DETAILED ACTION
This communication responsive to the Application No. 18/936,073 filed on 06/05/2026. Claims 1-18,25,26 are pending and are directed towards DEBUGGING METHOD, ELECTRONIC APPARATUS, AND COMPUTER READABLE STORAGE MEDIUM
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to arguments
Applicants’ argument regarding inherency of “dependent upon the private key” vs “dependent on the device public key”. Applicant’s Ex parte Levy argument treats Buskey’s Abstract in isolation but claims in Buskey remove any inherency gap. Buskey’s claim 12 recites that the verification module is operable to encrypt the random number and level into a challenge phrase using a public key corresponding to a private key of the embedded device stored on a secure server and operable to verify response. Claim 17 (a system claim) confirms this same pairing: the secure server stores “a private key of the embedded device” corresponding to the public key of the embedded device and issues the response to the challenge phrase dependent upon the private key of the embedded device, where the challenge phrase itself is expressly a “cipher… encoded with a public key” (claim 20). Combined together, Buskey’s claims establish, as a matter of the reference’s express disclosure, that: (1) the challenge is encrypted using the device’s public key, and (2) the server’s response is generated by operating on that same challenge using the mathematically corresponding private key. A response that is cryptographically derived from a challenge which was itself encoded with the public key is necessarily a function of that public key which is exactly the basis in fact and technical reasoning Ex parte Levy requires and it comes from claims 12, 17 and 20 not from speculation about generic PKI theory. Accordingly, the examiner’s characterization that the response is dependent on the device public key is supported by Buskey’s own claim language reciting the challenge/response pair as two ends of the same public key/private key operation.
Applicants’ argument regarding location of generation by the debugged device and sending from the debugged device, has been considered and are moot because applicants’ amendment to generate target encrypted information, changed the scope necessitating new grounds of rejection. A new reference Le Saint et al. (US 20160241389 A1) has been introduced to disclose a server sending encrypted credential data to a client and using a cryptographic nonce with a server public key to support secure credential provisioning.
Regarding claim 7, applicant argues that the examiner cited the device/ access manager rather than a distinct system. Examiner disagrees. Buskey discloses a secure server (element 120) that is structurally and functionally separate from the embedded device as it stores private keys, authenticates credentials and generates the challenge response, communicating with the device only via the JTAG Manager. This server independently satisfies the “computer system distinct from a debugged device” limitation. Trantham’s networked key server (505), which validates credentials and cryptographically signs the response before returning it to the device side, provides an additional, independent basis for the same limitation.
Hence, for all the above reasons the rejection is maintained, with the citation pointing to Buskey’s secure server (120) rather than the access manager.
Suggested amendments: To sharpen the distinction over the combination, consider amending claim 1 to recite that the debugged device generates the target encrypted information using key material stored exclusively at the debugged device, without transmitting the credential information to a remote server for encryption/response generation, and that the debugged device’s AEAD encryption step is performed by on-device cryptographic logic independent of any secure server. This provides a distinction between the claim and the references. Trantham’s debugger still obtains its signed response from a remote key server (505) before the DUT validates it. So, linking the generation step of the AEAD encrypted information, not just verification, exclusively to on-device processing with no server signed credential in the loop, would help overcome the cited prior art of record.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. — An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in Support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
Claims 13-18 in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AlA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “unit”, “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non- structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for’) or another linking word or phrase, such as “configured to” or “so that’; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means’ (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “unit” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “unit” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
This application includes one or more claim limitations that do not use the word “means” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AlA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: “a target encrypted information acquisition unit”, “debugging right enabling unit” and “an information transceiving unit” in claims 13-18.
Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may:
(1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or
(2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1,2,7,8,12-14,25 and 26 are rejected under 35 U.S.C. 103 as being unpatentable over Buskey et al. (US 20070162759 A1), hereinafter referred to as Buskey, in view of Trantham et al. (US 20190361073 A1), hereinafter referred to as Trantham in further view of Le Saint et al. (US 20160241389 A1).
As per claim 1, Buskey discloses a debugging method, comprising:
sending an identifier (ID) of a debugged device to a client in response to receiving a debugging request from the client; (Issuing a challenge phrase and a device identifier to the user device in response to the authorization request, Buskey, Claim 1)
receiving, at the debugged device, from the client, a public key corresponding to the ID of the debugged device and credential information; (The access manager issues a challenge phrase using a public key of the embedded device in response to a request by a user device, Buskey, Abstract).
However, Buskey does not explicitly disclose the limitation:
receiving, at the debugged device, encrypted debugging control information from the client, the encrypted debugging control information being generated based on the target encrypted information; and
enabling a debugging right in response to receiving the encrypted debugging control information.
Trantham discloses:
receiving, at the debugged device, encrypted debugging control information from the client, the encrypted debugging control information being generated based on the target encrypted information; and (The debugger may respond to the random challenge message with a signed authentication response, Trantham, para [0005]. Here, encrypted debugging control information corresponds to the signed authentication response retuned by the debugger and loaded into the register)
enabling a debugging right in response to receiving the encrypted debugging control information (Closing the control switch may allow the debugger full access to the protected electronics of the electronic device, Trantham, para [0005]. Here, enabling a debugging right corresponds to closing the control switch so that the debugger has full debug access, which is only done in response to receiving and validating the signed authentication response. The reception and successful authentication of this cryptographic control information conditions whether the debug interface becomes accessible, i.e., whether the debugging right is granted).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey with Trantham by protected port for access to a device (Buskey) with secure debug system for devices (Trantham). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey with Trantham in order to ensure security of a device is in closed state (See Trantham, para [0005])
However, Buskey in view of Trantham does not explicitly disclose the limitations:
generating, by the debugged device, target encrypted information by executing
sending the target encrypted information from the debugged device to the client, wherein the received credential information is generated based on a user credential and a challenge value corresponding to the received public key;
Le Saint discloses:
generating, by the debugged device, target encrypted information by ("FIG. 10 illustrates an example process 1000 for encrypting a message" Le Saint, para [0166]) executing ("AEAD", "sender public key", "receiver key identifier" or "payload encryption key" as credential, Le Saint, para [0175]).
sending the target encrypted information from the debugged device to the client, wherein the received credential information is generated based on a user credential and a challenge value corresponding to the received public key; (At block 408, the response message is sent to the client computer. The response message includes the encrypted response data, Le Saint, para [0120]. The response data can include encrypted credential data, a cryptographic nonce, a blinded server public key can be received from server computer, Le Saint, para [0130]. Here, the credential information to encrypted credential data and the challenge value corresponding to the received public key)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey with Trantham by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) with confidential communication management (Le Saint). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey and Trantham with Le Saint in order to securely provision credential information to a client by combining encryption with a nonce and public key based authentication mechanism (See Le Saint, para [0175])
As per claim 2, Buskey, Trantham and Le Saint discloses the debugging method of claim 1, wherein the generating executing
Furthermore, Trantham discloses:
verifying the received public key based on pre-stored public key information; and (The DUT may use an internally-stored public key to decrypt the response data and to confirm that the random number matches the number originally sent, Trantham, para [0032]. Here, the device may store a root public key and verify a certificate received from an external device using the stored root public key)
generating by executing (Upon successful authentication the device establishes a secure session and encrypts debug communications using an authenticated encryption mode, Trantham, claim 2. AES GCM is used to provide authenticated encryption of debug data)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey with Trantham by protected port for access to a device (Buskey) with secure debug system for devices (Trantham). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey with Trantham in order to ensure security of a device is in closed state (See Trantham, para [0005])
As per claim 7, Buskey discloses a debugging method, comprising:
obtaining, by a computer system distinct from a debugged device, a public key corresponding to an identifier (ID) of the [[a]] debugged device; receiving, from a client, the ID of the debugged device; (The access manager issues a challenge phrase using a public key of the embedded device in response to a request by a user device to access the embedded device, Buskey, Abstract)
generating, by the computer system, a challenge value corresponding to the public key in response to receiving the ID of the debugged device; (Access Manager 114 composes a message from a random number and the requested protection level information and encodes it into the challenge phrase, Buskey, para [0036])
sending the public key and the challenge value from the computer system to the client; (Along with the challenge, the device sends its ID, by which the secure server determines which key to use to generate response, Buskey, para [0038]).
However, Buskey does not explicitly disclose the limitations:
receiving, by the computer system, target encrypted information from the client;
verifying, by the computer system, the decrypted credential information; and
generating, by the computer system, encrypted debugging control information and sending the encrypted debugging control information from the computer system to the client in response to a determination that the verification of the decrypted credential information is successful, wherein the encrypted debugging control information indicates that the debugged device connected to the client has enabled a debugging right.
Trantham discloses:
receiving, by the computer system, target encrypted information from the client; (The control module 305, in conjunction with the debugger, may use a private key to cryptographically sign the random challenge message and the communication module 315 may then send the signed random challenge message to the authentication logic, Trantham, para [0050]).
verifying, by the computer system, the decrypted credential information; and (The DUT may use an internally-stored public key to decrypt the response data and to confirm that the random number matches the number originally sent, Trantham, para [0032]).
generating, by the computer system, encrypted debugging control information and sending the encrypted debugging control information from the computer system to the client in response to a determination that the verification of the decrypted credential information is successful, wherein the encrypted debugging control information indicates that the debugged device connected to the client has enabled a debugging right (The debugger may respond to the random challenge message with a signed authentication response, Trantham, para [0005]. Here, encrypted debugging control information corresponds to the signed authentication response retuned by the debugger and loaded into the register. (Closing the control switch may allow the debugger full access to the protected electronics of the electronic device, Trantham, para [0005]. Here, enabling a debugging right corresponds to closing the control switch so that the debugger has full debug access, which is only done in response to receiving and validating the signed authentication response. The reception and successful authentication of this cryptographic control information conditions whether the debug interface becomes accessible, i.e., whether the debugging right is granted).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey with Trantham by protected port for access to a device (Buskey) with secure debug system for devices (Trantham). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey with Trantham in order to ensure security of a device is in closed state (See Trantham, para [0005]).
However, Buskey in view of Trantham does not explicitly disclose the limitation:
generating, by the computer system, decrypted credential information by executing [[using]] an Authenticated Encryption with Associated Data (AEAD} decryption algorithm based on the target encrypted information in response to receiving the target encrypted information;
Le Saint discloses:
generating, by the computer system, decrypted credential information by executing [[using]] an Authenticated Encryption with Associated Data (AEAD} decryption algorithm based on the target encrypted information in response to receiving the target encrypted information; ("FIG. 10 illustrates an example process 1000 for encrypting a message" Le Saint, para [0166]) executing ("AEAD", "sender public key", "receiver key identifier" or "payload encryption key" as credential, Le Saint, para [0175]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey with Trantham by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) with confidential communication management (Le Saint). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey and Trantham with Le Saint in order to securely provision credential information to a client by combining encryption with a nonce and public key based authentication mechanism (See Le Saint, para [0175])
As per claim 8, Buskey, Trantham and Le Saint disclose the debugging method of claim 7, wherein the target encrypted information comprises encrypted credential information and ciphertext, and the generating by executing [[using]] the AEAD decryption algorithm based on the target encrypted information comprises:
Furthermore, Trantham discloses:
obtaining a private key corresponding to the public key, and generating a second key using a key encapsulation mechanism based on the private key and the ciphertext; and performing AEAD decryption on the encrypted credential information by using the second key to obtain the decrypted credential information (Upon successful authentication the device establishes a secure session and encrypts debug communications using an authenticated encryption mode, Trantham, claim 2. AES GCM is used to provide authenticated encryption of debug data)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey with Trantham by protected port for access to a device (Buskey) with secure debug system for devices (Trantham). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey with Trantham in order to ensure security of a device is in closed state (See Trantham, para [0005])
As per claim 12, Buskey, Trantham and Le Saint disclose the debugging method of claim 8, wherein
Furthermore, Buskey discloses:
the decrypted credential information is generated based on a user credential and the challenge value, and the second key is a same key as a first key generated by using the key encapsulation mechanism based on the public key (The secure server 120 is loaded with the private keys associated with devices IDs and user credentials. The credential verification procedure implemented on the server grants the correct response to the challenge provided by the user thus the requested protection level will be granted by device to the user authorized to obtain this level, Buskey, para [0049]).
As per claim 13, Buskey, Trantham and Le Saint disclose an electronic apparatus of a debugged device, comprising:
an information transceiving unit, configured to send an identifier (ID) of the [[a]] debugged device to a client in response to receiving a debugging request from the client; (Issuing a challenge phrase and a device identifier to the user device in response to the authorization request, Buskey, Claim 1).
a target encrypted information acquisition unit, configured to receive, from the client, a public key corresponding to the ID and credential information, generate executing (A secure server stores a private key corresponding to the public encryption key of the embedded device and is operable to authenticate the user credentials and issues the response to the challenge phrase dependent upon the private key of the embedded device, Buskey, Abstract, The secure server uses cryptography to authenticate the user credentials and issues the response to the challenge phrase. That server-generated response to the challenge phrase is a cryptographically formed value dependent on the device public key and user credentials which serve as the target encrypted information).
However, Buskey does not explicitly disclose the limitation:
a debugging right enabling unit, configured to receive encrypted debugging control information from the client, the encrypted debugging control information being generated based on the target encrypted information, and enable a debugging right in response to receiving the encrypted debugging control information.
Trantham discloses:
a debugging right enabling unit, configured to receive encrypted debugging control information from the client, the encrypted debugging control information being generated based on the target encrypted information, and enable a debugging right in response to receiving the encrypted debugging control information (The debugger may respond to the random challenge message with a signed authentication response, Trantham, para [0005]. Here, encrypted debugging control information corresponds to the signed authentication response retuned by the debugger and loaded into the register. Closing the control switch may allow the debugger full access to the protected electronics of the electronic device, Trantham, para [0005]. Here, enabling a debugging right corresponds to closing the control switch so that the debugger has full debug access, which is only done in response to receiving and validating the signed authentication response. The reception and successful authentication of this cryptographic control information conditions whether the debug interface becomes accessible, i.e., whether the debugging right is granted).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey with Trantham by protected port for access to a device (Buskey) with secure debug system for devices (Trantham). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey with Trantham in order to ensure security of a device is in closed state (See Trantham, para [0005]).
As per claim 14, Buskey, Trantham and Le Saint discloses the electronic apparatus of claim 13, wherein the target encrypted information acquisition unit is configured to:
Furthermore, Trantham discloses:
verify the received public key based on pre-stored public key information; and (The DUT may use an internally-stored public key to decrypt the response data and to confirm that the random number matches the number originally sent, Trantham, para [0032]. Here, the device may store a root public key and verify a certificate received from an external device using the stored root public key)
generate by executing (Upon successful authentication the device establishes a secure session and encrypts debug communications using an authenticated encryption mode, Trantham, claim 2. AES GCM is used to provide authenticated encryption of debug data)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey with Trantham by protected port for access to a device (Buskey) with secure debug system for devices (Trantham). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey with Trantham in order to ensure security of a device is in closed state (See Trantham, para [0005])
As per claim 25, Buskey, Trantham and Le Saint discloses an electronic apparatus, comprising:
Furthermore, Buskey discloses:
at least one memory storing computer executable instructions; and at least one processor, configured to execute the computer executable instructions to perform the debugging method of claim 1 (Processor 100, Buskey, para [0015])
As per claim 26, Buskey, Trantham and Le Saint discloses a computer readable storage medium storing computer executable instructions that, when executed by at least one processor,
Furthermore, Buskey discloses:
cause the at least one processor to perform the debugging method of claim 1 (Processor 100, Buskey, para [0015])
Claims 3-6,9-11,15-18 are rejected under 35 U.S.C. 103 as being unpatentable over Buskey et al. (US 20070162759 A1), hereinafter referred to as Buskey, in view of Trantham et al. (US 20190361073 A1), hereinafter referred to as Trantham in further view of Le Saint et al. (US 20160241389 A1), in further view of Saarinen et al. (US 20220066741 A1), hereinafter referred to as Saarinen
As per claim 3, Buskey, Trantham and Le Saint disclose the debugging method of claim 2, wherein the generating executing
However, Buskey, Trantham and Le Saint does not explicitly disclose the limitations:
generating a first key and corresponding ciphertext by using a key encapsulation mechanism based on the received public key;
performing AEAD encryption on the received credential information according to the first key to obtain encrypted credential information; and
using the encrypted credential information and the corresponding ciphertext as the target encrypted information
Saarinen discloses:
generating a first key and corresponding ciphertext by using a key encapsulation mechanism based on the received public key; (Terminals 300 access a common shared secret key 305, Saarinen, para [0057])
performing AEAD encryption on the received credential information according to the first key to obtain encrypted credential information; and (Fig 3 comprises an implementation of authenticated encryption with associated data (AEAD). The first terminal encrypts the data using the secret key and use associated data to generate an authentication tag, Saarinen, para [0057]- [0059])
using the encrypted credential information and the corresponding ciphertext as the target encrypted information (The encrypted data and the authentication tag may be combined as a ciphertext payload, Saarinen, para [0061]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey and Trantham with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey and Trantham with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061])
As per claim 4, Buskey, Trantham and Le Saint discloses the debugging method of claim 3, wherein the performing of AEAD encryption on the credential information according to the first key, comprises:
However, Buskey, Trantham and Le Saint does not explicitly disclose the limitations:
encrypting the credential information according to the first key and first preset associated data to obtain the encrypted credential information, wherein the first preset associated data indicates that the encrypted credential information comes from the debugged device
Saarinen discloses:
encrypting the credential information according to the first key and first preset associated data to obtain the encrypted credential information, wherein the first preset associated data indicates that the encrypted credential information comes from the debugged device (Use associated data to generate an authentication tag. The associated data may compromise an IP address, public data such as firmware update number or manufacturer data, Saarinen, para [0061]. Here, AD containing source-identifying/context fields are cryptographically bound via AEAD)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey and Trantham with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey, Trantham and Le Saint with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061]).
As per claim 5, Buskey, Trantham and Le Saint discloses the debugging method of claim 3, wherein the enabling of the debugging right in response to receiving the encrypted debugging control information from the client, comprises:
However, Buskey, Trantham and Le Saint does not explicitly disclose the limitations:
performing AEAD decryption on the encrypted debugging control information according to the first key to obtain decrypted debugging control information, and enabling the debugging right according to the decrypted debugging control information
Saarinen discloses:
performing AEAD decryption on the encrypted debugging control information according to the first key to obtain decrypted debugging control information, (The decryption system is configured to decrypt the encrypted data and to conditionally supply decrypted data. The supply may be conditional on a successful decryption and/or an integrity check. The integrity check may comprise comparing the copy of the associated data with the authentication tag, Saarinen, para [0062]) and enabling the debugging right according to the decrypted debugging control information (If the decrypted data comprises a firmware update, this may only be installed if the decryption is successful and the integrity check is passed, Saarinen, para [0062]. Here, install is the example post-decrypt action and corresponds to enabling debugging right being performed only after successful AEAD decrypt/ integrity)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey and Trantham with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey and Trantham with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061])
As per claim 6, Buskey, Trantham and Le Saint discloses the debugging method of claim 5, wherein the enabling of the debugging right according to the decrypted debugging control information, comprises:
However, Buskey, Trantham and Le Saint does not explicitly disclose the limitations:
enabling the debugging right according to the decrypted debugging control information, in response to obtaining, from the encrypted debugging control information, second preset associated data indicating that the encrypted debugging control information comes from a legitimate source
Saarinen discloses:
enabling the debugging right according to the decrypted debugging control information, in response to obtaining, from the encrypted debugging control information, second preset associated data indicating that the encrypted debugging control information comes from a legitimate source (The transceiver may also pass a copy of the associated data used to generate the authentication tag. The integrity check may comprise comparing the copy of the associated data with the authentication tag. If not passed, then the decrypted data may not be released, Saarinen, para [0062]. Legitimate source is enforced by requiring the AEAD verification to pass before releasing/ using the decrypted control information).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey and Trantham with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey and Trantham with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061])
As per claim 9, Buskey, Trantham and Le Saint discloses the debugging method of claim 8, wherein the performing of the AEAD decryption on the encrypted credential information by using the second key to obtain the decrypted credential information, comprises:
However, Buskey, Trantham and Le Saint does not explicitly disclose the limitations:
obtaining first preset associated data contained in the encrypted credential information; and
decrypting the encrypted credential information using the second key to obtain the decrypted credential information, in response to a determination that the first preset associated data indicates that the encrypted credential information comes from the debugged device
Saarinen discloses:
obtaining first preset associated data contained in the encrypted credential information; and (For a fixed-size cryptographic state, i.e. b bits, a rate of the AEAD systems may be set as r-bits, Saarinen, para [0077]).
decrypting the encrypted credential information using the second key to obtain the decrypted credential information, in response to a determination that the first preset associated data indicates that the encrypted credential information comes from the debugged device (Use associated data to generate an authentication tag. The associated data may compromise an IP address, public data such as firmware update number or manufacturer data, Saarinen, para [0061]. Here, AD containing source-identifying/context fields are cryptographically bound via AEAD).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey, Trantham and Le Saint with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) and Le Saint with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey, Trantham and Le Saint with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061])
As per claim 10, Buskey, Trantham and Le Saint discloses the debugging method of claim 8, wherein the generating of the encrypted debugging control information comprises:
obtaining corresponding debugging control information based on the decrypted credential information; and (The debugger may respond to the random challenge message with a signed authentication response, Trantham, para [0005]. Here, encrypted debugging control information corresponds to the signed authentication response retuned by the debugger and loaded into the register. (Closing the control switch may allow the debugger full access to the protected electronics of the electronic device, Trantham, para [0005]. Here, enabling a debugging right corresponds to closing the control switch so that the debugger has full debug access, which is only done in response to receiving and validating the signed authentication response. The reception and successful authentication of this cryptographic control information conditions whether the debug interface becomes accessible, i.e., whether the debugging right is granted).
However, Buskey, Trantham and Le Saint does not explicitly disclose the limitation:
performing AEAD encryption on the corresponding debugging control information according to the second key to generate the encrypted debugging control information
Saarinen discloses:
performing AEAD encryption on the corresponding debugging control information according to the second key to generate the encrypted debugging control information (Fig 3 comprises an implementation of authenticated encryption with associated data (AEAD). The first terminal encrypts the data using the secret key and use associated data to generate an authentication tag, Saarinen, para [0057]- [0059]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey and Trantham with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) and Le Saint with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey, Trantham and Le Saint with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061])
As per claim 11, Buskey and Trantham disclose the debugging method of claim 10, wherein the performing of the AEAD encryption on the corresponding debugging control information according to the second key to generate the encrypted debugging control information, comprises:
However, Buskey, Trantham and Le Saint does not explicitly disclose the limitations:
encrypting the corresponding debugging control information according to the second key and second preset associated data to generate the encrypted debugging control information, wherein the second preset associated data indicates that the encrypted debugging control information comes from a preset server responsible for granting a user the debugging right, wherein the computer system comprises the preset server.
Saarinen discloses:
encrypting the corresponding debugging control information according to the second key and second preset associated data to generate the encrypted debugging control information, wherein the second preset associated data indicates that the encrypted debugging control information comes from a preset server responsible for granting a user the debugging right, wherein the computer system comprises the preset server. (The transceiver may also pass a copy of the associated data used to generate the authentication tag. The integrity check may comprise comparing the copy of the associated data with the authentication tag. If not passed, then the decrypted data may not be released, Saarinen, para [0062]. Legitimate source is enforced by requiring the AEAD verification to pass before releasing/ using the decrypted control information).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey, Trantham and Le Saint with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) and Le Saint with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey, Trantham and Le Saint with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061])
As per claim 15, Buskey, Trantham and Le Saint discloses the electronic apparatus of claim 14, wherein the target encrypted information acquisition unit is further configured to:
However, Buskey, Trantham and Le Saint does not explicitly disclose the limitations:
generate a first key and corresponding ciphertext by using a key encapsulation mechanism based on the public key;
perform AEAD encryption on the received credential information according to the first key to obtain encrypted credential information; and
use the encrypted credential information and the corresponding ciphertext as the target encrypted information.
Saarinen discloses:
generate a first key and corresponding ciphertext by using a key encapsulation mechanism based on the public key; (Terminals 300 access a common shared secret key 305, Saarinen, para [0057]).
perform AEAD encryption on the received credential information according to the first key to obtain encrypted credential information; and (Fig 3 comprises an implementation of authenticated encryption with associated data (AEAD). The first terminal encrypts the data using the secret key and use associated data to generate an authentication tag, Saarinen, para [0057]- [0059]).
use the encrypted credential information and the corresponding ciphertext as the target encrypted information (The encrypted data and the authentication tag may be combined as a ciphertext payload, Saarinen, para [0061]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey, Trantham and Le Saint with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) and Le Saint with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey, Trantham and Le Saint with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061])
As per claim 16, Buskey, Trantham and Le Saint discloses the electronic apparatus of claim 15, wherein the target encrypted information acquisition unit is further configured to:
However, Buskey, Trantham and Le Saint does not explicitly disclose the limitations:
encrypt the received credential information according to the first key and first preset associated data to obtain the encrypted credential information, wherein the first preset associated data indicates that the encrypted credential information comes from the debugged device
Saarinen discloses:
encrypt the received credential information according to the first key and first preset associated data to obtain the encrypted credential information, wherein the first preset associated data indicates that the encrypted credential information comes from the debugged device (Use associated data to generate an authentication tag. The associated data may compromise an IP address, public data such as firmware update number or manufacturer data, Saarinen, para [0061]. Here, AD containing source-identifying/context fields are cryptographically bound via AEAD)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey and Trantham with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) and Le Saint with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey, Trantham and Le Saint with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061])
As per claim 17, Buskey, Trantham and Le Saint discloses the electronic apparatus of claim 15, wherein the debugging right enabling unit is configured to:
However, Buskey in view of Trantham does not explicitly disclose the limitations:
perform AEAD decryption on the encrypted debugging control information according to the first key to obtain decrypted debugging control information, debugging right according to the decrypted debugging control information
Saarinen discloses:
perform AEAD decryption on the encrypted debugging control information according to the first key to obtain decrypted debugging control information, (The decryption system is configured to decrypt the encrypted data and to conditionally supply decrypted data. The supply may be conditional on a successful decryption and/or an integrity check. The integrity check may comprise comparing the copy of the associated data with the authentication tag, Saarinen, para [0062]) and enable the debugging right according to the decrypted debugging control information (If the decrypted data comprises a firmware update, this may only be installed if the decryption is successful and the integrity check is passed, Saarinen, para [0062]. Here, install is the example post-decrypt action and corresponds to enabling debugging right being performed only after successful AEAD decrypt/ integrity).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey and Trantham with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) and Le Saint with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey and Trantham with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061])
As per claim 18, Buskey, Trantham and Le Saint discloses the electronic apparatus of claim 17, wherein the debugging right enabling unit is further configured to:
However, Buskey in view of Trantham does not explicitly disclose the limitations:
enable the debugging right according to the decrypted debugging control information, in response to obtaining, from the encrypted debugging control information, second preset associated data indicating that the encrypted debugging control information comes from a legitimate source from the encrypted debugging control information
Saarinen discloses:
enable the debugging right according to the decrypted debugging control information, in response to obtaining, from the encrypted debugging control information, second preset associated data indicating that the encrypted debugging control information comes from a legitimate source from the encrypted debugging control information (The transceiver may also pass a copy of the associated data used to generate the authentication tag. The integrity check may comprise comparing the copy of the associated data with the authentication tag. If not passed, then the decrypted data may not be released, Saarinen, para [0062]. Legitimate source is enforced by requiring the AEAD verification to pass before releasing/ using the decrypted control information).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Buskey and Trantham and Le Saint with Saarinen by protected port for access to a device (Buskey) and secure debug system for devices (Trantham) and Le Saint with cryptography using a cryptographic state (Saarinen). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Buskey and Trantham with Saarinen in order to effectively perform cryptographic operations by providing functions such as encryption and decryption (See Saarinen, para [0061])
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to RAGHAVENDER CHOLLETI whose telephone number is (703) 756-1065. The examiner can normally be reached M-F 9am-5pm ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, RUPAL DHARIA can be reached on (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Respectfully submitted,
/RAGHAVENDER NMN CHOLLETI/Examiner, Art Unit 2492
/MICHAEL W CHAO/Primary Examiner, Art Unit 2492