Prosecution Insights
Last updated: October 04, 2026
Application No. 18/399,497

SOFTWARE BASED VALIDATION OF MEMORY FOR FAULT TOLERANT SYSTEMS

Non-Final OA §103§112
Filed
Dec 28, 2023
Priority
Oct 20, 2023 — provisional 63/545,153
Examiner
XU, MICHAEL
Art Unit
2113
Tech Center
2100 — Computer Architecture & Software
Assignee
Stratus Technologies Ireland Ltd.
OA Round
3 (Non-Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
100 granted / 132 resolved
+20.8% vs TC avg
Strong +28% interview lift
Without
With
+27.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
12 currently pending
Career history
149
Total Applications
across all art units

Statute-Specific Performance

§101
14.2%
-25.8% vs TC avg
§103
60.5%
+20.5% vs TC avg
§102
16.5%
-23.5% vs TC avg
§112
2.5%
-37.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 132 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Objections Claims 1,13 objected to because of the following informalities: misspelled word “operation system” should be “operating system” in limitation “wherein the availability driver of the active node disables or suspends all processes that alter operating system memory and transfers all operation system memory”. Appropriate correction is required. For the purposes of examination, all instances of “operation system” will be interpreted as “operating system”. Claim 19 objected to because of the following informalities: naming inconsistency between “active node to the standby node” and “first node to the second node”. Appropriate correction is required. Claim 19 depends on claim 9, which depends on claim 8. Claims 8 and 9 do not use the terms active node and standby node, using the terms “first compute node” and “second compute node” instead. For the purposes of examination, in claim 19, the term “active node” will be interpreted as “first compute node” and “standby node” will be interpreted as “second compute node”. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 5 rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 5 recites the limitation " the … standby validation array” in “The computer system of claim 1, wherein the active validation array and standby validation array are generated by a checksum or hash function.”. There is insufficient antecedent basis for this limitation in the claim. The standby validation array is defined in claim 2, but claim 5 depends on claim 1, not on claim 2. For the purposes of examination, the standby validation array in claim 5 will be interpreted as a validation array associated with the standby node. Appropriate correction is required. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-3,5-7,13-14,16,18 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 20200050523 A1 (Pawlowski) in view of US 20080208923 A1 (Watanabe). Regarding claim 1, Pawlowski teaches, A computer comprising: a network device; a storage device; (fig 1; par 23-24 teaches- a fault tolerant computer, and a plurality of CPU nodes connected to the IO domains through a mesh fabric to the outside world and storage controllers and disks and additional IO devices.) and at least two compute nodes, wherein one compute node is designated an active node and the other compute node is designated a standby node, (par 9,13 – generally teaches a method of CPU-node failover in a fault-tolerant computer system in which memory and processor state are transferred from an active node to a standby node. Par 53 – teaches two computers/nodes that are assigned either an active/primary role or a standby/secondary role.) each compute node comprising a dedicated memory with an isolated utility executive, (par 54,57 – teaches how each node includes a CPU and memory, including a reserved memory region unavailable to the OS and containing the FT Virtual Machine Monitor (FTVMM). fig 5A:522 “FT Kernel mode driver”; par 60-61 describe the FT Kernel mode driver which “loads or writes the program and data code of the FT Virtual Machine Monitor (FTVMM) code 580, the FTVMM data 584, … and the VMCS-L0 Array 592 into the Reserved Memory Region.”; The reserved memory region corresponds to the claimed dedicated memory and the FTVMM corresponds to the isolated utility executive. par 70-71 – teaches some more details about the FT driver and how it copies memory pages into the corresponding memory pages in the second subsystem.) an operating system memory,(par 44 “The OS bootloader loads the OS image into memory and begins OS execution.”) and a firmware reserved memory(fig 5A:504,508; par 57 “Referring to FIG. 5A, in normal, non-mirrored, operation, the layers in the fault tolerant computer system include …; a server firmware layer 504 including the system Universal Extensible Firmware Interface (UEFI) BIOS 508; and a zero layer reserved memory region 512 … . The zero layer reserved memory 512 is reserved by the BIOS 508 at boot time. Although most of the memory of the fault tolerant computer system is available for use by the Operating System and software, the reserved memory 512 is not.”) and the active node operating system memory further comprises an availability driver; (fig 5A:522,536; par 58-60 – teaches an FT Management Layer which triggers and manages the FT mode driver.) wherein the availability driver of the active node disables or suspends all processes that alter operating system memory (par 70 – teaches how the FT driver executes driver code on all processors on the active but failing CPU concurrently and copies the final set of dirtied pages to the Standby CPU 14C. The FT Driver causes all processors on CPU 14 to disable system interrupt processing on each processor so as to prevent other programs in the Fault tolerant computer system from generating more Dirty Page Bits.) and transfers all operation system memory of the active node to the operating system memory of the standby node;( par 71 – teaches how “the FT Driver then copies the set of physical memory pages that are identified in the Dirty Page Bit Map into the corresponding physical memory addresses in the Second Subsystem.”. par 64 – teaches that the FT driver copies all of system memory into the second subsystem and “may use a DMA controller or the Switch 430 to perform a high speed memory transfer operation that copies all system memory into the secondary or standby computer.”) the isolated utility executive of the active node executes a code to trigger the transfer the memory of the active node to the standby node.(par 70-71,64 – teaches copying all of system memory into the second subsystem. In one embodiment, a high-speed memory transfer is used.) However, although Pawloski teaches the isolated utility executive transferring the memory to the standby node, Pawlowski does not specifically teach the isolated utility executive of the active node executes a code to generate an active validation array set of all operating system memory, the active validation array is then transferred to the standby node. On the other hand, Watanabe teaches, the isolated utility executive of the active node executes a code to generate an active validation array set of all operating system memory,(fig 11:1103; par 63 -teaches calculating a checksum of each page. Par 68 – teaches a data check log which collects the checksum of each page. ) the active validation array is then transferred to the standby node.(fig 2:210,211,213; fig 10; par 60,69 – teaches transferring the data check log through the log transmission means to the external log storage area. Fig 18:1806; Par 72 – teaches notifying the checksum calculation means when a data check log is received. Par 79 – teaches that the data check log is transmitted to the secondary site so that the check operation of the backup data can be done.) Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to further modify Pawlowski’s fault-tolerant active/standby memory-transfer system to incorporate the memory checksum generation and transfer technique of Watanabe. One of ordinary skill in the art would have been motivated to incorporate Watanabe’s memory verification technique to verify that memory copied from the active node to the standby node is consistent with the corresponding memory of the active node.(Watanabe par 5 “… in order to confirm that the backup data is normally prepared, it is necessary to verify the consistency of the data of both systems. … When verifying consistency of the data of both systems, a checksum of the data of the primary system and a checksum of the backup data of the secondary system are checked, thereby verifying whether or not the data are consistent.”). Pawlowski already copies all of system memory into the standby node. Applying Watanabe’s known memory checksum verification technique to the memory copied by Pawlowski would have predictably improved the system to determine whether the standby copy was prepared consistently before relying on that copy for failover. Regarding claim 2, Pawlowski and Watanabe teach, The computer system of claim 1, Pawlowski and Watanabe further teach, wherein the isolated utility executive of the standby node(Pawlowski par 64 – teaches a FT Kernel Mode Driver which together with the FTVMM, handles the memory transfer operations that copy all system memory into the standby computer. ) executes a code to generate a standby validation array set of all operating system memory(Watanabe fig 14; par 65 – teaches extracting the data for all the pages of a memory area, and notifying the checksum calculation at the end of the extraction process. Fig 2:229; Par 75,77 – teaches calculating a checksum at the backup site in the same way as the at primary site, and that the checksum is calculated for each page. ) that is verified against the active validation array. (Watanabe fig 2:230; par 46 teaches comparing the checksum calculated at the standby site against the checksum included in the data check log that was transferred over. Fig 21; par 77 – teaches checking the checksums generated at the secondary site and received from the primary site against each other.) Regarding claim 3, Pawlowski and Watanabe teach, The computer system of claim 2, Pawlowski and Watanabe further teach, wherein the isolated utility executive of the standby node(Watanabe par 77,78 – teaches how the standby side validation does the validation check and notifies the operation terminal 108 of the validation check results.) signals to the availability driver to complete or abort transfer of a network and storage device being used by the active node to the standby node. (Pawlowski par 73 – teaches how the failover operation can be aborted at any time before the active CPU node has been swapped. par 74-75 – teaches how the cpu nodes have a mailbox that show their respective states and trigger any final cleanup for the migration as required, actions like changing the switching fabric to switch to the new active CPU node and resume the operating system and interrupted instructions on the new active CPU node, allowing previously paused devices and transactions to flow again.) it would have been obvious to use Watanabe’s secondary-side consistency determination as the signal to Pawlowski’s FT Driver to complete the fail over when validation succeeds or abort the failover when validation fails, which would prevent the standby node from assuming operation using an inconsistent memory copy. Regarding claim 5, Pawlowski and Watanabe teach, The computer system of claim 1, Watanabe further teaches, wherein the active validation array and standby validation array are generated by a checksum function. (Watanabe par 63,68,75,77 – teaches generating a validation array by a checksum function.) Regarding claim 6, Pawlowski and Watanabe teach, The computer system of claim 1, Pawlowski and Watanabe further teach, wherein the isolated utility executive is a virtual machine monitor(Pawlowski par 57,61 – teaches how the FT Virtual Machine Monitor (FTVMM) is installed as a hypervisor. Pawlowski’s FTVMM hypervisor is analogous to applicant’s virtual machine monitor. ) which executes in the dedicated memory(Pawlowski par 60,57 – teaches how the FTVMM runs in the Reserved memory region and that this reserved memory region is isolated from ordinary OS/software use. ) to perform the validation array generation procured on the standby node. (Pawlowski par 53 – teaches identical active and standby computers/nodes; Watanabe Par 75,77 – teaches generating checksums at the secondary/standby system. ) Regarding claim 7, Pawlowski and Watanabe teach, The computer system of claim 5, Pawlowski and Watanabe further teach, wherein the isolated utility executive of the active node and of the standby node execute code on all processers of the computer system in parallel(Pawloski par 64 – teaches how the FT driver causes each logical processor to enter the FTVMM and process the request issued by the FT driver. Par 64 also teaches performing the function on all processors. Par 70 – teaches executing the FT driver executing driver code on all processors on the active but failing CPU concurrently(in parallel). ) to generate the active validation array and the standby validation array. (Watanabe par 63,75,77 teaches calculating the checksum of each page.) Regarding claim 13, Pawlowski teaches, A computer system configured to migrate a PC Server,(par 35,44 – teaches a fault-tolerant server architecture that migrates programs when a CPU node begins to fail.) the computer system comprising: a network device; a storage device;( fig 1; par 23-24 teaches- a fault tolerant computer, and a plurality of CPU nodes connected to the IO domains through a mesh fabric to the outside world and storage controllers and disks and additional IO devices.) and at least two compute nodes, wherein one compute node is designated an active node and the other compute node is designated a standby node, (par 9,13 – generally teaches a method of CPU-node failover in a fault-tolerant computer system in which memory and processor state are transferred from an active node to a standby node. Par 53 – teaches two computers/nodes that are assigned either an active/primary role or a standby/secondary role.) each compute node comprising a dedicated memory with an isolated utility executive, (par 54,57 – teaches how each node includes a CPU and memory, including a reserved memory region unavailable to the OS and containing the FT Virtual Machine Monitor (FTVMM). fig 5A:522 “FT Kernel mode driver”; par 60-61 describe the FT Kernel mode driver which “loads or writes the program and data code of the FT Virtual Machine Monitor (FTVMM) code 580, the FTVMM data 584, … and the VMCS-L0 Array 592 into the Reserved Memory Region.”; The reserved memory region corresponds to the claimed dedicated memory and the FTVMM corresponds to the isolated utility executive. par 70-71 – teaches some more details about the FT driver and how it copies memory pages into the corresponding memory pages in the second subsystem.) an operating system memory, the operating system memory including a plurality of files or data structures that are accessed by a driver running within the operating system, (par 44 “The OS bootloader loads the OS image into memory and begins OS execution.”. par 58 – teaches the operating system layer and drivers for the fault tolerant computer system. Par 67,71 – teaches a dirty page bit map and memory range list data structures that the FT driver accesses while operating.) and a firmware reserved memory; (fig 5A:504,508; par 57 “Referring to FIG. 5A, in normal, non-mirrored, operation, the layers in the fault tolerant computer system include …; a server firmware layer 504 including the system Universal Extensible Firmware Interface (UEFI) BIOS 508; and a zero layer reserved memory region 512 … . The zero layer reserved memory 512 is reserved by the BIOS 508 at boot time. Although most of the memory of the fault tolerant computer system is available for use by the Operating System and software, the reserved memory 512 is not.”) and the active node operating system memory further comprises an availability driver, (fig 5A:522,536; par 58-60 – teaches an FT Management Layer which triggers and manages the FT mode driver.) wherein the availability driver of the active node disables or suspends all processes that alter operating system memory (par 70 – teaches how the FT driver executes driver code on all processors on the active but failing CPU concurrently and copies the final set of dirtied pages to the Standby CPU 14C. The FT Driver causes all processors on CPU 14 to disable system interrupt processing on each processor so as to prevent other programs in the Fault tolerant computer system from generating more Dirty Page Bits.) and transfers all operation system memory of the active node to the operating system memory of the standby node; ( par 71 – teaches how “the FT Driver then copies the set of physical memory pages that are identified in the Dirty Page Bit Map into the corresponding physical memory addresses in the Second Subsystem.”. par 64 – teaches that the FT driver copies all of system memory into the second subsystem and “may use a DMA controller or the Switch 430 to perform a high speed memory transfer operation that copies all system memory into the secondary or standby computer.”) the isolated utility executive of the active node executes a code to transfer the memory of the active node to the standby node; (par 70-71,64 – teaches copying all of system memory into the second subsystem. In one embodiment, a high-speed memory transfer is used.) the isolated utility executive of the standby node signals to the availability driver to complete or abort transfer of a network and storage device being used by the active node to the standby node. (par 73 – teaches how the failover operation can be aborted at any time before the active CPU node has been swapped. par 74-75 – teaches how the cpu nodes have a mailbox that show their respective states and trigger any final cleanup for the migration as required, actions like changing the switching fabric to switch to the new active CPU node and resume the operating system and interrupted instructions on the new active CPU node, allowing previously paused devices and transactions to flow again.) However, although Pawloski teaches the isolated utility executive transferring the memory to the standby node, Pawlowski does not specifically teach the isolated utility executive of the active node executes a code to generate an active validation array set of all operating system memory, the active validation array is then transferred to the standby node; the isolated utility executive of the standby node executes a code to generate a standby validation array set of all operating system memory that is verified against the active validation array; On the other hand, Watanabe teaches, the isolated utility executive of the active node executes a code to generate an active validation array set of all operating system memory, (fig 11:1103; par 63 -teaches calculating a checksum of each page. Par 68 – teaches a data check log which collects the checksum of each page. ) the active validation array is then transferred to the standby node; (fig 2:210,211,213; fig 10; par 60,69 – teaches transferring the data check log through the log transmission means to the external log storage area. Fig 18:1806; Par 72 – teaches notifying the checksum calculation means when a data check log is received. Par 79 – teaches that the data check log is transmitted to the secondary site so that the check operation of the backup data can be done.) the isolated utility executive of the standby node executes a code to generate a standby validation array set of all operating system memory(Watanabe fig 14; par 65 – teaches extracting the data for all the pages of a memory area, and notifying the checksum calculation at the end of the extraction process. Fig 2:229; Par 75,77 – teaches calculating a checksum at the backup site in the same way as the at primary site, and that the checksum is calculated for each page. ) that is verified against the active validation array; (Watanabe fig 2:230; par 46 teaches comparing the checksum calculated at the standby site against the checksum included in the data check log that was transferred over. Fig 21; par 77-78 – teaches checking the checksum generated at the secondary site against the checksum received from the primary site.) Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to further modify Pawlowski’s fault-tolerant active/standby memory-transfer system to incorporate the memory checksum generation and transfer technique of Watanabe. One of ordinary skill in the art would have been motivated to incorporate Watanabe’s memory verification technique to verify that memory copied from the active node to the standby node is consistent with the corresponding memory of the active node.(Watanabe par 5 “… in order to confirm that the backup data is normally prepared, it is necessary to verify the consistency of the data of both systems. … When verifying consistency of the data of both systems, a checksum of the data of the primary system and a checksum of the backup data of the secondary system are checked, thereby verifying whether or not the data are consistent.”). Pawlowski already copies all of system memory into the standby node. Applying Watanabe’s known memory checksum verification technique to the memory copied by Pawlowski would have predictably improved the system to determine whether the standby copy was prepared consistently before relying on that copy for failover. Regarding claim 14, Pawlowski and Watanabe teach, The computer system of claim 13, Pawlowski and Watanabe further teach, wherein the isolated utility executive of the active node and of the standby node become completely idle after the availability driver is signaled. (Pawlowski par 62-63 – teaches that after the memory-mirroring/failover operation has been completed, the FTVMM code in the reserved memory is unloaded and no longer executing. ) Regarding claim 16, Pawlowski and Watanabe teach, The computer of claim 1, Pawlowski further teaches, wherein the availability driver is a kernel mode driver of the operating system. (par 58 – teaches how the kernel mode driver is part of the operating system layer. fig 5A:522 “FT Kernel mode driver”; par 60-61 describe the FT Kernel mode driver which “loads or writes the program and data code of the FT Virtual Machine Monitor (FTVMM) code 580, the FTVMM data 584, … and the VMCS-L0 Array 592 into the Reserved Memory Region.”.) Regarding claim 18, Pawlowski and Watanabe teach, The computer system of claim 1, Pawlowski further teaches, wherein bios and boot firmware of the standby node are configured to be identically or substantially identically configured to bios and boot firmware of the active node.(par 53 teaches that the nodes/computers are identical. Par 44 – teaches more details about how the boot process is the same on both computers and boots in the normal way. Par 57 – teaches a server firmware layer including the UEFI BIOS. Par 42 – teaches how the user can configure the system to their needs, or use a default configuration of replicated resources. ) Claim(s) 4,15,17 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 20200050523 A1 (Pawlowski) in view of US 20080208923 A1 (Watanabe) as applied to claims 3,14 above, and further in view of US 11372969 B1 (Sundahl). Regarding claim 4, Pawlowski and Watanabe teach, The computer system of claim 3, Pawlowski further teaches, wherein the compute nodes further comprise stack memory in the dedicated memory, (Pawlowski par 72 – teaches a server management interrupt (SMI) return stack created on the standby CPU node for the registers that need to be restored on the standby CPU node to resume processing from the exact point where the active but failing CPU node left off.) However, Pawlowski and Watanabe do not specifically teach wherein the stack memory can be verified through a data token. On the other hand, Sundahl teaches, wherein the compute nodes further comprise stack memory in the dedicated memory, wherein the stack memory can be verified through a data token. (Sundahl col 5 ln 5-27 – teaches a stack canary which is placed onto the stack that acts as a sentinel that the system can check on by using the stack canary value to verify that it matches a known value. col 11 ln 47-60, col 6 ln 2-6 – teaches a stack verification method;) Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to further modify Pawlowski and Watanabe to incorporate the stack verification method of Sundahl. It would have been obvious to apply Sundahl’s known stack-token verification technique at Watanabe’s page-by-page validation granularity so that the individual stack-memory pages could be checked for corruption. Sundahl provides a way to protect stack memory data from being attacked, modified, or corrupted (Sundahl col 2 ln 43-54) Regarding claim 15, Pawlowski and Watanabe teach, The computer system of claim 14, Pawlowski and Watanabe, further teach, wherein the memory further includes stack memory, (Pawlowski par 72 – teaches a server management interrupt (SMI) return stack created on the standby CPU node for the registers that need to be restored on the standby CPU node to resume processing from the exact point where the active but failing CPU node left off) and wherein each stack memory page is validated (Watanabe par 75,77 – teaches calculating a checksum at the backup site in the same way as the at primary site, and that the checksum is calculated for each page.) However, Pawlowski and Watanabe do not specifically teach using a data token. On the other hand, Sundahl teaches, wherein the memory further includes stack memory, and wherein stack memory is validated using a data token.(Sundahl col 5 ln 5-27 – teaches a stack canary which is placed onto the stack that acts as a sentinel that the system can check on by using the stack canary value to verify that it matches a known value. col 11 ln 47-60, col 6 ln 2-6 – teaches a stack verification method;) Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to further modify Pawlowski and Watanabe to incorporate the stack verification method of Sundahl. It would have been obvious to apply Sundahl’s known stack-token verification technique at Watanabe’s page-by-page validation granularity so that the individual stack-memory pages could be checked for corruption. Sundahl provides a way to protect stack memory data from being attacked, modified, or corrupted (Sundahl col 2 ln 43-54) Regarding claim 17, Pawlowski, Watanabe, and Sundahl teach, The computer system of claim 15, Pawlowski further teaches, wherein the availability driver is a kernel mode driver of the operating system. (par 58 – teaches how the kernel mode driver is part of the operating system layer. fig 5A:522 “FT Kernel mode driver”; par 60-61 describe the FT Kernel mode driver which “loads or writes the program and data code of the FT Virtual Machine Monitor (FTVMM) code 580, the FTVMM data 584, … and the VMCS-L0 Array 592 into the Reserved Memory Region.”.) Claim(s) 8-10,12,19 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 20200050523 A1 (Pawlowski) in view of US 20080208923 A1 (Watanabe) and US 20220156734 A1 (Iwato). Regarding claim 8, Pawlowski teaches, A method for verifying memory transfer in a fault tolerant computer system(par 9,13 – generally teaches a method of CPU-node failover in a fault-tolerant computer system in which memory and processor state are transferred from an active node to a standby node. Par 53 – teaches two computers/nodes that are assigned either an active/primary role or a standby/secondary role.) comprising: providing the fault tolerant system, the fault tolerant system comprising a first compute node comprising a first isolated utility executive and a second compute node comprising a second isolated utility executive, (par 54,57 – teaches how each node includes a CPU and memory, including a reserved memory region unavailable to the OS and containing the FT Virtual Machine Monitor (FTVMM). fig 5A:522 “FT Kernel mode driver”; par 60-61 describe the FT Kernel mode driver which “loads or writes the program and data code of the FT Virtual Machine Monitor (FTVMM) code 580, the FTVMM data 584, … and the VMCS-L0 Array 592 into the Reserved Memory Region.”; The rserved memory region corresponds to the claimed dedicated memory and the FTVMM corresponds to the isolated utility executive. par 70-71 – teaches some more details about the FT driver and how it copies memory pages into the corresponding memory pages in the second subsystem.) the compute nodes having memory;( par 44 “The OS bootloader loads the OS image into memory and begins OS execution.”. fig 5A:504,508; par 57 “Referring to FIG. 5A, in normal, non-mirrored, operation, the layers in the fault tolerant computer system include …; a server firmware layer 504 including the system Universal Extensible Firmware Interface (UEFI) BIOS 508; and a zero layer reserved memory region 512 … . The zero layer reserved memory 512 is reserved by the BIOS 508 at boot time. Although most of the memory of the fault tolerant computer system is available for use by the Operating System and software, the reserved memory 512 is not.”) suspending system execution on the first compute node, using an availability driver, to prevent changes in memory on the first compute node,( par 70 – teaches how the FT driver executes driver code on all processors on the active but failing CPU concurrently and copies the final set of dirtied pages to the Standby CPU 14C. The FT Driver causes all processors on CPU 14 to disable system interrupt processing on each processor so as to prevent other programs in the Fault tolerant computer system from generating more Dirty Page Bits.) wherein the availability driver is a kernel mode driver;( par 54,57 – teaches how each node includes a CPU and memory, including a reserved memory region unavailable to the OS and containing the FT Virtual Machine Monitor (FTVMM). fig 5A:522 “FT Kernel mode driver”; par 60-62 describe the FT Kernel mode driver which “loads or writes the program and data code of the FT Virtual Machine Monitor (FTVMM) code 580, the FTVMM data 584, … and the VMCS-L0 Array 592 into the Reserved Memory Region.”; The reserved memory region corresponds to the claimed dedicated memory and the FTVMM corresponds to the isolated utility executive. par 70-71 – teaches some more details about the FT driver and how it copies memory pages into the corresponding memory pages in the second subsystem.) transferring disk and network access to the second compute node;(par 74 – teaches network interfaces and storage controllers/disks associated with it’s I/O domains and swapping all of the resource mapping between the host ports for the two CPU nodes during failover.) and resuming system execution on the second compute node.(par 75 – teaches using a resume from system management (RSM) instruction to return control to the operating system and resume the interrupted instruction.) However, Pawlowski does not specifically teach generating, using the first isolated utility executive, a first array for every page of memory on the first compute node wherein the full memory bandwidth operates in parallel; generating, using the second isolated utility executive, a second array for every page of memory on the second compute node wherein the full memory bandwidth operates in parallel; verifying consistency between the first arrays on the first compute node and the second arrays on the second compute node. On the other hand, Watanabe teaches, generating, using the first isolated utility executive, a first array for every page of memory on the first compute node(fig 11:1103; par 63 -teaches calculating a checksum of each page. par 65 – teaches extracting the data for all the pages of a memory area, and notifying the checksum calculation at the end of the extraction process. Par 68 – teaches a data check log which collects the checksum of each page.) generating, using the second isolated utility executive, a second array for every page of memory on the second compute node(Par 75,77 – teaches calculating a checksum at the backup site in the same way as the at primary site, and that the checksum is calculated for each page. Par 63,65 – teaches calculating a checksum for each page. Par 68 – teaches a data check log which collects the checksum of each page.) verifying consistency between the first arrays on the first compute node and the second arrays on the second compute node;( Watanabe fig 2:230; par 46 teaches comparing the checksum calculated at the standby site against the checksum included in the data check log that was transferred over. Fig 21; par 77 – teaches checking the checksums generated at the secondary site and received from the primary site against each other.) Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to further modify Pawlowski’s fault-tolerant active/standby memory-transfer system to incorporate the memory checksum generation and transfer technique of Watanabe. One of ordinary skill in the art would have been motivated to incorporate Watanabe’s memory verification technique to verify that memory copied from the active node to the standby node is consistent with the corresponding memory of the active node.(Watanabe par 5 “… in order to confirm that the backup data is normally prepared, it is necessary to verify the consistency of the data of both systems. … When verifying consistency of the data of both systems, a checksum of the data of the primary system and a checksum of the backup data of the secondary system are checked, thereby verifying whether or not the data are consistent.”). Pawlowski already copies all of system memory into the standby node. Applying Watanabe’s known memory checksum verification technique to the memory copied by Pawlowski would have predictably improved the system to determine whether the standby copy was prepared consistently before relying on that copy for failover. However Pawlowski and Watanabe does not specifically teach wherein the full memory bandwidth operates in parallel. On the other hand, Iwato teaches, generating, a first array for every page of memory on the first compute node wherein the full memory bandwidth operates in parallel; (par 34 – teach employing multiple threads in order to shield an access latency of the memory and perform parallel computation that can make full use of the bandwidth of the memory. Par 30 – teaches accessing memory banks simultaneously, so that the bandwidth of the memory is effectively used.) generating, a second array for every page of memory on the second compute node wherein the full memory bandwidth operates in parallel; (par 34 – teach employing multiple threads in order to shield an access latency of the memory and perform parallel computation that can make full use of the bandwidth of the memory. Par 30 – teaches accessing memory banks simultaneously, so that the bandwidth of the memory is effectively used.) Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to further modify Pawlowski and Watanabe to incorporate the memory usage technique of Iwato. One of ordinary skill in the art would have been motivated to apply Iwato's parallel memory-access and parallel hash-computation technique to Watanabe's per-page validation calculations to increase utilization of available memory bandwidth when processing a large quantity of memory-resident data. Iwato provides a way to perform a large number of hash computations from memory banks, thereby making the most of a memory bandwidth effectively (Iwato par 18) Regarding claim 9, Pawlowski, Watanabe, and Iwato teach, The method of claim 8, Watanabe further teaches, wherein the arrays on the first compute node and the arrays on the second compute node are generated by a checksum or hash function. (Watanabe par 63,68,75,77 – teaches generating a validation array by a checksum function.) Regarding claim 10, Pawlowski, Watanabe, and Iwato teach, The method of claim 8, Pawlowski further teaches, further comprising detecting an immediate or impending failure of the first compute node.(par 35 – teaches detecting a failing CPU node, which triggers the transfer of the operating system and the application programs of that node, transferred to the standby CPU node. Par 4,6 – teach detecting an immediate failure(“fails, begins to fail, or is predicted to fail”). ) Regarding claim 12, Pawlowski, Watanabe, and Iwato teach, The method of claim 8 Pawlowski further teaches, further comprising transferring the memory of the first compute node to a second compute node via a virtual machine monitor. (Pawlowski par 57,61 – teaches how the FT Virtual Machine Monitor (FTVMM) is installed as a hypervisor. Pawlowski’s FTVMM hypervisor is analogous to applicant’s virtual machine monitor. Par 64 – Pawlowski teaches a memory-transfer procedure involving the FTVMM, wherein the FT Driver invokes the FTVMM to identify and track applicable memory pages and thereafter copies the identified memory pages to the standby node. Par 67,70 – teaches more details about how the FT driver copies the memory pages and how the FTVMM provides the tracking of the recently modified pages.) Regarding claim 19, Pawlowski, Watanabe, and Iwato teach, The method of claim 9 Pawlowski further teaches, further comprising copying processor state memory from the active node to the standby node, wherein the processor state memory comprises processor specific register states and Local Apic (Local Advanced Programmable Interrupt Controller) states. (par 62 “The remaining dirty pages and the active processor state are then copied to the standby computer memory.”; par 37 “In one embodiment, using a Windows operating system and zero-copy direct memory access (DMA), the switching fabric 30 can transfer the processor state and memory contents from one CPU node 14 to another at about 56 GB/sec.”; par 72 “Once all the memory of the active but failing CPU node 14 has been copied, the active but failing CPU node 14 saves the internal state of its processors (Step 340) (including its registers, local Advanced Programmable Interrupt Controller, High Precision Event Timer, etc.) to a memory location, copies that data to the Standby CPU node, where it is subsequently restored into the corresponding registers of the Standby CPU node 14C.”) Claim(s) 11 is/are rejected under 35 U.S.C. 103 as being unpatentable over 20200050523 A1 (Pawlowski) in view of US 20080208923 A1 (Watanabe) and US 20220156734 A1 (Iwato) as applied to claim 8 above, and further in view of US 11372969 B1 (Sundahl). Regarding claim 11, Pawlowski, Watanabe, and Iwato teach, The method of claim 8, Pawlowski and Watanabe, further teach, wherein the memory further includes stack memory,(Pawlowski par 72 – teaches a server management interrupt (SMI) return stack created on the standby CPU node for the registers that need to be restored on the standby CPU node to resume processing from the exact point where the active but failing CPU node left off) and wherein each stack memory page is validated(Watanabe par 75,77 – teaches calculating a checksum at the backup site in the same way as the at primary site, and that the validation checksum is calculated for each memory page.) However, Pawlowski, Watanabe, and Iwato do not specifically teach using a data token. On the other hand, Sundahl teaches, wherein the memory further includes stack memory, and wherein stack memory is validated using a data token.(Sundahl col 5 ln 5-27 – teaches a stack canary which is placed onto the stack that acts as a sentinel that the system can check on by using the stack canary value to verify that it matches a known value. col 11 ln 47-60, col 6 ln 2-6 – teaches a stack verification method;) Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to further modify Pawlowski, Watanabe, and Iwato to incorporate the stack verification method of Sundahl. It would have been obvious to apply Sundahl’s known stack-token verification technique at Watanabe’s page-by-page validation granularity so that the individual stack-memory pages could be checked for corruption. Sundahl provides a way to protect stack memory data from being attacked, modified, or corrupted (Sundahl col 2 ln 43-54) Claim(s) 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 20200050523 A1 (Pawlowski) in view of US 20080208923 A1 (Watanabe) as applied to claim 1 above, and further in view of US 20170123879 A1 (Donlin). Regarding claim 20, Pawlowski and Watanabe teach, The computer of claim 1, Watanabe further teaches, wherein the standby node further comprises software configured to detect details of memory that fails validation(par 77 – teaches the secondary/standby side performing the validation, validating every page with its own checksum.) However, although Pawlowski and Watanabe teaches validating memory, Pawlowski and Watanabe does not specifically teach characterizes a failure mode that occurred using the detected details of memory. On the other hand, Donlin teaches, software configured to detect details of memory that fails validation and characterizes a failure mode that occurred using the detected details of memory.(par 20 – teaches software for collecting detailed information concerning a detected memory failure and using those details to characterize the failure. Par 23,24 – teaches using those detected memory details to characterize the failure. Par 43 – teaches identifying a specific wire-fail failure mode based on the locations of memory errors) Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to further modify Pawlowski and Watanabe to incorporate the memory failure type analysis of Donlin. One of ordinary skill in the art would have been motivated to improve Watanabe's secondary-side memory validation by not only identifying memory pages that fail validation, but also analyzing details associated with the failed memory to characterize the type of memory failure that occurred. Donlin teaches analyzing memory-error location and history information to distinguish different failure modes, including transient, persistent, and wire-fail conditions, thereby permitting more accurate diagnosis and treatment of detected memory errors. Response to Arguments Applicant’s arguments, see pages 6-9, filed 7/10/2026, with respect to the rejections under 35 U.S.C. 103 as being unpatentable over US 20210342232 A1 (Gopalan) and further in view of US 20200050523 A1 (Pawlowski) have been fully considered and are persuasive. Applicant argues that “neither Gopalan nor Pawlowski, alone or in combination, discloses a validation array as recited in the independent claims” and that “neither reference discloses or suggests generating a validation array of all operating system memory using an isolated utility executive, transferring that array to a standby node, or verifying the integrity of received memory against such an array.” Applicant further argues that “the combination of Gopalan and Pawlowski is improper” because the references operate at different levels of the computing architecture. The prior rejections relying on Gopalan have been withdrawn. However, upon further consideration, new grounds of rejection are made based on US 20200050523 A1 (Pawlowski) in view of US 20080208923 A1 (Watanabe). Watanabe teaches calculating checksums for individual pages at the secondary system and comparing the checksum received from the primary system with the checksum calculated at the secondary system “for each page,” thereby determining whether the corresponding data is consistent or inconsistent. Accordingly, Applicant’s arguments directed specifically to Gopalan and to the combination of Gopalan and Pawlowski are no longer applicable to the present rejections. Applicant’s arguments, see pages 9-10 and 12-13, filed 7/10/2026, regarding Sundahl have been fully considered but are not persuasive. Applicant argues that “Sundahl is non-analogous art: (i) it is not in the same field of endeavor as the claimed invention (software security approach of Sundahl is unrelated to VM migration/fault tolerance of instant application); and (ii) it is not reasonably pertinent to the particular problem solved by the claimed invention (memory region integrity verification during migration is not equivalent to call stack buffer overflow detection).” Examiner respectfully disagrees. The relevant claimed limitation concerns verifying stack memory using a data token. Sundahl teaches a stack canary value located in stack memory and teaches that “the computing system checks the stack canary 230 value as before to verify that it matches the known value.” Thus, Sundahl is reasonably pertinent to the particular problem of detecting corruption of stack memory using a known data value. Further, for claims requiring that each stack memory page be validated, the present rejection does not rely on Sundahl alone to teach the page-by-page aspect. Watanabe teaches performing validation for each memory page, while Sundahl teaches use of the stack canary/data token for stack-memory integrity. Applicant’s arguments, see pages 11-12, filed 7/10/2026, regarding Iwato have been fully considered but are not persuasive. Applicant argues that “Iwato is non-analogous art. The field of cryptocurrency mining ASIC design is not in the same field of endeavor as fault-tolerant VM migration systems, and Iwato’s hardware-circuit-level bank-conflict avoidance mechanism is not reasonably pertinent to the problem of achieving maximum memory throughput during software-defined VM migration.” Examiner respectfully disagrees. Iwato is relied upon for the limited teaching of performing hash computation in parallel so as to make full use of memory bandwidth, not for its cryptocurrency application. Iwato expressly teaches that the hash-computation circuitry “employs multiple threads in order to shield an access latency of the memory and performs parallel computation that can make full use of the bandwidth of the memory.” (Iwato par 34). Iwato further teaches simultaneously accessing different memory banks so that “the bandwidth of the memory is effectively used.” (Iwato par 30). Accordingly, Iwato is reasonably pertinent to the claimed problem of performing parallel memory-intensive computation while making full use of available memory bandwidth. The rejection does not require incorporation of Iwato’s cryptocurrency-mining architecture into Pawlowski; rather, Iwato is relied upon for its known teaching of parallel computation and parallel memory access to utilize available memory bandwidth. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20240176739 A1 - Alden - DMA memory copy from failing active node to standby node. US 20220068421 A1 - Thommana - checks volatile memory when loading containers. Uses a checksum and a digest(cryptographic hash) US 8271700 B1 - Annem - teaches DMA concurrent memory access with modern system buses in par 98. US 20210342232 A1 - Gopalan - handles recovering from failed VM live migrations. US 20110145598 A1 - Smith - array of checksum generated for checking memory Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL XU whose telephone number is (571)272-5688. The examiner can normally be reached Monday-Friday 8:00am - 5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bryce Bonzo can be reached at (571) 272-3655. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MICHAEL XU/Examiner, Art Unit 2113
Read full office action

Prosecution Timeline

Dec 28, 2023
Application Filed
Oct 30, 2025
Non-Final Rejection mailed — §103, §112
Jan 30, 2026
Response Filed
Apr 10, 2026
Non-Final Rejection mailed — §103, §112
Jul 10, 2026
Response Filed
Aug 31, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12711029
MULTI-HOST ENVIRONMENT RESILIENCY
2y 3m to grant Granted Aug 18, 2026
Patent 12711016
Protection Groups for Backing up Cloud-Based Key-Value Stores
1y 11m to grant Granted Aug 18, 2026
Patent 12688099
METHOD AND APPARATUS FOR NODE-PAIR ENCLOSURE REPLACEMENT
2y 3m to grant Granted Jul 21, 2026
Patent 12657097
SYSTEM AND METHOD FOR AVAILABILITY GROUP DATABASE PATCHING
2y 5m to grant Granted Jun 16, 2026
Patent 12572503
APPLICATION LEVEL TO SHARE LEVEL REPLICATION POLICY TRANSITION FOR FILE SERVER DISASTER RECOVERY SYSTEMS
3y 0m to grant Granted Mar 10, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+27.6%)
2y 6m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 132 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month