DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The following is a Final Office action in response to communications received on May 13, 2026. Claims 1-3, 6, 8-14 and 17-25 are pending and addressed below.
Response to Arguments
Applicant’s amendments are sufficient to overcome the 35 U.S.C. 112(b) rejections set forth in the previous Office Action. However, Applicant’s amendments have necessitated new grounds 35 U.S.C. 112(b) rejections which are addressed herein below.
Applicant’s amendments are sufficient to overcome the claim objection set forth in the previous Office Action for claim 7. Applicant’s amendments are not sufficient to overcome the claim objection set forth in the previous Office Action for claim 17. Therefore, the objection for claim 17 is maintained and repeated herein below.
Applicant’s amendments are sufficient to overcome the 35 U.S.C. 103 rejections for claims 1-5 and 12-20 set forth in the previous Office action. However, Applicant’s amendments have necessitated a new grounds 35 U.S.C. 103 rejection for claims 13 and 14 (and newly added dependent claim 24) which are addressed herein below. It is noted that while Applicant stated that previously indicated allowable subject matter has been incorporated into the independent claims, claim 13 has not been amended to include the previously indicated allowable subject matter.
Examiner’s Note
Claim 17 previously recited limitations considered to invoke 35 U.S.C. 112(f). However, Applicant has amended the claim to remove this interpretation. No claims are currently considered to recite limitations that invoke 35 U.S.C. 112(f).
Claim Objections
Claim 17 is objected to because of the following informalities: Claim 17 recites the phrase “a prover comprising one or more processors and configured to::”. It is suggested the phrase be amended to “a prover comprising one or more processors and configured to:[[:]]”.
Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-3, 6, 8-12, 17-23 and 25 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 1 recites the limitation “the first verification.” There is insufficient antecedent basis for this limitation. Claim 17 is rejected for similar reasons to claim 1. Dependent claims 2-3, 6, 8-12, 18, 19, 21-23 and 25 are rejected for containing the same indefinite language as parent claims 1 and 17 without further remedying the indefinite language.
Claim 20 recites the limitations “the first verification” and “the prover”. There is insufficient antecedent basis for these limitations.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 13, 14 and 24 is/are rejected under 35 U.S.C. 103 as being unpatentable over Morbitzer (“Scanclave: Verifying Application Runtime Integrity in Untrusted Environments”) in view of Soriente et al. (U.S. Pub. No. 2019/0243950 and hereinafter referred to as Soriente).
As to claim 13, Morbitzer discloses a method, comprising:
sending, by a verifier and to a prover, a remote attestation request requesting to attest whether a target trusted application (TA) of the verifier is securely run (section I pg. 198, section III pg. 200 and Abstract, Morbitzer teaches a verifier requests a scan for a target application (TA) while the TA is running using a scanner operating in a TEE);
receiving, by the verifier from the prover, and in response to the remote attestation request, a first attestation report comprising measurement information (section I pg. 198, section III pg. 200 and Abstract, Morbitzer teaches integrity measurements while the TA is running), and first signature information (section I pg. 198, section III pg. 200 and Abstract, Morbitzer teaches signing the report), and wherein the measurement information comprises first measurement information based on measurement of data of the target TA during running (section I pg. 198, section III pg. 200 and Abstract, Morbitzer teaches the scanner sending a report to the verifier, the report based on integrity measurements while the TA is running), wherein the first signature information is based on signing the measurement information (section I pg. 198, section III pg. 200 and Abstract, Morbitzer teaches signing the report, the report being based on integrity measurements); and
verifying, by the verifier, the first attestation report to determine whether the target TA is securely run (section I pg. 198, section III pg. 200 and Abstract, Morbitzer teaches the report allows the verifier to determine if the TA is in a trusted state.). Morbitzer is not explicitly clear in disclosing whether a target trusted application (TA) of the verifier is securely run in a trusted execution environment (TEE) of the prover (emphasis added); a certificate of an attestation key (AK); using the AK, and wherein the certificate verifies the first signature information; and determine whether the target TA is securely run in the TEE (emphasis added) as claimed. However, Soriente does disclose
whether a target trusted application (TA) of the verifier is securely run in a trusted execution environment (TEE) of the prover (paragraphs [0052] and [0054]-[0055], Soriente teaches an application of a verifier is run in an enclave (i.e. TEE));
a certificate of an attestation key (AK) (paragraphs [0045], [0058] and [0061], Soriente teaches a certificate of an attestation key);
using the AK, and wherein the certificate verifies the first signature information (paragraphs [0045], [0058] and [0061], Soriente teaches verifying using a certificate);
and determine whether the target TA is securely run in the TEE (paragraphs [0052] and [0054]-[0055], Soriente teaches an application of a verifier is run in an enclave (i.e. TEE).).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Morbitzer with the teachings of Soriente for running a trusted application in a TEE because this would increase security.
As to claim 14, the combination of teachings between Morbitzer and Soriente disclose the method of claim 13, wherein the measurement information further comprises second measurement information indicating a status of the target TA during startup (paragraph [0084], Soriente teaches attestation on application startup.).
Examiner supplies the same rationale for the combination of the references as in claim 13 above.
As to claim 24, the combination of teachings between Morbitzer and Soriente disclose the method of claim 13, wherein verifying the first attestation report comprises: obtaining, by the verifier, a public key corresponding to the AK (section I pg. 198, section III pp. 199-200 and Abstract, Morbitzer teaches a verifier obtains a public key for attestation) from the certificate (paragraphs [0045], [0055], [0058], [0061] and [0065], Soriente teaches retrieving a public key from a certificate); and verifying, by the verifier, the first signature information using the public key corresponding to the AK (section I pg. 198, section III pp. 199-200 and Abstract, Morbitzer teaches verifying a signature.).
Examiner supplies the same rationale for the combination of the references as in claim 13 above.
Allowable Subject Matter
Claims 1-3, 6, 8-12, 17-23 and 25 would be allowable if rewritten or amended to overcome all of the rejection(s) set forth in this Office action.
Claim 1 recites, inter alia, “signing, by the prover, a trusted computing base (TCB) of the prover and the public key using a device root key (DRK) of the prover to obtain second signature information.” The prior art was not found to disclose this limitation in combination with the other limitations. Therefore, claim 1 is considered to recite allowable subject matter over the prior art. Independent claims 17 and 20 are considered to recite allowable subject matter over the prior art for similar reasons to claim 1. Dependent claims 2, 3, 6, 8-12, 18, 19, 21-23 and 25 are considered to recite allowable subject matter over the prior art based on their dependency.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to THADDEUS J PLECHA whose telephone number is (571)270-7506. The examiner can normally be reached M-F 8-4:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Taghi Arani can be reached at 571-272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/THADDEUS J PLECHA/Examiner, Art Unit 2438