DETAILED ACTION
Claims 1-20 are presented for consideration.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Martinez et al. [ US Patent Application No 2012/0185913 ], in view of Hadar et al. [ US Patent Application No 2013/0291052 ].
As per claim 1, Martinez discloses the invention as claimed including a system comprising:
a server system comprising one or more processors in communication with one or more memory devices, the server system configurable to cause:
obtaining a cloud-independent representation of network security information [ i.e. allows developer to define security zone and to apply at least one type of security policy ] [ Abstract; and paragraphs 0023, 0035, and 0078 ],
generating, based on the cloud-independent representation, by an executable policy builder having a plurality of different cloud-specific controls, a plurality of different policy sets [ i.e. policy engine allows policies to be created, policies could be access control policies, firewall policies ] [ paragraphs 0075, and 0078 ], each policy set being specific to a respective one of a plurality of different clouds of different cloud providers [ i.e. abstraction layers allow for integration with application programming interfaces made available by different vendors ] [ paragraphs 0074, 0084, 0094, and 0095 ],
sending, using a policy deployer having a cloud-specific configuration tool [ i.e. visual policy editor or XML editor ] [ Figure 9B; and paragraphs 0010, 0078, and 0112 ], the cloud-specific policy sets to the respective clouds [ i.e. cloud model utilized by the adapter to translate the management instruction to the (target) cloud API call, and cloud service bus routes the instructions to Amazon, EC2 ] [ Figure 2B; and paragraphs 0010, 0083, 0085, and 0086 ], and
monitoring deployment of one or more of the sent cloud-specific policy sets [ i.e. management module monitors cloud computing resource of the cloud-computing service through the adapter and provisions the cloud computing resource according to the policy engine module ] [ paragraphs 0017, 0104, and 0119 ].
Martinez does not specifically disclose
the monitoring comprising detecting a change between a sent cloud-specific policy set and a different policy set deployed at a respective cloud.
Hadar disclose
the monitoring comprising detecting a change between a sent cloud-specific policy set and a different policy set deployed at a respective cloud [ i.e. compliance status may be determined by comparing how a deployed cloud computing component should have been configured and comparing that to the actual configuration of the deployed cloud computing component [ paragraphs 0031, 0032, 0034 and 0044 ].
It would have been obvious to a person skill in the art before the effective filing date of the claimed invention to combine the teaching of Martinez and Hadar because the teaching of Hadar would enable to help secure a grid cloud by adding security policy instantiation at an infrastructure design stage, among other measures [ Hadar, paragraph 0002 ].
As per claim 2, Martinez discloses wherein the monitoring further comprises one or more of: obtaining deployment status information indicating success or an error in the deployment, obtaining resource status information indicating status of one or more computing resources in the respective cloud, generating a notification message indicating the change, or sending to the respective cloud a request message that the change be reverted [ i.e. alert, notification ] [ paragraphs 0035, and 0115 ].
As per claim 3, Martinez discloses verifying deployment of a cloud-specific policy set to a respective cloud [ i.e. verified and validated before published for use ] [ paragraphs 0059, and 0067 ].
As per claim 4, Martinez discloses wherein the network security information comprises one or more of: a set of security policies indicating permitted communications between or among computing resources, subnet data, Internet Protocol (IP) address allocation data, service data, workload data, security group data, security zone data, or access policy data [ i.e. security zone, ACL list ] [ Abstract; and paragraphs 0078, and 0095 ].
As per claim 5, Martinez discloses the policy deployer being associated with a deployment pipeline to a cloud, the policy deployer being configurable to process a cloud-specific policy set, the cloud-specific policy set comprising cloud-specific configuration data comprising one or more of: computing resource data or container data [ i.e. API for a target cloud-computing resource ] [ Figure 2B; and paragraphs 0082, 0083, and 0085 ].
As per claim 6, Martinez discloses wherein the cloud-independent representation specifies one or more functional domains for an instance of a data center, each functional domain comprising one or more of: security groups of computing services, one or more subnets, one or more ingress rules, or one or more egress rules [ i.e. groups of users, enterprise, department within enterprise, and firewall rules ] [ paragraphs 0090, 0095, and 0129 ].
As per claim 7, Martinez discloses wherein a cloud-specific policy set specifies one or more of: an instance of a data center, one or more computing resources, security data, one or more subnets, one or more ingress rules, or one or more egress rules [ i.e. monitoring of running instances ] [ paragraphs 0067, 0092, and 0115 ].
As per claims 8-14, they are rejected for similar reasons as stated above in claims 1-7.
As per claims 15-20, they are rejected for similar reasons as stated above in claims 1-6.
Response to Arguments
Applicant's arguments filed 04/03/2026 have been fully considered but they are not persuasive.
As per remarks, Applicants argued that (1) Martinez fails to disclose or suggest a policy builder that is capable of generating a plurality of different policy sets, where each policy set is specific to a respective one of a plurality of different clouds of different cloud providers.
As to point (1), Examiner respectfully disagrees because Martinez discloses a visual policy editor which provides easy-to-use graphical user interface to feature-rich and extensible policy engine, policies could be access control policies, firewall policies, access control policies could be defined by cloud or other service providers [ i.e. broadly interpret as generating a plurality of different policy data, and each policy set is specific to a respective one of a plurality of different clouds of different cloud providers as claimed ] [ paragraphs 0074, 0078, 0084, and 0095 ].
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Ashley et al. [ US Patent No 9,609,023 ] discloses system for software defined deployment of security appliances using policy template
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DUSTIN NGUYEN whose telephone number is (571)272-3971. The examiner can normally be reached Monday-Friday 9-6 PST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Brian Gillis can be reached at 571-2727952. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DUSTIN NGUYEN/Primary Examiner, Art Unit 2446