DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This written action is responding to the Requested Continued Examination on 07/09/2025 and the Supplemental submitted on 08/11/2025.
Claims 1-13 and 17-23 are submitted for examination.
Claims 1-13 and 17-23 are pending.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 07/09/2025 has been entered.
Response to Arguments
Applicant’s amendment filed on 07/09/2025 and the Supplemental submitted on 08/11/2025 has claims 1-3, 6-7 and 18-19 have been amended, claims 14-16 canceled and 21-23 have been added.
Applicant’s arguments, presented in the remarks dated on 08/11/2025, at pages 10-11, indicates “Applicant submits that the cited references fail to disclose or suggest, at least, receiving, from the key storage service, data representative of the requested cryptographic key and the cryptographic algorithm associated with the cryptographic operation of the user request; cryptographically processing the request portion of the large-scale dataset based on the received data representative of the requested cryptographic key and cryptographic algorithm. In contrast, Sloan at most describes generating a key for encrypting data and transmitting the key to the central control module. However, Applicant's claim 1 recites, receiving, from the key storage service, data representative of the requested cryptographic key. Data representative of the requested cryptographic key is not the same as a cryptographic key. In particular, Sloan describes that a key management and storage module generates a key for encrypting the data, which is a cryptographic key. Sloan, para. 123. In contrast, Applicant recites that data representative of the requested cryptographic key is transmitted from a key storage service. Applicant further submits that at least the aforementioned features are neither disclosed nor suggested by the cited references: attempting to perform the cryptographic operation at the key storage service; determining that a scale of the cryptographic operation exceeds a threshold scale and is unable to be performed at the key storage service; ... storing, in a data storage, the cryptographically processed portion, wherein the data storage prevents any one or more non- cryptographic operations from being performed on the cryptographically processed portion;... and in response to the compute service/key storage service receiving a request to perform a non- cryptographic operation on the large-scale dataset, sending, by the compute service, a denial of the request to perform the non-cryptographic operation. … Accordingly, Applicant submits that the present application is now in condition for allowance.”
Applicant’s argument has been considered and is found persuasive. Therefore, the previous prior-art rejection is withdrawn. However, Applicant’s amendment necessitates a new ground of rejection.
Accordingly, a new ground of rejection based on the newly identified prior-arts by Munsil et al. (US 2020/0065500) hereinafter Munsil and L’Heureux et al. (US 8,621,036) hereinafter L’Heureux has been applied to the amendment.
Specifically, Munsil discloses a method for determining when a large dataset, required to be encrypted, exceeds a threshold size, thus, the system or device cannot performed the requested cryptographic operation. For example, Parag. [0029] discloses: “Thus, host data of a size that exceeds a constraint of an encryption operation is received and the host data is separated or divided into segments that satisfy the constraints or requirements of the encryption operation.” Therefore, Munsil clearly teaches the amended limitation “determining that a scale of the cryptographic operation exceeds a threshold scale and is unable to be performed at the key storage service”. See rejection below.
L’Heureux discloses a method where a system grants or denies access to an encrypted data file based on a user profile. The user request to perform actions like open, save, copy and print (i.e., the claimed non-cryptographic operations) on an encrypted file. Specifically, the teaching in Col. 8, lines 11-22 describes the following: “as previously described, the set of one or more designated actions may include, for example, one or more of an open action, a save action, a save as action, a copy action, a print action. The access query may further indicate a requested designated action to be performed on the file. The access reply may indicate whether the requested designated action indicated by the access query is authorized to be performed. If, for example, a requested designated action is not authorized to be performed, the file access server may withhold the second decryption key from the requesting computing device to deny the requested access.” Therefore, L’Heureux discloses the featured amended limitation “wherein the data storage prevents any one or more non-cryptographic operations from being performed on the cryptographically processed portion”. See rejection below.
Additionally, Examiner respectfully submits that the previously applied reference by Sloan teaches the newly amended feature “in response to the compute service receiving a request to perform a non-cryptographic operation on the … dataset, sending, by the compute service, a denial of the request to perform the non-cryptographic operation”. Sloan at Parag. [0133] teaches a system that includes an storage for storing documents (in plaintext or encrypted) along with access policies. When a user tries to access or perform an operation on a document, the system determines if the user has the appropriate access to perform non-cryptographic operations, like write or read. Depending of the access level the systems will allow or deny the requested operation.” Finally, Examiner respectfully submits that this feature is an obvious design choice. The system/device could send an indication whether a cryptographic operation or non-cryptographic operation is performed or not.).
Finally, Applicant argues that Sloan does not teach accessing the cryptographic material and the cryptographic algorithm from a key server. Examiner acknowledge that Sloan does not expressly teach that the key server process and provides the key material and the algorithm. However, the combination of Sloan and Ma teaches the limitation. Ma teaches at applying for a key from a token and an identification code to a key management service (i.e., key server) comprises: sending, by the object storage gateway, the token and the identity to a key management service; accessing, by a key management service, an authentication token of an authentication service; and accessing the database multi-master synchronization cluster by the key management service in response to the token passing the verification to obtain a key corresponding to the identification code and sending the key to the object storage gateway. See page 4 at Ma prior art.
Examiner respectfully submits that the newly formulated rejection based on the combination of Sloan, Munsil, Ma and L’Heureux would render the claimed limitations of the amended independent claim 1 obvious. Same rationale applied to independent claims 2 and 3.
Regarding newly added claims 21 and 23, the Examiner submits that the combination of Sloan, Munsil, Ma and L’Heureux discloses the claimed features. See the aforementioned response at item 8 and the rejection below.
Regarding newly added claim 22, the Examiner submits that the combination of Sloan, Munsil, Ma and L’Heureux discloses the claimed features. See the aforementioned response at item 8 and the rejection below. Additionally, the prior art reference by Carlough et al. (US) hereinafter Carlough. Specifically, Carlough discloses a rate of access to cryptographic keys that can be used to performed cryptographic operations that is protected using the cryptographic keys. In an example, a user of a computing resource service provider submits a request to a cryptographic key management service to impose a rate limit (i.e., the attribute) for accessing a cryptographic key managed by the computing resource service provider. Multiple grants can be generated and may specify that the user is authorized to utilize the cryptographic key a certain number of times within a particular interval of time. See rejection below.
Claim Objections
Claim 22 is objected to because of the following informalities: the claim recites “the cryptographic operation of the user request is associated with a second attribute associated with the second cryptographic operation”. However, it is not clear if the meaning of a second attribute it is the same as claimed first attribute that comprises a scale or a rate of the first cryptographic operation. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claim 1 (and similarly for independent claims 2 and 3) is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The specification as originally filed on 06/22/2022, does not describe the limitation “determining that a scale of the cryptographic operation exceeds a threshold scale and is unable to be performed at the key storage service” and “in response to determining that the scale of the cryptographic operation exceeds the threshold scale …”. As best, the specification discloses at page 10, lines 6-10; “The system may include a key storage service and a compute service operating in a high trust environment, where the key storage service is configured to delegate the performance of cryptographic operations on large-scale datasets to the compute service when the computing resources of the key storage service are not capable of processing the large-scale datasets.” In addition, page 23, lines 20-25; describes “In some embodiments, a user 110 of user device 108 may request a cryptographic operation (e.g. encryption or decryption) or a compute job with cryptographic operations to be performed on a portion of a large-scale dataset in which the portion of the large-scale dataset is large enough such that the key storage service 102 does not have the necessary computing resources to perform the cryptographic operation.” Therefore, Examiner submits that the description from the specification of the instant application fails to provide adequate support for the limitations presented above. Specifically, the specification does not adequately describe or provide a definition on the limitation, “a scale of the cryptographic operation” and how such a “scale” of the cryptographic operation is measured or determined. Furthermore, the specification of the instant application fails to describe or convey what constitutes the claimed “threshold scale”, or how the system determines that the operation “exceeds” that threshold. In view of the absence of such disclosure, it is unclear how the inventor had possession of this aspect of the invention at the time of filing.
Claims 4-13 and 21-23 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. (pre-AIA ), first paragraph, as they are dependent to independent claim 1.
Claims 17-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. (pre-AIA ), first paragraph, as they are dependent to independent claim 2.
Claim 1 (and similarly for independent claims 2 and 3) is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The specification as originally filed on 06/22/2022, does not describe the limitation “sending, from the key storage service to the compute service, data representative of the requested cryptographic key and the cryptographic algorithm associated with the cryptographic operation of the user request, while prohibiting access to the data representative of the requested cryptographic key by the user device or the user …”. As best, the specification discloses at page 3, lines 3-16; “in response to the key storage service granting cryptographic access to the compute service, performing the steps of: receiving, from the key storage service, data representative of the requested cryptographic key and the cryptographic algorithm associated with the cryptographic operation of the user request; cryptographically processing the request portion of the large-scale dataset based on the received cryptographic key and cryptographic algorithm; and sending, to the user device, a user response indicating the portion of the large-scale dataset has been cryptographically processed; in response to the key storage service determining user does not have permission and/or denying cryptographic key access to the compute service based on the user token and/or compute service token, sending, to the user device, a user response indicating denial of the user request.” Therefore, Examiner submits that the description from the specification of the instant application fails to provide adequate support for the limitations presented above. Specifically, the specification does not adequately describe or provide a definition on the limitation, “prohibiting access to the data representative”. In view of the absence of such disclosure, it is unclear how the inventor had possession of this aspect of the invention at the time of filing.
Claims 4-13 and 21-23 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. (pre-AIA ), first paragraph, as they are dependent to independent claim 1.
Claims 17-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. (pre-AIA ), first paragraph, as they are dependent to independent claim 2.
Claim 1 (and similarly for independent claims 2 and 3) is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The specification as originally filed on 06/22/2022, does not describe the limitation “storing, in a data storage, the cryptographically processed portion, wherein the data storage prevents any one or more non-cryptographic operations from being performed on the cryptographically processed portion” and “in response to the compute service receiving a request to perform a non-cryptographic operation on the large-scale dataset, sending, by the compute service, a denial of the request to perform the non-cryptographic operation …”. As best, the specification discloses, on page 17, lines 3-9, “Said computational and/or storage nodes are configured to trust each other. In addition, high trust environment is one in which only highly trusted code may executed inside the compute engine and/or key storage service. Users can be authenticated in the system, but are unable to write and execute code within the nodes of the high trust environment. For example, a compute service in the high trust environment may only perform or execute certain approved operations on the compute engine, which in this case is encryption and/or other cryptographic operations”. In addition, on pages 14-15, lines 30-6, the specification describes the data storage, as follows: “Data Storage: Any computer readable storage medium and/or device (or collection of data storage mediums and/or devices). Examples of data stores include, but are not limited to, optical disks (e.g., CD-ROM, DVD-ROM, etc.), magnetic disks (e.g., hard disks, floppy disks, etc.), memory circuits (e.g., solid state drives, random-access memory (RAM), etc.), and/or the like. Another example of a data store is a hosted storage environment that includes a collection of physical data storage devices that may be remotely accessible and may be rapidly provisioned as needed (commonly referred to as "cloud" storage)”. Therefore, Examiner submits that the description from the specification of the instant application fails to provide adequate support for the limitations presented above. Specifically, the specification merely states that a user is unable to write or execute code within the trust environment, but does not describe how the data storage itself prevents the claimed non-cryptographic operations being performed or denies a request for performing non-cryptographic operations. In view of the absence of such disclosure, it is unclear how the inventor had possession of this aspect of the invention at the time of filling.
Claims 4-13 and 21-23 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. (pre-AIA ), first paragraph, as they are dependent to independent claim 1.
Claims 17-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. (pre-AIA ), first paragraph, as they are dependent to independent claim 2.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-8, 11-12, 17-21 and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Sloan et al. (WO 2012/120313) hereinafter Sloan in view of Munsil et al. (US 2020/0065500) hereinafter Munsil and further in view of Ma (CN 110602132A) and L’Heureux et al. (US 8,621,036) hereinafter L’Heureux.
As per Claim 1, Sloan teaches a computer-implemented method for performing a cryptographic operation in a high-trust environment (Sloan, Parag. [0095]; “The cryptographic management system 10 provides a trusted and secure environment which carries out cryptography functions, such as encrypting and decrypting data files, on request from a registered user from within a user entity of the system.”) comprising a compute service (Sloan, Parag. [0102]; “A central control module 24 is connected to the interface modules 20, 21 and to the user authentication module 22. The central control module 24 is configured to start a cryptographic operation session on receipt of an identity token issued on successful authentication of a user by the authentication and identity token modules.”) and key storage service (Sloan, Parag. [0105]; “A key management and storage module 26 is connected to the central control module. The key management and storage module is configured to create, transport, refresh, archive and destroy cryptographic material including cryptographic keys and digital certificates, as required in order to perform requested cryptographic operations.”), the method comprising:
receiving, at the compute service from a user device, a user request for performing a cryptographic operation [on at least a portion of a large-scale dataset] (Sloan, Parag. [0027]; “The reference to a user entity being located remotely from the system means a user entity having a user computing system which is located remotely from the system. The user computing system may comprise one or more user devices.” … Parag. [0049]; “receiving from one of said plurality of user entities a request to perform one or more cryptographic operations.” … Parag. [0097]; “The cryptographic management system 10 comprises an abstracted interface module 20, through which users within a user entity interact with the system to perform cryptographic operations. The abstracted interface module 20 provides a graphical user interface which can be accessed by users of the system. Alternatively, or in addition, the abstracted interface module 20 may provide an automated mechanism which operates under software control without user intervention. The abstracted interface module is used to submit a request for cryptographic services to the system. The graphical user interface (if present) may prompt the user to provide authentication credentials, details of cryptographic operations to be performed”), the user request including a user token associated with a user of the user device (Sloan, Parag. [0019]; “interface means for receiving from one of said plurality of user entities a request to perform one or more cryptographic operations, and authentication information for identifying the user entity, associated with the request (i.e. user identity token).” … Parag. [0097]; “The graphical user interface (if present) may prompt the user to provide authentication credentials (i.e., user identity token), details of cryptographic operations to be performed” … Parag. [0100]; “The user authentication module is configured to receive users' authentication credentials from the relevant interface module, and then to verify the authentication of a user by means of, for example, a username and password, RADIUS authentication, two factor authentication, and/or service issued third party digital certificates. Such authentication means are referred to herein as "identity tokens".);
sending, by the compute service to the key storage service, a cryptographic key access request corresponding to the received user request (Sloan, Parag. [0049]; “receiving from one of said plurality of user entities a request to perform one or more cryptographic operations.” … Parag. [0095]; “The cryptographic management system 10 provides a trusted and secure environment which carries out cryptography functions, such as encrypting and decrypting data files, on request from a registered user from within a user entity of the system.” … Parag. [0105]; “The central control module 24 is configured to identify the cryptographic material required to perform a requested operation, and obtain this from the key management and storage module 26. This may involve, for example, requesting an existing stored key or the generation and storage of a new key.”), the cryptographic key access request including data representative of the user token or a compute service token (Sloan, Parag. [0120]-[0123]; “The request includes authentication information (i.e., user token) for user A. The request also attaches document X, and includes an indication that user A is entitled to read/write access to the document and that user B is entitled to read only access to the document. The abstracted interface module 20 receives the request and passes the authentication information to the authentication module 22. On successful authentication of user A, the authentication module passes an identity token for user A to the central control module 24. The central control module obtains details of the requested operation, and looks up the rights policy for user A. The central control module finds that user A is authorised to upload encrypted documents to the data centre. The central control module 24 then updates the access rights policy information stored therein, to indicate that user A is entitled to read/write access to the document, and that user B is entitled to read only access. Accordingly, the central control module 24 forwards the request to the key management and storage module 26. The key management generates a key for encrypting the data, and stores the new key together with details which identify the document to be encrypted. The key is then transmitted to the central control module.” Examiner submits that the compute service token is an optional feature.);
processing, [at the key storage service], the user token or compute service token to determine whether the user has permission to have the cryptographic operation performed and whether to grant the compute service access to data representative of the cryptographic key associated with the cryptographic operation of the user request when the user has permission (Sloan, Parag. [0102]; “the central control module 24 receives details of the requested operation(s) from the interface module 20. These details, together with user details contained in the identity token are looked up in an access rights policy database 25. The access rights policy database stores details of access rights for each registered user. These details indicate whether a requested cryptographic operation may be performed on behalf of that user. The access rights database may comprise general access rights details, and access rights details which relate to specific data files.” … Parag. [0105-0106]; “The central control module 24 is configured to identify the cryptographic material required to perform a requested operation, and obtain this from the key management and storage module 26. This may involve, for example, requesting an existing stored key or the generation and storage of a new key. Having identified a permitted request for an authenticated user, and obtained the necessary cryptographic material from the key management and storage module 26, the central control module 24 determines whether a data file is required in order to complete the requested operation and the location of that file, and then obtains the file for processing.”);
[in response to the key storage service granting access to the compute service], performing the steps of:
attempting to perform the cryptographic operation at the key storage service (Sloan, Parag. [0123]; “Accordingly, the central control module 24 forwards the request to the key management and storage module 26. The key management generates a key for encrypting the data, and stores the new key together with details which identify the document to be encrypted. The key is then transmitted to the central control module.”);
[determining that a scale of the cryptographic operation exceeds a threshold scale and is unable to be performed at the key storage service];
in response to determining that the scale of the cryptographic operation exceeds the threshold scale, sending, from the key storage service to the compute service, data representative of the requested cryptographic key (Sloan, Parag. [0123]; “Accordingly, the central control module 24 forwards the request to the key management and storage module 26. The key management generates a key for encrypting the data, and stores the new key together with details which identify the document to be encrypted. The key is then transmitted to the central control module.”) and [the cryptographic algorithm associated with the cryptographic operation of the user request], while prohibiting access to the data representative of the requested cryptographic key by the user device or the user (Sloan, Parag. [0103]; “If the user is not authenticated, or if one or more operations are not permitted, the central control module will trigger the interface module to return a suitable error message to the user.”);
cryptographically processing, by the compute service, [the portion of the large-scale dataset] based on the received data representative of the requested cryptographic key and [cryptographic algorithm] (Sloan, Parag. [0124]; “The central control module 24 then selects a suitable security module 27, 28 to perform the operation, and prepares instructions to perform the operation in a language/interface appropriate to the selected security module. The instructions are forwarded to the selected security module together with the key and the document (i.e., data) to be encrypted.”);
storing, in a data storage, the cryptographically processed [portion] (Sloan, Parag. [0112]; “For example, if a user A requests the system to store an encrypted version of document X at a specified location in a data centre, the selected security module will encrypt document X and the central control module 24 will route the encrypted document to the data centre 14.” … Parag. [0120]; “user A may send document X to the cryptographic management system 10 over the network, with a request to store an encrypted version of the document at a specified location in the data centre 14.”), [wherein the data storage prevents any one or more non-cryptographic operations from being performed on the cryptographically processed portion];
sending a user response indicating [the portion of the large-scale] dataset has been cryptographically processed (Sloan, Parag. [0120]; “user A may send document X to the cryptographic management system 10 over the network, with a request to store an encrypted version of the document at a specified location in the data centre 14. The request includes authentication information (i.e., identity token) for user A. The request also attaches document X, and includes an indication that user A is entitled to read/write access to the document.” … Parag. [0124-0125]; “The central control module 24 then selects a suitable security module 27, 28 to perform the operation, and prepares instructions to perform the operation in a language/interface appropriate to the selected security module. The instructions are forwarded to the selected security module together with the key and the document to be encrypted. The security module 27, 28 encrypts the document according to the instructions, and returns the encrypted document to the control centre for onward transmission to the specified location in the data centre 14, via the abstracted interface module. The central control module 24 also triggers the abstracted interface module 20 to send confirmation of successful completion of the task to user A (i.e. cryptographic operation performed).” (Examiner submits that the confirmation sent to user is an indication that the cryptographic operation (encryption/decryption) requested by the user has been executed accordingly.); and
in response to the key storage service determining user does not have permission and denying cryptographic key access to the compute service, sending, by the compute service, a user response indicating denial of the user request (Sloan, Parag. [0103]; “If the user is not authenticated, or if one or more operations are not permitted, the central control module will trigger the interface module to return a suitable error message to the user.”) and
in response to the compute service receiving a request to perform a non-cryptographic operation on the large-scale dataset, sending, by the compute service, a denial of the request to perform the non-cryptographic operation (Sloan, Parag. [0133]; “Similarly, if user C attempts to access the document, when the central control module 24 looks up the access rights policy for user C, it finds no indication that C is entitled to decrypt the document. By default, if no positive permission is specified in relation to a specific operation and document, permission is denied. Thus, an error message is returned to user C and the decryption and document retrieval operations are not performed.” Examiner submits that this feature is an obvious design choice. The system/device could send an indication whether a cryptographic operation or non-cryptographic operation is performed or not.).
Sloan does not expressly teach:
performing a cryptographic operation on at least a portion of a large-scale dataset,
the cryptographically processed portion …
processing, at the key storage service, the … compute service token;
in response to the key storage service granting access to the compute service …;
attempting to perform the cryptographic operation at the key storage service;
determining that a scale of the cryptographic operation exceeds a threshold scale and is unable to be performed at the key storage service;
in response to determining that the scale of the cryptographic operation exceeds the threshold scale sending, … the cryptographic algorithm associated with the cryptographic operation of the user request;
cryptographically processing, … dataset based on the received … and cryptographic algorithm; and
the portion of the large-scale dataset has been cryptographically processed
wherein the data storage prevents any one or more non-cryptographic operations from being performed on the cryptographically processed portion
However, Munsil teaches:
performing a cryptographic operation on at least a portion of a large-scale dataset (Munsil, Parag. [0026]; “The encryption operation utilized by the conventional memory sub-system can operate on data blocks based on certain constraints such as the size of the data blocks. For example, the encryption operation can encrypt data blocks that are less than or equal to a threshold size but cannot be used to securely encrypt data blocks that are larger than the threshold size. Certain host systems can provide host data as data blocks at a large size that exceeds the threshold size utilized by the encryption operation. Thus, if the conventional memory sub-system is utilized by a host system that provides the host data as data blocks of a large size that exceeds the capability of the encryption operation utilized by the conventional memory sub-system, then the memory sub-system will not be able to encrypt the host data.”)
the cryptographically processed portion (Munsil, Parag. [0029]; “Referring to FIG. 2, at block 240 the processing logic performs the encryption operation with the segments of data and, at block 250, the processing logic stores the encrypted segments of data at the memory sub-system. Thus, host data of a size that exceeds a constraint of an encryption operation is received and the host data is separated or divided into segments that satisfy the constraints or requirements of the encryption operation.”)
determining that a scale of the cryptographic operation exceeds a threshold scale and is unable to be performed at the key storage service (Munsil, Abstract; “A determination can be made that the host data exceeds a threshold size associated with an encryption operation.” … Parag. [0014]; “Certain host systems can provide host data as data blocks at a large size that exceeds the threshold size utilized by the encryption operation. Thus, if the conventional memory sub-system is utilized by a host system that provides the host data as data blocks of a large size that exceeds the capability of the encryption operation utilized by the conventional memory sub-system, then the memory sub-system will not be able to encrypt the host data.” … Parag. [0029]; “Thus, host data of a size that exceeds a constraint of an encryption operation is received and the host data is separated or divided into segments that satisfy the constraints or requirements of the encryption operation.”); and
in response to determining that the scale of the cryptographic operation exceeds the threshold scale (Munsil, Abstract; “A determination can be made that the host data exceeds a threshold size associated with an encryption operation.” … Parag. [0014]; “Certain host systems can provide host data as data blocks at a large size that exceeds the threshold size utilized by the encryption operation. Thus, if the conventional memory sub-system is utilized by a host system that provides the host data as data blocks of a large size that exceeds the capability of the encryption operation utilized by the conventional memory sub-system, then the memory sub-system will not be able to encrypt the host data.” … Parag. [0029]; “Thus, host data of a size that exceeds a constraint of an encryption operation is received and the host data is separated or divided into segments that satisfy the constraints or requirements of the encryption operation.”) sending, … the cryptographic algorithm associated with the cryptographic operation of the user request (Munsil, Parag. [0030]; “The encryption of the segments of data can utilize the XTS-AES encryption operation. In some embodiments, the XTS - AES encryption operation can encrypt each segment based on a first cryptographic key, a second cryptographic key, and a tweak value. Each segment of data can be encrypted by using the first cryptographic key and the second cryptographic key and a different tweak value. For example, a first segment of the data can be encrypted by the XTS-AES encryption operation with the first and second cryptographic keys and a first tweak value. For the next segment of the data, the first tweak value can be incremented to generate a second tweak value. The next segment of data can be encrypted with the same first and second crypto graphic keys and the second tweak value. For each subsequent segment of data, the tweak value can be incremented and used to encrypt the respective segment of data.”);
cryptographically processing, … dataset based on the received … and cryptographic algorithm (Munsil, Parag. [0029-0030]; “Referring to FIG. 2, at block 240 the processing logic performs the encryption operation with the segments of data and, at block 250, the processing logic stores the encrypted segments of data at the memory sub-system. Thus, host data of a size that exceeds a constraint of an encryption operation is received and the host data is separated or divided into segments that satisfy the constraints or requirements of the encryption operation. The encryption of the segments of data can utilize the XTS-AES encryption operation. In some embodiments, the XTS - AES encryption operation can encrypt each segment based on a first cryptographic key, a second cryptographic key, and a tweak value. Each segment of data can be encrypted by using the first cryptographic key and the second cryptographic key and a different tweak value. For example, a first segment of the data can be encrypted by the XTS-AES encryption operation with the first and second cryptographic keys and a first tweak value. For the next segment of the data, the first tweak value can be incremented to generate a second tweak value. The next segment of data can be encrypted with the same first and second crypto graphic keys and the second tweak value. For each subsequent segment of data, the tweak value can be incremented and used to encrypt the respective segment of data.”);
the portion of the large-scale dataset has been cryptographically processed (Munsil, Parag. [0029]; “Referring to FIG. 2, at block 240 the processing logic performs the encryption operation with the segments of data and, at block 250, the processing logic stores the encrypted segments of data at the memory sub-system. Thus, host data of a size that exceeds a constraint of an encryption operation is received and the host data is separated or divided into segments that satisfy the constraints or requirements of the encryption operation.”)
Sloan and Munsil are from similar field of technology. Prior to the instant application’s effective filling date, there was a need for a method for encrypting large data sets in trusted environments.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Munsil system into Sloan-Murray-Ma system, with a motivation to provide a method for determining when a data size exceeds a threshold (Munsil, Abstract).
The combination of Sloan and Munsil does not expressly teach:
processing, at the key storage service, the … compute service token
in response to the key storage service granting access to the compute service …
wherein the data storage prevents any one or more non-cryptographic operations from being performed on the cryptographically processed portion
However, Ma teaches:
processing, at the key storage service, the … compute service token (Ma, page 4, lines 3-7; “In some embodiments, applying for a key from a token and an identification code to a key management service comprises: sending, by the object storage gateway, the token and the identity to a key management service; accessing, by a key management service, an authentication token of an authentication service; and accessing the database multi-master synchronization cluster by the key management service in response to the token passing the verification to obtain a key corresponding to the identification code and sending the key to the object storage gateway.”)
in response to the key storage service granting access to the compute service (Ma, page 4, lines 3-7; “In some embodiments, applying for a key from a token and an identification code to a key management service comprises: sending, by the object storage gateway, the token and the identity to a key management service; accessing, by a key management service, an authentication token of an authentication service; and accessing the database multi-master synchronization cluster by the key management service in response to the token passing the verification to obtain a key corresponding to the identification code and sending the key to the object storage gateway.”) …
Sloan, Munsil and Ma are from similar field of technology. Prior to the instant application’s effective filling date, there was a need for a method for encrypting large data sets in trusted environments.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Ma system into Sloan-Murray system, with a motivation to provide a method for providing device authentication using a token or credentials (Ma, Page. 4).
The combination of Sloan, Munsil and Ma does not expressly teach:
wherein the data storage prevents any one or more non-cryptographic operations from being performed on the cryptographically processed portion
However, L’Heureux teaches:
wherein the data storage prevents any one or more non-cryptographic operations from being performed on the cryptographically processed portion (L’Heureux, Col. 6, lines 1-5; “FIG. 2 further depicts file access permission data 230 including one or more user identifiers such as USERID 240, USER ID 242, and USER ID 244, and a set of one or more designated actions such as OPEN, SAVE, SAVE AS, COPY, and PRINT. (i.e., non-cryptographic operations)” … Col. 6, lines 46-53; “Operation 314 comprises saving the encrypted file to a data storage device. In at least some implementations, the encrypted file may be saved as a file having a “.ss” file extension. However, other suitable file extensions may be utilized to indicate that the file is encrypted. The encrypted file may be stored locally at a computing device in mass storage and/or may be transmitted to a remote data store for storage.” … Col. 7, lines 16-23; “Operation 318 may be performed in response to receiving the request to access the encrypted file at operation 316. In at least some implementations, the access query may further indicate an action that is requested by the computer program or by a user via the computer program, such as one or more of an open action, a save action, a save as action, a copy action, or a print action, for example.” … Col. 8, lines 11-28; “As previously described, the set of one or more designated actions may include, for example, one or more of an open action, a save action, a save as action, a copy action, a print action. The access query may further indicate a requested designated action to be performed on the file. The access reply may indicate whether the requested designated action indicated by the access query is authorized to be performed. If, for example, a requested designated action is not authorized to be performed, the file access server may withhold the second decryption key from the requesting computing device to deny the requested access. Alternatively, the process flow of method 300 may proceed to operation 326 if access has not been authorized by the file access server. Operation 326 comprises receiving an access reply from the file access server that indicates denial of access to the encrypted second segment.”)
Sloan, Munsil, Ma and L’Heureux are from similar field of technology. Prior to the instant application’s effective filling date, there was a need for a method for encrypting large data sets in trusted environments.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of L’Heureux system into Sloan-Munsil-Ma system, with a motivation to provide a method for determining if the user is allow or not allow to perform non-cryptographic operations on an encrypted file (L’Heureux, Col. 6-8).
As per claim 2, it is a method claim that recites similar limitations as of claim 1. Therefore, claim 2 is rejected based on the same rationale and motivation applied to claim 1.
As per claim 3, it is a method claim that recites similar limitations as of claim 1. Therefore, claim 3 is rejected based on the same rationale and motivation applied to claim 1.
As per claim 4, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Sloan further teaches wherein each user is associated with a cryptographic license stored in the high trust environment, and determining whether said user has permission to request said cryptographic operation based on retrieving the cryptographic license associated with the user based on said user token (Sloan, Parag. [0102]; “the central control module 24 receives details of the requested operation(s) from the interface module 20. These details, together with user details contained in the identity token are looked up in an access rights policy database 25. The access rights policy database stores details of access rights (i.e., license) for each registered user. These details indicate whether a requested cryptographic operation may be performed on behalf of that user.”).
As per claim 5, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Sloan further teaches the method comprising sending, by the compute service to the key storage service, the cryptographic key access request corresponding to the received user request (Sloan, Parag. [0105]; “The central control module 24 is configured to identify the cryptographic material required to perform a requested operation, and obtain this from the key management and storage module 26. This may involve, for example, requesting an existing stored key or the generation and storage of a new key.”), the cryptographic key access request including data representative of the user token (Sloan, Parag. [0120]-[0123]; “The request includes authentication information (i.e., user token) for user A. The request also attaches document X, and includes an indication that user A is entitled to read/write access to the document and that user B is entitled to read only access to the document. The abstracted interface module 20 receives the request and passes the authentication information to the authentication module 22. On successful authentication of user A, the authentication module passes an identity token for user A to the central control module 24. The central control module obtains details of the requested operation, and looks up the rights policy for user A. The central control module finds that user A is authorised to upload encrypted documents to the data centre. The central control module 24 then updates the access rights policy information stored therein, to indicate that user A is entitled to read/write access to the document, and that user B is entitled to read only access. Accordingly, the central control module 24 forwards the request to the key management and storage module 26. The key management generates a key for encrypting the data, and stores the new key together with details which identify the document to be encrypted. The key is then transmitted to the central control module.”) and
In addition, Ma teaches:
the compute service token (Ma, page 4, lines 3-7; “In some embodiments, applying for a key from a token and an identification code to a key management service comprises: sending, by the object storage gateway, the token and the identity to a key management service; accessing, by a key management service, an authentication token of an authentication service; and accessing the database multi-master synchronization cluster by the key management service in response to the token passing the verification to obtain a key corresponding to the identification code and sending the key to the object storage gateway.”).
As per claim 6, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Sloan further teaches the method comprising:
sending, by the compute service to the key storage service, a first cryptographic key access request corresponding to the received user request (Sloan, Parag. [0105]; “The central control module 24 is configured to identify the cryptographic material required to perform a requested operation, and obtain this from the key management and storage module 26. This may involve, for example, requesting an existing stored key or the generation and storage of a new key.”), the first cryptographic key access request including data representative of the user token (Sloan, Parag. [0120]-[0123]; “The request includes authentication information (i.e., user token) for user A. The request also attaches document X, and includes an indication that user A is entitled to read/write access to the document and that user B is entitled to read only access to the document. The abstracted interface module 20 receives the request and passes the authentication information to the authentication module 22. On successful authentication of user A, the authentication module passes an identity token for user A to the central control module 24. The central control module obtains details of the requested operation, and looks up the rights policy for user A. The central control module finds that user A is authorised to upload encrypted documents to the data centre. The central control module 24 then updates the access rights policy information stored therein, to indicate that user A is entitled to read/write access to the document, and that user B is entitled to read only access. Accordingly, the central control module 24 forwards the request to the key management and storage module 26. The key management generates a key for encrypting the data, and stores the new key together with details which identify the document to be encrypted. The key is then transmitted to the central control module.”);
processing, at the key storage service, the user token to determine whether the user has permission to have the cryptographic operation performed (Sloan, Parag. [0102]; “the central control module 24 receives details of the requested operation(s) from the interface module 20. These details, together with user details contained in the identity token are looked up in an access rights policy database 25. The access rights policy database stores details of access rights for each registered user. These details indicate whether a requested cryptographic operation may be performed on behalf of that user. The access rights database may comprise general access rights details, and access rights details which relate to specific data files.”);
In addition, Ma teaches:
in response to the key storage service determining the user has permission, sending, by the compute service to the key storage service, a second cryptographic key access request corresponding to the received user request, the second cryptographic key access request including data representative of the compute service token (Ma, page 4, lines 3-7; “In some embodiments, applying for a key from a token and an identification code to a key management service comprises: sending, by the object storage gateway, the token and the identity (i.e., compute service token) to a key management service; accessing, by a key management service, an authentication token of an authentication service; and accessing the database multi-master synchronization cluster by the key management service in response to the token passing the verification to obtain a key corresponding to the identification code and sending the key to the object storage gateway.” … lines 10-15; “it can be seen from the foregoing embodiments that, in the data encryption processing method provided in the embodiments of the present invention, the object storage gateway receives the encryption request, the original information, the user information of the key management service, and the identification code of the key management service; applying for a token to the authentication service according to the user information; applying for a key from a key management service according to the token and the identity code; the technical scheme of encrypting and storing the original information according to the secret key can improve the technical scheme of storage safety and can improve the storage safety” Examiner submits that the second request is interpreted as when the key storage process the compute service token.); and
processing, at the key storage service, the compute service token to determine whether to grant the compute service access to data representative of the cryptographic key associated with the cryptographic operation of the user request when user has permission (Ma, page 4, lines 3-7; “In some embodiments, applying for a key from a token and an identification code to a key management service comprises: sending, by the object storage gateway, the token and the identity to a key management service; accessing, by a key management service, an authentication token of an authentication service; and accessing the database multi-master synchronization cluster by the key management service in response to the token passing the verification to obtain a key corresponding to the identification code and sending the key to the object storage gateway.” … lines 10-15; “it can be seen from the foregoing embodiments that, in the data encryption processing method provided in the embodiments of the present invention, the object storage gateway receives the encryption request, the original information, the user information of the key management service, and the identification code of the key management service; applying for a token to the authentication service according to the user information; applying for a key from a key management service according to the token and the identity code; the technical scheme of encrypting and storing the original information according to the secret key can improve the technical scheme of storage safety and can improve the storage safety”).
As per claim 7, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Sloan further teaches wherein the key storage service previously granted the user permission to a previous user request, the method further comprising receiving a further request associated with the previous user request (Sloan, Parag. [0062]; “In a preferred embodiment, the system may comprise interface means for receiving authentication information for identifying a user entity of the user device. This may be the same interface means which receives the authentication information for identifying the user device, or a separate module. In this embodiment, the system may comprise authentication means for identifying the user entity. This may be the same authentication means which identifies the user device, or a separate module. In this embodiment, the session management means is preferably configured to establish a cryptographic session, only in the event that the user device and the user entity are successfully authenticated.” … Parag. [0098]; “Rather, access to cryptographic operations provided by the system is granted or denied on the basis of authentication of the identity of the user and the access rights policy in place for that user”), and sending, by the compute service to the key storage service, the cryptographic key access request corresponding to the received request (Sloan, Parag. [0105]; “The central control module 24 is configured to identify the cryptographic material required to perform a requested operation, and obtain this from the key management and storage module 26. This may involve, for example, requesting an existing stored key or the generation and storage of a new key.”),
In addition, Ma teaches the cryptographic key access request including data representative of the compute service token (Ma, page 4, lines 3-7; “In some embodiments, applying for a key from a token and an identification code to a key management service comprises: sending, by the object storage gateway, the token and the identity (i.e., compute service token) to a key management service; accessing, by a key management service, an authentication token of an authentication service; and accessing the database multi-master synchronization cluster by the key management service in response to the token passing the verification to obtain a key corresponding to the identification code and sending the key to the object storage gateway.” … lines 10-15; “it can be seen from the foregoing embodiments that, in the data encryption processing method provided in the embodiments of the present invention, the object storage gateway receives the encryption request, the original information, the user information of the key management service, and the identification code of the key management service; applying for a token to the authentication service according to the user information; applying for a key from a key management service according to the token and the identity code; the technical scheme of encrypting and storing the original information according to the secret key can improve the technical scheme of storage safety and can improve the storage safety” Examiner submits that the second request is interpreted as when the key storage process the compute service token.); and
processing, at the key storage service, the compute service token to determine whether to grant the compute service access to data representative of the cryptographic key associated with the cryptographic operations of the request when user has permission (Ma, page 4, lines 3-7; “In some embodiments, applying for a key from a token and an identification code to a key management service comprises: sending, by the object storage gateway, the token and the identity (i.e., compute service token) to a key management service; accessing, by a key management service, an authentication token of an authentication service; and accessing the database multi-master synchronization cluster by the key management service in response to the token passing the verification to obtain a key corresponding to the identification code and sending the key to the object storage gateway.” … lines 10-15; “it can be seen from the foregoing embodiments that, in the data encryption processing method provided in the embodiments of the present invention, the object storage gateway receives the encryption request, the original information, the user information of the key management service, and the identification code of the key management service; applying for a token to the authentication service according to the user information; applying for a key from a key management service according to the token and the identity code; the technical scheme of encrypting and storing the original information according to the secret key can improve the technical scheme of storage safety and can improve the storage safety” Examiner submits that the second request is interpreted as when the key storage process the compute service token.).
As per claim 8, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Ma additionally teaches determining whether said compute service is authorized to perform said cryptographic operation on at least said portion of the large-scale dataset based on said compute service token (Ma, page 4, lines 3-7; “In some embodiments, applying for a key from a token and an identification code to a key management service comprises: sending, by the object storage gateway, the token and the identity to a key management service; accessing, by a key management service, an authentication token of an authentication service; and accessing the database multi-master synchronization cluster by the key management service in response to the token passing the verification to obtain a key corresponding to the identification code and sending the key to the object storage gateway.” … lines 10-15; “it can be seen from the foregoing embodiments that, in the data encryption processing method provided in the embodiments of the present invention, the object storage gateway receives the encryption request, the original information, the user information of the key management service, and the identification code of the key management service; applying for a token to the authentication service according to the user information; applying for a key from a key management service according to the token and the identity code; the technical scheme of encrypting and storing the original information according to the secret key can improve the technical scheme of storage safety and can improve the storage safety”).
As per claim 11, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Sloan further teaches wherein each authorized user is linked to a cryptographic license stored within the high trust environment, each cryptographic license of an authorized user specifying data representative of permissions for said user to have one or more cryptographic operations performed in relation to corresponding data of a large-scale dataset, said processing the user token (Sloan, Parag. [0102]; “the central control module 24 receives details of the requested operation(s) from the interface module 20. These details, together with user details contained in the identity token are looked up in an access rights policy database 25. The access rights policy database stores details of access rights (i.e., license) for each registered user. These details indicate whether a requested cryptographic operation may be performed on behalf of that user.”) further comprising:
determining the user of the user device providing the user token is an authorized user (Sloan, Parag. [0100]; “The user authentication module is configured to receive users' authentication credentials from the relevant interface module, and then to verify the authentication of a user by means of, for example, a username and password, RADIUS authentication, two factor authentication, and/or service issued third party digital certificates. Such authentication means are referred to herein as "identity tokens".);
retrieving a linked cryptographic license corresponding to the authorized user (Sloan, Parag. [0102]; “the central control module 24 receives details of the requested operation(s) from the interface module 20. These details, together with user details contained in the identity token are looked up in an access rights policy database 25. The access rights policy database stores details of access rights (i.e., license) for each registered user. These details indicate whether a requested cryptographic operation may be performed on behalf of that user. The access rights database may comprise general access rights details, and access rights details which relate to specific data files. For example, the database may specify that a user A is entitled to create and send encrypted, digitally signed documents in a specified application. It may also specify that user A is entitled to read and overwrite a specified data file X. By default, access rights are positively specified. Thus, if the access rights database for user A does not specify a data file Y, the system will not perform a requested cryptographic operation on data file Y when requested to do so by user A.” Examiner submits that the details on the access rights (i.e., cryptographic license) needs to be retrieved in order to perform the authorized operation.); and
determining whether said authorized user has permissions to request one or more cryptographic operations to be performed on at least said portion of the large-scale dataset based on the retrieved cryptographic license (Sloan, Parag. [0100]; “The user authentication module is configured to receive users' authentication credentials from the relevant interface module, and then to verify the authentication of a user by means of, for example, a username and password, RADIUS authentication, two factor authentication, and/or service issued third party digital certificates. Such authentication means are referred to herein as "identity tokens". Parag. [0102]; “The central control module 24 is configured to start a cryptographic operation session on receipt of an identity token issued on successful authentication of a user by the authentication and identity token modules. If an identity token is not issued in association with a particular request, the central control module will trigger the relevant interface module to return an error message to the user without starting a session. The central control module 24 receives details of the requested operation(s) from the interface module 20. These details, together with user details contained in the identity token are looked up in an access rights policy database 25. The access rights policy database stores details of access rights (i.e., license) for each registered user. These details indicate whether a requested cryptographic operation may be performed on behalf of that user.”).
In addition, Munsil discloses the cryptographic operation performed into a portion of large-scale dataset (Munsil, Parag. [0026]; “The encryption operation utilized by the conventional memory sub-system can operate on data blocks based on certain constraints such as the size of the data blocks. For example, the encryption operation can encrypt data blocks that are less than or equal to a threshold size but cannot be used to securely encrypt data blocks that are larger than the threshold size. Certain host systems can provide host data as data blocks at a large size that exceeds the threshold size utilized by the encryption operation. Thus, if the conventional memory sub-system is utilized by a host system that provides the host data as data blocks of a large size that exceeds the capability of the encryption operation utilized by the conventional memory sub-system, then the memory sub-system will not be able to encrypt the host data.”).
As per claim 12, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Sloan teaches wherein the one or more cryptographic operations comprises at least one from the group of:
encryption;
decryption;
hashing; and/or any other cryptographic function or operation (Sloan, Parag. [0035]; “The cryptographic operations performed by the system preferably include encryption of specified data and decryption of specified data. They preferably include digital signing of specified data and verification of digital signatures and data. They preferably include re-keying of data.”).
As per claim 17, the rejection of claim 2 is included and it is a method claim that recites similar limitations as disclosed in claim 5. Therefore, claim 17 is rejected based on the same rationale applied to claim 5.
As per claim 18, the rejection of claim 2 is included and it is a method claim that recites similar limitations as disclosed in claim 6. Therefore, claim 18 is rejected based on the same rationale applied to claim 6.
As per claim 19, the rejection of claim 2 is included and it is a method claim that recites similar limitations as disclosed in claim 7. Therefore, claim 19 is rejected based on the same rationale applied to claim 7.
As per claim 20, the rejection of claim 2 is included and it is a method claim that recites similar limitations as disclosed in claim 8. Therefore, claim 20 is rejected based on the same rationale applied to claim 8.
As per claim 21, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Sloan teaches further comprising deleting the data representative of the cryptographic key in response to cryptographically processing, by the compute service, the portion of the large-scale dataset (Sloan, Parag. [0046]; “erasure means for causing cryptographic material provided by the system to the device to be deleted from the device on termination of the cryptographic session.” … Parag. [0081]; “perform cryptographic operations using said cryptographic material during a cryptographic session; and delete cryptographic material provided by the system on termination of a cryptographic session.”).
As per claim 23, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Sloan teaches wherein the determining whether the user has permission comprises determining particular entries that the user has permission (Sloan, Parag. [0052]; “determining whether the cryptographic operation (s) requested by a user entity are permitted in accordance with the access rights stored for the user entity as identified at the authentication step; and permitting only those operation (s) which are permitted by said access rights to be performed.”).
Claims 9 and 10 are rejected under 35 U.S.C. 103 as being unpatentable over Sloan et al. (WO 2012/120313) hereinafter Sloan in view of Munsil et al. (US 2020/0065500) hereinafter Munsil and further in view of Ma (CN 110602132A) and L’Heureux et al. (US 8,621,036) hereinafter L’Heureux as applied to claim 8, and Grawrock (US 2004/0117318).
As per claim 9, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 8.
The combination of Sloan, Munsil, Ma and L’Heureux does not expressly teach:
wherein the compute service token is generated for the compute service when the compute service operates in the high trust environment, and determining whether said compute service is authorized to perform said cryptographic operation further comprising determining the compute service operates in the high trust environment based on said compute service token.
However, Grawrock teaches:
wherein the compute service token is generated for the compute service when the compute service operates in the high trust environment, and determining whether said compute service is authorized to perform said cryptographic operation further comprising determining the compute service operates in the high trust environment based on said compute service token (Grawrock, Abstract, “In one embodiment, the computing device stores information on the portable token that is required in order to launch the trusted environment. In another embodiment, information that is required to launch the trusted environment is encrypted with a key that has been sealed to a portable token.” … Parag. [0003]; “Further, the fixed token may be used by a computing device to establish a trust environment in which secrets may be protected. In particular, the trusted environment may encrypt such secrets such that only the trusted environment may decrypt the secrets. Accordingly, untrusted environments are unable to obtain such secrets without requesting the trusted environment for the secrets. While this generally provides an isolated container for protecting secrets, a local user of the computing device may want further assurances that the computing device will not release secrets of a trusted environment without the authorization of the user or the user being present.”)
Sloan, Munsil, Ma, L’Heureux and Grawrock are from similar field of technology. Prior to the instant application’s effective filling date, there was a need for a method for encrypting large data sets in trusted environments.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Grawrock system into Sloan-Munsil-Ma-L’Heureux system, with a motivation to provide a method for determining that a device is authorized to perform cryptographic operations by verifying a device token (Grawrock, Abstract).
As per claim 10, the combination of Sloan, Munsil, Ma, L’Heureux and Grawrock teaches the computer-implemented method according to claim 9. Grawrock teaches wherein the compute service operates in the high trust environment when the compute service only executes cryptographic operations approved or authorized by the operator of the high trust environment (Grawrock, Abstract, “In one embodiment, the computing device stores information on the portable token that is required in order to launch the trusted environment. In another embodiment, information that is required to launch the trusted environment is encrypted with a key that has been sealed to a portable token.” … Parag. [0003]; “Further, the fixed token may be used by a computing device to establish a trust environment in which secrets may be protected. In particular, the trusted environment may encrypt such secrets such that only the trusted environment may decrypt the secrets. Accordingly, untrusted environments are unable to obtain such secrets without requesting the trusted environment for the secrets. While this generally provides an isolated container for protecting secrets, a local user of the computing device may want further assurances that the computing device will not release secrets of a trusted environment without the authorization of the user or the user being present.”).
Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Sloan et al. (WO 2012/120313) hereinafter Sloan in view of Munsil et al. (US 2020/0065500) hereinafter Munsil and further in view of Ma (CN 110602132A) and L’Heureux et al. (US 8,621,036) hereinafter L’Heureux as applied to claim 1, and further in view of Horvath (EP 3407237 A1).
As per claim 13, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Sloan teaches wherein the one or more cryptographic operations comprises an encryption cryptographic operation (Sloan, Parag. [0035]; “The cryptographic operations performed by the system preferably include encryption of specified data and decryption of specified data. They preferably include digital signing of specified data and verification of digital signatures and data. They preferably include re-keying of data.”) and the portion of the large-scale dataset is at least one from the group of: a bulk dataset or full dataset.
The combination of Sloan, Munsil, Ma and L’Heureux does not expressly teach:
the portion of the large-scale dataset is at least one from the group of: a bulk dataset or full dataset
Horvath teaches:
the portion of the large-scale dataset is at least one from the group of: a bulk dataset or full dataset (Horvath, page 6, parag. 3; “A dataset here describes a non-empty finite set of data elements or data objects. In this case, a data volume comprises at least one data element. Data elements may include, for example, letters, numbers, special characters, or the like, as well as combinations thereof, such as formulas, words, numerical values, measurements, strings, or the like. For example, a dataset may include datasets, data fields, or data items. For example, a dataset may include a set of metrics or words. For example, a set of data includes one or more sentences, paragraphs, paragraphs, or chapters. Further, a set of data may include a text such as an essay, a scientific journal article, a document, a study, a journal, a book, or the like. Likewise, a quantity of data may also include image and/or sound data, such as photo, video, or sound recordings.”)
Sloan, Munsil, Ma, L’Heureux and Horvath are from similar field of technology. Prior to the instant application’s effective filling date, there was a need for a method for encrypting large data sets in trusted environments.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Horvath system into Sloan-Munsil-Ma-L’Heureux system, with a motivation to provide a method for to perform cryptographic operations on a dataset belonging to bulk or group (Horvath, Page 6).
Claim 22 is rejected under 35 U.S.C. 103 as being unpatentable over Sloan et al. (WO 2012/120313) hereinafter Sloan in view of Munsil et al. (US 2020/0065500) hereinafter Munsil and further in view of Ma (CN 110602132A) and L’Heureux et al. (US 8,621,036) hereinafter L’Heureux as applied to claim 1, and further in view of Carlough, et al. (US 10,313,117) hereinafter Carlough.
As per claim 22, the combination of Sloan, Munsil, Ma and L’Heureux teach the computer-implemented method according to claim 1. Sloan teaches wherein the user request comprises a first user request (Sloan, Parag. [0027]; “The reference to a user entity being located remotely from the system means a user entity having a user computing system which is located remotely from the system. The user computing system may comprise one or more user devices.” … Parag. [0049]; “receiving from one of said plurality of user entities a request to perform one or more cryptographic operations.”);
the cryptographic operation comprises a first cryptographic operation (Sloan, Parag. [0027]; “The reference to a user entity being located remotely from the system means a user entity having a user computing system which is located remotely from the system. The user computing system may comprise one or more user devices.” … Parag. [0049]; “receiving from one of said plurality of user entities a request to perform one or more cryptographic operations.”); and
[the data representative of the requested cryptographic key and the cryptographic algorithm identifies a first attribute associated with the first cryptographic operation, the first attribute comprising a scale or a rate of the first cryptographic operation]; and
the computer-implemented method further comprising:
receiving, at the compute service from a second user device, a second user request for performing a second cryptographic operation on [at least a portion of the large-scale dataset or a second large-scale dataset], the second user request including a second user token associated with a second user of the second user device (Sloan, Parag. [0019]; “interface means for receiving from one of said plurality of user entities a request to perform one or more cryptographic operations, and authentication information for identifying the user entity, associated with the request (i.e. user identity token).” … Parag. [0027]; “The reference to a user entity being located remotely from the system means a user entity having a user computing system which is located remotely from the system. The user computing system may comprise one or more user devices.” … Parag. [0049]; “receiving from one of said plurality of user entities (i.e., first or second user) a request to perform one or more cryptographic operations (i.e., first and second operations).” … Parag. [0097]; “The cryptographic management system 10 comprises an abstracted interface module 20, through which users within a user entity interact with the system to perform cryptographic operations. The abstracted interface module 20 provides a graphical user interface which can be accessed by users of the system. Alternatively, or in addition, the abstracted interface module 20 may provide an automated mechanism which operates under software control without user intervention. The abstracted interface module is used to submit a request for cryptographic services to the system. The graphical user interface (if present) may prompt the user to provide authentication credentials (i.e., user token), details of cryptographic operations to be performed.” … Parag. [0100]; “The user authentication module is configured to receive users' authentication credentials from the relevant interface module, and then to verify the authentication of a user by means of, for example, a username and password, RADIUS authentication, two factor authentication, and/or service issued third party digital certificates. Such authentication means are referred to herein as "identity tokens".);
sending, by the compute service to the key storage service, a second cryptographic key access request corresponding to the received second user request (Sloan, Parag. [0049]; “receiving from one of said plurality of user entities a request to perform one or more cryptographic operations.” … Parag. [0095]; “The cryptographic management system 10 provides a trusted and secure environment which carries out cryptography functions, such as encrypting and decrypting data files, on request from a registered user from within a user entity of the system.” … Parag. [0105]; “The central control module 24 is configured to identify the cryptographic material required to perform a requested operation, and obtain this from the key management and storage module 26. This may involve, for example, requesting an existing stored key or the generation and storage of a new key.”), the second cryptographic key access request including data representative of the second user token or a second compute service token (Sloan, Parag. [0120]-[0123]; “The request includes authentication information (i.e., user token) for user A. The request also attaches document X, and includes an indication that user A is entitled to read/write access to the document and that user B is entitled to read only access to the document. The abstracted interface module 20 receives the request and passes the authentication information to the authentication module 22. On successful authentication of user A, the authentication module passes an identity token for user A to the central control module 24. The central control module obtains details of the requested operation, and looks up the rights policy for user A. The central control module finds that user A is authorised to upload encrypted documents to the data centre. The central control module 24 then updates the access rights policy information stored therein, to indicate that user A is entitled to read/write access to the document, and that user B is entitled to read only access. Accordingly, the central control module 24 forwards the request to the key management and storage module 26. The key management generates a key for encrypting the data, and stores the new key together with details which identify the document to be encrypted. The key is then transmitted to the central control module.” Examiner submits that the compute service token is an optional feature.);
processing, [at the key storage service], the second user token or second compute service token to determine whether the user has permission to have the second cryptographic operation performed and whether to grant the compute service access to data representative of the second cryptographic key associated with the second cryptographic operation of the user request when the second user has permission (Sloan, Parag. [0102]; “the central control module 24 receives details of the requested operation(s) from the interface module 20. These details, together with user details contained in the identity token are looked up in an access rights policy database 25. The access rights policy database stores details of access rights for each registered user. These details indicate whether a requested cryptographic operation may be performed on behalf of that user. The access rights database may comprise general access rights details, and access rights details which relate to specific data files.” … Parag. [0105-0106]; “The central control module 24 is configured to identify the cryptographic material required to perform a requested operation, and obtain this from the key management and storage module 26. This may involve, for example, requesting an existing stored key or the generation and storage of a new key. Having identified a permitted request for an authenticated user, and obtained the necessary cryptographic material from the key management and storage module 26, the central control module 24 determines whether a data file is required in order to complete the requested operation and the location of that file, and then obtains the file for processing.”);
selectively sending, from the key storage service to the compute service, second data representative of the requested second cryptographic key (Sloan, Parag. [0123]; “Accordingly, the central control module 24 forwards the request to the key management and storage module 26. The key management generates a key for encrypting the data, and stores the new key together with details which identify the document to be encrypted. The key is then transmitted to the central control module.”) and the cryptographic algorithm associated with the cryptographic operation of the user request, [wherein the second data representative of the requested second cryptographic key and the cryptographic algorithm associated with the cryptographic operation of the user request is associated with a second attribute associated with the second cryptographic operation]; and
selectively cryptographically processing, by the compute service, [the portion of the large- scale dataset based on the received] data representative of the requested cryptographic key and [cryptographic algorithm] (Sloan, Parag. [0124]; “The central control module 24 then selects a suitable security module 27, 28 to perform the operation, and prepares instructions to perform the operation in a language/interface appropriate to the selected security module. The instructions are forwarded to the selected security module together with the key and the document (i.e., data) to be encrypted.”).
In addition, Munsil teaches:
second cryptographic operation on at least a portion of the large-scale dataset or a second large-scale dataset (Munsil, Parag. [0026]; “The encryption operation utilized by the conventional memory sub-system can operate on data blocks based on certain constraints such as the size of the data blocks. For example, the encryption operation can encrypt data blocks that are less than or equal to a threshold size but cannot be used to securely encrypt data blocks that are larger than the threshold size. Certain host systems can provide host data as data blocks at a large size that exceeds the threshold size utilized by the encryption operation. Thus, if the conventional memory sub-system is utilized by a host system that provides the host data as data blocks of a large size that exceeds the capability of the encryption operation utilized by the conventional memory sub-system, then the memory sub-system will not be able to encrypt the host data.” Examiner submits that performing a cryptographic operation does not represent any difference in the method applied to a first data. Applying a cryptographic operation on a second data set is an obvious design regarding this invention.)
cryptographically processing, … the portion of the large- scale dataset based on … and cryptographic algorithm (Munsil, Parag. [0029-0030]; “Referring to FIG. 2, at block 240 the processing logic performs the encryption operation with the segments of data and, at block 250, the processing logic stores the encrypted segments of data at the memory sub-system. Thus, host data of a size that exceeds a constraint of an encryption operation is received and the host data is separated or divided into segments that satisfy the constraints or requirements of the encryption operation. The encryption of the segments of data can utilize the XTS-AES encryption operation. In some embodiments, the XTS - AES encryption operation can encrypt each segment based on a first cryptographic key, a second cryptographic key, and a tweak value. Each segment of data can be encrypted by using the first cryptographic key and the second cryptographic key and a different tweak value. For example, a first segment of the data can be encrypted by the XTS-AES encryption operation with the first and second cryptographic keys and a first tweak value. For the next segment of the data, the first tweak value can be incremented to generate a second tweak value. The next segment of data can be encrypted with the same first and second crypto graphic keys and the second tweak value. For each subsequent segment of data, the tweak value can be incremented and used to encrypt the respective segment of data.”)
Additionally, Ma teaches:
processing, at the key storage service, the second user token (Ma, page 4, lines 3-7; “In some embodiments, applying for a key from a token and an identification code to a key management service comprises: sending, by the object storage gateway, the token and the identity to a key management service; accessing, by a key management service, an authentication token of an authentication service; and accessing the database multi-master synchronization cluster by the key management service in response to the token passing the verification to obtain a key corresponding to the identification code and sending the key to the object storage gateway.”)
The combination of Sloan, Munsil, Ma and L’Heureux does not expressly teach:
the data representative of the requested cryptographic key and the cryptographic algorithm identifies a first attribute associated with the first cryptographic operation, the first attribute comprising a scale or a rate of the first cryptographic operation;
However, Carlough teaches:
the data representative of the requested cryptographic key and the cryptographic algorithm identifies a first attribute associated with the first cryptographic operation, the first attribute comprising a scale or a rate of the first cryptographic operation (Carlough, Col. 2, lines 15-21; “This disclosure relates to limiting the rate of access to cryptographic keys that can be used to decrypt data that is protected using the cryptographic keys. In an example, a customer of a computing resource service provider submits a request to a cryptographic key management service to impose a rate limit for accessing a cryptographic key managed by the computing resource service provider.” … Col. 11, lines 26-36; “In response to the request, the cryptographic key management service 304 may obtain one or more grants applicable to the request. The one or more grants may specify whether the client 302 is authorized to utilize the cryptographic key to perform one or more operations. Further, the one or more grants may specify a usage rage limitation for the cryptographic key. For instance, the one or more grants may specify that the client 302 is authorized to utilize the cryptographic key a certain number of times within a particular interval of time.”)
wherein the second data representative of the requested second cryptographic key and the cryptographic algorithm associated with the cryptographic operation of the user request is associated with a second attribute associated with the second cryptographic operation (Carlough, Col. 2, lines 15-21; “This disclosure relates to limiting the rate of access to cryptographic keys that can be used to decrypt data that is protected using the cryptographic keys. In an example, a customer of a computing resource service provider submits a request to a cryptographic key management service to impose a rate limit for accessing a cryptographic key managed by the computing resource service provider.” … Col. 11, lines 26-36; “In response to the request, the cryptographic key management service 304 may obtain one or more grants applicable to the request. The one or more grants may specify whether the client 302 is authorized to utilize the cryptographic key to perform one or more operations. Further, the one or more grants may specify a usage rage limitation for the cryptographic key. For instance, the one or more grants may specify that the client 302 is authorized to utilize the cryptographic key a certain number of times within a particular interval of time.”)
Sloan, Munsil, Ma, L’Heureux and Carlough are from similar field of technology. Prior to the instant application’s effective filling date, there was a need for a method for encrypting large data sets in trusted environments.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Carlough system into Sloan-Munsil-Ma-L’Heureux system, with a motivation to provide a method for determining and assigning to a user a rate for performing cryptographic operations. (Carlough, Col. 2).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Osmond et al. (US 2007/0300062) relates to provides a data storage architecture for networked access by clients includes a file server capable of communication with the clients via the network, physical storage organized as a plurality of logical volumes, and an encryption device in communication with both the file server and the physical storage. The encryption device is operable in response to signaling from the file server to cause encryption of data being moved into the physical storage, and decryption of data being retrieved from storage. Two logical paths are provided for I/O operations. A first path is reserved for use by a first type of requestor, Such as file owners. Data retrieved via the first path is decrypted by the encryption device, and Writes via the first path are allowed. A second path is employed for others than the owners, e.g., administrators. Data retrieved via the second path is not decrypted by the encryption device, and attempted Writes via the second first path are denied. Metadata may be delivered in-the-clear via both paths in response to a Read so that legitimate management tasks can be performed.
Bowman et al. (US 2019/0129888) relates to an apparatus includes a processor component to: transmit node device identifiers to multiple node devices to define an ordering there among; following block exchanges redistributing the subsets among a reduced number of node devices, receive sizes of blocks or sub-blocks of data within each subset from the reduced number of node devices; based on the received sizes, generate map data organized to define an ordering among the blocks stemming from the ordering among the multiple node devices; determine whether the total size of the map data and metadata, together, exceeds a minimum size for data transmissions to storage device(s); and in response to the total size exceeding the minimum size, form the map data and metadata into segment(s) that each fit the minimum size and a maximum size, and transmit the segment(s) at least partially in parallel with other segments of the blocks transmitted by the reduced number of node devices.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALEX D CARRASQUILLO whose telephone number is (571)270-5045. The examiner can normally be reached Monday - Friday 9:00 am - 6:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/A.D.C./Examiner, Art Unit 2498
/YIN CHEN SHAW/Supervisory Patent Examiner, Art Unit 2498