Prosecution Insights
Last updated: October 02, 2026
Application No. 18/364,067

EXTEND MACHINE TRUST TO THIRD-PARTY FIRMWARE

Non-Final OA §103
Filed
Aug 02, 2023
Examiner
LANE, GREGORY A
Art Unit
2438
Tech Center
2400 — Computer Networks
Assignee
Dell Products L.P.
OA Round
3 (Non-Final)
75%
Grant Probability
Favorable
3-4
OA Rounds
2m
Est. Remaining
74%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
454 granted / 607 resolved
+16.8% vs TC avg
Minimal -1% lift
Without
With
+-0.7%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
16 currently pending
Career history
629
Total Applications
across all art units

Statute-Specific Performance

§101
13.1%
-26.9% vs TC avg
§103
61.5%
+21.5% vs TC avg
§102
12.6%
-27.4% vs TC avg
§112
7.8%
-32.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 607 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 4/10/2026 has been entered. claims 1, 7, and 13 are amended Claims 1-5, 7-11, and 13-17 are pending Examiner’s Note: The specification discloses on page 14 that the management controller may include a processor, memory, and a network interface Response to Arguments Applicant’s amendment to claims 1, 7 and 13 filed on 3/11/2026 regarding, “wherein the bootloader component is a first-party component that is cryptographically signed by a manufacturer of the information handling system, and a runtime component, wherein the runtime component is a third-party component that is not cryptographically signed by the manufacturer of the information handling system;” necessitated the new ground(s) of rejection presented in this Office action. Therefore, Applicant's arguments with respect to claims 1-5, 7-11, and 13-17 have been considered but are moot in view of the new ground(s) of rejection. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 1.) Claims 1, 7 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over US 20170154184, Shivanna in view of US 20190097793, Nix In regards to claim 1, Shivanna teaches an information handling system comprising: a host system(US 20170154184, Shivanna, para. 0020, FIG. 2 is a block diagram of an example system 200 with server device 202 in communication with management station 204 for providing OS agnostic validation of firmware images.); and a management controller configured to provide out-of-band management of the information handling system and comprising a firmware that includes a bootloader component, wherein the bootloader component is a first-party component that is cryptographically signed by a manufacturer of the information handling system(US 20170154184, Shivanna, para. 0009 and 0017: [0009]- the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor[i.e. note: the bootloader image is signature agnostic and therefore, may have a signature. Moreover, the signature may inherently be provided by the manufacturer].[0017]- the sideband interface[i.e. note: sideband interfaces are associated with out-of-band communication] can provide an application programming interface (API) that allows for a firmware installation associated with the IO controller to be accessed using commands sent over the sideband interface. In some cases, metadata (e.g., version, signature[e.g. note: ], compile date, etc.) associated with the firmware installation is accessed.) and a runtime component, wherein the runtime component is a third-party component that is not cryptographically signed by the manufacturer of the information handling system(US 20170154184, Shivanna, para. 0009, the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor. Run-time authentication by an IO Controller allows for the detection of hacked IO firmware images without loading the complete firmware image. [i.e. note: the runtime component image is signature agnostic and may not be signed Moreover, runtime processing via an IO controller may inherently be performed via a 3rd party component]); Shivanna does not teach wherein the management controller is configured to establish trust with a remote information handling system by: receiving a handshake request from the remote information handling system, the handshake request including a payload; the runtime component transmitting the payload to the bootloader component for encryption; the bootloader component encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component; and responding to the handshake request by transmitting the encrypted payload to the remote information handling system However, Nix teaches wherein the management controller is configured to establish trust with a remote information handling system by: receiving a handshake request from the remote information handling system, the handshake request including a payload(US 20190097793, Nix, para. 0155, if TCP is utilized as the transport protocol for message 208, then the series of TCP messages including the initial handshake, one or more packets of payload data, and the closing of the connection could together comprise message 208); the runtime component transmitting the payload to the bootloader component for encryption(US 20190097793, Nix, para. 0050, machine-to-machine communications may comprise communication between a module 101 and a server 105, such that data can be transferred between the two with minimal manual intervention, although manual intervention can be required to set up system 100 and any occasional manual maintenance required.); the bootloader component encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component(US 20190097793, Nix, para. 0308, module 101 can create a module encrypted data 403a using the shared secret key 813, which could be recorded in nonvolatile memory earlier at step 803. Note that if module 101 is deriving keys for the very first time, then shared secret key 813 could comprise a pre-shared secret key 129a, which could be installed by a module provider 109 or end user before module 101 connects with a server 105. As one example, shared secret key 813 used in Step 1001 could have been recorded with a bootloader program 125 for module 101 in a nonvolatile memory such as a flash memory 101w[i.e. note: module 101 forms part of the bootloader component since it contains the bootloader]); and responding to the handshake request by transmitting the encrypted payload to the remote information handling system(US 20190097793, Nix, para. 0074, The module program 101i and/or data reporting steps 101x can enable the module 101 to transmit or send data from sensor 101f or module 101 by recording data in memory such as RAM 101e, where the data can include as sensor data, a destination IP:port number, a packet or packet header value, an encryption or ciphering algorithm and key, a digital signature algorithm and key, etc., and the data can be subsequently read by the operating system 101h or the device driver 101g. The operating system 101h or the device driver 101g can write the data to a physical interface 101a using a system bus 101d in order to use a physical interface 101a to send data to a server 105.). Shivanna and Nix are combinable because both are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Shivanna with the teaching of Nix because a user would have been motivated to use a pre-shared secret key that uniquely identifies a module to establish secure communication between devices, taught by Nix, in order to securely transmit commands over the sideband interface for communicating with the IO controller in the system taught by Shivanna(Nix, para. 0025) In regards to claim 7, Shivanna teaches a method comprising: wherein the management controller includes a firmware that includes a bootloader component, wherein the bootloader component is a first-party component that is cryptographically signed by a manufacturer of the information handling system and a runtime component(US 20170154184, Shivanna, para. 0009 and 0017: [0009]- the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor[i.e. note: the bootloader image is signature agnostic and therefore, may have a signature. Moreover, the signature may inherently be provided by the manufacturer].[0017]- the sideband interface[i.e. note: sideband interfaces are associated with out-of-band communication] can provide an application programming interface (API) that allows for a firmware installation associated with the IO controller to be accessed using commands sent over the sideband interface. In some cases, metadata (e.g., version, signature[e.g. note: ], compile date, etc.) associated with the firmware installation is accessed.), wherein the runtime component is a third-party component that is not cryptographically signed by the manufacturer of the information handling system(US 20170154184, Shivanna, para. 0009, the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor. Run-time authentication by an IO Controller allows for the detection of hacked IO firmware images without loading the complete firmware image. [i.e. note: the runtime component image is signature agnostic and may not be signed]. Moreover, runtime processing via an IO controller may inherently be performed via a 3rd party component); Shivanna does not teach the following limitations: a management controller of an information handling system that is configured to provide out-of-band management of the information handling system receiving handshake request from a remote information handling system, the handshake request including a payload, the bootloader component management controller encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component; and the management controller responding to the handshake request by transmitting the encrypted payload to the remote information handling system; the runtime component transmitting the payload to the bootloader component for encryption; However, Nix teaches the limitations as follows: a management controller of an information handling system that is configured to provide out-of-band management of the information handling system receiving handshake request from a remote information handling system, the handshake request including a payload(US 20190097793, Nix, para. 0155, if TCP is utilized as the transport protocol for message 208, then the series of TCP messages including the initial handshake, one or more packets of payload data, and the closing of the connection could together comprise message 208), the bootloader component management controller encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component(US 20190097793, Nix, para. 0308, module 101 can create a module encrypted data 403a using the shared secret key 813, which could be recorded in nonvolatile memory earlier at step 803. Note that if module 101 is deriving keys for the very first time, then shared secret key 813 could comprise a pre-shared secret key 129a, which could be installed by a module provider 109 or end user before module 101 connects with a server 105. As one example, shared secret key 813 used in Step 1001 could have been recorded with a bootloader program 125 for module 101 in a nonvolatile memory such as a flash memory 101w[i.e. note: module 101 forms part of the bootloader component since it contains the bootloader]); and the management controller responding to the handshake request by transmitting the encrypted payload to the remote information handling system(US 20190097793, Nix, para. 0074, The module program 101i and/or data reporting steps 101x can enable the module 101 to transmit or send data from sensor 101f or module 101 by recording data in memory such as RAM 101e, where the data can include as sensor data, a destination IP:port number, a packet or packet header value, an encryption or ciphering algorithm and key, a digital signature algorithm and key, etc., and the data can be subsequently read by the operating system 101h or the device driver 101g. The operating system 101h or the device driver 101g can write the data to a physical interface 101a using a system bus 101d in order to use a physical interface 101a to send data to a server 105.); the runtime component transmitting the payload to the bootloader component for encryption(US 20190097793, Nix, para. 0050, machine-to-machine communications may comprise communication between a module 101 and a server 105, such that data can be transferred between the two with minimal manual intervention, although manual intervention can be required to set up system 100 and any occasional manual maintenance required.). Shivanna and Nix are combinable because both are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Shivanna with the teaching of Nix because a user would have been motivated to use a pre-shared secret key that uniquely identifies a module to establish secure communication between devices, taught by Nix, in order to securely transmit commands over the sideband interface for communicating with the IO controller in the system taught by Shivanna(Nix, para. 0025) In regards to claim 13, Shivanna teaches an article of manufacture comprising a non-transitory, computer-readable medium having computer-executable instructions thereon that are executable by a processor of a management controller of an information handling system that is configured to provide out-of-band management of the information handling system, wherein the management controller includes a firmware that includes a bootloader component, wherein the bootloader component is a first-party component that is cryptographically signed by a manufacturer of the information handling system and a runtime component(US 20170154184, Shivanna, para. 0009 and 0017: [0009]- the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor[i.e. note: the bootloader image is signature agnostic and therefore, may have a signature. Moreover, the signature may inherently be provided by the manufacturer].[0017]- the sideband interface[i.e. note: sideband interfaces are associated with out-of-band communication] can provide an application programming interface (API) that allows for a firmware installation associated with the IO controller to be accessed using commands sent over the sideband interface. In some cases, metadata (e.g., version, signature[e.g. note: ], compile date, etc.) associated with the firmware installation is accessed.), wherein the runtime component is a third-party component that is not cryptographically signed by the manufacturer of the information handling system(US 20170154184, Shivanna, para. 0009, the integrity of firmware images are validated on-demand (i.e., during boot or run-time and for images with and without signatures) by using a trusted group of management processors in a server chassis and a firmware validation service hosted by each management processor. Run-time authentication by an IO Controller allows for the detection of hacked IO firmware images without loading the complete firmware image. [i.e. note: the runtime component image is signature agnostic and may not be signed]. Moreover, runtime processing via an IO controller may inherently be performed via a 3rd party component), Shivanna does not teach the instructions executable for: receiving handshake request from a remote information handling system, the handshake request including a payload; the runtime component transmitting the payload to the bootloader component for encryption; the bootloader component encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component; and responding to the handshake request by transmitting the encrypted payload to the remote information handling system; However, Nix teaches the instructions executable for: receiving handshake request from a remote information handling system, the handshake request including a payload(US 20190097793, Nix, para. 0155, if TCP is utilized as the transport protocol for message 208, then the series of TCP messages including the initial handshake, one or more packets of payload data, and the closing of the connection could together comprise message 208); the runtime component transmitting the payload to the bootloader component for encryption(US 20190097793, Nix, para. 0050, machine-to-machine communications may comprise communication between a module 101 and a server 105, such that data can be transferred between the two with minimal manual intervention, although manual intervention can be required to set up system 100 and any occasional manual maintenance required.); the bootloader component encrypting the payload upon a subsequent boot of the management controller via a key that is accessible by the bootloader component but not accessible by the runtime component(US 20190097793, Nix, para. 0308, module 101 can create a module encrypted data 403a using the shared secret key 813, which could be recorded in nonvolatile memory earlier at step 803. Note that if module 101 is deriving keys for the very first time, then shared secret key 813 could comprise a pre-shared secret key 129a, which could be installed by a module provider 109 or end user before module 101 connects with a server 105. As one example, shared secret key 813 used in Step 1001 could have been recorded with a bootloader program 125 for module 101 in a nonvolatile memory such as a flash memory 101w[i.e. note: module 101 forms part of the bootloader component since it contains the bootloader]); and responding to the handshake request by transmitting the encrypted payload to the remote information handling system(US 20190097793, Nix, para. 0074, The module program 101i and/or data reporting steps 101x can enable the module 101 to transmit or send data from sensor 101f or module 101 by recording data in memory such as RAM 101e, where the data can include as sensor data, a destination IP:port number, a packet or packet header value, an encryption or ciphering algorithm and key, a digital signature algorithm and key, etc., and the data can be subsequently read by the operating system 101h or the device driver 101g. The operating system 101h or the device driver 101g can write the data to a physical interface 101a using a system bus 101d in order to use a physical interface 101a to send data to a server 105.). Shivanna and Nix are combinable because both are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Shivanna with the teaching of Nix because a user would have been motivated to use a pre-shared secret key that uniquely identifies a module to establish secure communication between devices, taught by Nix, in order to securely transmit commands over the sideband interface for communicating with the IO controller in the system taught by Shivanna(Nix, para. 0025) 2.) Claims 2, 3, 8, 9, 14 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over US 20170154184, Shivanna in view of US 20190097793, Nix and further in view of US 20230342446, Reddy In regards to claim 2, the combination of Shivanna and Nix teach the information handling system of claim 1. The combination of Shivanna and Nix do not teach wherein the remote information handling system is a chassis management controller However, Reddy teaches wherein the remote information handling system is a chassis management controller (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Reddy, Shivanna and Nix are combinable because all are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware (Reddy, para. 0038) In regards to claim 3, the combination of Shivanna and Nix teach the information handling system of claim 1. The combination of Shivanna and Nix do not teach wherein the management controller comprises a baseboard management controller (BMC) However, Reddy teaches wherein the management controller comprises a baseboard management controller (BMC) (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Shivanna, Nix and Reddy are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware(Reddy, para. 0038) In regards to claim 8, the combination of Shivanna and Nix teach the method of claim 7. The combination of Shivanna and Nix do not teach wherein the remote information handling system is a chassis management controller However, Reddy teaches wherein the remote information handling system is a chassis management controller (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Shivanna, Nix and Reddy are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware(Reddy, para. 0038) In regards to claim 9, the combination of Shivanna and Nix teach the method of claim 7. The combination of Shivanna and Nix do not teach wherein the management controller comprises a baseboard management controller (BMC) However, Reddy teaches wherein the management controller comprises a baseboard management controller (BMC (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Shivanna, Nix and Reddy are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware(Reddy, para. 0038) In regards to claim 14, the combination of Shivanna and Nix teach the article of claim 13. The combination of Shivanna and Nix do not teach wherein the remote information handling system is a chassis management controller However, Reddy teaches wherein the remote information handling system is a chassis management controller (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Shivanna, Nix and Reddy are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware(Reddy, para. 0038) In regards to claim 15, the combination of Shivanna and Nix teach the article of claim 13. The combination of Shivanna and Nix do not teach wherein the management controller comprises a baseboard management controller (BMC) However, Reddy teaches wherein the management controller comprises a baseboard management controller (BMC) (US 20230342446, Reddy, para. 0029, The baseboard management controller may have hardware level access to hardware devices that are located in a server chassis including system memory.). Shivanna, Nix and Reddy are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Reddy because a user would have been motivated to utilize the management controller and security processor, taught by Reddy, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to provide security functions that resist tampering and malicious software affecting the firmware(Reddy, para. 0038) 3.) Claims 4, 10 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over US 20170154184, Shivanna in view of US 20190097793, Nix and further in view of US 20230134324, Emerson In regards to claim 4, the combination of Shivanna and Nix teach the information handling system of claim 1. The combination of Shivanna and Nix do not teach wherein the key is a derived key based on a hardware identity certificate However, Emerson teaches wherein the key is a derived key based on a hardware identity certificate (US 20230134324, Emerson, para. 0038, In response to the request API call corresponding to the request for the key, the secure enclave 140 may extract the requisite hashes, extract the hardware identity certificate, generate the key, and provide the key to the remote management server 190.). Shivanna, Nix and Emerson are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Emerson because a user would have been motivated to utilize the baseboard management controller and secure enclave, taught by Emerson, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent tampering and malicious manipulation of the firmware(Emerson, para. 0057) In regards to claim 10, the combination of Shivanna and Nix teach the method of claim 7. The combination of Shivanna and Nix do not teach wherein the key is a derived key based on a hardware identity certificate However, Emerson teaches wherein the key is a derived key based on a hardware identity certificate (US 20230134324, Emerson, para. 0038, In response to the request API call corresponding to the request for the key, the secure enclave 140 may extract the requisite hashes, extract the hardware identity certificate, generate the key, and provide the key to the remote management server 190.). Shivanna, Nix and Emerson are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Emerson because a user would have been motivated to utilize the baseboard management controller and secure enclave, taught by Emerson, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent tampering and malicious manipulation of the firmware(Emerson, para. 0057) In regards to claim 16, the combination of Shivanna and Nix teach the article of claim 13. The combination of Shivanna and Nix do not teach wherein the key is a derived key based on a hardware identity certificate However, Emerson teaches wherein the key is a derived key based on a hardware identity certificate (US 20230134324, Emerson, para. 0038, In response to the request API call corresponding to the request for the key, the secure enclave 140 may extract the requisite hashes, extract the hardware identity certificate, generate the key, and provide the key to the remote management server 190.). Shivanna, Nix and Emerson are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Emerson because a user would have been motivated to utilize the baseboard management controller and secure enclave, taught by Emerson, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent tampering and malicious manipulation of the firmware(Emerson, para. 0057) 4.) Claims 5, 11 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over US 20170154184, Shivanna in view of US 20190097793, Nix and further in view of US 20200134185, Cho In regards to claim 5, the combination of Shivanna and Nix teach the information handling system of claim 1. The combination of Shivanna and Nix do not teach wherein the key is a hidden root key (HRK) However, Cho teaches wherein the key is a hidden root key (HRK)(US 20200134185, Cho, para. 0006, In a number of the disclosed embodiments of the BMC, the HRK may comprise a symmetric advanced encryption standard (AES) cryptographic key based on one-time programmable (OTP) fuse bits fused in a first configuration.). Shivanna, Nix and Cho are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Cho because a user would have been motivated to utilize the baseboard management controller, taught by Cho, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent malicious code from modifying the firmware(Cho, para. 0041) In regards to claim 11, the combination of Shivanna and Nix teach the method of claim 7. The combination of Shivanna and Nix do not teach wherein the key is a hidden root key (HRK) However, Cho teaches wherein the key is a hidden root key (HRK) (US 20200134185, Cho, para. 0006, In a number of the disclosed embodiments of the BMC, the HRK may comprise a symmetric advanced encryption standard (AES) cryptographic key based on one-time programmable (OTP) fuse bits fused in a first configuration.). Shivanna, Nix and Cho are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Cho because a user would have been motivated to utilize the baseboard management controller, taught by Cho, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent malicious code from modifying the firmware(Cho, para. 0041) In regards to claim 17, the combination of Shivanna and Nix teach the article of claim 13. The combination of Shivanna and Nix do not teach wherein the key is a hidden root key (HRK) However, Cho teaches wherein the key is a hidden root key (HRK) (US 20200134185, Cho, para. 0006, In a number of the disclosed embodiments of the BMC, the HRK may comprise a symmetric advanced encryption standard (AES) cryptographic key based on one-time programmable (OTP) fuse bits fused in a first configuration.). Shivanna, Nix and Cho are combinable because they are from the same field of endeavor of device booting. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of the combination of Shivanna and Nix with the teaching of Cho because a user would have been motivated to utilize the baseboard management controller, taught by Cho, to provide enhanced protection for the firmware, taught by the combination of Shivanna and Nix, in order to prevent malicious code from modifying the firmware(Cho, para. 0041) CONCLUSION Any inquiry concerning this communication or earlier communications from the examiner should be directed to GREGORY LANE whose telephone number is (571)270-7469. The examiner can normally be reached on 571 270 7469 from 8:00 AM to 6:00 PM. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Taghi Arani, can be reached on 571 272 3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /GREGORY A LANE/Examiner, Art Unit 2438 /TAGHI T ARANI/Supervisory Patent Examiner, Art Unit 2438
Read full office action

Prosecution Timeline

Aug 02, 2023
Application Filed
Jun 30, 2025
Non-Final Rejection mailed — §103
Sep 30, 2025
Response Filed
Jan 12, 2026
Final Rejection mailed — §103
Mar 11, 2026
Response after Non-Final Action
Apr 10, 2026
Request for Continued Examination
Apr 18, 2026
Response after Non-Final Action
Sep 09, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739642
METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR DETECTING AND MITIGATING SECURITY ATTACKS ON PRODUCER NETWORK FUNCTIONS (NFs) USING MAPPINGS BETWEEN DYNAMICALLY ASSIGNED SERVICE-BASED INTERFACE (SBI) MESSAGE IDENTIFIERS AND PROXY NF IDENTIFIERS AT PROXY NF
2y 9m to grant Granted Sep 15, 2026
Patent 12706893
METHOD FOR MANAGING COMMUNICATION BETWEEN TERMINALS IN A COMMUNICATION NETWORK, AND DEVICES AND SYSTEM FOR IMPLEMENTING THE METHOD
4y 7m to grant Granted Aug 11, 2026
Patent 12705361
SYSTEMS AND METHODS FOR GENERATING AGGREGATED APPLICATION ACCESS RISK SCORES
2y 9m to grant Granted Aug 11, 2026
Patent 12701409
SECURE COMMUNICATION OF BROADCAST INFORMATION RELATED TO CELL ACCESS
5y 4m to grant Granted Aug 04, 2026
Patent 12683797
CONDITIONAL AUTHENTICATION ACCESS CONTROL METHOD
2y 10m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
75%
Grant Probability
74%
With Interview (-0.7%)
3y 4m (~2m remaining)
Median Time to Grant
High
PTA Risk
Based on 607 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month