CTNF 18/919,586 CTNF 81070 DETAILED ACTION Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. Claims 1-20 are pending. Double Patenting 08-33 AIA The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg , 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman , 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi , 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum , 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel , 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington , 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA/25, or PTO/AIA/26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. 08-34 AIA Claim s 1, 6, 11 and 16 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim s 1 and 12 of U.S. Patent No. 11,595,401 . Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the present application are anticipated by the claims of the ‘401 patent. See the chart below for comparison . 18/919,586 U.S. Patent No. 11,595,401 1. A computer-implemented method executed by data processing hardware that causes the data processing hardware to perform operations comprising: assigning a plurality of workloads to an isolated secure compute environment on a distributed computing system based on respective security criteria for each of the plurality of workloads, the isolated secure compute environment isolated from one or more other isolated secure compute environments on the distributed computing system; and while executing the plurality of workloads in the isolated secure compute environment on the distributed computing system: determining resource utilization for the isolated secure compute environment; and adjusting, using the determined resource utilization, a number of computing resources assigned to the isolated secure compute environment. 6. The computer-implemented method of claim 1, wherein the operations further comprise, for each particular workload, identifying, using a security level of the particular workload, one or more of the isolated secure compute environments that are eligible for executing the particular workload. 1. A computer-implemented method when executed by data processing hardware causes the data processing hardware to perform operations comprising: receiving a plurality of workloads, each workload associated with respective security criteria and scheduled for execution on a distributed computing system, the distributed computing system divided into a plurality of security rings, each security ring of the plurality of security rings associated with a respective subset of computing devices of the distributed computing system that is physically isolated from the respective subset of computing devices of the distributed computing system associated with each other security ring of the plurality of security rings; and for each respective workload of the plurality of workloads: determining, using the respective security criteria, a security level of the respective workload; identifying, using the security level of the respective workload, one or more of the plurality of security rings that are eligible for executing the respective workload; and executing the respective workload on one or more computing devices selected from one of the respective subsets of computing devices associated with the identified one or more of the plurality of security rings eligible for executing the respective workload. 11. A system comprising: data processing hardware; and memory hardware in communication with the data processing hardware, the memory hardware storing instructions that, when executed on the data processing hardware, cause the data processing hardware to perform operations comprising: assigning a plurality of workloads to an isolated secure compute environment on a distributed computing system based on respective security criteria for each of the plurality of workloads, the isolated secure compute environment isolated from one or more other isolated secure compute environments on the distributed computing system; and while executing the plurality of workloads in the isolated secure compute environment on the distributed computing system: determining resource utilization for the isolated secure compute environment; and adjusting, using the determined resource utilization, a number of computing resources assigned to the isolated secure compute environment. 16. The system of claim 11, wherein the operations further comprise, for each particular workload, identifying, using a security level of the particular workload, one or more of the isolated secure compute environments that are eligible for executing the particular workload. 12. A system comprising: data processing hardware; and memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising: receiving a plurality of workloads, each workload associated with respective security criteria and scheduled for execution on a distributed computing system, the distributed computing system divided into a plurality of security rings, each security ring of the plurality of security rings associated with a respective subset of computing devices of the distributed computing system that is physically isolated from the respective subset of computing devices of the distributed computing system associated with each other security ring of the plurality of security rings; and for each respective workload of the plurality of workloads: determining, using the respective security criteria, a security level of the respective workload; identifying, using the security level of the respective workload, one or more of the plurality of security rings that are eligible for executing the respective workload; and executing the respective workload on one or more computing devices selected from one of the respective subsets of computing devices associated with the identified one or more of the plurality of security rings eligible for executing the respective workload . 08-34 AIA Claim s 1 and 11 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim s 1 and 11 of U.S. Patent No. 12,137,101 . Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the present application are anticipated by the claims of the ‘101 patent. See the chart below for comparison . 18/919,586 U.S. Patent No. 12,137,101 1. A computer-implemented method executed by data processing hardware that causes the data processing hardware to perform operations comprising: assigning a plurality of workloads to an isolated secure compute environment on a distributed computing system based on respective security criteria for each of the plurality of workloads, the isolated secure compute environment isolated from one or more other isolated secure compute environments on the distributed computing system; and while executing the plurality of workloads in the isolated secure compute environment on the distributed computing system: determining resource utilization for the isolated secure compute environment; and adjusting, using the determined resource utilization, a number of computing resources assigned to the isolated secure compute environment. 1. A computer-implemented method when executed by data processing hardware causes the data processing hardware to perform operations comprising: receiving a plurality of workloads for execution on a distributed computing system, each respective workload associated with respective security criteria, the distributed computing system divided into a plurality of security rings, each security ring of the plurality of security rings associated with a respective subset of computing devices of the distributed computing system that is physically isolated from the respective subset of computing devices of the distributed computing system associated with each other security ring of the plurality of security rings; executing each respective workload of the plurality of workloads on the distributed computing system based on the respective security criteria; and while executing the plurality of workloads, for a respective security ring of the plurality of security rings: determining resource utilization for the respective subset of computing devices associated with the respective security ring; and adjusting, using the determined resource utilization, a number of computing devices in the respective subset of computing devices associated with the respective security ring. 11. A system comprising: data processing hardware; and memory hardware in communication with the data processing hardware, the memory hardware storing instructions that, when executed on the data processing hardware, cause the data processing hardware to perform operations comprising: assigning a plurality of workloads to an isolated secure compute environment on a distributed computing system based on respective security criteria for each of the plurality of workloads, the isolated secure compute environment isolated from one or more other isolated secure compute environments on the distributed computing system; and while executing the plurality of workloads in the isolated secure compute environment on the distributed computing system: determining resource utilization for the isolated secure compute environment; and adjusting, using the determined resource utilization, a number of computing resources assigned to the isolated secure compute environment. 11. A system comprising: data processing hardware; and memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising: receiving a plurality of workloads for execution on a distributed computing system, each respective workload associated with respective security criteria, the distributed computing system divided into a plurality of security rings, each security ring of the plurality of security rings associated with a respective subset of computing devices of the distributed computing system that is physically isolated from the respective subset of computing devices of the distributed computing system associated with each other security ring of the plurality of security rings; executing each respective workload of the plurality of workloads on the distributed computing system based on the respective security criteria; and while executing the plurality of workloads, for a respective security ring of the plurality of security rings: determining resource utilization for the respective subset of computing devices associated with the respective security ring; and adjusting, using the determined resource utilization, a number of computing devices in the respective subset of computing devices associated with the respective security ring . Claim Rejections - 35 USC § 103 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-21-aia AIA Claim s 1-3, 6-13 and 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over US 9,069,599 to Martinez et al., and further in view of US 9,009,294 to Dawson et al . Regarding claim 1, Martinez teaches a computer-implemented method executed by data processing hardware that causes the data processing hardware to perform operations comprising: assigning a plurality of workloads to an isolated secure compute environment on a distributed computing system based on respective security criteria for each of the plurality of workloads (Abstract and col. 6, line 5: teaches associating a security policy with a software workload. Martinez teaches allowing to define a “security zone” (isolated secure compute environment) and applying security policies (criteria) so the workload is assigned to the appropriate zone), the isolated secure compute environment isolated from one or more other isolated secure compute environments on the distributed computing system (col. 11, line 12: platform 20 may reside on a client network 31 or separate from a client network 31. Col. 26, line 56: each computing workflow can be separated into a set of distinct workloads, each workload having requirements such as input, storage, processing, output, and the like.); and while executing the plurality of workloads in the isolated secure compute environment on the distributed computing system (col. 7, line 45: a plurality of computer workloads to perform the computing workflow. col. 25, line 50: a cloud-computing resource from the plurality of cloud-computing resources to perform a computer workload): determining resource utilization for the isolated secure compute environment (col. 24, line 50: policy engine 603 instructs action engine 606 to issue management actions to provisioning module 106 (e.g., issue management actions to increase or decrease the number of cloud-computing resources based on CPU utilization of the existing resources… a plurality of computer workloads to perform the computing workflow). Martinez lacks or does not expressly disclose adjusting, using the determined resource utilization, a number of computing resources assigned to the isolated secure compute environment. However, Dawson teaches adjusting, using the determined resource utilization, a number of computing resources assigned to the isolated secure compute environment (col. 3, line 1-40 teaches dynamic resource allocation and dynamically scaling computing resources based on the monitoring). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Martinez with Dawson to include adjusting a number of computing resources in order to maintain performance and efficiency, as taught by Dawson. Regarding claims 2-3. Martinez lacks or does not expressly disclose moving a computing resource. However, Dawson teaches wherein adjusting the number of computing resources assigned to the isolated secure compute environment comprises moving a computing resource from the isolated secure compute environment to a different isolated secure computing environment (col. 8, lines 26-32: provision software (modify existing or install new, this may include installing the Cloud software and middleware itself); suspend low priority jobs currently executing on the Cloud; dynamically move jobs currently executing on the Cloud (within the current Cloud, to an alternate Cloud or an alternate non-Cloud environment); and/or temporarily borrow resources from another Cloud.); wherein adjusting the number of computing resources assigned to the isolated secure compute environment comprises moving a computing resource from a different isolated secure compute environment to the isolated secure compute environment (Fig. 4, In step S2, an evaluation module receives the requirements data from step S1, and analyzes the current state of the Cloud against the requirements. In step S3, a determination is made whether or not a state change is required/desired within the Cloud.). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Martinez with Dawson to include moving a computing resource in order to pull idle resources from one zone and push them to an over-utilized zone, as taught by Dawson. Regarding claim 6, Martinez, as modified above, further computer-implemented method of claim 1, wherein the operations further comprise, for each particular workload, identifying, using a security level of the particular workload, one or more of the isolated secure compute environments that are eligible for executing the particular workload (col. 25, lines 22-30: governor module 103 utilizes instance placement 627 to make decisions on where to place an instance of a cloud-computing resource. For example, when an image is built for a cloud-computing service using a builder module, it can be tagged (e.g., using a metamodel) to prevent deployment to certain zones (e.g., security zone) as part of a security policy, cost control policy, performance or availability management policy.). Regarding claim 7, Martinez, as modified above, further computer-implemented method of claim 1, wherein: each isolated secure compute environment is associated with a corresponding security requirement; and each computing resource assigned to a particular isolated secure compute environment complies with the corresponding security requirement of the particular isolated secure compute environment (col. 25, lines 29-37: Instance placement 627 may cause the governor module 103 to place an instance of a cloud-computing resource based on availability of client-computing resources, or (real-time) performance of particular clouds. Virtual Machine (VM) lifecycle management 624 may be utilized by governor module 103 to determine and enforce expiration of virtual machines Auto-scale 621 may be utilized by governor module 103 to scale computer workloads being performed on one or more a cloud-computing resources). Regarding claim 8, Martinez, as modified above, further computer-implemented method of claim 7, wherein the corresponding security requirement for a particular isolated secure compute environment comprises a different level of physical security or a different level of logical security than the other isolated secure compute environments (col. 26, line 59: Each computing workload may have policy and metadata information stored by the system that includes what computing workload it is, how the computing workload is used, how quickly the computing workload needs to be performed, and the like. Each computing workload is instantiated through a customizable workflow. For example, a computing workload may require approval by a business unit, development team, quality assurance team, and an operations team. The workflow in this example would then be instantiated to solicit approval of requirements defined by each workload from each team.). Regarding claim 9, Martinez, as modified above, further computer-implemented method of claim 1, wherein: each isolated secure compute environment is associated with a corresponding security requirement; and each workload assigned to a particular isolated secure compute environment complies with the corresponding security requirement of the particular isolated secure compute environment (col. 23, lines 35-45: once a user is successfully authenticated using identity store 415, identity module 29 redirects that user's credentials to the cloud-computing service for authentication. Once the cloud-computing service successfully authenticates the user based on the forwarded user credentials, the user is redirected to the logged in cloud-computing service. It should be noted that identity capabilities may be applied to a cloud-computing resource as well as to a user, such that a specific cloud-computing resource may be authorized (based on its identity) to be used in connection with execution of a computer workload. Col. 5, line 63: a security zone may be defined as a specified virtual private network (VPN) or a specified physical network of a business enterprise, such that computer workloads being performed by a cloud-computing resource operating in that zone may be modified only by users who have specified authorization credentials issued by that enterprise. Among some embodiments, a security zone may be defined as cloud-computing resources (public or private) that are physically located in a geographical area, such as the United States, allowing a security policy to be applied that prohibits export of data that is to be associated with computer workloads executed in that security zone. In other embodiments, the policies are defined and implemented on the firewalls through a central policy server.). Regarding claim 10, Martinez, as modified above, further computer-implemented method of claim 1, wherein the operations further comprise: obtaining a set of parameters characterizing a security posture of a particular computing resource; and assigning, using the set of parameters, the particular computing resource to one of the isolated secure compute environments (col. 20, line 26: the platform 20 may provide for end-to-end security across internal and external clouds, such as including secure data in transit from the platform to external clouds, secure access for users, secure encryption keys, secure logs for auditing, secure instances from breaches, secure data in storage, and the like. The platform may provide for comprehensive security capabilities designed for agile IT operating models, such as for network security, instance security, data security, access security, and the like. For instance, network security may include an encrypted overlay network across multiple clouds and enterprise data centers, firewall integration with support for multicast, static IP management, point-to-point routing, and the like. Instance security may include images with pluggable host-based intrusion detection systems and virus scanning, and the like. Col. 25, line 38: Auto-scale 621 can add or remove instances of cloud-computing resources to increase or decrease the performance of computer workloads based on monitored resource consumption, a schedule, or a set of rules. Availability & disaster recovery 618 may be utilized when operation of a cloud-computing resource has failed and the failed cloud-computing resource must be recovered according to the constraints, conditions, or policies governed by governor module 103.). As per claims 11-13 and 16-20, this is a system version of the claimed method discussed above in claims 1-3 and 6-10 wherein all claimed limitations have also been addressed and/or cited as set forth above . 07-22-aia AIA Claim s 4-5 and 14-15 are rejected under 35 U.S.C. 103 as being unpatentable over US 9,069,599 to Martinez et al., and further in view of US 9,009,294 to Dawson et al , as applied to claim s 1 and 11 above and further in view of US 2021/0209684 to Foote et al . Regarding claim 4, Martinez, lacks or does not expressly disclose sanitizing a rserouce. However, Foot teaches wherein moving the computing resource to the isolated secure compute environment comprises sanitizing the moved computing resource, wherein sanitizing the moved computing resources comprises performing a memory wipe of the moved computing resources (0135: he malicious code from the electronic communication to create a sanitized electronic communication, wherein the extracting comprises scanning the communication for an identified beginning malicious code marker, flagging each scanned byte between the beginning marker and a successive end malicious code marker, continuing scanning until no further beginning malicious code marker is found, and creating a new data file by sequentially copying all non-flagged data bytes into a new file that forms a sanitized communication file; transferring the sanitized electronic communication to the non-quarantine sector of the memory; and deleting all data remaining in the quarantine sector.). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Martinez, as modified above, with Foote to include sanitizing a resource in order to prevent malicious code, as taught by Foote, 0135. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to AUBREY H WYSZYNSKI whose telephone number is (571)272-8155. The examiner can normally be reached M-F 9-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AUBREY H WYSZYNSKI/ Primary Examiner, Art Unit 2434 Application/Control Number: 18/919,586 Page 2 Art Unit: 2434 Application/Control Number: 18/919,586 Page 3 Art Unit: 2434 Application/Control Number: 18/919,586 Page 4 Art Unit: 2434 Application/Control Number: 18/919,586 Page 5 Art Unit: 2434 Application/Control Number: 18/919,586 Page 6 Art Unit: 2434 Application/Control Number: 18/919,586 Page 7 Art Unit: 2434 Application/Control Number: 18/919,586 Page 8 Art Unit: 2434 Application/Control Number: 18/919,586 Page 9 Art Unit: 2434 Application/Control Number: 18/919,586 Page 10 Art Unit: 2434 Application/Control Number: 18/919,586 Page 11 Art Unit: 2434 Application/Control Number: 18/919,586 Page 12 Art Unit: 2434 Application/Control Number: 18/919,586 Page 13 Art Unit: 2434 Application/Control Number: 18/919,586 Page 14 Art Unit: 2434 Application/Control Number: 18/919,586 Page 15 Art Unit: 2434 Application/Control Number: 18/919,586 Page 16 Art Unit: 2434 Application/Control Number: 18/919,586 Page 17 Art Unit: 2434 Application/Control Number: 18/919,586 Page 18 Art Unit: 2434 Application/Control Number: 18/919,586 Page 19 Art Unit: 2434 Application/Control Number: 18/919,586 Page 20 Art Unit: 2434 Application/Control Number: 18/919,586 Page 21 Art Unit: 2434 Application/Control Number: 18/919,586 Page 22 Art Unit: 2434