DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This Office Action is responsive to application 19/005,089 that the Applicant filed on December 30, 2024 and presented 20 claims. In accordance with the restriction requirement of April 23, 2026, the Applicant elects without traverse Group I, claims 1-5, for examination, and claims 6-20 are withdrawn. Claim 1 is amended through a preliminary amendment.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The following conventions apply to the mapping of the prior art to the claims:
Italicized text – claim language.
Parenthetical plain text – Examiner’s citation and explanation.
Citation without an explanation – an explanation has been previously provided for the respective limitation(s).
Quotation marks – language quoted from a prior art reference.
Underlining – language quoted from a claim.
Brackets – material altered from either a prior art reference or a claim, which includes the Examiner’s explanation that relates a claim limitation to the quoted material of a reference.
Braces – a limitation taught by another reference, but the limitation is presented with the mapping of the instant reference for context.
Numbered superscript – a first phrase to be moved upwards to the primary reference analysis.
Lettered superscript – a second phrase to be moved after the movement of the first phrase from which it was lifted, or more succinctly, move numbered material first, lettered material last.
A. Claims 1 and 2 are rejected under 35 U.S.C. 103 as being unpatentable over Dekens (2021/0117579, “Dekens”) in view of Dragone et al. (US 2018/0314840, “Dragone”), and further in view of Temple et al. (US 2017/0302441, “Temple”).
Regarding Claim 1
Dekens discloses
A hardware security module (HSM) (¶¶ [0043]-[0045], “The use of such hardware security modules can enable bus masters to be assigned security attributes in the bus layer.”), comprising:
an HSM bus matrix (¶ [0038], “The bus system may be a multi-layer [matrix] bus system (i.e. supporting parallel access paths between masters and slaves) and one or more of the interception points may be between two respective bus layers of the (multi-layer) bus system.”; and Fig. 1, ¶ [0081], “The bus system 2 may comprise a number [matrix] of interconnected buses.”);
a plurality of HSM master modules connected to a master side of the HSM bus matrix (Fig. 1, ¶ [0082], “The bus masters [modules] 6 may be other processors, peripherals with built-in DMA controllers, or any other bus masters.”, i.e., as illustrated in Fig. 1, the “bus 2” separates the master side of the bus masters/master modules from the “slave side”) and
comprising an HSM central processing unit (CPU) core and an HSM direct memory access (DMA) (Fig. 1, ¶ [0082], “The bus masters [modules] 6 may be other processors [central processing unit (CPU) core], peripherals with built-in DMA controllers, or any other bus masters.”),
the HSM DMA configured for data movement within the HSM and…1 (¶ [0032], “However, it is not essential that the filtering rules vary depending on which master component [DMA] initiated a bus transaction [for data movement]. For example, the filtering rules may simply require that, for a set of one or more of the slave components, no non-secure bus transactions (initiated by any master component) are allowed to reach these slave components [within the HSM], but that all secure bus transactions (initiated by any master component) are receivable by all slave components.”),
the HSM CPU core configured to process associated data and configure the HSM DMA (¶ [0042], “The processor [CPU] (optionally including an IDAU and/or SAU) may be configured to output a security-state signal to the bus system that indicates whether a bus transaction initiated by the processor [to process associated data] is secure or non-secure. The processor may be able to switch itself between a secure state and a non-secure state under the control of software instructions executed on the processor.”);
2 …. and a plurality of first HSM slave modules (Fig. 1, ¶ [0041], “The hardware filter logic may additionally comprise one or more slave-component filter units configured to apply at least some of the filtering rules within or adjacent one or more respective slave [modules] components.”),
which are all connected to a slave side of the HSM bus matrix (Fig. 1, ¶ [0103], “The master-side secure control logic 20 and slave-side secure control logic 22 [connected to the bus matrix as illustrated in Fig. 1] provide a number of filter units (or firewalls), which intercept bus transfers and implement the filtering rules.”),
3 …,
the first HSM slave modules (Fig. 1, ¶ [0041]) comprising…4; and
an HSM external bus port, one side of the HSM external bus port is connected to the slave side of the HSM bus matrix (Fig. 1, ¶ [0087], “The device 1 further includes a general purpose input/output (GPIO) controller 30 [establishing a connection to the slave side of the HSM bus matrix] which controls access to GPIO pins [external bus port] 31, 32, to which devices external to the device 1 can be connected.”), and
5 …,
6 …,
which are capable of accessing corresponding resources in the host via the HSM bus matrix and the HSM {external bus port (Dragone ¶ [0026], “Computing system 100 can receive incoming requests [via the external bus port] from a host via a bus 110.)} (¶ [0061], “The filtering rules may further depend on a type of each bus transaction [via the bus matrix]—e.g., depending on whether the bus transaction is a data-read request [for accessing corresponding resources], or a data-write request, or an instruction-fetch request. The hardware filter logic may be configured to read a bus access attribute from an intercepted bus request to determine whether the request is a data read, a data write, or an instruction fetch.”),
7 ….
Dekens doesn’t disclose
1 … data movement between the HSM and a corresponding module in a host,
2 an HSM static random-access memory (SRAM)…
3 the HSM SRAM configured to store sensitive information,
4 … at least one encryption/decryption engine module each configured to provide a respective encryption/decryption algorithm,
5 the other side of the HSM external bus port is connected to a master side of a host bus matrix of the host,
6 wherein both the HSM CPU core and the HSM DMA act as host master modules of the host,
7 wherein the HSM, the host and the host bus matrix are all integrated in a single controller.
Dragone, however, discloses
1 … data movement between the HSM and a corresponding module in a host (¶ [0020], “In some cases, the HSM can have two processors (a first processor and a second processor) that both receive the same inputs/requests from a host.”),
2 an HSM static random-access memory (SRAM)… (¶ [0047], “A non-exhaustive list of more specific examples of the computer-readable storage medium includes the following: …, a static random access memory (SRAM),…”; ¶ [0026], “Computing system 100 can be implemented as a hardware security module.”)
3 the HSM SRAM configured to store sensitive information (¶ [0023], “In the course of performing cryptographic functionality, an HSM manages and stores cryptographic keys, certificates, and/or configurations. These cryptographic keys, certificates, and/or configurations constitute a state of the HSM. With embodiments of the present invention, the state of an HSM can be stored in a persistent memory of the HSM.”),
4 … at least one encryption/decryption engine module each configured to provide a respective encryption/decryption algorithm (¶ [0026], “Computing system 100 can be implemented as a hardware security module.”; and “Computing system 100 can thus perform a variety of cryptographic [encryption/decryption] operations [via algorithms implemented by engine modules] 190 such as, for example, Advanced Encryption Standard (AES) operations, RSA operations, Secure Hash Algorithm (SHA) operations, and/or keyed-hash message authentication code (HMAC) operations.”),
5 the other side of the {HSM external bus port (Dekens Fig. 1, ¶ [0087], “The device 1 further includes a general purpose input/output (GPIO) controller 30 which controls access to GPIO pins [external bus port] 31, 32, to which devices external to the [host] device 1 can be connected.”)} is connected to a master side of a host bus matrix of the host (Fig. 1, i.e., the “on-chip bus system” of the host that is connected to the GPIO pins/external bus port),
6 wherein both the HSM CPU core and the HSM DMA act as {host master modules (Dekens Fig. 1, ¶ [0082])} of the host (¶ [0026], “Computing system 100 can receive incoming requests from a host via a bus 110. Bus 110 can be a Peripheral Component Interconnect Express (PCIe) bus, for example. Computing system 100 can also include a Direct Memory Access (DMA) controller 120 that can communicate with at least a first processor (CPU) 130 and a second processor 140 to process the requests.”),
Regarding the combination of Dekens and Dragone, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the HSM system of Dekens to arrive at the claimed invention. KSR establishes that a rationale for obviousness is proven by showing a “use of [a] known technique to improve similar devices in the same way.” See MPEP § 2143(I)(C).
To substantiate the conclusion of obviousness under this KSR rationale, the Examiner finds pursuant to MPEP § 2143(I)(C):
1) the prior art contained a base system, namely the HSM system of Dekens, upon which the claimed invention can be seen as an “improvement” through the use of memory and cryptographic algorithm features;
2) the prior art contained a “comparable” system, namely the HSM system of Dragone, that has been improved in the same way as the claimed invention through the memory and cryptographic algorithm features; and
3) one of ordinary skill in the art could have applied the known improvement technique of applying the memory and cryptographic algorithm features to the base HSM system of Dekens, and the results would have been predictable to one of ordinary skill in the art.
Temple, however, discloses
7 wherein the HSM, the host and the host bus matrix are all integrated in a single controller (Fig. 2, ¶¶ [0020]-[0021], “FIG. 2 shows an electronic control unit (ECU) 200 (also referred to as microcontrol unit) including an HSM 201. The HSM 201, the application core 202 and peripherals 203 are coupled via a first bus [matrix] 204.”; and ¶ [0033], “As in the example of FIG. 2, a DMA controller may perform data transactions within an embedded system [integrated within a single controller] which also includes a host CPU ( e.g. cores 206, 207 in FIG. 2).”).
Regarding the combination of Dekens-Dragone and Temple, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the HSM system of Dekens-Dragone to arrive at the claimed invention. KSR establishes that a rationale for obviousness is proven by showing a “use of [a] known technique to improve similar devices in the same way.” See MPEP § 2143(I)(C).
To substantiate the conclusion of obviousness under this KSR rationale, the Examiner finds pursuant to MPEP § 2143(I)(C):
1) the prior art contained a base system, namely the HSM system of Dekens-Dragone, upon which the claimed invention can be seen as an “improvement” through the use of a single controller feature;
2) the prior art contained a “comparable” system, namely the HSM system of Temple, that has been improved in the same way as the claimed invention through the single controller feature; and
3) one of ordinary skill in the art could have applied the known improvement technique of applying the single controller feature to the base HSM system of Dekens-Dragone, and the results would have been predictable to one of ordinary skill in the art.
Regarding Claim 2
Dekens in view of Dragone, and further in view of Temple (“Dekens-Dragone-Temple”) discloses the HSM of claim 1, and Dekens further discloses
wherein the HSM DMA (Fig. 1, ¶ [0082]) comprises
an HSM DMA controller and an HSM DMA arbiter (¶ [0082], “The bus masters 6 may be other processors, peripherals with built-in DMA controllers, or any other bus masters.”; and ¶¶ [0039]-[0041], “The hardware filter logic [DMA arbiter] may be configured to intercept bus transactions at one or more bus arbiters and/or one or more bridges.”),
the HSM DMA controller sharing the HSM bus matrix with the HSM CPU core and having a plurality of channels (Fig. 1 [illustrating the various relationships]), ¶¶ [0039]-[0041], “The hardware filter logic may additionally comprise one or more slave-component filter units [and associated channels] configured to apply at least some of the filtering rules within or adjacent one or more respective slave components [and associated channels].”],
each of the channels dedicated to management of one or more requests for a memory access to the HSM (¶¶ [0060]-[0061], “The hardware filter logic may be configured to intercept [and manage] all bus requests that pass the interception point. The filtering may depend on a slave (target) address of an intercepted bus transaction. However, the filtering [management] rules preferably specify access criteria at the component level—i.e., with the same filtering rules being applied to all memory addresses assigned to a register interface of a particular slave component (for a given security state of the slave component).”; and “The filtering rules may further depend on a type of each bus transaction—e.g., depending on whether the bus transaction is a data-read [memory access] request,...”),
the HSM DMA arbiter configured for priority management of the requests for the memory access (¶ [0031], “Secondly, embodiments of the present invention can support a particularly efficient integrated-circuit design, especially where some of the filtering rules [for memory access requests] apply only to [i.e., prioritize] a subset of the master components (i.e., where the filtering rules distinguish between the master components, so are not the same for all of the master components).”).
B. Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over Dekens in view of Dragone and Temple, and further in view of Mayer et al. (US 2017/0315944, “Mayer”).
Regarding Claim 3
Dekens-Dragone-Temple discloses the HSM of claim 1, and Dekens further discloses
1 …, and
when the HSM DMA and the HSM CPU core (Fig. 1, ¶ [0082])…2.
Dekens-Dragone-Temple
1 wherein permitted access to the HSM bus matrix is determined by round-robin scheduling,
2 …have the same destination for the memory access, the HSM DMA disrupts access of the HSM CPU core to the HSM bus matrix in appropriate bus cycles.
Mayer, however, discloses
1 wherein permitted access to the HSM bus matrix is determined by round-robin scheduling (¶ [0043], “With a bus (e.g., BBB 220), for example, the bus itself can be a shared resource [between the CPU core and DMA] with the SOC 121, so the other CPUs have to wait to use the resource when any one of the master agents (e.g., CPUs 4-7, CPUs via transparent bus 140, or other components) are utilizing it. However, with the on-chip interconnects 216-218 as part of the transparent interface 140, different masters talking to different slaves can be running in parallel (concurrently, at the same time) on the same resource (e.g., SRIs 0-2), and only when different masters talk to the same slave agent (e.g., Ethernet port ETH1, or other components) would contention be possible so that arbitration schemes could be utilized such as by round robin schemes, time division multiple access schemes, or otherwise.”),
2 …have the same destination for the memory access, the HSM DMA disrupts access of the HSM CPU core to the HSM bus matrix in appropriate bus cycles (¶ [0056], “In one example, a master agent (e.g., a CPU, DMA or the other similar component) could be selected via the arbitration component 306 according to an arbitration scheme for access requests [to the same destination for the memory access], and then facilitate a master-agent protocol that competes for bus [matrix] access to a particular slave agent (e.g., a memory or other component).”; and ¶ [0067], “For example, with multiple CPUs/DMAs with a lot of channels, to enable the customer to use the on chip resources in a flexible way, interrupts [disrupt access] can be mapped to CPUs/DMA channels by the interrupt component 308, for example.”).
Regarding the combination of Dekens-Dragone-Temple and Mayer, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the HSM system of Dekens-Dragone-Temple to arrive at the claimed invention. KSR establishes that a rationale for obviousness is proven by showing a “use of [a] known technique to improve similar devices in the same way.” See MPEP § 2143(I)(C).
To substantiate the conclusion of obviousness under this KSR rationale, the Examiner finds pursuant to MPEP § 2143(I)(C):
1) the prior art contained a base system, namely the HSM system of Dekens-Dragone-Temple, upon which the claimed invention can be seen as an “improvement” through the use of an access management feature;
2) the prior art contained a “comparable” system, namely the HSM system of Mayer, that has been improved in the same way as the claimed invention through the access management feature; and
3) one of ordinary skill in the art could have applied the known improvement technique of applying the access management feature to the base HSM system of Dekens-Dragone-Temple, and the results would have been predictable to one of ordinary skill in the art.
C. Claims 4 and 5 are rejected under 35 U.S.C. 103 as being unpatentable over Dekens in view of Dragone and Temple, and further in view of Fons et al. (US 2018/0217942, “Fons”).
Regarding Claim 4
Dekens-Dragone-Temple discloses the HSM of claim 1, and Dekens further discloses
wherein the host comprises…1,
one side of the {FMC (Fons ¶ [0059])} is connected to the slave side of the HSM bus matrix (Fig. 1, ¶ [0094], “This hardware security system logic 24 implements filtering rules that determine, for each pairing of master component 4, 6 and slave component 12, 14, 16, whether secure bus requests from the master component are receivable by the slave, and whether non-secure bus requests from the master component are receivable by the slave component. The filtering rules may also determine access permissions for the master components 4, 6 to defined regions of the RAM 8 and/or flash [FCM that is connected to the slave side as illustrated] memory 10.”), and
2 …,
the FMC having a dedicated flash memory area assigned to the HSM (Fig. 1, ¶ [0094], “The filtering rules may also determine access permissions [establishing a dedicated area] for the master components 4, 6 to defined regions of the RAM [memory area] 8 and/or flash memory [FMC] 10.”) and
configured for non-volatile storage of the sensitive information or running of security code (¶ [0057], “Typically, software code executing on a processor (being one of the master components) will be divided into secure code and non-secure code, with non-secure code executing when the processor is in the non-secure state, and not being able access one or more secure slave components and/or one or more secure regions of memory, and with secure code executing when the processor is in the secure state, and being able to access the one or more secure slave components and/or the one or more secure regions of the memory (and potentially having access to all the peripherals and/or memory on the device, depending how the device is configured).”).
Dragone further discloses
2 the other side of the FMC is connected to a slave side of the host bus matrix (Fig. 1, i.e., the “on-chip bus system” serving as the host bus matrix that divides master-slave sides as taught by Dekens),
Regarding the combination of Dekens and Dragone, the rationale to combine is the same as provided for claim 1 due to the overlapping subject matter of claims 1 and 4.
Dekens-Dragone-Temple doesn’t disclose
1 …a flash memory controller (FMC),
Fons, however, discloses
1 …a flash memory controller (FMC) (¶ [0059], “A non-volatile (e.g., flash) memory controller 357 is connected to the bus 210 and provides communication with a non-volatile (e.g., flash) memory 360.”),
Regarding the combination of Dekens-Dragone-Temple and Fons, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the HSM system of Dekens-Dragone-Temple to arrive at the claimed invention. KSR establishes that a rationale for obviousness is proven by showing a “use of [a] known technique to improve similar devices in the same way.” See MPEP § 2143(I)(C).
To substantiate the conclusion of obviousness under this KSR rationale, the Examiner finds pursuant to MPEP § 2143(I)(C):
1) the prior art contained a base system, namely the HSM system of Dekens-Dragone-Temple, upon which the claimed invention can be seen as an “improvement” through the use of a flash memory controller;
2) the prior art contained a “comparable” system, namely the HSM system of Fons, that has been improved in the same way as the claimed invention through the flash memory controller; and
3) one of ordinary skill in the art could have applied the known improvement technique of applying the flash memory controller to the base HSM system of Dekens-Dragone-Temple, and the results would have been predictable to one of ordinary skill in the art.
Regarding Claim 5
Dekens-Dragone-Temple discloses the HSM of claim 4, and Dekens further discloses
wherein the dedicated flash memory area (Fig. 1, ¶ [0094]) comprises at least one of a program region, a data region and a cache region (¶¶ [0083]-[0084], “The RAM 8 and flash memory 10 may be divided [dedicated] into regions which are assigned different respective security attributes (i.e., “secure” memory regions and “non-secure” memory regions).”; and “The various memory regions and peripherals may be responsive to secure requests [including data], non-secure requests, or both types of request. The security attribute of each memory region or peripheral may be fixed at the design stage or may be dynamically configurable.”).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to D'ARCY WINSTON STRAUB whose telephone number is (303)297-4405. The examiner can normally be reached Monday-Friday 9:00-5:00 Mountain Time.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, WILLIAM KORZUCH can be reached at (571)272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/D'Arcy Winston Straub/Primary Examiner, Art Unit 2491