Prosecution Insights
Last updated: October 01, 2026
Application No. 18/791,934

ENABLING LARGE FRAMES FOR SECURE VIRTUAL MACHINES

Non-Final OA §101§103§112
Filed
Aug 01, 2024
Examiner
LEE, ADAM
Art Unit
2198
Tech Center
2100 — Computer Architecture & Software
Assignee
International Business Machines Corporation
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
587 granted / 698 resolved
+29.1% vs TC avg
Strong +61% interview lift
Without
With
+61.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
42 currently pending
Career history
731
Total Applications
across all art units

Statute-Specific Performance

§101
23.3%
-16.7% vs TC avg
§103
42.3%
+2.3% vs TC avg
§102
15.7%
-24.3% vs TC avg
§112
16.8%
-23.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 698 resolved cases

Office Action

§101 §103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claims 1-25 are pending. Examiner Notes Examiner cites particular paragraphs and/or columns and lines in the references as applied to Applicant’s claims for the convenience of the Applicant. Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested that, in preparing responses, the Applicant fully consider the references in entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior art or disclosed by the examiner. The prompt development of a clear issue requires that the replies of the Applicant meet the objections to and rejections of the claims. Applicant should also specifically point out the support for any amendments made to the disclosure. See MPEP § 2163.06. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Authorization for Internet Communications in a Patent Application Applicant is encouraged to file an Authorization for Internet Communications in a Patent Application form (http://www.uspto.gov/sites/default/files/documents/sb0439.pdf) along with the response to this office action to facilitate and expedite future communication between Applicant and the examiner. If the form is submitted then Applicant is requested to provide a contact email address in the signature block at the conclusion of the official reply. Claim Objections Claim 5 is objected to because in ll. 2 “in trusted” should be “in the trusted”. Appropriate correction is required. Claim 13 is objected to because it is duplicative of claim 7. Appropriate correction is required. As per claim 18, it has similar limitations as claim 5 and is therefore objected to using the same rationale. As per claim 25, it has similar limitations as claim 5 and is therefore objected to using the same rationale. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-25 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (an abstract idea) without significantly more. Step 1: The claim is a process, machine, manufacture, or composition of matter: Claim 1. A computer program product comprising. Step 2A Prong One: The claim recites an abstract idea because it includes limitations that can be considered mental processes (concepts performed in the human mind including an observation, evaluation, judgment, and/or opinion). If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the human mind or via pen and paper, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea: determining that all small pages comprising the large page and the large page meet pre-defined security requirements (abstract idea mental process), wherein the call is to determine a status of a large page of memory for use by a secure guest (abstract idea mental process). Step 2A Prong Two: The abstract idea is not integrated into a practical application because the abstract idea is recited but for generically recited additional computer elements (i.e. data storage, processor, memory, computer readable medium, etc.) which do not add meaningful limitations to the abstract idea amounting to simply implementing the abstract idea on a generic computer using generic computing hardware and/or software (e.g. generally linking the use of the judicial exception to a particular technological environment or field of use (see MPEP 2106.05(h)). Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The generic computing components are recited at a high-level of generality such that they amount to no more than mere instructions to apply the exception using the recited generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea: a set of one or more computer-readable storage media (generic computing components); and program instructions, collectively stored in the set of one or more computer-readable storage media, for causing at least one computing device to perform computer operations including (generic computing components). executing, in a trusted computing environment, a call from a host in an untrusted computing environment, wherein the secure guest is managed by the host in the untrusted computing environment (generic computing components performing extra-solution activity of merely reciting the words "apply it" or an equivalent with the judicial exception, or merely including instructions to implement an abstract idea on a computer, or merely using the computer as a tool to perform the abstract idea), wherein the executing comprises: based on the determining, setting security properties of the large page and the small pages comprising the large page to enable translation for the large page for a given block of memory of the secure guest (generic computing components performing extra-solution activity of modifying/updating data/information); and storing in a computing element, a designation identifying the large page as belonging to the secure guest (generic computing components performing extra-solution activity of saving/storing/recording data/information). Step 2B: The claim includes limitations which can be considered extra-solution activity (see MPEP 2106.05(g)) insufficient to amount to significantly more than the abstract idea because the additional limitations only perform at least one of collecting, gathering, displaying, generating, modifying, updating, storing, retrieving, sending, and receiving data/information data which are well-understood, routine, conventional computer functions as recognized by the court decisions listed in MPEP § 2106.05(d)II. The claim further includes limitations that do not integrate the judicial exception into a practical application because they merely recite the words "apply it" (or an equivalent) with the judicial exception, or merely including instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea, as discussed in MPEP § 2106.05(f). Therefore, the claim, and its limitations when considered separately and in combination, is directed to patent ineligible subject matter: executing, in a trusted computing environment, a call from a host in an untrusted computing environment, wherein the secure guest is managed by the host in the untrusted computing environment (extra-solution activity of merely reciting the words "apply it" or an equivalent with the judicial exception, or merely including instructions to implement an abstract idea on a computer, or merely using the computer as a tool to perform the abstract idea), wherein the executing comprises: based on the determining, setting security properties of the large page and the small pages comprising the large page to enable translation for the large page for a given block of memory of the secure guest (extra-solution activity of modifying/updating data/information); and storing in a computing element, a designation identifying the large page as belonging to the secure guest (extra-solution activity of saving/storing/recording data/information). Claim 2. The computer program product of claim 1, wherein the secure guest comprises a virtual machine (generic computing components). Claim 3. The computer program product of claim 1, wherein the host comprises a hypervisor (generic computing components). Claim 4. The computer program product of claim 1, wherein the computing element is selected from the group consisting of: a bitmap and a table (abstract idea mental process). Claim 5. The computer program product of claim 1, wherein the translation for the large page for the given block of memory of the secure guest is performed by hardware in trusted computing environment (extra-solution activity of merely reciting the words "apply it" or an equivalent with the judicial exception, or merely including instructions to implement an abstract idea on a computer, or merely using the computer as a tool to perform the abstract idea). Claim 6. The computer program product of claim 1, wherein determining that all small pages comprising the large page and the large page meet pre-defined security requirements comprises: for each page of the small pages and the large page: determining that a page index field of a virtual address matches a page index field of a corresponding absolute address (abstract idea mental process); determining that the page is secure (abstract idea mental process); determining that the page has the same guest owner as all other pages of the small pages and the large page (abstract idea mental process); and determining that an absolute address of the page is located within a common large page in absolute memory (abstract idea mental process). Claim 7. The computer program product of claim 1, the computer operations further comprising: receiving a request from the host to back the secure guest with the large page (extra-solution activity of receiving data/information); and providing the host with access to the large page (extra-solution activity of merely reciting the words "apply it" or an equivalent with the judicial exception, or merely including instructions to implement an abstract idea on a computer, or merely using the computer as a tool to perform the abstract idea). Claim 8. The computer program product of claim 1, wherein the executing is performed by a secure interface control in the trusted computing environment (generic computing components). Claim 9. The computer program product of claim 1, the computer operations further comprising: obtaining a request from the host to export a small page of the small pages comprising the large page (extra-solution activity of receiving data/information); and determining that the host has permission to perform the export (abstract idea mental process), wherein based on the export, the security properties are re-set to disallow translation for the large page (extra-solution activity of modifying/updating data/information). Claim 10. The computer program product of claim 1, the computer operations further comprising: obtaining a request from the host to export a small page of the small pages comprising the large page (extra-solution activity of receiving data/information); and based on determining that the host does not have permission to perform the export, generating an error (extra-solution activity of generating data/information). Claim 11. The computer program product of claim 1, the computer operations further comprising: executing, in the trusted computing environment, another call from the host, wherein the executing comprises: re-setting the security properties to disallow translation for the large page (extra-solution activity of modifying/updating data/information). Claim 12. The computer program product of claim 8, wherein the secure interface control comprises elements selected from the group consisting of: millicode and firmware (abstract idea mental process). As per claim 13, it has similar limitations as claim 7 and is therefore rejected using the same rationale. As per claim 14, it has similar limitations as claim 1 and is therefore rejected using the same rationale. As per claim 15, it has similar limitations as claim 2 and is therefore rejected using the same rationale. As per claim 16, it has similar limitations as claim 3 and is therefore rejected using the same rationale. As per claim 17, it has similar limitations as claim 4 and is therefore rejected using the same rationale. As per claim 18, it has similar limitations as claim 5 and is therefore rejected using the same rationale. As per claim 19, it has similar limitations as claim 6 and is therefore rejected using the same rationale. As per claim 20, it has similar limitations as claim 7 and is therefore rejected using the same rationale. As per claim 21, it has similar limitations as claim 1 and is therefore rejected using the same rationale. As per claim 22, it has similar limitations as claim 2 and is therefore rejected using the same rationale. As per claim 23, it has similar limitations as claim 3 and is therefore rejected using the same rationale. As per claim 24, it has similar limitations as claim 4 and is therefore rejected using the same rationale. As per claim 25, it has similar limitations as claim 5 and is therefore rejected using the same rationale. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 1-25 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention. As per claim 1, it is indefinite because it recites “small” pages and “large” pages and it is unclear how to properly interpret “small” and “large” since both terms are subjectively determined. For the purposes of examination, it is interpreted that “small” and “large” can refer to any sized memory page. Furthermore, it is not clear what the relationship is between “a status” recited in ll. 7 and “pre-defined security requirements” recited in ll. 12. For the purposes of examination, it is interpreted that “a status” and “pre-defined security requirements” can be either the same or different from each other. Appropriate correction is required. As per claim 14, it has similar limitations as claim 1 and is therefore rejected using the same rationale. As per claim 21, it has similar limitations as claim 1 and is therefore rejected using the same rationale. As per the remaining dependent claims not specifically mentioned above, they are also rejected using the same rationale as above by virtue of being dependent upon on one of the appropriate independent claims rejected above. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3, 5, 8, 14-16, 18, 21-23, and 25 are rejected under 35 U.S.C. 103 as being unpatentable over Lal et al. (US 20204/0061697) (hereinafter Lal) in view of Musoll et al. (US 2002/0016883) (hereinafter Musoll). As per claim 1, Lal primarily teaches the invention as claimed including a computer program product comprising: a set of one or more computer-readable storage media ([0014]); and program instructions, collectively stored in the set of one or more computer-readable storage media, for causing at least one computing device to perform computer operations including ([0014]): executing, in a trusted computing environment, a call from a host in an untrusted computing environment ([0027] Trusted Domain Resource Manager acts as a host but cannot access a trusted domain’s execution or memory state and [0037] Trusted Domain architecture and Trusted Domain Instruction Set Architecture extensions provide confidentiality and integrity for customer software running in the customer/tenants (i.e., the Trusted Domains) in untrusted cloud service providers), wherein the secure guest is managed by the host in the untrusted computing environment ([0039]-[0040] Trusted Domain Resource Manager may include as part of VMM functionality to manage virtual machines i.e., the Trusted Domains), wherein the executing comprises: determining that all pages meet pre-defined security requirements ([0067] allow access to IO pages that meet certain requirements, and access to the IO pages is allowed if certain criteria are met); based on the determining, setting security properties of the pages to enable translation for the page for a given block of memory of the secure guest ([0056] check if the device is allowed to access Trusted Domain memory and perform the translations using the Trusted table and [0067] if the device uses input/output virtual address or guest physical address, these are translated to host physical address using trusted translation tables); and storing in a computing element, a designation identifying the page as belonging to the secure guest ([0055] each Trusted Domain includes code/data, which may include references to one or more guest virtual addresses. To translate a guest virtual address into a physical address that can be used to access a portion of the computing system's physical memory, a Trusted Domain may use guest page table. Thus, guest virtual address may be translated using guest page table to guest physical address which may then be mapped to a host physical address via extended page tables to access host physical memory). Lal does not explicitly teach: wherein the call is to determine a status of a large page of memory for use by a secure guest; small pages comprising the large page and the large page. However, Musoll teaches: wherein the call is to determine a status of a large page of memory for use by a secure guest (abstract checking allocation state for virtual pages of a smallest size that is equal to or larger than the packet size, then allocation state for next larger virtual pages, and so on, until a de-allocated, available virtual page is found); small pages comprising the large page and the large page (fig. 5 and [0065] memory is 256 KB divided into 4 sub-blocks of 64 KB each. Each 64 KB block is divided into smaller sub-blocks of atomic pages of 256 bytes each, which are used to construct virtual pages). Musoll and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll because it would provide a way to continually select the best mapping scheme that enables data storage with minimum fragmentation. Therefore, the way that the local packet memory hardware controlled is mapped can vary according to need. The exact criteria for determining when to change the mapping scheme may be established using a threshold scheme that automatically triggers a dynamic re-mapping of hardware-controlled memory. Because of this flexibility, fragmentation may be kept to a minimum to greatly simplify computation, requiring minimum circuitry, and providing for a smaller and faster chip implementation. As per claim 2, Lal further teaches wherein the secure guest comprises a virtual machine ([0039]). As per claim 3, Lal further teaches wherein the host comprises a hypervisor ([0019]). As per claim 5, Lal further teaches wherein the translation for the large page for the given block of memory of the secure guest is performed by hardware in trusted computing environment ([0055]). As per claim 8, Lal further teaches wherein the executing is performed by a secure interface control in the trusted computing environment ([0040] programming interface and [0056] Peripheral Component Interconnect Express). As per claim 14, it has similar limitations as claim 1 and is therefore rejected using the same rationale. As per claim 15, it has similar limitations as claim 2 and is therefore rejected using the same rationale. As per claim 16, it has similar limitations as claim 3 and is therefore rejected using the same rationale. As per claim 18, it has similar limitations as claim 5 and is therefore rejected using the same rationale. As per claim 21, it has similar limitations as claim 1 and is therefore rejected using the same rationale. As per claim 22, it has similar limitations as claim 2 and is therefore rejected using the same rationale. As per claim 23, it has similar limitations as claim 3 and is therefore rejected using the same rationale. As per claim 25, it has similar limitations as claim 5 and is therefore rejected using the same rationale. Claims 4, 17, and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Lal in view of Musoll in view of Kumar et al. (US 2024/0241742) (hereinafter Kumar). As per claim 4, Lal in view of Musoll do not explicitly teach wherein the computing element is selected from the group consisting of: a bitmap and a table. However, Kumar teaches wherein the computing element is selected from the group consisting of: a bitmap and a table ([0055]-[0056]). Kumar and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll in view of Kumar because it would provide a way of tracking changes to VM memory, dirtied memory, or memory dirtiness at the sub-page level during a live migration which has the technical advantage of reducing data transferred during the migration. By increasing a granularity of dirtiness tracking and reducing a size of units transferred, less data is required to be transferred and network traffic may be reduced. Reducing network traffic may improve a speed of the live migration and cause some migrations to converge which would not converge without tracking dirtiness at the sub-page level. Additional advantages are gained by refining the granularity at which memory dirtiness is tracked during a live migration. Determining a granularity level for tracking memory dirtiness during a live migration may yield the advantages of sub-page tracking while mitigating the disadvantages of naive implementation of sub-page tracking, such as increased VM exits. By reducing VM exits during live migration, determining the granularity level for tracking memory dirtiness improves the function of a computer by reducing required processing power. By determining the granularity level for tracking memory dirtiness, the same migration can be accomplished using less processing power. Determining the granularity level for tracking memory dirtiness may optimize processor and network usage during the live migration, reducing the time required for the migration and increasing the likelihood of convergence. Furthermore, dynamically adjusting the granularity level during the live migration may further optimize the use of processor and network resources. As per claim 17, it has similar limitations as claim 4 and is therefore rejected using the same rationale. As per claim 24, it has similar limitations as claim 4 and is therefore rejected using the same rationale. Claims 6 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Lal in view of Musoll in view of Hall et al. (US 2010/0125708) (hereinafter Hall) in view of Loafman et al. (US 9,645,628) (hereinafter Loafman) in view of Ault et al. (US 6,289,432) (hereinafter Ault). As per claim 6, Lal further teaches for each page of the small pages and the large page: determining that the page is secure ([0017] secure page table and [0058] protected memory). Lal in view of Mosoll do not explicitly teach: determining that a page index field of a virtual address matches a page index field of a corresponding absolute address; determining that the page has the same guest owner as all other pages of the small pages and the large page; and determining that an absolute address of the page is located within a common large page in absolute memory. However, Hall teaches: determining that a page index field of a virtual address matches a page index field of a corresponding absolute address ([0045] the real address of the page table entry group selects a page table entry group from the page table containing 8 page table entries. One page table entry group is selected if its abbreviated virtual page number field matches the upper bits of the virtual page number field of the virtual address). Hall and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll in view of Hall because it would provide a mechanism for the hypervisor's assignment of primary fast real memory to logical partitions, including enforcement of real memory separation between partitions while allowing authorized sharing of memory. Moreover, it would provide an architecture for the hypervisor real memory map that is used directly by the hardware and that avoids the OS changes and calls to the hypervisor of paravirtualization. The architecture further reduces the size of the hypervisor core function whose correctness determines the security of real memory separation of partitions. Lal in view of Musoll in view of Hall do not explicitly teach: determining that the page has the same guest owner as all other pages of the small pages and the large page; and determining that an absolute address of the page is located within a common large page in absolute memory. However, Loafman teaches: determining that the page has the same guest owner as all other pages of the small pages and the large page (col. 18, ll. 30-34 the first and second guest applications share ownership of the data in the physical page(s) of memory. Both, the first and second guest applications running in different co-resident VM's continue to execute while sharing the data in the physical page(s) of memory). Loafman and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll in view of Hall in view of Loafman because it would provide a way for co-resident guest applications to avoid computationally expensive copying actions at their commonly shared node via a low-overhead inter-process communication method for the VMs for corresponding guest applications to share access to physical memory pages at a node. Instead of copying physical memory page into the virtual memory of either of the guest application, a pointer to the physical memory page is copied to either location within a segment or location within the segment. In this way, the virtual machines can either simultaneously share access or transfer access to the physical memory page for processing by their corresponding guest applications without having to copy the entire physical memory page from the node into each of the virtual memories for their respective guest applications. Lal in view of Musoll in view of Hall in view of Loafman do not explicitly teach: determining that an absolute address of the page is located within a common large page in absolute memory. However, Ault teaches: determining that an absolute address of the page is located within a common large page in absolute memory (col. 8, ll. 1-7 the real address of the shared page table is stored within page table, when the page table for segment is brought into real memory through known paging techniques). Ault and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll in view of Hall in view of Loafman in view of Ault because it would advantageously provide the ability to share large amounts of storage, without the overhead of additional control structures or the exorbitant cost of additional storage. The resulting system could also allow a user to attach to the same shared memory multiple times at different virtual addresses and raise the level of sharing from a page level to a segment level by providing an efficient way of sharing whole segments of data among any number of user address spaces at varying user-specified virtual addresses. It can advantageously allow the frame e.g., a 4-kilobyte block of real storage backing the page table to be shared between a data space and an address space, such that a segment of storage can be shared between the data space and the address space. As per claim 19, it has similar limitations as claim 6 and is therefore rejected using the same rationale. Claims 7, 13, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Lal in view of Musoll in view of Bak et al. (US 2020/0159558) (hereinafter Bak). As per claim 7, Lal in view of Musoll do not explicitly teach the computer operations further comprising: receiving a request from the host to back the secure guest with the large page; and providing the host with access to the large page. However, Bak teaches the computer operations further comprising: receiving a request from the host to back the secure guest with the large page ([0095] the construction of a large page sized region can take advantage of existing utilizations of small pages by processes whose memory is being utilized to back the guest physical memory of virtual machine computing environments); and providing the host with access to the large page ([0043] provide memory access responsive to a memory access request and [0083] increase speed and efficiency of memory access). Bak and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll in view of Bak because it would provide a way to increase the efficiency of memory utilization by virtual machine processes executing on a host computing device, whereby those virtual machine processes can be backed by the host's virtual memory, thereby enabling traditional virtual memory efficiencies to apply to the memory consumed by such virtual machine processes. To increase the speed with which the hierarchical levels of a Second Layer Address Table (SLAT) are traversed as part of a memory access in such an environment where the guest physical memory of the virtual machine environment is backed by virtual memory assigned to one or more processes executing on a host computing device, one or more hierarchical levels of tables within the SLAT can be skipped or otherwise not referenced, thereby resulting in more efficient SLAT traversal and more efficient memory access. While the SLAT can be populated with memory correlations at hierarchically higher-levels of tables, the page table of the host computing device, supporting the host computing device's provision of virtual memory, can maintain a corresponding contiguous set of memory correlations at the hierarchically lowest table level, thereby enabling the host computing device to page out, or otherwise manipulate, smaller chunks of memory. If such manipulation occurs, the SLAT can be repopulated with memory correlations at the hierarchically lowest table level. Conversely, if the host can reassemble a sufficiently large contiguous set of small pages, the SLAT can again be populated with a correlation at hierarchically higher-levels of tables, thereby again resulting in more efficient SLAT traversal and more efficient memory access. In such a manner, more efficient SLAT traversal can be achieved while maintaining the memory utilization efficiency benefits of backing virtual machine processes with a host computing device's virtual memory. As per claim 13, it has similar limitations as claim 7 and is therefore rejected using the same rationale. As per claim 20, it has similar limitations as claim 7 and is therefore rejected using the same rationale. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Lal in view of Musoll in view of Horman et al. (US 2012/036334) (hereinafter Horman) in view of Moriki et al. (US 2017/0277632) (hereinafter Moriki). As per claim 9, Lal in view of Musoll do not explicitly teach obtaining a request from the host to export a small page of the small pages comprising the large page; and determining that the host has permission to perform the export, wherein based on the export, the security properties are re-set to disallow translation for the large page. However, Horman teaches obtaining a request from the host to export a small page of the small pages comprising the large page; and determining that the host has permission to perform the export ([0049] if the request is a write request, the memory management unit generates a page fault because the write request is in conflict with the read only permission and transfers control to the page exception handler). Horman and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll in view of Horman because it would provide a way of improving access to shared memory segments by multiple application processes by utilizing application enable processes from different applications and/or different processes of the same application to transparently migrate data between a shared state and a private state using a copy-on-write mechanism and system function calls to minimize latency experienced by processes from different applications and/or different processes of the same application. Lal in view of Musoll in view of Horman do not explicitly teach wherein based on the export, the security properties are re-set to disallow translation for the large page. However, Moriki teaches wherein based on the export, the security properties are re-set to disallow translation for the large page ([0142] the hypervisor disables address translation by the host page table by changing the setting of the virtual machine control structure). Moriki and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll in view of Horman in view of Moriki because it would provide a way to reduce an overhead caused by two-stage address translation by operating an unmodified guest OS in a virtual computer system that uses an existing CPU. Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Lal in view of Musoll in view of Horman. As per claim 10, Lal in view of Musoll do not explicitly teach obtaining a request from the host to export a small page of the small pages comprising the large page; and based on determining that the host does not have permission to perform the export, generating an error. However, Horman teaches obtaining a request from the host to export a small page of the small pages comprising the large page; and based on determining that the host does not have permission to perform the export, generating an error ([0049] if the request is a write request, the memory management unit generates a page fault because the write request is in conflict with the read only permission and transfers control to the page exception handler). Horman and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll in view of Horman because it would provide a way of improving access to shared memory segments by multiple application processes by utilizing application enable processes from different applications and/or different processes of the same application to transparently migrate data between a shared state and a private state using a copy-on-write mechanism and system function calls to minimize latency experienced by processes from different applications and/or different processes of the same application. Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Lal in view of Musoll in view of Moriki. As per claim 11, Lal in view of Musoll do not explicitly teach executing, in the trusted computing environment, another call from the host, wherein the executing comprises: re-setting the security properties to disallow translation for the large page. However, Moriki teaches executing, in the trusted computing environment, another call from the host, wherein the executing comprises: re-setting the security properties to disallow translation for the large page ([0142] the hypervisor disables address translation by the host page table by changing the setting of the virtual machine control structure). Moriki and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll in view of Moriki because it would provide a way to reduce an overhead caused by two-stage address translation by operating an unmodified guest OS in a virtual computer system that uses an existing CPU. Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Lal in view of Musoll in view of Busaba et al. (US 2023/0061511) (hereinafter Busaba). As per claim 12, Lal in view of Musoll do not explicitly teach wherein the secure interface control comprises elements selected from the group consisting of: millicode and firmware. However, Busaba teaches wherein the secure interface control comprises elements selected from the group consisting of: millicode and firmware ([0038]). Busaba and Lal are both concerned with memory pages in computing environments and are therefore combinable/modifiable. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Lal in view of Musoll in view of Busaba because it would provide a way for based on determining that the select area of memory is inaccessible to the virtual machine, virtual machine execution is exited with a select interception code. This facilitates processing by preventing guest instruction execution if the select area of memory, expected to be accessible, is inaccessible. The select area of memory, expected to be accessible, is once again checked for accessibility to facilitate processing. Processing is facilitated by determining a cause/condition of an exit and performing actions based thereon. Citation of Relevant Prior Art The prior art made of record and not relied upon is considered pertinent to Applicant's disclosure: Tsirkin et al. (US 2020/0073691) disclose secure and efficient memory sharing for guests. Traut et al. (US 2007/0136506) disclose large page optimizations in a virtual machine environment. Shifer (US 2019/0042425) disclose management of coherent links and multi-level memory. Rozas et al. (US 2018/0089468) disclose loading encrypted copies of protected container pages into protected container memory. Raval et al. (US 2018/0232320) disclose controlling access by IO devices to pages in a memory. Oster et al. (US 2020/0081847) disclose a page protection layer. Mather et al. (US 2005/0223321) disclose demotion of memory pages to largest possible sizes. Manthey (US 12,650,871) disclose dynamic page size selection for virtual memory sharing. Kaplan et al. (US 2018/0189190) disclose controlling access to pages in a memory. Kakaiya et al. (US 2022/0398017) disclose independently controlled DMA and CPU access to a shared memory region. Dieffenderfer et al. (US 2006/0149981) disclose TLB suppression for intra-page program counter relative or absolute address branch instructions. Caspi et al. (US 2019/0042671) disclose avoiding asynchronous enclave exits based on requests to invalidate TLB entries. Brannock et al. (US 2019/0042780) disclose hardware enforced protection environment for a system management mode. Baskakov et al. (US 2015/0363326) disclose identification of low-activity large memory pages. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Adam Lee whose telephone number is (571) 270-3369. The examiner can normally be reached on M-TH 8AM-5PM. If attempts to reach the above noted Examiner by telephone are unsuccessful, the Examiner’s supervisor, Pierre Vital, can be reached at the following telephone number: (571) 272-4215. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from Patent Center. Status information for published applications may be obtained from Patent Center. Status information for unpublished applications is available through Patent Center for authorized users only. Should you have questions about access to Patent Center, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/uspto-automated-interview-request-air-form. /Adam Lee/Primary Examiner, Art Unit 2198 July 14, 2026
Read full office action

Prosecution Timeline

Aug 01, 2024
Application Filed
Jul 15, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748635
COST MEASUREMENT AND ANALYTICS FOR OPTIMIZATION ON COMPLEX PROCESSING
3y 1m to grant Granted Sep 29, 2026
Patent 12737218
METHOD AND DEVICE FOR SCHEDULING TASKS IN MULTI-CORE PROCESSOR
3y 4m to grant Granted Sep 15, 2026
Patent 12737212
DYNAMIC PARAMETER REPLACEMENT
2y 10m to grant Granted Sep 15, 2026
Patent 12724624
GENERATING EXECUTABLE TASKS FROM NON-EXECUTABLE TEXT FILES
2y 12m to grant Granted Sep 01, 2026
Patent 12717649
DYNAMICALLY ASSIGNING USER DEVICES TO WORKLOAD CLUSTERS
2y 9m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+61.0%)
3y 0m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 698 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month