Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments, filed 04/16/2026 , with respect to the rejection(s) of claims 21-35 have been fully considered. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of US 20200272770 A1 (KOYUNCU et al) and US 20230094125 (ROGERS et al).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 21-35 are rejected under 35 U.S.C. 103 as being unpatentable over US 20200272770 A1 (KOYUNCU et al) in view of US 20230094125 (ROGERS et al).
With respect to claim 21, US 20200272770 A1 (KOYUNCU et al) teach apparatus comprising: processing circuitry (secure processor) to: configure access permissions relating to a secure buffer (the secure processor configured to manage encryption of a transient data buffer)[Par. 0047-0049] to allow one or more user entities to access the secure buffer (the secure processor configured to give the hardware unit access, i.e. configured to validate hardware unit as being authorized producer of the transient data buffe) [Abstract; Par. 0046-0048], wherein the one or more user entities include one or more virtual machines; allocate memory space to the secure buffer (a memory having a portion configured as a transient data buffer) [Abstract; Par. 0036-0038]; and allow secure access to the secure buffer to the one or more user entities in response to successfully verifying the one or more user entities and authorizing the one or more user entities to access the secure buffer (the secure processor being further configured to validate the hardware unit as being an authorized user of the transient data buffer prior to automatically directing to data access associated with the transient buffer) [Par. 0069-0073], wherein the secure buffer is created and assigned to a secure buffer owner to authorize the one or more user entities to access the secure buffer.
KOYUNCU teaches secure processor configured to secure application data being maintained in transient data buffers of an example computing system [Fig. 3; Par. 0049]; but fails to specifically teach the one or more entities being to include one or more virtual machines. However, US 20230094125 (ROGERS et al) teaches parallel processing units (PPUs), such as graphics processing units (GPUs), to execute user code or perform other operations in a virtualized environment, the PPU being encrypted virtual machines executing within the TEE and set up to operate within a Trusted Execution Environment (TEE) implemented at least in part by the operation of one or more central processing units (CPUs) [Abstract; Par. 0056-0059]. Therefore, it would have been obvious to one having at least ordinary skill in the art before the effective filing date of the instant application to combine the secure processor of KOYUNCU with the secure encrypted virtualization of ROGERS in order to allow multiple users to utilize the same physical computing resources, as taught by ROGERS [Par. 0001].
With respect to claim 22, KOYUNCU and ROGERS, combined, teach the apparatus, wherein the secure buffer is securely shared by multiple users, wherein the one or more virtual machines include one or more trusted execution environment (TEE)-based virtual machines (the secure processor to determine that a transient data buffer is typically shared with other one of the hardware units, i.e., the secure processor to determine that a transient data buffer created by an image processing hardware accelerator unit (trusted machine) with a first size or at a first location in memory is shared with a machine-learning hardware accelerator unit and a transient data buffer created by the image processing hardware accelerator unit (trusted machine) with a second size (e.g., different than the first size) or at a second location in memory (e.g., different than the first location) is shared with the camera subsystem (another trusted machine)) [KOYUNCU’s Par. 0047-0048].
With respect to claim 23, KOYUNCU and ROGERS, combined, teach the apparatus, wherein the processing circuitry is further to control the secure buffer, wherein to control includes creating the secure buffer, deleting the secure buffer, and setting and revoking the access permissions to the secure buffer (for each transient data buffer being managed by the secure processor, the secure processor to maintain a set of permissions that indicate any authorized producer from the hardware units and any authorized consumer from the hardware units; the secure processor to execute preprogrammed logic to assign a set of permissions, determine parameters of a transient data buffer to be created (e.g., size, name, offset, address, type, owner), and based on the parameters, update record to indicate which of the hardware units have access to which of the transient data buffers, i.e., infer which of the hardware units is a valid consumer or producer of data with a transient data buffer) [KOYUNCU’s Par. 0045-0047].
With respect to claim 24, KOYUNCU and ROGERS, combined, teach the apparatus, wherein the secure buffer owner and the one or more user entities relate to one or more trusted domains (TDs), wherein the one or more TDs are configured to verify and authorize the one or more user entities (multiples of the hardware units to securely share data within transient data buffers that may be located in a memory that is otherwise accessible to other components of computing system; manager component to assign encryption to the transient data buffer which is shared between the hardware units) [KOYUNCU’s Par. 0054-0057].
With respect to claim 25, KOYUNCU and ROGERS, combined, teach the apparatus, wherein the secure buffer comprises a selected set of host physical address pages allocated from a private guest physical address space relating to the secure buffer owner, and wherein the one or more user entities share a key domain with the secure buffer owner, wherein the processing circuitry is coupled to a memory, the processing circuitry including one or more of application processing circuitry or graphics processing circuitry (secure processor to validate, using the encryption key 316B that is assigned to the transient data buffer, whether each one of the hardware units is an authorized consumer of the transient data buffer prior to automatically directing the data access application within the transient data buffer and secure the data within the transient data buffers to prevent unauthorized access) [KOYUNCU’s Par. 0071-0073].
With respect to independent claims 26 and 31, that repeat the features as recited in claim 21 in other claim format, the rejection by KOYUNCU and ROGERS, combined, is applicable under the same rationale.
With respect to dependent claims 27-30 and 32 to 35, that repeat the features as recited in claims 22 to 25 in other claim format, the rejection by KOYUNCU and ROGERS, combined, is applicable under the same rationale.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US 20220107999 A1 (STEPHENS et al) teaching device including processing circuitry that includes a processor and a memory, where the memory is configured to store a logical container including a plurality of encrypted data portions and a plurality of executable code portions, each encrypted data portion and executable code portion being separately encrypted with a different encryption key and associated with a user, wherein: in response to a first request associated with at least one encrypted data portion and one executable code portion of the logical container, the processing circuitry triggers a verification code portion to determine whether the first request is authorized and performs at least one operation to fulfill the first request in response to determining the request is authorized.
A. Shabtai, Y. Fledel, U. Kanonov, Y. Elovici, S. Dolev and C. Glezer, "Google Android: A Comprehensive Security Assessment," in IEEE Security & Privacy, vol. 8, no. 2, pp. 35-44, March-April 2010.
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to PIERRE MICHEL BATAILLE whose telephone number is (571)272-4178. The examiner can normally be reached Monday - Thursday 7-6 ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, TIM VO can be reached at (571) 272-3642. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/PIERRE MICHEL BATAILLE/Primary Examiner, Art Unit 2138