DETAILED ACTION
This office action has been issued in response to communications received on 6/26/2025. Claims 1-2 and 4-13 were amended. Claims 3 and 14 were previously cancelled. Claims 1-2, 4-13 and 15 are presented for examination. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
EXAMINER NOTE
The Examiner strongly cautions Applicant that to avoid independent claims becoming restrictable from one another, the independent claims should not contain substantive limitations that are different from one another. For example, if the Examiner is having to generate different grounds of rejections for different independent claims (as the Examiner did for claim 1 vs. claims 13 and 15), then the Examiner is being forced to conduct different search and examination for different claims – which is basically forcing the examiner to examine different inventions at the same time. To avoid this, independent claims should have substantially the same substantive content.
Response to Arguments
Applicant’s amendments to claims 1 and 13 adding memory are sufficient to overcome the rejection of claims 1-2 and 4-13 under 35 USC 101. Accordingly, the rejection of claims 1-2 and 4-13 under 101 has been withdrawn.
Applicant’s Remarks with respect to the rejection of the claims under 35 USC 103 have been considered, but are found unpersuasive.
Applicant argues on pages 7-8 of the Remarks that Taylor does not disclose “environment information describing the execution environment at a runtime of the application program” because Taylor does not explicitly disclose “environment information”, however the Examiner respectfully disagrees. Taylor does not need to explicitly disclose the exact words “environment information” if it functionally discloses environment information. Taylor explicitly discloses generating a fingerprint of “the underlying platform code on which an application is running” (paras. [0052], [0055]), therefore the underlying platform code comprises part of the “environment” of the application.
Applicant further argues that Taylor does not teach the claimed limitations because it does not disclose that “the application performs fingerprinting of its execution environment by processing raw information of the execution environment in advance and using the attestation to confirm what kind of execution environment it is running” in the same manner as the current invention, however the Examiner respectfully disagrees. The claims currently do not disclose processing raw information of the execution environment in advance. Claims 13 and 15 don’t even specify what the execution environment comprises like claim 1. Applicant is free to amend the claims to further define the execution environment and/or attestation process.
Applicant’s arguments filed 6/26/2026, with respect to the rejection of the claims under 35 USC § 103(a) have been fully considered but are moot because newly added claim limitations requiring “a non-transitory memory storing an application program to be executed by the one or more processors in an execution environment comprising at least one of a container runtime environment, a virtual machine, or a trusted execution environment (TEE)” require new grounds of rejection necessitated by amendments.
The remaining arguments fail to comply with 37 C.F.R. 1.111(b) because they amount to a general allegation that the claims define a patentable invention without specifically pointing out how the language of the claims patentably distinguishes them from the references.
Consequently, the rejection of the claims under 35 U.S.C. 103 is sustained.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claim 1 is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The Examiner could not support in the Specification for disclosing that the environment information is created using “output of proofs and/or sysfs interfaces” and “data relating to processor registers”. In addition, the Examiner could not find where the Specification discloses that cryptographically protecting comprises “generating a cryptographic signature over the fingerprint”. While these amendments are helpful to push the claims closer to allowance, there must be Specification support. Please clarify where in the Specification there is support for these claim amendments.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or non-obviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claims 1-2 and 4-12 are rejected under 35 U.S.C. 103 as being unpatentable over Taylor (US 2018/0114000) in view of Yunlong Guo et al., Building Trust in Container Environment in 18th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (2019) (hereafter “Guo”).
Regarding claim 1, Taylor discloses the limitations of claim 1 substantially as follows:
A computing system
one or more processors; and
wherein the application program comprises:
a documentation unit implemented by the one or more processors to create environment information describing the execution environment at a runtime of the application program, wherein creating the environment information comprises obtaining at least one of (i) outputs of proofs and/or sysfs interfaces, or (ii) data relating to processor registers (paras. [0045], [0052], [0055]-[0057], Fig. 4: generating a fingerprint of information on the underlying platform code on which an application is running (i.e. environment information) comprising a client device’s type and configuration & version of the operating system of a device on which application code is running), where the fingerprint of the information is generated from a hash calculated from the client application software and the underlying platform support code (i.e. as an output of a proof)); and
an attestation unit implemented by instructions executed by the one or more processors to cryptographically protect the environment information forming a piece of attestation information, wherein the environment information comprises a fingerprint formed as at least one cryptographic hash value (paras. [0052], [0055]-[0057], Fig. 4: generating a fingerprint in the form of a cryptographic hash calculated from the software code content as part of attestation response, wherein the fingerprint is a fingerprint signature formed from a hash value).
Taylor does not explicitly disclose the remaining limitations of claim 1:
a non-transitory memory storing an application program to be executed by the one or more processors in an execution environment comprising at least one of a container runtime environment, a virtual machine, or a trusted execution environment (TEE);
and wherein cryptographically protecting comprises generating a cryptographic signature over the fingerprint
However, in the same field of endeavor Guo discloses the remaining limitations of claim 1 as follows:
a non-transitory memory storing an application program to be executed by the one or more processors in an execution environment comprising at least one of a container runtime environment, a virtual machine, or a trusted execution environment (TEE) (pages 1-2 Introduction, section 2.2 Trusted Computing, section 5 Secure the Operating System (pages 3-4) and Sections 6.1-6.2 (page 4): executing authorized programs in an execution environment comprising a container runtime environment or a virtualized TPM in a virtual machine);
and wherein cryptographically protecting comprises generating a cryptographic signature over the fingerprint (page 4, section 6.1: a binding signature is generated of a fingerprint and a container signature (i.e. generating signature over the fingerprint))
Guo is combinable with Taylor because both are from the same field of endeavor of generating a fingerprint for a runtime environment. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to integrate Guo’s method of running the application in a container runtime environment with the system of Taylor in order to increase the security of the system by ensuring the application is tightly constrained by the container protecting the host infrastructure from a runaway or compromised application.
Regarding claim 2, Taylor and Guo disclose the limitations of claim 1.
Taylor discloses the limitations of claim 2 as follows:
The computing system
an output unit to transmit the attestation information (paras. [0047], [0052], Fig. 2: transmitting the attestation response containing the fingerprint).
Regarding claim 4, Taylor and Guo disclose the limitations of claim 1.
Taylor discloses the limitations of claim 4 as follows:
The computing system
hardware of the execution environment;
an infrastructure of the execution environment;
further application programs of the execution environment;
an operating system of the execution environment (paras. [0055]-[0057): information on the underlying platform code on which an application is running (i.e. environment information) comprising data that the client is running specific operating system platform software);
a device and/or a system on which the execution environment is implemented;
a file of the execution environment;
a property of the execution environment;
data relating to processor registers of the execution environment or of a system superordinate to the execution environment;
configuration data of the application program;
configuration data of a peripheral module of the execution environment or of a system superordinate to the execution environment;
configuration data of an extension module of the execution environment or of a system superordinate to the execution environment;
data from access operations by the application program to components of the execution environment or to a system superordinate to the execution environment;
a performance measurement of the execution environment;
a cryptographic key accessible by the application program;
a security token accessible by the application program; and/or
a digital certificate accessible by the application program.
Regarding claim 5, Taylor and Guo disclose the limitations of claim 1.
Taylor discloses the limitations of claim 5 as follows:
The computing system (paras. [0055]-[0057]: fingerprint of information on the underlying platform code on which an application is running (i.e. environment information).
Regarding claim 6, Taylor and Guo disclose the limitations of claims 1 and 5.
Taylor discloses the limitations of claim 6 as follows:
The computing system
a cryptographic checksum;
a cryptographic hash value (paras. [0052], [0056]: fingerprint is generated using hashing algorithm); and/or
an aggregated hash value.
Regarding claim 7, Taylor and Guo disclose the limitations of claim 1.
Taylor discloses the limitations of claim 7 as follows:
The computing system
a checking unit to check the environment information and/or the attestation information (para. [0056]: attestation module checks authenticity of the operating system kernel and checks to determine if the device has been rooted allowing arbitrary kernel changes or other operating system modifications that are not approved).
Regarding claim 8, Taylor and Guo disclose the limitations of claim 1.
Taylor discloses the limitations of claim 8 as follows:
The computing system (paras. [0056]: calculating fingerprint signature of the code using a hashing algorithm to generate attestation response).
Regarding claim 9, Taylor and Guo disclose the limitations of claims 1 and 8.
Taylor discloses the limitations of claim 9 as follows:
The computing system (paras. [0056], [0066]-[0068], [0070]: a salt value that is random enough so that it cannot be predicted by the attacker (i.e. secret private key) is used to generate the fingerprint).
Regarding claim 10, Taylor and Guo disclose the limitations of claim 1.
Taylor discloses the limitations of claim 10 as follows:
The computing system (paras. [0056]: calculating fingerprint signature of the code using a hashing algorithm to generate attestation response).
Regarding claim 11, Taylor and Guo disclose the limitations of claim 1.
Taylor discloses the limitations of claim 11 as follows:
The computing system application program as claimed in claim 1, further comprising
a memory function to initiate the storage of the attestation information (paras. [0056], [0060]: performing attestation to trigger generating and storing the fingerprints).
Regarding claim 12, Taylor and Guo disclose the limitations of claim 1.
Taylor discloses the limitations of claim 12 as follows:
The computing system
during the runtime of the application program; and/or retrospectively to the runtime of the application program (paras. [0055]-[0057]: the fingerprint is generated while the application is running).
Claims 13 & 15 are rejected under 35 U.S.C. 103 as being unpatentable over Taylor (US 2018/0114000).
Regarding claim 13, Taylor discloses the limitations substantially as follows:
A computing system
one or more processors; and
a non-transitory memory storing an application program to be executed by the one or more processors in an execution environment implemented by the computing system;[,]
wherein the application program comprises
a documentation unit implemented by the one or more processors using instructions from the application program to create environment information describing the execution environment at a runtime of the application program (paras. [0045], [0055]-[0057], Fig. 4: generating a fingerprint of information on the underlying platform code on which an application is running (i.e. environment information) comprising a client device’s type and configuration & version of the operating system of a device on which application code is running); and
an attestation unit implemented by the one or more processors using instructions from the application program to cryptographically protect the environment information forming a piece of attestation information (paras. [0052], [0055]-[0057], Fig. 4: generating a fingerprint in the form of a cryptographic hash calculated from the software code content as part of attestation response).
Taylor does not explicitly disclose the term “environment information”, however it would be obvious to one of ordinary skill in the art before the effective filing date of the claimed invention that the type and configuration information of the operating system functions as information about the environment describing the execution environment because Taylor discloses that the platform code may comprise operating system versions and including this information in the fingerprint would increase the security of the system because it enables the system to take into account scenarios where an application might have been “influenced my modifications to the underlying operating system libraries present on the client device” (Taylor, para. [0055]).
Regarding claim 15, Taylor discloses the limitations substantially as follows:
A method for forming a piece of attestation information of an application program to be executed in an execution environment, the method comprising:
creating environment information describing the execution environment at a runtime of the application program (paras. [0045], [0055]-[0057], Fig. 4: generating a fingerprint of information on the underlying platform code on which an application is running (i.e. environment information) comprising a client device’s type and configuration & version of the operating system of a device on which application code is running); and
cryptographically protecting the environment information and forming a piece of attestation information (paras. [0052], [0055]-[0057], Fig. 4: generating a fingerprint in the form of a cryptographic hash calculated from the software code content as part of attestation response).
Taylor does not explicitly disclose the term “environment information”, however it would be obvious to one of ordinary skill in the art before the effective filing date of the claimed invention that the type and configuration information of the operating system functions as information about the environment describing the execution environment because Taylor discloses that the platform code may comprise operating system versions and including this information in the fingerprint would increase the security of the system because it enables the system to take into account scenarios where an application might have been “influenced my modifications to the underlying operating system libraries present on the client device” (Taylor, para. [0055]).
Prior art not relied upon but applied/considered includes:
1) Kumar (US 2012/0216244) disclosing requesting an application artifact for the application from an attestation service, for example, by a runtime monitor, and requesting an application statement from the attestation service, for example, by network access enforcer(s). The method may further include requesting, by the attestation service from a plurality of collaboration services, a context (e.g., an introspection based security context) for the application on the instrumented target platform. The method may also include requesting a notification of or subscribing to a change (e.g., any change) in the execution context of the application on the instrumented target platform (para. [0020], [0047], [0053]).
Conclusion
For the above reasons, claims 1-2, 4-13 and 15 are rejected.
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHARON S LYNCH whose telephone number is (571)272-4583. The examiner can normally be reached on 10AM-6PM.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Taghi T Arani can be reached on 571-272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHARON S LYNCH/Primary Examiner, Art Unit 2438