Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This action is in response to the communication filed on 2/6/2026.
Claims 1-10 and 12-17 are examined and rejected.
Claim 11 is cancelled.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114.
Applicant's submission filed on 2/6/2026 has been entered.
Response to Arguments
As per Applicant’s argument / explanation dated 2/6/2026 are considered.
As per applicant’s arguments with respect to the amended claims have been considered but are moot in view of new rejection. New reference of Miller along with combination of references (Jeong - Miller) has been updated in the office action.
Examiner is open for phone call interview to discuss further with applicant’s representative for the purpose of compact prosecution.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-17 are rejected under 35 U.S.C. 103 as being unpatentable by U.S. Patent 10311229 to Pohlack et al. (hereinafter known as “Pohlack”) and in view of U.S. Publication 2019/0228137 to Johannson et al. (hereinafter known as “Johansson”) and further in view of U.S. Publication 2021/0209255 to Immonen et al. (hereinafter known as “Immonen”).
As per claim 1 Pohlack teaches, a method of securing executable code, the method comprising:
receiving usage data for a plurality of elements of the program state of the executable code during execution (Pohlack Fig 2 and 3 col 8 lines 45-67 teaches analyzing application code for execution);
identifying, from the received usage data, at least one element of the program state having at least one pre-defined update characteristic (Pohlack Fig 2 and 3 col 8 lines 45-67 teaches analyzing application code for malware or intrusion where malware is analyzed based on code signature or database of malware signatures); and
modifying the executable code to select between at least two equivalent execution paths (Pohlack Fig 2 and 3 col 9 lines 4-35 where two executable paths are described for execution based on code analysis).
Pohlack does not teach however Johansson teaches value of the executable code in dependence on the value of the identified at least one element of the program state (Johansson Fig 3 para 39-40 teaches value of program state for encoding function with state variable of code block is interpreted by examiner as value of code block generated for the purpose of code analysis and based on code value code is further processed for intrusion or normal function of code).
Pohlack – Johannson are analogous with security or prevent tampering in code(s). Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Pohlack – Johannson before him or her, to combine, Pohlack’s runtime analysis of application code test service with modifying the executable code to select between at least two equivalent execution paths with Johannsen’s teaching of value of the executable code in dependence on the value of the identified at least one element of the program state (Johannson Fig 3). The suggestion/motivation for doing so would have been to prevent unauthorized access to content by code analysis for modification, obfuscation or extraction of keys (Johanson para 2).
Although Pohlack teaches memory address at col 5 lines 30-45 inorder to enhance Pohlack’s teaching examiner introduces, Immonen further teaches,
execution, wherein an element of the program state comprises one of. a main memory address; a cache memory address; a framebuffer address: a CPU register a GPU register an FPU register a part of a call stack a variable of the executable code and an address relating to a symbol of the executable code (Immonen para 61 teaches code blocs address space, para 70 teaches memory address which covers one of many conditions of claim).
Pohlack – Johannson - Immonen are analogous with security or prevent tampering in code(s). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Pohlack – Johannson - Immonen before him or her, to combine, Pohlack - Johannson’s runtime analysis of application code test service with modifying the executable code to select between at least two equivalent execution paths with Immonen’s teaching of memory address (Immonen para 61, 70). The suggestion/motivation for doing so would have been to prevent unauthorized modification of executable code (Immonen para 1).
As per claim 2 combination of Pohlack – Johannson - Immonen teaches the method of claim 1,
method of claim 1 wherein the step of modifying comprises copying, in the executable code, operations from a first execution path of the executable code to generate a second execution path in the executable code, wherein the second executable path is functionally equivalent to the first execution path (Pohlack Fig 2 and 3 col 9 lines 4-35 and col 12 lines 5-35 teaches where two executable paths are described for execution based on code analysis where path value based on example of both path being 64 bytes wide and maximum instructions of 15 bytes is interpreted as same value path allocation).
As per claim 3 combination of Pohlack – Johannson - Immonen teaches the method of claim 2 wherein an operation in the second execution path is modified such that an intermediate result in the second executable path is dependent on the value of the at least one element of the program state (Pohlack Fig 3 element 310/320 and col 11 lines 25-55 teaches where dividing the instructions for the identified critical code paths and alternate code path is based on code analysis (interpreted as program state).
As per claim 4 combination of Pohlack – Johannson - Immonen teaches the method of claim 3 wherein a first modified operations alters the intermediate result based on the value of the at least one element of the program state and a second modified operation compensates for the alteration based on an expected value for the at least one element of the program state (Pohlack Fig 3 element 330/340 and col 11 lines 25-55 and col 12 lines 1-15 teaches where code distribution based on identified critical code paths and alternate code path is based on code value analysis).
As per claim 5 combination of Pohlack – Johannson - Immonen teaches the method of claim 1 further comprising, receiving call data for the first callable unit in one of the execution paths, wherein the step of identifying is identifying, from the received usage data and the received call data, the at least one element of the program state having the at least one pre-defined update characteristic at the start of the execution path (Pohlack Fig 2 and 3 and col 8 lines 25-55 teaches where code analysis for intrusion / malware based on code usage data and script function where script function is interpreted as received call data).
As per claim 6 combination of Pohlack – Johannson - Immonen teaches the method of claim 5 wherein the call data is generated by dynamically profiling the executable code (Pohlack Fig 2 element 210 and 3 and col 8 lines 40-67 teaches where identified data for code analysis is for particular section for code path).
As per claim 7 combination of Pohlack – Johannson - Immonen teaches the method of claim 1 wherein the usage data is generated by dynamically profiling the executable code (Pohlack Fig 1 element 170/150 col 5 lines 25-67 teaches where code analysis based on active code is similar to profiling executable code).
As per claim 8 combination of Pohlack – Johannson - Immonen teaches the method of claim 6 wherein the dynamically profiling includes collecting a plurality of snapshots of the program state during execution, optionally wherein the plurality of snapshots are collected periodically based on time or the occurrence of events (Pohlack Fig 1 element 130/140 col 5 lines 25-67 teaches where code analysis based on sections / chunks or critical section based on time intervals of codes which is interpreted as periodic snapshots of code).
As per claim 9 combination of Pohlack – Johannson - Immonen teaches the method of claim 1 wherein the usage data comprises usage data generated during a plurality of execution instances of the executable code (Pohlack col 5 lines 20-35 teaches application code).
As per claim 10 combination of Pohlack – Johannson - Immonen teaches the method of claim 1 wherein the usage data comprises a plurality of sets of usage data, each set of usage data corresponding to the usage of the plurality of elements of the program state during execution in a respective execution environment (Pohlack col 5 lines 30-45 teaches application code in shared memory or cache or application environment).
As per claim 12 combination of Pohlack – Johannson - Immonen teaches the method of claim 1 wherein the usage data comprises one or more metrics for each of the plurality of elements of the program state (Pohlack teaches Col 7 lines 25-55).
As per claim 13 combination of Pohlack – Johannson - Immonen teaches the method of claim 12 wherein a metric is any of: a measure of update frequency of an element of the program state during execution; a measure of a range of values taken by an element of the program state during execution (Pohlack - col 17 lines 50-67 teaches monitoring code value); a measure of variance of the values taken by an element of the program state during execution (Pohlack - col 18 lines 55-67 teaches variation limit); a number of updates of an element of the program state during execution; the values taken by an element of the program state during execution.
As per claim 14 combination of Pohlack – Johannson - Immonen teaches the method of claim 12 wherein the pre-defined update characteristic requires the element of the program state to having at least a threshold level of a metric (Pohlack col 17 lines 50-67 teaches address translation with threshold for value code during runtime).
As per claim 15 combination of Pohlack – Johannson - Immonen teaches the method of claim 1 wherein the pre-defined update characteristic specifies any of: an update frequency; a measure of randomness of the values taken by the element of the program state; a measure of entropy of the values taken by the element of the program state; a variance of the values taken by the element of the program state (Pohlack col 18 lines 55-67 teaches analysis on variation of value during runtime analysis of program code).
Claim 16,
Claim 16 is rejected in accordance with claim 1.
Claim 17,
Claim 17 is rejected in accordance with claim 1.
Prior Art of Record
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Immonen et al US Publication 20210209255
Zoubeiri et al US Patent 10970065
Couillard et al US Patent 11204748
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to VIRAL S LAKHIA whose telephone number is (571)270-3363. The examiner can normally be reached on 8 am - 6 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/VIRAL S LAKHIA/Primary Examiner, Art Unit 2431