DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1, 3-9, and 11-22 are pending. Claims 1, 9, and 16 are independent. Claims 1, 3-9, and 11-22 are amended. Claims 2 and 10 are cancelled. Claims 1, 3-9, and 11-22 are rejected.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 8/27/2026 has been entered.
Information Disclosure Statement
The information disclosure statement(s) (IDS) submitted on 12/13/2024, 10/23/2025, and 8/14/2026 is/are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is/are being considered by the examiner.
Third-party submissions under 37 CFR 1.290 were submitted on 3/10/2026 and 3/21/2026. Accordingly, these references are being considered by the examiner.
Response to Arguments
Applicant’s arguments, see page(s) 8, filed 8/27/2026, with respect to the objection(s) to the drawings have been fully considered and are persuasive. The associated objection(s) to the drawings has/have been withdrawn.
Applicant’s arguments, see page(s) 8 and 9, filed 8/27/2026, with respect to the rejection of claim(s) 1, 3-9, and 11-22 under 35 USC 112(a) have been fully considered and are persuasive. The associated rejections to the listed claim(s) have been withdrawn.
Applicant’s arguments, see page(s) 8 and 9, filed 8/27/2026, with respect to the rejection of claim(s) 1, 3-9, and 11-22 under 35 USC 112(b) have been fully considered and are persuasive. The associated rejections to the listed claim(s) have been withdrawn.
Applicant’s arguments, see page(s) 9-12, filed 8/27/2026, with respect to the rejection of claim(s) 1, 3-9, and 11-22 under 35 USC 103 have been fully considered but they are not persuasive. However, due to the change in scope of the claims, a new grounds for rejection is made in view of COLLIER et al (Doc ID US 20170288867 A1) and HAGIWARA et al (Doc ID US 20160026810 A1). This rejection is withdrawn.
Regarding the prior art of AHMAD:
Applicant argues that the checking for a modified value performed by Ahmad does not read on checking for the absence of a value recited by the claims. Examiner respectfully disagrees. In the context of computer memory, there is no distinction in the art between a value in memory which is “missing” and a value which has been modified. In either case, for a computer to programmatically determine the absence or difference in the value, it must read the memory location in which that value is stored, and compare what is read in that location against what is expected to be in that location. Whether the actual stored value is all zeroes or simply different than the expected value is irrelevant. Out of context, if an object is not in its expected place, it would be said to be absent whether there is no object there, or whether there is a different object in its place.
If one were to store in memory the “pre-determined information stored in one or more predetermined volatile storage locations” recited in the claims, and then reboot the device on which the information is stored, the prior art of Ahmad would find that predetermined information to be “absent.”
Examiner notes that additional arguments are directed to the alleged allowability of claims based on their dependency to already-argued claims, and will not be addressed.
Specification
The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification.
Claim Objections
Claim(s) 17 is/are objected to because of the following informalities:
Regarding claim(s) 17:
The amended draft of the claim repeats the first instance of the word “wherein.”
Appropriate correction is required.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3-5, 8, 9, 11, and 16 are rejected under 35 U.S.C. 103 as being unpatentable over COLLIER et al (Doc ID US 20170288867 A1), and further in view of CHOI et al (Doc ID US 20140380484 A1) and HAGIWARA et al (Doc ID US 20160026810 A1).
Regarding claim 1:
COLLIER teaches:
One or more processors, comprising: circuitry to: use an absence of predetermined information stored in one or more predetermined volatile storage locations ([0027] "…the nonce may be stored in volatile memory in the storage device 102 (such as a buffer in the controller 120), such that it is lost in the event of power disruption or power cycle event.") …
CHOI teaches the following limitation(s) not taught by COLLIER:
… use an absence of predetermined information … to detect that … values … in the one or more security devices have been subject to unauthorized modifications ([0037] "... security intelligence system 120 identifies security-related information that is absent or missing, as an indicator of higher risk. … Missing security-related information may indicate inappropriate tampering or other suspicious activity …").
Storing a value is volatile storage with the intent that it be lost during a power cycle is/are known technique(s) in the art, as demonstrated by COLLIER. Further, detecting tampering of a device when expected data is missing is/are known technique(s) in the art, as demonstrated by CHOI. It would have been obvious to a person having ordinary skill in the art (PHOSITA) before the effective filing date of the claimed invention to modify the storage of values in volatile storage of COLLIER with the detection of absent information of CHOI with the motivation to detect a reboot as a form of tampering, where absent information in a volatile memory location indicates a previous loss of power and subsequent rebooting of the device. This is a combination of prior art elements according to known methods which yields predictable results.
HAGIWARA teaches the following limitations not taught by the above combination:
… hash values stored in one or more Platform Configuration Registers (PCRs) ([0048] "The system uses the CRTM … to calculate device information and a hash value of a module to be executed subsequently and record them at a PCR …" and [0049] "… The PCR group 173 is a volatile memory, and so the PCR value once written cannot be deleted until the power supply of the TPM 29 stops.") …
Storing hash values in PCRs is/are well-known technique(s) in the art, as demonstrated by HAGIWARA. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the reboot detection of COLLIER and CHOI with the PCR of HAGIWARA with the motivation to detect potential tampering with PCRs, as they are a form of volatile memory and would be erased upon reboot in a like manner as the predetermined value. This is a combination of prior art elements according to known methods which yields predictable results.
Regarding claim 3:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The one or more processors of claim 1, wherein the predetermined information comprises at least one of a random sequence of bytes, a string, a random number, or a counter (COLLIER [0027] "… The nonce may further comprise an arbitrary number, comprising a random or pseudo random number ...").
Regarding claim 4:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The one or more processors of claim 1, wherein the predetermined information in the one or more predetermined volatile storage locations remains intact until the one or more security devices are rebooted (COLLIER [0027] "…the nonce may be stored in volatile memory in the storage device 102 (such as a buffer in the controller 120), such that it is lost in the event of power disruption or power cycle event.").
Regarding claim 5:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The one or more processors of claim 1, wherein the one or more security devices comprise a trusted platform module (TPM) (HAGIWARA [0049] "… The PCR group 173 is a volatile memory, and so the PCR value once written cannot be deleted until the power supply of the TPM 29 stops.").
Utilizing a TPM as a security device is a known technique in the art, as demonstrated by HAGIWARA. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the tamper detection of COLLIER, CHOI, and HAGIWARA with the TPM of HAGIWARA with the motivation to detect tampering within the common system of a TPM paired with a processor. This is a combination of prior art elements according to known methods which yields predictable results.
Regarding claim 8:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The one or more processors of claim 1, wherein the one or more predetermined volatile storage locations are distinct from the one or more PCRs ([0027] "…the nonce may be stored in volatile memory in the storage device 102 (such as a buffer in the controller 120), such that it is lost in the event of power disruption or power cycle event.").
Examiner notes there is no teaching in COLLIER that would indicate this nonce is stored in a PCR, which are highly regulated registers.
Regarding claim 11:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The method of claim 9, wherein the predetermined information includes a unique identifier (COLLIER [0027] "… The nonce may further comprise … text or code that may only be used for one request from a system to ensure that the nonce cannot be reused in replay attacks.").
Regarding claims 9 and 16:
These claims are rejected with the same justification, mutatis mutandis, as their counterpart claim 1 above.
Claims 6, 14, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over COLLIER et al (Doc ID US 20170288867 A1), CHOI et al (Doc ID US 20140380484 A1), and HAGIWARA et al (Doc ID US 20160026810 A1) as applied to claims 1, 9, and 16 above, and further in view of LEE et al (Doc ID US 9989043 B2).
Regarding claim 6:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The one or more processors of claim 1,
LEE teaches the following limitation(s) not taught by the combination of COLLIER, CHOI, and HAGIWARA:
wherein the circuitry is to cause a duplicate of the predetermined information to be stored (Col 28 lines 19-22 "… the CPU seals the newly created storage area to the hypervisor's identity by copying the contents of the hypervisor_hash register into the secure_storage_owner register.").
Duplicating security information is a known technique in the art, as demonstrated by LEE. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the reboot detection of COLLIER, CHOI, and HAGIWARA with the data duplication of LEE with the motivation to provide a backup or comparative copy of the data. It is obvious to create a duplicate of data which will be used to determine security related matters, so that a comparison can be made to ensure the data has not been tampered with.
Regarding claims 14 and 18:
These claims are rejected with the same justification, mutatis mutandis, as their counterpart claim 6 above.
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over COLLIER et al (Doc ID US 20170288867 A1), CHOI et al (Doc ID US 20140380484 A1), and HAGIWARA et al (Doc ID US 20160026810 A1) as applied to claim 1 above, and further in view of PÅLSSON et al (Doc ID US 20210367787 A1).
Regarding claim 7:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The one or more processors claim 1,
PÅLSSON teaches the following limitation(s) not taught by the above combination:
The one or more processors of claim 1, wherein the circuitry is to cause the predetermined information to be stored in the one or more predetermined volatile storage locations of the one or more security devices via a secure session ([0067] "In step 170, the SC sends the encrypted population information (comprised in the previously received data packet and stored in the SC) and the public part (Kpub) of the temporary asymmetric key to the TPM using the secure session.").
Storing security information in a security device is a known technique in the art, as demonstrated by PÅLSSON. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the reboot detection of COLLIER, CHOI, and HAGIWARA with the security device storage of PÅLSSON with the motivation to keep the data in a secure storage location which is less likely to be manipulated by an attacker.
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over COLLIER et al (Doc ID US 20170288867 A1), CHOI et al (Doc ID US 20140380484 A1), and HAGIWARA et al (Doc ID US 20160026810 A1) as applied to claim 9 above, and further in view of TARSAULIYA et al (Doc ID US 20220201010 A1).
Regarding claim 12:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The method of claim 9,
TARSAULIYA teaches the following limitation(s) not taught by the combination of COLLIER, CHOI, and HAGIWARA:
further comprising: replacing the predetermined information with a different piece of information upon a reboot of the one or more security devices ([0030] "… a parameter may be a unique identifier that may be changed or modified after a factory reset …").
Modifying stored data after a reboot is a known technique in the art, as demonstrated by TARSAULIYA. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the reboot detection of COLLIER, CHOI, and HAGIWARA with the altered data of TARSAULIYA with the motivation to prevent a potential replay attack using previously used data, which could indicate a false result of reboot detection.
Claims 13 and 22 are rejected under 35 U.S.C. 103 as being unpatentable over COLLIER et al (Doc ID US 20170288867 A1), CHOI et al (Doc ID US 20140380484 A1), and HAGIWARA et al (Doc ID US 20160026810 A1) as applied to claims 1 and 9 above, and further in view of HOROVITZ et al (Doc ID US 20150227744 A1).
Regarding claim 13:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The method of claim 9,
HOROVITZ teaches the following limitation(s) not taught by the combination of COLLIER, CHOI, and HAGIWARA:
wherein each of the one or more security devices includes one or more registers that store the hash values to record a state of a computer ([0005] "A TPM contains a set of fixed-size platform configuration registers ("PCRs") that store the resulting values of cryptographic one-way hashes of state information.").
Using PCRs to record a computer’s state is a well-known technique in the art, as demonstrated by HOROVITZ. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the tamper detection of COLLIER, CHOI, and HAGIWARA with the state measurements stored in registers of HOROVITZ with the motivation to use a known system state as a base of comparison when performing a secure boot process. This is a combination of prior art elements according to known methods which yields predictable results.
Regarding claim 22
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The one or more processors of claim 1,
HOROVITZ teaches the following limitation(s) not taught by the combination of COLLIER, CHOI, and HAGIWARA:
wherein the hash values comprise hash values generated by combining a current hash value in a respective PCR with a hash of a software component and rehashing the combined values for storage in the respective PCR ([0007] A sequence of extension operations on a single PCR is useful for representing a series of measurements compactly as a single, fixed-size hash value, computed as a chain of hashes.).
Storing a hash chain in a PCR is a well-known technique in the art, as demonstrated by HOROVITZ. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the tamper detection of COLLIER, CHOI, and HAGIWARA with the state measurements stored in registers of HOROVITZ with the motivation to use the well-known method of use for attesting computer components using PCRs. This is a combination of prior art elements according to known methods which yields predictable results.
Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over COLLIER et al (Doc ID US 20170288867 A1), CHOI et al (Doc ID US 20140380484 A1), and HAGIWARA et al (Doc ID US 20160026810 A1) as applied to claim 9 above, and further in view of ARENO et al (Doc ID US 20190311126 A1).
Regarding claim 15:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The method of claim 9,
ARENO teaches the following limitation(s) not taught by the above combination:
further comprising: storing a public key, which is compared with a public key stored on the one or more security devices to verify that the one or more security devices are intended security devices with which a central processing unit (CPU) communicates via a secure channel ([0043] "… step 320, the host platform 130 may authenticate the security device 110 based upon the received owner public key. ... the host platform 130 may generate a hash value from the received public key and compare the hash value with a hash value stored in the host platform ...").
Authenticating a security device through a comparison of stored keys is a known technique in the art, as demonstrated by ARENO. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the reboot detection of COLLIER, CHOI, and HAGIWARA with the security device authentication of ARENO with the motivation to ensure that the security device being communicated to is authenticated and not being spoofed by an attacker.
Claims 17 and 21 are rejected under 35 U.S.C. 103 as being unpatentable over COLLIER et al (Doc ID US 20170288867 A1), CHOI et al (Doc ID US 20140380484 A1), and HAGIWARA et al (Doc ID US 20160026810 A1) as applied to claims 1 and 16 above, and further in view of PÅLSSON et al (Doc ID US 20210367787 A1) and FORTANIX.COM.
Regarding claim 17:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The system of claim 16,
PÅLSSON teaches the following limitation(s) not taught by the above combination:
wherein wherein the one or more processors are to further store the predetermined information in the one or more predetermined volatile storage locations via a secure session between the one or more processors and the one or more security devices ([0067] "In step 170, the SC sends the encrypted population information (comprised in the previously received data packet and stored in the SC) and the public part (Kpub) of the temporary asymmetric key to the TPM using the secure session.")
Using a secure session to store security information in a security device is a known technique in the art, as demonstrated by PÅLSSON. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the reboot detection of COLLIER, CHOI, and HAGIWARA with the secure session of PÅLSSON with the motivation to use a well-known and established protocol for transferring information to a TPM.
FORTANIX.COM teaches the following limitation(s) not taught by the above combination:
using security keys provisioned to the one or more processors and the one or more security devices at manufacture ("Both problems can be solved by provisioning the TPMs of genuine devices with a device identity key, certified by a Certificate Authority (CA) under the control of the manufacturer.").
Utilizing keys which are provisioned during device manufacture is a known technique in the art, as demonstrated by FORTANIX.COM. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the reboot detection of COLLIER, CHOI, HAGIWARA, and PÅLSSON with the pre-provisioned keys of FORTANIX.COM with the motivation to ensure that the keys used were attested and hardcoded into the device. This is a combination of prior art elements according to known methods which yields predictable results.
Regarding claim 21:
This claim is rejected with the same justification, mutatis mutandis, as its counterpart claim 17 above.
Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over COLLIER et al (Doc ID US 20170288867 A1), CHOI et al (Doc ID US 20140380484 A1), and HAGIWARA et al (Doc ID US 20160026810 A1) as applied to claim 16 above, and further in view of THOM et al (Doc ID US 20120110644 A1).
Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over AHMAD et al (Doc ID US 20110302415 A1) and CHOI et al (Doc ID US 20140380484 A1) as applied to claim 16 above, and further in view of THOM et al (Doc ID US 20120110644 A1).
Regarding claim 19:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The system of claim 16,
THOM teaches the following limitation(s) not taught by the combination of COLLIER, CHOI, and HAGIWARA:
wherein each of the one or more security devices includes PCRs that store hash values to record a state of a computer, wherein the one or more processors have a public key that is used to verify the one or more security devices to extend hash values therein ([0038] "… extend operations … that can extend one or more of the PCRs 155 with measurement values of some or all of the components of the operating system 144 …" and [0042] "… one or more of the TPM-specific keys 151 can be utilized in a manner well known to those skilled in the art to quote the current values of one or more of the PCRs 155. For example, an AIK can be utilized to sign the values of one or more of the PCRs 155.").
Authenticating a security device prior to issuing an extend operation is a known technique in the art, as demonstrated by THOM. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the reboot detection of COLLIER, CHOI, and HAGIWARA with the security device authentication of THOM with the motivation to ensure that the security device being communicated to is authenticated and not being spoofed by an attacker.
Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over COLLIER et al (Doc ID US 20170288867 A1), CHOI et al (Doc ID US 20140380484 A1), and HAGIWARA et al (Doc ID US 20160026810 A1) as applied to claim 16 above, and further in view of LEE et al (Doc ID US 20100281273 A1).
Regarding claim 20:
The combination of COLLIER, CHOI, and HAGIWARA teaches:
The system of claim 16,
LEE teaches the following limitation(s) not taught by the combination of COLLIER, CHOI, and HAGIWARA:
wherein the one or more security devices are rebooted responsive to a command issued through a session by a central processing unit (CPU) ([0012] "The fixed amount of TPM registers ... limits the number of software contexts that can be ... stored in the TPM. Similarly, its simple I/O interface prevents it from handling more than one session at a time (one session is a set of I/O transactions transferring the data and commands necessary to complete a specific security function).").
Limiting a security device to processing a single command per session is a known technique in the art, as demonstrated by LEE. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the reboot detection of COLLIER, CHOI, and HAGIWARA with the single command processing of LEE with the motivation to work within the limits of known devices such as a TPM. It is obvious to limit processing to a single command in a system which has extremely limited memory for processing such commands.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRANDON BINCZAK whose telephone number is (703)756-4528. The examiner can normally be reached M-F 0800-1700.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BRANDON BINCZAK/Examiner, Art Unit 2437