DETAILED ACTION
In a communication received on 11 May 2026, the applicants amended claims 1-11, 19 and 21.
Claims 1-19 and 21 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claim(s) 1-11, 19 and 21 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 11, and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Regniere et al. (US 2021/0049030 A1) in view of Shanbhogue et al. (US 2023/0098288 A1).
With respect to claim 1, Regniere discloses: A computing device, comprising:
guest circuitry comprising hardware configured to provide a virtual function isolated from host circuitry by the hardware (i.e., GPU hardware provides virtual functions for VMs and isolates each virtual function’s directly available resources from other virtual functions in Regniere, ¶0012; ¶0013).
Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere do(es) not explicitly disclose the following. Shanbhogue, in order to implements selective role-based protection because unprotected registers create security vulnerabilities, while blanket restriction would prevent legitimate OS/VMM use (¶0334; ¶0335), discloses:
authorization circuitry configured to authorize host circuitry to access an architecture performance counter for the virtual function (i.e., policy, read-access, and write-access registers identify which initiators, including OS/VMM agents, may access protected registers in Shanbhogue, ¶0337; ¶0339); and
security circuitry configured to perform a security action based on the authorization. (i.e., security hardware checks the initiator against the current policy and either aborts the transaction or permits the protected-register update in Shanbhogue, ¶0360; ¶0363).
Based on Regniere in view of Shanbhogue, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Shanbhogue to improve upon those of Regniere in order to implements selective role-based protection because unprotected registers create security vulnerabilities, while blanket restriction would prevent legitimate OS/VMM use.
With respect to claim 11, the limitation(s) of claim 11 are similar to those of claim(s) 1. Therefore, claim 11 is rejected with the same reasoning as claim(s) 1.
With respect to claim 19, Regniere discloses: A computer-implemented method comprising: (i.e., allocating and authorizing performance-counter registers for virtual functions in Regniere, ¶0027; ¶0029)
providing, by at least one processor, a virtual function (i.e., the processor/GPU provides virtual functions associated with virtual machines. in Regniere, ¶0012; ¶0013).
Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere do(es) not explicitly disclose the following. Shanbhogue, in order to implements selective role-based protection because unprotected registers create security vulnerabilities, while blanket restriction would prevent legitimate OS/VMM use (¶0334; ¶0335), discloses:
in conjunction with providing the virtual function, recording, by the at least one processor, in a circuit of the at least one processor, a security setting associated with a virtual function (i.e., processor hardware records access permissions in policy-group control registers or an on-chip table associated with protected registers in Shanbhogue, ¶0336; ¶0337)
indicating permission to access an architecture performance counter for the virtual function (i.e., the read/write access-control setting indicates which initiators have permission to access the protected register in Shanbhogue, ¶0337; ¶0339); and
authorizing, by the at least one processor, a function to access the architecture performance counter for the virtual function based on the recorded permission of the security setting (i.e., the processor authorizes the requested register transaction by checking the recorded policy and aborting or permitting the operation in Shanbhogue, ¶0360; ¶0363).
Based on Regniere in view of Shanbhogue, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Shanbhogue to improve upon those of Regniere in order to implements selective role-based protection because unprotected registers create security vulnerabilities, while blanket restriction would prevent legitimate OS/VMM use.
Claim(s) 2-3, 9, 12, and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Regniere et al. (US 2021/0049030 A1) in view of Shanbhogue et al. (US 2023/0098288 A1), and further in view of Kegel et al. (US 2013/0007379 A1).
With respect to claim 2, Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere do(es) not explicitly disclose the following. Shanbhogue, in order to implements selective role-based protection because unprotected registers create security vulnerabilities, while blanket restriction would prevent legitimate OS/VMM use (¶0334; ¶0335), discloses: the computing device of claim 1,
the modification based on a security setting indicating that the host circuitry is authorized to receive the architecture performance counter (i.e., stored read/write access-control policy identifies whether the OS/VMM initiator is permitted to receive or use the protected register in Shanbhogue, ¶0339; ¶0349).
Based on Regniere in view of Shanbhogue, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Shanbhogue to improve upon those of Regniere in order to implements selective role-based protection because unprotected registers create security vulnerabilities, while blanket restriction would prevent legitimate OS/VMM use.
Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere and Shanbhogue do(es) not explicitly disclose the following. Kegel, in order to preserve isolation and prevent unprivileged misuse by implementing access controls because they provide current counter data with low overhead (¶0004; ¶0036), discloses: wherein the security action includes providing, to the host circuitry, the architecture performance counter at least partly in response to a modification of the architecture performance counter (i.e., the event counter is modified when an event is detected, and its updated contents are made accessible to authorized software through protect-register mediation in Kegel, ¶0006; ¶0034).
Based on Regniere in view of Shanbhogue, and further in view of Kegel, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kegel to improve upon those of Regniere in order to preserve isolation and prevent unprivileged misuse by implementing access controls because they provide current counter data with low overhead.
With respect to claim 3, Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere do(es) not explicitly disclose the following. Shanbhogue, in order to implements selective role-based protection because unprotected registers create security vulnerabilities, while blanket restriction would prevent legitimate OS/VMM use (¶0334; ¶0335), discloses: the computing device of claim 2, wherein the security circuitry
receive a request for the architecture performance counter from the host circuitry (i.e., a protected-register transaction carries an initiator security attribute, enabling security hardware to recognize and evaluate a host/OS/VMM request. in Shanbhogue, ¶0339; ¶0363).
Based on Regniere in view of Shanbhogue, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Shanbhogue to improve upon those of Regniere in order to implements selective role-based protection because unprotected registers create security vulnerabilities, while blanket restriction would prevent legitimate OS/VMM use.
Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere and Shanbhogue do(es) not explicitly disclose the following. Kegel, in order to preserve isolation and prevent unprivileged misuse by implementing access controls because they provide current counter data with low overhead (¶0004; ¶0036), discloses:
provide the architecture performance counter to the host circuitry via the security circuitry further in response to the request (i.e., the control module mediates read access to the counter value according to the protect register, providing the counter through the security-control path in Kegel, ¶0007; ¶0032).
Based on Regniere in view of Shanbhogue, and further in view of Kegel, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kegel to improve upon those of Regniere in order to preserve isolation and prevent unprivileged misuse by implementing access controls because they provide current counter data with low overhead.
With respect to claim 9, Regniere discloses: the computing device of claim 1, wherein the authorization circuitry is configured to maintain the architecture performance counter (i.e., trusted controller and profiling logic maintain lists and properties of performance-counter registers allocated to virtual functions. in Regniere, ¶0019; ¶0021).
Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere and Shanbhogue do(es) not explicitly disclose the following. Kegel, in order to preserve isolation and prevent unprivileged misuse by implementing access controls because they provide current counter data with low overhead (¶0004; ¶0036), discloses: and to control access by the host circuitry to the architecture performance counter based on a security setting indicating that the host circuitry is authorized to access the architecture performance counter (i.e., protect registers store access-control information and the control module exposes counter values only as permitted by that setting. in Kegel, ¶0032; ¶0034).
Based on Regniere in view of Shanbhogue, and further in view of Kegel, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kegel to improve upon those of Regniere in order to preserve isolation and prevent unprivileged misuse by implementing access controls because they provide current counter data with low overhead.
With respect to claim 12, the limitation(s) of claim 12 are similar to those of claim(s) 2. Therefore, claim 12 is rejected with the same reasoning as claim(s) 2.
With respect to claim 13, the limitation(s) of claim 13 are similar to those of claim(s) 3. Therefore, claim 13 is rejected with the same reasoning as claim(s) 3.
Claim(s) 4-8, 14-17 and 21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Regniere et al. (US 2021/0049030 A1) in view of Shanbhogue et al. (US 2023/0098288 A1) and Kegel et al. (US 2013/0007379 A1)., and further in view of Meola (US 2011/0173545 A1).
With respect to claim 4, Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere, Shanbhogue, and Kegel do(es) not explicitly disclose the following. Meola, in order to improve decision making for a user to grant access based on information about the request and the requestor (¶0018), discloses: the computing device of claim 3, wherein the request includes information indicating at least one of:
one or more intended uses of the architecture performance counter (i.e., message to a user to grant access to a request includes reasoning for granting access - "a message to the second user regarding why access should be granted and request reconsideration of the decision" in Meola, ¶0031); or
at least one of a particular hypervisor corresponding to a physical function provided by the host circuitry or a particular type of the particular hypervisor corresponding to the physical function (i.e., requesting entity is identified in a request for granting access to protected information - "second user may prefer authorization requests to identify information regarding, for example, the name of the requesting entity, the location of the computing device 201, an indication as to whether a request was sent and/or received from an additional mobile computing device (e.g., the other parent), and a quantity of times the particular request has been made" in Meola, ¶0018).; or
at least one of a particular hypervisor corresponding to a physical function provided by the host circuitry or a particular an identity or type of a particular hypervisor corresponding to a physical function provided by the host circuitry. (i.e., an entity identifier and requester name identify who seeks access; in the combined PF/VF system, that requester is the hypervisor associated with the host physical function in Meola, ¶0017; ¶0018).
Based on Regniere in view of Shanbhogue and Kegel, and further in view of Meola, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Meola to improve upon those of Regniere in order to improve decision making for a user to grant access based on information about the request and the requestor.
With respect to claim 5, Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere, Shanbhogue, and Kegel do(es) not explicitly disclose the following. Meola, in order to improve decision making for a user to grant access based on information about the request and the requestor (¶0018), discloses: the computing device of claim 4,
wherein the security setting (i.e., stored access rights contain criteria applied to grant or deny resource access, matching a setting containing one or both listed authorization criteria in Meola, ¶0024; ¶0030)
includes at least one of: at least one trusted hypervisor security setting authorizing at least one of the particular hypervisor or the particular type of the particular hypervisor to receive the architecture performance counter (i.e., entity identifiers and entity-type criteria permit approval of a particular requester or requester category in Meola, ¶0017; ¶0018); or
at least one trusted use security setting authorizing the one or more intended uses of the architecture performance counter (i.e., stored access rights authorize specified purposes for requested data in Meola, ¶0028; ¶0029),
wherein the security setting encodes a policy associated with the virtual function. (i.e., a policy set is created, stored, and reused for the same entity/resource relationship in Meola, ¶0024; ¶0031).
Based on Regniere in view of Shanbhogue and Kegel, and further in view of Meola, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Meola to improve upon those of Regniere in order to improve decision making for a user to grant access based on information about the request and the requestor.
With respect to claim 6, Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere, Shanbhogue, and Kegel do(es) not explicitly disclose the following. Meola, in order to improve decision making for a user to grant access based on information about the request and the requestor (¶0018), discloses: The computing device of claim 5,
wherein the authorization circuitry is configured to authorize the host circuitry based on the policy encoded in the security setting associated with the virtual function (i.e., authorization results from comparing the request with stored access rights in Meola, ¶0024; ¶0030),
including at least one of: the at least one trusted hypervisor security setting; or (i.e., the authorization decision may use the requesting entity’s identifier or type in Meola, ¶0017; ¶0018)
the at least one trusted use security setting. (i.e., the authorization decision may use the approved purpose for the requested information in Meola, ¶0028; ¶0029).
Based on Regniere in view of Shanbhogue and Kegel, and further in view of Meola, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Meola to improve upon those of Regniere in order to improve decision making for a user to grant access based on information about the request and the requestor.
With respect to claim 7, Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere, Shanbhogue, and Kegel do(es) not explicitly disclose the following. Meola, in order to improve decision making for a user to grant access based on information about the request and the requestor (¶0018), discloses: the computing device of claim 4,
wherein the security circuitry is configured to communicate a prompt, in response to the request, to a user interacting with the virtual function (i.e., prompting a second user to grant access to the request - "upon a request from the entity 110 to access location information of the computing device 201, the second user may be prompted to authorize or deny access to the location information of the computing device 201" in Meola, ¶0018), wherein
the prompt is configured to communicate, to the user, the information indicating at least one of: the at least one of the particular hypervisor or the particular type of the particular hypervisor (i.e., second user receives requests to grant access including the identity of the requestor - "second user may prefer authorization requests to identify information regarding, for example, the name of the requesting entity, the location of the computing device 201, an indication as to whether a request was sent and/or received from an additional mobile computing device (e.g., the other parent), and a quantity of times the particular request has been made" in Meola, ¶0018); or
the one or more intended uses of the architecture performance counter (i.e., request can include reasoning for granting the request - "a message to the second user regarding why access should be granted and request reconsideration of the decision" in Meola, ¶0031),
wherein the prompt is associated with the virtual function (i.e., the stored policy and subsequent checks remain associated with the same requesting entity and resource, the prompt is scoped to the relevant virtual function in Meola, ¶0026; ¶0031).
Based on Regniere in view of Shanbhogue and Kegel, and further in view of Meola, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Meola to improve upon those of Regniere in order to improve decision making for a user to grant access based on information about the request and the requestor.
With respect to claim 8, Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere, Shanbhogue, and Kegel do(es) not explicitly disclose the following. Meola, in order to improve decision making for a user to grant access based on information about the request and the requestor (¶0018), discloses: the computing device of claim 7, wherein:
the security circuitry is configured to receive user input from the user interacting with the virtual function (i.e., user responds with decision to grant or deny access in Meola, ¶0030); and
the authorization circuitry is configured to modify the security setting associated with the virtual function based on the user input. (i.e., the authorization decision updates the stored access rights or policy set in Meola, ¶0024; ¶0031).
Based on Regniere in view of Shanbhogue and Kegel, and further in view of Meola, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Meola to improve upon those of Regniere in order to improve decision making for a user to grant access based on information about the request and the requestor.
With respect to claim 14, the limitation(s) of claim 14 are similar to those of claim(s) 4. Therefore, claim 14 is rejected with the same reasoning as claim(s) 4.
With respect to claim 15, the limitation(s) of claim 15 are similar to those of claim(s) 5. Therefore, claim 15 is rejected with the same reasoning as claim(s) 5.
With respect to claim 16, the limitation(s) of claim 16 are similar to those of claim(s) 6. Therefore, claim 16 is rejected with the same reasoning as claim(s) 6.
With respect to claim 17, the limitation(s) of claim 17 are similar to those of claim(s) 7. Therefore, claim 17 is rejected with the same reasoning as claim(s) 7.
With respect to claim 21, Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere and Shanbhogue do(es) not explicitly disclose the following. Kegel, in order to preserve isolation and prevent unprivileged misuse by implementing access controls because they provide current counter data with low overhead (¶0004; ¶0036), discloses: the computer-implemented method of claim 19,
the security setting indicates permission to access the architecture performance counter for the virtual function (i.e., a protect register stores access information governing the counter value register in Kegel, ¶0007; ¶0032).
Based on Regniere in view of Shanbhogue, and further in view of Kegel, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kegel to improve upon those of Regniere in order to preserve isolation and prevent unprivileged misuse by implementing access controls because they provide current counter data with low overhead.
Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere, Shanbhogue, and Kegel do(es) not explicitly disclose the following. Meola, in order to improve decision making for a user to grant access based on information about the request and the requestor (¶0018), discloses:
wherein the security setting is specific to the virtual function and (i.e., stored access rights remain associated with the same requesting entity and resource in Meola, ¶0026; ¶0031) and an intended use of the access indicated by the permission, (i.e., the access rights identify authorized purposes for the requested information in Meola, ¶0028; ¶0029)
and wherein accessing the architecture performance counter is based on the security setting indicating the virtual function and the intended use of the access. (i.e., access is granted by comparing a request to rights tied to the requester/resource and authorized purpose in Meola, ¶0024; ¶0030).
Based on Regniere in view of Shanbhogue and Kegel, and further in view of Meola, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Meola to improve upon those of Regniere in order to improve decision making for a user to grant access based on information about the request and the requestor.
Claim(s) 10 and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Regniere et al. (US 2021/0049030 A1) in view of Shanbhogue et al. (US 2023/0098288 A1), and further in view of Sahita et al. (US 2011/0061050 A1).
With respect to claim 10, Regniere discloses: the computing device of claim 1, further comprising additional guest circuitry configured to provide an additional virtual function (i.e., the GPU supports multiple virtual machines and multiple virtual functions under one physical function, supplying additional guest circuitry and an additional virtual function in Regniere, ¶0012; ¶0013).
Regniere discloses GPU security processor and hardware register configured as a performance counter for a particular virtual function (¶0014; ¶0015). Regniere and Shanbhogue do(es) not explicitly disclose the following. Sahita, in order to restrict unprivileged access to performance information by requiring authentication of cross-VM counter access (¶0013, ¶0017), discloses: wherein:
the security circuitry is configured to receive a request for the architecture performance counter from the additional guest circuitry (i.e., a privileged monitoring VM requests performance information associated with another subject VM in Sahita, ¶0027; ¶0029);
the authorization circuitry is configured to additionally authorize the additional guest circuitry to access the architecture performance counter upon satisfaction of a condition specified by a security setting (i.e., hardware checks a recorded authentication/permission flag and separately verifies authorization before allowing the monitoring VM’s access in Sahita, ¶0019; ¶0024); and
the security circuitry is configured to provide the architecture performance counter to the additional guest circuitry based on the additional authorization (i.e., after verifying permission, the VM manager or computing platform provides the requested performance information to the monitoring VM in Sahita, ¶0029; ¶0030).
Based on Regniere in view of Shanbhogue, and further in view of Sahita, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Sahita to improve upon those of Regniere in order to restrict unprivileged access to performance information by requiring authentication of cross-VM counter access.
With respect to claim 18, the limitation(s) of claim 18 are similar to those of claim(s) 10. Therefore, claim 18 is rejected with the same reasoning as claim(s) 10.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHERMAN L LIN whose telephone number is (571)270-7446. The examiner can normally be reached Monday through Friday 9:00 AM - 5:00 PM (Eastern).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Joon Hwang can be reached at 571-272-4036. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Sherman Lin
7/11/2026
/S. L./Examiner, Art Unit 2447
/JOON H HWANG/Supervisory Patent Examiner, Art Unit 2447