Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
The response filed 8/7/2026 was received and considered.
Claims 1-20 are pending.
Terminal Disclaimer
The terminal disclaimer filed on 8/7/2026 disclaiming the terminal portion of any patent granted on this application which would extend beyond the expiration date of 12,219,049 has been reviewed and is accepted. The terminal disclaimer has been recorded.
Claim Objections
Claims 3 and 16 are objected to because of the following informalities:
In claim 3, line 3, “an one-time” should be replaced with “a one-time”.
In claim 16, line 2, “an one-time” should be replaced with “a one-time”.
Appropriate correction is required.
Response to Arguments
Applicant’s remarks (p. 6, regarding the rejections on the ground of nonstatutory double patenting) are persuasive in view of the terminal disclaimer.
Applicant’s remarks (pp. 7-8, regarding rejections under 35 U.S.C. §103) are persuasive in view of Applicant’s clarification of common ownership. A rejection is set forth below and thus this Office Action is Non-Final.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim 1 is rejected under 35 U.S.C. 103 as being unpatentable over US 2022/0222348 A1 to Vaswani et al. (Vaswani), in view of US 2017/0337380 A1 to Domke et al. (Domke).
Regarding claim 1, Vaswani discloses a method for generating a key in a storage device, the method comprising: receiving a salt value (receiving measurement of L0, ¶¶41-42) from a firmware (L0 firmware, ¶41); generating a key material (derive CDI, ¶43, from unique device secret, ¶41); generating a private key using the salt value from the firmware and the key material (generate private key AK or DevID using at least CDI, ¶46); storing the generated private key (derive AK and create attestation certificate, ¶48); and storing the salt value used for generating the private key (storing measurement of L0 in an area of memory, ¶49) in a memory (stores public keys, signature and measurements in memory, ¶49). Vaswani lacks the memory comprising a non-volatile memory. However, Domke, in an analogous art (generating and storing a sealing key), teaches that it was known to generate a private key (sealing key) based on a random seed (sealing key is generated using the internal secret as the key, the random seed as the data, ¶32) and store the random seed in a non-volatile memory for later use (GUID 106, the random seed 108, and the sealing key 102 written to fields of the TMM 104, the partially-populated TMM 104 can be stored in non-volatile memory of the electronic device 100, such as the hard drive of the electronic device 100, ¶33). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Vaswani such that the area of memory storing the measurement of L0 is non-volatile. One of ordinary skill in the art would have been motivated to perform such a modification to enable further use of the data, as taught by Domke.
Claims 2-3 are rejected under 35 U.S.C. 103 as being unpatentable over Vaswani and Domke, as applied to claim 1, in view of US 2020/0313911 A1 to Mondello et al. (Mondello).
Regarding claim 2, Vaswani, as modified, lacks wherein the firmware cannot access the key material received from a key material generator. However, Mondello teaches that it was known to utilize a PUF value as a unique device secret (UDS) of DICE-RIoT (¶204). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to further modify Vaswani such that the firmware cannot access the key material received from a key material generator (construction of the PUF is not available to the firmware). One of ordinary skill in the art would have been motivated to perform such a modification to gain the benefits are creating a UDS that is specific to a particular device (PUF), as taught by Mondello.
Regarding claim 3, Vaswani, as modified, lacks wherein the key material is unique information related to the storage device and is generated using at least one of a physical unclonable function (PUF) or a one-time password (OTP). However, Mondello teaches that it was known to utilize a PUF value as a unique device secret (UDS) of DICE-RIoT (¶204). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to further modify Vaswani such that the key material (CDI derived from UDS) is unique information related to the storage device and is generated using at least one of a physical unclonable function (PUF) or a one-time password (OTP). One of ordinary skill in the art would have been motivated to perform such a modification to gain the benefits are creating a UDS that is specific to a particular device (PUF), as taught by Mondello.
Allowable Subject Matter
Claims 8-20 are allowable.
Claims 4-7 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims and if the rejection under non-statutory double patenting is overcome.
The following is a statement of reasons for the indication of allowable subject matter:
The Examiner initially refers to the Notice of Allowability in parent application 17/842,201, mailed 9/4/2024.
US 20200186340 A1 (Du; Ke et al.) teaches generate a key material (OTP memory, UDS C_PIN_PSID, ¶39), generating a private key using the salt value (¶45).
US 20220038275 A1 (HWANG; Su Ik et al.) teaches generating a unique encryption key for a device (¶42) based on a unique identifier (¶¶53-58).
“Rolling dice: Lightweight remote attestation for COTS IoT hardware” (Jäger, Lukas, Richard Petri, and Andreas Fuchs) teaches Device Identity Composition Engine (DICE), including generating a key from key material and a salt (Fig. 2 and §3).
“Dice harder: a hardware implementation of the device identifier composition engine” (Jäger, Lukas, and Richard Petri) teaches Device Identity Composition Engine (DICE), including generating a key from key material (measurement of next firmware level) and a salt (UDS, CDI) (Fig. 1).
US 20190044716 A1 (Nemiroff; Daniel et al.) teaches generating private keys based on a seed (¶32) and checking the validity of the key (¶101).
US 20220261508 A1 (Chuang; Kai-Hsin) teaches generating a private key from a salt and storing the salt (Figs. 6-7, ¶¶21-34).
US 20120185683 A1 (Krstic; Ivan et al.) teaches storing a salt in non-volatile memory (¶55), where the salt changes each boot (claim 13).
US 8423789 B1 (Poo; Tze Lei et al.) teaches a firmware module for encryption/decryption (Fig. 200, 202) and generating a cryptographic key (cols. 4-6).
US 20190342090 A1 (Pisasale; Michelangelo et al.) teaches using a PUF to generate cryptographic keys.
US 20160344545 A1 (Chou; Chun-Ming) teaches generating an encrypted key from a salt value storing in non-volatile memory (¶¶28-31).
“DICE: A Formally Verified Implementation of DICE Measured Boot” (Tao, Zhe, et al.) teaches generating a private key based on a salt and key material (Fig. 1).
“Implicit Identity Based Device Attestation” (TCG) teaches generating first and second private keys based on a UDS and firmware measurements (Fig. 1).
However, regarding claim 4, the prior art – individually, or in a reasonable combination – does not teach generating a seed based on the salt value provided from the firmware and the key material; generating a random number based on the seed; generating a primitive key based on the generated random number; and verifying the primitive key to generate the private key in combination with the remaining elements of the claims when considered as a whole.
Regarding claim 8, the prior art – individually, or in a reasonable combination – does not teach receiving a key ID from a firmware, in response to the salt value stored in the non-volatile memory matching the key ID; receiving a salt value from the firmware and generating a second private key using the salt value from the firmware and the key material, in response to the salt value matching the key ID not being stored in the non-volatile memory; and storing the salt value used for generating the second private key in the non-volatile memory, in combination with the recited key generation, when considered as a whole.
Regarding claim 18, the prior art – individually, or in a reasonable combination – does not teach wherein in response to a first salt value stored in a non-volatile memory matching a key ID, the private key is generated using the first salt value stored in the non-volatile memory and a key material, and in response to the first salt value matching the key ID not being stored in the non-volatile memory, the private key is generated using a second salt value from a firmware and the key material, in combination with the key certification steps, when considered as a whole.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL J SIMITOSKI whose telephone number is (571)272-3841. The examiner can normally be reached on Monday - Friday, 7:00-3:00.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached on 571-272-38623862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Michael Simitoski/ Primary Examiner, Art Unit 2493
August 14, 2026