DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-3, 5-14 and 16-21 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Smith et al. 20200242258 herein Smith.
Per claim 1, Smith discloses: generating a first memory key that maps a host address space from a first protection domain associated with the host node to a second protection domain associated with a proxy node; (fig. 17, ¶0089; interface 1700 receives a workload request with encrypted cipher text, interface 1700 determines if the workload request is permitted by performing an access check based on a certificate, and memory controller 1726 writes the encrypted cipher text into memory…. A workload can request a memory region read or write request or other actions (e.g., create, update, delete, or notify); the examiner notes that the key is merely an ID to the memory space) generating a second memory key based on the first memory key and a first address range associated with the host node; and transmitting the second memory key to a software component executing on the proxy node, wherein the software component causes a shared storage system to access a first portion of the physical memory based on the second memory key (¶0091; (A received workload can be signed by a tenant key (e.g., encrypted using a tenant key) and arrive with tenant certificate. A certificate can identify a tenant (e.g., peer 1750) in some cases. Management interfaces 1704 can use the received certificate to create an appropriate entry in a certification table 1706 and set an expiration (e.g., time to live (TTL)) for the entry).
Per claim 2, Smith discloses: generating a third memory key based on the first memory key and a second address range associated with the host node; and transmitting the third memory key to the software component, wherein the software component causes the shared storage system to access a second portion of the physical memory based on the third memory key (¶0091; (A received workload can be signed by a tenant key (e.g., encrypted using a tenant key) and arrive with tenant certificate. A certificate can identify a tenant (e.g., peer 1750) in some cases. Management interfaces 1704 can use the received certificate to create an appropriate entry in a certification table 1706 and set an expiration (e.g., time to live (TTL)) for the entry; the examiner notes that the third key is merely an iteration of the process in claim 1).
Per claim 3, Smith discloses: wherein the first portion of the physical memory comprises a first host buffer that corresponds to the first address range (¶0099; If the certificate provided with the request is valid, at Action C, by specification of an entry in configuration table 1708, target process 1722 associated with memory region [a,b] in buffer 1724 identifies initiator 1754 is trusted on platform 1720. At Action D, a “load/store” is performed at PASID p, offset o, in buffer 1724. At Action E, a translation of <p,o> to a page table entry (PTE) address (β)+sub-page block (y)+remainder (p) in in buffer 1724 occurs using page table 1710;).
Per claim 5, Smith discloses: further comprising storing the second memory key in a memory key cache based on the first address range prior to transmitting the second memory key to the software component (¶0094 and ¶0098; Page table 1710 can store mapping between virtual addresses and physical addresses. A page table entry in page table 1710 can convert a virtual address in configuration table 1708 to a physical addresses in buffer 1724. In some examples, validation and RDMA control 1702 can encrypt page table 1710 using one or more keys.).
Per claim 6, Smith discloses: further comprising failing to retrieve the second memory key from a memory key cache based on the first address range prior to generating the second memory key (¶0088; interface 1700 perform or include: (1) certification to store and manage certificates from sources accessing memory ranges within a local node and corresponding permissions based on received certificates; (2) validation of requests as well as memory access checks (e.g., within different ranges of a page of a local node); and (3) interfaces to manage certification and configuration in an out-of-band fashion or in-band fashion).
Per claim 7, Smith discloses: the shared storage system, the host node, and the proxy node are separate from one another, (fig. 20) and wherein the software component causes the shared storage system to access the first portion of the physical memory by causing a storage driver executing on the proxy node to transmit to the shared storage system a remote direct memory access request that specifies the first address range and the second memory key (fig. 17, ¶0090; management interfaces 1704 can be accessed both in-band (e.g., ring 0 or kernel mode) or out-of-band to configure certificates of peer PASIDs (e.g., tokens) of the systems and a list of peer PASIDS that can access to that memory as well as the type of protection being associated to that range. For example, in-band management can be from a dedicated set of control plane and management plane devices whereas out-of-band can include an orchestrator defining permitted interactions across platforms or nodes by specific processes, VMs or containers).
Per claim 8, Smith discloses: wherein the software component comprises a software application that resides in a user space (fig. 17, ¶0088; a tenant workload can be built into multiple processes, VMs, or containers that interact across platforms or nodes. For example, to continue operation across platforms or nodes, peer 1750 can send a workload to interface 1700. The architecture can be used in an interface 1700 (e.g., Host Fabric Interface or network interface card), for example. Various embodiments of interface 1700 perform or include: (1) certification to store and manage certificates from sources accessing memory ranges within a local node and corresponding permissions based on received certificates; (2) validation of requests as well as memory access checks (e.g., within different ranges of a page of a local node); and (3) interfaces to manage certification and configuration in an out-of-band fashion or in-band fashion).
Per claim 9, Smith discloses: wherein the second memory key includes one or more memory access attributes that enable at least one of remote write access or remote read access for the first portion of the physical memory (fig. 17, ¶0029; a memory controller to use a proper key (e.g., multiple key total memory encryption (MKTME) key) to read data from a memory region, decrypt the read data, modify the read data with received data, encrypt the modified data and write the encrypted modified data to the memory region).
Per claim 10, Smith discloses: wherein the shared storage system comprises at least one of shared file storage, shared block storage, or object storage (¶0134; The system can use embodiments described herein to share memory region access and one or more keys with an initiator.).
Per claim 11, Smith discloses: wherein at least the generating the second memory key is implemented via a service ( ¶0127; An SGX security model may use an architectural enclave such as a Platform Configuration Enclave (PCE) or a Platform Services Enclave (PSE) to allow access to SGX protected PAS pages).
Claims 12-13, and15-19 are the CRM claims corresponding to the method claims 1-3 and 5-8 and are rejected under the same reasons set forth in connection with the rejection of claims 1-8.
Per claim 14, Smith discloses: wherein the second memory key comprises a remote key that is subordinate to the first memory key ( ¶0092-93; In some examples, a tenant can be identified by a node identifier (Node ID) and a local Process Address Space ID (PASID). A local PASID can be used by interface 1700 and platform 1720 to identify the tenant and the local PASID can be assigned irrespective of a PASID of the tenant assigned by a different device….. An entry in certification table 1706 can also include a “Token” that is signed by an attestation provider. An attestation provider could be an issuer of the certificate presented with the workload request. The token could be an indication by interface 1700 to permit access by peer 1750 to a memory region in platform 1720 after performing an attestation protocol with peer 1750. An entry in certification table 1706 can include a key or keys (e.g., MKTME keys) for use to access a memory region using a memory controller (MC) 1726; the examiner notes that subordinate is interpreted as associated with).
Per claim 20, Smith discloses: wherein the second memory key includes an attribute indicating that the second memory key is subordinate to the first memory key ( ¶0092-93; In some examples, a tenant can be identified by a node identifier (Node ID) and a local Process Address Space ID (PASID). A local PASID can be used by interface 1700 and platform 1720 to identify the tenant and the local PASID can be assigned irrespective of a PASID of the tenant assigned by a different device….. An entry in certification table 1706 can also include a “Token” that is signed by an attestation provider. An attestation provider could be an issuer of the certificate presented with the workload request. The token could be an indication by interface 1700 to permit access by peer 1750 to a memory region in platform 1720 after performing an attestation protocol with peer 1750. An entry in certification table 1706 can include a key or keys (e.g., MKTME keys) for use to access a memory region using a memory controller (MC) 1726).
Claim 21 is the system claim corresponding to the method claim 1 and is rejected under the same reasons set forth in connection with the rejection of claim 1.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 4 and 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Smith in view of An et al. 20180241549 herein An.
Per claim 4, Smith does not specifically disclose: wherein the first memory key comprises a cross domain memory key and is generated using both a host memory key associated with the host address space and a proxy memory key associated with a proxy address space that corresponds to the second protection domain
However, An discloses: wherein the first memory key comprises a cross domain memory key and is generated using both a host memory key associated with the host address space and a proxy memory key associated with a proxy address space that corresponds to the second protection domain (fig. 1. Abstract; The key generation method comprises: encrypting a first key factor generated by a first device with an initial key, and sending the encrypted first key factor to a second device through a first secure channel, wherein the initial key is a key preset for the first device and the second device; receiving, through the first secure channel, a second key factor encrypted with the initial key, wherein the second key factor is generated by the second device; decrypting the second key factor encrypted with the initial key and received through the first secure channel, so as to obtain the second key factor; and generating a shared key between the first device and the second device according to the first key factor and the second key factor. See ¶00116; cross-domain key negotiation and sharing between a terminal device and a server through a gateway device as an intermediate node. A shared key is unknown to the gateway device, thereby ensuring end-to-end secure transmission of Internet of Things data between the terminal device and the server. Additionally, secure data transmission between the terminal device and the gateway device, and secure data transmission between the gateway device and the public network server are ensured).
It would have been obvious to one having ordinary skill in the art at the effective filing date of the invention to combine the teachings of Smith and An’s double encryption key generation method to reduce the risk of data being captured illegally. An ensures the security of data transmission (Abstract).
Claim 15 is the CRM claim corresponding to the method claim 4 and is rejected under the same reasons set forth in connection with the rejection of claim 4.
Response to Arguments
Applicant's arguments filed 8/21/26 have been fully considered but they are not persuasive.
The applicant argues: In the rejections, the Examiner maps the first memory key, recited in prior claim 1, to the identifier for the entire memory region in Smith being accessed; and the host node, recited in prior claim 1, to the memory region in Smith being accessed. The Examiner further maps the second memory key, recited in prior claim 1, to the tenant certificate signed with the tenant key disclosed in Smith; and the proxy node, recited in prior claim 1, to the tenant device in Smith that is transmitting the workload request in order to access the memory region. See Final Office Action at pp. 2-3; see also Advisory Action at p. 2. Based on these claim mappings, to teach or suggest the above limitations of amended claim 1, Smith would have to disclose that the tenant certificate signed with the tenant key is generated based on the identifier of the entire memory region being accessed. Smith also would have to disclose that the tenant certificate indicates one particular address range that corresponds to a portion of the memory region being accessed, where the tenant certificate enables the indicated address range in the portion of the memory region to be accessed. Importantly, Smith contains no such teachings.
In that regard, Smith discloses only that the tenant certificate that is signed with the tenant key identifies the tenant device making the request, so that the tenant device can be verified before allowing the tenant device to access the memory region. Notably, nowhere does Smith teach or otherwise suggest that the tenant certificate is generated based on the identifier for the entire memory region being accessed, where the tenant certificate identifies a particular address range corresponding to a portion of the memory region to be accessed. Such teachings are required to meet the above limitations of amended claim 1. Further, in Smith, the only security measure limiting access to the memory region is a time to live (I I L) field in the tenant certificate. This field limits the lifespan of the tenant certificate in order to reduce/limit unauthorized access to the memory region if the tenant certificate is ever compromised. See Smith at [0091]. Notably, Smith fails to disclose or suggest that the tenant certificate includes any kind of indication of a specific address range for only a portion of the memory region that the tenant device can access. Such teachings also are required to meet the amended claim language. In view of at least these distinctions, Applicant submits that Smith cannot be properly interpreted as teaching or suggesting the above limitations of amended claim 1.
The examiner respectfully disagrees and asserts that Smith discloses generating a second memory key based on the first memory key, wherein the second memory key indicates a first address range that is associated with the host node and corresponds to a portion of the host address space, and wherein the second memory key enables the first address range to be accessed. First, the examiner notes that the claim requires that the second memory key is generated based on the first key. The claim does not set forth how the key is generated based on the first key other than identifying the host address space. Further the second key indicates/points to an address range within the host address space. That is the second key protects an area in the assigned host address space. Smith discloses a PSAID is used to identify the tenant and a corresponding certificate/token in the certification table is used to authenticate to a corresponding memory region. Also, corresponding keys can be used in the certification table to access the memory region. See ¶0091 & ¶0099. The tenant key generated is based on identifier, certificate and memory address region. Therefore, Smith discloses generating a second memory key based on the first memory key, wherein the second memory key indicates a first address range that is associated with the host node and corresponds to a portion of the host address space.
In response to applicant's argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., the only security measure limiting access to the memory region is a time to live (I I L) field in the tenant certificate. This field limits the lifespan of the tenant certificate in order to reduce/limit unauthorized access to the memory region if the tenant certificate is ever compromised. See Smith at [0091]. Notably, Smith fails to disclose or suggest that the tenant certificate includes any kind of indication of a specific address range for only a portion of the memory region that the tenant device can access.) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993).
Remark
Examiner respectfully requests, in response to this Office action, support be shown for language added to any original claims on amendment and any new claims. That is, indicate support for newly added claim language by specifically pointing to page(s) and line number(s) in the specification and/or drawing figure(s). This will assist Examiner in prosecuting the application.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BABOUCARR FAAL whose telephone number is (571)270-5073. The examiner can normally be reached M-F 8:30-5:30 EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Tim VO can be reached at 5712723642. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
BABOUCARR . FAAL
Primary Examiner
Art Unit 2138
/BABOUCARR FAAL/Primary Examiner, Art Unit 2138