Prosecution Insights
Last updated: August 17, 2026
Application No. 18/982,736

HARDWARE SECURITY MODULES INTEGRATED IN MEMORY DEVICES AND SYSTEMS

Final Rejection §103
Filed
Dec 16, 2024
Examiner
MENDEL, JULIAN SCOTT
Art Unit
2133
Tech Center
2100 — Computer Architecture & Software
Assignee
SK hynix Inc.
OA Round
2 (Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
26 granted / 34 resolved
+21.5% vs TC avg
Strong +52% interview lift
Without
With
+52.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
24 currently pending
Career history
67
Total Applications
across all art units

Statute-Specific Performance

§101
7.9%
-32.1% vs TC avg
§103
54.1%
+14.1% vs TC avg
§102
16.1%
-23.9% vs TC avg
§112
21.3%
-18.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 34 resolved cases

Office Action

§103
DETAILED ACTION This Action is responsive to the amendments filed on 04/22/2026. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Status Claims 1-9 and 11-20 are amended. Claim 10 is cancelled. Claim 21 is newly presented. Claims 1-9 and 11-21 are pending and have been examined. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-7, 16-17, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US 20210091954 A1)(cited by applicant in 07/01/2026 IDS)(hereafter referred to as Brown) further in view of Lee et al. (US 20130156195 A1)(cited by examiner in previous action)(hereafter referred to as Lee). Regarding Claim 1, Brown discloses the following limitations: A memory device (Portable Secure Storage Device 110, Fig. 2), comprising: a non-volatile memory (NV Memory 276 + Memory 289, Fig. 2) including a secure memory portion (NV Memory 276, Fig. 2) and a data memory portion (Memory 289, Fig. 2 // “a non-volatile memory” [0027]), wherein the secure memory portion stores secure data including a first private key (“The security controller may store the concealed encryption key in the non-volatile memory 276 … The security controller may also store the transformation key in the non-volatile memory 276.” … The security controller 270 has the highest security level among the components in the portable storage device 110.” [0045-47]) – Non-volatile memory 276 is located within security controller 270 having the highest security level among components of the storage device 110. NV memory 276 stores keys including a “concealed encryption key” and a “transformation key”. Examiner considers a transformation key stored within NV memory 276 as reading on the claimed concept of “secure data including a first private key”--, and the data memory portion stores user data (“the user data stored in the memory 289 is encrypted or securely stored” [0039]); a memory controller (Memory Controller 280, Fig. 2) coupled to the data memory portion, the memory controller configured to receive a data access request and access the user data in response to the data access request (“the host 120 and the portable secure storage device 110 may be ready to exchange data (e.g., commands, user data, other data) … The data transfer controller 260 may receive data … from the host 120 … The memory controller 280 may encrypt the data and store the encrypted data in the memory 289” [0060-61]) – Memory Controller 280 receives user data from a host 120 (via data transfer controller 260), encrypts the user data, and stores the encrypted user data into memory 289--; a secure controller (Security Controller 270, Fig. 2) coupled to the secure memory portion, the secure controller configured to access the secure data and implement a secure operation on the secure data (“before the portable secure storage device 110 communicates with the host 120, the security controller may generate a new operating encryption key and a new transformation key” [0045] // “the security controller 270 may fetch the concealed encryption key from the non-volatile memory 276.” [0055]) – Security controller 270 generates and stores keys within NV 276 (i.e., at least “implement[s] a secure operation on the secure data”) and fetches keys from NV 276--; and an integrated memory enclosure (Portable Secure Storage Device 110, Fig. 2) for enclosing the secure controller, the memory controller, and the non-volatile memory (“the portable secure storage device 110 includes a casing … the memory 289 and each of the controllers 260, 270, and 280 are disposed within the casing.” [0026]); wherein the secure controller is distinct from the memory controller (“The security controller 270 is separate and distinct from the memory controller 280” [0047]) Brown does not explicitly disclose security controller 270 performing the following limitations: configured to generate a first signature based on the first private key, generate a first signed message based on the user data provided by the memory controller, and provide the first signed message to a host device coupled to the memory device or to a data processor of the memory device. However, Lee discloses the following limitations: the secure controller (Authentication Code Generator 212, Fig. 6) is distinct from the memory controller (Authenticated Read Controller 210, Fig. 6)(“the authentication code generator 212 may be located externally to the authenticated read controller 210” [0123] // Fig. 6 // ¶¶0127; 0129) – Examiner considers Authentication Code Generator 212 and Authenticated Read Processor 210 depicted in Lee Fig. 6 (in the embodiment described in ¶0123 whereby the authentication code generator is external to authenticated read processor 210) as analogous to the Brown Fig. 2 Security Controller 270 and Memory Controller 280, respectively.-- configured to generate a first signature (“device authentication code DA_CODE” [0129]) based on the first private key (“a key” [0129])(“The authentication code generator 212 may generate the device authentication code DA_CODE based on a key shared with the host 300 … The shared key value may be previously set.” [0129] // ¶¶0121-130) – As shown in Fig. 6 and detailed in ¶0129, authentication code generator 212 generates a “device authentication code” (i.e., “a first signature”) using a key whose value is previously set (analogous to “the first private key”)--, generate a first signed message (DA_CODE, Fig. 6) based on the user data provided by the memory controller (“The authenticated read processor 211 may provide the memory device 100 with a command to read data stored in the write protection area of the memory device 100” [0125] // “generate the device authentication code DA_CODE based on a key shared with the host 300 and the read data R_DATA” [0129]) – As shown in Fig. 6, the DA_CODE is provided to host 300. Examiner accordingly considers the DA_CODE as “a first signed message”. The DA_CODE is generated based on R_DATA read by authenticated read processor 211 and stored to buffer 200 (i.e., “based on the user data provided by the memory controller”)--, and provide the first signed message to a host device (Host 300, Fig. 6) coupled to the memory device (“The authentication code generator may provide the host 300 with the generated device authentication code DA_CODE” [0129]) or to a data processor (Brown, Data Transfer Controller 260, Fig. 2) of the memory device. (see MPEP 2140.03, selection of an element from list of alternatives) Brown and Lee are considered analogous to the claimed invention because they all relate to the same field of performing data encryption/decryption and identity authorization in a data storage device. Therefore, it would have been obvious for someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Brown with the teachings of Lee and realize a storage device whereby a secure controller transmits a signed message to a host based on a key. Doing so improves data security by enabling a host to identify and prevent replay attacks whereby messages between the host and the storage device are intercepted, as disclosed in Lee ¶¶0075-76: “the storage device 50 may transmit th read data to the host 300 and may transmit the second response including the device authentication code to the host 300 … The host 300 may determine whether the series of requests and the responses regarding the security read are properly exchanged with the storage device … the host 300 may prevent a replay attack, in which a device other than the storage device 50 intercepts the series of requests and provides a response to the host 300.” [0075-76] Regarding Claim 2, The same motivation to combine provided in Claim 1 is equally applicable to Claim 2. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1, wherein the secure data is associated with the user data, and the user data is accessed based on a result of the secure operation on the secure data. (Brown, “The memory controller may then encrypt the data received from the data transfer controller 260 using the operating encryption key and provide the encrypted data to the memory 289” [0067] // “after a security access code is inputted at the input device 296 is verified, the memory controller 280 may receive the concealed encryption key from the security controller” [0063] // ¶0045) – As taught in Brown, user data is encrypted using a concealed encryption key generated by the security controller 270. Accordingly, the concealed encryption key is at least associated with the user data because the user data is encrypted using the encryption key and at least based on generation of the encryption key. Regarding Claim 3, The same motivation to combine provided in Claim 1 is equally applicable to Claim 3. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1, further comprising: a volatile memory (Brown, Fig. 2) including a first memory portion (Brown, Volatile Memory 277, Fig. 2) and a second memory portion (Brown, Volatile Memory 286, Fig. 2 // Lee, Buffer 220, Fig. 6); wherein the first memory portion is coupled to the secure controller (Brown, Fig. 2) and is accessible by the secure controller to store the secure data temporarily (Brown, “The security controller 270 may temporarily store the operating encryption key in the volatile memory 277” [0045]) – As taught in Brown, encryption keys are , and the second memory portion is coupled to the memory controller (Brown, Fig. 2 // Lee, Fig. 6) and accessible by the memory controller to store the user data temporarily in response to the data access request. (Lee, “The buffer 220 may receive the read data R_DATA from the memory device 100 and may store the received data R_DATA therein. The buffer 220 may provide the stored read data R_DATA to the host 300” [0130]) – As taught in Lee, read data is temporarily stored in buffer 220 prior to being provided to the host 300 in response to a host request. Regarding Claim 4, The same motivation to combine provided in Claim 1 is equally applicable to Claim 4. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1, further comprising: the data processor (Brown, Data Transfer Controller 260, Fig. 2) coupled to the non-volatile memory, the secure controller, and the memory controller (Brown, Fig. 2), wherein the data processor is configured to exchange the user data with the memory controller and implement a data processing operation associated with the user data. (Brown, “The data transfer controller 260 may receive data compatible with the standard communication interface protocol from the host 120 … The data transfer controller 260 may then convert the received data to data that is compatible with a standard memory interface protocol … The converted data may then be provided to the memory controller 280” [0061]) – As taught in Brown, Data Transfer Controller 260 performs a conversion operation on user data to transform the data from a communication protocol format into a memory protocol formal (i.e., “implement[s] a data processing operation” on user data) and transmits the user data to memory controller 280. Regarding Claim 5, The same motivation to combine provided in Claim 1 is equally applicable to Claim 5. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 4, wherein the data processor is configured to implement the data processing operation associated with the user data based on a result of the secure operation implemented by the secure controller on the secure data. (Brown, “In a primary mode (prior to an operational mode), the security controller 270 may generate a transformation key and a concealed encryption key internally within the portable secure storage device” [0046] // “The operating encryption key is to be used to encrypt data to be stored into the memory 289 and to decrypt data read from the memory 289 during an operational mode.” [0050]) – As taught in Brown, encryption keys are generated by the security controller 270 during a “primary mode”, whereas data received from a host is encrypted by memory controller 280 during an “operational mode”. One of ordinary skill in the art would accordingly understand that the data processing operation performed by Data Transfer Controller 260 (see Claim 4 limitation mappings above) would be performed during an operational mode and thus would be performed after the encryption keys are generated (i.e., after the encryption keys are created). Regarding Claim 6, The same motivation to combine provided in Claim 1 is equally applicable to Claim 6. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1, wherein the secure data include one or more of: a cryptographic key, (Brown, “operating encryption key” [0045]) a digital certificate, authentication token or data, security policy, and audit log. (see MPEP 2140.03, selection of an element from list of alternatives) Regarding Claim 7, The same motivation to combine provided in Claim 1 is equally applicable to Claim 7. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1, wherein the secure operation includes one or more of: key generation, (Brown, “the security controller may generate a new operating encryption key” [0045]) encryption, decryption, generation of a digital signature, key wrapping or unwrapping, key storage, key rotation, key destruction, cryptographic hashing, managing a message authentication code (MAC), managing a digital certificate, user authentication and authorization, secure boot, and recording a log. (see MPEP 2140.03, selection of an element from list of alternatives). Regarding Claim 16, The same motivation to combine provided in Claim 1 is equally applicable to Claim 16. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1, wherein the secure data include an encrypted format of plaintext cryptographic security parameters (CSPs) (Lee, EMUK 112, Fig. 6 // ¶0096); and the secure controller is configured to operate on the plaintext CSPs. (Lee, Fig. 6 // ¶0093 // “the secure logic 140 stores the EMUK 122, which is obtained by reading, error-correcting, and encrypting the MUK 112” [0097] // Fig. 6) – As taught in Lee, secure logic 140 encrypts MUK 112 and stores the encrypted EMUK 122 in the second memory area 120 (inaccessible to writes by controller 200). Examiner accordingly considers EMUK 122 as additional “secure data”. Examiner considers the concept of a “memory unique key” (e.g., MUK 112) as disclosed in Lee as reading on the claimed concept of “plaintext cryptographic security parameters (CSPs)” (i.e., security parameters are “plaintext”/unencrypted). As shown in Fig. 6, secure logic 140 performs error correction on and encrypts (i.e., at least “operate[s] on”) the unencrypted MUK 112. Regarding Claim 17, The same motivation to combine provided in Claim 1 is equally applicable to Claim 17. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1, wherein the secure memory portion is accessible to the secure controller, and not accessible to the memory controller (Lee, Fig. 2) – As shown in Fig. 2, secure logic 140 can access first memory area 110, and controller 200 cannot access first memory area 110. Regarding Claim 20, Brown discloses the following limitations: A computer system (Fig. 1), comprising: a plurality of memory devices (Portable Secure Storage Devices 110, Fig. 1), each respective memory device (Fig. 2) further including: a non-volatile memory (NV Memory 276 + Memory 289, Fig. 2) including a secure memory portion (NV Memory 276, Fig. 2) and a data memory portion (Memory 289, Fig. 2 // “a non-volatile memory” [0027]), wherein the secure memory portion stores secure data including a first private key (“The security controller may store the concealed encryption key in the non-volatile memory 276 … The security controller may also store the transformation key in the non-volatile memory 276.” … The security controller 270 has the highest security level among the components in the portable storage device 110.” [0045-47]) – Non-volatile memory 276 is located within security controller 270 having the highest security level among components of the storage device 110. NV memory 276 stores keys including a “concealed encryption key” and a “transformation key”. Examiner considers a transformation key stored within NV memory 276 as reading on the claimed concept of “secure data including a first private key”--, and the data memory portion stores user data (“the user data stored in the memory 289 is encrypted or securely stored” [0039]); a memory controller (Memory Controller 280, Fig. 2) coupled to the data memory portion, the memory controller configured to receive a data access request and access the user data in response to the data access request (“the host 120 and the portable secure storage device 110 may be ready to exchange data (e.g., commands, user data, other data) … The data transfer controller 260 may receive data … from the host 120 … The memory controller 280 may encrypt the data and store the encrypted data in the memory 289” [0060-61]) – Memory Controller 280 receives user data from a host 120 (via data transfer controller 260), encrypts the user data, and stores the encrypted user data into memory 289--; a secure controller (Security Controller 270, Fig. 2) coupled to the secure memory portion, the secure controller configured to access the secure data and implement a secure operation on the secure data (“before the portable secure storage device 110 communicates with the host 120, the security controller may generate a new operating encryption key and a new transformation key” [0045] // “the security controller 270 may fetch the concealed encryption key from the non-volatile memory 276.” [0055]) – Security controller 270 generates and stores keys within NV 276 (i.e., at least “implement[s] a secure operation on the secure data”) and fetches keys from NV 276--, wherein the secure controller is distinct from the memory controller (“The security controller 270 is separate and distinct from the memory controller 280” [0047]) … and an integrated memory enclosure (Portable Secure Storage Device 110, Fig. 2) for enclosing the secure controller, the memory controller, and the non-volatile memory (“the portable secure storage device 110 includes a casing … the memory 289 and each of the controllers 260, 270, and 280 are disposed within the casing.” [0026]); wherein secure memory portions of the plurality of memory devices provide a distributed hardware security system. (Fig. 1) – Examiner considers the system depicted in Fig. 1 as “a distributed hardware security system”. Brown does not explicitly disclose security controller 270 performing the following limitations: configured to generate a first signature based on the first private key, generate a first signed message based on the user data provided by the memory controller, and provide the first signed message to a host device coupled to the respective memory device or to a data processor of the respective memory device; However, Lee discloses the following limitations: the secure controller (Authentication Code Generator 212, Fig. 6) is distinct from the memory controller (Authenticated Read Controller 210, Fig. 6)(“the authentication code generator 212 may be located externally to the authenticated read controller 210” [0123] // Fig. 6 // ¶¶0127; 0129) – Examiner considers Authentication Code Generator 212 and Authenticated Read Processor 210 depicted in Lee Fig. 6 (in the embodiment described in ¶0123 whereby the authentication code generator is external to authenticated read processor 210) as analogous to the Brown Fig. 2 Security Controller 270 and Memory Controller 280, respectively.-- configured to generate a first signature (“device authentication code DA_CODE” [0129]) based on the first private key (“a key” [0129])(“The authentication code generator 212 may generate the device authentication code DA_CODE based on a key shared with the host 300 … The shared key value may be previously set.” [0129] // ¶¶0121-130) – As shown in Fig. 6 and detailed in ¶0129, authentication code generator 212 generates a “device authentication code” (i.e., “a first signature”) using a key whose value is previously set (analogous to “the first private key”)--, generate a first signed message (DA_CODE, Fig. 6) based on the user data provided by the memory controller (“The authenticated read processor 211 may provide the memory device 100 with a command to read data stored in the write protection area of the memory device 100” [0125] // “generate the device authentication code DA_CODE based on a key shared with the host 300 and the read data R_DATA” [0129]) – As shown in Fig. 6, the DA_CODE is provided to host 300. Examiner accordingly considers the DA_CODE as “a first signed message”. The DA_CODE is generated based on R_DATA read by authenticated read processor 211 and stored to buffer 200 (i.e., “based on the user data provided by the memory controller”)--, and provide the first signed message to a host device (Host 300, Fig. 6) coupled to the respective memory device (“The authentication code generator may provide the host 300 with the generated device authentication code DA_CODE” [0129]) or to a data processor (Brown, Data Transfer Controller 260, Fig. 2) of the respective memory device. (see MPEP 2140.03, selection of an element from list of alternatives) Brown and Lee are considered analogous to the claimed invention because they all relate to the same field of performing data encryption/decryption and identity authorization in a data storage device. Therefore, it would have been obvious for someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Brown with the teachings of Lee and realize a storage device whereby a secure controller transmits a signed message to a host based on a key. Doing so improves data security by enabling a host to identify and prevent replay attacks whereby messages between the host and the storage device are intercepted, as disclosed in Lee ¶¶0075-76: “the storage device 50 may transmit th read data to the host 300 and may transmit the second response including the device authentication code to the host 300 … The host 300 may determine whether the series of requests and the responses regarding the security read are properly exchanged with the storage device … the host 300 may prevent a replay attack, in which a device other than the storage device 50 intercepts the series of requests and provides a response to the host 300.” [0075-76] Claims 8-9 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Brown further in view of Lee and Bert (US 20240020047 A1)(cited by examiner in previous Action)(hereafter referred to as Bert). Regarding Claim 8, The same motivation to combine provided in Claim 1 is equally applicable to Claim 8. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1 (see Claim 1 limitation mappings above), Although Lee teaches that secure logic 140 generally manages cryptographic keys, Brown and Lee do not explicitly disclose the following limitations: wherein the secure operation includes one or more of: establishing or managing one or more administrator credentials; associating an administrator account with a set of cryptographic keys; managing one or more administrator privileges for the administrator account; establishing or enforcing one or more policies associated with tampering events for the administrator account; controlling an access to a user account; managing one or more respective cryptographic keys for the user account; and enabling the user account to use the one or more respective cryptographic keys for cryptographic operations. However, Bert discloses the following limitations: the secure operation (Figs. 4, 22-23) includes one or more of: -- As shown in Bert Fig. 22, a storage device includes a secure memory region 333 which is coupled to an access controller 309, similar to how the storage device of Lee Fig. 6 includes a first memory area 110 coupled to secure logic 140. Examiner accordingly considers secure memory region 333 and access controller 309 as analogous to the claimed “secure memory portion” and “secure controller”, respectively.-- establishing or managing one or more administrator credentials (¶0158); associating an administrator account with a set of cryptographic keys; managing one or more administrator privileges for the administrator account; establishing or enforcing one or more policies associated with tampering events for the administrator account; controlling an access to a user account; (Figs. 22-23 // “manage access control configuration data 141 (e.g., user accounts, access rights, credential.)” [0158]) – As taught in ¶0158, a storage product 102 performs access control for user accounts. managing one or more respective cryptographic keys for the user account; and enabling the user account to use the one or more respective cryptographic keys for cryptographic operations. -- Claim 8 is being interpreted, in view of MPEP 2143.03, as requiring selection of an element from a list of alternatives. Brown, Lee and Bert are considered analogous to the claimed invention because they all relate to the same field of controlling access to secure data stored in secure memory portions of a memory device. Therefore, it would have been obvious for someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Brown and Lee with the teachings of Bert and realize a memory device which performs access control for user accounts using secure data stored in a secure memory portion. Doing so offloads a burden of processing data messages from a host to the memory device, improving scalability of a storage system by enabling a single host device to control multiple memory subsystems, as disclosed in Bert ¶0056: “Bypassing the local host system 120 in the processing of data messages greatly reduces the workloads of the local host system 120. Thus, the local host system 120 can be used to control multiple memory sub-systems (e.g., 110) in expanding storage capacity” [0056]. Regarding Claim 9, The same motivation to combine provided in Claim 1 is equally applicable to Claim 9. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1 (see Claim 1 limitation mappings above), Brown and Lee are silent regarding the following limitations: wherein the secure controller is configured to authenticate a user account based on the secure data and generate an authentication confirmation, and the memory controller is configured to grant the access to the user data based on the authentication confirmation However, Bert discloses the following limitations: wherein the secure controller (Access Controller 309, Fig. 22) is configured to -- As shown in Bert Fig. 22, a storage device includes a secure memory region 333 which is coupled to an access controller 309, similar to how the storage device of Lee Fig. 6 includes a first memory area 110 coupled to secure logic 140. Examiner accordingly considers secure memory region 333 and access controller 309 as analogous to the claimed “secure memory portion” and “secure controller”, respectively.-- authenticate a user account (“manage access control configuration data 141 (e.g., user accounts, access rights, credential.)” [0158]) based on the secure data (Cryptographic Keys 351, Fig. 22) and generate an authentication confirmation (Figs. 22 + 23 // “an access controller 309 configured to determine whether requests … are permitted by the cryptographic keys 351 … When a request … is determined to be valid using a cryptographic key 351, the request can be considered from an entity in possession of a cryptographic key representative of authorization or privilege to have the request processed in the storage product 102, otherwise, the request having no valid verification code can be rejected, ignored, discarded, etc.” [0364]), and the memory controller (Memory Sub-System Controller 115, 4 // ¶0165) is configured to grant the access to the user data based on the authentication confirmation (“the local host system 120 can send the storage device commands for storage operations, such as … read data at specified address, write data at specified address” [0165]) – As shown in Fig. 4 and taught in ¶0165, Memory Sub-System Controller 115 performs reads and writes on data stored in Memory Devices 130-140 at the request of a host. Examiner accordingly considers Memory Sub-System Controller 115 as analogous to the claimed “memory controller” coupled to “user data” stored outside of a secure memory portion. One of ordinary skill in the art would understand that memory sub-system controller 115 would perform an operation on user data (e.g., “have the request processed in the stored product”; see ¶0364) in response to access controller 309 determining that the host request is valid. Brown, Lee and Bert are considered analogous to the claimed invention because they all relate to the same field of controlling access to secure data stored in secure memory portions of a memory device. Therefore, it would have been obvious for someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Brown and Lee with the teachings of Bert and realize a memory device which performs access control for user data using secure data stored in a secure memory portion. Doing so offloads a burden of processing data messages from a host to the memory device, improving scalability of a storage system by enabling a single host device to control multiple memory subsystems, as disclosed in Bert ¶0056: “Bypassing the local host system 120 in the processing of data messages greatly reduces the workloads of the local host system 120. Thus, the local host system 120 can be used to control multiple memory sub-systems (e.g., 110) in expanding storage capacity” [0056]. Regarding Claim 11, The same motivation to combine provided in Claim 1 is equally applicable to Claim 11. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1 (see Claim 1 limitation mappings above), Brown and Lee do not explicitly disclose the following limitations: wherein: the secure data stored in the secure memory portion include a public key; the secure controller is configured to receive a signed message from a host device coupled to the memory device or from a data processor of the memory device, obtain the public key from the secure memory portion, verify the signature associated with the signed message using the public key, and extract content of the signed message in accordance with verification of the signature. However, Bert discloses the following limitations: the secure data stored in the secure memory portion (Secure Memory Region 333, Fig. 22) include a public key (Cryptographic Keys 351, Fig. 22 // “a public cryptographic key” [0394]) – As shown in Bert Fig. 22, a storage device includes a secure memory region 333 which is coupled to an access controller 309, similar to how the storage device of Lee Fig. 6 includes a first memory area 110 coupled to secure logic 140. Examiner accordingly considers secure memory region 333 and access controller 309 as analogous to the claimed “secure memory portion” and “secure controller”, respectively. As shown in Fig. 22 and clarified in ¶0394, the secure memory portion includes a public key--; the secure controller (Access Controller 309, Fig. 22) is configured to receive a signed message (“a request” [0364]) from a host device coupled to the memory device or from a data processor of the memory device (“a request received in the network interface 113, or the host interface 112, includes a verification code (e.g., a digital signature or a message authentication code)” [0364]), obtain the public key from the secure memory portion, verify the signature associated with the signed message using the public key, and extract content of the signed message in accordance with verification of the signature. (Figs. 22 + 23 // “an access controller 309 configured to determine whether requests … are permitted by the cryptographic keys 351 … When a request … is determined to be valid using a cryptographic key 351, the request can be considered from an entity in possession of a cryptographic key representative of authorization or privilege to have the request processed in the storage product 102, otherwise, the request having no valid verification code can be rejected, ignored, discarded, etc.” [0364] // “the recipient performs the validation of a verification code of a message using a public cryptography key” [0394]) – As taught in ¶0364, access controller 309 processes (i.e., at least “extract[s] content of”) a request received from a host or a network after validating the signature of the request using the public key stored in secure memory region 333. Brown, Lee and Bert are considered analogous to the claimed invention because they all relate to the same field of controlling access to secure data stored in secure memory portions of a memory device. Therefore, it would have been obvious for someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Brown and Lee with the teachings of Bert and realize a memory device whereby a public key stored in a secure memory portion is used to validate signatures of messages received from a host or elsewhere in a network. Doing so offloads a burden of processing data messages from a host to the memory device, improving scalability of a storage system by enabling a single host device to control multiple memory subsystems, as disclosed in Bert ¶0056: “Bypassing the local host system 120 in the processing of data messages greatly reduces the workloads of the local host system 120. Thus, the local host system 120 can be used to control multiple memory sub-systems (e.g., 110) in expanding storage capacity” [0056]. Claims 12-14 are rejected under 35 U.S.C. 103 as being unpatentable over Brown further in view of Lee and Lu et al. (US 20230104923 A1)(cited by examiner in previous Action)(hereafter referred to as Lu). Regarding Claim 12, The same motivation to combine provided in Claim 1 is equally applicable to Claim 12. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1 (see Claim 1 limitation mappings above), Brown and Lee are silent regarding the following limitations: wherein the integrated memory enclosure includes one or more tamper evidence labels configured to visually indicate whether a tamper attempt has occurred to the memory device However, Lu discloses the following limitations: wherein the integrated memory enclosure (Enclosure 130, Fig. 6A) includes one or more tamper evidence labels (“tamper stickers” [0066]) configured to visually indicate whether a tamper attempt has occurred to the memory device (“In some embodiments, tamper stickers can be placed on, in, or around the enclosure, electronics, and surfaces of the device in order to allow users of the device to easily identify if the device has been tampered with.” [0066] // Figs. 6A + 6B) – Examiner considers Enclosure 130 of Fig. 6A as analogous to the claimed “integrated memory enclosure” because it is an enclosure of a memory device (see Fig. 6B). As taught in ¶0066, tamper stickers are placed on the enclosure to indicate to users when tampering occurs. Brown, Lee and Lu are considered analogous to the claimed invention because they all relate to the same field of performing security operations on memory devices and on secure data stored within the memory devices. Therefore, it would have been obvious for someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Brown and Lee with the teachings of Lu and realize an integrated memory enclosure which includes mechanical components used to identify tampering attempts. Doing so is a cost effective, durable, and weather resistant method of securing memory devices from physical attacks, as disclosed in Lu ¶0041 - 43: “Even devices that are not connected to an open network, those that only transmit, store data, and/or send commands to devices in a local network, can leak sensitive information or send and store malicious information after being tampered with physically by an attacker … the inventors have developed gateways, software, and methods designed to reliably and securely transmit, store, and process data while being tamper proof and able to defend against physical and remote attacks.” [0041-43] Regarding Claim 13, The same motivation to combine provided in Claim 1 is equally applicable to Claim 12. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1 (see Claim 1 limitation mappings above), Brown and Lee are silent regarding the following limitations: further comprising: a fastening structure for mechanically holding the integrated memory enclosure; a tamper detection circuit configured to generate tamper indication data indicating an occurrence of a tamper attempt in response to a mechanical unfastening force applied to the fastening structure. However, Lu discloses the following limitations: a fastening structure (“tamper resistant screws” [0043]) for mechanically holding the integrated memory enclosure (Gateway 100, Fig. 1 // ¶0043) (“the inventors have developed gateways … to reliably and securely transmit, store and process data while being tamper proof and able to defend against physical and remote attacks … this can involve the integration of locks, tamper proof stickers, tamper resistant screws, tamper switches … among other techniques” [0043]) – As shown in Lu Fig. 1 and taught in ¶0043, a gateway 100 includes a memory 108 and protects stored data from attacks. Examiner accordingly considers gateway 100 of Lu Fig. 1 as analogous to the claimed “integrated memory enclosure”. As taught in ¶0043, gateway 100 includes physical security including tamper resistant screws (i.e., “a fastening structure”); a tamper detection circuit (Tamper Switch 104 + Data Generation Device 110, Fig. 1) configured to generate tamper indication data (“sense information” [0047]) indicating an occurrence of a tamper attempt ( “Tamper switch 104 is configured to sense tampering” [0051] // “Gateway 100 receives sense information transmitted by one or more data generation devices (1101 , 1102 ,… 110N ) coupled to the gateway … a data generation device may include a device that detects tampering (such as a tamper switch) to detect unauthorized tampering of the gateway or other devices. In this example, the sense information can be the state of the device and data generated by the device” [0047]) – As taught in ¶¶0047 and 0051, data generation devices 110 and tamper switch 104 create “sense information” in response to detected tampering attempts-- in response to a mechanical unfastening force applied to the fastening structure (“physical … attacks” [0043] // ¶0051) – One of ordinary skill in the art would understand that physical tampering attacks would at least include mechanical unfastening force applied to fastening structures such as screws. Brown, Lee and Lu are considered analogous to the claimed invention because they all relate to the same field of performing security operations on memory devices and on secure data stored within the memory devices. Therefore, it would have been obvious for someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Brown and Lee with the teachings of Lu and realize an integrated memory enclosure which includes mechanical components used to identify tampering attempts. Doing so is a cost effective, durable, and weather resistant method of securing memory devices from physical attacks, as disclosed in Lu ¶0041 - 43: “Even devices that are not connected to an open network, those that only transmit, store data, and/or send commands to devices in a local network, can leak sensitive information or send and store malicious information after being tampered with physically by an attacker … the inventors have developed gateways, software, and methods designed to reliably and securely transmit, store, and process data while being tamper proof and able to defend against physical and remote attacks.” [0041-43] Regarding Claim 14, The same motivation to combine provided in Claim 13 is equally applicable to Claim 14. The combined teachings of Brown, Lee, and Lu disclose the following limitations: The memory device of claim 13, wherein the secure controller (Lu, Controller 106, Fig. 1 // ¶¶0049; 0054) – Examiner considers Controller 106 depicted in Lu Fig. 1 as analogous to the claimed “secure controller” because controller 106 stores protected data including “sense information” (see ¶0049; i.e., “secure data”) into a protected memory (see ¶0054; i.e., “secure memory portion”)-- is configured to: receive the tamper indication data directly from the tamper detection circuit (Lu, “controller 106 may store … the sense information” [0049]); and in response to receiving the tamper indication data, select one of a plurality of tamper deterring actions (Lu, Fig. 3, step 308 // “the gateway generates an alert signal in response to sensing tampering of the gateway … At step 308, the gateway is placed in a secure state in response to receiving the alert signal … performed using controller 106” [0059-60]), the plurality of tamper deterring actions including at least self destruction of the secure memory portion storing the secure data (Lu, “any combination of the following actions may be taken: … 3) remove sense previously-stored information from the memory of the gateway (e.g., memory 108) … 6) delete and overwrite all information” [0062]) – As clarified in Lu ¶0062, controller 106 can take a variety of actions after placing the gateway into a secure state, including 3) deleting previously-stored sense information (“secure data”) from memory 108 (“secure memory portion”); and 6) deleting and overwriting all information. Examiner considers deleting secure data from a secure memory portion as “self destruction” (e.g., deleting all data stored within) of the data and memory. Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over Brown further in view of Lee and Ponnuswamy et al. (US 20220060317 A1)(cited by examiner in previous action)(hereafter referred to as Ponnuswamy). Regarding Claim 15, The same motivation to combine provided in Claim 1 is equally applicable to Claim 15. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1 (see Claim 1 limitation mappings above), Brown and Lee are silent regarding the following limitations: wherein the memory device is coupled to a baseboard management controller (BMC), and the BMC is configured to apply the secure controller to access the secure data and implement the secure operation on the secure data However, Ponnuswamy discloses the following limitations: wherein the memory device (Server 120, Fig. 1 // “persistent storage device” [0033]) is coupled to a baseboard management controller (BMC) (¶0036), and the BMC is configured to apply the secure controller (Service Agent 180, Fig. 1) to access the secure data and implement the secure operation on the secure data (“Device management through out-of-band management may be performed … In a specific embodiment, the out-of-band management platform can only be accessed from within the host OS via the service agent. The out-of-band management platform may interface with baseboard management controller (BMC) chips” [0035-36]) – As shown in Ponnuswamy Fig. 1, a server 120 includes a service agent 180 which enables access to a persistent memory 175 storing data encryption keys 179, similar to how the memory device 100 of Lee Fig. 6 includes secure logic 140 enabling access to a non-volatile memory area 110 storing memory unique keys. Examiner accordingly considers server 120 and service agent 180 of Ponnuswamy Fig. 1 as analogous to the claimed “memory device” and “secure controller”, respectively. As taught in Ponnuswamy, BMC chips can couple to server 120 and can provide, via memory agent 180, memory management functionality to an administrator. Brown, Lee and Ponnuswamy are considered analogous to the claimed invention because they all relate to the same field of performing access control operations on memory devices storing secure data. Therefore, it would have been obvious for someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Brown and Lee with the teachings of Ponnuswamy and realize a memory device storing secure data which is coupled to a BMC. Doing so enables an administrator to perform device management functions on the memory device to ensure the establishment of trust boundaries on the memory device, as disclosed in Ponnuswamy ¶0035: “The out-of-band management platform can provide an alternate and dedicated connection to the system separate from the actual network that the system runs on. This allows an administrator to ensure the establishment of trust boundaries since there is only a single entry point for the management interface. Device management through out-of-band management may be performed” [0035] Claim 18 is rejected under 35 U.S.C. 103 as being unpatentable over Brown further in view of Lee and DeVetter et al. (US 20190036704 A1)(cited by examiner in previous Action)(hereafter referred to as DeVetter). Regarding Claim 18, The same motivation to combine provided in Claim 1 is equally applicable to Claim 18. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1 (see Claim 1 limitation mappings above), wherein the secure controller is coupled to the host device (Lee, Host Device 300, Fig. 6 // Fig. 15) via a data transport protocol (Lee, ¶0183), which includes a peripheral component interconnect express (PCIe) protocol (Lee, “a PCI-express (PCI-E) protocol” [0183]) Lee is silent regarding the following limitations: and a nonvolatile memory express (NVMe) protocol. However, DeVetter discloses the following limitations: a nonvolatile memory express (NVMe) protocol (Fig. 1 // “The system may include a host device 102 and a storage device 104 communicatively and/or physically coupled together though … NVMe (Non-Volatile Memory Express)” [0012]) – As taught in DeVetter, a host device 102 communicates with a storage device 104 using a variety of protocols including NVMe. Lee discloses a storage device (Storage Memory Device 100, Fig. 6) coupled to a host device (Host Device 300, Fig. 6). DeVetter discloses a known method of coupling a storage device to a host device using an NVMe protocol (see limitation mappings above). It would have been obvious to one of ordinary skill in the art, as taught by DeVetter, to implement the method of coupling a storage device to a host device using an NVMe protocol to the storage device and host device of DeVetter. A person of ordinary skill in the art would have recognized that applying the known technique of coupling a host device and a storage device using an NVMe protocol as taught by DeVetter to the environment of Lee would have yielded the predictable result of a storage device and a host device being coupled using an NVMe protocol. Using an NVMe protocol to couple a storage device and a host device which are already coupled using alternative protocols would have been expected to make the storage device usable in a greater number of settings and environments. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to apply the known technique of coupling a storage device to a host device using an NVMe protocol, as taught by DeVetter, to the storage device and host device disclosed in Lee. See MPEP 2143, Rationale D. Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over Brown further in view of Lee and Baskaran et al. (US 20180053018 A1)(cited by examiner in previous action)(hereafter referred to as Baskaran). Regarding Claim 19, The same motivation to combine provided in Claim 1 is equally applicable to Claim 19. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1 (see Claim 1 limitation mappings above), Brown and Lee are silent regarding the following limitations: wherein the secure controller is configured to verify a first user account associated with the host device by: receiving, from the host device, a password associated with the first user account; receiving, from the host device, a user signature provided by the first user account, wherein the user signature is generated based on a user private key and a challenge provided by the secure controller to the host device; verifying the password and the user signature; and in accordance with a verification of both the password and the user signature, providing the secure data to the host device However, Baskaran discloses the following limitations: wherein the secure controller (Processor 202, Fig. 2 // Fig. 1 // ¶¶0032; 0037) is configured to verify a first user account (“performs authentication of user 110” [0037] // Fig. 1 // ¶0003) associated with the host device (User Device 112, Fig. 1 // ¶0028) – As shown in Baskaran Figs. 1 and 2 and taught in ¶0037, a processor 202 of a server performs operations on “encryption/decryption keys”, similar to how secure logic 140 of Lee Fig. 6 performs encryption on keys. Examiner accordingly considers processor 202 of Baskaran Fig. 2 as analogous to the “secure controller”. As taught in Baskaran ¶0037, processor 202 authenticates users when accessing bank accounts (see ¶0003) through a user device 112.-- by: receiving (¶0028), from the host device, a password (“password” [0044]) associated with the first user account; receiving, from the host device, a user signature (“digital signatures” [0044]) provided by the first user account, wherein the user signature is generated based on (¶0029) a user private key (“encryption/decryption key” [0029]) and a challenge (“authentication message” [0028]) provided by the secure controller to the host device (¶¶0028; 0042); verifying (¶0029) the password and the user signature (“the host computer 102 is used by the user 110 to access the data stored on the storage device 104 … the server 106 identifies … the user 110 … and transmits an authentication message to the user 110 … the user 110 provides an authentication response to the server 106 … Thereafter, the server 106 checks for the authentication response and authenticates the user 110” [0028-29] // “the server 200 transmits one or more authentication messages to user 110 … multiple messages can be sent to the personal device … In such cases, the user 110 provides an authentication response corresponding to each authentication message” [0042] // “the authentication response may be in the form of an OTP (One Time Password), PIN, password, security questions, tokens, digital signatures, or the like” [0044]) – As taught in Baskaran, processor 202 of a server sends multiple “authentication messages” (i.e., at least “a challenge”) to user device 112, after which user device 112 returns “authentication responses” including a password and a digital signature. The server validates the user after receiving the authentication responses. The authentication response (i.e., including the signature) is generated by the user device and is provided to the server so the user device can receive an encryption/decryption key (i.e., the signature is provided to the server in order for the user to receive “a user private key”; i.e., the signature is generated by the user device for the purposes of receiving (i.e., “based on”) the private key)--; and in accordance with a verification of both the password and the user signature, providing (¶0029) the secure data (“encryption/decryption key” [0029]) to the host device (“Accordingly, the server 106 may transmit encryption/decryption key to the host computer 102. In this manner, the user 110 is granted access to the data stored on or within the storage device” [0029] // ¶0045) – As clarified in Baskaran, the server sends encryption and decryption keys (i.e., “secure data”) to the user device after authentication the user to enable the user to access data. Brown, Lee, and Baskaran are considered analogous to the claimed invention because they all relate to the same field of controlling access to secure data by external requestors. Therefore, it would have been obvious for someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Brown and Lee with the teachings of Baskaran and realize a method of validating a user account based on a signature and a password received from an external host. Such an authentication process improve memory device security and reliability by protecting sensitive data from unauthorized access, as disclosed in Baskaran ¶0002: “With the advent of many method of unethical hacking and data theft, protection of sensitive data from unauthorized access has gained importance … The most commonly used scheme is authenticating access to data … Anther popular scheme is the use of an encryption algorithm, where data protected is first converted to a new form – cipher text --- using an encryption key and only then is stored.” [0002]. Claim 21 is rejected under 35 U.S.C. 103 as being unpatentable over Brown further in view of Lee and Orloff (US 20180260578 A1)(hereafter referred to as Orloff). Regarding Claim 21, The same motivation to combine provided in Claim 1 is equally applicable to Claim 21. The combined teachings of Brown and Lee disclose the following limitations: The memory device of claim 1 (see Claim 1 limitation mappings above), wherein at least one of a size of the secure controller (Brown, ¶¶0047; 0096) and a size of the secure memory portion -- see MPEP 2143.03-- is dynamically adjusted (Brown, “the encryption keys … are newly generated without receiving any such keys from the host 120 or a user and without receiving a command from the host 120 instructing the device 100 to generate any such keys” [0047] // “In one or more implementations, when the portable secure storage device is caused to be locked, the operating encryption key is deleted from the portable storage device 110 and is not retained in the portable secure storage device 110 (e.g.,not retained in … local memories … 276…)” [0047]) – As taught in Brown, security controller 270 generates encryption keys independently of host 120 and a user. Accordingly, when security controller 270 generates an encryption key, an amount of keys which are managed by the security controller 270 (i.e., “a size of the secure controller”) is increased independently of a host (i.e., the number of keys managed by the security controller is “dynamically adjusted” independent of the host). Similarly, when the portable storage device is locked, the operating encryption key is deleted from memory 276 and a number of keys managed by the security controller is reduced. Although Brown ¶0056 discloses a security tampering detection circuit included within security controller 270, Brown does not explicitly link the creation or deletion of an encryption key to a particular access or demand on the encryption key. Accordingly, Brown and Lee do not explicitly disclose the following limitations: a size of the secure controller … is dynamically adjusted in response to a demand on the secure operation and the secure data. However, Orloff discloses the following limitations: a size of the secure controller (Key Management Unit 1220, Fig. 1) … is dynamically adjusted (Fig. 7, step 7020-1) in response to a demand (Fig. 7, step 7010) on the secure operation and the secure data. (“The cryptographic keys may be securely stored by the container application 1180” [0027] // “In some examples, the container application may register with an operating system to receive certain events that indicate a desire to tamper with the system in an effort to circumvent the encryption and the various permissions … At operation 7010 the container application may receive an event indicating an attempt at circumventing the encryption … the keys of the encrypted file system element container may be deleted 7020-1, preventing access to the encrypted file system element container.” [0049] // Fig. 7 // ¶0030) – Examiner considers key management component 1220 depicted in Orloff Fig. 1 as analogous to security controller 270 of Brown Fig. 2 because both manage secure storage of encryption keys. As taught in Orloff, in response to a tampering event to circumvent encryption (i.e., “in response to a demand on the secure operation and the secure data”), encryption keys are deleted from the secure storage within the container application (i.e., “dynamically adjusting” a number of encryption keys managed by the key management component). Brown, Lee, and Orloff are considered analogous to the claimed invention because they all relate to the same field of managing encryption keys in a secure storage environment. Therefore, it would have been obvious for someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Brown and Lee with the teachings of Orloff and realize a memory device whereby an amount of secure data which is managed by a secure controller is reduced in response to a tampering event. Doing so would improve device security by preventing unauthorized access to encrypted data, as disclosed in Orloff ¶0049: At operation 7020, corrective action may be taken. For example, the keys of the encrypted file system element container may be deleted 7020-1, preventing access to the encrypted file system element container.” [0049] Response to Arguments Applicant’s arguments with respect to claims 1-9 and 11-21 have been considered but are moot in view of the newly-applied Brown reference because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JULIAN SCOTT MENDEL whose telephone number is (703)756-1608. The examiner can normally be reached M-F 10am - 4pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rocío del Mar Pérez-Vélez can be reached at 571-270-5935. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /J.S.M./Examiner, Art Unit 2133 /ROCIO DEL MAR PEREZ-VELEZ/Supervisory Patent Examiner, Art Unit 2133
Read full office action

Prosecution Timeline

Dec 16, 2024
Application Filed
Jan 22, 2026
Non-Final Rejection mailed — §103
Apr 16, 2026
Examiner Interview Summary
Apr 16, 2026
Applicant Interview (Telephonic)
Apr 22, 2026
Response Filed
Jul 21, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12681859
Memory Copy in Mesh Networks
3y 0m to grant Granted Jul 14, 2026
Patent 12670098
SYSTEMS AND METHODS FOR PREFETCHING DATA VIA A HOST-ACCESSIBLE PREFETCHER QUEUE
2y 10m to grant Granted Jun 30, 2026
Patent 12638975
METHOD AND SYSTEM FOR DISTRIBUTING AND MANAGING IO IN A DISAGGREGATED STORAGE ARCHITECTURE
3y 5m to grant Granted May 26, 2026
Patent 12625612
ELECTRONIC DEVICE FOR MANAGING MEMORY AND OPERATING METHOD THEREOF
4y 1m to grant Granted May 12, 2026
Patent 12619374
HOST MULTI-PATH LAYER WITH DYNAMIC ADJUSTMENT OF ZONE SETS THROUGH INTERACTION WITH A CENTRALIZED DISCOVERY CONTROLLER
2y 5m to grant Granted May 05, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+52.4%)
2y 4m (~8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 34 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month