DETAILED ACTION
This action is responsive to the pending claims, 1-20, received 13 January 2025. Accordingly, the detailed action of claims 1-20 is as follows:
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 01/02/2025; 09/08/2025 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by the examiner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-3, 7, 9-11, 15, 17-19 rejected under 35 U.S.C. 103 as being unpatentable over Wagner (US 20160092252 A1, hereafter referred to as Wagner) in view of Potter et al (US 20120210333 A1, hereafter referred to as Potter).
Regarding claim 1, Wagner teaches a method comprising:
providing a virtualization environment comprising a plurality of virtual machines (Wagner [0014] teaches virtual machine instances in a virtual compute system), each virtual machine comprising an operating system for hosting a respective container in an isolated execution environment (Wagner [0014] teaches the virtual machine instances have software components including operating systems and isolated containers created on the virtual machine instances);
receiving a request to execute a computer routine associated with an application written in an arbitrary programming language (Wagner [0064, 0026 and 0062] teaches receiving a request to execute or deploy a user code written in a program language [0062, 0064, 0052]);
providing, based at least in part on the request and at a virtual machine of the plurality of virtual machines, a container in which to execute the computer routine in an isolated environment (Wagner [0040, 0057 and 0070] teaches pulling a new virtual machine instance from a warming pool, assigning the instance to the user associated with the request and creating a new container on the instance for isolated virtual compute system execution [0037]), wherein the container includes dependencies for executing the computer routine (Wagner [0070] teaches language runtimes and libraries used to run the user’s code loaded into the virtual machine container based on the configuration information associated with the request);
assigning, to the container and based at least in part on the operating system of the virtual machine, virtualized computing resources (Wagner [0070] teaches reserving a portion of the virtual machine instance’s resources and creating a container that meets the resource requirements [0066]);
executing, in the container, the computer routine (Wanger [0059]); and
discarding, upon completion of execution of the computer routine, the computer routine in the container (Wagner [0045 and 0059] teaches automatically releasing a container after the user code has finished executing in the container).
However, Wagner does not explicitly teach wherein the isolated execution environment prevents a first computer routine in a first container at a first virtual machine from accessing a second computer routine in a second container at a second virtual machine; discarding, the computer routine in the container to prevent persistent storage of the computer routine on the virtual machine.
Potter, in an analogous art teaches wherein the isolated execution environment prevents a first computer routine in a first container at a first virtual machine from accessing a second computer routine in a second container at a second virtual machine (Potter [0050] teaches providing containers with their own private kernel namespaces, file system and display server to provide isolation at the process, file system and display level such that individual applications run in parallel with separate containers)
discarding, upon completion of execution of the computer routine, the computer routine in the container to prevent persistent storage of the computer routine on the virtual machine (Potter [0069] teaches removal of ephemeral containers one the single application execution is completed such that exploits associated with a container are removed not to be used again such that the exploits cannot persist [0029 and 0032]).
It would have been obvious for a person having ordinary skill in the art, before the effective filing date of the claimed invention, to modify Wagner in view of Potter in order to configure the isolated execution environment, as taught by Wagner, to prevent a first computer routine in a first container at a first virtual machine from accessing a second computer routine in a second container at a second virtual machine; discarding, the computer routine in the container to prevent persistent storage of the computer routine on the virtual machine, as taught by Potter.
One of ordinary skill in the art would have been motivated in order to prevent cross-contamination across containers, protect users from compromises that have already occurred on a system, provide a means to launch applications safely and inhibit compromises (Potter [0029-0032]).
Regarding claim 2, Wagner-Potter teaches the limitations of claim 1, as rejected above.
Additionally, Wagner-Potter teaches the method wherein providing the container including the dependencies for executing the computer routine comprises:
providing a filesystem that includes components for executing the computer routine in the isolated environment, wherein the components include runtime, system tools, language bindings, and system libraries (Wagner [0033] teaches varying configurations of operating systems, language runtimes, libraries, container language bindings [0033, 0052] and software components [0070]).
Regarding claim 3, Wagner-Potter teaches the limitations of claim 1, as rejected above.
Additionally, Wagner-Potter teaches the method wherein providing the container comprises:
selecting the container from a pool of pre-warmed containers (Wagner [0058, 0074]); and
providing the selected container (Wagner [0059]).
Regarding claim 7, Wagner-Potter teaches the limitations of claim 1, as rejected above.
Additionally, Wagner-Potter teaches the method wherein receiving the request to execute the computer routine comprises receiving the request via an HTTP endpoint (Wagner [0027]).
Regarding claims 9-11 and 15, they do not teach or further limit over the limitations presented above with respect to claims 1-3 and 7.
Therefore, claims 9-11 and 15 are rejected for the same reasons set forth above regarding claims 1-3 and 7.
Regarding claims 17-19, they do not teach or further limit over the limitations presented above with respect to claims 1-3.
Therefore, claims 17-19 are rejected for the same reasons set forth above regarding claims 1-3.
Claims 4, 8, 12, 16, 20 rejected under 35 U.S.C. 103 as being unpatentable over Wagner (US 20160092252 A1, hereafter referred to as Wagner) in view of Potter et al (US 20120210333 A1, hereafter referred to as Potter) as applied above regarding claim 1, further in view of Christopher et al (US 8966464 B1, hereafter referred to as Christopher).
Regarding claim 4, Wagner-Potter teaches the limitations of claim 1, as rejected above.
However, Wagner-Potter does not explicitly teach the method wherein executing the computer routine comprises: limiting, based at least in part on a control group, an amount of computing resources capable of being consumed during execution of the computer routine.
Christopher, in an analogous art, teaches the method wherein executing the computer routine comprises:
limiting, based at least in part on a control group, an amount of computing resources capable of being consumed during execution of the computer routine (Christopher [25:64-26:5] teaches mechanisms to limit compute resources allocated by a tenant based on a predefined threshold).
It would have been obvious for a person having ordinary skill in the art, before the effective filing date of the claimed invention, to modify Wagner-Potter in view of Christopher to limit, based at least in part on a control group, an amount of computing resources capable of being consumed during execution of the computer routine, as taught by Christopher.
One of ordinary skill in the art would have been motivated in order to prevent resource starvation by one or more tenants (Christopher [2:48-54])
Regarding claim 8, Wagner-Potter teaches the limitations of claim 1, as rejected above.
However, Wagner-Potter does not explicitly teach the method further comprising: associating thread resources with the request to execute the computer routine; and tracking, at a thread level, the thread resources used during execution of the computer routine.
Christopher, in an analogous art, teaches the method further comprising:
associating thread resources with the request to execute the computer routine (Christopher [8:11-45] teaches requests for thread creation by a tenant and association of the number of threads created by that tenant or virtual machine [8:46-55]); and
tracking, at a thread level, the thread resources used during execution of the computer routine (Christopher [8:30-65] teaches monitoring the number of threads create by each of the tenants).
It would have been obvious for a person having ordinary skill in the art, before the effective filing date of the claimed invention, to modify Wagner-Potter in view of Christopher to associate thread resources with the request to execute the computer routine and track, at a thread level, the thread resources used during execution of the computer routine, as taught by Christopher.
One of ordinary skill in the art would have been motivated in order to prevent a tenant from creating a disproportionate number of threads that starve the other tenants from being able to create threads (Christopher [9:12-18]).
Regarding claims 12 and 16, they do not teach or further limit over the limitations presented above with respect to claims 4 and 8.
Therefore, claims 12 and 16 are rejected for the same reasons set forth above regarding claims 4 and 8.
Regarding claim 20, it does not teach or further limit over the limitations presented above with respect to claim 4.
Therefore, claim 20 is rejected for the same reasons set forth above regarding claim 4.
Claims 5, 13 rejected under 35 U.S.C. 103 as being unpatentable over Wagner (US 20160092252 A1, hereafter referred to as Wagner) in view of Potter et al (US 20120210333 A1, hereafter referred to as Potter) as applied above regarding claim 1, further in view of Coleman et al (US 20160147529 A1, hereafter referred to as Coleman).
Regarding claim 5, Wagner-Potter teaches the limitations of claim 1, as rejected above.
However, Wagner-Potter does not explicitly teach the method wherein the container is associated with a webtask cluster configured with one or more firewall rules that prevent an untrusted computer routine in one webtask container from communicating with other webtask containers and webtask infrastructure associated with the webtask cluster.
Coleman, in an analogous art, teaches the method wherein the container is associated with a webtask cluster configured with one or more firewall rules that prevent an untrusted computer routine in one webtask container from communicating with other webtask containers and webtask infrastructure associated with the webtask cluster (Coleman [0055] teaches applying security labeling and types to the container that fence off the container from other containers on the node and prevent the container from accessing underlying system resources).
It would have been obvious for a person having ordinary skill in the art, before the effective filing date of the claimed invention, to modify Wagner-Potter in view of Coleman in order to associate the container with a webtask cluster configured with one or more firewall rules that prevent an untrusted computer routine in one webtask container from communicating with other webtask containers and webtask infrastructure associated with the webtask cluster, as taught by Coleman.
One of ordinary skill in the art would have been motivated in order to provide users with a cost-effective and secure PaaS service using reduced infrastructure (Coleman [0015]).
Regarding claim 13, it does not teach or further limit over the limitations presented above with respect to claim 5.
Therefore, claim 13 is rejected for the same reasons set forth above regarding claim 5.
Claims 6, 14 rejected under 35 U.S.C. 103 as being unpatentable over Wagner (US 20160092252 A1, hereafter referred to as Wagner) in view of Potter et al (US 20120210333 A1, hereafter referred to as Potter) as applied above regarding claim 1, further in view of Wagner (US 20160092251 A1, hereafter referred to as Allen).
Regarding claim 6, Wagner-Potter teaches the limitations of claim 1, as rejected above.
However, Wagner-Potter does not explicitly teach the method wherein receiving the request to execute the computer routine comprises receiving a URL link to an online file storage server that stores the computer routine (Wagner [0026, 0028] teaches the user code is uploaded in a storage service or storage system).
Allen, in an analogous art, teaches the method wherein receiving the request to execute the computer routine comprises receiving a URL link to an online file storage server that stores the computer routine (Allen [0068]).
It would have been obvious for a person having ordinary skill in the art, before the effective filing date of the claimed invention, to modify Wagner-Potter in view of Allen in order to configure the request to execute the computer routine comprising receiving a location to an online file storage server that stores the computer routine, to include a URL link, as taught by Allen.
KSR rationale B, simple substitution of one known element (storage location, as taught by Wagner-Potter) for another known element (URL link storage location, as taught by Allen) in order to yield predictable results (retrieval of the user code from an identified location) supports the conclusion of obviousness.
Regarding claim 14, it does not teach or further limit over the limitations presented above with respect to claim 6.
Therefore, claim 14 is rejected for the same reasons set forth above regarding claim 6.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1, 9 and 17 rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 5-6 of U.S. Patent No. 11622003 in view of Wagner (US 20160092252 A1). Although the conflicting claims are not identical, they are not patentably distinct from each other for the following reasons.
Regarding claim 1, the claim simply combines limitations of claims 1 and 5-6 of the parent application. One of ordinary skill in the art would understand that the elements of claims 5 and 6 could be combined because they are not mutually exclusive features. Claims 1 and 5-6 of ‘003 patent claims all of the limitations except “providing a virtualization environment comprising a plurality of virtual machines, each virtual machine comprising an operating system for hosting a respective container in an isolated execution environment” Wagner (US 20160092252 A1) teaches providing a virtualization environment comprising a plurality of virtual machines (Wagner [0014] teaches virtual machine instances in a virtual compute system), each virtual machine comprising an operating system for hosting a respective container in an isolated execution environment (Wagner [0014] teaches the virtual machine instances have software components including operating systems and isolated containers created on the virtual machine instances). Therefore, it would be obvious to one of ordinary skill in the art to combine the virtualization environment of Wager with the subject matter of ‘003 claims 1 and 5-6 so that the requested computer routine could execute in an isolated environment inaccessible by other routines running on the host.
Regarding claim 9 the instant application claims are directed to a device identical to the method steps executed in claims 1 and 5-6 of the patent, in view of Wagner as set forth above, such that the device claims of the instant application execute the method of claim 1 of the patent. It would have been obvious for a person having ordinary skill in the art to modify the claims of the patent to be adopted as a device for executing the method such that the method could be executed by a plurality of computing devices.
Regarding claim 17 the instant application claims are directed computer readable media identical to the method steps executed in claims 1 and 5-6 of the patent, in view of Wagner as set forth above, such that the claims of the instant application comprise the method of claims 1 and 5-6 of the patent, ‘003. It would have been obvious for a person having ordinary skill in the art to modify the claims of the patent to be adopted as computer readable media for a device such that the computer readable media could be distributed and executed by a plurality of computing devices.
Regarding the dependent claims, the claims depend on independent claims 1, 9 and 17 such that the dependent claims inherit the deficiencies of the independent claims 1, 9 and 17 and do not cure the deficiencies of the independent claims.
The mapping of claim 1 of the instant application and the referenced patent is provided.
Instant Application
US Patent 11622003
1. A method comprising: providing a virtualization environment comprising a plurality of virtual machines, each virtual machine comprising an operating system for hosting a respective container in an isolated execution environment, wherein the isolated execution environment prevents a first computer routine in a first container at a first virtual machine from accessing a second computer routine in a second container at a second virtual machine; receiving a request to execute a computer routine associated with an application written in an arbitrary programming language; providing, based at least in part on the request and at a virtual machine of the plurality of virtual machines, a container in which to execute the computer routine in an isolated environment, wherein the container includes dependencies for executing the computer routine; assigning, to the container and based at least in part on the operating system of the virtual machine, virtualized computing resources; executing, in the container, the computer routine; and discarding, upon completion of execution of the computer routine, the computer routine in the container to prevent persistent storage of the computer routine on the virtual machine
1. A method of executing a computer routine of an arbitrary application, the method comprising: providing a webtask container in an isolated environment at a server in which to execute the computer routine, the webtask container having an associated programming language; receiving a webtask request that includes: client data; the computer routine in the form of executable computer code or a uniform resource locator (URL) link to the computer routine; and at least one client secret associated with the computer routine; determining a programming language of the computer routine; responsive to the determined programming language corresponding to the programming language associated with the webtask container: applying computing resources to the webtask container to create a uniform logic-agnostic execution environment for executing the received webtask request; executing the computer routine in the webtask container; returning a calculated result based on the executed computer routine; and destroying the webtask container upon completion of the executing of the computer routine to prevent persistent storage of the computer routine.
5. The method of claim 1, wherein the webtask container includes all dependencies of the computer routine to run in the isolated environment.
6. The method of claim 5, wherein the isolated environment is provided such that the computer routine or its data is prevented from access by another computer routine
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Fanning et al (US 20130212595 A1);
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHEAN TOKUTA whose telephone number is (571)272-5145. The examiner can normally be reached M-TH 630-430.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Brian Gillis can be reached at 5712727952. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
SHEAN TOKUTA
Primary Examiner
Art Unit 2446
/SHEAN TOKUTA/Primary Examiner, Art Unit 2419