DETAILED ACTION
Claims 1–20 are presented for examination.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1–20 are rejected under 35 U.S.C. 103 as being unpatentable over Cleeton et al. (hereinafter ‘Cleeton’) US 20160210457 A1 in view of Diamant et al. (hereinafter ‘Diamant’) US 10943013 B2.
As to claim 1, Cleeton teaches a method, comprising: causing, by a computing device, a virtual machine comprising a security module to be initialized [Cleeton (¶¶ 0023–0027) Fig.3: “is a flow diagram showing example acts that may be performed by the facility in some examples to create a virtual machine for execution on the virtualization host. At 301, the facility receives a request to create a virtual machine…. At 302, the facility creates the requested virtual machine…. At 304, the facility copies the secure boot policy from the host secure boot policy store to a local boot policy store of the virtual machine. Returning to Figure 4, it can be seen that the facility has copied secure boot policy 411 from host secure boot policy store 410 to local secure boot policy store 460 as secure boot policy 461…. Returning to Fig. 3, at 305, the facility establishes an encryption key for encrypting an encrypted disk in the virtual machine. At 306, the facility seals the encryption key established at 305 in a vTPM established for the virtual machine, based both on a present system state (stored in the vTPM as the “prior system state”) and the secure boot policy in the local secure boot policy store”], wherein the virtual machine utilizes a boot process configuration that is to be utilized by the computing device [Cleeton (¶¶ 0037): “In some examples, the facility provides a method for booting a virtual machine hosted on a host, the method comprising: booting the virtual machine in accordance with a policy instance associated with the virtual machine; as part of the booting, extracting information needed to complete the booting from a virtual trusted platform module associated with the virtual machine, the extraction based upon the policy instance associated with the virtual machine; and, at the completion of the booting, copying contents of a policy instance associated with the host into the policy instance associated with the virtual machine”];
Cleeton does not explicitly disclose accessing, by the computing device, a configuration value derived by the security module within the virtual machine, the configuration value being associated with a decryption key operable to decrypt data stored on a storage device.
However, Diamant teaches accessing, by the computing device, a configuration value derived by the security module within the virtual machine [Diamant (¶¶ 0009): “A TPM is used to process measurement data generated for the executable code and thereby generate a decryption key used to decrypt subsequently executed code. The measurement data is stored within a platform configuration register (PCR) of the TPM”. Diamant (¶¶ 0011): “This new boot stage can initialize the TPM, unseal and securely extract the key, use it to decrypt data or executable code, and jump to execute the next stage of boot”], the configuration value being associated with a decryption key operable to decrypt data stored on a storage device [Diamant (¶¶ 0009): “A TPM is used to process measurement data generated for the executable code and thereby generate a decryption key used to decrypt subsequently executed code.” Diamant (¶¶ 0032): “This unsealed key (e.g., a decryption key) can be used to decrypt other executable code or data accessible to the computer”];
and implementing, by the computing device, a boot process action of the computing device based on the configuration value [Cleeton (¶¶ 0032, fig7): “the secure boot process proceeds successfully to permit recovery of the key from the vTPM. At 703, the facility uses the key to decrypt the encrypted disk as needed. At 704, the facility copies the secure boot policy stored in the host secure boot policy store to the local secure boot policy store, replacing the secure boot policy formerly stored there…. At 705, the facility reseals the encryption key in the vTPM using the current state of the virtual machine, together with the secure boot policy stored in the local secure boot policy store.”].
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Cleeton with the teachings of Diamant since doing so would have achieved the desirable result of enabling secure, automated booting and strict access control.
As to claim 2, Cleeton in view of Diamant teaches the method of claim 1, wherein implementing the boot process action comprises initiating a computing system boot process [Cleeton (¶¶ 0032): “Figure 7 is a flow diagram showing example acts that may be performed by the facility in some embodiments to handle booting of the virtual machine. At 701, booting of the virtual machine is initiated.”].
As to claim 3, Cleeton in view of Diamant teaches the method of claim 1, wherein implementing the boot process action comprises terminating a computing system boot process [Cleeton (¶¶ 0016): “The inventors have recognized that performing upgrades on a virtual machine having a virtual Trusted Platform Module (“vTPM”) and a recovery mode protected and TPM-dependent full disk encryption solution (such as MICROSOFT BITLOCKER) may trip the virtual machine into a recovery state. The transition into a recovery mode happens because the upgrade operation in many ways resembles an attack on Secure Boot which provides the infrastructure to secure the boot process by preventing the loading of drivers or OS loaders that are not signed with an acceptable digital signature.”].
As to claim 4, Cleeton in view of Diamant teaches the method of claim 1, further comprising: based on the configuration value, outputting, to a display device a prompt indicative of an alternative option to decrypt the data stored on the storage device, [Cleeton (para 0003): “Without being able to decrypt the disk, booting cannot be completed, and the encryption system enters a recovery mode that can only be exited with an extra measure of authentication, such as entering a recovery password”]. Cleeton teaches entering authentication externally which can generally refer to prompt and require a display to provide the Prompt.
As to claim 5, Cleeton in view of Diamant teaches the method of claim 4, further comprising: receiving, in response to the prompt, user input associated with an alternative decryption key operable to decrypt the data stored on the storage device, [ Cleeton (para 0003): “Without being able to decrypt the disk, booting cannot be completed, and the encryption system enters a recovery mode that can only be exited with an extra measure of authentication, such as entering a recovery password.”].
Examiner note: Receiving user password in response to such recovery constitutes the ordinary implementation of the disclosed claim.
As to claim 6, Cleeton in view of Diamant teaches the method of claim5, wherein receiving the user input comprises receiving a user passphrase that is operable to decrypt the data stored on the storage device, [Cleeton (para 0003): “the key needed by the encryption system to decrypt the disk cannot be retrieved from the TPM. Without being able to decrypt the disk, booting cannot be completed, and the encryption system enters a recovery mode that can only be exited with an extra measure of authentication, such as entering a recovery password.”].
Examiner note: A recovery password is reasonably interpreted as the claimed user passphrase.
As to claim 7, Cleeton in view of Diamant teaches the method of claim 1, wherein accessing the configuration value comprises obtaining the configuration value from a platform configuration register (PCR) [Diamant (¶¶ 0009): “The measurement data is stored within a platform configuration register (PCR) of the TPM… The decryption key can be unsealed from the TPM using the measurement value stored in the TPM PCR”].
As to claim 8, Cleeton in view of Diamant teaches the method of claim 1, further comprising: storing the configuration value in the security module, wherein the computing device accesses the configuration value from the security module [Diamant (¶¶ 0009): “The measurement data is stored within a platform configuration register (PCR) of the TPM… The decryption key can be unsealed from the TPM using the measurement value stored in the TPM PCR”].
Examiner note: TPM is a security module and storing the configuration value within the TPM security module is expressly taught.
As to claim 9, Cleeton in view of Diamant teaches the method of claim 1, further comprising initializing the security module by initializing a trusted platform module (TPM), the TPM comprising at least one of a hardware chip or a software module [Diament (¶¶ 0011): “This new boot stage can initialize the TPM, unseal and securely extract the key, use it to decrypt data or executable code, and jump to execute the next stage of boot”. Diament (¶¶ 0035): “In some examples of the disclosed technology, the second portion of software, which can be executed immediately after the boot ROM executes, is used to manage the outlined method, including initiating and managing the TPM”].
As to claim 10, Cleeton in view of Diamant teaches the method of claim1, further comprising: detecting a changed configuration value; and based on the changed configuration value, initializing the virtual machine and the security module [Cleeton (¶¶ 0018-0019): “The host's security policy is immediately updated in response to each secure boot policy update received by the host …Once the encryption key is recovered and recovery state is avoided, the facility checks whether the secure boot policy in the host secure boot policy store has been updated, and, if so, copies the updated secure boot policy to the vm's local secure boot policy store. In this situation, the facility also reseals the encryption key in the virtual machine's vTPM based upon the updated secure boot policy now stored in the vm's local secure boot policy store.”].
As to claim 11, Cleeton in view of Diamant teaches the method of claim 10, further comprising: storing the changed configuration value in the security module; and in response to storing the changed configuration value, updating an encryption specification of the storage device, wherein the encryption specification comprises decryption options to decrypt the data stored on the storage device [Diamant (¶¶ 0009): “The measurement data is stored within a platform configuration register (PCR) of the TPM”. Diamant (¶¶ 0011): “This new boot stage can initialize the TPM, unseal and securely extract the key, use it to decrypt data or executable code”].
As to claim 12, A computing device, comprising: one or more processor devices to: cause a virtual machine comprising a security module to be initialized, wherein the virtual machine utilizes a boot process configuration that is to be utilized by the computing device; access a configuration value derived by the security module within the virtual machine, the configuration value being associated with a decryption key that is operable to decrypt data stored on a storage device; and implement a boot process action of the computing device based on the configuration value, it recites one or more processor devices to perform substantially the same operations recited in Claim 1. Cleeton also teaches a virtualization host computer system comprising one or more processors [Cleeton (¶¶ 0022): “In some examples, the virtualization host is a physical computer system having physical components such as a processor, memory, network interface card, etc.”]. Accordingly, claim 12 is rejected for the same reason as mentioned in the rejection of claim1.
Claim 13 is rejected for the same reason as mentioned in the rejection of claim 2, since both claims 2 & 13 recite identical claim limitations with insignificant change in wording.
Claim 14 is rejected for the same reason as mentioned in the rejection of claim 3, since both claims 3 & 14 recite identical claim limitations with insignificant change in wording.
Claim 15 is rejected for the same reason as mentioned in the rejection of claim 7, since both claims 7 & 15 recite identical claim limitations with insignificant change in wording.
Claim 16 is rejected for the same reason as mentioned in the rejection of claim 4, since both claims 4 & 16 recite identical claim limitations with insignificant change in wording.
Claim 17 is rejected for the same reason as mentioned in the rejection of claim 5, since both claims 5 & 17 recite identical claim limitations with insignificant change in wording.
Claim 18 is rejected for the same reason as mentioned in the rejection of claim1.
Claim 19 is rejected for the same reason as mentioned in the rejection of claim 2, since both claims 2 & 19 recite identical claim limitations with insignificant change in wording.
Claim 20 is rejected for the same reason as mentioned in the rejection of claim 3, since both claims 3 & 20 recite identical claim limitations with insignificant change in wording.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AFRINA MURSHID whose telephone number is (571)270-0796. The examiner can normally be reached 9:00AM-5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jaweed Abbaszadeh can be reached at (571) 270-1640. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/AFRINA MURSHID/Examiner, Art Unit 2176
/JAWEED A ABBASZADEH/Supervisory Patent Examiner, Art Unit 2176