Prosecution Insights
Last updated: October 02, 2026
Application No. 18/068,531

Apparatus, Device, Method, and Computer Program for Monitoring a Processing Device from a Trusted Domain

Final Rejection §103
Filed
Dec 20, 2022
Examiner
RUSIN, KAYO LISA
Art Unit
2114
Tech Center
2100 — Computer Architecture & Software
Assignee
Intel Corporation
OA Round
2 (Final)
89%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 89% — above average
89%
Career Allowance Rate
24 granted / 27 resolved
+33.9% vs TC avg
Strong +18% interview lift
Without
With
+17.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 2m
Avg Prosecution
13 currently pending
Career history
45
Total Applications
across all art units

Statute-Specific Performance

§101
14.1%
-25.9% vs TC avg
§103
51.4%
+11.4% vs TC avg
§102
13.5%
-26.5% vs TC avg
§112
18.4%
-21.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 27 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA Response to Amendment With respect to the double patenting rejections, necessary amendments have been made to overcome the rejections; the rejections have been withdrawn. With respect to the 112(b) rejections, necessary amendments have been made to overcome the rejections; the rejection have been withdrawn. With respect to the 35 U.S.C. 101 rejections, necessary amendments have been made to overcome the rejections; the rejections have been withdrawn. With respect to the 35 U.S.C. 103 rejections, the arguments are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of “Multitenancy” (Wikipedia, revised on 12 October 2022). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-5, 7, 9-23 are rejected under 35 U.S.C. 103 as being unpatentable over Bulygin et al (US 20200074086 A1) in view of “Multitenancy” (Wikipedia, revised on 12 October 2022) from henceforth referred to as Tenant-NPL Per claim 1, Bulygin teaches: An apparatus for monitoring a processing device from a trusted domain, the apparatus comprising interface circuitry, machine-readable instructions, and processing circuitry to execute the machine-readable instructions to: ([0049] methods may be performed by executing stored instructions with one or more logic devices (e.g., processors) in combination with one or more additional hardware elements such as storage devices, memory; [0023] communications is conducted over an authenticated channel) receive a request for monitoring the processing device from a … virtual machine executing in the trusted domain; authenticate the request; ([0023] monitoring can be done remotely in which the host operating system is located remotely in a virtual machine or other cloud-hosted services and communicate over authenticated channel) responsive to authenticating the request, trigger execution of an in-field scan circuitry integrated in the processing device during runtime operation of the processing device while the … virtual machine remains in an active execution state in the trusted domain; ([0025] responsive to a request from a third party tool, a local security agent may be launched in order to scan the host devices to collect information ([0044] the method in which it collects the data may include security mechanisms built-in to hardware and/or firmware by manufacturer of the hardware/firmware, which the Examiner interprets as including the in-field scan circuitry); if the virtual machine is not active, it would not be able to send a request to trigger the testing; [0023] the information such as firmware code and data of the host device may be extracted, along with configuration, timing, interrupts, execution counters, and related statistics of the host device may be collected) obtain information from the in-field scan circuitry on a failure report related to a component of the processing device, with a possible failure having occurred at runtime of the processing device; and (FIG. 3, step 306, the system receives information from host device; [0044] the method collection can be performed via the in-field scan circuitry built in to the hardware; FIG. 3, step 316, [0036] the collected information is displayed in a report) provide the information on the failure report to the … virtual machine in the trusted domain. ([0036] the report is transmitted and may be provided to a user interface in which an administrator or other users can view the result of the analysis; [0023] the remote monitoring can be conducted locally through a virtual machine) Bulygin fails to teach tenant virtual machine However, Tenant-NPL teaches tenant virtual machine (top of page 4, virtualized multitenancy). It is obvious to a person of ordinary skill in the art prior to the effective filing date of the claimed invention to combine the teaching of Bulygin with the teaching of Tenant-NPL in order to teach the use of tenant virtual machine because Bulygin already teaches the use of “virtual machines” (Bulygin, [0023]) and does not restrict it to the use of a dedicated virtual machine. Thus, the use of a tenant virtual machine which involves multiple isolated instances of the application to run on more servers (Tenant-NPL, top of page 4) is an implementation choice for the claimed invention in Bulygin, for those who want to reap in the benefits of multitenacy (Tenant-NPL, top of page 4). Per claim 2, Bulygin in view of Tenant-NPL teaches: The apparatus of claim 1, wherein the machine-readable instructions further comprise instructions to determine information on a microcode update to be applied to the processing device to remedy a failure related to the component, and to configure the processing device to apply the microcode update (Bulygin, [0048] “When weaknesses, vulnerabilities, or misconfigurations in a system are identified as described above, a virtual patching capability may be deployed as an emergency stop gap to the risk until a more permanent fix is available from manufacturers of the system”) Per claim 3, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 1, wherein the machine-readable instructions further comprise instructions to decode the request. (Bulygin, [0023] communication is held over an authenticated channel) Per claim 4, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 1, wherein the machine-readable instructions further comprise instructions to forward information on the request to a secure arbitration module for processing the request based on a microcode routine associated with the request (Bulygin, [0025] local security agent is used as a secure arbitration module in which the request can be passed to the local security agent and based on the microcode routine associated with the request, the security agent may conduct different types of scans) Per claim 5, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 4, wherein the machine-readable instructions further comprise instructions to receive information on the failure report from the secure arbitration module (Bulygin, [0024] local security agent collect information on the failure report and send the info to analysis services such as those on a cloud-hosted service) Per claim 7, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 1, wherein the information on the failure report related to the component is based on a failure related to the component occurring in the field. (Bulygin, [0015] the monitoring and analysis can monitor runtime behavior performance in order to detect any vulnerabities) Per claim 9, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 1, wherein the machine-readable instructions comprise instructions to obtain the information on the failure report related to the component in response to an interrupt raised by the in-field scan circuitry of the processing device. (Bulygin, [0023] during the scan, information related to vulnerabilities are captured, including interrupts; Bulygin, [0035] the information is collected in a report) Per claim 10, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 2, wherein the machine-readable instructions comprise instructions to determine the information on the microcode update to be applied to the processing device to remedy the failure related to the component based on a mapping between failures and microcode updates. (Bulygin, [0048] the virtual patch concept involves identifying the vulnerability or misconfiguration and making specific modifications to the firmware or hardware settings such that the risk of an attack is removed; Bulygin, [0045] this includes analyzing the firmware components against others that are known to be good as well as keeping a database of independently collected measurements of firmware from a plurality of host devices that is integrated into the system backend along with information about the measurement source for each firmware measurement and enabling integrity checks of operational systems against the previously known measurements) Per claim 11, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 10, wherein the machine-readable instructions comprise instructions to update the mapping between the failures and microcode updates. (Bulygin, [0045] adaptive whitelisting may be performed, which automatically incorporates measurements that meet a set of criteria into the expected values for a host) Per claim 12, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 10, wherein the mapping is an operator- defined policy supplied by an operator of a computer system comprising the processing device. (Bulygin, [0045] the database with the mapping can be customized to be organization-specific) Per claim 13, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 1, wherein the machine-readable instructions comprise instructions to obtain second information on a failure of a component of the processing device occurring in other computer systems, to determine information on a microcode update to be applied to the processing device to remedy the failure related to the component included in the second information, and to configure the processing device to apply the microcode update. (Bulygin, [0048] when weaknesses, vulnerabilities, or misconfigurations in a system are identified, specific modifications to the firmware or hardware settings are identified and adjusted in order to fix the issue) Per claim 14, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 2, wherein the microcode update affects one or more elements of the group of an operating frequency of the component of the processing device, a use of one or more components of the processing device for performing an instruction being exposed by an instruction set architecture of the processing device, instructions to emulate a functionality originally provided by the component, a shared use of one or more components of the processing device in simultaneous multithreading, or instructions being exposed by an instruction set architecture of the processing device. (Bulygin, [0048] micro-code patch for a specific CPU vulnerability or enabling a BIOS write protect bit which when not enabled exposes a firmware storage control vulnerability. Instructions exposed through instruction set architecture (ISA) can be used for exploitation attempts and so the micro-code patch can help prevent such vulnerability attempts) Per claim 15, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 2, wherein the microcode update relates to one or more elements of the group of an input/output controller of the processing device, affecting the use of at least a part of an interface being coupled to the processing device, a memory controller of the processing device, affecting the use of at least a portion of memory included in a computer system comprising the processing device, or a storage controller of the processing device, affecting the use of at least a portion of storage circuitry included in a computer system comprising the processing device. (Bulygin, [0048] microcode patch may enable a BIOS write protect bit) Per claim 16, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 2, wherein the microcode update is configured to disable the component or portions of logic within the component. (Bulygin, [0015] may disable the network interface through a hardware interface in order to isolate the affected component) Per claim 17, Bulygin in view of Tenant-NPL teaches: The apparatus according to claim 1, wherein the processing device is an XPU, the XPU being one of a Central Processing Unit (CPU), Graphics Processing Unit (GPU),an Artificial Intelligence (AI) accelerator, an accelerator card and offloading circuitry. (Bulygin, [0048] processing device is a CPU) As per claim 18, the claim recites similar claim limitation as claim 1. Claim 18 further recites …a plurality of processing devices… …a plurality of components of the plurality of processing devices …plurality of failure reports… (Bulygin, [0016] the security monitoring mechanism may be deployed for use by multiple organizations and may include one or more host devices such as laptops, desktop computers, and/or other computing devices. A local agent may be installed on each of the host devices in each group in order to collect information from the respective host devices). Per claim 19, Bulygin in view of Tenant-NPL teaches: A computer system comprising the apparatus according to claim 1 and the processing device (Bulygin, [0016] host devices) Per claim 20, Bulygin in view of Tenant-NPL teaches: The computer system according to claim 19, wherein the apparatus is implemented as part of a system firmware of the computer system. (Bulygin [0044] method includes accessing a state and configuration of security mechanisms built-in to hardware and/or firmware by manufacturers of the hardware/firmware) Per claim 21, the claim recites similar claim limitation as claim 1 and thus is rejected for similar reasons. Per claim 22, Bulygin in view of Tenant-NPL teaches: A non-transitory, computer-readable medium comprising a program code that, when the program code is executed on a processor, a computer, or a programmable hardware component, causes the processor, computer, or programmable hardware component to perform the method of claim 21. (Bulygin, [0004] includes a processor and a storage device storing instructions executable by the processor to collect firmware and/or hardware information relating to the client system and transmit, via the data interface, to a remote device) Per claim 23, Bulygin in view of Tenant-NPL teaches: A method for monitoring a processing device from an application in a trusted domain, the method comprising transmitting, by a tenant virtual machine executing in a trusted domain, a request for monitoring the processing device in the trusted domain, the request causing execution of in-field scan circuitry integrated in the processing device during runtime operation of the processing device while the tenant virtual machine remains in an active execution state in the trusted domain; and (Bulygin, [0023] monitoring can be done remotely in which the host operating system is located in a virtual machine over authenticated channel; Bulygin, [0025] the monitoring request is sent from the virtual machine to the local security agent; if the virtual machine is not active, it would not be able to transmit the request; Bulygin, [0044] information may be collected from the security mechanisms built-in to hardware and/or firmware by manufacturers of the hardware/firmware; Bulygin, [0015] monitoring can collect runtime behavior; Tenant-NPL, top of page 4, virtualized multitenancy) receiving, by the tenant virtual machine in the trusted domain, information on a failure report about the processing device from the in-field scan circuitry. (Bulygin, [0036] the report is generated from the gathered information; Tenant-NPL, top of page 4, virtualized multitenancy) Claims 6 is rejected under 35 U.S.C. 103 as being unpatentable over Bulygin et al (US 20200074086 A1) in view of “Multitenancy” (Wikipedia, revised on 12 October 2022) from henceforth referred to as Tenant-NPL in further view of Kuo (US 20070283222 A1) Per claim 6, Bulygin fails to teach wherein the information on the failure report related to the component comprises information on a circuit-level failure affecting the component. However, Kuo teaches wherein the information on the failure report related to the component comprises information on a circuit-level failure affecting the component. (Kuo, [0060] errors due to design defects) It is obvious to a person of ordinary skill in the art prior to the effective filing date of the claimed invention to combine the teaching of Bulygin with the teaching of Kuo in order to teach capturing information related to circuit-level failure when collecting vulnerability data because design defects may add vulnerabilities. By addressing them and changing the logic paths through patches, the system data signal is more likely to follow defect free logic paths (Kuo, [0060]). Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Bulygin et al (US 20200074086 A1) in view of “Multitenancy” (Wikipedia, revised on 12 October 2022) from henceforth referred to as Tenant-NPL in further view of Shanbhogue et al (US 20160364308 A1) Per claim 8, Bulygin teaches The apparatus according to claim 1, wherein the machine-readable instructions comprise instructions to obtain the information on the failure report related to the component of the processing device from the in-field scan circuitry of the processing device ([0036] a report on vulnerabilities is made through information gathered by the local security agent; [0044] information may be collected from the built-in security mechanisms by manufacturers of the hardware/software) Bullygin fails to teach by reading a register or memory region associated with the in-field scan circuitry. However, Shanbhogue teaches by reading a register or memory region associated with the in-field scan circuitry. ([0015] inventive concept is regarding enabling multiple types of in-field testing including built-in self-tests; [0025] control registers can be used to hold test results) It is obvious to a person of ordinary skill in the art prior to the effective filing date of the claimed invention to combine the teaching of Bulygin with the teaching of Shanbhogue in order to make the information from the built-in self-test accessible (Shanbhogue [0025]). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KAYO LISA RUSIN whose telephone number is (703)756-1679. The examiner can normally be reached Monday-Friday 8:30 - 5:00 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ashish Thomas can be reached at 571-272-0631. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /K.L.R./ Examiner, Art Unit 2114 /ASHISH THOMAS/Supervisory Patent Examiner, Art Unit 2114
Read full office action

Prosecution Timeline

Dec 20, 2022
Application Filed
Feb 06, 2023
Response after Non-Final Action
Feb 08, 2023
Response after Non-Final Action
Feb 24, 2026
Non-Final Rejection mailed — §103
May 26, 2026
Response Filed
Aug 11, 2026
Final Rejection mailed — §103
Sep 30, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699638
SYSTEM AND METHOD FOR VIRTUALIZATION SOFTWARE MANAGEMENT IN A WIRELESS NETWORK
2y 4m to grant Granted Aug 04, 2026
Patent 12632330
Identifying and Remediating Anomalies in a Self-Healing Network
3y 1m to grant Granted May 19, 2026
Patent 12632327
SYSTEMS AND METHODS FOR PERFORMING A ROOT CAUSE ANALYSIS UTILIZING PARAMETERS INCLUDING DEVICE CONTEXT FEATURES TO TROUBLESHOOT ENTERPRISE INFORMATION TECHNOLOGY PROBLEMS
2y 10m to grant Granted May 19, 2026
Patent 12625777
DATA BACKUP METHOD OF STORAGE DEVICE USING SENSOR INFORMATION, AND STORAGE DEVICE AND STORAGE SYSTEM PERFORMING THE SAME
2y 10m to grant Granted May 12, 2026
Patent 12591500
Event Monitoring and Code Autocorrecting Batch Processing System
2y 1m to grant Granted Mar 31, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
89%
Grant Probability
99%
With Interview (+17.6%)
2y 2m (~0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 27 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month