Prosecution Insights
Last updated: August 18, 2026
Application No. 18/879,618

METHODS AND APPARATUS FOR POINTER SECURITY

Final Rejection §103
Filed
Dec 27, 2024
Priority
Jun 28, 2022 — GB 2209440.3 +1 more
Examiner
SCHMIDT, KARI L
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
ARM Limited
OA Round
2 (Final)
74%
Grant Probability
Favorable
3-4
OA Rounds
2y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
557 granted / 752 resolved
+16.1% vs TC avg
Strong +42% interview lift
Without
With
+42.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 9m
Avg Prosecution
15 currently pending
Career history
774
Total Applications
across all art units

Statute-Specific Performance

§101
17.1%
-22.9% vs TC avg
§103
50.9%
+10.9% vs TC avg
§102
10.9%
-29.1% vs TC avg
§112
13.1%
-26.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 752 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office Action is in response to the Amendment filed on 7/6/2026. In instant Amendment, claims 1, 3-15, 17 and 18 have been amended; claim 2 has been canceled; claims 1 and 15 are independent claims. Claims 1, 3-15, 17 and 18 have been examined and are pending. This Action is made Final. The examiner notes the IDS filed on 7/13/2026 has been considered. Response to Arguments The objection to claims 2-15 are withdrawn as the claims have been amended. The rejection of claim 18 under 35 U.S.C. 101 is withdrawn as the claims has been amended. Applicant's arguments filed 7/6/2026 with respect to the 35 U.S.C. 103 rejection have been fully considered but they are not persuasive. Applicant Argues: At least the following features of claim 1 are not disclosed or suggested by the proposed combination of Durham and Wu: "combine the pointer authentication value with the plurality of encrypted address bits, including performing a cryptographic shuffle on the pointer authentication value and the plurality of encrypted address bits, to produce a signed encrypted pointer." The technology in claim 1 improves security because a malicious attacker is not able to determine which bits (and in which order) correspond to the address, and which bits correspond to the pointer authentication value. See page 3, line 31, to page 4, line 2, of the specification. Page 4 of the OA admits that Durham lacks the claim feature quoted above and turns to Wu. Cited paragraphs [0028] and [0048] of Wu teach applying a shuffle-vector to an input string as part of an encryption/decryption process. However, Wu does not teach performing a cryptographic shuffle on the pointer authentication value and the plurality of encrypted address bits, as in claim 1. In other words, Wu teaches applying a shuffle-vector to a generic input string. Wu, like Durham, fails to disclose or suggest performing a cryptographic shuffle specifically on a combination of a pointer authentication value, like a PAC, and an already encrypted address bits. By specifically performing a cryptographic shuffle on the combination of a pointer authentication value and encrypted address bits, the technology in clam 1 improves security because a malicious attacker will not be able to determine which bits (and in which order) correspond to the address, and which bits correspond to the pointer authentication value. Therefore, even if the skilled person combined Durham and Wu, they would not arrive at claim 1. Hence, Wu does not remedy the deficiencies of Durham. Therefore, claim 1 is new and not obvious. For at least the same reasons, claims 3 to 15, 17 and 18 are new and not obvious. The proposed combination of Wu and Durham, even if it could be made for the sake of argument, fails to disclose or suggest all the features recited in claim 1. Corresponding features are recited in independent claims 15 and 18. The obviousness rejection based on Wu and Durham should be withdrawn. The application is in condition for allowance. An early notice to that effect is requested. By responding only to particular positions asserted in the office action, Applicant does not acquiesce in other positions that have not been explicitly addressed. Applicant's arguments for the patentability of a claim should not be understood as implying that no other reasons for the patentability of that claim exist. Nothing in this response should be construed as an intent to concede any issue regarding any claim, except as specifically stated in this response, and the amendment of any claim does not necessarily signify concession of unpatentability of the claim prior to its amendment. Nothing stated or unstated in this response should be interpreted as an explicit or implicit admission regarding the applicability of art applied or cited or that there is any compatibility between disparate references. Examiner’s Response: The examiner respectfully disagrees. In response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. In this instance Durham was shown to disclose combine the pointer authentication value with the plurality of encrypted address bits, including performing a cryptographic [encryption] on the pointer authentication value and the plurality of encrypted address bits, to produce a signed encrypted pointer (FIG. 4 depicts Ciphertext including MAC and [0074] - FIG. 4 illustrates a cryptographically encoded pointer 400 with various context information according to at least one embodiment of the present disclosure and [0089] - The plaintext corresponding to ciphertext 404 includes message authentication code 426. The MAC 426 may be computed over any suitable portion of the pointer 400 including any of the context information and/or any portion (or all) of the linear address). The examiner has construed that the cryptographically encoded pointer is encoded with various context information as shown in the Durham citation(s) above. The means of encoding/computing is silent in Durham. The examiner sought to combine Wu to teach ...including performing a cryptographic shuffle... ([0028] - More specifically, this disclosure provides encryption and decryption techniques which are based on the use of a shuffle-vector (or transposition-vector), derived from one or more shared (secret) keys. and [0048] - This transposition vector (221) is applied to an input string 229 as part of an encryption/decryption process (231), to process each of one or more segments of an input string 229 (i.e., of a quantum of characters equal in length to elements in the transposition vector), and to generate an output string 233 from this processing... In an encryption process, the output string is encrypted relative to the input, and in a decryption process, the output is decrypted relative to the input). The examiner notes that Wu, as construed, teaches the use of shuffle-vector/transposition vector as part of an encryption/decryption process, see [0028]. Wu teaches that one or more segments of an input string are applied to a transposition vector to thereby perform a cryptographic shuffle on the input string to product an encrypted output string. The examiner respectfully notes this “processing” via a cryptographic shuffle can be applied to the “encoding/computing” that is silent in Durham, thus, producing a combination that reads on the argued limitation. The examiner has provided motivation for such a combination, from Wu, and Wu states it provides/allows assist[ance] with the protection of electronic information and access to electronic systems (Wu, [0003]). Therefore, it is the combination of Durham in view of Wu that teaches the aforementioned limitation, thus, the examiner finds this argument not persuasive. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 3-13, 15, 17, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Durham (US 2021/0117342 A1) in view of Wu et al. (US 2019/0007390 A1). Regarding Claim 1; Durham discloses an apparatus comprising: interface circuitry to receive a pointer comprising a plurality of address bits (FIG. 1 and [0018] - Some cryptographic computing systems may implement the encryption and decryption of pointer addresses (or portions thereof), keys, data, and code in a processor core using encrypted memory access instructions and [0021] - In some pointer encodings, a slice or segment of the address in the pointer includes a plurality of bits and is encrypted (and decrypted) based on a secret address key and a tweak based on the metadata. Other pointers can be encoded with a plaintext memory address (e.g., linear address) and metadata and [0044] and [0079]); and pointer processing circuitry to: extract said plurality of address bits from the pointer ([0044] - In an embodiment, the valid range metadata is used to select a portion (or slice) of the encoded pointer 114 to be encrypted. In other embodiments, the slice of the encoded pointer 114 to be encrypted may be known a priori (e.g., upper 32 bits, lower 32 bits, etc.). The selected slice of the encoded pointer 114 (and the adjustment, in some embodiments) is encrypted using a secret address key (e.g., keys 116) and optionally, an address tweak, as described further below and [0079]); encrypt said plurality of address bits, to produce a plurality of encrypted address bits ([0044] - In an embodiment, the valid range metadata is used to select a portion (or slice) of the encoded pointer 114 to be encrypted. In other embodiments, the slice of the encoded pointer 114 to be encrypted may be known a priori (e.g., upper 32 bits, lower 32 bits, etc.). The selected slice of the encoded pointer 114 (and the adjustment, in some embodiments) is encrypted using a secret address key (e.g., keys 116) and optionally, an address tweak, as described further below and [0079]); determine, based at least in part on the plurality of address bits, a pointer authentication value ([0044] and [0089] - The plaintext corresponding to ciphertext 404 includes message authentication code 426. The MAC 426 (i.e., pointer authentication value) may be computed over any suitable portion of the pointer 400 including any of the context information and/or any portion (or all) of the linear address. Prior to accessing data or code, the processor unit may recompute the MAC 426 from the corresponding portion(s) of the linear address and/or context information); and combine the pointer authentication value with the plurality of encrypted address bits, including performing a cryptographic [encryption] on the pointer authentication value and the plurality of encrypted address bits, to produce a signed encrypted pointer (FIG. 4 depicts Ciphertext including MAC and [0074] - FIG. 4 illustrates a cryptographically encoded pointer 400 with various context information according to at least one embodiment of the present disclosure and [0089] - The plaintext corresponding to ciphertext 404 includes message authentication code 426. The MAC 426 may be computed over any suitable portion of the pointer 400 including any of the context information and/or any portion (or all) of the linear address). Durham fails to explicitly discloses ...including performing a cryptographic shuffle.... However, in an analogous art, Wu teaches ... including performing a cryptographic shuffle... ([0028] - More specifically, this disclosure provides encryption and decryption techniques which are based on the use of a shuffle-vector (or transposition-vector), derived from one or more shared (secret) keys. and [0048] - This transposition vector (221) is applied to an input string 229 as part of an encryption/decryption process (231), to process each of one or more segments of an input string 229 (i.e., of a quantum of characters equal in length to elements in the transposition vector), and to generate an output string 233 from this processing... In an encryption process, the output string is encrypted relative to the input, and in a decryption process, the output is decrypted relative to the input). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Wu to the cryptographic [encryption] of Durham to include ...including performing a cryptographic shuffle. One would have been motivated to combine the teachings of Wu to Durham to do so as it provides / allows improved assist[ance] with the protection of electronic information and access to electronic systems (Wu, [0003]). Regarding Claim 3; Durham in view of Wu discloses the apparatus to Claim 2. wherein the pointer processing circuitry is configured to: encrypt the plurality of address bits based on a cryptographic key ([0021] - In some pointer encodings, a slice or segment of the address in the pointer includes a plurality of bits and is encrypted (and decrypted) based on a secret address key and a tweak based on the metadata. and [0029] and [0044] –The selected slice of the encoded pointer 114 (and the adjustment, in some embodiments) is encrypted using a secret address key (e.g., keys 116) and optionally, an address tweak, as described further below); and perform said cryptographic [encryption] based on said cryptographic key ([0021] and [0029] and [0044]). However, in an analogous art, Wu teaches ... perform said cryptographic shuffle ([0028] - More specifically, this disclosure provides encryption and decryption techniques which are based on the use of a shuffle-vector (or transposition-vector), derived from one or more shared (secret) keys and [0048]). Similar rationale and motivation is noted for the combination of Wu to Durham, as per claim 1, above. Regarding Claim 4; Durham in view of Wu discloses the apparatus to Claim 3. Durham further discloses wherein the cryptographic key is a pointer authentication code, PAC, key ([0041] - Secret keys (i.e., PAC key) may also be generated and associated with cryptographically encoded pointers for encrypting/decrypting the address portion (or slice) encoded in the pointer). Regarding Claim 5; Durham in view of Wu discloses the apparatus to Claim 1. Durham further discloses wherein the pointer processing circuitry is configured to determine the pointer authentication value by performing at least one of a hash, and an encryption, of the plurality of address bits ([0089]-[0090] - In some embodiments, the MAC 426 may be generated by calculating a hash function using the relevant bits of the pointer 400.) Regarding Claim 6; Durham in view of Wu discloses the apparatus to Claim 1. Durham further discloses wherein the pointer processing circuitry is configured to obscure the pointer authentication value (FIG. 4 depicts Ciphertext including MAC and [0077] - The ciphertext portion 404 (e.g., 64 bits in the example shown) of the pointer 400 may be encrypted with a small tweakable block cipher (e.g., a SIMON, SPECK, or tweakable K-cipher at a 64-bit block size, or other variable bit size tweakable block cipher and[0089]-[0090] - In some embodiments, the MAC 426 may be generated by calculating a hash function using the relevant bits of the pointer 400.)) Regarding Claim 7; Durham in view of Wu discloses the apparatus to Claim 6. Durham further discloses wherein the pointer processing circuitry is configured to obscure the pointer authentication value by performing at least one of a hash, and an encryption, of the pointer authentication value (FIG. 4 depicts Ciphertext including MAC and [0077] - The ciphertext portion 404 (e.g., 64 bits in the example shown) of the pointer 400 may be encrypted with a small tweakable block cipher (e.g., a SIMON, SPECK, or tweakable K-cipher at a 64-bit block size, or other variable bit size tweakable block cipher and[0089]-[0090] - In some embodiments, the MAC 426 may be generated by calculating a hash function using the relevant bits of the pointer 400.)) Regarding Claim 8; Durham in view of Wu discloses the apparatus to Claim 1. Durham further discloses comprising pointer decryption circuitry to: extract the pointer authentication value from the signed encrypted pointer ([0027] - Although the cryptographically encoded pointer (or non-cryptographically encoded pointers) can be used to isolate data, via encryption, the integrity of the data may still be vulnerable. For example, unauthorized access of cryptographically isolated data can corrupt the memory region where the data is stored regardless of whether the data is encrypted, corrupting the data contents unbeknownst to the victim. Data integrity may be supported using an integrity verification (or checking) mechanism such as message authentication codes (MACS) or implicitly based on an entropy measure of the decrypted data, or both); and based on the extracted pointer authentication value, authenticate the signed encrypted pointer ([0027] and [0089] - If the recomputed MAC matches the one embedded in the pointer 400, then the pointer is considered to be valid for use at that access site. This check may verify the integrity of the pointer (to detect forgery of the pointer). If the check fails, the memory access is not allowed to proceed.) Regarding Claim 9; Durham in view of Wu discloses the apparatus to Claim 8. Durham further discloses wherein the pointer decryption circuitry is configured to extract the pointer authentication value by: performing a cryptographic [decryption] of the signed encrypted pointer ([0021] - In some pointer encodings, a slice or segment of the address in the pointer includes a plurality of bits and is encrypted (and decrypted) based on a secret address key and a tweak based on the metadata) and [0044]-[0045]); and extracting a block of bits, corresponding to the pointer authentication value, from the [decryption] signed encrypted pointer ([0021] and [0044]-[0045] -To do this, the encrypted slice of the encoded pointer 114 (and in some embodiments, the encrypted adjustment) is decrypted using a secret address key (e.g., keys 116) and an address tweak (if the address tweak was used in the encryption), as described further below. The encoded pointer 114 is returned to its original (e.g., canonical) form, based on appropriate operations in order to restore the original value of the encoded pointer 114 (e.g., the true, original linear memory address)). Wu further teaches ...performing a cryptographic deshuffle... and extracting... from the deshuffle ([0028] - More specifically, this disclosure provides encryption and decryption techniques which are based on the use of a shuffle-vector (or transposition-vector), derived from one or more shared (secret) keys. and [0048] - This transposition vector (221) is applied to an input string 229 as part of an encryption/decryption process (231), to process each of one or more segments of an input string 229 (i.e., of a quantum of characters equal in length to elements in the transposition vector), and to generate an output string 233 from this processing... In an encryption process, the output string is encrypted relative to the input, and in a decryption process, the output is decrypted relative to the input). Similar rationale and motivation is noted for the combination of Wu to Durham in view of Wu, as per Claim 1, above. Regarding Claim 10; Durham in view of Wu discloses the apparatus to Claim 8. Durham further discloses wherein the pointer decryption circuitry is responsive to a successful authentication of the signed encrypted pointer to execute a processing instruction based on the address bits of said pointer ([0027] and [0045] and [0089] - If the recomputed MAC matches the one embedded in the pointer 400, then the pointer is considered to be valid for use at that access site. This check may verify the integrity of the pointer (to detect forgery of the pointer). If the check fails, the memory access is not allowed to proceed.) Regarding Claim 11; Durham in view of Wu discloses the apparatus to Claim 10. Durham further discloses wherein the pointer decryption circuitry is configured to identify the address bits by: extracting the plurality of encrypted address bits from the signed encrypted pointer ([0027] and [0044]-[0045] - The encoded pointer 114 is returned to its original (e.g., canonical) form, based on appropriate operations in order to restore the original value of the encoded pointer 114 (e.g., the true, original linear memory address). To do this in at least one possible embodiment, the address metadata encoded in the unused bits of the encoded pointer 114 are removed (e.g., return the unused bits to their original form); and decrypting the plurality of encrypted address bits ([0027] and [0044]-[0045] - The encoded pointer 114 is returned to its original (e.g., canonical) form, based on appropriate operations in order to restore the original value of the encoded pointer 114 (e.g., the true, original linear memory address). To do this in at least one possible embodiment, the address metadata encoded in the unused bits of the encoded pointer 114 are removed (e.g., return the unused bits to their original form). Regarding Claim 12; Durham in view of Wu discloses the apparatus to Claim 11. Durham further discloses wherein the pointer decryption circuitry is configured to authenticate the signed encrypted pointer by: based on the decrypted address bits, repeat said determining of the pointer authentication value to determine a re-calculated pointer authentication value ([0027] and [0044]-[0045] - If the encoded pointer 114 decodes successfully, the memory access operation completes successfully and [0089] - If the recomputed MAC matches the one embedded in the pointer 400, then the pointer is considered to be valid for use at that access site. This check may verify the integrity of the pointer (to detect forgery of the pointer). If the check fails, the memory access is not allowed to proceed); and verifying that the extracted pointer authentication value matches the re-calculated pointer authentication value ([0027] and [0044]-[0045] and [0089] - If the recomputed MAC matches the one embedded in the pointer 400, then the pointer is considered to be valid for use at that access site. This check may verify the integrity of the pointer (to detect forgery of the pointer). If the check fails, the memory access is not allowed to proceed Regarding Claim 13; Durham in view of Wu discloses the apparatus to Claim 8. Durham further discloses wherein the pointer decryption circuitry is responsive to a failed authentication of the signed encrypted pointer to identify an error [0045] - If the encoded pointer 114 decodes successfully, the memory access operation completes successfully. However, if the encoded pointer 114 has been manipulated (e.g., by software, inadvertently or by an attacker) so that its value falls outside the valid range indicated by the range metadata (e.g., overflows the buffer), the encoded pointer 114 may be corrupted as a result of the decrypting process performed on the encrypted address bits in the pointer. A corrupted pointer will raise a fault (e.g., a general protection fault or a page fault if the address is not mapped as present and [0089]). Regarding Claim 15; Durham in view of Wu discloses an apparatus comprising: interface circuitry configured to receive a pointer comprising a plurality of address bits (FIG. 1 and [0018] - Some cryptographic computing systems may implement the encryption and decryption of pointer addresses (or portions thereof), keys, data, and code in a processor core using encrypted memory access instructions and [0021] - In some pointer encodings, a slice or segment of the address in the pointer includes a plurality of bits and is encrypted (and decrypted) based on a secret address key and a tweak based on the metadata. Other pointers can be encoded with a plaintext memory address (e.g., linear address) and metadata and [0044] and [0079]); and pointer processing circuitry configured to: extract said plurality of address bits from the pointer ([0044] - In an embodiment, the valid range metadata is used to select a portion (or slice) of the encoded pointer 114 to be encrypted. In other embodiments, the slice of the encoded pointer 114 to be encrypted may be known a priori (e.g., upper 32 bits, lower 32 bits, etc.). The selected slice of the encoded pointer 114 (and the adjustment, in some embodiments) is encrypted using a secret address key (e.g., keys 116) and optionally, an address tweak, as described further below and [0079]); determine, based at least in part on the plurality of address bits, a pointer authentication value ([0044] and [0089] - The plaintext corresponding to ciphertext 404 includes message authentication code 426. The MAC 426 (i.e., pointer authentication value) may be computed over any suitable portion of the pointer 400 including any of the context information and/or any portion (or all) of the linear address. Prior to accessing data or code, the processor unit may recompute the MAC 426 from the corresponding portion(s) of the linear address and/or context information); combine the pointer authentication value with the plurality of address bits (FIG. 4 and [0089] - The plaintext corresponding to ciphertext 404 includes message authentication code 426. The MAC 426 may be computed over any suitable portion of the pointer 400 including any of the context information and/or any portion (or all) of the linear address); and encrypt said combined pointer authentication value and plurality of address bits, including performing a cryptographic [encryption] on the pointer authentication value and the plurality of encrypted address bits, to produce a signed encrypted pointer (FIG. 4 depicts Ciphertext including MAC and [0044] - In an embodiment, the valid range metadata is used to select a portion (or slice) of the encoded pointer 114 to be encrypted. In other embodiments, the slice of the encoded pointer 114 to be encrypted may be known a priori (e.g., upper 32 bits, lower 32 bits, etc.). The selected slice of the encoded pointer 114 (and the adjustment, in some embodiments) is encrypted using a secret address key (e.g., keys 116) and optionally, an address tweak, as described further below and [0074] - FIG. 4 illustrates a cryptographically encoded pointer 400 with various context information according to at least one embodiment of the present disclosure and [0079]); Durham fails to explicitly discloses ...including performing a cryptographic shuffle.... However, in an analogous art, Wu teaches ... including performing a cryptographic shuffle... ([0028] - More specifically, this disclosure provides encryption and decryption techniques which are based on the use of a shuffle-vector (or transposition-vector), derived from one or more shared (secret) keys. and [0048] - This transposition vector (221) is applied to an input string 229 as part of an encryption/decryption process (231), to process each of one or more segments of an input string 229 (i.e., of a quantum of characters equal in length to elements in the transposition vector), and to generate an output string 233 from this processing... In an encryption process, the output string is encrypted relative to the input, and in a decryption process, the output is decrypted relative to the input). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Wu to the cryptographic [encryption] of Durham to include ...including performing a cryptographic shuffle. One would have been motivated to combine the teachings of Wu to Durham to do so as it provides / allows improved assist[ance] with the protection of electronic information and access to electronic systems (Wu, [0003]). Regarding Claim(s) 17; claim(s) 17 is/are directed to a/an medium associated with the apparatus claimed in claim(s) 1. Claim(s) 17 is/are similar in scope to claim(s) 1, and is/are therefore rejected under similar rationale. Regarding Claim(s) 18; claim(s) 18 is/are directed to a/an medium associated with the apparatus claimed in claim(s) 1. Claim(s) 18 is/are similar in scope to claim(s) 1, and is/are therefore rejected under similar rationale. Claim(s) 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Durham (US 2021/0117342 A1) in view of Wu et al. (US 2019/0007390 A1) and further in view of Blasco et al. (US 11,468,168 B1). Regarding Claim 14; Durham in view of Wu discloses the apparatus to Claim 1. Durham further discloses comprising: instruction receiving circuitry to receive, as part of a program flow, a branch instruction, said branch instruction identifying a function ([0101] - In various embodiments, the context information 428 may include information associated with a code path. For example, the context information 428 may include a hash of the code path or a hash of critical events (e.g., conditional branches) leading up to the issuance of the memory access instruction that includes the pointer); instruction authentication circuitry (FIG. 1 – Address Cryptography Unit) and to: determine, based at least in part on the function, an instruction authentication value (FIG. 4 depicts Ciphertext including MAC and Other Context Information and [0089] - The plaintext corresponding to ciphertext 404 includes message authentication code 426. The MAC 426 may be computed over any suitable portion of the pointer 400 including any of the context information and/or any portion (or all) of the linear address and [0101] – conditional branches); and combine the instruction authentication value with the branch instruction to produce an authenticatable branch instruction (FIG. 4 depicts Ciphertext including MAC and Other Context Information and [0027] and [0044]-[0045] - If the encoded pointer 114 decodes successfully, the memory access operation completes successfully and [0089] - The plaintext corresponding to ciphertext 404 includes message authentication code 426. The MAC 426 may be computed over any suitable portion of the pointer 400 including any of the context information and/or any portion (or all) of the linear address and [0101] – conditional branches), and branch circuitry (FIG. 1 – Secure Memory Access Logic w/ Decryption Load Logic and [0030]- The secure memory access logic... provide access control to memory locations pointed to by the encoded pointer 114) to: based on a function authentication value, authenticate the authenticatable branch instruction FIG. 4 depicts Ciphertext including MAC and Other Context Information and [0027] and [0044]-[0045] - If the encoded pointer 114 decodes successfully, the memory access operation completes successfully and [0089] - The plaintext corresponding to ciphertext 404 includes message authentication code 426. The MAC 426 may be computed over any suitable portion of the pointer 400 including any of the context information and/or any portion (or all) of the linear address and [0101] – conditional branches),; and responsive to a successful authentication of the authenticatable branch instruction [operation completes successfully] (FIG. 4 depicts Ciphertext including MAC and Other Context Information and [0027] and [0044]-[0045] - If the encoded pointer 114 decodes successfully, the memory access operation completes successfully and [0089] - The plaintext corresponding to ciphertext 404 includes message authentication code 426. The MAC 426 may be computed over any suitable portion of the pointer 400 including any of the context information and/or any portion (or all) of the linear address and [0101] – conditional branches). Durham in view of Wu fails to explicitly disclose ...execute a jump in the program flow to said function. However, in an analogous art, Blasco teaches ...execute a jump in the program flow to said function (col. 5, lines 19-21 - In various embodiments, each of the entry point and the exit point of a subroutine uses a control transfer instruction. Examples of control transfer instructions are conditional branch instructions, unconditional branch instructions, which are also referred to as jump instructions, the jump instruction of call instructions of subroutine prologues and the jump instruction in return (jump) instructions of subroutine epilogues). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Blasco to the responsive to a successful authentication of the authenticatable branch instruction of Durham in view of Wu to include ....execute a jump in the program flow to said function. One would have been motivated to combine the teachings of Blasco to Durham in view of Wu to do so as it provides / allows efficient handling of subroutines (Blasco, col. 1, lines 9-11). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KARI L SCHMIDT whose telephone number is (571)270-1385. The examiner can normally be reached Monday-Friday 10am - 6pm (MDT). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KARI L SCHMIDT/Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Dec 27, 2024
Application Filed
Apr 06, 2026
Non-Final Rejection mailed — §103
Jul 06, 2026
Response Filed
Jul 29, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705372
CONTROLLING AN INTERACTION USING ONLINE ACCOUNT OPENING INDICATORS
3y 1m to grant Granted Aug 11, 2026
Patent 12695782
UPDATING REMOTE SCAN ENGINES WITH CUSTOM VULNERABILITY CHECKS
1y 7m to grant Granted Jul 28, 2026
Patent 12689917
Determining a Subset of Base Stations in a Wireless Network
2y 3m to grant Granted Jul 21, 2026
Patent 12682026
MULTIDIMENSIONAL LOCAL LARGE LANGUAGE MODEL USER AUTHENTICATION
2y 5m to grant Granted Jul 14, 2026
Patent 12666259
Authentication of a Communications Device
5y 1m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
74%
Grant Probability
99%
With Interview (+42.4%)
3y 9m (~2y 1m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 752 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month