting instance is the first attribute; stored/assigned IP of the instance to which the credential was originally locked is the second attribute; mismatch detection; [0031] detect use of a credential from an IP address that is not assigned to a given user’s or given account’s assigned resources; [0035] if the systems identify a call with a source IP address that is not this stored IP address, then the systems may have detected a credential not being used on the instance it was assigned to and may assume that those credentials have been compromised; [0028]-[0029] describe a request)
Regarding claim 21, claim 21 is a directed to the system of claim 19. Claim 21 is similar in scope to claim 5 and is therefore rejected under the same rationale.
Regarding claim 22, claim 22 is a directed to the system of claim 19. Claim 22 is similar in scope to claim 6 and is therefore rejected under the same rationale.
Regarding claim 23, claim 23 is a directed to the system of claim 19. Claim 23 is similar in scope to claim 11 and is therefore rejected under the same rationale.
Claims 12 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Bengston et al (“Bengston,” US 20190349369) in view of Brandwine et al (“Brandwine,” US 11,334,661) and further in view of Spiers et al ("Spiers," US 20140331309).
Regarding claim 12, Bengston and Brandwine disclose the non-transitory computer-readable medium of claim 1.
Bengston and Brandwine fail to explicitly disclose wherein detecting the anomaly associated with the originating information of the request comprises: determining that the originating information is indicative of a first virtual cloud network (VCN) from which the request originated; determining that an original non-user entity of the cloud environment is located within a second VCN of the cloud environment that is different from the first VCN, wherein credentials originally assigned to the original non-user entity accompanies the request or is a part of the request; and in response to determining that the original non-user entity of the cloud environment is located within the second VCN of the cloud environment that is different from the first VCN, detecting the anomaly associated with the originating information of the request.
However, in an analogous art, Spiers discloses wherein detecting the anomaly associated with the originating information of the request comprises: (Spiers describes wherein detecting an anomaly [0053] associated with originating information the request [0009])
determining that the originating information is indicative of a first virtual cloud network (VCN) form which the request originated; (Spiers, [0157], [0047] describes determining that the originating information is indicative of a first virtual cloud network form which the request originated [0009])
determining that an original non-user entity of the cloud environment is located within a second VCN of the cloud environment that is different from the first VCN, wherein credentials originally assigned to the original non-user entity accompanies the request or is a part of the request; (Spiers, [0157]-[0158], [0047] describes determining that an original non-user entity of the cloud environment is located within a second virtual cloud network of the cloud that is different from the first virtual cloud network wherein credentials are assigned to the original non-user entity accompanies the request [0058], [0161], [0094], [0009])
and in response to determining that original the non-user entity of the cloud environment is located within the second VCN of the cloud environment that is different from the first VCN, detecting the anomaly associated with the originating information of the request, (Spiers, [0094]-[0095], [0047] describes and in response to determining that the original non-user entity of the cloud environment is located within the second virtual cloud network of the cloud that is different from the first virtual cloud network, detecting an anomaly associated with the originating information of the request [0053], [0009])
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Spiers with Bengston and Brandwine to include wherein detecting the anomaly associated with the originating information of the request comprises: determining that the originating information is indicative of a first virtual cloud network (VCN) form which the request originated; determining that an original non-user entity of the cloud environment is located within a second VCN of the cloud environment that is different from the first VCN, wherein credentials originally assigned to the original non-user entity accompanies the request or is a part of the request; and in response to determining that original the non-user entity of the cloud environment is located within the second VCN of the cloud environment that is different from the first VCN, detecting the anomaly associated with the originating information of the request. One would have been motivated to create a trusted cloud environment in which a virtual machine may be instantiated, loaded, booted, and utilized (Spiers, [0009]).
Regarding claim 18, claim 18 is a directed to the method of claim 15. Claim 18 is similar in scope to claim 12 and is therefore rejected under the same rationale.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure includes the following:
US Patent Publication 20180145835 by Barbour et al discloses techniques for using short-term credentials using asymmetric session keys are described herein. A request for a short-term credential is received that is digitally signed with a different credential. In response to the request, short-term credential data is generated and populated with a public session key corresponding to a private session key. The short-term credential data is then encrypted with a session encryption key to produce the short-term credential token, which can then be used by the requester as a short-term credential for subsequent requests.
US Patent Publication 20230315840 by Cambric discloses methods, systems, apparatuses, and computer-readable storage mediums described herein are configured to detect anomalous post-authentication behavior/state change(s) with respect to a workload identity. Audit logs that specify actions performed with respect to the workload identity of a platform-based identity service, a causing state change(s), while another identity is authenticated with the platform-based identity service, are analyzed. The audit log(s) are analyzed via a model for anomaly prediction based on actions. The model generates an anomaly score indicating a probability whether a particular sequence of the actions is indicative of anomalous behavior/state change(s). A determination is made that an anomalous behavior has occurred based on the anomaly score, and when anomalous behavior has occurred, a mitigation action may be performed that mitigates the anomalous behavior.
US Patent Publication 20230195863 by Xu et al discloses a method and system for improving the security of service principals, service accounts, and other application identity accounts by detecting compromise of account credentials. Application identity accounts provide computational services with access to resources, as opposed to human identity accounts which operate on behalf of a particular person. Authentication attempt access data is submitted to a machine learning model which is trained specifically to detect application identity account anomalies. Heuristic rules are applied to the anomaly detection result to reduce false positives, yielding a compromise assessment suitable for access control mechanism usage. Embodiments reflect differences between application identity accounts and human identity accounts, in order to avoid inadvertent service interruptions, improve compromise detection for application identity accounts, and facilitate compromise containment and recovery efforts by focusing on credentials individually.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES J WILCOX whose telephone number is (571)270-3774. The examiner can normally be reached M-F: 8 A.M. to 5 P.M..
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu T. Pham can be reached on (571)270-5002.. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users.
To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JAMES J WILCOX/Examiner, Art Unit 2439
/LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439