Prosecution Insights
Last updated: October 02, 2026
Application No. 18/087,919

SYSTEMS AND METHODS RELATING TO CONFIDENTIAL COMPUTING KEY MIXING HAZARD MANAGEMENT

Final Rejection §103§112
Filed
Dec 23, 2022
Examiner
WILCOX, JAMES J
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Advanced Micro Devices Inc.
OA Round
4 (Final)
70%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 70% — above average
70%
Career Allowance Rate
437 granted / 623 resolved
+12.1% vs TC avg
Strong +61% interview lift
Without
With
+61.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
25 currently pending
Career history
659
Total Applications
across all art units

Statute-Specific Performance

§101
15.0%
-25.0% vs TC avg
§103
58.6%
+18.6% vs TC avg
§102
14.5%
-25.5% vs TC avg
§112
7.1%
-32.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 623 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This Office Action is in response to the Amendment filed on 04/24/2026. In the instant Amendment, claims 1, 11 and 20 were amended; claims 1, 11 and 20 are independent claims. Claims 1-20 are pending in this application. THIS ACTION IS MADE FINAL. Response to Arguments Claim interpretation under 35 U.S.C. 112(f) has been maintained. Applicant’s arguments with respect to claim(s) 1, 11 and 20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Applicant’s arguments filed 04/24/2026 have been fully considered but they are not persuasive. Applicant argues (on pages 7-8): that Shanbhogue ‘012 merely receives a key identifier and flushes entries that match that identifier, and therefore does not disclose “identifying a second encryption key currently associated with the specific memory address and used before the access request; detecting that the second encryption key mismatches the first encryption key used with the access request; and evicting the second encryption key in response to the mismatch. The Examiner respectfully disagrees. In the Non-Final Office action on 01/28/2026, Pages 8-9, Shanbhogue ‘012 expressly describes a cache lookup in which both a physical-address tag and a key-identifier tag are compared for an incoming memory request. Shanbhogue ‘012 states that the key identifier may be appended to, integrated with, or otherwise associated with the physical address, and that the resulting address tag is processed by the cache controller. Shanbhogue ‘012 further explains that a transaction includes a key identifier and that the cache or snoop-filter structures stores key identifiers corresponding to cached memory lines. Shanbhogue ‘012 discloses that the key-identifier hash operates as an index of a second tag on cache lines currently present in the coherent domain. Shanbhogue ‘012 then expressly states “if the miss is due to matching physical address tag but not key ID, then the cache line that matched the physical address tag is picked as victim and is evicted and replaced with new requests.” Thus, for a request directed to a particular physical memory address: the key ID accompanying the new request corresponds to the claimed first encryption key; the key-ID tag already stored for the cache line at that physical address corresponds to the claimed second encryption key currently associated with the specific memory address. Matching the physical address tag while failing to match the keyID tag constitutes detecting that the stored key and the request key mismatch; and selecting the existing cache line as the victim and evicting it in response to that mismatch corresponds to the claimed eviction operation. Shanbhogue ‘012 therefore does not merely disclose flushing every entry having a supplied key identifier. It separately discloses an ordinary cache-access operation in which the physical address matches an existing line, the request’s key ID fails to match the keyID tag stored for that line, and the existing line is consequently evicted and replaced by the new request. Applicant’s distinction between “providing a key ID” and “detecting a mismatch” is therefore inconsistent with Shanbhogue ‘012 disclosure. Shanbhogue ‘012’s lookup necessarily identifies the key ID associated with the existing line and compares the keyID against the key ID of the incoming request. A key-ID miss following a physical address match is the claimed determination that the previously associated encryption key differs from the encryption key used by the current access request. Applicant argues (on pages 7-8): that paragraphs [0030] and [0060] merely identify entries matching a supplied key. The Examiner respectfully disagrees with the applicant. In the Non-Final Office action on 01/28/2026, Pages 8-9, those portions do describe key-directed write-back and invalidation, but they do not negate the separate disclosure in Shanbhogue ‘012 that an existing cache line is evicted when the physical-address tag matches and the keyID tag mismatches. Shanbhogue ‘012 teachings must be considered as a whole rater than limited to the particular write-back-invalidate embodiment selected by the Applicant. Shanbhogue ‘012 teaches or renders obvious, the disputed identifying, mismatch-detection and eviction limitations of claim 1. Applicant argues (on page 9): that Shanbhogue ‘012 does not disclose a verifier that, by referencing an access-rights table: identifies a stale encryption key associated with the specific memory address; detects that the stale encryption key mismatches a new encryption key; and causes eviction of the stale encryption key from the cache hierarchy or access-rights table. The Examiner respectfully disagrees with the applicant. In the Non-Final Office action on 01/28/2026, Pages 10-15, Shanbhogue ‘012 discloses a tag-storage architecture that may be partitioned into a key identifier cache (KIC) and a metadata-storage structure. The KIC stores key IDs corresponding to address tags and cached memory lines. Shanbhogue ‘012 further describes the KIC as an index of a second tag on the cache lines currently cached in the coherent domain. Under broadest reasonable interpretation, Shanbhogue ‘012’s KIC and associated tag storage structure correspond to the claimed access rights table because they maintain the association between: a specific physical memory address or address tag; the key identifier governing access to data at that address and the cache line holding the corresponding data. The claimed “access-rights table” doe not distinguish the claim where Shanbhogue ‘012 KIC performs the recited function of retaining address-to-encryption-key association information used to determine whether a request is associated with the proper encryption domain. Shanbhogue ‘012 cache controller, snoop filter, or caching and home agent lookup circuitry corresponds to the claimed verifier. That circuitry compares the incoming request’s physical-address and keyID tags against the tags stored for the existing cache line. When the physical address matches but the key ID does not, the circuitry has identified the previously stored or stale key ID associated with that address; determined that the stale key ID differs from the new request key ID; and selected the line containing the stale key ID as a victim for eviction and replacement. Shanbhogue ‘012 also discloses that a snoop filter indexes cache lines across multiple cache levels and multiple processor cores, permitting the relevant line to be found throughout the cache hierarchy. The snoop filter identifies matching entries, writes back associated data, and marks the corresponding entries invalid. Shanbhogue ‘012 claims recite levels and cores, identifying entries by key-identifier comparison, writing the associated data back, and marking the entries invalid. The claimed “stale encryption key” is taught as a key-ID tag stored for the existing line at the physical address, the claimed “new encryption key” is met by the key ID accompanying the incoming request, selection and eviction is met by Shanbhogue ‘012 selection and eviction of the existing line when the address matches but the keyIDs differ. Applicant’s characterization of Shanbhogue ‘012 as performing only a positive match against the supplied flush key overlooks Shanbhogue ‘012 explicit address-match/KeyID mismatch embodiment. For the reasons discussed above, Shanbhogue ‘012 alone or renders obvious the disputed limitations of independent claims 11 and 20. Therefore, Applicant’s arguments have been fully considered but are not persuasive. Shanbhogue ‘012 discloses comparing the key identifier associated with the incoming request against the key identifier tag currently associated with a cache line for the same physical address and upon detecting a key-identifier mismatch, evicting and replacing the existing cache line. Shanbhogue ‘012 further discloses key-identifier and tag-storage structures including a KIC and snoop filter, that retain and evaluate the address to key associations across the cache hierarchy. The rejection of independent claims 1, 11 and 20 and the claims depending therefrom is therefore maintained. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: a detector that detects [] (Claims 11 & 20); a verifier that identifies [] (Claims 11 & 20) and an evictor that evicts [] (Claims 11, 13 & 20); probe filter being configured to evict [] (Claims 15 and 19); cache hierarchy is configured to [] (Claim 17). Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 3, 5, 9-11, 14-15, and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al (“Shanbhogue ‘787” US 20200201787) and further in view of Shanbhogue et al (“Shanbhogue ‘012” US 20200202012). Regarding claim 1, Shanbhogue ‘787 discloses a method comprising: (Shanbhogue ‘787, FIG 4, Claim 16) detecting, by a probe filter, an access request using a first encryption key to a specific memory address; (Shanbhogue ‘787 describes in [0018]-[0025], Figures 1-2, claim 16 a memory access request where KeyID is selected from a KAT registered based on KSEL, and the KeyID identifies the encryption key. The request is to a physical address/block of memory. A snoop filter [probe filter] is coupled to the cache hierarchy and can identify entries by comparing the key identifier information in address tags) identifying, by the probe filter, a second encryption key currently associated with the specific memory address and that was used with the specific memory address before the access request; (Shanbhogue ‘787 in [0038], FIG 4, claim 16 describes that the KIC stores the KeyID for each cached block, indexed/determined by physical address; the KeyID associated with a cached block identifies the encryption key used with that block. The stored KeyID is the prior/currently cached KeyID for that physical address) detecting, by the probe filter, that the second encryption key mismatches the first encryption key; (Shanbhogue ‘787 in [0021], [0039], FIG 4 items 410/414/416 claim 17 discloses that when access is requested, the system determines whether the KeyID stored in the KIC is the same as the selected KeyID; if the stored KeyID does not match the selected KeyID, the cached block is removed/written back thus detecting mismatching between the prior/stored KeyID and the newly selected KeyID) and evicting, by the probe filter in response to the second encryption key mismatching the first encryption key, the second encryption key, (Shanbhogue ‘787 discloses in [0021], [0039], FIG 4 items 410/414/416, claim 17 describes evicting/removing the cached block when the stored KeyID does not match the selected KeyID, writing it back encrypted with the old/stored KeyID, then caching the block with the new selected KeyID, then caching the block with the new selected Key ID) Shanbhogue ‘787 fails to explicitly disclose identifying, by the probe filter, a second encryption key currently associated with the specific memory address and that was used with the specific memory address before the access request; and evicting, by the probe filter in response to the second encryption key mismatching the first encryption key, the second encryption key. However, in an analogous art, Shanbhogue ‘012 discloses identifying, by the probe filter, a second encryption key currently associated with the specific memory address and that was used with the specific memory address before the access request (Shanbhogue ‘012 in Figure 3-4, claims 8-9 describe the snoop filter has entries/tags including key-ID information and identifies matching entries by key ID) and evicting, by the probe filter in response to the second encryption key mismatching the first encryption key, the second encryption key, (Shanbhogue ‘012 in [0030], FIG 5 items 530-550, claims 8-11 describes the snoop filter can write back data and marking matching snoop-filter entries invalid) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shanbhogue ‘012 with Shanbhogue ‘787 to include identifying, by the probe filter, a second encryption key currently associated with the specific memory address and that was used with the specific memory address before the access request; and evicting, by the probe filter in response to the second encryption key mismatching the first encryption key, the second encryption key. One would have been motivated to provide write-back invalidation by key identifier (ID) (Shanbhogue ‘012). Regarding claim 3, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the method of claim 1. Shanbhogue ‘012 further discloses wherein the probe filter implements a table to track which encryption keys are assigned to which specific memory addresses, and evicting the second encryption key includes evicting references to the second encryption key from the table, (Shanbhogue ‘012 discloses wherein the probe filter [0030] implements a table [0115], [0067]-[0068], to track [0048] which encryption keys [0124], [0126], [0025], [0035] are assigned to which specific memory addresses [0070], [0126] and evicting [0029], [0068] the second encryption key [0124], [0126], [0025], [0035] includes evicting references [0029], [0068] to the second encryption key [0124], [0126], [0025], [0035]) from the table [0115], [0067]-[0068]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shanbhogue ‘012 with Shanbhogue ‘787 to include wherein the probe filter implements a table to track which encryption keys are assigned to which specific memory addresses, and evicting the second encryption key includes evicting references to the second encryption key from the table. One would have been motivated to provide write-back invalidation by key identifier (ID) (Shanbhogue ‘012). Regarding claim 5, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the method of claim 1. Shanbhogue ‘012 further discloses wherein evicting the second encryption key maintains either data coherence or data integrity, (Shanbhogue ‘012 describes wherein evicting [0029], [0068] the second encryption key [0124], [0126], [0025], [0035] maintains either data coherence [0078], [0048] or data integrity [0022]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shanbhogue ‘012 with Shanbhogue ‘787 to include wherein evicting the second encryption key maintains either data coherence or data integrity. One would have been motivated to provide write-back invalidation by key identifier (ID) (Shanbhogue ‘012). Regarding claim 9, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the method of claim 1. Shanbhogue ‘012 further discloses wherein evicting the second encryption key is performed by issuing an invalidating probe, (Shanbhogue ‘012 discloses wherein evicting [0029], [0068] the second encryption key [0124], [0126], [0025], [0035] is performed by issuing an invalidating probe [0030], [0124], [0126]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shanbhogue ‘012 with Shanbhogue ‘787 to include wherein evicting the second encryption key is performed by issuing an invalidating probe. One would have been motivated to provide write-back invalidation by key identifier (ID) (Shanbhogue ‘012). Regarding claim 10, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the method of claim 9. Shanbhogue ‘012 further discloses wherein the invalidating probe invalidates all references to the second encryption key within a cache hierarchy corresponding to the probe filter, (Shanbhogue ‘012 discloses wherein the invalidating probe [0030], [0124], [0126] invalidates all references [0030], [0124], [0126] to the second encryption key [0124], [0126], [0025], [0035] within a cache hierarchy [0051], [0079] corresponding to the probe filter [0030]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shanbhogue ‘012 with Shanbhogue ‘787 to include wherein the invalidating probe [0030], [0124], [0126]) invalidates all references to the second encryption key within a cache hierarchy corresponding to the probe filter. One would have been motivated to provide write-back invalidation by key identifier (ID) (Shanbhogue ‘012). Regarding claim 11, Shanbhogue ‘787 discloses a probe fitter comprising: (Shanbhogue ‘787 discloses in [0016], [0036] the coherent domain system includes snoop filters, LLCs, KeyID caches, and caching/home agents) a detector that detects, within a coherent fabric interconnect, an access request using a new encryption key to a specific memory address of a cache; (Shanbhogue ‘787 in [0018]-[0019], [0021], also see [0032], [0035]-[0037], Figures 3-4, items 404-408 discloses a memory access request, a selected KeyID from a KAT register, and the KeyID identifying the encryption key; it also teaches a mesh/coherent domain with snoop filters, LLCs, KICs and memory controllers) an access rights table that maps memory locations to encryption keys; (Shanbhogue ‘787 in [0018]-[0019], also see [0023]-[0024], [0038], claim 16 that the KIC/KeyID cache which stores KeyIDs for each cached block of memory. Since a KeyID identifies an encryption key, the KIC maps memory blocks/physical address to encryption keys) a verifier that identifies, by referencing the access rights table, a stale encryption key that is currently associated with the specific memory address in the access rights table and that was used with the specific memory address before the access request, (Shanbhogue ‘787 in [0021]; [0038]-[0039]; FIG 4 blocks 410-416; claim 17 describes checking the KIC for the KeyID associated with the cached block corresponding to the physical address. The previously stored KeyID is the stale key association) and detects that the stale encryption key mismatches the new encryption key; (Shanbhogue ‘787 in [0021]-[0039], FIG 4, block 414, claim 17 describes if the block is cached with a KeyID not the same as the selected KeyID from the KAT register, the cache line is evicted/written back; claim 17 describes determining that the cached block is not associated with the selected KeyID) and an evictor that evicts, in response to the stale encryption key mismatching the new encryption key, the stale encryption key from the cache, (Shanbhogue ‘787 in [0021], [0039], FIG 4, item 416; claim 17 describes evicting the block when the stored KeyID does not match the selected keyID) Shanbhogue ‘787 fails to explicitly disclose a cache hierarchy; and an evictor that evicts, in response to the stale encryption key mismatching the new encryption key, the stale encryption key from the cache hierarchy. However, in an analogous art, Shanbhogue ‘012 discloses a cache hierarchy; (Shanbhogue ‘012 in FIG 1A; [0030], FIG 5, item 530 describes the snoop filter/cache hierarchy context) and an evictor that evicts, in response to the stale encryption key mismatching the new encryption key, the stale encryption key from the cache hierarchy, (Shanbhogue ‘012 in [0030], [0058], [0071]; FIG 5, items 530-550; claims 8-11 describe a snoop filter/LLC key-ID-based writeback and invalidation: identify entries by comparing a key identifier with address-tag information, write back data, and mark entries invalid) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shanbhogue ‘012 with Shanbhogue ‘787 to include a cache hierarchy; and an evictor that evicts, in response to the stale encryption key mismatching the new encryption key, the stale encryption key from the cache hierarchy. One would have been motivated to provide write-back invalidation by key identifier (ID) (Shanbhogue ‘012). Regarding claim 14, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the probe filter of claim 11. Shanbhogue ‘012 further discloses wherein the probe filter is coupled to a memory controller that performs encryption or decrypting of data for the specific memory address, (Shanbhogue ‘012, [0038]-[0039], also see [0126], [0155] describes a snoop filter [probe filter] is coupled to a memory controller that performs encryption or decryption of data for the particular memory address) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shanbhogue ‘012 with Shanbhogue ‘787 to include wherein the probe filter is coupled to a memory controller that performs encryption or decrypting of data for the specific memory address. One would have been motivated to provide write-back invalidation by key identifier (ID) (Shanbhogue ‘012). Regarding claim 15, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the probe filter of claim 11. Shanbhogue ‘012 further discloses wherein the probe filter being configured to evict the stale encryption key from the cache hierarchy maintains wither data coherence or data integrity, (Shanbhogue ‘012, [0028], [0068], [0132] describe wherein the snoop filter [probe filter] is configured to remove invalid [stale] encryption keys as described in [0064] & [0035] from the [0122], cache hierarchy; [0022], describes maintains data integrity; [0078] describes data coherence) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shanbhogue ‘012 with Shanbhogue ‘787 to include wherein the probe filter being configured to evict the stale encryption key from the cache hierarchy maintains wither data coherence or data integrity. One would have been motivated to provide write-back invalidation by key identifier (ID) (Shanbhogue ‘012). Regarding claim 19, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the probe filter of claim 11. Shanbhogue ‘012 further discloses wherein the probe filter is configured to evict the references to the stale encryption key from the cache hierarchy at least in part by issuing an invalidating probe, (Shanbhogue ‘012, [0028], [0068], [0132] describe wherein the snoop filter [probe filter] is configured to remove invalid [stale] encryption keys as described in [0064] & [0035] from the [0122], [0079] cache hierarchy; [0063] describes issuing an invalidating probe) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shanbhogue ‘012 with Shanbhogue ‘787 to include wherein the probe filter is configured to evict the references to the stale encryption key from the cache hierarchy at least in part by issuing an invalidating probe. One would have been motivated to provide write-back invalidation by key identifier (ID) (Shanbhogue ‘012). Regarding claim 20, Shanbhogue '787 discloses a computer chip comprising: (Shanbhogue '787 discloses [0078] a system-on-a-chip with logical processors; [0036]-[0037] caching/home agents, snoop filters, LLCs, KeyID caches, [0040] mesh-to-memory interfaces [0022] and memory-controller/ [0027] TME units) a detector that detects, within a coherent fabric interconnect, an access request using a new encryption key to a specific memory address of a cache; (Shanbhogue '787 in [0019], [0021], [0023]-[0025], also see [0035]-[0039], Figures 3-4 teaches a logical processor sending a memory access request, selecting a keyID from a KAT register, and sending the KeyID with the memory access request. The KeyID identifies the encryption key . [0078] a system-on-a-chip with logical processors; [0036]-[0037] caching/home agents, snoop filters, LLCs, KeyID caches, [0040] mesh-to-memory interfaces [0022] and memory-controller/ [0027], [0035] TME units unites in a coherent domain) an access rights table that maps memory locations to encryption keys; (Shanbhogue '787 discloses [0019], [0038] , claim 16 describe KIC/KeyID. It stores KeyIDs for each cached block of memory, indexed/determined by physical address. Because KeyIDs identify encryption keys, the KIC maps memory locations to encryption keys) a verifier that identifies, by referencing the access rights table, a stale encryption key that is currently associated with the specific memory address in the access rights table and that was used with the specific memory address before the access request, (Shanbhogue ‘787, [0021], [0039], FIG 4, items 410-414, claim 17 describes that when a block is accessed, the caching/home agent uses the physical address to query the snoop filter and/or LLC then determines whether the KeyID stored in the KIC for that physical address is the same as the selected KeyID. The stored KIC KeyID is the old/stale key association for that address) and detects that the stale encryption key mismatches the new encryption key; (Shanbhogue '787 in [0021], [0039], FIG 4, item 414; claim 17 describes that if the stored KeyID does not match the selected KeyID, the block is removed from cache and written back) and an evictor that evicts, in response to the stale encryption key mismatching the new encryption key, the stale encryption key from the access rights table, (Shanbhogue '787 [0039], Figure 4 items 416-418, claim 17 describes that if the stored KeyID does not match the selected KeyID, the block is removed from cache and written back using the old KeyID, then the block is recached with the new selected KeyID and that new KeyID is stored in the KIC. That evicts/replaces the stale KeyID entry in the access rights table) Shanbhogue '787 fails to explicitly disclose a cache hierarchy; and an evictor that evicts, in response to the stale encryption key mismatching the new encryption key, the stale encryption key from the access rights table However, in an analogous art, Shanbhogue '012 discloses a cache hierarchy; (Shanbhogue ‘012 in FIG 1A; [0030], FIG 5, item 530 describes the snoop filter/cache hierarchy context) and an evictor that evicts, in response to the stale encryption key mismatching the new encryption key, the stale encryption key from the access rights table (Shanbhogue '012 discloses in [0030], FIG 5, items 530-550; claims 8-11 describes snoop-filter entries identified by keyID, writeback, and marking matching entries invalid) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shanbhogue ‘012 with Shanbhogue ‘787 to include a computer chip comprising: a cache hierarchy; and an evictor that evicts, in response to the stale encryption key mismatching the new encryption key, the stale encryption key from the access rights table. One would have been motivated to provide write-back invalidation by key identifier (ID) (Shanbhogue ‘012). Claims 2 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al (“Shanbhogue ‘787” US 20200201787) in view of Shanbhogue et al (“Shanbhogue ‘012” US 20200202012) and further in view of Fel et al (“Fel,” US 20150220456). Regarding claim 2, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the method of claim 1. Shanbhogue ‘787 and Shanbhogue ‘012 fail to explicitly disclose wherein data is stored within a cache hierarchy in an unencrypted state by decrypting the data prior to storage. However, in an analogous art, Fel discloses wherein data is stored within a cache hierarchy in an unencrypted state by decrypting the data prior to storage (Fel, [0015]-[0016], [0024] and [0126] describe wherein information is stored within a cache hierarchy in an unencrypted state by decrypting the information prior to storing it in storage). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Fel with Shanbhogue ‘787 and Shanbhogue ‘012 to include wherein data is stored within a cache hierarchy in an unencrypted state by decrypting the data prior to storage. One would have been motivated to provide protection of program code intended to be executed by a microprocessor which makes program code less sensitive to attacks (Fel, [0002]). Regarding claim 12, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the probe filter of claim 11. Shanbhogue ‘787 and Shanbhogue ‘012 fail to explicitly disclose wherein data is stored within the cache hierarchy in an unencrypted state. However, in an analogous art, Fel discloses wherein data is stored within the cache hierarchy in an unencrypted state, (Fel, [0015]-[0016], [0024] & [0126] describe wherein information is stored within the cache hierarchy in an unencrypted state) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Fel with Shanbhogue ‘787 and Shanbhogue ‘012 to include wherein data is stored within the cache hierarchy in an unencrypted state. One would have been motivated to provide protection of program code intended to be executed by a microprocessor which makes program code less sensitive to attacks (Fel, [0002]). Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al (“Shanbhogue ‘787” US 20200201787) in view of Shanbhogue et al (“Shanbhogue ‘012” US 20200202012) and further in view of Altman et al (“Altman,” US 20150089245). Regarding claim 4, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the method of claim 1. Shanbhogue ‘787 and Shanbhogue ‘012 fail to explicitly disclose wherein encrypting or decrypting an item of data is performed by a memory controller. However, in an analogous art, Altman discloses wherein encrypting or decrypting an item of data is performed by a memory controller, (Altman, [0012], describes wherein encrypting an item of data is performed by a memory controller) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Altman with Shanbhogue ‘787 and Shanbhogue ‘012 to include wherein encrypting or decrypting an item of data is performed by a memory controller. One would have been motivated to provide secure use of persistent (non-volatile) memory to emulate volatile memory (Altman, [0001]). Claims 6-7 and 16-17 are rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al (“Shanbhogue ‘787” US 20200201787) in view of Shanbhogue et al (“Shanbhogue ‘012” US 20200202012) and further in view of Roberts et al (“Roberts,” US 20230058668) Regarding claim 6, Shanbhogue ‘787 and Shanbhogue ‘012 discloses the method of claim 1. Shanbhogue ‘787 and Shanbhogue ‘012 fail to explicitly disclose wherein an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss. However, in an analogous art, Roberts discloses wherein an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss, (Roberts, [0056], [0058], [0064] describes an attempt to access a particular memory address using an encryption key that is not currently associated with the particular memory address results in a cache miss) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Roberts with Shanbhogue ‘787 and Shanbhogue ‘012 to include wherein an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss. One would have been motivated to provide a selective cache line memory encryption (Roberts, [0091]) Regarding claim 7, Shanbhogue ‘787 and Shanbhogue ‘012 discloses the method of claim 6. Shanbhogue ‘787 and Shanbhogue ‘012 fail to explicitly disclose wherein an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss without detection of a failed write operation. However, in an analogous art, Roberts discloses wherein an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss without detection of a failed write operation, (Roberts, [0056], [0058], [0064] describes an attempt to access a particular memory address using an encryption key that is not currently associated with the particular memory address results in a cache miss without detection of a failed write) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Roberts with Shanbhogue ‘787 and Shanbhogue ‘012 to include wherein an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss without detection of a failed write operation. One would have been motivated to provide a selective cache line memory encryption (Roberts, [0091]) Regarding claim 16, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the probe filter of claim 11. Shanbhogue ‘787 and Shanbhogue ‘012 fail to explicitly disclose wherein the cache hierarchy is configured such that an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss. However, in an analogous art, Roberts discloses wherein the cache hierarchy is configured such that an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss, (Roberts, [0079] memory hierarchy with lower level caches; [0056], [0058], [0064] describes an attempt to access a particular memory address using an encryption key that is not currently associated with the particular memory address results in a cache miss) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Roberts with Shanbhogue ‘787 and Shanbhogue ‘012 to include wherein the cache hierarchy is configured such that an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss. One would have been motivated to provide a selective cache line memory encryption (Roberts, [0091]) Regarding claim 17, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the probe filter of claim 16. Shanbhogue ‘787 and Shanbhogue ‘012 fail to explicitly disclose wherein the cache hierarchy is configured such that an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss without detection of a failed write operation. However, in an analogous art, Roberts discloses wherein the cache hierarchy is configured such that an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss without detection of a failed write operation, (Roberts, [0079] memory hierarchy with lower level caches; [0056], [0058], [0064] describes an attempt to access a particular memory address using an encryption key that is not currently associated with the particular memory address results in a cache miss without detection of a failed write) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Roberts with Shanbhogue ‘787 and Shanbhogue ‘012 to include wherein the cache hierarchy is configured such that an attempt to access the specific memory address using an encryption key not currently associated with the specific memory address results in a cache miss without detection of a failed write operation. One would have been motivated to provide a selective cache line memory encryption (Roberts, [0091]) Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al (“Shanbhogue ‘787” US 20200201787) in view of Shanbhogue et al (“Shanbhogue ‘012” US 20200202012) and further in view of Buendgen et al (“Buendgen,” US 20230040468). Regarding claim 8, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the method of claim 1. Shanbhogue ‘787 and Shanbhogue ‘012 fail to explicitly disclose wherein usage of the first encryption key and the second encryption key facilitates achievement of confidential computing. However, in an analogous art, Buendgen discloses wherein usage of the first encryption key and the second encryption key facilitates achievement of confidential computing, (Buendgen, [0054], describes the usage of encryption keys [first and second encryption keys] facilitates achievement of confidential computing) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Buendgen with Shanbhogue ‘787 and Shanbhogue ‘012 to include wherein usage of the first encryption key and the second encryption key facilitates achievement of confidential computing. One would have been motivated to provide a method for providing a system-specific secret to a computing system (Buendgen, [0001]). Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al (“Shanbhogue ‘787” US 20200201787) in view of Shanbhogue et al (“Shanbhogue ‘012” US 20200202012) and further in view of Shveykin et al (“Shveykin,” US 20180054302). Regarding claim 13, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the probe filter of claim 11. Shanbhogue ‘787 and Shanbhogue ‘012 fail to explicitly disclose wherein the evictor is configured to evict the stale encryption key in the cache hierarchy by evicting all such references within the cache hierarchy. However, in an analogous art, Shveykin discloses wherein the evictor is configured to evict the stale encryption key in the cache hierarchy by evicting all such references within the cache hierarchy, (Shveykin, [0033], [0036] describes revoking the expired [stale] encryption key in a cache hierarchy by revoking all such references within the cache hierarchy) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Shveykin with Shanbhogue ‘787 and Shanbhogue ‘012 to include wherein the evictor is configured to evict the stale encryption key in the cache hierarchy by evicting all such references within the cache hierarchy. One would have been motivated to provide a message service with distributed key caching for server-side encryption (Shveykin, [0012]). Claim 18 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al (“Shanbhogue ‘787” US 20200201787) in view of Shanbhogue et al (“Shanbhogue ‘012” US 20200202012) and further in view of Kumar et al (“Kumar,” US 20210110049). Regarding claim 18, Shanbhogue ‘787 and Shanbhogue ‘012 disclose the probe filter of claim 11. Shanbhogue ‘787 further discloses the coherent fabric interconnect (Shanbhogue ‘787 [0036], describes a mesh of interconnected memory devices that communicate and coordinate with one another to coherently cache blocks of memory and metadata on the SoC 300 [coherent fabric interconnect]). Shanbhogue ‘787 and Shanbhogue ‘012 fail to explicitly disclose wherein usage of the new encryption key and the stale encryption key facilitates achievement of confidential computing with respect to the fabric interconnect. However, in an analogous art, Kumar discloses wherein usage of the new encryption key and the stale encryption key facilitates achievement of confidential computing with respect to the fabric interconnect (Kumar, [0033], [0050], describes usage of the new encryption key and the expired [stale] encryption key that facilitates [0037] confidential computing with respect to the [0022], [0119] fabric interconnect) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Kumar with Shanbhogue ‘787 and Shanbhogue ‘012 to include wherein usage of the new encryption key and the stale encryption key facilitates achievement of confidential computing with respect to the fabric interconnect. One would have been motivated to provide a method and system of storing both public and private data (Kumar, [0003]). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES J WILCOX whose telephone number is (571)270-3774. The examiner can normally be reached M-F: 8 A.M. to 5 P.M.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu T. Pham can be reached at (571)270-3774. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JAMES J WILCOX/Examiner, Art Unit 2439 /LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Show 1 earlier event
Apr 11, 2025
Non-Final Rejection mailed — §103, §112
Jul 07, 2025
Response Filed
Oct 16, 2025
Final Rejection mailed — §103, §112
Jan 06, 2026
Request for Continued Examination
Jan 08, 2026
Response after Non-Final Action
Jan 28, 2026
Non-Final Rejection mailed — §103, §112
Apr 24, 2026
Response Filed
Jul 15, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750351
UNIQUE MACHINE-USER ID-SSH KEY FINGERPRINT
3y 4m to grant Granted Sep 29, 2026
Patent 12732357
SYSTEM AND METHOD SUPPORTING DATA RESIDENCY REQUIREMENT IN CLOUD HOSTED HARDWARE SECURITY MODULES
1y 5m to grant Granted Sep 08, 2026
Patent 12719868
METHOD, APPARATUS, AND COMPUTER-READABLE RECORDING MEDIUM FOR CONTROLLING ACCESS TO REMOTE SYSTEM IN HOME NETWORK ENVIRONMENT
3y 2m to grant Granted Aug 25, 2026
Patent 12719869
MULTI-TENANT SECRETS MANAGER
2y 7m to grant Granted Aug 25, 2026
Patent 12719871
SYSTEMS AND METHODS FOR DATA SEGREGATION AND SECURITY BASED ON ACCESS RIGHTS FOR ADDITIONAL SERVICES
2y 3m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
70%
Grant Probability
99%
With Interview (+61.2%)
3y 2m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 623 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month