Prosecution Insights
Last updated: October 02, 2026
Application No. 18/375,391

APPARATUS AND METHOD TO PREVENT SINGLE- AND ZERO-STEPPING OF TRUSTED EXECUTION ENVIRONMENTS

Non-Final OA §101§103
Filed
Sep 29, 2023
Priority
Jul 27, 2023 — provisional 63/529,328 +1 more
Examiner
SIMITOSKI, MICHAEL J
Art Unit
Tech Center
Assignee
Intel Corporation
OA Round
1 (Non-Final)
80%
Grant Probability
Favorable
1-2
OA Rounds
2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
630 granted / 785 resolved
+20.3% vs TC avg
Strong +28% interview lift
Without
With
+28.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
19 currently pending
Career history
802
Total Applications
across all art units

Statute-Specific Performance

§101
10.7%
-29.3% vs TC avg
§103
45.2%
+5.2% vs TC avg
§102
13.9%
-26.1% vs TC avg
§112
21.1%
-18.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 785 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION The IDS filed 10/6/2026 was received and considered. Claims 1-27 are pending. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 19-27 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter because claims 19-27 are directed to a “machine-readable medium”. The specification does not limit the interpretation of machine-readable medium to non-transitory media (“machine-readable storage media may include, without limitation…”, specification at ¶227, further clarifying that “embodiments of the disclosure also include non-transitory, tangible machine-readable media”, specification at ¶228). Therefore, the claimed “machine-readable medium” could be interpreted as a signal, per se and thus does not necessarily within at least one of the four categories of patent eligible subject matter defined under 35 U.S.C. §101. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 10 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over US 2022/0012369 A1 to Constable et al. (Constable), in view of “Mitigating interrupt-driven attacks against enclaved execution” by Piessens. Regarding claim 1, Constable discloses an apparatus comprising: a cache (system memory, Fig. 1) to store a plurality of instructions and data associated with a trusted execution environment (memory access request is service by the cache, ¶50; memory stores enclave code and data, Fig. 1, 134, 136); instruction processing circuitry to execute the plurality of instructions and process the data (processor executes the enclave, ¶118), the plurality of instructions to include one or more instructions with memory operands (processor decodes opcode IR, for example, ¶97, comprising operands, ¶98), wherein responsive to an interrupt or an exception (handling an asynchronous exit and enter, ¶87; event triggers AEX, enclave is suspended, ¶88), the instruction processing circuitry is to pause processing of the plurality of instructions and to execute a handler (event triggers AEX, enclave is suspended, ¶88; ERESUME invokes handler to handle an operating system signal caused by asynchronous exit and then resumes execution of the code from the enclave, ¶87); and decode circuitry (circuitry to determine one or more memory addresses to be accessed by one or more instructions to be executed by the architecturally protected enclave following an asynchronous enclave exit (AEX) event, ¶268) to partially decode a next instruction of the plurality of instructions to be processed following execution of the handler (preload instructions and data, ¶258; begins with tickling the first few instructions that are executed following the handler, ¶260) to determine if the next instruction indicates a memory access (software instruction decoder in the TEE may determine, at operation 2810, which memory addresses will be accessed by the first few TEE instructions, ¶260) and, if so, to calculate at least one corresponding memory address (determine which memory addresses will be accessed by the first few TEE instructions; tickling will be done on those memory addresses, ¶260). Constable lacks wherein the partial decode is to be performed in accordance with one or more constant time programming restrictions. However, Piessens, in an analogous art (AEX-Notify1, p. 20), teaches that it was known to implement the decoding of the next instructions as a constant-time instruction disassembler (p. 21), such that latency is constant (p. 25). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Constable such that the partial decode is to be performed in accordance with one or more constant time programming restrictions. One of ordinary skill in the art would have been motivated to perform such a modification to implement the AEX-Notify handler to achieve a constant latency, as taught by Piessens2. Regarding claim 10, the claim is similar in scope to claim 1 and is therefore rejected using a similar rationale. Regarding claim 19, the claim is similar in scope to claim 1 and is therefore rejected using a similar rationale, with Constable further disclosing machine-readable medium having program code stored thereon which, when executed by a machine, causes the machine to perform operations (¶242). Claims 8, 17 and 26 are rejected under 35 U.S.C. 103 as being unpatentable over Constable and Piessens, as applied to claims 1, 10 and 19, in view of “Smashex: Smashing SGX enclaves using exceptions” by Cui et al. (Cui). Regarding claims 8, 17 and 26, Constable, as modified, teaches saving registers within the enclave memory in a state save area (Constable, ¶62), but lacks wherein to pause processing the instruction processing circuitry is to save an instruction pointer (IP) indicating the next instruction. However, Cui, in an analogous art (asynchronous entry/exit on SGX), teaches that at an AEX, the hardware automatically stores the current instruction pointer (rip) in a state save area (p. 781, § Asynchronous Entry/Exits). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to further modify Constable such that to pause processing the instruction processing circuitry is to save an instruction pointer (IP) indicating the next instruction. One of ordinary skill in the art would have been motivated to perform such a modification to conform to SGX ERRESUME, as taught by Cui. Claims 9, 18 and 27 are rejected under 35 U.S.C. 103 as being unpatentable over Constable and Piessens, as applied to claims 1, 10 and 19, in view of US 5,148,538 to Celtruda et al. (Celtruda). Regarding claims 9, 18 and 27, Constable discloses wherein the decode circuitry comprises register identification circuitry to identify an address associated with a memory access (after AEX, the handler determines which memory addresses will be accessed based on the first view TEE instructions, ¶260), wherein information stored at the address is to be evaluated prior to execution of the next instruction (after determining memory addresses, access those memory locations, ¶260), but lacks identifying a register containing an address. However, Celtruda teaches that it was known for a cache access system to receive and decode an instruction from a processor within a computer system (col. 4, lines 29-31), where the decoded instruction provides indicators of registers containing address information to access the cache memory (col. 4, lines 33-37). Celtruda teaches that the processor uses a base register to generate a real address (col. 4, lines 39-44 and 52-55), with the benefit of shortening address generation (col. 3, lines 55-65; see also col. 6, lines 22-33). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to further modify Constable such that the decode circuitry (processor) comprises register identification circuity to identify a register containing an address associated with the memory access. One of ordinary skill in the art would have been motivated to perform such a modification to utilize predicted address to decrease address generation time, as taught by Celtruda. Allowable Subject Matter Claims 2, 11 and 20 are objected to as being dependent upon a rejected base claim but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims and any rejections under 35 U.S.C. §101 are overcome. The following is a statement of reasons for the indication of allowable subject matter: Regarding claims 2, 11 and 20, Constable, for example, teaches that the decode/tickle mitigation option determines the next instruction such that it can access/warm a portion of memory (¶260). However, the prior art – individually, or in a reasonable combination, fails to teach performing, as part of the partial decode: confirming that one or more measured variables associated with decoding of the next instruction are consistent with one or more stored variables corresponding to an instruction type of the next instruction, within the context of the claims as a whole. Claims 3-7, 12-16 and 21-25 inherit allowable subject matter. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20200409711 A1 (Constable; Scott et al.) teaches tracking cache entries impacted by security-critical events (¶¶51-52; see also ¶68) to mitigate side-channel attacks. US 20200004552 A1 (LIU; Fangfei et al.) teaches secure execution and memory protection with respect to a TEE. US 20170185533 A1 (Rozas; Carlos V. et al.) teaches suspend and resume operations in SGX (¶¶38-39). “Teesec: Pre-silicon vulnerability discovery for trusted execution environments” (Ghaniyoun, Moein, et al.) teaches hardware designs to mitigate secret leakage from secure enclaves (§1). “SGX-Step: A practical attack framework for precise enclave execution control” (Van Bulck, Jo, Frank Piessens, and Raoul Strackx, cited on IDS filed on 10/6/2023) teaches interrupt-driven attacks in SGX (§2.2). Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL J SIMITOSKI whose telephone number is (571)272-3841. The examiner can normally be reached Monday - Friday, 7:00-3:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Michael Simitoski/ Primary Examiner, Art Unit 2493 August 26, 2026 1 Constable references combining the disclosure with the AEX Notify instruction set ISA to detect and prevent single-stepping and zero-stepping using an AEX Notify handler, ¶249, ¶258 2 Piessens cites “Provably secure isolation for interruptible enclaved execution on small microprocessors” (Busi, Matteo, et al.), which teaches that constant-time execution mitigates timing leakage (p. 266).
Read full office action

Prosecution Timeline

Sep 29, 2023
Application Filed
Nov 03, 2023
Response after Non-Final Action
Sep 04, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12732808
VEHICLE, IN-VEHICLE DEVICE, AND MANAGEMENT METHOD
5y 0m to grant Granted Sep 08, 2026
Patent 12712747
SECURE CHANNEL INITIATION BETWEEN CARD AND HOST
2y 0m to grant Granted Aug 18, 2026
Patent 12695631
INTERIM ROOT-OF-TRUST ENROLMENT AND DEVICE-BOUND PUBLIC KEY REGISTRATION
2y 10m to grant Granted Jul 28, 2026
Patent 12695722
Network Traffic Control Method and Related System
2y 4m to grant Granted Jul 28, 2026
Patent 12689646
Malicious application detection
3y 7m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+28.4%)
3y 2m (~2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 785 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month