DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Drawings
The drawings are objected to as failing to comply with 37 CFR 1.84(p)(5) because they include the following reference character(s) not mentioned in the description: 138 in Fig. 2B. Corrected drawing sheets in compliance with 37 CFR 1.121(d), or amendment to the specification to add the reference character(s) in the description in compliance with 37 CFR 1.121(b) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
The drawings are objected to as failing to comply with 37 CFR 1.84(p)(5) because they do not include the following reference sign(s) mentioned in the description in ¶49: Figure 12A, Figure 12A step 108, Figure 12A step 110. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Referring to claim 1, the claim recites the limitation: “causing, by the computing device, the data to be entered as a command to a second CLI of an isolated computing environment”. The limitation does not reasonably define what event or condition constitutes the data being “entered as a command”. Even if the data is provided to the second CLI, the claim remains ambiguous as to what specifically satisfies the limitation “entered as a command,” such that the metes and bounds are not reasonably certain. Applicant should amend the claim to recite the operation more precisely, for example by clarifying whether the data is redirected to the second CLI as command input, provided to the second CLI for processing as a command, or otherwise specifically handled. For example: insertion into an input field of the second CLI, supplied to the second CLI as command-line input, parsing/interpreting by the second CLI as a command, or for execution in the isolated computing environment. Secondly, the claim recites the limitation: “outputting, to a display device, information generated in response to the data being entered as the command to the second CLI”, treating that event as though it is clearly defined and completed. It is unclear whether the relevant triggering event is supply of the data to the second CLI, receipt by the second CLI, parsing/interpreting by the second CLI, execution of the command, or some other event. Lastly, the claim recites the element of “an isolated computing environment”, and is defined in the specification in ¶24: “The term “isolated computing environment” refers to a computing environment that is isolated from the computing environment in which the user 36 desires to paste the command into the CLI 14.”. The definition of the claim element provides no objective measure for the boundaries of isolation. Therefore, a person of ordinary skill in the art cannot determine with reasonable certainty where the boundary lies between included and excluded environments.
Claims 14 and 20 are rejected under 35 U.S.C. 112(b) for the same reasons as recited by claim 1. Claims 2-13 depend on rejected claim 1 and claims 15-19 depend on rejected claim 14, and do not overcome the deficiency raised in the rejection of their parent claims. The rejection of the dependent claims based on their dependency may be in addition to any rejections raised against the dependent claims themselves.
Referring to claim 2, the claim recites the limitation: “the clipboard comprising a temporary storage area for copying and pasting the data between applications”. It is unclear whether this is a functional limitation: wherein for example the clipboard must be used for inner application paste data transfer, or merely a description of the clipboard’s general capability. Therefore, because it is unclear whether the limitation adds a boundary to the scope of the claim, the claims metes and bounds are unclear.
Referring to claims 3, 4, 7-10, 16-18, the claims recite the claim element: “the isolated computing environment”. The claims are rejected based on the claim element for the same reasons recited in claim 1.
Referring to claim 3, the claim recites the limitation: “initiating the isolated computing environment”. For the limitation of “initiating”, the claim does not define what events constitute initiating or the temporal context required for initiating (for example: when initiation begins or ends). The claim additionally ties the limitation of “initiating” to: “subsequent to inhibiting the data from being transferred to the UI text field”, creating the necessary need to specify what events constitute “initiating” and the associated temporal context.
Referring to claim 5, the claim recites: “The method of claim 4, wherein the container is configured with a read-only file system.”. It is unclear whether this limitation means the container’s entire filesystem is read-only, or only a set of filesystems within the container are read-only.
Referring to claim 10, the claim recites the limitation “generating, by the isolated computing environment, information that identifies a result of causing the data to be entered as the command on the second CLI”. For the limitation “information that identifies a result”, the claim does not reasonably define what qualifies as a result nor what specific information must be associated with identifying the result. Secondly, the limitation: “of causing the data to be entered as the command” depends on the ambiguity issue recited in the 35 U.S.C. 112(b) rejection of claim 1.
Referring to claim 15, the claim recites the limitation: “the clipboard comprising a temporary storage area for copying and pasting the data between applications”. The claim is rejected based on this limitation for the same reasons recited in the 35 U.S.C 112(b) rejection recited in claim 2.
Referring to claim 16, the claim recites the limitation: “initiate the isolated computing environment”. The claim is rejected based on this limitation for the same reasons recited by the 35 U.S.C 112(b) initiating limitation rejection of claim 3.
Referring to claim 19, the claim recites the limitation “the display device”. Claim 19 depends on claim 14, claim 14 does not recite a display device. There is insufficient antecedent basis for this limitation in the claim.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 1, 2, 7-15, 18-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Balachandran, U.S Publication No. 2025/0370793 (hereinafter “Balachandran”) in view of Nedelcu, U.S Publication No. 2025/0265332 (hereinafter “Nedelcu”).
Referring to claim 1
Balachandran discloses, a method comprising: detecting, by a computing device (Computer System 110) , a command in a first command line interface (CLI) (Balachandran discloses a web portal containing a user interface in the form of a webpage with a command line interface for receiving user input/output (¶36, ¶43, ¶78); [0036], “An example implementation of the user interface 134 is shown in FIG. 2, discussed below. In FIG. 2, the user interface includes a text-based command line interface (CLI) for receiving commands via text input.”; “The server 130 may treat each command received through the portal 132 as a separate access request, e.g., a request to execute the command at the remote system 112. In response to an incoming command, the access control system 120 may determine which policy or policies apply to the command [0044], Balachandran discloses “When the user submits a command (e.g., by pressing the “Enter” key on a keyboard to transition the CLI 230 to a new command line);
causing, by the computing device, the data to be entered as a command to a second CLI of an isolated computing environment (Balachandran discloses routing the inputted command from the CLI in the user interface of the web portal to a remote system for execution as the second CLI (¶24, ¶36, ¶78, ¶85, [0044] “When the user submits a command (e.g., by pressing the “Enter” key on a keyboard to transition the CLI 230 to a new command line”; Balachandran discloses that the remote system contains a CLI for execution in ¶30 by disclosing: “Some users may be able to access the remote system 112 directly, for example, by logging in to establish a terminal session”. Balachandran further discloses that the remote system in which commands are executed has one or more machine components (abstract, ¶23, ¶28, ¶44 ¶79), wherein a machine component includes a virtual machine (¶29), which meets the limitation of an isolated computing environment; For example, the CLI 230 may be substantially similar or identical in appearance to a CLI that would be presented to a user logged directly into the remote system 112. “ the user may not even be aware that they are interacting with the computer system 110 rather than the remote system 112”.);
outputting, to a display device, information generated in response to the data being entered as the command to the second CLI (Balachandran discloses that after the command is executed in the remote system, the system can communicate the command execution result back to the user interface CLI of the web portal (¶44, ¶85).)
Balachandran does not disclose, but Nedelcu discloses:
a method comprising: detecting, by a computing device, a paste command to transfer data to a user interface (UI) text field (Nedelcu teaches a cybersecurity data loss prevention service containing a browser extension configured to detect a paste operation associated with a browsers clipboard event for a user’s text input (abstract, ¶3, ¶15, ¶27, ¶30, ¶46)); inhibiting, by the computing device, the data from being transferred to the UI text field (Nedelcu teaches the cybersecurity data loss prevention service may cause the browser extension to block the clipboard event associated with the paste operation for text insertion from the user’s browser input to prevent possible data exfiltration (abstract, ¶3, ¶15, ¶21, ¶27, ¶30, ¶46).);
It would have been obvious before the effective filing date of the invention to modify Balachandran by combining Balachandran’s remote command execution environment containing a communication stream of a first UI CLI and a remote system CLI, with Nedelcu’s detecting/intercepting mechanism and asynchronous evaluation of the clipboard paste command data. A person of ordinary skill in the art would have been motivated since the combination would have enhanced command line security by using the cybersecurity agents evaluation decision taught by Nedelcu blocking potentially malicious commands before execution and allowing permitted commands to proceed, which yields predictable results. Furthermore, the combination of prior art elements according to known methods yield predictable results with the teachings of Nedelcu (see M.P.E.P. 2143(I)(A)).
Referring to claim 2, the previously cited combination of Balachandran in view of Nedelcu teaches the method of claim 1, wherein detecting the paste command comprises detecting a request to transfer the data from a clipboard, the clipboard comprising a temporary storage area for copying and pasting the data between applications. (Nedelcu teaches in ¶49 reading exfiltration events such as data to be pasted are stored in memory allocated to the browser application. Nedelcu teaches in ¶27, when the user initiates clipboard events like “paste” both the browser extension and the cybersecurity agent “recognize and interpret the clipboard event 100”. Nedelcu further teaches in ¶30 “the browser extension 70 captures the text 112 from a paste payload associated with the clipboard event 100”.)
Referring to claim 7, the previously cited combination of Balachandran in view of Nedelcu teaches the method of claim 1, wherein the isolated computing environment comprises a virtual machine. (Balachandran discloses that the remote system in which commands are executed has one or more machine components (abstract, ¶23, ¶28, ¶44 ¶79), wherein a machine component includes a virtual machine (¶29).)
Referring to claim 8, the previously cited combination of Balachandran in view of Nedelcu teaches the method of claim 1, wherein causing the data to be entered as the command further comprises: providing the data to the second CLI of the isolated computing environment. (As recited by the causing limitation of claim 1, Balachandran teaches routing the command from the user interface CLI in the web portal to the remote system for execution, wherein the remote system has one or more machine components including a virtual machine [0044]])
Referring to claim 9, the previously cited combination of Balachandran in view of Nedelcu teaches the method of claim 8, further comprising executing the command within the isolated computing environment (As recited by the causing limitation of claim 1, Balachandran teaches that the user inputted command of the CLI from the user interface of the web portal is sent to a remote system capable of including a virtual machine for executing the command [0044])
Referring to claim 10, the previously cited combination of Balachandran in view of Nedelcu teaches the method of claim 1, further comprising: generating, by the isolated computing environment, information that identifies a result of causing the data to be entered as the command on the second CLI; and providing, by the isolated computing environment to the first CLI, the information (As recited in the 103 rejection for claim 1, Balachandran teaches that after the command is executed in the remote system, the system can communicate the command execution result back to the user interface CLI of the web portal (¶44, ¶85).)
Referring to claim 11
the previously cited combination of Balachandran in view of Nedelcu teaches the method of claim 1, wherein outputting, to the display device, the information generated in response to the data being entered as the command further comprises: generating a prompt that includes a first option and a second option; and outputting the prompt to the display device. (Balachandran teaches a confirmation prompt in a CLI where when a Boolean variable is set to true as a configuration option for the CLI, the user will be prompted with a confirmation message (“yes/no question”) indicating if they wanted to execute that command (¶60).)
The previously cited combination of Balachandran in view of Nedelcu does not teach, but Nedelcu further discloses:
to transfer the data to the UI text field first and to not transfer the data to the UI text field (Nedelcu teaches the browser extension injects “isolated world content scripts” (IWCS), which send the duplicated copy of the intercepted clipboard event data as an exfiltration event to the cybersecurity agent (¶23). The cybersecurity agent evaluates the exfiltration event based on a data loss prevention policy and communicates an “ALLOW/BLOCK” decision to the IWCS, determining whether to trigger the clipboard event (¶52).)
It would have been obvious before the effective filing of the invention to modify the previously cited combination of Balachandran in view of Nedelcu by combining prior art elements according to known methods to yield predictable results with the additional teachings of Nedelcu. A person of ordinary skill in the art would have recognized to combine Nedelcu’s cybersecurity agent paste command evaluation decision of allow/block as an output associated with Balachandran’s confirmation prompt in Balachandran’s first UI CLI. Providing the user with a confirmation prompt in the UI CLI with the additional context of the cybersecurity agents evaluation decision of allow/block before the command execution result is routed/outputted back to the first CLI would provide a more enhanced security system, ensuring the user validates the integrity of the command to be pasted.
Referring to claim 12
The previously cited combination of Balachandran in view of Nedelcu teaches:
the method of claim 11, further comprising: receiving user input selecting the first option; and in response to the user input (Balachandran teaches the limitation of “receiving user input selecting the first option” via the confirmation prompt in a CLI as recited by the 103 rejection of claim 11. Balachandran teaches the additional limitation: “in response to user input” in ¶60: “For example, if the user enters “no”, then the command may be rejected.”)
executing the paste command to transfer the data to the UI text field (Nedelcu teaches in ¶52: “If, however, the IWCS receives an ALLOW from the cybersecurity agent 50 (e.g., Block 214), then for paste events the exfiltration decision 88 triggers a paste command”).
Referring to claim 13,
The previously cited combination of Balachandran in view of Nedelcu teaches:
the method of claim 11, further comprising: receiving user input selecting the second option; and in response to the user input (Balachandran teaches this limitation as recited by the 103 rejection of claim 12.)
inhibiting the paste command from transferring the data to the UI text field (Nedelcu teaches in ¶52: “if the cybersecurity agent 50 blocks the exfiltration, IWCS receives a BLOCK and the exfiltration/clipboard event 74/100 is confirmed denied and blocked”).
Regarding claim 14 and claim 20, claim 14 and claim 20 recite similar limitations specified in claim 1 and are rejected for the same reasons recited in the 103-rejection of claim 1.
Regarding claim 15, the claim recites similar limitations as claim 2 and is rejected for the same reasons specified in the 103-rejection of claim 2.
Regarding claim 18, the claim recites similar limitations as claim 10 and is rejected for the same reasons specified in the 103-rejection of claim 10.
Regarding claim 19, the claim recites similar limitations as claim 11 and is rejected for the same reasons specified in the 103-rejection for claim 11.
Claim(s) 3-6, 16, 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Balachandran, U.S Publication No. 2025/0370793 (hereinafter “Balachandran”), in view of Nedelcu, U.S Publication No. 2025/0265332 (hereinafter “Nedelcu”), and further in view of Stopel, U.S Publication No. 2024/0338460 (hereinafter “Stopel”).
Regarding claim 3, the previously cited combination of Balachandran in view of Nedelcu teaches the method of claim 1.
The previously cited combination of Balachandran in view of Nedelcu does not teach:
further comprising: subsequent to inhibiting the data from being transferred to the UI text field, initiating the isolated computing environment.
However, in an analogous art, Stopel teaches: subsequent to inhibiting the data from being transferred to the UI text field, initiating the isolated computing environment (In ¶78 Stopel teaches initiating an app container “upon receiving an event indicative of instantiation”. In ¶2 Stopel teaches “a software container is an instance of a user-space running an application within the operating system (OS) of a host device”. Further in ¶31 that the host device can be a virtual machine).
It would have been obvious before the effective filing of the invention to modify Balachandran by use of known technique to improve similar devices (methods, or products) in the same way (see M.P.E.P. 2143(I)(C)) with the teachings of Nedelcu and the teachings of Stopel. A person of ordinary skill in the art would have recognized incorporating Stopel’s containerized execution environment into Balachandran’s virtual machine isolated computing environment would predictably improve isolation and result in a more robust and secure execution environment for sending the intercepted paste command data to, wherein the data is detected/inhibited using the detecting/intercepting mechanism taught by Nedelcu.
Regarding claim 4, the previously cited combination of Balachandran in view of Nedelcu and Stopel teaches the method of claim 3, wherein the isolated computing environment comprises a container (Stopel teaches ¶2, “a software container)
Regarding claim 5, the previously cited combination of Balachandran in view of Nedelcu and Stopel teaches the method of claim 4, wherein the container is configured with a read-only file system. (Stopel teaches in ¶6: “The software container 200 includes a base image 210 … The base image 210 includes one or more image layers 215-1 through 215-q … The layers 215 are read-only layers that represent filesystem differences … the layers 215 are stacked on top of each other to form a base for the container's 200 root filesystem … the layers 215 are read only”.)
Regarding claim 6, the previously cited combination of Balachandran in view of Nedelcu and Stopel teaches the method of claim 4, wherein the container is initiated with a sandboxing mechanism that intercepts application system calls made by the container. (Stopel teaches in ¶59 “the detector container 315 is configured to monitor events (or system calls) indicative of instantiation, running, or both, of a new APP container”. Further in ¶60: “the detector container 315 may proxy any communication between the client and daemon programs of an APP container 311. The intercepted communications may include, for example, system calls, access to the filesystem, access to network resource, execution of processes, and so on. Each intercepted communication is analyzed to detect an attempt by the APP container 311-C”.)
Regarding claim 16, the claim recites similar limitations as claim 3 and is rejected for the same reasons specified in the 103-rejection for claim 3.
Regarding claim 17, the claim recites similar limitations as claim 4 and is rejected for the same reasons specified in the 103-rejection for claim 4.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20250373642 A1 discloses a cybersecurity service for command line interpretation that uses a machine learning model to make a prediction for assessing command line commands as malicious or benign. WO 2024170064 A1 discloses a secure computing environment configured for operators to receive command input and evaluate the safety of a command before execution. US 11038847 B1 discloses a message gateway authentication service that creates a secure channel between a client device including a CLI and a computing instance including a virtual machine that processes the client device input commands and routes the results back to the client device as output. US 20250004807 A1 discloses a computer program configured to intercept an instruction originating from a cluster, wherein the instruction includes a command line command and wherein the cluster contains nodes including a virtual machine and the nodes are capable of containing pods including a container.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to NOAH J KAISER whose telephone number is (571)272-8906. The examiner can normally be reached M-F: 10:00 a.m-6:00 p.m.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Alexander Lagor can be reached at 571-270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and hhttps://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/N.J.K./
Examiner, Art Unit 2437
/ALEXANDER LAGOR/Supervisory Patent Examiner, Art Unit 2437