Prosecution Insights
Last updated: August 17, 2026
Application No. 18/822,835

MEMORY SYSTEM GENERATING ERASE CERTIFICATE

Final Rejection §102
Filed
Sep 03, 2024
Priority
Sep 06, 2022 — continuation of PCTJP2022033420
Examiner
GILLESPIE, KAMRYN JORDAN
Art Unit
2408
Tech Center
2400 — Computer Networks
Assignee
KIOXIA Corporation
OA Round
2 (Final)
73%
Grant Probability
Favorable
3-4
OA Rounds
8m
Est. Remaining
96%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
22 granted / 30 resolved
+15.3% vs TC avg
Strong +23% interview lift
Without
With
+23.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
6 currently pending
Career history
41
Total Applications
across all art units

Statute-Specific Performance

§101
8.1%
-31.9% vs TC avg
§103
53.2%
+13.2% vs TC avg
§102
21.6%
-18.4% vs TC avg
§112
15.3%
-24.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 30 resolved cases

Office Action

§102
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Allowable Subject Matter Claims 1-10 are allowed. None of the prior art alone, or reasonably combined appear to teach “generate an erase certificate that includes the first information and the second information, wherein the first information is related to the number of program/erase cycles for at least one of the plurality of first storage areas before the data erase operation is executed, and the second information is related to the number of program/erase cycles for the at least one of the plurality of first storage areas after the data erase operation is executed.” Response to Arguments Applicant’s arguments filed 04/23/2026 have been fully considered, but are considered moot in view of the following new ground of rejection. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 11-20 is/are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Kelly (US 20260030390 A1), hereafter Kelly. For claims 11-20, Kelly demonstrates the following: 11. (Currently Amended) A memory system comprising: a nonvolatile memory that includes a plurality of first storage areas each configured to store user data (KELLY [0009] “FIG. 1 illustrates an example system that implements attestable secure erasure operations on a storage drive.”, [0079] “he processing device 600 may also include one or more storage drives 620 (e.g., non-volatile storage)”, [0017] “The system 100 includes a cloud storage service 102 that provides a cloud-based data storage service to users. The cloud storage service 102 receives user data from various end users and stores the user data on various storage drives that are owned and operated by the cloud storage service 102.”); and a controller configured to: in response to a command from a host(KELLY [0018] “In various circumstances, the storage drive 104 may be provided with a request to erase the user data 108.”), execute a data erase operation on each of the plurality of first storage areas(KELLY [0038] “The erase instructions 224 instruct the storage drive 204 to perform one or more erase operations and to collect and record measurements in association with each requested erase operation. In response to receiving the erase instructions 224, the requested erase operation(s) are executed”); in response to completion of the data erase operation, acquire information related to at least the number of program/erase cycles for at least one of the plurality of first storage areas after the data erase operation is executed (KELLY [0038] “The erase instructions 224 instruct the storage drive 204 to perform one or more erase operations and to collect and record measurements in association with each requested erase operation. In response to receiving the erase instructions 224, the requested erase operation(s) are executed, and the RoT 206 takes measurements following each erase operation.”, [0060] “The block erase claim 318 includes a second set of encrypted measurements (second PCR values) recorded following the block-erase operation along with metadata, including a persistent monotonic counter of erase cycles…”); and generate an erase certificate that includes at least the information(KELLY [0006] “receiving a drive erasure attestation generated in association with the erasure operation and by a root-of-trust of the storage drive.”, [0060] “The block erase claim 318 includes a second set of encrypted measurements (second PCR values) recorded following the block-erase operation along with metadata, including a persistent monotonic counter of erase cycles…”, [0026] “In various implementations, the drive erasure attestation 210 assumes different forms. In one implementation, the drive erasure attestation 210 is a certificate generated by the RoT 206 that includes claims 226 of one or more erase operations as attributes of the certificate (a “device attestation certificate”).”). 12. (Original) The memory system according to claim 11, wherein the nonvolatile memory further includes a second storage area that stores a signature key(KELLY [0046] “The ledger service 227 is, during initial provisioning operations of the storage drive 204, provided with various public keys 232 usable to verify each entity in the device identity chain 234. For example, these keys may include the public attestation key of the storage drive 204 that is needed to validate the digital signature 231 in the drive erasure certificate 210;”, [0039] “the drive erasure attestation 210 is endorsed via a digital signature 231 of the RoT 206 that is generated using a private key of the RoT.”), and the controller is further configured to: generate log data related to the executed data erase operation (KELLY [0021] “The attestation 130 is provided to a ledger service 132 (e.g., a web-based application) that records claims made in the attestation 130 on a drive-specific ledger 134.”, [0050] “the ledger 230 is tied to the unique cryptographic identity of the storage drive 204 and each update to the ledger 230 is conditioned upon validation of all endorsements within device identity chain 234. This guarantees that that erase operation logged in the ledger 230 corresponds to an accurate and completely-executed erase operation.” The logged erase operation data in the ledger is mapped to log data); generate auxiliary information for managing the erase certificate (KELLY [0038] “In one implementation, the erase instructions 224 include a nonce value (e.g., a random or non-repeating number), and the erase instructions 224 further include an instruction to generate an attestation certificate that includes the nonce value.” The nonce value is mapped to the auxiliary information.);calculate a hash value of certification data that includes the information([0025] “Each claim corresponding to an erase operation includes measurements of the storage drive 204 that have been hashed by a hashing algorithm and stored in the PCRs of the RoT 206.” The claim containing the hashed measurements of the storage drive is mapped to the calculated hash value of certification data that includes the information.), the log data([0006] “In some implementations, the drive erasure attestation further comprises a certificate chain that is recorded in the ledger along with the first claim.”, [0021] “The attestation 130 is provided to a ledger service 132 (e.g., a web-based application) that records claims made in the attestation 130 on a drive-specific ledger 134.”, [0045] “The erasure attestation 229 includes the claims 226 as well as a chain of cryptographic endorsements (shown as device identity chain 234), including, for example, a certificate generated by the attestor 218, a certificate of the auditor 214, the drive erasure attestation 210, and the device identity certificate 228.” The chain of cryptographic endorsements logged within the ledger, especially in the example of a certificate serving as a drive erasure attestation, is mapped to the log data included within the hash value of certification as the instant attestation mapped to the hash value of certification is taught to include other claims and chains of attestations logged within the ledger(log data).), and the auxiliary information([0060] “The crypto-erase claim 316 includes the first set of encrypted measurements (first PCR values) recorded immediately following the crypto-erase operation, along with metadata representing a monotonic counter used in the Key Derivation Function and the provided nonce value.”); generate a digital signature for the certification data by using the hash value and the signature key; and generate the erase certificate that includes the certification data and the digital signature([0039] “In addition to the claims 226, the drive erasure attestation 210 is endorsed via a digital signature 231 of the RoT 206 that is generated using a private key of the RoT. In various implementations, the drive erasure attestation assumes different forms and is endorsed and verified in different ways.”, [0068] “In one implementation, the ledger service 402 creates the digital signature by applying an algorithm to create a hash of the contents of the requested firmware file. The ledger service 402 then encrypts the hash with the private boot key 406 and adds this encrypted hash—the digital signature—to the firmware file, yielding endorsed firmware 429 that the ledger service 402 then transmits back to the host device 420.”). 13. (Original) The memory system according to claim 11, wherein the controller is configured to: in response to receiving a first request from a first host, execute the data erase operation, the first request requesting the data erase operation on the plurality of first storage areas and (KELLY [0018] “In various circumstances, the storage drive 104 may be provided with a request to erase the user data 108.”, [0038] “When a secure data erase is initiated, the attestor 218 transmits erase instructions 224 to the server 220. The erase instructions 224 may, in some implementations, comprise a sequence of communications as opposed to a single communication (see, e.g., erase and attestation operations discussed with respect to FIG. 3) The erase instructions 224 instruct the storage drive 204 to perform one or more erase operations and to collect and record measurements in association with each requested erase operation. In response to receiving the erase instructions 224, the requested erase operation(s) are executed,”) generation of the erase certificate ([0029] “In some implementations, the RoT 206 automatically generates a crypto-erase claim each time it carries out a crypto-erase operation. In other implementations, crypto-erase claims are generated upon receipt of a specific request associated with a crypto-erase operation, such as a request to record a claim or to generate a drive erasure attestation that includes a claim.”); and in response to the completion of the data erase operation, generate the erase certificate([0038] “In response to receiving the erase instructions 224, the requested erase operation(s) are executed, and the RoT 206 takes measurements following each erase operation… the erase instructions 224 further include an instruction to generate an attestation certificate that includes the nonce value.”). 14. (Original) The memory system according to claim 13, wherein the controller is further configured to, in response to the generation of the erase certificate, transmit a response to the first request to the first host, the response indicating that the erase certificate has been generated ([0049-0050] “In one implementation, the ledger 230 is a decentralized (distributed) ledger backed by Blockchain or Blockchain-like technology. As described with respect to FIG. 1, the ledger 230 may, in some implementations, be a confidential ledger that is accessible exclusively to the owner(s) of data stored on the storage drive 204. For example, the ledger service 227 may be maintained within a security boundary that is off-limits to a hypervisor executing on the server 220 that hosts a VM that the storage drive 204 has been dedicated to support. // Per the above-described operations, the ledger 230 is tied to the unique cryptographic identity of the storage drive 204 and each update to the ledger 230 is conditioned upon validation of all endorsements within device identity chain 234…Thus, the ledger 230 offers a verifiable guarantee of data erasure to the owner(s) of data stored on the storage drive 204.” See FIG. 1, where “Data Erase Guarantee” is transmitted to user device from Drive-Specific Ledger 134). 15. (Original) The memory system according to claim 11, wherein the controller is further configured to, in response to receiving a second request from a second host (KELLY [0017] “The system 100 includes a cloud storage service 102 that provides a cloud-based data storage service to users. The cloud storage service 102 receives user data from various end users and stores the user data on various storage drives that are owned and operated by the cloud storage service 102.”), transmit the erase certificate in a response to the second request to the second host, the second request requesting issuance of the erase certificate(KELLY [0029] “In other implementations, crypto-erase claims are generated upon receipt of a specific request associated with a crypto-erase operation, such as a request to record a claim or to generate a drive erasure attestation that includes a claim.”,). 16. (Original) The memory system according to claim 11, wherein the information includes: a sum of the numbers of program/erase cycles for the respective first storage areas before the data erase operation is executed; and a sum of the numbers of program/erase cycles for the respective first storage areas after the data erase operation is completed(KELLY [0060] “The block erase claim 318 includes a second set of encrypted measurements (second PCR values) recorded following the block-erase operation along with metadata, including a persistent monotonic counter of erase cycles and the nonce value.”). 17. (Original) The memory system according to claim 11, wherein the information includes: the number of program/erase cycles for each of the first storage areas before the data erase operation is executed; and the number of program/erase cycles for each of the first storage areas after the data erase operation is completed(KELLY [0060] “The block erase claim 318 includes a second set of encrypted measurements (second PCR values) recorded following the block-erase operation along with metadata, including a persistent monotonic counter of erase cycles and the nonce value.”). 18. (Original) The memory system according to claim 11, wherein the information includes: at least one of a maximum value and a minimum value of the numbers of program/erase cycles for the respective first storage areas before the data erase operation is executed, and at least one of a maximum value and a minimum value of the numbers of program/erase cycles for the respective first storage areas after the data erase operation is completed (KELLY [0060] “The block erase claim 318 includes a second set of encrypted measurements (second PCR values) recorded following the block-erase operation along with metadata, including a persistent monotonic counter of erase cycles and the nonce value.”). 19. (Original) The memory system according to claim 11, wherein the information further includes one or more parameters related to a degree of wear-out of the nonvolatile memory (KELLY [0036] “An attestor 218 stores the verified erasure criteria 216 for use in comparison relative to claims made by the RoT 206 in association with various erase operations during the lifetime of the storage drive 204.” [0060] “The block erase claim 318 includes a second set of encrypted measurements (second PCR values) recorded following the block-erase operation along with metadata, including a persistent monotonic counter of erase cycles and the nonce value.”). 20. (Original) The memory system according to claim 11, wherein the nonvolatile memory includes a plurality of blocks, and each of the first storage areas includes one or more blocks on which the data erase operation is executable in parallel, among the plurality of blocks(KELLY [0031] “Additionally, the PCR values of the block erase claim evidence a state of user data blocks that were targeted by the secure erase operation (e.g., to demonstrate that the blocks of user data were, in fact, erased).”, [0054] “The crypto-erase operation identifies a target range of data blocks on the storage drive 302, and an instruction to erase cryptographic key(s) used to encrypt or decrypt user data stored within the target range of data blocks.” Further see FIG. 2 where Kelly demonstrates a Full-Drive Block Erase within ledger 230). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Kamryn Gillespie whose telephone number is 703-756-5498. The examiner can normally be reached on Monday through Thursday from 9am to 6pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached on (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pairdirect.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /K.J.G./Examiner, Art Unit 2408 /LINGLAN EDWARDS/Supervisory Patent Examiner, Art Unit 2408
Read full office action

Prosecution Timeline

Sep 03, 2024
Application Filed
Feb 09, 2026
Non-Final Rejection mailed — §102
Apr 07, 2026
Applicant Interview (Telephonic)
Apr 10, 2026
Examiner Interview Summary
Apr 23, 2026
Response Filed
Jul 08, 2026
Final Rejection mailed — §102 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12664261
SYSTEMS AND METHODS FOR MONITORING A PLURALITY OF VEHICLES
2y 8m to grant Granted Jun 23, 2026
Patent 12645786
SUBSYSTEM PERMISSION ERROR DIAGNOSTIC AID
2y 9m to grant Granted Jun 02, 2026
Patent 12632548
CYBER THREAT INFORMATION PROCESSING APPARATUS, CYBER THREAT INFORMATION PROCESSING METHOD, AND STORAGE MEDIUM STORING CYBER THREAT INFORMATION PROCESSING PROGRAM
3y 3m to grant Granted May 19, 2026
Patent 12627488
HANDLING OF DATABASE ENCRYPTION KEY REVOCATION
3y 5m to grant Granted May 12, 2026
Patent 12619578
Encoding / Decoding System and Method
3y 7m to grant Granted May 05, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
73%
Grant Probability
96%
With Interview (+23.2%)
2y 7m (~8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 30 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month