DETAILED ACTION
This Office Action is in response to the Amendment filed on 06/10/2026.
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the instant Amendment, filed on 06/10/2026, claims 1-20 have been examined and are pending; claims 1, 4, and 14 are independent. This Action is made FINAL.
Response to Arguments/Remarks
As to the rejections of claims 4, 13, 14, and 20, rejected under 35 U.S.C. § 101, the rejections are withdrawn as the claims have been amended to recite additional limitations, and the limitations, in combination, amount to significantly more than the abstract idea.
Applicant’s arguments with respect to prior-art rejections to claims 1-20, filed on 06/10/2026, have been considered, but are moot, because the arguments do not apply to any of the references being used in the current rejection, where a new ground of rejection is applied with new art that is necessitated based on the amendment.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
This application currently names joint inventors. In considering patentability of the claims the Examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the Examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Krishnan et al (“Krishnan,” US 2017/0185504, published on 06/29/2017), in view of Sreedhar (“Sreedhar,” US 2007/0282841, published on 12/06/2007), and further in view of Chess et al (“Chess,” US 2007/0074169 published on 03/29/2007).
As to claim 1, Krishnan teaches a computer-implemented method (Krishnan: pars 0003-0004, teaches method and system for analyzing a software program, and generating result, indicating whether the software program satisfies a predetermined criterion) comprising:
receiving at least a portion of a security protocol model codebase that implements a security protocol model; the security protocol model codebase to verify the security protocol model codebase with an auto-active verifier (Krishnan: pars 0003-0004, 0016, the method divides a software program into various program slices according to the analysis objectives, and where each program slice covers different code segments of the software program, with independent or overlapping code segments, and where each segment is selected for generating a result of security analysis);
executing, by at least one processor, static analyses (Krishnan: pars 0003, 0016, 0064, thus the method generating a report, using the results of each components pointer analysis result, as a set of pointer analysis, where tainted analysis and escape analysis [i.e., a set of static analyses] are incorporated in an order, resulting combined report of result, indicating whether the software program, as a whole, satisfies a predetermined criterion); the static analyses including at least:
executing a taint analysis tool to verify that at least a secret value in a data source does not reach a data sink in the application codebase (Krishnan: pars 0058, 0070, for any independent program slices and dependent program slices, and paths, the analysis involves checking whether the security-sensitive method uses potentially “tainted” data (or data passed in to a software program by an application) for generating result indicating potential tainted data [i.e., a taint analysis tool to verify]);
executing an escape analysis tool to verify that the application codebase does not concurrently access at least a first portion of memory used by a thread in the security protocol sensitive code (Krishnan: pars 0058, 0063, since the tainted analysis is insufficient as execution paths might accept potentially tainted data, the method applies an escape analysis. With escape analysis, one is interested in whether potentially sensitive data returned by a function or method “escapes” for use by other functions or methods before that sensitive data is “declassified.” The escape analysis involves checking whether a security-sensitive method uses potentially sensitive data that has not been properly declassified. Escape analysis aims to identify paths that do not have proper declassification and, thus, removes paths that do declassify the potentially sensitive data before its use [i.e., an escape analysis tool to verify]);
executing a pointer analysis tool to verify that the application codebase does not write to at least a second portion of memory used by the annotated security protocol sensitive code (Krishnan: pars 0016, 0064-0065, the method then performs a pointer analysis on each program slice, from a starting point for the pointer analysis within the program slice, and to an ending point); and
outputting, based on results from the taint analysis tool, the escape analysis tool, and the pointer analysis tool, an indication of whether behavior of the application codebase is contained within the security protocol model (Krishnan: pars 0003, 0016, 0064, thus the method generating a report, using the results of each components pointer analysis result, as a set of pointer analysis, where tainted analysis and escape analysis are incorporated in an order, resulting combined report of result, indicating whether the software program, as a whole, satisfies a predetermined criterion).
Krishnan does not explicitly teach codebase including annotated security protocol sensitive code including annotations, wherein the annotations include an indication of an assumed role under the security protocol model; integrating the annotated security protocol sensitive code in an application codebase to cryptographically secure a communications interface; verify. . in the annotated security protocol sensitive code.
However, in an analogous art, Sreedhar teaches codebase including annotated security protocol sensitive code including annotations, wherein the annotations include an indication of an assumed role under the security protocol model; integrating the annotated security protocol sensitive code in an application codebase to cryptographically secure a communications interface (Sreedhar: pars 0006, 0060-0063, 0071, system and method of access controlling of an application/program applying assignment role and security model, and annotating pointer graph for security analysis. For consistency, the values of the two data fields should use the same encryption/decryption keys);
to verify that operations within the application codebase verify .. the annotated security protocol sensitive code (Sreedhar: pars 0066, 0068, 0102, identifying and defining the consistency properties as code annotation, and the code annotation, used in extended escape analysis and pointer analysis).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Sreedhar with the method/system of Krishnan to include the limitation(s), codebase including annotations of security protocol sensitive code, wherein the annotations include an indication of an assumed role under the security protocol model; integrating the annotated security protocol sensitive code in an application codebase to cryptographically secure a communications interface; verify. . in the annotated security protocol sensitive code, where one would have been motivated for the benefit of providing a user with a means for code annotating with role assignment in the security analysis model so that the pointer analysis and escape analysis can be followed with the consideration of the code annotation for the role assignment incorporating in security model (Sreedhar: pars 0006, 0060-0063, 0066, 0102).
Krishnan and Sreedhar does not explicitly teach the limitations, integrating the annotated security protocol sensitive code in an application codebase; [verify that operations] do not invalidate security properties of the security protocol model.
However, in an analogous art, Chess teaches, integrating the annotated security protocol sensitive code in an application codebase (Chess: pars 0006, 0018-0019, 0087, a system and method for analysis of program instructions, where a piece of protective code is selectively inserted [i.e., integrating] into the compiled program [i.e., application codebase] using the security module); [verify that operations] do not invalidate security properties of the security protocol model (Chess: pars 0006, 0018-0019, 0087, the of inserting of the protective code is used along with the source code in run operation, and the analysis security behavior, intercepts attacks, and takes defensive measures [i.e., as the operation is run on the integrated protective code, perform its function, without getting invalidated by the source code].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Chess with the method/system of Krishnan and Sreedhar to include the limitation(s), integrating the annotated security protocol sensitive code in an application codebase; [verify that operations] do not invalidate security properties of the security protocol model, where one would have been motivated for using techniques to insert protective code and run the analysis using the combined integrated code set, where the insert protective code preforms the protection analysis on the source code part as configured to do (Chess: pars 0006, 0018-0019, 0087).
As to claim 2, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 1,
Sreedhar further teaches further comprising: annotating the security protocol sensitive code in the security protocol model codebase with one or more invariants of the security protocol model; and executing a software verifier to verify with at least the annotated security protocol sensitive code as input to prove that behavior of the security protocol sensitive code is contained within the security protocol model (Sreedhar: pars 0066, 0068, 0102, identifying and defining the consistency properties as code annotation, and the code annotation, used in extended escape analysis and pointer analysis. Par 0079, enables modeling of a complex hierarchical type state diagram by abstracting away detailed behavior into multiple levels).
As to claim 3, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 2,
Sreedhar further teaches wherein the annotations are based at least in part on an input/output specification of the security protocol model generated by a model verifier application (Sreedhar: pars 0066, 0068, 0102, identifying and defining the consistency properties as code annotation, and the code annotation, used in extended escape analysis and pointer analysis [i.e., input output flow of set of analysis of the security protocol model).
As to claim 4, Krishnan teaches a computer-implemented method (Krishnan: pars 0003-0004, teaches method and system for analyzing a software program, and generating result, indicating whether the software program satisfies a predetermined criterion) comprising:
receiving at least a portion of a security protocol model codebase that implements a security protocol model (Krishnan: pars 0003-0004, 0016, the method divides a software program into various program slices according to the analysis objectives, and where each program slice covers different code segments of the software program, with independent or overlapping code segments, and where each segment is selected for generating a result of security analysis);
executing, by at least one processor, static analyses of the security protocol sensitive code (Krishnan: pars 0058, 0070, for any independent program slices and dependent program slices, and paths, the analysis involves checking whether the security-sensitive method uses potentially “tainted” data (or data passed in to a software program by an application) for generating result indicating potential tainted data [i.e., 1st static analysis]. Pars 0058, 0063, with escape analysis, one is interested in whether potentially sensitive data returned by a function or method “escapes” for use by other functions or methods before that sensitive data is “declassified.” The escape analysis involves checking whether a security-sensitive method uses potentially sensitive data that has not been properly declassified. Escape analysis aims to identify paths that do not have proper declassification and, thus, removes paths that do declassify the potentially sensitive data before its use [i.e., 2nd static analysis]. Pars 0016, 0064-0065, the method then performs a pointer analysis on each program slice, from a starting point for the pointer analysis within the program slice, and to an ending point [i.e., 3rd static analysis]); and
outputting, based on results from the static analyses, an indication of whether behavior of the application codebase is contained within the security protocol model (Krishnan: pars 0003, 0016, 0064, thus the method generating a report, using the results of each components pointer analysis result, as a set of pointer analysis, where tainted analysis and escape analysis [i.e., a set of static analyses] are incorporated in an order, resulting combined report of result, indicating whether the software program, as a whole, satisfies a predetermined criterion).
Krishnan does not explicitly teach the security protocol model codebase including annotated security protocol sensitive code, including annotations; by including one or more references to the annotated security protocol sensitive code in the application codebase; to verify that operations within the application codebase.
However, in an analogous art, Sreedhar teaches the security protocol model codebase including annotations of security protocol sensitive code; including one or more references to the annotated security protocol sensitive code in an application codebase (Sreedhar: pars 0006, 0060-0063, system and method of access controlling of an application/program applying assignment role and security model, and annotating pointer graph for security analysis);
to verify that operations within the application codebase (Sreedhar: pars 0066, 0068, 0102, identifying and defining the consistency properties as code annotation, and the code annotation, used in extended escape analysis and pointer analysis).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Sreedhar with the method/system of Krishnan to include the limitation(s), the security protocol model codebase including annotations of security protocol sensitive code; including one or more references to the annotated security protocol sensitive code in an application codebase; to verify that operations within the application codebase are independent of the annotated security protocol sensitive code, where one would have been motivated for the benefit of providing a user with a means for code annotating with role assignment in the security analysis model so that the pointer analysis and escape analysis can be followed with the consideration of the code annotation for the role assignment incorporating in security model (Sreedhar: pars 0006, 0060-0063, 0066, 0102).
Krishnan and Sreedhar does not explicitly teach the limitations, integrating the annotated security protocol sensitive code into an application codebase; [verify that operations] do not invalidate security properties of the security protocol model.
However, in an analogous art, Chess teaches, integrating the annotated security protocol sensitive code into an application codebase (Chess: pars 0006, 0018-0019, 0087, a system and method for analysis of program instructions, where a piece of protective code is selectively inserted [i.e., integrating] into the compiled program [i.e., application codebase] using the security module); [verify that operations] do not invalidate security properties of the security protocol model (Chess: pars 0006, 0018-0019, 0087, the of inserting of the protective code is used along with the source code in run operation, and the analysis security behavior, intercepts attacks, and takes defensive measures [i.e., as the operation is run on the integrated protective code, perform its function, without getting invalidated by the source code].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Chess with the method/system of Krishnan and Sreedhar to include the limitation(s), integrating the annotated security protocol sensitive code into an application codebase; [verify that operations] do not invalidate security properties of the security protocol model, where one would have been motivated for using techniques to insert protective code and run the analysis using the combined integrated code set, where the insert protective code preforms the protection analysis on the source code part as configured to do (Chess: pars 0006, 0018-0019, 0087).
As to claim 5, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 4,
Krishnan and Sreedhar further teaches wherein executing the static analyses includes at least one of: executing a taint analysis tool to verify that at least a secret value in a data source in the annotated security protocol sensitive code does not reach a data sink in the application codebase (Krishnan: pars 0058, 0070, for any independent program slices and dependent program slices, and paths, the analysis involves checking whether the security-sensitive method uses potentially “tainted” data (or data passed in to a software program by an application) for generating result indicating potential tainted data [i.e., a taint analysis tool to verify]);
executing an escape analysis tool to verify that the application codebase does not concurrently access at least a first portion of memory used by a thread in the annotated security protocol sensitive code Krishnan: pars 0058, 0063, since the tainted analysis is insufficient as execution paths might accept potentially tainted data, the method applies an escape analysis. With escape analysis, one is interested in whether potentially sensitive data returned by a function or method “escapes” for use by other functions or methods before that sensitive data is “declassified.” The escape analysis involves checking whether a security-sensitive method uses potentially sensitive data that has not been properly declassified. Escape analysis aims to identify paths that do not have proper declassification and, thus, removes paths that do declassify the potentially sensitive data before its use [i.e., an escape analysis tool to verify]); or
executing a pointer analysis tool to verify that the application codebase does not write to at least a second portion of memory used by the annotated security protocol sensitive code (Krishnan: pars 0016, 0064-0065, the method then performs a pointer analysis on each program slice, from a starting point for the pointer analysis within the program slice, and to an ending point).
As to claim 6, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 5,
Sreedhar further teaches further comprising: annotating the security protocol sensitive code in the security protocol model codebase with one or more invariants of the security protocol model; and executing a software verifier to verify with at least the annotated security protocol sensitive code as input to prove that behavior of the security protocol sensitive code is contained within the security protocol model (Sreedhar: pars 0066, 0068, 0102, identifying and defining the consistency properties as code annotation, and the code annotation, used in extended escape analysis and pointer analysis. Par 0079, enables modeling of a complex hierarchical type state diagram by abstracting away detailed behavior into multiple levels).
As to claim7, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 6,
Sreedhar further teaches wherein the annotations are based at least in part on an input/output specification of the security protocol model (Sreedhar: pars 0066, 0068, 0102, identifying and defining the consistency properties as code annotation, and the code annotation, used in extended escape analysis and pointer analysis [i.e., input output flow of set of analysis of the security protocol model]).
As to claim 8, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 7,
Sreedhar further teaches wherein the annotations define a permission for an input or output operation in the annotated security protocol sensitive code (Sreedhar: pars 0061-0062, 0066, 0068, 0102, identifying and defining the consistency properties as code annotation, and the code annotation, used in extended escape analysis and pointer analysis. The role assignment method for code annotation includes permission level).
As to claim 9, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 6,
Sreedhar further teaches wherein the annotations define a permission for a portion of memory used by the annotated security protocol sensitive code (Sreedhar: pars 0061-0062, 0066, 0068, 0102, identifying and defining the consistency properties as code annotation, and the code annotation, used in extended escape analysis and pointer analysis. The role assignment method for code annotation includes permission level to the data object [i.e., to portion of memory]).
As to claim 10, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 6,
Krishnan and Sreedhar further teaches further comprising: receiving a definition of the security protocol model; and executing a model verifier with the definition of the security protocol model as an input to verify the security protocol model is secure with respect to one or more security properties (Sreedhar: pars 0066, 0068, 0102, identifying and defining the consistency properties as code annotation, and the code annotation, used in extended escape analysis and pointer analysis for verification [i.e., input output flow of set of analysis of the security protocol model]).
As to claim 11, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 10,
Sreedhar further teaches wherein the security protocol model includes operations to exchange a key over an open network (Sreedhar: pars 0071, for consistency, the values of the two data fields should use the same encryption/decryption keys).
As to claim 12, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 10,
Krishnan further teaches wherein the security protocol model includes operations to cryptographically sign a message (Sreedhar: pars 0071, for consistency, the values of the two data fields should use the same encryption/decryption keys).
As to claim 13, the combination of Krishnan and Sreedhar teaches the computer-implemented method of claim 4,
Krishnan further teaches wherein receiving the portion of the security protocol model codebase comprises downloading the portion of the security protocol model codebase as a distributable from the internet (Krishnan: par 0082, computing system can be located at a remote location and connected to the other elements over a network, and can be implemented on a distributed system).
As to claim 14, the claim is directed to a system and the scope of the claim limitations is similar to the scope of the method claim 4, and therefore, the claim is rejected for the same reason set forth above for claim 4.
As to claims 15-20, the claims are similar to the claims 5-10, respectively, and are rejected for the same reasons set forth above for claims 5-10.
Conclusion
Applicant’s amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Jahangir Kabir whose telephone number is (571) 270-3355. The examiner can normally be reached on 9:00- 5:00 Mon-Thu.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached on (571) 270-5002. The fax number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/uspto-automated- interview-request-air-form.
/JAHANGIR KABIR/ Primary Examiner, Art Unit 2439