DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
1. This action is responsive to the application filed on 01/08/2025.
2. Claims 1-20 are pending.
3. Claims 15-20 are not elected.
4. Claims 1-14 are rejected.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 01/08/2025 and 06/15/2026 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Election/Restrictions
Applicant's election with traverse of Group I, claims 1-14, in the reply filed on 06/03/2026 is acknowledged. The traversal is on the grounds that Group II, claims 15-20, if the search and examination of the entire application can be made without a serious burden, the Examiner must examine it on the merits.
The Examiner respectfully disagrees, as independent claim 1 and independent claim 8 disclose verifying the security of the memory device in order to update the firmware data. Independent Claim 15 discloses encrypting and decrypting data in the memory device and randomize a cache mapping function used to store the data in the cache memory used to store data. Thus, the Examiner will be under serious burden because the search strategy would require different fields of search in different classes/subclasses and having to employ different search queries.
The requirement is still deemed proper and is therefore made FINAL.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-14 are rejected under 35 U.S.C. 103 as being unpatentable over Shiva Dasari et al (US 20140281504 A1), hereinafter “Dasari” in view of Murugasamy K. Nachimuthu et al (US 20210011706 A1), hereinafter “Nachimuthu”.
Regarding Claim 1 and Claim 8, Dasari discloses a method and an apparatus, comprising:
receiving, at a memory controller and from a host, a command and firmware data (Dasari, Paragraph 0013, receiving instructions to update a firmware), wherein:
and the command is executed to update firmware stored on the first memory device (Dasari, Paragraph 0013, firmware update module is used in order to provide a firmware update);
accessing a first public key from a second memory device (Dasari, Paragraph RAM is authorized to use a test key signed build in order to authorize the firmware update);
validating the first public key with a second public key within the firmware data (Dasari, Paragraph 0013, firmware update module determined that the signature within the update capsule file is valid);
validating the firmware data (Dasari, Paragraph 0013, determining that the validation data within the signed update capsule file matches the unique data associated with the target system);
verifying a security version of the firmware data (Dasari, Paragraph 0025, comparing endorsement key numbers in order to determine that the signed update is valid);
and updating the first memory device with the firmware data (Dasari, Paragraphs 0013, 0026, updating the firmware of the target system).
However, Dasari fails to explicitly disclose the memory controller manages a first memory device using a compute express link (CXL) protocol.
Nachimuthu, from the same or similar field of endeavor, discloses the memory controller manages a first memory device using a compute express link (CXL) protocol (Nachimuthu, Paragraph 0032, providing an interface through a compute express link (CXL) register interface).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Dasari in view of Nachimuthu in order to further modify the method of authorizing a use of a test key signed built from the teachings of Dasari with the method of memory device firmware update and activation from the teachings of Nachimuthu.
One of ordinary skill in the art would have been motivated because the memory will be able to be upgraded using the appropriate interface of the CXL in a seamless manner (Nachimuthu – Paragraphs 0032, 0035).
Regarding Claim 2, the combination of Dasari and Nachimuthu disclose the method of claim 1 above, where Dasari further discloses wherein the first memory device is a non-volatile memory device and the second memory device is a volatile memory device (Dasari, Fig 1, Paragraphs 0010-0011, computer (target system) includes a random access memory and a non-volatile memory).
Regarding Claim 3, the combination of Dasari and Nachimuthu disclose the method of claim 2 above, where Nachimuthu further discloses wherein the first memory device is a ferroelectric memory device (Nachimuthu, Paragraph 0027, non-volatile memory includes a ferroelectric transistor random access memory).
Regarding Claim 4, the combination of Dasari and Nachimuthu disclose the method of claim 1 above, where Dasari further discloses further comprising determining whether a slot of the first memory device identified by the command is a correct slot for updating the first memory device with the firmware data (Dasari, Paragraph 0013, the firmware update module is also configured to determine that a signature within the signed update capsule file is valid and in response to determining that the signature is valid, determining that the validation data within the signed update capsule file matches the unique data associated with the target system. Paragraphs 0020-0021, 0026, using the information in the signed update capsule file in order to determine the update).
Regarding Claim 5, the combination of Dasari and Nachimuthu disclose the method of claim 1 above, where Dasari further discloses wherein verifying the security version comprises checking a customer ID associated with the firmware data; wherein the method further comprises terminating the update with the firmware data in response to determining that the firmware data and the customer ID do not match (Dasari, Paragraphs 0013, 0025-0026, matching unique data associated with target system and determining that the signed update capsule file matches the unique data associated with the target system).
Regarding Claim 6, the combination of Dasari and Nachimuthu disclose the method of claim 1 above, where Dasari further discloses wherein the validating of the firmware data is performed using an Rivest-Shamir-Adleman (RSA) operation (Dasari, Paragraphs 0011-0012, utilizing unique and secret RSA key in order to perform platform authentication).
Regarding Claim 7, the combination of Dasari and Nachimuthu disclose the method of claim 1 above, where Dasari further discloses further comprising receiving a command from the host indicating to activate the updated firmware data (Dasari, Fig 3, Paragraph 0029, updating the firmware of the target system based on determining that the target system is authorized to use the test key signed build).
Regarding Claim 9, the combination of Dasari and Nachimuthu disclose the apparatus of claim 8 above, where Dasari further discloses wherein the first public key is a public signing key accessed by reading the first public key from the first memory device (Dasari, Paragraphs 0013, 0022, using a public test key for decrypting a test key signed build).
Regarding Claim 10, the combination of Dasari and Nachimuthu disclose the apparatus of claim 8 above, where Dasari further discloses wherein, in response to the first public key being accessed, the memory controller is configured to check that a target slot for the firmware update is a same slot as an active slot (Dasari, Paragraph 0013, the firmware update module is also configured to determine that a signature within the signed update capsule file is valid and in response to determining that the signature is valid, determining that the validation data within the signed update capsule file matches the unique data associated with the target system. Paragraphs 0020-0021, 0026, using the information in the signed update capsule file in order to determine the update).
Regarding Claim 11, the combination of Dasari and Nachimuthu disclose the apparatus of claim 8 above, where Dasari further discloses wherein, in response to the target slot not being the same slot as the active slot, the memory controller is configured to issue an invalid slot return code and terminate the update of the first memory device with the firmware data (Dasari, Paragraphs 0013, 0025-0026, matching unique data associated with target system and determining that the signed update capsule file matches the unique data associated with the target system).
Regarding Claim 12, the combination of Dasari and Nachimuthu disclose the apparatus of claim 8 above, where Dasari further discloses wherein the memory controller is further configured to validate the second public key within the firmware data by comparing the second public key with the first public key (Dasari, Paragraph 0013, firmware update module determined that the signature within the update capsule file is valid).
Regarding Claim 13, the combination of Dasari and Nachimuthu disclose the apparatus of claim 8 above, where Nachimuthu further discloses wherein the second public key is a public key from a firmware image and the first public key is a public key previously stored in the first memory device (Nachimuthu, Paragraph 0036, FW images stored on the memory, wherein the firmware module is updated).
Regarding Claim 14, the combination of Dasari and Nachimuthu disclose the apparatus of claim 8 above, where Nachimuthu further discloses wherein, in response to updating the first memory device with the firmware data, the updated firmware is enabled via a CXL Activate command from the host (Nachimuthu, Paragraph 0032, using the CXL register interface in order to upgrade the firmware in the memory module).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. All the references listed on 892 are related to the subject matter of securely updating the firmware on a memory device.
Some of the prior art include:
US 20190042480 A1, which discloses a method of non-volatile memory and memory controller secured and authenticated pairing.
US 20140237261 A1, which discloses a method of process authenticated memory page encryption.
US 20220113960 A1, which discloses a method of differential firmware update generation.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAVIER O GUZMAN whose telephone number is (571)270-0588. The examiner can normally be reached Monday - Friday 8 am to 4 pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado can be reached at (571)272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JAVIER O GUZMAN/ Primary Examiner, Art Unit 2496