DETAILED ACTION
Claims 1-20 have been examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 12/16/2024 has been considered by the examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 11-18 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 11 recites the limitation "the binary file" in line 2. There is insufficient antecedent basis for this limitation in the claim due to claim 11 is dependent upon claim 1, and “binary file” is not within the limitations of claim 1. Limitations for a “binary file” are first present within claim 4 (which depends upon claim 1).
Claims 12-18 are rejected by virtue of their dependencies upon rejected claim 11; with claims 12, 14, and 17 (all dependent upon claim 11) also having limitations pertaining to “the binary file”. Appropriate correction is required.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by United States Patent Application Publication No. US 20170177860 A1 to Suarez et al, hereinafter Suarez.
Regarding claim 1, Suarez teaches a method for controlling access to restricted functionality of a computing device (paragraphs 29, 65, and 88-90), the method comprising:
receiving, by one or more electronic processors, a request for access to restricted functionality of a computing device from a user, the request for access identifying at least a portion of the restricted functionality of the computing device to be unlocked for access by the user (paragraph 29, “Each repository may have various associated roles and policies specifying access types and restricting access to the repository to entities authorized by the customer to access the repository”, and paragraph 89, “time limits”, paragraph 90, “expiration times, number of uses”);
transmitting, by the one or more electronic processors, the request to a trusted license store (paragraphs 79 and 81);
receiving, by the one or more electronic processors, data indicative of a license from the trusted license store, the data indicative of the license comprising an identifier of the portion of the restricted functionality to be unlocked for access and a number of times the user may access the restricted functionality (paragraph 89, “time limits”, and paragraph 90, “expiration times, number of uses”);
determining, by the one or more electronic processors, that the user has not accessed the restricted functionality more than the number of times the user may access the restricted functionality (paragraphs 81-83, 89, and 90);
and in response to determining that the user has not accessed the restricted functionality more than the number of times the user may access the restricted functionality: providing, by the one or more electronic processors, access to the restricted functionality to the user (paragraphs 81-83, 89, and 90).
Regarding claim 2, Suarez teaches wherein transmitting the request to the trusted license store comprises establishing a secure, mutually-authenticated network connection to the trusted license store; and receiving the data indicative of the license comprises receiving the data indicative of the license over the mutually-authenticated network connection from the trusted license store (paragraphs 41, 43, 84, 87-90, 108, 113, 119, 122, 126, and 128).
Regarding claim 3, Suarez teaches wherein the request includes a credential associated with the user (paragraph 85, “The request may include credentials or proof of credentials 978 (e.g., username/password, biometric identifying information, one-time passcode, a cryptographic hash of any or all of the aforementioned data, etc.) usable to authenticate”).
Regarding claim 4, Suarez teaches wherein the data indicative of the license further comprises an identity of a binary file for execution, and wherein providing access to the restricted functionality comprises allowing execution of the binary file on the computing device (paragraphs 34, 65, and 98, “binary file”, and paragraph 103).
Regarding claim 5, Suarez teaches executing, by the one or more electronic processors, the binary file, wherein the binary file executes a software image version on the computing device (paragraphs 34, 65, and 98, “binary file”, and paragraph 103).
Regarding claim 6, Suarez teaches wherein executing the binary file on the computing device comprises: allowing execution, by the one or more electronic processors, of a single software application permitting a limited set of operations for the computing device (paragraphs 34, 65, and 98, “binary file”, and paragraph 103).
Regarding claim 7, Suarez teaches wherein executing the binary file on the computing device comprises: enabling, by the one or more electronic processors, access to a shell with a limited set of tools and actions, wherein access to the shell is limited by one or more access controls (paragraphs 57 and 78).
Regarding claim 8, Suarez teaches wherein determining that the user has not accessed the restricted functionality more than the number of times the user may access the restricted functionality comprises comparing the number of times the user may access the restricted functionality to a monotonic counter of the computing device (paragraphs 81-83, 89, and 90).
Regarding claim 9, Suarez teaches wherein the user is determined to not have accessed the restricted functionality more than the number of times if a value of the monotonic counter is less than or equal to the number of times the user may access the restricted functionality (paragraphs 81-83, 89, and 90).
Regarding claim 10, Suarez teaches in response to executing the binary file, incrementing, by the one or more processors, the monotonic counter (paragraphs 89 and 90).
Regarding claim 11, Suarez teaches validating, by the one or more processors, the binary file before allowing execution of the binary file (paragraphs 89, 90, 98, 118, and 119).
Regarding claim 12, Suarez teaches wherein validating the binary file comprises: determining, by the one or more processors, a public key associated with the binary file; determining, by the one or more processors, a public key hash value based on the public key; comparing, by the one or more processors, the public key hash value to a programmed hash value accessed from a first set of fuses of the computing device; and in response to the public key hash value being equal to the programmed hash value, verify a signature associated with the binary file using the public key; and in response to the verified signature matching a computed hash value of the binary file, allowing execution of the binary file (paragraphs 69, 85, 87, 88, and 122).
Regarding claim 13, Suarez teaches identifying, by the one or more processors, the first set of fuses containing the programmed hash value based on a value of a switch fuse of the computing device (paragraphs 85, 104, and 122).
Regarding claim 14, Suarez teaches wherein validating the binary file comprises: determining, by the one or more processors, a security version number associated with the binary file; comparing, by the one or more processors, the security version number to a programmed value associated with a first set of fuses of the computing device; and in response to the security version number value being greater than or equal to the programmed value, allowing execution of the binary file (paragraphs 26, and paragraph 28, Table 1,”version 1, version 2”, and paragraphs 33, 34, 36, 48-50, 52, 53, 55, and 71, “version number”, and paragraphs 94, 100, 101, and 104).
Regarding claim 15, Suarez teaches identifying, by the one or more processors, the programmed value based on a value of a switch fuse of the computing device (paragraphs 67 and 104).
Regarding claim 16, Suarez teaches in response to a user input indicating that the programmed hash value has been compromised, irrevocably changing, by the one or more processors, the value of the switch fuse (paragraph 120, “has been tampered with or corrupted”, and paragraph 122).
Regarding claim 17, Suarez teaches in response to the binary file not being validated, not executing the binary file (paragraph 78, “the running software may be rendered unavailable/inaccessible”, and paragraphs 79, 81, 83, 86, 88-90, 116, 120, 122, and 128).
Regarding claim 18, Suarez teaches in response to the binary file not being validated, performing a reboot of the computing device (paragraphs 89 and 90).
Regarding claim 19, Suarez discloses a computing device, comprising:
one or more processors (paragraphs 77, 106, 111, 117, 125, and 133);
and a non-transitory, computer-readable medium comprising instructions that, when executed by the one or more processors (paragraphs 111, 117, 125, and 133), cause the one or more processors to execute operations, the operations comprising:
receiving a request for access to restricted functionality of a computing device from a user, the request for access identifying at least a portion of the restricted functionality of the computing device to be unlocked for access by the user (paragraph 29, “Each repository may have various associated roles and policies specifying access types and restricting access to the repository to entities authorized by the customer to access the repository”, and paragraph 89, “time limits”, paragraph 90, “expiration times, number of uses”);
transmitting the request to a trusted license store (paragraphs 79 and 81);
receiving data indicative of a license from the trusted license store, the data indicative of the license comprising an identifier of the portion of the restricted functionality to be unlocked for access and a number of times the user may access the restricted functionality (paragraph 89, “time limits”, and paragraph 90, “expiration times, number of uses”);
determining that the user has not accessed the restricted functionality more than the number of times the user may access the restricted functionality (paragraphs 81-83, 89, and 90);
and in response to determining that the user has not accessed the restricted functionality more than the number of times the user may access the restricted functionality: providing access to the restricted functionality to the user (paragraphs 81-83, 89, and 90).
Regarding claim 20, Suarez discloses a non-transitory, computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute operations (paragraphs 111, 117, 125, and 133), the operations comprising:
receiving a request for access to restricted functionality of a computing device from a user, the request for access identifying at least a portion of the restricted functionality of the computing device to be unlocked for access by the user (paragraph 29, “Each repository may have various associated roles and policies specifying access types and restricting access to the repository to entities authorized by the customer to access the repository”, and paragraph 89, “time limits”, paragraph 90, “expiration times, number of uses”);
transmitting the request to a trusted license store (paragraphs 79 and 81);
receiving data indicative of a license from the trusted license store, the data indicative of the license comprising an identifier of the portion of the restricted functionality to be unlocked for access and a number of times the user may access the restricted functionality (paragraph 89, “time limits”, and paragraph 90, “expiration times, number of uses”);
determining that the user has not accessed the restricted functionality more than the number of times the user may access the restricted functionality (paragraphs 81-83, 89, and 90);
and in response to determining that the user has not accessed the restricted functionality more than the number of times the user may access the restricted functionality: providing access to the restricted functionality to the user (paragraphs 81-83, 89, and 90).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The references cited on form PTO-892 are cited to further show the state of the art with respect to access control.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JEREMIAH L AVERY whose telephone number is (571)272-8627. The examiner can normally be reached M-F 8:30am -5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JEREMIAH L AVERY/Primary Examiner, Art Unit 2431