Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 7/8/2026 have been fully considered but they are not persuasive.
Applicant argues that Fox in view of Wagner has not met the burden of establishing a prima facie case of obviousness.
The Examiner has shown all the claim elements (see above) and provided sufficient support and rational for the obviousness rejections, meeting the claim limitations as written. Further, risk assessment and secure deployment of software are well-known concepts, and substituting for quarantine state management would be obvious to one of ordinary skill in the art and is not considered hindsight.
As such, the Examiner maintains the rejection.
2. Applicant argues that the prior art Fox and Wagner do not disclose “determining that the software artifact is approved for deployment within a second computing system; and providing the software artifact to a second artifact repository, wherein the software artifact is deployable from the second artifact repository to the second computing system”, as recited in independent claims.
In response to Applicants arguments, the Examiner respectfully disagrees with the applicant and would like to show that Fox in view of Wagner discloses determining that the software artifact is approved for deployment within a second computing system; and providing the software artifact to a second artifact repository, wherein the software artifact is deployable from the second artifact repository to the second computing system. The Examiner points out that Fox discloses in response to the attempt failing, storing an identifier of the storage object representing the second storage feature to a quarantine list on second persistent storage of the DSS distinct from the first persistent storage; and subsequently, receiving an additional request to access the second storage feature, and, in response: finding that the quarantine list identifies the storage object representing the second storage feature and in response to finding, denying access to the second storage feature due to it being quarantined (claim 1).
Examiner asserts that the second storage in Wagner correlates to the second artifact repository, as described in Applicant’s invention.
As such the Examiner maintains the rejection.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Fox (US Patent Pub. 2021/0056209) in view of Wagner (US Patent Pub. 2020/0210606).
As per claim 1: Fox discloses a method comprising:
retrieving, from a software artifact list within a quarantine subsystem, information relating to a software artifact (Paragraph 198; According to known techniques for handling malicious software, a list which specifies various malicious components is shared, and the repository 407 (and probably the source repository 411) will remove, notify, quarantine, or otherwise block use of the malicious component 413);
based on the information relating to the software artifact, retrieving the software artifact from a first artifact repository within a first computing system (Paragraph 234; quarantine the new version, i.e., store the new version in quarantine storage which is reserved for components that are not available for retrieval by the repository manager until in the future when expressly released from quarantine);
causing a vulnerability checker within the quarantine subsystem to perform one or more vulnerability checks on the software artifact (Paragraph 245; The repository manager can be set to use the data that the component is suspicious, to quarantine the component, to automatically notify the requesting user of the suspicious data, to prevent download of the suspicious component, and/or similar).
Fox does not specifically disclose determining that the software artifact is approved for deployment within a second computing system; and providing the software artifact to a second artifact repository, wherein the software artifact is deployable from the second artifact repository to the second computing system (See Wagner; Claim 1; in response to the attempt failing, storing an identifier of the storage object representing the second storage feature to a quarantine list on second persistent storage of the DSS distinct from the first persistent storage; and subsequently, receiving an additional request to access the second storage feature, and, in response: finding that the quarantine list identifies the storage object representing the second storage feature and in response to finding, denying access to the second storage feature due to it being quarantined).
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, having the teachings of Fox and Wagner in it’s entirety, to modify the technique of Fox for a list which specifies various malicious components is shared, and the repository (and probably the source repository) will remove, notify, quarantine, or otherwise block use of the malicious component by adopting Wagner‘s teaching for finding that the quarantine list identifies the storage object representing the second storage feature. The motivation would have been to improve secure deployment of software packages.
As per claim 2: The method of claim 1, wherein the second artifact repository is within the quarantine subsystem (See Wagner; Claim 1; in response to the attempt failing, storing an identifier of the storage object representing the second storage feature to a quarantine list on second persistent storage of the DSS distinct from the first persistent storage).
As per claim 3: The method of claim 1, wherein the second artifact repository is within the second computing system (See Wagner; Claim 1; receiving an additional request to access the second storage feature, and, in response: finding that the quarantine list identifies the storage object representing the second storage feature and in response to finding, denying access to the second storage feature due to it being quarantined).
As per claim 4: The method of claim 1, wherein the software artifact list undergoes synchronization with a further software artifact list within the first computing system (See Fox; Paragraph 30; quarantine manager 76 operates to persistently quarantine the storage object 50 until the metadata can be synchronized between the correct memory-resident storage object 50 and the incorrect object entry 64 within the MDDB 62).
As per claim 5: The method of claim 1, wherein the one or more vulnerability checks on the software artifact involve scanning the software artifact for viruses, malware, or other defects (See Fox; Paragraph 245; The repository manager can be set to use the data that the component is suspicious, to quarantine the component, to automatically notify the requesting user of the suspicious data, to prevent download of the suspicious component, and/or similar).
As per claim 6: The method of claim 1, wherein determining that the software artifact is approved for deployment within the second computing system comprises:
determining that the one or more vulnerability checks performed on the software artifact have all passed (See Wagner; Claim 1; receiving an additional request to access the second storage feature, and, in response: finding that the quarantine list identifies the storage object representing the second storage feature and in response to finding, denying access to the second storage feature due to it being quarantined).
As per claim 7: The method of claim 1, wherein determining that the software artifact is approved for deployment within the second computing system comprises: receiving an approval to deploy the software artifact from a user associated with the quarantine subsystem (See Wagner; Claim 1; receiving an additional request to access the second storage feature, and, in response: finding that the quarantine list identifies the storage object representing the second storage feature and in response to finding, denying access to the second storage feature due to it being quarantined).
As per claim 8: The method of claim 1, further comprising:
providing an update to a further software artifact list within the first computing system, wherein to the update indicates that the software artifact is deployable from the second artifact repository to the second computing system (See Fox; Paragraph 188; update of an artifact, who updated it, from what sponsor, and why it was updated; recording a download of an artifact from the project, who downloaded it).
As per claim 9: The method of claim 1, further comprising: retrieving, from the software artifact list, further information relating to the software artifact;
determining that the software artifact is approved for deletion from the second computing system (See Fox; Paragraph 198);
providing a deletion command to the second artifact repository, wherein the deletion command causes the software artifact to be deleted from the second artifact repository (See Fox; Paragraph 198; According to known techniques for handling malicious software, a list which specifies various malicious components is shared, and the repository 407 (and probably the source repository 411) will remove, notify, quarantine, or otherwise block use of the malicious component 413); and
updating a further software artifact list within the first computing system to indicate that the software artifact is no longer deployable to the second computing system (See Fox; Paragraph 188; update of an artifact, who updated it, from what sponsor, and why it was updated; recording a download of an artifact from the project, who downloaded it).
As per claim 10: The method of claim 1, wherein the software artifact comprises one or more of: executable images, dependencies, or configuration files (See Fox; Paragraph 182; artifacts).
As per claim 11: The method of claim 1, wherein the vulnerability checker is configurable to perform different vulnerability checks based on one or more of: a type of the software artifact, the second computing system, or a user associated with the software artifact (Paragraph 198; According to known techniques for handling malicious software, a list which specifies various malicious components is shared, and the repository 407 (and probably the source repository 411) will remove, notify, quarantine, or otherwise block use of the malicious component 413).
Relevant Prior Art References
The following prior art is cited as being of interest to the claimed invention but has not been applied in any of the current rejections.
Matthew et al.- US Patent Publication 2011/0185353- the prior art teaches techniques for automatically quarantine one or more files associated with the non-priority software identified in the incompatibility list.
Mazina et al.- US Patent Pub. 8,370,688 - the prior art teaches techniques for identifying a storage device as faulty for a first storage volume.
Sundrani et al.- US Patent Pub. 2010/0037019 - the prior art teaches techniques for high performance consistency check.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANTHONY D BROWN whose telephone number is (571)270-1472. The examiner can normally be reached 730-330pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached at 5712705440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ANTHONY D BROWN/Primary Examiner, Art Unit 2408