3DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
CLAIM INTERPRETATION
Claims in this application are not interpreted under 35 U.S.C. §112(f).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-2, 4-6, 9-11, 13-16, 20 and 23 are rejected under 35 U.S.C. 103 as being unpatentable over US Patent Application Publication No. US 2012/0278564 A1 (Goss_1) in view of World Intellectual Property Organization Patent Publication Number WO 2006/062511 A1 (Jensen) in further view of US Patent Application Publication No. US 2021/0150041 A1 (Tang) in further view of US Patent Application Publication US 2018/0158534 A1 (Otterstedt).
Regarding claim 10 and analogous claims 1 and 20:
Goss_1 teaches, an electronic device (SSD (100) [0036]) comprising a memory (flash memory (104) [0036]) and one or more processors communicatively coupled to the memory (controller (102), which is a programmable processor with instructions in local memory (non-transitory computer readable medium) for performing the functions of the controller [0034] [Fig. 1]), the one or more processors configured to: shred data stored in the memory by overprogramming the memory (by teaching that the host can issue commands to sanitize (shred data stored in the memory), which can designate a file or range of LBAs to be sanitized [0056] [Fig. 7]. Sanitization operations can be sequentially applied (i.e., implies that they may be performed more than once), as seen by the return path through decision step (146) [Fig. 6]. The sanitization operations can include a data overwrite sequence step (144) [0055]. The overwriting can include overwriting random values to the memory cells of the locations to be sanitized [0077] [Fig. 14]).
Goss_1 does not explicitly disclose, but Jensen teaches that the processor generates the random value (by teaching that a data pattern used in an erasure (overwrite) operation may be randomly generated [0008], the random number generator may be included in a CPU (processor) [0026]).
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the programmable processor with instructions as taught by Goss_1 to include the random number generator for providing the random data pattern for the erasure/overwrite operation as taught by Jensen because it would have only required the combination of known elements according to known results to reach a predictable result. For example, Goss_1 teaches that the memory controller includes a processor and instructions, and that the memory device may be controlled to generate random values to overwrite pages in memory, but doesn’t teach that the processor may include a random number generator. However, Jensen teaches that a processor may include a random number generate that can be used to generate random patterns that may be used to overwrite data in memory locations. Accordingly, one of ordinary skill in the art could have included the random number generator of the processor of Jensen in the processor of Goss_1 to generate the random values of data that may be written to the pages as taught by Goss_1 using known methods and the results would have been predictable. Furthermore, in combination, each element would continue to perform the same function that they did separately.
Goss_1 does not explicitly disclose, but Tang teaches, overprogramming the memory unit twice, and for the processor to determine the complement of the random value, such that the memory unit may be overwritten with the random value and the complement of the random value (i.e., overprogramming the memory unit at least twice) (by teaching that theoretically, data overwriting with a single overwrite may destroy the previously written data, but there may be some residue, and so overwriting needs to be performed multiple times to ensure security [0005]. Most overwriting vendors use the DoD 5220.22M standard, which involves overwriting random numbers first, then complement numbers of the random numbers, and finally, random numbers again, which should be enough to destroy the data written on the storage device [0005]. This would transform the data written in the memory unit to all 0’s.
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified processor performing the sanitizing operation including overwriting data with a random value as taught by Goss_1 to include overwriting the data with multiple overwrite passes, such as according to the well-known DoD 5220 standard, including writing the random value, then the complement of the random value, and then a random value again as taught by Tang.
One of ordinary skill in the art would have been motivated to make this modification because using overwrite passes is a non-destructive method that can effectively destroy the written data without destroying the storage medium, and can ensure that data is overwritten without leaving a residue that may allow data to be recovered, as taught by Tang in [0005].
Goss_1 in view of Jensen in further view of Tang does not explicitly disclose, but Otterstedt teaches to transform the data stored in the memory unit to a value that is a result of a bitwise AND of the data stored in the memory unit, the random value, and the complement of the random value (by teaching that overwriting data in a memory is applicable to non-volatile memory such as flash memory and EEPROM as well as SSD and other memory devices [0121-0124]. In particular, the data overwriting technique involves writing already existing data D with a pattern P at the same memory location in a process called “overlaid writing”. This writing technique combines the bits of the already existing data with the newly written pattern by a logic bitwise AND operation [0091-0093]. The logic operation need not be performed by a separate logic-gate, but “may be performed implicitly through an additional writing of the memory cells” [0094], such as when a write operation may only switch memory cells in one direction, but not the other (such as from a ‘1’ (erased state) to a ‘0’ (programmed state), but not the other way [0095-0096] [Fig. 5a]. Additionally, it is advantageous to iteratively program the memory location several times using different values of P to gradually and verifiably reduce the amount of information remaining in the stored data [0105], such that the overlaid-writing process may be repeated iteratively with additional patterns [0115]. Such overlaid-writing permits the NVM data to be securely overwritten down to all 0’s [0116-0117]. Overwriting the data in this way allows the result to be checked by reading the value that is stored in the memory after the overprogramming and checking it with the bitwise AND of the value that was stored in the memory (D) with the pattern programmed to the memory (P) [0097]).
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the successive overwriting of data in a memory (D) performed with the random value (R), then the complement of the random value (R̄), and then a random value again as taught by Tang to include performing the overwriting using the secure overlaid-writing technique, which performs an explicit or implicit bitwise AND of the data stored in the memory unit and the data programmed in each sequential overprogramming operation (such as with the random value and the complement of the random value as taught by Tang) as taught by Otterstedt (such that the resulting overlaid-writing would be (D AND R) AND R̄, which equals D AND (R AND R̄), which equals D AND 0, which equals 0 (to transform the data stored in the memory unit to a value that is a result of a bitwise AND of the data stored in the memory unit, the random value, and the complement of the random value).
One of ordinary skill in the art would have been motivated to make this modification because it would allow the system to verify that the intended data were overwritten, the correct location were overwritten, and that the overwriting was successful because the memory system can check if the resulting data stored in the memory cells is the bitwise AND of the pre-existing data (D) and the data pattern to be written to the location (P) as taught by Otterstedt in [0097].
Regarding claim 11 and analogous claim 2:
The electronic device of claim 10 is made obvious by Goss_1 in view of Jensen in further view of Tang in further view of Otterstedt (Goss_1-Jensen-Tang-Otterstedt).
Goss_1 further discloses, wherein the memory is a non-volatile memory (NVM) (by teaching that the memory module (104) is a non-volatile memory [0035]).
Regarding claim 13 and analogous claim 4:
The electronic device of claim 11 is made obvious by Goss_1-Jensen-Tang-Otterstedt.
Goss_1 further discloses, wherein the NVM is a Flash memory (by teaching that the memory module may include flash memory cells [0036]).
Regarding claim 14 and analogous claim 5:
The electronic device of claim 11 is made obvious by Goss_1-Jensen-Tang-Otterstedt.
Goss_1 further discloses wherein the NVM is secured with a scrambling logic (by teaching that the data may be encrypted prior to storage in the memory (104), such as by using an encryption engine (scrambling logic) to scramble received user with an encryption key before storage in the memory (104) [0059] [Fig. 9]).
Regarding claim 15:
The electronic device of claim 10 is made obvious by Goss_1-Jensen-Tang-Otterstedt.
Goss_1 further discloses, wherein the one or more processors are configured to perform the steps of generating the random value (the processor is configured to generate the random value as taught by Jensen and applied in claim 10 above), determining the complement of the random value (the processors are configured to determine the complement of the random value as taught by Tang and applied in claim 10 above), and shredding the data for each of the one or more memory units of the memory (by teaching that the data for sanitization may be specified with a file name or LBA range (i.e., one or more memory units of the memory), which are then sanitized by the memory device (shredding the data for each of the one or more memory units of the memory) [0052] [Fig. 6] [0056] [Fig. 7]).
Regarding claim 16 and analogous claim 6:
The electronic device of claim 10 is made obvious by Goss_1-Jensen-Tang-Otterstedt.
Goss_1 does not explicitly disclose, but Jensen teaches, wherein the random value is generated using a random number generator (through the analysis performed for claim 10).
Regarding claim 9:
The method of claim 1 is made obvious by Goss_1-Jensen-Tang-Otterstedt.
Goss_1 further discloses, wherein shredding the data stored in the memory is performed upon completion of cryptographic operations (by teaching that the purge commands (132) identifies logical addresses of data to be purged (is no longer needed (upon completion of cryptographic operations)), which may store encrypted data for which the encryption key is to be destroyed (142) and to make it no longer useful as encrypted data (upon completion of cryptographic operations). After the encryption key is destroyed, the encrypted data may be overwritten [Fig. 6] [0050] [0052] [0055-0056] [0060] [0073] (analogous to Applicant’s disclosed completion of cryptographic operations, such as when the key is no longer needed as disclosed in Applicant’s specification [0064])).
Regarding claim 23:
The method of claim 1 is made obvious by Goss_1-Jensen-Tang-Otterstedt.
Goss_1-Jensen-Tang-Otterstedt further make obvious wherein the value is zero (through the analysis performed for claim 1).
Claims 3 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Goss_1-Jensen-Tang-Otterstedt as evidenced by US 2006/0253620 A1 (Kang).
Regarding claim 12 and analogous claim 3:
The electronic device of claim 11 is made obvious by Goss_1-Jensen-Tang-Otterstedt.
Goss_1 as evidenced by Kang further discloses, wherein the NVM is an electrically erasable programmable read-only memory (EEPROM) (by teaching that the non-volatile memory may use flash memory cells [Goss_1, 0036], which is a type of EEPROM as evidenced by Kang (“The flash memory is a type of EEPROM (electrically erasable and programmable read-only memory), and is divided into NOR type, which performs input/output operations in byte mode, and NAND type, which performs input/output operations in page mode”) [Kang, 0005]).
Claims 7 is rejected under 35 U.S.C. 103 as being unpatentable over Goss_1-Jensen-Tang-Otterstedt in further view of the Wikipedia page titled, “Bitwise operation” as preserved by the Internet Archive on 28 August 2022 (Bitwise_operation).
Regarding claim 7:
The method of claim 1 is made obvious by Goss_1-Jensen-Tang-Otterstedt.
Goss_1-Jensen-Tang-Otterstedt does not explicitly disclose, but Bitwise_operation teaches wherein determining the complement of the random value comprises performing, by the processor, a NOT operation on the random value (by teaching that a bitwise NOT operation, performs logical negation on each bit, and returns the one’s complement of the given binary value (complement of the random value) [pg. 1, ¶1-2] [pg. 2, §NOT]).
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the complement of the random number generated by the processor as taught by Goss_1 in view of Jensen in further view of Tang to include being generated by a bitwise NOT that inverts each bit of a bit string as taught by Bitwise_operation because it would have only required the combination of known elements according to known methods to yield predictable results. For example, Goss_1 teaches the controller may be a processor with programming for performing the functions and Tang teaches to use the complement of a random number (generated by the processor as taught by Jensen), but does not specifically teach a method for the processor to obtain the complement of the random number. However, Bitwise_operation teaches that a bitwise NOT operation may be used to obtain the invert of all bits of a number (i.e., the complement). Accordingly, it would have been obvious to one of ordinary skill in the art to combine obtaining a complement of a random number with a processor as taught by Goss_1-Jensen-Tang-Otterstedt to include using a bitwise NOT operation to invert each bit of a number as taught by Bitwise_operation because it would have only required the combination of known elements according to known methods to yield predictable results. Furthermore, in combination, each element would continue to the perform the same function that it did separately.
Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Goss_1-Jensen-Tang-Otterstedt in further view of US Patent Application Publication No. US 2012/0278579 A1 (Goss_2).
Regarding claim 8:
The method of claim 1 is made obvious by Goss_1-Jensen-Tang-Otterstedt.
Goss_1 does not explicitly disclose, but Goss_2 teaches wherein shredding the data stored in the memory is performed upon a power failure detection (by teaching that when there is an unauthorized power down as determined by a monitoring circuit keeping track of a power status, a secure erase operation (140) may be triggered [0036-0041]. The triggering event may include the loss of applied power to the device (power failure detection) without the presence of a corresponding “authorization” signal indicating that the power event is benign [Fig. 5] [0044]. The secure erase operation includes overwrite of the data (150) as well as destruction of the keys [Fig. 6] [0047]).
It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the secure erase operation as taught by Goss_1 to include being triggered by a unauthorized power failure as taught by Goss_2.
One of ordinary skill in the art would have been motivated to make this modification because it allows for data to be protected in the event an attacker is able to interrupt communications between the storage device and the host prior to the host being able to successfully transmit a data sanitization command as taught by Goss_2 in [0017-0018].
Response to Arguments/Amendments
As necessitated by the amendments to the claims, a new 35 USC §103 rejection has been made to the claims over Goss_1-Jensen-Tang-Otterstedt with various combinations of Kang, Bitwise_operation and Goss_2.
Applicant’s arguments with respect to the 35 USC §103 rejection of the claims have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Paul Tavern, “RAFFS: Model Checking a Robust Abstract Flash File Store”, 2009, Master’s Thesis for TU Delft, pgs. 1-94 (Tavern) – teaches that a program to a flash page programs the contents of the page buffer into the page corresponding to the index page_number given in the command. The new contents of the Flash page must be the result of a bitwise AND operation on the contents of the page buffer (the data being written) and the current contents of the Flash page [pg. 79, B.6.4].
STMicroelectronics, “ST7LITE1xB”, June 2008, Technical Datasheet for “8-BIT MCU WITH SINGLE VOLTAGE FLASH MEMORY, DATA EEPROM, ADC, 5 TIMERS, SPI”, pgs. 1-159 (STM) – teaches “Care should be taken during the programming cycle. Writing to the same memory location will over-program the memory (logical AND between the two write access data result) because the data latches are only cleared at the end of the programming cycle” [pg. 16].
NVIDIA, “Flash Operations”, 18 September 2019, NVIDIA Firmware Tools (MFT) Documentation, pgs. 1-4 (NVIDIA) – teaches that a write to flash memory that was not previously erased results in a bitwise AND between the data being written and the previously flash contents at the specified address [pg. 2].
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CURTIS JAMES KORTMAN whose telephone number is (303)297-4404. The examiner can normally be reached Monday through Friday 7:30 AM through 4:00 PM MT.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Reginald Bragdon can be reached on (571) 272-4204. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CURTIS JAMES KORTMAN/ Primary Examiner, Art Unit 2139