DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In communications filed on 06/24/2026. Claims 1, 4-20 are amended. Claims 2-3 are cancelled. Claims 21, and 22 newly added. Claims 1-20 are pending in this examination.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This examination is in response to US Patent Application No. 19/003,867.
Examiner Note
Applicant’s submitting a replacement title on 06/24/2026 obviates previously raised title objection.
Applicant’s amendment to claim 17 obviates previously raised claim 17, claim objection.
Applicant’s submitting a replacement title on 06/24/2026 obviates previously raised title objection.
Applicant’s amendment to word “being” in claims 1, 3, 18-20 obviates previously raised claims 1-20 , 35 USC112(b) , second paragraph rejection.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION. —The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 4, 10, and 15 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 4, 10, and 15 are rejected for the following reason: these claims recite the word” being” which does not indicates performing definite action. Examiner suggest replacing the word “being with “is “or “are” or any other proper wording.
Examiner Note
The independent claims 1, 19, and 20 claims an alternative option “OR” in the limitation “indicating whether the application information is sensitive information or non- sensitive information “which this option gives the examiner to only map one of the alternatives , for example if the examiner chooses the non-sensitive alternative , then only few limitations needs to be mapped, and consequently , most of the dependent claims needs not to be mapped. Examiner suggests applicant, to make an appropriate correction/ modification in the subsequent claim set.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, and 4-22 are rejected under 35 U.S.C. 103 as being unpatentable over ZHANG QIANYING (CN110750791A) (filed in IDS 02/28/2025), hereinafter “Zhang” and in view of US Patent Application No. (2009/0293130) issued to Henry (filed in IDS 11/03/2025), and further in view of CHEN LIANG (CN110865884A), hereinafter “Chen”.
Regarding claim 1, Zhang discloses an information processing method, applied to an electronic device the method comprising:
[ Abstract, the embodiment of the disclosure discloses a method and a system for guaranteeing a trusted execution environment against physical attacks based on memory encryption, wherein the system for guaranteeing the trusted execution environment against physical attacks based on memory encryption comprises at least one first memory, at least one second memory, at least one first processor and at least one second processor…], and
wherein the first memory is disposed in a processor, and the second memory is disposed independently of the processor
[Page 6, paragraphs(2-7), FIG. 1 illustrates a schematic diagram of a system for protecting a trusted execution environment against physical attacks based on memory encryption according to an embodiment of the present disclosure. As shown in FIG. 1, the system 100 based on memory encryption to guarantee a trusted execution environment against physical attacks includes at least one first memory 101, at least one second memory 102, at least one first processor 103, and at least one second processor 104 ,wherein: The first memory 101 is an SoC on-chip memory, and is configured to store security data that requires high security protection, wherein the security data includes security-sensitive tasks; The second memory 102 is an SoC off-chip memory, and is configured to store the ciphertext of the security-sensitive task after encryption and integrity protection; The first processor 103 is configured to obtain the ciphertext of the security-sensitive task after encryption and integrity protection from the second memory 102, and perform integrity verification and decryption on the ciphertext of the security-sensitive task, Storing the security-sensitive task that has passed the integrity verification and decryption to the first memory 101 so as to be scheduled to run by the second processor 104;The first processor 103 is further configured to perform encryption and integrity protection on the security-sensitive tasks in the first memory 101 that are scheduled and run by the second processor 104, and then store them in the second memory. In the memory 102; The second processor 104 is configured to schedule and run the security-sensitive tasks that pass the integrity verification and decryption from the first memory 101]; and
and based on the attribute of the application information indicating the application information is non-sensitive information, writing the application information into the second memory without encryption.
[ Page 3, 6th paragraph, the second storage is divided into a first storage portion and a second storage portion, wherein the first storage portion is allocated to a secure world for storing the ciphertext of the security-sensitive task; the second storage portion the storage portion is allocated to the common world and is used to store general-purpose operating systems and non-security-sensitive tasks].
Zhang does not explicitly disclose; however, Henry discloses while loading application information, obtaining an attribute of the application information indicating whether the application information is sensitive information or non- sensitive information
[Abstract, an apparatus providing for a secure execution environment including a microprocessor and a secure non-volatile memory. The microprocessor executes non-secure application programs and a secure application program. The non-secure application programs are accessed from a system memory via a system bus, and the secure application program is executed in a secure execution mode. The microprocessor has a watchdog manager that monitors environments of the microprocessor by noting and evaluating data communicated by a plurality of monitors, and that classifies the data to indicate a security level associated with execution of the secure application program, and that directs secure execution mode logic to perform responsive actions in accordance with the security level. The secure non-volatile memory is coupled to the microprocessor via a private bus and stores the secure application program. Transactions over the private bus are isolated from the system bus and corresponding system bus resources within the microprocessor], and
[0021-0022] It is furthermore desirable when applications are loaded for secure execution by the microprocessor, that a mechanism is provided to obfuscate the structure and content of the applications from any extant observation means and that a mechanism be provided to authenticate the source of the application and to confirm its veracity…the present invention provides a superior technique over that which has heretofore been provided that enables the execution of secure application programs in a general purpose microprocessor platform. In one embodiment, an apparatus providing for a secure execution environment is presented. The apparatus includes a microprocessor and a secure non-volatile memory. The microprocessor is configured to execute non-secure application programs and a secure application program, where the non-secure application programs are accessed from a system memory via a system bus, and where the secure application program is executed in a secure execution mode….], and [0043, The microprocessor 101 includes SEM logic 105. The SEM logic 105 according to the present invention is configured to provide for initialization, operation, and termination of a secure execution mode within the microprocessor 101 as will be described in further detail herein below. The SEM logic 105 comprises logic, circuits, devices, or microcode (i.e., micro instructions or native instructions), or a combination of logic, circuits, devices, or microcode, or equivalent elements that are employed to initialize a secure execution mode, to load secure applications for execution, to execute those applications in a secure environment, to monitor a number of microprocessor and system attributes in order to detect and preclude tampering, to terminate the secure execution mode under appropriate conditions, and to halt processing altogether if tampering is detected], and [Abstract].
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Zhang by incorporating “secure execution environment including a microprocessor and a secure non-volatile memory”, as taught by Henry. One could have been motivated to do so in order for monitoring execution of secure application program in a secure non-volatile memory and classifying the data to indicate a security level associated with execution of the secure application program, and that directs secure execution mode logic to perform responsive actions in accordance with the security level [ Henry, Abstract]
While Zhang discloses determining whether storage space required to store the application information is greater than a remaining memory space of a first memory, based on the storage space required to store the application information being greater than the remaining memory space of the first memory as:
[Page 6, paragraphs(2-7), FIG. 1 illustrates a schematic diagram of a system for protecting a trusted execution environment against physical attacks based on memory encryption according to an embodiment of the present disclosure. As shown in FIG. 1, the system 100 based on memory encryption to guarantee a trusted execution environment against physical attacks includes at least one first memory 101, at least one second memory 102, at least one first processor 103, and at least one second processor 104 ,wherein: The first memory 101 is an SoC on-chip memory, and is configured to store security data that requires high security protection, wherein the security data includes security-sensitive tasks; The second memory 102 is an SoC off-chip memory, and is configured to store the ciphertext of the security-sensitive task after encryption and integrity protection; The first processor 103 is configured to obtain the ciphertext of the security-sensitive task after encryption and integrity protection from the second memory 102, and perform integrity verification and decryption on the ciphertext of the security-sensitive task, Storing the security-sensitive task that has passed the integrity verification and decryption to the first memory 101 so as to be scheduled to run by the second processor 104;The first processor 103 is further configured to perform encryption and integrity protection on the security-sensitive tasks in the first memory 101 that are scheduled and run by the second processor 104, and then store them in the second memory. In the memory 102; The second processor 104 is configured to schedule and run the security-sensitive tasks that pass the integrity verification and decryption from the first memory 101].
Zhang, and Henry do not explicitly disclose memory space; however, Chen discloses memory space as:[ A memory management method and device, in the method, firstly detecting the remaining memory space of the memory of the electronic device, then determining whether the residual memory space is less than or equal to the first threshold value, if the remaining content space is less than or equal to a first threshold, then the portion of data in the memory to the external memory of the electronic device, and releasing the memory space occupied by the part data for transfer to the external memory. kernel due to the migration to the external memory and releasing the memory space occupied by the part data of part data in the memory, thus, not by forcibly ending the application program is running, it can make the remaining memory space of the memory becomes larger, so as to avoid the residual memory space is too small to forced termination caused by the part program, it can realize all running program alive.].
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Zhang , and Henry by incorporating “memory management method,”, as taught by Chen. One could have been motivated to do so in order for determining whether the residual memory space is less than or equal to the first threshold value, if the remaining content space is less than or equal to a first threshold, then the portion of data in the memory to the external memory of the electronic device, and releasing the memory space occupied by the part data for transfer to the external memory. [ Chen, Abstract].
Regarding claim 4, wherein the writing the application information into the first memory comprises: obtaining remaining memory space of the first memory; when based on storage space required by the application information being greater than the remaining memory space of the first memory,
Henry does not explicitly disclose; however, the combination of Zhang and Chen discloses these limitations:
While Zhang discloses: [Page 6, paragraphs(2-7), FIG. 1 illustrates a schematic diagram of a system for protecting a trusted execution environment against physical attacks based on memory encryption according to an embodiment of the present disclosure. As shown in FIG. 1, the system 100 based on memory encryption to guarantee a trusted execution environment against physical attacks includes at least one first memory 101, at least one second memory 102, at least one first processor 103, and at least one second processor 104 ,wherein: The first memory 101 is an SoC on-chip memory, and is configured to store security data that requires high security protection, wherein the security data includes security-sensitive tasks; The second memory 102 is an SoC off-chip memory, and is configured to store the ciphertext of the security-sensitive task after encryption and integrity protection; The first processor 103 is configured to obtain the ciphertext of the security-sensitive task after encryption and integrity protection from the second memory 102, and perform integrity verification and decryption on the ciphertext of the security-sensitive task, Storing the security-sensitive task that has passed the integrity verification and decryption to the first memory 101 so as to be scheduled to run by the second processor 104;The first processor 103 is further configured to perform encryption and integrity protection on the security-sensitive tasks in the first memory 101 that are scheduled and run by the second processor 104, and then store them in the second memory. In the memory 102; The second processor 104 is configured to schedule and run the security-sensitive tasks that pass the integrity verification and decryption from the first memory 101].
Zhang does not explicitly disclose memory space , however. Chen discloses memory space as[ A memory management method and device, in the method, firstly detecting the remaining memory space of the memory of the electronic device, then determining whether the residual memory space is less than or equal to the first threshold value, if the remaining content space is less than or equal to a first threshold, then the portion of data in the memory to the external memory of the electronic device, and releasing the memory space occupied by the part data for transfer to the external memory. kernel due to the migration to the external memory and releasing the memory space occupied by the part data of part data in the memory, thus, not by forcibly ending the application program is running, it can make the remaining memory space of the memory becomes larger, so as to avoid the residual memory space is too small to forced termination caused by the part program, it can realize all running program alive.].
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Zhang , and Henry by incorporating “memory management method,”, as taught by Chen. One could have been motivated to do so in order for determining whether the residual memory space is less than or equal to the first threshold value, if the remaining content space is less than or equal to a first threshold, then the portion of data in the memory to the external memory of the electronic device, and releasing the memory space occupied by the part data for transfer to the external memory. [ Chen, Abstract].
Regarding claim 18, Zhang discloses based on the application information including information about a trusted application, configuring the first memory to be accessible by a trusted execution environment (TEE) but inaccessible by a rich execution environment (REE). Zhang discloses [ Page 1, last paragraph-page 2 , 1st paragraph, ARM TrustZone technology enables the secure world to resist malware attacks from the common world through resource access control and memory isolation, and builds a Trusted Execution Environment (TEE) for trusted applications, thereby enhancing the embedded system ’s safety….The method for protecting the confidentiality and integrity of security-sensitive tasks in the TEE system based on the first memory 101 using a software memory protection engine can improve the physical security of the TEE system and enable it to defend against physical attacks].
Regarding claims 19, and 20 , these claims are interpreted and rejected for the same rational set forth in claim 1.
Regarding claims 5-17, and 21-22 , these claims are not mapped because they contain the sensitive information from the independent claims which examiner has not chosen as an alternative option.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
See 892 for more relevant references.
FANG, XIAO-JIAN (CN 113051066 A) The embodiment of the invention claims a memory management method, device, device and storage medium. in the memory management method, when the first operator in the process applies memory space, if the available memory space remaining in the memory pool is less than the memory space of the first operator application, then finding the occupied memory space greater than the target operator of memory space of which the operation depends on the process. the target operator can release the memory space occupied by it is greater than the memory space of the operation dependent, namely the target operator releases the memory space occupied by it, until the available memory space remaining in the memory pool satisfies the application requirement of the first operator. Based on this embodiment, it can effectively improve the utilization rate of the memory space, which is beneficial to improve the processing efficiency of the task executed by the operator.
PARK KYU HO (KR 20110106058 A)[ [ Page 2, last paragraph, a two-stage main memory structure using heterogeneous memory using volatile memory as the primary main memory and nonvolatile memory as the secondary main memory has been proposed. In addition, conventionally, two levels of main memory are configured, and an interface is configured to allow transfer between the memories. Actually, the input / output of the conventional main memory is configured to be possible only in the primary volatile memory. If there is no data to be read in the primary volatile memory, the data is read from the secondary nonvolatile memory, and the primary volatile When the memory is short of write space, the data transfer is generated to the secondary nonvolatile memory], and [ Page 6, 1st paragraph].
ZENG, Yuan-qing (CN 104461737 B) [ Abstract, the invention claims a memory management method and device for recycled memory at a proper time and improve the efficiency of memory management. the method comprises the following steps: obtaining quasi-exchange exchange memory of designated area in the memory, using the exchange of exchange size Mswap memory representation and proportional to the fswap restriction factor fswap; The spare memory threshold value or a spare memory threshold value and process importance evaluation relation, calculating the free memory threshold of exchange factor f'swap; when the system is idle memory less than Mf, compressed to exchange exchange factor f'swap characterization memory; and the data exchange memory compression in exchange to the assigned region. In one aspect, the method of the invention is more rational, so the process will not be planes, on the other hand, system free memory is less than Mf, is compressed to the calculated exchange factor f'swap characterizing the exchange memory, when the memory is not enough, not only can expand memory space, but also can effectively protect the process].
RAO, MENG-LIANG(CN 103365721 A) [ Abstract, the invention claims a method and mobile terminal for adjusting mobile terminal in memory, wherein the method comprises the following steps: mobile terminal after obtaining operating browser memory space remaining quantity, judging whether the amount of memory space is less than or equal to threshold value, if it is, to release the memory space about the browser. The invention can save memory resource under the condition of not influencing the web page quality].
Jakobsson ( US2013/0024933) [0312] The security-sensitive task can involve loading and executing a predetermined application.
Nakata ( US2017/0109098) [0101] The garbage collection is an operation for creating a free space in NAND memory 12a by removing stale (invalid) data. Since the garbage collection operation increases the number of free blocks in the NAND memory 12a, valid data can be aggregated by using a plurality of erase blocks in which valid data and invalid data are mixed.
Chung ( US2006/0090029) [ [0013] Referring to FIG. 1, the flash memory system includes a host 110, a controller 120, at least one flash memory for main storage 130, and at least one flash memory for erase information storage 140.[0014] In this time, the flash memory for main storage 130 and the flash memory for erase information storage 140 have the same structure. In this case, the flash memory 130 and the flash memory 140 can share a portion of a single chip or share several chips with them being divided in a proper number. This can be set when designing the controller. For example, the smaller the size of the flash memory for erase information storage 140, the less the amount of data stored therein. Therefore, the data of the flash memory for erase information storage 140 is erased frequently. In this case, the flash memory for erase information storage 140 having a size enough to cover important data such as a program code can be used.[0015] The flash memory for main storage 130 stores stored data for erase in the flash memory for erase information storage 140 and then firstly erases the stored data for erase, if a temporary erase command for temporarily erasing data is received.[0016] The flash memory for erase information storage 140 secondarily completely erases the stored data for erase, if a complete erase command for completely erasing data is received.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHAHRIAR ZARRINEH whose telephone number is (571)272-1207. The examiner can normally be reached Monday-Friday, 8:30am-5:30pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached at 571-272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHAHRIAR ZARRINEH/Primary Examiner, Art Unit 2496