Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The Application number 19/208,901 filed on 5/15/2025 has been considered. Claims 1-20 are pending.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 7/15/2025 is being considered by the examiner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-6, 8-13 and 15-18 are rejected under 35 U.S.C. 103 as being unpatentable over Bilugu et al. (US 2022/0124117 hereinafter Bilugu) in view of Kaimal et al. US 2023/0319093 hereinafter Kaimal).
Regarding claim 1, Bilugu discloses a method comprising:
executing a hypercontainer system including an encapsulated software application environment having built-in intelligent security features (FIG 1-2 & 3A-B, ¶ [0039]-[0042], [0048]-[0051]; i.e. executing a container cloud system against malicious attacks), including:
receiving a request for processing by an application hosted at the hypercontainer system in a first intelligent data container (IDC), the first IDC including software container executing the application (FIG 1-2 & 3A-B, ¶ [0039]-[0042], [0048]-[0051]; i.e. receiving an access request from user system to be processed by application in the container);
evaluating the request via a mini security manager [[integrated in the first IDC]] to determine if the request includes a security threat (FIG 1-2 & 3A-B, ¶ [0043]-[0045], [0056]-[0063]; i.e. checking whether the access request contains any of the malicious patterns);
rejecting the request without processing by the application when the request includes the security threat (FIG 1-2 & 3A-B, ¶ [0043]-[0045], [0056]-[0063]; i.e. blocking the access request if it is a malicious attack); and
processing the request by the application and returning a response when the request does not include the security threat (FIG 1-2 & 3A-B, ¶ [0043]-[0045], [0056]-[0063]; i.e. processing the access request by the application to access the storage).
Bilugu does not explicitly disclose the utility system or mini security manager integrated in the intelligent data container.
However, Kaimal discloses malicious analysis engine integrated in the container (FIG. 3, ¶ [0068]-[0072]).
Therefore, it would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to combine Bilugu and Kaimal in order to ensure computing instances in the container environment comply with a corporate policy (Kaimal, ¶ [0021]-[0026]).
Regarding claim 2, Bilugu in view of Kaimal discloses the method of claim 1 further comprising: evaluating the request at the mini security manager using a deterministic rule set for the application (Bilugu, ¶ [0043]-[0045], [0056]-[0063], [0097]; Kaimal, ¶ [0071]-[0072]).
Regarding claim 3, Bilugu in view of Kaimal discloses the method of claim 2 further comprising: evaluating the request at the mini security manager using a machine learning model trained based on normal operating patterns (Bilugu, ¶ [0060]-[0064]; Kaimal, ¶ [0071]).
Regarding claim 4, Bilugu in view of Kaimal discloses the method of claim 3 further comprising: evaluating the request at an authorization layer integrated in the first IDC to determine whether the request is authorized for processing by the application based on credentials included in the request (Bilugu, ¶ [0031]-[0035]; Kaimal, ¶ [0030]-[0031]); and forwarding the request to the mini security manager for evaluation based on the request being authorized for processing (Bilugu, ¶ [0031]-[0035]; Kaimal, ¶ [0030]-[0031]).
Regarding claim 5, Bilugu in view of Kaimal discloses the method of claim 4 further comprising: determining which of a plurality of IDCs hosted at the hypercontainer system to route the request for processing, each of the plurality of IDCs including its own mini security manager (Bilugu, FIG. 3A-B, ¶ [0030]; Kaimal, ¶ [0075]-[0077]); and routing the request to the first IDC based on the determination (Bilugu, FIG. 3A-B, ¶ [0030]; Kaimal, ¶ [0075]-[0077]).
Regarding claim 6, Bilugu in view of Kaimal discloses the method of claim 5 further comprising: evaluating the request via an intelligent security manager integrated into the hypercontainer system to determine if the request includes a security risk, the intelligent security manager including a large language model (LLM) artificial immune system (AIS) (Bilugu, ¶ [0043]-[0045], [0056]-[0063], [0097]; Kaimal, ¶ [0071]-[0072]); and routing the request to the first IDC based on determining that the request does not include a security risk (Bilugu, ¶ [0043]-[0045], [0056]-[0063], [0097]; Kaimal, ¶ [0071]-[0072]).
Regarding claim 8, Bilugu discloses a memory device storing instructions that, when executed, cause a processor to:
execute a hypercontainer system including an encapsulated software application environment having built-in intelligent security features (FIG 1-2 & 3A-B, ¶ [0039]-[0042], [0048]-[0051]; i.e. executing a container cloud system against malicious attacks), including:
receive a request for processing by an application hosted at the hypercontainer system in a first intelligent data container (IDC), the first IDC including software container executing the application (FIG 1-2 & 3A-B, ¶ [0039]-[0042], [0048]-[0051]; i.e. receiving an access request from user system to be processed by application in the container);
evaluate the request via a mini security manager [[integrated in the first IDC]] to determine if the request includes a security threat (FIG 1-2 & 3A-B, ¶ [0043]-[0045], [0056]-[0063]; i.e. checking whether the access request contains any of the malicious patterns);
reject the request without processing by the application when the request includes the security threat (FIG 1-2 & 3A-B, ¶ [0043]-[0045], [0056]-[0063]; i.e. blocking the access request if it is a malicious attack); and
process the request by the application and return a response when the request does not include the security threat (FIG 1-2 & 3A-B, ¶ [0043]-[0045], [0056]-[0063]; i.e. processing the access request by the application to access the storage).
Bilugu does not explicitly disclose the utility system or mini security manager integrated in the intelligent data container.
However, Kaimal discloses malicious analysis engine integrated in the container (FIG. 3, ¶ [0068]-[0072]).
Therefore, it would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to combine Bilugu and Kaimal in order to ensure computing instances in the container environment comply with a corporate policy (Kaimal, ¶ [0021]-[0026]).
Regarding claim 9, Bilugu in view of Kaimal discloses the memory device of claim 8 storing instructions that, when executed, cause the processor to further: evaluate the request at the mini security manager using a deterministic rule set for the application (Bilugu, ¶ [0043]-[0045], [0056]-[0063], [0097]; Kaimal, ¶ [0071]-[0072]).
Regarding claim 10, Bilugu in view of Kaimal discloses the memory device of claim 8 storing instructions that, when executed, cause the processor to further: evaluate the request at the mini security manager using a machine learning model trained based on normal operating patterns (Bilugu, ¶ [0060]-[0064]; Kaimal, ¶ [0071]).
Regarding claim 11, Bilugu in view of Kaimal discloses the memory device of claim 8 storing instructions that, when executed, cause the processor to further: evaluate the request at an authorization layer integrated in the first IDC to determine whether the request is authorized for processing by the application based on credentials included in the request (Bilugu, ¶ [0031]-[0035]; Kaimal, ¶ [0030]-[0031]); and forward the request to the mini security manager for evaluation based on the request being authorized for processing (Bilugu, ¶ [0031]-[0035]; Kaimal, ¶ [0030]-[0031]).
Regarding claim 12, Bilugu in view of Kaimal discloses the memory device of claim 8 storing instructions that, when executed, cause the processor to further: determine which of a plurality of IDCs hosted at the hypercontainer system to route the request for processing based on a content of the request and a purpose of each of the plurality of the IDCs, each of the plurality of IDCs including its own mini security manager (Bilugu, FIG. 3A-B, ¶ [0030]; Kaimal, ¶ [0075]-[0077]); and route the request to the first IDC based on the determination (Bilugu, FIG. 3A-B, ¶ [0030]; Kaimal, ¶ [0075]-[0077]).
Regarding claim 13, Bilugu in view of Kaimal discloses the memory device of claim 8 storing instructions that, when executed, cause the processor to further: evaluate the request via an intelligent security manager integrated into the hypercontainer system to determine if the request includes a security risk, the intelligent security manager including a large language model (LLM) artificial immune system (AIS) (Bilugu, ¶ [0043]-[0045], [0056]-[0063], [0097]; Kaimal, ¶ [0071]-[0072]); and route the request to the first IDC based on determining that the request does not include a security risk (Bilugu, ¶ [0043]-[0045], [0056]-[0063], [0097]; Kaimal, ¶ [0071]-[0072]) .
Regarding claim 15, Bilugu discloses an apparatus comprising:
a processor (FIG. 9); and
a memory device storing instructions that cause the processor to execute a hypercontainer system including an encapsulated software application environment having built-in intelligent security features (FIG. 1-2, 3A-B, & 9, ¶ [0039]-[0042], [0048]-[0051]; i.e. executing a container cloud system against malicious attacks), including:
receive a request for processing by an application hosted at the hypercontainer system in a first intelligent data container (IDC), the first IDC including software container executing the application (FIG 1-2 & 3A-B, ¶ [0039]-[0042], [0048]-[0051]; i.e. receiving an access request from user system to be processed by application in the container);
evaluate the request via a mini security manager [[integrated in the first IDC]] to determine if the request includes a security threat (FIG 1-2 & 3A-B, ¶ [0043]-[0045], [0056]-[0063]; i.e. checking whether the access request contains any of the malicious patterns);
reject the request without processing by the application when the request includes the security threat (FIG 1-2 & 3A-B, ¶ [0043]-[0045], [0056]-[0063]; i.e. blocking the access request if it is a malicious attack); and
process the request by the application and return a response when the request does not include the security threat (FIG 1-2 & 3A-B, ¶ [0043]-[0045], [0056]-[0063]; i.e. processing the access request by the application to access the storage).
Bilugu does not explicitly disclose the utility system or mini security manager integrated in the intelligent data container.
However, Kaimal discloses malicious analysis engine integrated in the container (FIG. 3, ¶ [0068]-[0072]).
Therefore, it would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to combine Bilugu and Kaimal in order to ensure computing instances in the container environment comply with a corporate policy (Kaimal, ¶ [0021]-[0026]).
Regarding claim 16, Bilugu in view of Kaimal discloses the apparatus of claim 15, further comprising the processor configured to execute the instructions to: evaluate the request at the mini security manager using: a deterministic rule set for the application (Bilugu, ¶ [0043]-[0045], [0056]-[0063], [0097]; Kaimal, ¶ [0071]-[0072]); and a machine learning model trained based on normal operating patterns (Bilugu, ¶ [0060]-[0064]; Kaimal, ¶ [0071]).
Regarding claim 17, Bilugu in view of Kaimal discloses the apparatus of claim 15, further comprising the processor configured to execute the instructions to: evaluate the request at an authorization layer integrated in the first IDC to determine whether the request is authorized for processing by the application based on credentials included in the request (Bilugu, ¶ [0031]-[0035]; Kaimal, ¶ [0030]-[0031]); and forward the request to the mini security manager for evaluation based on the request being authorized for processing (Bilugu, ¶ [0031]-[0035]; Kaimal, ¶ [0030]-[0031]).
Regarding claim 18, Bilugu in view of Kaimal discloses the apparatus of claim 15, further comprising the processor configured to execute the instructions to: determine which of a plurality of IDCs hosted at the hypercontainer system to route the request for processing based on a content of the request and a purpose of each of the plurality of the IDCs, each of the plurality of IDCs including its own mini security manager (Bilugu, FIG. 3A-B, ¶ [0030]; Kaimal, ¶ [0075]-[0077]); and route the request to the first IDC based on the determination (Bilugu, FIG. 3A-B, ¶ [0030]; Kaimal, ¶ [0075]-[0077]).
Claims 7, 14 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Bilugu et al. (US 2022/0124117 hereinafter Bilugu) in view of Kaimal et al. US 2023/0319093 hereinafter Kaimal) and further in view of Sundaram et al. (US 8,789,208 hereinafter Sundaram).
Regarding claim 7, Bilugu in view of Kaimal discloses the method of claim 6 further comprising: evaluating the request at an authorization module integrated in the hypercontainer system to determine whether the request is authorized for processing by any IDC hosted at the hypercontainer system based on the credentials included in the request (Bilugu, ¶ [0031]-[0035]; Kaimal, ¶ [0030]-[0031]); and routing the request to the intelligent security manager based on the request being authorized for processing (Bilugu, ¶ [0031]-[0035]; Kaimal, ¶ [0030]-[0031]).
Bilugu in view of Kaimal does not explicitly disclose receiving the request at the hypercontainer system via a specific exposed port, the specific exposed port being the only path of interfacing with the hypercontainer system.
However, Sundaram discloses receiving the request at the hypercontainer system via a specific exposed port, the specific exposed port being the only path of interfacing with the hypercontainer system (col. 7, lines 13-41).
Therefore, it would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to combine Bilugu, Kaimal and Sundaram in order to protect security credentials and other operational information on the storage gateway from being intentionally or unintentionally compromised by person or processes on the client network or by external persons or networks (Sundaram, col. 7 lines 13-41).
Regarding claims 14 and 19, see claim 7 above for the same reasons of rejections.
Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Bilugu et al. (US 2022/0124117 hereinafter Bilugu) in view of Kaimal et al. US 2023/0319093 hereinafter Kaimal) and further in view of Pratt (US 10,140,139).
Regarding claim 20, Bilugu in view of Kaimal discloses the apparatus of claim 15.
Bilugu in view of Kaimal does not explicitly disclose the hypercontainer system executes using an address range reserved for use exclusively by the hypercontainer system.
However, Pratt discloses the hypercontainer system executes using an address range reserved for use exclusively by the hypercontainer system (col. 4, lines 12-22).
Therefore, it would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to combine Bilugu, Kaimal and Pratt in order to prevent a malicious host operating system from accessing a portion of resources reserved for isolated computing container (Pratt, col. 1 lines 27-60, col. 2, lines 27-46).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHI D NGUY whose telephone number is (571)270-7311. The examiner can normally be reached Monday-Friday 9-5 ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571)270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/C.D.N/Examiner, Art Unit 2435
/AMIR MEHRMANESH/Supervisory Patent Examiner, Art Unit 2435