Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 are pending.
This is in response to communications filed on 11/21/24.
Claim Objections
Claims 14-20 are objected to because of the following informalities:
Claim 14 recites –the IHS—in line 10, which lacks antecedent basis. Claims 15-20 depend on claim 14 and incorporate the informalities by virtue of dependency. Appropriate correction is required.
Claim Interpretation
The broadest reasonable interpretation of a method (or process) claim having contingent limitations requires only those steps that must be performed and does not include steps that are not required to be performed because the condition(s) precedent is not met. If the condition for performing a contingent step is not satisfied, the performance recited by the step need not be carried out in order for the claimed method to be performed. See Ex Parte Schulhauser. For example, assume a method claim requires step A if a first condition happens and step Bif a second condition happens. If the claimed invention may be practiced without either the first or second condition happening, then neither step A or B is required by the broadest reasonable interpretation of the claim. If the claimed invention requires the first condition to occur, then the broadest reasonable interpretation of the claim requires step A. If the claimed invention requires both the first and second conditions to occur, then the broadest reasonable interpretation of the claim requires both steps A and B (MPEP 2111.04).
Claim 14 is the method claim that recites “determining, … in response to determining that the first initialization hash value matches the second initialization hash value.” The limitation in response to determining that the first initialization hash value matches the second initialization hash value is not a required condition to occur. Therefore, the BRI does not include steps corresponding to the conditions. However, for compact prosecution, Examiner is addressing the condition and the corresponding steps as described below.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-3, 5-9, 11-16, 18-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Mendez et al (US Patent Application Publication 20200293694), and further in view of Wilks (US Patent Application Publication 20130031541), further in view of Ghetie (US Patent Application Publication 2022/0006653).
For claim 1, Mendez teaches the following limitations: A Basic Input/Output System (BIOS) secure boot configuration modification reporting system (Fig 1 – Fig 6; [0024]-[0025] – BIOS creates hash and firmware will indicate the system is compromised or not on any subsequent boot), comprising: a computing device (Fig 1, Fig 2 and Fig 4); a non-volatile memory subsystem that is housed in the computing device (132 in Fig 1– [0040]); and a Basic Input/Output System (BIOS) that is housed in the computing device (firmware shown in Fig 2; [0014]; [0030]) , that is coupled to the non-volatile memory subsystem (Fig 2), and that includes: a BIOS database storing a secure boot configuration (stored inventory 222 in Fig 2 which includes configuration settings 218 and TPM 216; [0035][0041]); and a BIOS subsystem that is coupled to the BIOS database (firmware engine 110, firmware 220 and BMC shown in Fig 2; [0035]) and that is configured, during a first initialization of the computing device ([0015] – “reboots”; [0025] – “subsequent boot”), to: generate, using the secure boot configuration, a first initialization hash value (Fig 5 step 506; “new has” – [0013]; [0015] – hash based on inventory during boot; [0024]-[0025] – hash is created based on configuration settings, inventory; [0048] – during booting a current hash can be created based on the inventory); determine whether the first initialization hash value matches a second initialization hash value (“original hash” mentioned in [0050]; [0050] mention about matching the two hashes) and that was generated using the secure boot configuration during a second initialization of the computing device that was performed prior to the first initialization of the computing device ([0013][0024] [0025] [0021][0022] – “first calculated hash”; [0045][0046] – hash created during initialization); generate, in response to determining that the first initialization hash value does not match the second initialization hash value, an unexpected secure boot configuration modification message (if hashes do not match, there is anomaly and compromise; [0025][0050][0012][0026][0052] – alert/notification/message); determine, in response to determining that the first initialization hash value matches the second initialization hash value ([0015] [0025] - hash matches and there is no compromise), that a BIOS image included in the BIOS provides a modification to component authentication information included in the secure boot configuration ([0015] – hash allows continue to boot process; [0052] – firmware does not allow booting if no match; thus BIOS image continues to boot (i.e., provides component authentication information to the system) in response to the match; [0077]; [0022][0027] mentions that firmware can be updated to update firmware revision inventories; thus the BIOS provides modification to firmware inventories included in inventories 222, which includes modification to firmware component authentication information – the updated firmware has different component authentication information [0041] – firmware version identifier is part of inventory).
Mendez does not explicitly mention the following limitations:
a BIOS image included in the BIOS
second hash is stored in the non-volatile memory
generate, in response to determining that the BIOS image provides a modification to component authentication information included in the secure boot configuration, an expected secure boot configuration modification message
Wilks et al teach the following limitations:
generate, in response to determining that the BIOS image provides a modification to component authentication information included in the secure boot configuration (Fig 3 BIOS Update [0028][0030]), an expected secure boot configuration modification message (step 324 Fig 3 [0030] – “displays successful completion message”)
It would have been obvious for one ordinary skill in the art before the effective filing date of the invention to combine the teachings of Mendez and Wilks to provide the expected secure boot configuration message in response to BIOS providing modification, since this ensures the user that the system is modified properly. Mendez teaches confirming that hashes match and displaying the appropriate messages [0026], which is part of the booting as the hash acts as the code to continue as mentioned in [0015]. Therefore, when updating the firmware, the further notification provides user the confirmation that the system has the authorized change. The limitations “BIOS image” and “storing hash in non-volatile storage” are known in the art (Ghetie [0147] – hash in non-volatile and [0142] – BIOS image). It would have been obvious for one ordinary skill in the art before the effective filing date of the invention to provide BIOS image and hash stored in non-volatile, because of the reliability. The image and non-volatile storage are effective against loss of data in a system.
For claim 2, Wilks teaches wherein the generation of the expected secure boot configuration modification message provides at least one of: the display of the expected secure boot configuration modification message on a display device; and the inclusion of the expected secure boot configuration modification message in a log (a display device to display - Fig 3 step 324 [0030]).
For claim 3, Mendez teaches wherein the component authentication information includes at least one of a component authentication certificate and a component authentication signature ([0053] – firmware is not updated unless it is signed – thus the authentication information includes the authentication signature).
For claim 5, Mendez teaches wherein the secure boot configuration includes a plurality of secure boot databases and a plurality of BIOS settings (Fig 2 – various databases 216, 218 and 222; [0022] [0041] – firmware configuration settings).
For claim 6, Mendez teaches the BIOS image provides a modification to the component authentication information included in at least one of the plurality of secure boot databases ([0027] – firmware updating changes firmware revision inventories mentioned in [0022]).
For claim 7, Mendez teaches the following limitations: An Information Handling System (IHS) (Fig 6), comprising: a processing system; and a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system (Fig 4; [0058]-[[0064] – 410 is the processing system and 420 is the memory system), cause the processing system to provide a Basic Input/Output System (BIOS) engine that is configured (firmware engine 110, firmware 220 and BMC shown in Fig 2; [0035]), during a first initialization of the IHS ([0015] – “reboots”; [0025] – “subsequent boot”), to: generate, using the secure boot configuration, a first initialization hash value (Fig 5 step 506; “new has” – [0013]; [0015] – hash based on inventory during boot; [0024]-[0025] – hash is created based on configuration settings, inventory; [0048] – during booting a current hash can be created based on the inventory); determine whether the first initialization hash value matches a second initialization hash value (“original hash” mentioned in [0050]; [0050] mention about matching the two hashes) and that was generated using the secure boot configuration during a second initialization of the IHS that was performed prior to the first initialization of the IHS([0013][0024] [0025] [0021][0022] – “first calculated hash”; [0045][0046] – hash created during initialization); generate, in response to determining that the first initialization hash value does not match the second initialization hash value, an unexpected secure boot configuration modification message (if hashes do not match, there is anomaly and compromise; [0025][0050][0012]); determine, in response to determining that the first initialization hash value matches the second initialization hash value ([0015] [0025] - hash matches and there is no compromise), that ([0015] – hash allows continue to boot process; [0052] – firmware does not allow booting if no match; thus BIOS image continues to boot (i.e., provides component authentication information to the system) in response to the match; [0077]; [0022][0027] mentions that firmware can be updated to update firmware revision inventories; thus the BIOS provides modification to firmware inventories included in inventories 222, which includes modification to firmware component authentication information – the updated firmware has different component authentication information [0041] – firmware version identifier is part of inventory).
Mendez does not explicitly mention the following limitations:
a BIOS image included in the BIOS
second hash is stored in the non-volatile memory
generate, in response to determining that the BIOS image provides a modification to component authentication information included in the secure boot configuration, an expected secure boot configuration modification message
Wilks et al teach the following limitations:
generate, in response to determining that the BIOS image provides a modification to component authentication information included in the secure boot configuration (Fig 3 BIOS Update [0028][0030]), an expected secure boot configuration modification message (step 324 Fig 3 [0030] – “displays successful completion message”)
It would have been obvious for one ordinary skill in the art before the effective filing date of the invention to combine the teachings of Mendez and Wilks to provide the expected secure boot configuration message in response to BIOS providing modification, since this ensures the user that the system is modified properly. Mendez teaches confirming that hashes match and displaying the appropriate messages [0026], which is part of the booting as the hash acts as the code to continue as mentioned in [0015]. Therefore, when updating the firmware, the further notification provides user the confirmation that the system has the authorized change. The limitations “BIOS image” and “storing hash in non-volatile storage” are known in the art (Ghetie [0147] – hash in non-volatile and [0142] – BIOS image). It would have been obvious for one ordinary skill in the art before the effective filing date of the invention to provide BIOS image and hash stored in non-volatile, because of the reliability. The image and non-volatile storage are effective against loss of data in a system.
For claim 8, Wilks teaches wherein the generation of the expected secure boot configuration modification message provides at least one of: the display of the expected secure boot configuration modification message on a display device; and the inclusion of the expected secure boot configuration modification message in a log (a display device to display - Fig 3 step 324 [0030]).
For claim 9, Mendez teaches wherein the component authentication information includes at least one of a component authentication certificate and a component authentication signature ([0053] – firmware is not updated unless it is signed – thus the authentication information includes the authentication signature).
For claim 11, Mendez teaches wherein the secure boot configuration includes a plurality of secure boot databases and a plurality of BIOS settings (Fig 2 – various databases 216, 218 and 222; [0022] [0041] – firmware configuration settings).
For claim 12, Mendez teaches the BIOS image provides a modification to the component authentication information included in at least one of the plurality of secure boot databases ([0027] – firmware updating changes firmware revision inventories mentioned in [0022]).
For claim 13, Mendez teaches wherein the plurality of secure boot databases include a signature database ([0053] – firmware is not updated unless it is signed. Thus, there is a signature database). Mendez does not explicitly mention plural signatures. Examiner takes official notice that database storing plural signatures is well known in the art. It would have been obvious for one ordinary skill in the art before the effective filing date of the invention to include a database including plurality of signatures, since this enhances security of the system.
For claim 14, Mendez teaches the following limitations: A method for reporting modifications ([0026] – displaying message that system has not compromised; [0052] – modification detected) to a secure boot configuration in a Basic Input Output System (BIOS) (stored inventory 222 in Fig 2 which includes configuration settings 218 and TPM 216; [0035][0041]), comprising: generating, by a Basic Input/Output System (BIOS) subsystem (firmware engine 110, firmware 220 and BMC shown in Fig 2; [0035]) during a first initialization of a computing device ([0015] – “reboots”; [0025] – “subsequent boot”) and using a secure boot configuration, a first initialization hash value (Fig 5 step 506; “new has” – [0013]; [0015] – hash based on inventory during boot; [0024]-[0025] – hash is created based on configuration settings, inventory; [0048] – during booting a current hash can be created based on the inventory); determining, by the BIOS subsystem during the first initialization of the computing device, whether the first initialization hash value matches a second initialization hash value (“original hash” mentioned in [0050]; [0050] mention about matching the two hashes) (Fig 1 and Fig 2) and that was generated using the secure boot configuration during a second initialization of the IHS that was performed prior to the first initialization of the IHS ([0013][0024] [0025] [0021][0022] – “first calculated hash”; [0045][0046] – hash created during initialization), wherein the BIOS subsystem is configured to generate an unexpected secure boot configuration modification message in response to determining that the first initialization hash value does not match the second initialization hash value (if hashes do not match, there is anomaly and compromise; [0025][0050][0012]; [0026] and [0052] mention notification); determining, by the BIOS subsystem during the first initialization of the computing device in response to determining that the first initialization hash value matches the second initialization hash value ([0015] [0025] - hash matches and there is no compromise), that a BIOS in the secure boot configuration ([0015] – hash allows continue to boot process; [0052] – firmware does not allow booting if no match; thus BIOS image continues to boot (i.e., provides component authentication information to the system) in response to the match; [0077]; [0022][0027] mentions that firmware can be updated to update firmware revision inventories; thus the BIOS provides modification to firmware inventories included in inventories 222, which includes modification to firmware component authentication information – the updated firmware has different component authentication information [0041] – firmware version identifier is part of inventory).
Mendez does not explicitly mention the following limitations:
a BIOS image included in the BIOS
second hash is stored in the non-volatile memory
generating, by the BIOS subsystem during the first initialization of the computing device in response to determining that the BIOS image provides a modification to component authentication information included in the secure boot configuration, an expected secure boot configuration modification message
Wilks et al teach the following limitations:
generate, by the BIOS system during the initialization of the computing device, in response to determining that the BIOS image provides a modification to component authentication information included in the secure boot configuration (Fig 3 BIOS Update [0028][0030]), an expected secure boot configuration modification message (step 324 Fig 3 [0030] – “displays successful completion message”)
It would have been obvious for one ordinary skill in the art before the effective filing date of the invention to combine the teachings of Mendez and Wilks to provide the expected secure boot configuration message in response to BIOS providing modification, since this ensures the user that the system is modified properly. Mendez teaches confirming that hashes match and displaying the appropriate messages [0026], which is part of the booting as the hash acts as the code to continue as mentioned in [0015]. Therefore, when updating the firmware, the further notification provides user the confirmation that the system has the authorized change. The limitations “BIOS image” and “storing hash in non-volatile storage” are known in the art (Ghetie [0147] – hash in non-volatile and [0142] – BIOS image). It would have been obvious for one ordinary skill in the art before the effective filing date of the invention to provide BIOS image and hash stored in non-volatile, because of the reliability. The image and non-volatile storage are effective against loss of data in a system.
For claim 15, Wilks teaches wherein the generation of the expected secure boot configuration modification message provides at least one of: the display of the expected secure boot configuration modification message on a display device; and the inclusion of the expected secure boot configuration modification message in a log (a display device to display - Fig 3 step 324 [0030]).
For claim 16, Mendez teaches wherein the component authentication information includes at least one of a component authentication certificate and a component authentication signature ([0053] – firmware is not updated unless it is signed – thus the authentication information includes the authentication signature).
For claim 18, Mendez teaches wherein the secure boot configuration includes a plurality of secure boot databases and a plurality of BIOS settings (Fig 2 – various databases 216, 218 and 222; [0022] [0041] – firmware configuration settings).
For claim 19, Mendez teaches the BIOS image provides a modification to the component authentication information included in at least one of the plurality of secure boot databases ([0027] – firmware updating changes firmware revision inventories mentioned in [0022]).
For claim 20, Mendez teaches wherein the plurality of secure boot databases include a signature database ([0053] – firmware is not updated unless it is signed. Thus, there is a signature database). Mendez does not explicitly mention plural signatures. Examiner takes official notice that database storing plural signatures is well known in the art. It would have been obvious for one ordinary skill in the art before the effective filing date of the invention to include a database including plurality of signatures, since this enhances security of the system.
Allowable Subject Matter
Claims 4, 10 and 17 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FAHMIDA RAHMAN whose telephone number is (571)272-8159. The examiner can normally be reached Monday - Friday 10 AM - 7 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Andrew Jung can be reached at 571-270-3779. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/FAHMIDA RAHMAN/Primary Examiner, Art Unit 2175