DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-3,5-11 and 13-20 are rejected under 35 U.S.C. 102(a)(1)as being anticipated by Caliptra: A Datacenter System on a Chip(SOC) Root of Trust (RoT) (Revision 1.00 Version.5)
Regrading Claim 1 Caliptra discloses: an interface provided on at least one circuit to initiate First Mutable Code (FMC) fetches that are loaded to a Root of Trust (RoT) module [[Page., 33-35], a hardware/firmware interface (the Caliptra IP’s boot-flow logic and mailbox interface) that fetches the “SOC First Mutable Code (FMC)” and loads it. E.g., in Active Profile, “Caliptra copies the SOC First Mutable Code (FMC) into an SOC internal SRAM mailbox buffer and measure the firmware,” and in Passive profile in “SOC ROM buffer,” with Caliptra itself constituting the RoT module (A “Silicon RoT/RTM”)]
and to enforce a boot policy that requires independent acknowledgement and approval of at least a system-on- chip (SoC) manager and the RoT module before allowing a boot process to continue. [Page 33-35, Caliptra’s Passive Profile boot flow expressly requires bidirectional handshake between SoC ROM (an SoC-side manager entity) and the Caliptra RoT before boot proceeds” “SOC ROM signals Caliptra for its ROM to execute” “SOC ROM pauses and waits for a signal (resume) from Caliptra” and “Caliptra signals back to SOC to resume reset.” The specification future states the SoC design and Caliptra RTM jointly gate reset/boot continuation (“Caliptra may signal to SOC ROM and SOC uncore to continue power-on reset”) i.e., a policy requiring mutual acknowledgement/approval of both the SoC-Side entity and the RoT module before the boot process continues.]
Regarding Claim 2 Caliptra discloses: the interface is comprised in a fixed- function hardware state machine or processor of the at least one circuit that is independent of further circuits comprising a plurality of processors associated with one or more of the SoC manager or the RoT module. [[0033] “the first uncore microcontroller taken out of reset with direct access to persistent storage.” A dedicated microcontroller/state machine that is physically and functionally separate from the SoC’s other processor. Page. 45 Caliptra shall run on a dedicated microcontroller, isolated physically from access by other components in the system.]
Regarding Claim 3 Caliptra discloses: comprising a reporting feature to sign measurements associated with an attester's configuration, [Page. 18, Cryptographically measure its code & configuration. sign these measurements with a unique attestation key and Report measurements to a host and/or external entity, which can further verify the authenticity & integrity of the device (a.k.a Attestation)] a storage feature to hold the measurements, [Page 38. FMC alias key, ROM makes CDIFMC] , AliasFMC and its certificate, available to FMC] and an identity feature to issue and endorse identifies identities of an attester in the system. [Page. 37, IDevID is used to endorse LDevID, page. 38 DevId identity is endorsed by IDevID and in turn endorses the FMC Alias key]
Regarding Claim 5 Caliptra discloses: at least a clock to be associated with the interface is determined, in part, from the boot media parameters and using a fuse hardware feature of the system. [Page, 66, Fuse Requirement, page 60, Note that SPI will be operating in basic functional single-IO mode and at 20MHz frequency. (clock)]
Regarding Claim 6 Caliptra discloses: the interface is further to copy at least one FMC, from the FMC fetches performed, to a mailbox of the RoT module, and is to wait for the RoT module to acknowledge the at least one FMC as an attested copy. [Page. 59, SOC will follow the mailbox protocol and push Caliptra FW into the mailbox. Page. 34, Caliptra copies the SOC First Mutable Code (FMC) into an SOC internal SRAM mailbox buffer and measures that firmware]
Regrading Claim 7 Caliptra discloses: allow one or more of the SoC manager or the RoT module to access contents of a mailbox of the RoT module, wherein the contents comprise at least one FMC, and wherein the at least one FMC enables one or more of the SoC manager or the RoT module to enact a respective security policy and to set a handshake that confirms presence of firmware to continue the boot process. [The Caliptra Mailbox architecture is expressly a shared-access structure through which “the SOC” and the RoT exchanges firmware and Command/status data under an arbitrated Sender/Recevier, LOCK-based protocol (Mailbox chapter). The mailbox’s contents include the FMC, and the security state/measurement handshake described throughout the Secure Boot Flow.]
Regarding Claim 8 Caliptra discloses: the interface is further to:allow the SoC manager to copy the firmware to a storage of the SoC manager, wherein the firmware enables the SoC manager to continue the boot process. [Page. 35, SOC reads in its firmware, cryptographically authenticates its FW and provides measurements to Caliptra before executing. This is a copay of firmware to Sic-side storage that enables the Soc to continues to boot process]
Regarding Claim 9 Caliptra discloses: A system comprising: [Fig.1] a system-on-chip (SoC) manager, [SOC FMC, SoC Runtime FW and other SOC FW comments ] a root of trust (RoT) module, [ROT/ RTM] and an interface associated therewith, wherein the interface is to receive boot media parameters of connected and expected devices in the system, to initiate First Mutable Code (FMC) fetches that are loaded to the RoT module, [[Page., 33-35], a hardware/firmware interface (the Caliptra IP’s boot-flow logic and mailbox interface) that fetches the “SOC First Mutable Code (FMC)” and loads it. E.g., in Active Profile, “Caliptra copies the SOC First Mutable Code (FMC) into an SOC internal SRAM mailbox buffer and measure the firmware,” and in Passive profile in “SOC ROM buffer,” with Caliptra itself constituting the RoT module (A “Silicon RoT/RTM”)]
and to enforce a boot policy that requires independent acknowledgement and approval of at least the SoC manager and the RoT module before allowing a boot process to continue. [[0033] “the first uncore microcontroller taken out of reset with direct access to persistent storage.” A dedicated microcontroller/state machine that is physically and functionally separate from the SoC’s other processor. Page. 45 Caliptra shall run on a dedicated microcontroller, isolated physically from access by other components in the system.]
Claim 10 has similar limitations to that of the apparatus of claim 2.Accordingly, claim 10 is rejected under a similar rational as that of claim 2 above.
Claim 11 has similar limitations to that of the apparatus of claim 3.Accordingly, claim 11is rejected under a similar rational as that of claim 3 above.
Claim 13 has similar limitations to that of the apparatus of claim 5.Accordingly, claim 13 is rejected under a similar rational as that of claim 5 above.
Claim 14 has similar limitations to that of the apparatus of claim 6.Accordingly, claim 14 is rejected under a similar rational as that of claim 6 above.
Regarding Claim 15 Caliptra discloses: A system [Fig.1 and Fig.2] comprising: at least one circuit to perform a boot process with at least one interface that receives boot media parameters of connected and expected devices, [[Page., 33-35], a hardware/firmware interface (the Caliptra IP’s boot-flow logic and mailbox interface) that fetches the “SOC First Mutable Code (FMC)” and loads it. E.g., in Active Profile, “Caliptra copies the SOC First Mutable Code (FMC) into an SOC internal SRAM mailbox buffer and measure the firmware,” and in Passive profile in “SOC ROM buffer,” with Caliptra itself constituting the RoT module (A “Silicon RoT/RTM”)]
initiates First Mutable Code (FMC) fetches that are loaded to the RoT module, and that enforces a boot policy that requires independent acknowledgement and approval of at least the SoC manager and the RoT module before allowing the boot process to continue a boot process. [[0033] “the first uncore microcontroller taken out of reset with direct access to persistent storage.” A dedicated microcontroller/state machine that is physically and functionally separate from the SoC’s other processor. Page. 45 Caliptra shall run on a dedicated microcontroller, isolated physically from access by other components in the system.]
Claim 16 has similar limitations to that of the apparatus of claim 7.Accordingly, claim 16 is rejected under a similar rational as that of claim 7 above.
Claim 17 has similar limitations to that of the apparatus of claim 8.Accordingly, claim 17 is rejected under a similar rational as that of claim 8 above.
Regarding Claim 18 Caliptra discloses: A method for a boot process, comprising: receiving, in an interface associated with a system-on-chip (SoC) manager and a root of trust (RoT) module, boot media parameters of connected and expected devices; [[Page., 33-35], a hardware/firmware interface (the Caliptra IP’s boot-flow logic and mailbox interface) that fetches the “SOC First Mutable Code (FMC)” and loads it. E.g., in Active Profile, “Caliptra copies the SOC First Mutable Code (FMC) into an SOC internal SRAM mailbox buffer and measure the firmware,” and in Passive profile in “SOC ROM buffer,” with Caliptra itself constituting the RoT module (A “Silicon RoT/RTM”)] initiating, by the interface, First Mutable Code (FMC) fetches that are loaded to the RoT module; and enforcing, using the interface, a boot policy that requires independent acknowledgement and approval of at least the SoC manager and the RoT module before allowing the boot process to continue. [[0033] “the first uncore microcontroller taken out of reset with direct access to persistent storage.” A dedicated microcontroller/state machine that is physically and functionally separate from the SoC’s other processor. Page. 45 Caliptra shall run on a dedicated microcontroller, isolated physically from access by other components in the system.]
Claim 19 has similar limitations to that of the apparatus of claim 7.Accordingly, claim 19 is rejected under a similar rational as that of claim 7 above.
Claim 20 has similar limitations to that of the apparatus of claim 8.Accordingly, claim 19 is rejected under a similar rational as that of claim 8 above.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 4 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Caliptra: A Datacenter System on a Chip(SOC) Root of Trust (RoT) (Revision 1.00 Version.5) in view of Gupta et al. (Gupta) (Pub No. US 2020/0293662)
Regrading Claim 4 Caliptra teaches boot media parameters are determined based in part on detected ones of connected and expected devices from of the system. [Boot selection based on device’s configuration detected at reset]
Caliptra does not teach from a recovery mode select feature.
However, Gupta teaches: from a recovery mode select feature.[Fig.5, boot select between secure/unsecure modes]
Therefore, it would have been obvious to one of the ordinary skilled in the art to which this invention pertains before the effective filing date of the invention to include the recovery mode selection feature of Gupta in Caliptra’s system.
A person with ordinary skill in the art would have been motivated to combine Gupta and Caliptra to ensure the integrity of the firmware or boot code. [Background]
Claim 12 has similar limitations to that of the apparatus of claim 4.Accordingly, claim 12 is rejected under a similar rational as that of claim 4 above.
Response to Arguments
Applicant’s arguments, see Remarks, filed 05/11/2026, with respect to the rejection(s) of claims 1-20 under USC 103 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Caliptra and Gupta.
Citation of Relevant Prior Art
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
-Prior art Shivanna et al. (Pub NO. US 2018/0096154) teaches: a first controller and a second controller. The first controller is to verify integrity of a first root of trust (ROT), and generate an integrity signal indicating the results. The second controller is to verify integrity of a second ROT, write the firmware image to the first controller, and verify integrity of the written firmware image.
-Prior art Obaidi et al. (Pub No. US 2017/0195122) teaches generation of digital certificates using RoT features on computing devices, which are capable of extending trusts among devices based on a combination of user personas and device identities.
-Prior art Kim et al. (Pub No. US 2015/0186651) teaches: processor core uses the second root key selected by a select bit at the time of booting the system, a root of trust (RoT) which is a basis for secure boot chain verification can be changed to the second root key.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZAHID CHOUDHURY whose telephone number is (571)270-5153. The examiner can normally be reached Monday-Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Andrew J Jung can be reached at 571-270-3779. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ZAHID CHOUDHURY/ Primary Examiner, Art Unit 2175