DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 4/10/2026 has been entered.
claims 1, 7, and 13 are amended
Claims 1-5, 7-11, and 13-17 are pending
Examiner’s Note: The specification discloses on page 14 that the management controller may include a processor, memory, and a network interface
Response to Arguments
Applicant’s amendment to claims 1, 7 and 13 filed on 3/11/2026 regarding, “wherein the bootloader component is a first-party component that is cryptographically signed by a manufacturer of the information handling system, and a runtime component, wherein the runtime component is a third-party component that is not cryptographically signed by the manufacturer of the information handling system;” necessitated the new ground(s) of rejection presented in this Office action. Therefore, Applicant's arguments with respect to claims 1-5, 7-11, and 13-17 have been considered but are moot in view of the new ground(s) of rejection.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
1.) Claims 1, 7 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over US 20170154184, Shivanna in view of US 20190097793, Nix
In regards to claim 1, Shivanna teaches an information handling system comprising: a host system(US 20170154184, Shivanna, para. 0020, FIG. 2 is a block diagram of an example system 200 with server device 202 in communication with management station 204 for providing OS agnostic validation of firmware images.); and
a management controller configured to provide out-of-band management of the information handling system and comprising a firmware that includes a bootloader component, wherein the bootloader component is a first-party component that is cryptographically signed by a manufacturer of the information handling system(US 20170154184, Shivanna, para. 0009 and 0017: [0009]- the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor[i.e. note: the bootloader image is signature agnostic and therefore, may have a signature. Moreover, the signature may inherently be provided by the manufacturer].[0017]- the sideband interface[i.e. note: sideband interfaces are associated with out-of-band communication] can provide an application programming interface (API) that allows for a firmware installation associated with the IO controller to be accessed using commands sent over the sideband interface. In some cases, metadata (e.g., version, signature[e.g. note: ], compile date, etc.) associated with the firmware installation is accessed.) and
a runtime component, wherein the runtime component is a third-party component that is not cryptographically signed by the manufacturer of the information handling system(US 20170154184, Shivanna, para. 0009, the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor. Run-time authentication by an IO Controller allows for the detection of hacked IO firmware images without loading the complete firmware image. [i.e. note: the runtime component image is signature agnostic and may not be signed Moreover, runtime processing via an IO controller may inherently be performed via a 3rd party component]); Shivanna does not teach
wherein the management controller is configured to establish trust with a remote information handling system by:
receiving a handshake request from the remote information handling system, the handshake request including a payload;
the runtime component transmitting the payload to the bootloader component for encryption;
the bootloader component encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component; and
responding to the handshake request by transmitting the encrypted payload to the remote information handling system
However, Nix teaches
wherein the management controller is configured to establish trust with a remote information handling system by:
receiving a handshake request from the remote information handling system, the handshake request including a payload(US 20190097793, Nix, para. 0155, if TCP is utilized as the transport protocol for message 208, then the series of TCP messages including the initial handshake, one or more packets of payload data, and the closing of the connection could together comprise message 208);
the runtime component transmitting the payload to the bootloader component for encryption(US 20190097793, Nix, para. 0050, machine-to-machine communications may comprise communication between a module 101 and a server 105, such that data can be transferred between the two with minimal manual intervention, although manual intervention can be required to set up system 100 and any occasional manual maintenance required.);
the bootloader component encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component(US 20190097793, Nix, para. 0308, module 101 can create a module encrypted data 403a using the shared secret key 813, which could be recorded in nonvolatile memory earlier at step 803. Note that if module 101 is deriving keys for the very first time, then shared secret key 813 could comprise a pre-shared secret key 129a, which could be installed by a module provider 109 or end user before module 101 connects with a server 105. As one example, shared secret key 813 used in Step 1001 could have been recorded with a bootloader program 125 for module 101 in a nonvolatile memory such as a flash memory 101w[i.e. note: module 101 forms part of the bootloader component since it contains the bootloader]); and
responding to the handshake request by transmitting the encrypted payload to the remote information handling system(US 20190097793, Nix, para. 0074, The module program 101i and/or data reporting steps 101x can enable the module 101 to transmit or send data from sensor 101f or module 101 by recording data in memory such as RAM 101e, where the data can include as sensor data, a destination IP:port number, a packet or packet header value, an encryption or ciphering algorithm and key, a digital signature algorithm and key, etc., and the data can be subsequently read by the operating system 101h or the device driver 101g. The operating system 101h or the device driver 101g can write the data to a physical interface 101a using a system bus 101d in order to use a physical interface 101a to send data to a server 105.). Shivanna and Nix are combinable because both are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Shivanna with the teaching of Nix because a user would have been motivated to use a pre-shared secret key that uniquely identifies a module to establish secure communication between devices, taught by Nix, in order to securely transmit commands over the sideband interface for communicating with the IO controller in the system taught by Shivanna(Nix, para. 0025)
In regards to claim 7, Shivanna teaches a method comprising: wherein the management controller includes a firmware that includes a bootloader component, wherein the bootloader component is a first-party component that is cryptographically signed by a manufacturer of the information handling system and a runtime component(US 20170154184, Shivanna, para. 0009 and 0017: [0009]- the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor[i.e. note: the bootloader image is signature agnostic and therefore, may have a signature. Moreover, the signature may inherently be provided by the manufacturer].[0017]- the sideband interface[i.e. note: sideband interfaces are associated with out-of-band communication] can provide an application programming interface (API) that allows for a firmware installation associated with the IO controller to be accessed using commands sent over the sideband interface. In some cases, metadata (e.g., version, signature[e.g. note: ], compile date, etc.) associated with the firmware installation is accessed.), wherein the runtime component is a third-party component that is not cryptographically signed by the manufacturer of the information handling system(US 20170154184, Shivanna, para. 0009, the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor. Run-time authentication by an IO Controller allows for the detection of hacked IO firmware images without loading the complete firmware image. [i.e. note: the runtime component image is signature agnostic and may not be signed]. Moreover, runtime processing via an IO controller may inherently be performed via a 3rd party component); Shivanna does not teach the following limitations:
a management controller of an information handling system that is configured to provide out-of-band management of the information handling system receiving handshake request from a remote information handling system, the handshake request including a payload,
the bootloader component management controller encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component; and
the management controller responding to the handshake request by transmitting the encrypted payload to the remote information handling system;
the runtime component transmitting the payload to the bootloader component for encryption;
However, Nix teaches the limitations as follows:
a management controller of an information handling system that is configured to provide out-of-band management of the information handling system receiving handshake request from a remote information handling system, the handshake request including a payload(US 20190097793, Nix, para. 0155, if TCP is utilized as the transport protocol for message 208, then the series of TCP messages including the initial handshake, one or more packets of payload data, and the closing of the connection could together comprise message 208),
the bootloader component management controller encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component(US 20190097793, Nix, para. 0308, module 101 can create a module encrypted data 403a using the shared secret key 813, which could be recorded in nonvolatile memory earlier at step 803. Note that if module 101 is deriving keys for the very first time, then shared secret key 813 could comprise a pre-shared secret key 129a, which could be installed by a module provider 109 or end user before module 101 connects with a server 105. As one example, shared secret key 813 used in Step 1001 could have been recorded with a bootloader program 125 for module 101 in a nonvolatile memory such as a flash memory 101w[i.e. note: module 101 forms part of the bootloader component since it contains the bootloader]); and
the management controller responding to the handshake request by transmitting the encrypted payload to the remote information handling system(US 20190097793, Nix, para. 0074, The module program 101i and/or data reporting steps 101x can enable the module 101 to transmit or send data from sensor 101f or module 101 by recording data in memory such as RAM 101e, where the data can include as sensor data, a destination IP:port number, a packet or packet header value, an encryption or ciphering algorithm and key, a digital signature algorithm and key, etc., and the data can be subsequently read by the operating system 101h or the device driver 101g. The operating system 101h or the device driver 101g can write the data to a physical interface 101a using a system bus 101d in order to use a physical interface 101a to send data to a server 105.);
the runtime component transmitting the payload to the bootloader component for encryption(US 20190097793, Nix, para. 0050, machine-to-machine communications may comprise communication between a module 101 and a server 105, such that data can be transferred between the two with minimal manual intervention, although manual intervention can be required to set up system 100 and any occasional manual maintenance required.). Shivanna and Nix are combinable because both are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Shivanna with the teaching of Nix because a user would have been motivated to use a pre-shared secret key that uniquely identifies a module to establish secure communication between devices, taught by Nix, in order to securely transmit commands over the sideband interface for communicating with the IO controller in the system taught by Shivanna(Nix, para. 0025)
In regards to claim 13, Shivanna teaches an article of manufacture comprising a non-transitory, computer-readable medium having computer-executable instructions thereon that are executable by a processor of a management controller of an information handling system that is configured to provide out-of-band management of the information handling system, wherein the management controller includes a firmware that includes a bootloader component, wherein the bootloader component is a first-party component that is cryptographically signed by a manufacturer of the information handling system and a runtime component(US 20170154184, Shivanna, para. 0009 and 0017: [0009]- the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor[i.e. note: the bootloader image is signature agnostic and therefore, may have a signature. Moreover, the signature may inherently be provided by the manufacturer].[0017]- the sideband interface[i.e. note: sideband interfaces are associated with out-of-band communication] can provide an application programming interface (API) that allows for a firmware installation associated with the IO controller to be accessed using commands sent over the sideband interface. In some cases, metadata (e.g., version, signature[e.g. note: ], compile date, etc.) associated with the firmware installation is accessed.), wherein the runtime component is a third-party component that is not cryptographically signed by the manufacturer of the information handling system(US 20170154184, Shivanna, para. 0009, the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor. Run-time authentication by an IO Controller allows for the detection of hacked IO firmware images without loading the complete firmware image. [i.e. note: the runtime component image is signature agnostic and may not be signed]. Moreover, runtime processing via an IO controller may inherently be performed via a 3rd party component), Shivanna does not teach the instructions executable for:
receiving handshake request from a remote information handling system, the handshake request including a payload;
the runtime component transmitting the payload to the bootloader component for encryption;
the bootloader component encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component; and
responding to the handshake request by transmitting the encrypted payload to the remote information handling system;
However, Nix teaches the instructions executable for:
receiving handshake request from a remote information handling system, the handshake request including a payload(US 20190097793, Nix, para. 0155, if TCP is utilized as the transport protocol for message 208, then the series of TCP messages including the initial handshake, one or more packets of payload data, and the closing of the connection could together comprise message 208);
the runtime component transmitting the payload to the bootloader component for encryption(US 20190097793, Nix, para. 0050, machine-to-machine communications may comprise communication between a module 101 and a server 105, such that data can be transferred between the two with minimal manual intervention, although manual intervention can be required to set up system 100 and any occasional manual maintenance required.);
the bootloader component encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component(US 20190097793, Nix, para. 0308, module 101 can create a module encrypted data 403a using the shared secret key 813, which could be recorded in nonvolatile memory earlier at step 803. Note that if module 101 is deriving keys for the very first time, then shared secret key 813 could comprise a pre-shared secret key 129a, which could be installed by a module provider 109 or end user before module 101 connects with a server 105. As one example, shared secret key 813 used in Step 1001 could have been recorded with a bootloader program 125 for module 101 in a nonvolatile memory such as a flash memory 101w[i.e. note: module 101 forms part of the bootloader component since it contains the bootloader]); and
responding to the handshake request by transmitting the encrypted payload to the remote information handling system(US 20190097793, Nix, para. 0074, The module program 101i and/or data reporting steps 101x can enable the module 101 to transmit or send data from sensor 101f or module 101 by recording data in memory such as RAM 101e, where the data can include as sensor data, a destination IP:port number, a packet or packet header value, an encryption or ciphering algorithm and key, a digital signature algorithm and key, etc., and the data can be subsequently read by the operating system 101h or the device driver 101g. The operating system 101h or the device driver 101g can write the data to a physical interface 101a using a system bus 101d in order to use a physical interface 101a to send data to a server 105.). Shivanna and Nix are combinable because both are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Shivanna with the teaching of Nix because a user would have been motivated to use a pre-shared secret key that uniquely identifies a module to establish secure communication between devices, taught by Nix, in order to securely transmit commands over the sideband interface for communicating with the IO controller in the system taught by Shivanna(Nix, para. 0025)
2.) Claims 2, 3, 8, 9, 14 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over US 20170154184, Shivanna in view of US 20190097793, Nix and further in view of US 20230342446, Reddy
In regards to claim 2, the combination of Shivanna and Nix teach the information handling system of claim 1. The combination of Shivanna and Nix do not teach wherein the remote information handling system is a chassis management controller However, Reddy teaches wherein the remote information handling system is a chassis management controller (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Reddy, Shivanna and Nix are combinable because all are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware (Reddy, para. 0038)
In regards to claim 3, the combination of Shivanna and Nix teach the information handling system of claim 1. The combination of Shivanna and Nix do not teach wherein the management controller comprises a baseboard management controller (BMC) However, Reddy teaches wherein the management controller comprises a baseboard management controller (BMC) (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Shivanna, Nix and Reddy are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware(Reddy, para. 0038)
In regards to claim 8, the combination of Shivanna and Nix teach the method of claim 7. The combination of Shivanna and Nix do not teach wherein the remote information handling system is a chassis management controller However, Reddy teaches wherein the remote information handling system is a chassis management controller (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Shivanna, Nix and Reddy are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware(Reddy, para. 0038)
In regards to claim 9, the combination of Shivanna and Nix teach the method of claim 7. The combination of Shivanna and Nix do not teach wherein the management controller comprises a baseboard management controller (BMC) However, Reddy teaches wherein the management controller comprises a baseboard management controller (BMC (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Shivanna, Nix and Reddy are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware(Reddy, para. 0038)
In regards to claim 14, the combination of Shivanna and Nix teach the article of claim 13. The combination of Shivanna and Nix do not teach wherein the remote information handling system is a chassis management controller However, Reddy teaches wherein the remote information handling system is a chassis management controller (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Shivanna, Nix and Reddy are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware(Reddy, para. 0038)
In regards to claim 15, the combination of Shivanna and Nix teach the article of claim 13. The combination of Shivanna and Nix do not teach wherein the management controller comprises a baseboard management controller (BMC) However, Reddy teaches wherein the management controller comprises a baseboard management controller (BMC) (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Shivanna, Nix and Reddy are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware(Reddy, para. 0038)
3.) Claims 4, 10 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over US 20170154184, Shivanna in view of US 20190097793, Nix and further in view of US 20230134324, Emerson
In regards to claim 4, the combination of Shivanna and Nix teach the information handling system of claim 1. The combination of Shivanna and Nix do not teach wherein the key is a derived key based on a hardware identity certificate However, Emerson teaches wherein the key is a derived key based on a hardware identity certificate (US 20230134324, Emerson, para. 0038, In response to the request API call corresponding to the request for the key, the secure enclave 140 may extract the requisite hashes, extract the hardware identity certificate, generate the key, and provide the key to the remote management server 190.). Shivanna, Nix and Emerson are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Emerson because a user would have been motivated to utilize the baseboard management controller and secure enclave, taught by Emerson, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent tampering and malicious manipulation of the firmware(Emerson, para. 0057)
In regards to claim 10, the combination of Shivanna and Nix teach the method of claim 7. The combination of Shivanna and Nix do not teach wherein the key is a derived key based on a hardware identity certificate However, Emerson teaches wherein the key is a derived key based on a hardware identity certificate (US 20230134324, Emerson, para. 0038, In response to the request API call corresponding to the request for the key, the secure enclave 140 may extract the requisite hashes, extract the hardware identity certificate, generate the key, and provide the key to the remote management server 190.). Shivanna, Nix and Emerson are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Emerson because a user would have been motivated to utilize the baseboard management controller and secure enclave, taught by Emerson, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent tampering and malicious manipulation of the firmware(Emerson, para. 0057)
In regards to claim 16, the combination of Shivanna and Nix teach the article of claim 13. The combination of Shivanna and Nix do not teach wherein the key is a derived key based on a hardware identity certificate However, Emerson teaches wherein the key is a derived key based on a hardware identity certificate (US 20230134324, Emerson, para. 0038, In response to the request API call corresponding to the request for the key, the secure enclave 140 may extract the requisite hashes, extract the hardware identity certificate, generate the key, and provide the key to the remote management server 190.). Shivanna, Nix and Emerson are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Emerson because a user would have been motivated to utilize the baseboard management controller and secure enclave, taught by Emerson, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent tampering and malicious manipulation of the firmware(Emerson, para. 0057)
4.) Claims 5, 11 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over US 20170154184, Shivanna in view of US 20190097793, Nix and further in view of US 20200134185, Cho
In regards to claim 5, the combination of Shivanna and Nix teach the information handling system of claim 1. The combination of Shivanna and Nix do not teach wherein the key is a hidden root key (HRK) However, Cho teaches wherein the key is a hidden root key (HRK)(US 20200134185, Cho, para. 0006, In a number of the disclosed embodiments of the BMC, the HRK may comprise a symmetric advanced encryption standard (AES) cryptographic key based on one-time programmable (OTP) fuse bits fused in a first configuration.). Shivanna, Nix and Cho are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Cho because a user would have been motivated to utilize the baseboard management controller, taught by Cho, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent malicious code from modifying the firmware(Cho, para. 0041)
In regards to claim 11, the combination of Shivanna and Nix teach the method of claim 7. The combination of Shivanna and Nix do not teach wherein the key is a hidden root key (HRK) However, Cho teaches wherein the key is a hidden root key (HRK) (US 20200134185, Cho, para. 0006, In a number of the disclosed embodiments of the BMC, the HRK may comprise a symmetric advanced encryption standard (AES) cryptographic key based on one-time programmable (OTP) fuse bits fused in a first configuration.). Shivanna, Nix and Cho are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Cho because a user would have been motivated to utilize the baseboard management controller, taught by Cho, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent malicious code from modifying the firmware(Cho, para. 0041)
In regards to claim 17, the combination of Shivanna and Nix teach the article of claim 13. The combination of Shivanna and Nix do not teach wherein the key is a hidden root key (HRK) However, Cho teaches wherein the key is a hidden root key (HRK) (US 20200134185, Cho, para. 0006, In a number of the disclosed embodiments of the BMC, the HRK may comprise a symmetric advanced encryption standard (AES) cryptographic key based on one-time programmable (OTP) fuse bits fused in a first configuration.). Shivanna, Nix and Cho are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Cho because a user would have been motivated to utilize the baseboard management controller, taught by Cho, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent malicious code from modifying the firmware(Cho, para. 0041)
CONCLUSION
Any inquiry concerning this communication or earlier communications from the examiner should be directed to GREGORY LANE whose telephone number is (571)270-7469. The examiner can normally be reached on 571 270 7469 from 8:00 AM to 6:00 PM.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Taghi Arani, can be reached on 571 272 3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/GREGORY A LANE/Examiner, Art Unit 2438
/TAGHI T ARANI/Supervisory Patent Examiner, Art Unit 2438