DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 06/15/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Amendment
Claims 1-20 are currently pending. Claims 1, 13 and 17 have been amended.
Response to Arguments
According to the arguments filed on 02/03/2026, Applicant argues (pg. 8), with respect to the rejection of claim 1 under 35 USC § 102, that LORESKAR ‘581 does not teach the amended limitation “deny access requests to the data from other applications of the multiple applications, an operating system, or a virtual machine monitor.” As the basis for this argument, Applicant states that “Loreskar' s secure execution environment operates at a coarser granularity – isolating an entire secure environment from a less secure environment – rather than providing a private memory region that is not accessible by other applications, an operating system, or a virtual machine monitor.” However, the Examiner respectfully disagrees for the following reasons.
Applicant first points out that LORESKAR ‘581 operates at a “coarser granularity.” This appears to be based on Applicant’s position that LORESKAR ‘581 does not permit or deny access to individual memory regions, but rather distinguishes an entire environment as secure or less secure and permits or denies access based on such distinction. In this sense, LORESKAR ‘581 may be viewed as operating at a coarser granularity. However, the issue is whether amended claim 1, conversely, is sufficiently clear in requiring operation at a finer granularity. To the extent that Applicant relies on the recitation of requesting access to a “private memory region in memory” as requiring such finer granularity, the Examiner is not persuaded that this limitation, by itself, requires the asserted finer-grained access control. Rather, this limitation is sufficiently read on LORESKAR ‘581’s cited disclosure ([0065]) of “access requests ... in the less secure execution environment 22 are not permitted to read/write a region of the memory address space that is restricted for access by the secure execution environment 20.”
Thus, Applicant’s argument is not persuasive, and the rejection of claim 1 under 35 USC § 102 is maintained.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-2, 13 and 17 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by LORESKAR et al., US-20200296581-A1 (hereinafter “LORESKAR ‘581”).
Per claim 1 (independent):
LORESKAR ‘581 discloses: A system comprising:
a processor configured to:
request a private memory region in memory for data of a first application of multiple applications; and
cause the data of the first application to be stored in the private memory region without encryption; and
deny access requests to the data from other applications of the multiple applications, an operating system, or a virtual machine monitor
(FIG. 2, [0065], a hardware architecture which provides for a secure execution environment 20 and a less secure (normal) execution environment 22 which coexist on the device (a processor; a computing device 2 of FIG. 1). Software applications (multiple applications) and data may be associated with one of the secure or less secure execution environments, and application code or data (data of a first application) associated with the secure execution environment 20 (request a private memory region in memory) is isolated from access by the code executed within the less secure execution environment 22 ... using a memory management unit which may define a partition of memory address space (in memory) into secure (a private memory region) and less secure regions, and may enforce memory protection so that access requests (for the data) issued by an application (other applications of the multiple applications) executed in the less secure execution environment 22 are not permitted to read/write (deny access requests to the data) a region of the memory address space (since the data of the first application is stored in the private memory region without encryption; Rather, [0065] recites that encryption may be performed for storing data outside of the secure regions) that is restricted for access by the secure execution environment 20).
Per claim 2 (dependent on claim 1):
LORESKAR ‘581 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference.
LORESKAR ‘581 discloses: The system of claim 1, wherein the private memory region of the memory is defined at a page level or as a range of memory addresses (FIG. 2, [0065], using a memory management unit which may define a partition of memory address space into secure (the private memory region) and less secure regions, and may enforce memory protection so that access requests issued by an executed in the less secure execution environment 22 are not permitted to read/write a region of the memory address space (a range of memory addresses) that is restricted for access by the secure execution environment 20).
Per claim 13 (independent):
The limitations of the claim(s) correspond(s) to features of claim 1 and the claim(s) is/are rejected for the reasons detailed with respect to claim 1.
Per claim 17 (independent):
LORESKAR ‘581 discloses: A system comprising:
a host device with one or more processor cores configured to request a private memory region for data of one or more applications of multiple applications; and
a memory device communicatively coupled to the host device, the memory device comprising a memory unit configured to store the data of the one or more applications in a private memory region in an unencrypted format, the host device further configured to deny access requests to the data from other applications of the multiple applications, an operating system, or a virtual machine monitor
(FIG. 2, [0065], a hardware architecture which provides for a secure execution environment 20 and a less secure (normal) execution environment 22 which coexist on the device (a host device; a computing device 2 of FIG. 1). Software applications (multiple applications) and data may be associated with one of the secure or less secure execution environments, and application code or data (data of one or more applications) associated with the secure execution environment 20 (request a private memory region) is isolated from access by the code executed within the less secure execution environment 22 ... using a memory management unit (a memory device; As shown in FIG. 1, the CPU 4 is communicatively connected to both the volatile memory 6 and the non-volatile memory 7 on the computing device 2) which may define a partition of memory address space into secure (a private memory region) and less secure regions, and may enforce memory protection so that access requests (for the data) issued by an application (other applications of the multiple applications) executed in the less secure execution environment 22 are not permitted to read/write (deny access requests to the data) a region of the memory address space (since the data of the one or more applications are stored in the private memory region in an unencrypted format; Rather, [0065] recites that encryption may be performed for storing data outside of the secure regions) that is restricted for access by the secure execution environment 20).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 3 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of Durham et al., US-20240333501-A1 (hereinafter “Durham ‘501”).
Per claim 3 (dependent on claim 1):
LORESKAR ‘581 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference.
LORESKAR ‘581 does not disclose but Durham ‘501 discloses: The system of claim 1, wherein the processor is further configured to request a shared memory region accessible by the first application and a second application of the multiple applications (Fig. 7, [0163], memory accesses by a hardware thread of a multi-hardware threaded process may include accesses to one or more shared memory regions (request a shared memory region) by the hardware thread (the first application) and by one or more other hardware threads of the process (a second application of the multiple applications) ... one or more group selector-to-shared key ID mappings assigned to the hardware thread. The mappings can include group selectors mapped to respective shared key IDs that the hardware thread is authorized to use to obtain cryptographic keys. Data or code can be retrieved from (or stored in) a shared memory area based on a pointer (e.g., 710); [0172], If a determination is made at 736 that the group selector 715 in the encoded portion 712 is specified in one of the HTGRs 720, then at 740, core (e.g., 142A or 142B) and/or the memory controller circuitry (e.g., 148) assigns the shared key ID that is mapped to group selector in the identified HTGR to the memory transaction (in the shared memory region) , that is, when respective group selectors mapped to individual threads are identical to the HTGSs 720, the corresponding shared memory is to be accessed by the threads having the same group selector).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 with the access of shared memory regions based on the mapping of group selector-to-shared key ID to threads as taught by Durham ‘501 because the shared memory region can be efficiently protected and managed by appending the shared key ID retrieved from a group selector register associated with the hardware thread to a physical memory address [0068]. Additionally, Durham ‘501 is analogous to the claimed invention because it teaches memory accesses by a hardware thread of a multi-hardware threaded process may include accesses to one or more shared memory regions [0163].
Claim(s) 4-5 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of Okamoto et al., US-20090125683-A1 (hereinafter “Okamoto ‘683”).
Per claim 4 (dependent on claim 1):
LORESKAR ‘581 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference.
LORESKAR ‘581 does not disclose but Okamoto ‘683 discloses: The system of claim 1, wherein the processor is further configured to cause scrubbing of the data in the private memory region in response to an indication that the private memory region has transitioned to a shared memory region (FIG. 1, [0054], Moreover, it is preferable that memory access control section 3 is configured to store the mode set in mode setting section 1 in nonvolatile memory 6 (the private memory region), make a comparison with previously stored mode, and forcibly erase data stored inside nonvolatile memory 6 (scrubbing of the data in the private memory region), for example, when detecting (in response to an indication that) that a mode change is made from the data protection mode to the normal mode in this Embodiment 1 (the private memory region has transitioned to a shared memory region). Accordingly, the act of a third person for switching the data protection mode to the normal mode and reading content of the nonvolatile memory can be prevented).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 with the forcible erase data stored in a NVM when detecting a mode change is made from the data protection mode to the normal mode as taught by Okamoto ‘683 because the act of a third person for switching the data protection mode to the normal mode and reading content of the nonvolatile memory can be prevented [0054]. Additionally, Okamoto ‘683 is analogous to the claimed invention because it teaches memory access control section 3 controls access to a nonvolatile memory according to a state of mode setting section 1 [0034].
Per claim 5 (dependent on claim 4):
LORESKAR ‘581 in view of Okamoto ‘683 discloses the elements detailed in the rejection of claim 4 above, incorporated herein by reference.
LORESKAR ‘581 does not disclose but Okamoto ‘683 discloses: The system of claim 4, wherein the scrubbing is initiated by a compute unit in or near the memory (FIG. 1, [0054], Moreover, it is preferable that memory access control section 3 (a compute unit) is configured to store the mode set in mode setting section 1 in nonvolatile memory 6 (in or near the memory), make a comparison with previously stored mode, and forcibly erase data stored inside nonvolatile memory 6 (the scrubbing), for example, when detecting that a mode change is made from the data protection mode to the normal mode in this Embodiment 1. Accordingly, the act of a third person for switching the data protection mode to the normal mode and reading content of the nonvolatile memory can be prevented).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 with the forcible erase data stored in a NVM when detecting a mode change is made from the data protection mode to the normal mode as taught by Okamoto ‘683 because the act of a third person for switching the data protection mode to the normal mode and reading content of the nonvolatile memory can be prevented [0054].
Claim(s) 6 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of Okamoto ‘683 and WOOD, US-20210334222-A1 (hereinafter “WOOD ‘222”).
Per claim 6 (dependent on claim 4):
LORESKAR ‘581 in view of Okamoto ‘683 discloses the elements detailed in the rejection of claim 4 above, incorporated herein by reference.
LORESKAR ‘581 in view of Okamoto ‘683 does not disclose but WOOD ‘222 discloses: The system of claim 4, wherein the scrubbing comprises writing zero or one values to each data value in the private memory region (FIG. 14 and 15, [0115], different lifecycle states in which a given memory region (the private memory region) can exist, and FIG. 15 is a state machine showing the commands that trigger transitions between the respective lifecycle states. In a similar way to the realm lifecycle states shown in FIG. 11, the transitions between memory region lifecycle states are managed to ensure that a memory region passing from ownership by one realm to ownership of another realm must first undergo an invalidation process where data in that region is scrubbed (e.g. set to zero), that is, the scrubbing comprises writing zero or one values to each data value).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Okamoto ‘683 with the scrubbing of a memory region by setting to zero in case of an ownership change between different realms as taught by WOOD ‘222 because it would prevent any data associated with the old realm being leaked to other realms through the reuse of the same realm identifier [0108]. Additionally, WOOD ‘222 is analogous to the claimed invention because it teaches memory access circuitry controls access to memory based on ownership information defining, for a given memory region, an owner realm specified from among two or more realms [ABSTRACT].
Claim(s) 7 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of Okamoto ‘683 and Ramrakhyani et al., US-20190251275-A1 (hereinafter “Ramrakhyani ‘275”).
Per claim 7 (dependent on claim 4):
LORESKAR ‘581 in view of Okamoto ‘683 discloses the elements detailed in the rejection of claim 4 above, incorporated herein by reference.
LORESKAR ‘581 in view of Okamoto ‘683 does not disclose but Ramrakhyani ‘275 discloses: The system of claim 4, wherein the scrubbing comprises writing random values to each data value in the private memory region ([0062], the security violation response could include any of the following: ... overwriting (the scrubbing) the target data block with dummy data, random data or any other data (writing random values to each data value) uncorrelated with the previous contents of the target data block to prevent that data being accessed; raising an exception to trigger a software process such as an operating system to take counter measures against the attack; overwriting or clearing (the scrubbing) all the data (not just the target data block; writing random values to each data value) in the protected memory region (in the private memory region) in case it has been compromised).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Okamoto ‘683 with the clearing of the protected memory region by overwriting with random data in case it has been compromised as taught by Ramrakhyani ‘275 because it would protect data from a malicious adversary who has physical access to the system and the ability to observe and/or replay the data or code being exchanged between the microprocessor and the off-chip system memory [0068]. Additionally, Ramrakhyani ‘275 is analogous to the claimed invention because it teaches the system on-chip 4 may include a memory security unit 20 provided for protecting data stored to a protected memory region 22 [0068].
Claim(s) 8 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of Okamoto ‘683 and Lavin, US-20080034173-A1 (hereinafter “Lavin ‘173”).
Per claim 8 (dependent on claim 4):
LORESKAR ‘581 in view of Okamoto ‘683 discloses the elements detailed in the rejection of claim 4 above, incorporated herein by reference.
LORESKAR ‘581 in view of Okamoto ‘683 does not disclose but Lavin ‘173 discloses: The system of claim 4, wherein the processor is further configured to cause scrubbing of the data in the private memory region in response to an indication of a transition of the private memory region from shared memory to private memory (FIG. 1, [0010], a portable memory erasing device 10 that connects directly to a computer "hard disk" memory storage drive 20 (the private memory region) to provide the function of erasing (or "wiping") – scrubbing of the data in the private memory region– data stored on the drive ... to delete sensitive and/or private information without requiring use of a separate computer and/or extra hardware or software, e.g., a state in which a hard disk is not connected to a user device can be interpreted as shared memory ... to ensure that all accessed information is quickly and securely removed from the hard drive ... it allows the hard drive to be reusable (an indication of a transition of the private memory region from shared memory to private memory) after erasing).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Okamoto ‘683 with the function of erasing data stored on a hard disk memory without requiring a separate computer as taught by Lavin ‘173 because it would ensure all accessed information is quickly and securely removed from the hard drive before reuse [0010]. Additionally, Lavin ‘173 is analogous to the claimed invention because it teaches a portable memory erasing device that provides the function of erasing (or "wiping") data stored on a hard disk memory [0010].
Claim(s) 9-10 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of Okamoto ‘683 and Som et al., US-20240411883-A1 (hereinafter “Som ‘883”).
Per claim 9 (dependent on claim 4):
LORESKAR ‘581 in view of Okamoto ‘683 discloses the elements detailed in the rejection of claim 4 above, incorporated herein by reference.
LORESKAR ‘581 in view of Okamoto ‘683 does not disclose but Som ‘883 discloses: The system of claim 4, wherein access requests to the private memory region are prevented until the scrubbing is completed ([0015], The command block indication provides time for the system to determine the likelihood that the potential attack is a real attack. In response to determining that the likelihood of a real attack is high, the system can trigger an erase (e.g., zeroization; the scrubbing) of the nonvolatile memory and activate a lock to prevent further access of the nonvolatile memory ... The memory access blocking feature also prevents access of the data in the nonvolatile memory (access requests to the private memory region are prevented) while a zeroization process is proceeding to erase data in the nonvolatile memory – until the scrubbing is completed).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Okamoto ‘683 with the prevention to access of the data in the nonvolatile memory while a zeroization process is proceeding to erase data in the nonvolatile memory as taught by Som ‘883 because it would prevent an attacker from accessing a part of the data in the nonvolatile memory not yet erased [0010]. Additionally, Som ‘883 is analogous to the claimed invention because it teaches that in response to detecting the potential attack in the system, the security processor issues a command block indication to block processing of commands to access a nonvolatile memory [ABSTRACT].
Per claim 10 (dependent on claim 9):
LORESKAR ‘581 in view of Okamoto ‘683 and Som ‘883 discloses the elements detailed in the rejection of claim 9 above, incorporated herein by reference.
LORESKAR ‘581 in view of Okamoto ‘683 does not disclose but Som ‘883 discloses: The system of claim 9, wherein the access requests are prevented by ordering the access requests to occur after completion of the scrubbing ([0015], The command block indication provides time for the system to determine the likelihood that the potential attack is a real attack. In response to determining that the likelihood of a real attack is high, the system can trigger an erase (e.g., zeroization; the scrubbing) of the nonvolatile memory and activate a lock to prevent further access of the nonvolatile memory ... The memory access blocking feature also prevents access of the data in the nonvolatile memory while a zeroization process is proceeding to erase data in the nonvolatile memory – Moreover, this indicates that once the zeroization process is completed, the access request changes from “a locked state” to “an unlocked state”, enabling the execution of the request. Reference is made to [0042-0043]).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Okamoto ‘683 with the prevention to access of the data in the nonvolatile memory while a zeroization process is proceeding to erase data in the nonvolatile memory as taught by Som ‘883 because it would prevent an attacker from accessing a part of the data in the nonvolatile memory not yet erased [0010].
Claim(s) 11 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of WOOD ‘222.
Per claim 11 (dependent on claim 1):
LORESKAR ‘581 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference.
LORESKAR ‘581 does not disclose but WOOD ‘222 discloses: The system of claim 1, wherein the processor is further configured to establish a trust boundary with a memory system through mutual authentication and attestation (FIG. 6, [0081], realm hierarchies (a trust boundary to be established) ... the root realm 130 ... at exception level EL3 (a trust boundary). The root realm defines two child realms 142 ... at EL2 (a trust boundary) ... great-grandchild realms 146 ... at the least privileged exception level EL0 (a trust boundary) ... A parent realm in the hierarchy can transfer ownership of a memory page (a memory system) that it currently owns to a new child realm (through mutual authentication and attestation) ... A page ownership command may be rejected if the specified page of the memory address space is not already owned by the parent realm which issued the command (through mutual authentication and attestation)).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 with the generation of realm hierarchies including different exception levels with which the transferring of ownership of a memory page is to be determined as taught by WOOD ‘222 because memory access can be performed safely and efficiently by determining the ownership of each memory page based on the corresponding realm, that is, realm hierarchies.
Claim(s) 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of OSUGI, US-20210004495-A1 (hereinafter “OSUGI ‘495”).
Per claim 12 (dependent on claim 1):
LORESKAR ‘581 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference.
LORESKAR ‘581 does not disclose but OSUGI ‘495 discloses: The system of claim 1, wherein the processor is further configured to transfer, on behalf of the first application, the data to the private memory region using link encryption to encrypt the data for transmission over a link between the processor and the private memory region (FIG. 2, [0017], the IC 102 includes a processor complex 202 (the processor) ... a second memory controller 206 that controls read operations from and write operations to the volatile memory 104b (transfer the data to the private memory region) via a bus 207 (which includes a write data path 207a, a read data path 207b, and an address/control path 207c – for transmission over a link between the processor and the private memory region) ... an encryption bus bridge 216 that encrypts data that is being written out to the volatile memory 104b (using link encryption to encrypt the data for transmission); [0010], a method and apparatus for encrypting and decrypting data on an integrated circuit. In various embodiments, the apparatus includes an on-chip high performance bus bridge that transparently encrypts and decrypts data between the embedded microprocessor(s) and off-chip system memory. An embodiment of the apparatus is suited for execution of applications (on behalf of the first application) on secure systems and protecting software from unauthorized copying or alteration.).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 with the encryption/decryption of data between the embedded microprocessor(s) and off-chip system memory via an on-chip high performance bus bridge as taught by OSUGI ‘495 because it would execute applications on secure systems and protecting software from unauthorized copying or alteration [0010]. Additionally, OSUGI ‘495 is analogous to the claimed invention because it teaches a method and apparatus for encrypting and decrypting data on an integrated circuit [0010].
Claim(s) 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of Okamoto ‘683 and Heagney, US-20190377878-A1 (hereinafter “Heagney ‘878”).
Per claim 14 (dependent on claim 13):
LORESKAR ‘581 discloses the elements detailed in the rejection of claim 13 above, incorporated herein by reference.
LORESKAR ‘581 does not disclose but Okamoto ‘683 discloses: The method of claim 13, wherein the method further comprises:
causing, by a memory controller, scrubbing of the private memory region, in response to an indication of a mode change of the memory
(FIG. 1, [0054], Moreover, it is preferable that memory access control section 3 is configured to store the mode set in mode setting section 1 in nonvolatile memory 6 (the private memory region), make a comparison with previously stored mode, and forcibly erase data stored inside nonvolatile memory 6 (scrubbing of the private memory region), for example, when detecting (in response to an indication of a mode change of the memory) that a mode change is made from the data protection mode to the normal mode in this Embodiment 1. Accordingly, the act of a third person for switching the data protection mode to the normal mode and reading content of the nonvolatile memory can be prevented).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 with the forcible erase data stored in a NVM when detecting a mode change is made from the data protection mode to the normal mode as taught by Okamoto ‘683 because the act of a third person for switching the data protection mode to the normal mode and reading content of the nonvolatile memory can be prevented [0054].
LORESKAR ‘581 in view of Okamoto ‘683 does not disclose but Heagney ‘878 discloses: scrubbing of the private memory region in response to an indication of a power cycling of the memory (FIG. 1, [0019], Upon power on, gate array 104 reads the image loaded into secure memory 102a. The secure image has been previously loaded with software configured to a known good state and encrypted ... during the next power cycle (in response to an indication of a power cycling of the memory), contents of operational memory 102b (the private memory region) will be overwritten (scrubbing) with the contents of the secure image from secure memory 102a. Thus, returning the operating system to a known good state. Any malicious software effects are erased).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Okamoto ‘683 with the overwriting of the operational memory by the contents from the secure memory during next power cycle as taught by Heagney ‘878 because it prevents malicious code stored on persistent memory from automatically executing after a power cycle [0020]. Additionally, Heagney ‘878 is analogous to the claimed invention because it teaches the non-volatile memory drive has secure, operational, and persistent memory spaces [ABSTRACT].
Claim(s) 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of Okamoto ‘683 and Heagney ‘878 and WOOD ‘222.
Per claim 15 (dependent on claim 14):
LORESKAR ‘581 in view of Okamoto ‘683 and Heagney ‘878 discloses the elements detailed in the rejection of claim 13 above, incorporated herein by reference.
LORESKAR ‘581 in view of Okamoto ‘683 and Heagney ‘878 does not disclose but WOOD ‘222 discloses: The method of claim 14, wherein the scrubbing comprises writing zero values, one values, or random values to each data value in the private memory region (FIG. 14, [0115], different lifecycle states in which a given memory region (the private memory region) can exist, and FIG. 15 is a state machine showing the commands that trigger transitions between the respective lifecycle states. In a similar way to the realm lifecycle states shown in FIG. 11, the transitions between memory region lifecycle states are managed to ensure that a memory region passing from ownership by one realm to ownership of another realm must first undergo an invalidation process where data in that region is scrubbed (e.g. set to zero), that is, the scrubbing comprises writing zero values to each data value).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Okamoto ‘683 and Heagney ‘878 with the scrubbing of a memory region by setting to zero in case of an ownership change between different realms as taught by WOOD ‘222 because it would prevent any data associated with the old realm being leaked to other realms through the reuse of the same realm identifier [0108].
Claim(s) 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of Okamoto ‘683 and Heagney ‘878 and WOOD ‘222 and Obereiner et al., US-20090249014-A1 (hereinafter “Obereiner ‘014”).
Per claim 16 (dependent on claim 15):
LORESKAR ‘581 in view of Okamoto ‘683 and Heagney ‘878 and WOOD ‘222 discloses the elements detailed in the rejection of claim 15 above, incorporated herein by reference.
LORESKAR ‘581 in view of Okamoto ‘683 and Heagney ‘878 and WOOD ‘222 does not disclose but Obereiner ‘014 discloses: The method of claim 15, wherein the method further comprises:
causing, by the memory, scrubbing of the private memory region in response to a detection of a new attestation and authentication request from the processor
([0008], if a wipe erase of a memory region is initiated, a user can be requested to input an authentication credential a predetermined number of times, and the access management component can receive such authentication information (in response to a detection of a new attestation and authentication request from the processor) ... If each piece of received authentication information respectively matches the stored authentication information, the access management component can determine that access to the memory region in order to perform a wipe erase can be enabled, and the access management component can facilitate performing a wipe erase of the memory region (scrubbing of the private memory region)).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Okamoto ‘683 and Heagney ‘878 and WOOD ‘222 with the wipe erase of the memory region if each piece of received authentication information respectively matches the stored authentication information as taught by Obereiner ‘014 because information, such as sensitive information of a user, can be secured in the memory device, and securely and completely removed from the memory device [0004]. Additionally, Obereiner ‘014 is analogous to the claimed invention because it teaches controlling access to memory regions in a memory component(s) [ABSTRACT].
Claim(s) 18 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over LORESKAR ‘581 in view of Okamoto ‘683 and Kramer et al., US-20230289085-A1 (hereinafter “Kramer ‘085”).
Per claim 18 (dependent on claim 17):
LORESKAR ‘581 discloses the elements detailed in the rejection of claim 17 above, incorporated herein by reference.
LORESKAR ‘581 discloses: the private memory region is in the memory device (FIG. 1 and 2, [0065], a hardware architecture which provides for a secure execution environment 20 and a less secure (normal) execution environment 22 which coexist on the device ... using a memory management unit which may define a partition of memory address space (in the memory device, i.e., a computing device 2 of FIG. 1) into secure (the private memory region) and less secure regions).
LORESKAR ‘581 does not disclose but Okamoto ‘683 discloses: the memory device further comprises a compute unit in or near the memory unit that is configured to cause scrubbing of the data in the private memory region in response to an indication that the private memory region has transitioned to a shared memory region (FIG. 1, [0054], Moreover, it is preferable that memory access control section 3 (a compute unit) is configured to store the mode set in mode setting section 1 in nonvolatile memory 6 (the private memory region; in or near the memory unit), make a comparison with previously stored mode, and forcibly erase data stored inside nonvolatile memory 6 (scrubbing of the data in the private memory region), for example, when detecting (in response to an indication that) that a mode change is made from the data protection mode to the normal mode in this Embodiment 1 (the private memory region has transitioned to a shared memory region). Accordingly, the act of a third person for switching the data protection mode to the normal mode and reading content of the nonvolatile memory can be prevented).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 with the forcible erase data stored in a NVM when detecting a mode change is made from the data protection mode to the normal mode as taught by Okamoto ‘683 because the act of a third person for switching the data protection mode to the normal mode and reading content of the nonvolatile memory can be prevented [0054].
LORESKAR ‘581 in view of Okamoto ‘683 does not disclose but Kramer ‘085 discloses: the memory region is distributed across multiple memory units (FIG. 2, [0020], In the exemplary system 50 in FIG. 2, three processing cores 20, 21 and 22 are connected via a memory protection unit 30 to three exemplary memories 10, 11 and 12 – multiple memory units).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Okamoto ‘683 with the memory protection system comprising multiple processing cores and memories as taught by Kramer ‘085 because memory optimization would be performed reliably during parallel execution of multiple tasks in a muti-core system [0002]. Additionally, Kramer ‘085 is analogous to the claimed invention because it teaches a method for optimizing the memory of a partitioned system which includes multiple memories, at least one processing core [0003].
Per claim 20 (dependent on claim 18):
LORESKAR ‘581 in view of Okamoto ‘683 and Kramer ‘085 discloses the elements detailed in the rejection of claim 17 above, incorporated herein by reference.
LORESKAR ‘581 in view of Kramer ‘085 does not disclose but Okamoto ‘683 discloses: The system of claim 18, wherein the scrubbing is performed in the memory unit for a memory associated with the private memory region (FIG. 1, [0054], Moreover, it is preferable that memory access control section 3 is configured to store the mode set in mode setting section 1 in nonvolatile memory 6 (the private memory region), make a comparison with previously stored mode, and forcibly erase data stored inside nonvolatile memory 6 (the scrubbing is performed in the memory unit), for example, when detecting that a mode change is made from the data protection mode to the normal mode in this Embodiment 1. Accordingly, the act of a third person for switching the data protection mode to the normal mode and reading content of the nonvolatile memory can be prevented).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Kramer ‘085 with the forcible erase data stored in a NVM when detecting a mode change is made from the data protection mode to the normal mode as taught by Okamoto ‘683 because the act of a third person for switching the data protection mode to the normal mode and reading content of the nonvolatile memory can be prevented [0054].
LORESKAR ‘581 in view of Okamoto ‘683 does not disclose but Kramer ‘085 discloses: the multiple memory units for a range of memory addresses associated with the memory region. (FIG. 2, [0020], In the exemplary system 50 in FIG. 2, three processing cores 20, 21 and 22 are connected via a memory protection unit 30 to three exemplary memories 10, 11 and 12 – the multiple memory units; [0023], The method furthermore includes allocating 130 the multiple registers of the at least one memory protection unit 30 for the certain placement of the data in the multiple memories 10, one register of the multiple registers identifying a memory area of the multiple memories 10 (by using a range of memory addresses associated with the memory region). The identification of a memory area by a register of the multiple registers may take place with the aid of the boundaries of the memory area (for example with the aid of a start address and a target address – the range of memory addresses).
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified LORESKAR ‘581 in view of Okamoto ‘683 with the memory protection system comprising multiple processing cores and memories based on accessing a range of memory in the memories with the aid of a start address and a target address as taught by Kramer ‘085 because memory optimization would be performed reliably during parallel execution of multiple tasks in a muti-core system [0002].
Allowable Subject Matter
Claim(s) 19 is/are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
The following is a statement of reasons for the indication of allowable subject matter:
Regarding claim 19, the prior art of record (LORESKAR ‘581 in view of Okamoto ‘683) does not disclose: “the scrubbing is performed in the multiple memory units in parallel and in response to a single command from one or more processor cores” in the recited context.
In particular, Okamoto ‘683 teaches that the portable auxiliary storage device includes a memory access control section that controls access to data stored in a nonvolatile memory based on a selected operation mode. In a data protection mode, a timer monitors an elapsed time associated with permitted memory access. When a predetermined time limit is reached, access to the stored data is prohibited, thereby protecting the data from unauthorized access. The disclosed protection scheme may further forcibly erase (the scrubbing) the stored data under a prescribed security condition to prevent subsequent recovery or unauthorized use. This reference merely teaches forcibly erasing data, i.e., scrubbing; however, it is silent as to performing such scrubbing in parallel across multiple memories using a plurality of cores.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Tsirkin, US-20240069950-A1 – discloses a virtual machine having private memory that is protected from access by a host or hypervisor. Data stored in the private memory may be protected using encryption, thereby preventing unauthorized access to sensitive VM data. Selected memory pages may be securely shared while maintaining the integrity of data maintained in the VM’s private memory.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SANGSEOK PARK whose telephone number is (571)272-4332. The examiner can normally be reached Monday-Friday 7:30-5:30 and Alternate Fridays 9:00 am-5:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, PHILIP CHEA can be reached at (571)272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SANGSEOK PARK/Primary Examiner, Art Unit 2499