DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendments
This communication is in response to the amendments filed on 13 May 2026:
Claims 1, 7, 13 and 18 are amended.
Claim 20 is canceled.
Claim 21 is added.
Claims 1-19 and 21 are pending.
Response to Arguments
In response to Applicant’s remarks filed on 13 May 2026:
a. Applicant’s arguments regarding the 35 U.S.C. 101 rejection on claim 20 has been fully considered and is deemed fully persuasive in view of the amendments. The 35 U.S.C. 101 rejection on claim 20 has been withdrawn.
b. Applicant’s arguments that none of the cited references teach the amended limitation of “a second privilege level that is at a higher processor privilege level than the first privilege” has been fully considered but is deemed moot in view of the new grounds of rejection presented in this Office Action.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 7, 13 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over PAEK et al. (U.S. PGPub. 2019/0065737), hereinafter Paek, in view of Fisher et al. (U.S. PGPub. 2020/0125282), hereinafter Fisher, in further view of PETER (U.S. PGPub. 2019/0303214), hereinafter Peter.
Regarding claim 1, Paek teaches A kernel protection method (Paek, Paragraph [0126], see “…LMBench for kernel and synthetic benchmark for application when security application operates”), wherein the method comprises:
working in a first privilege (Paek, Figure 2, see “OUTER DOMAIN”, which is being read as working in a first privilege), and detecting a page table modification command (Paek, Paragraph [0084], see “…it instruments the outer domain code to route all page table modification operations to the inner domain”, which is being read as detecting a page table modification command in a first privilege), (Paek, Paragraph [0084], see “…The intra-level domain isolation unit 110 initially configures page tables as read-only to prevent the outer domain from modifying them…it instruments the outer domain code to route all page table modification operations to the inner domain…the inner domain can modify the contents of the page tables through section shadow mapping”), and the target page table is a kernel-related page table (Paek, Paragraph [0063], see “…two TTBR registers, i.e., TTBR0_EL1 and TTBR1_EL1 to simultaneously indicate the user space and the kernel space”, where the target page table is a kernel-related page table (indicated by the kernel space));
switching from the first privilege to a second privilege (Paek, Paragraph [0084], “…The intra-level domain isolation unit 110 initially configures page tables as read-only to prevent the outer domain from modifying them…it instruments the outer domain code to route all page table modification operations to the inner domain…the inner domain can modify the contents of the page tables through section shadow mapping”, where “inner domain” is being read as switching to a second privilege, where the inner domain determines whether to modify the target page table based on the command), wherein a permission of the second privilege is higher than that of the first privilege (Paek, Paragraph [0047], see “…the inner domain becomes more privileged than the outer domain”, where “inner domain” is being read as the second privilege and “outer domain” is being read as the first privilege); and
modifying the access permission data in the target page table if determining to modify the target page table (Paek, Paragraph [0084], see “…The inner domain may checks the constraints and performs those operations for the outer domain…the inner domain can modify the contents of the page tables through section shadow mapping”, which is being read as modifying the access permission data in the target page table if determining to modify the target page table).
Paek does not teach the following limitation(s) as taught by Fisher: wherein the first privilege comprises a kernel privilege (Fisher, Paragraph [0078], see “…Virtualized environments also often have their own kernel which runs at a lower privilege than the primary system kernel, or have limited direct access to the primary system kernel”, which is analogous to the first privilege (lower privilege) comprising a kernel privilege).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Paek, by implementing techniques of the first privilege comprising a kernel privilege, disclosed of Fisher.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for kernel protection, comprising of the first privilege comprising a kernel privilege. This allows for better security management and system efficiency by allowing the first privilege (lower privilege) to have limited access to the primary system kernel, such as read-only privileges in order to determine if the system should switch from the first privilege to the second privilege. Fisher is deemed as analogous art due to the art disclosing techniques of the first privilege comprising a kernel privilege (Fisher, Paragraph [0078]).
Paek as modified by Fisher do not teach the following limitation(s) as taught by Peter: switching from the first privilege to a second privilege that is at a higher processor privilege level than the first privilege (Peter, Paragraph [0056], see “…virtualization systems 22a and 22b are two instances of the same virtualization system…When they are coupled, they may switch between the guest systems concurrently or at the same time…”) (Peter, Paragraph [0064], see “…two processor privilege levels of the processor or core are used…an operating system (guest system) running in a partition and the applications running on the operating system or guest system are running in the same processor privilege level, and the virtualization system is running with a higher processor privilege level”, which is analogous to switching from a guest system (e.g., first privilege) to a virtualization system (second privilege), wherein the virtualization system is at a higher processor privilege than the guest system).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Paek, and techniques disclosed of Fisher, by implementing techniques of the second privilege having a higher processor privilege level than the first privilege, disclosed of Peter.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for kernel protection, comprising of the second privilege having a higher processor privilege level than the first privilege. This allows for better security management by ensuring that modifications are only made in a second privilege level, which ultimately maximizes system stability and security. Peter is deemed as analogous art due to the art disclosing techniques of the second privilege having a higher processor privilege level than the first privilege (Peter, Paragraph [0064]).
Regarding claims 7, 13 and 18, the claims are rejected under the same reasoning as claim 1.
Claims 3-5, 9-11, 15-17 and 21 are rejected under 35 U.S.C. 103 as being unpatentable over Paek, in view of Fisher, in further view of Peter, in further view of KEMISETTI et al. (U.S. PGPub. 2024/0220425), hereinafter Kemisetti.
Regarding claim 3, Paek as modified by Fisher and further modified by Peter do not teach the following limitation(s) as taught by Kemisetti: The method according to claim 1, wherein the method further comprises: creating first physical memory (Kemisetti, FIG. 3, see “SYSTEM MEMORY 308”), a first page table (Kemisetti, Paragraph [0066], see “…generating a first page table”), and a second page table under the first privilege (Kemisetti, Paragraph [0066], see “…generating a second page table”), wherein
the first page table and the second page table are stored in the first physical memory (Kemisetti, FIG. 3, see “NON-SECURE PAGE TABLE 326”, which is being read as the first page table, which is stored in the physical memory (308), and see “SECURE PAGE TABLE 324”, which is being read as the second page table, which is stored in the physical memory (308)), the first page table is a page table used for mapping the first physical memory (Kemisetti, Paragraph [0051], see “…the first page table may map a range of 64-bit virtual memory addresses to physical addresses in the secure memory 320”), and the second page table is a kernel-related page table (Kemisetti, FIG. 3, see “SECURE PAGE TABLE 324”, which is being read as the second page table (kernel-related), since it is stored in the secure memory 320).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Paek, techniques disclosed of Fisher, and techniques disclosed of Peter, by implementing techniques of a first and second page table, wherein the first page table is used for mapping the physical memory and the second page table is kernel-related, disclosed of Kemisetti.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for kernel protection, comprising of a first and second page table, wherein the first page table is used for mapping the physical memory and the second page table is kernel-related. This allows for better security management by providing efficient memory management and isolation with the use of separate page tables. It allows for sparse address spaces, reducing memory overhead, while enabling rapid kernel-user address space separation. Kemisetti is deemed as analogous art due to the art disclosing techniques of a first and second page table, wherein the first page table is used for mapping the physical memory and the second page table is kernel-related (Kemisetti, FIG. 3).
Regarding claim 4, Paek as modified by Fisher and further modified by Peter and Kemisetti teaches The method according to claim 3, wherein an access permission of the first physical memory is read-only under the first privilege (Paek, FIG. 3, see “OUTER DOMAIN VIEW”, which is being read as the first privilege, wherein an access permission is read only for the first physical memory (i.e., where the page tables are stored)).
Regarding claim 5, Paek as modified by Fisher and further modified by Peter and Kemisetti teaches The method according to claim 3, wherein the first page table does not comprise a write permission under the first privilege (Paek, FIG. 3, see “Page Table (PERMISSION: r)”, wherein the first page table does not comprise a write permission under the first privilege (OUTER DOMAIN VIEW)), and the first page table comprises the write permission under the second privilege (Paek, FIG. 3, see “Page Table (PERMISSION: rw)”, wherein the first page table comprises the write permission under the second privilege (INNER DOMAIN VIEW)).
Regarding claims 9, 15 and 21, the claims are rejected under the same reasoning as claim 3.
Regarding claims 10 and 16, the claims are rejected under the same reasoning as claim 4.
Regarding claims 11 and 17, the claims are rejected under the same reasoning as claim 5.
Allowable Subject Matter
Claims 2, 6, 8, 12, 14 and 19 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Additional Art Considered
The prior art made of record and not relied upon is considered pertinent to the Applicants’ disclosure.
The following prior art are cited to further show the state of the art at the time of Applicants’ invention with respect to a method for kernel protection.
a. LUTAS (U.S. PGPub. 2018/0173555) discloses techniques of event filtering for virtual machine security applications, comprising of assigned protection rings with different processor privileges.
Conclusion
Applicant’s amendment necessitated the new ground(s) of rejection presented in this Office Action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to RODMAN ALEXANDER MAHMOUDI whose telephone number is (571)272-8747. The examiner can normally be reached on M-F 11:00am – 7:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached on (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/RODMAN ALEXANDER MAHMOUDI/Examiner, Art Unit 2499