DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
This Office action is in response to communications dated 5/19/2026.
Claims 1-20 are pending.
Claims 1-20 are rejected.
The text of those sections of Title 35, U. S. Code not included in this action can be found in a prior Office action.
Claim Rejections - 35 USC § 103
Claims 1-8 and 12-18 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Patent No. 5,557,674 (“Yeow”) in view of U.S. Patent No. 5,644,444 (“Braithwaite”).
As per claim 1, Yeow substantially teaches a storage device to secure data stored on a memory device when the storage device is unlocked, the storage device comprises:
a storage device to secure data stored on a memory device when the storage device is unlocked: (Yeow, Abstract; FIGURE 1; column 1, lines 8-20; column 2, lines 12-35, where the system of Yeow may lock individual files and directories of a storage device while leaving other portions of the storage device unlocked. This means that the storage device is unlocked. The Examiner notes that both files and directories are logical zones that contain data. Yeow therefore substantially teaches a storage device to secure data stored on a memory device when the storage device is unlocked);
a memory device to store data: (Yeow, Abstract; FIGURE 1; column 1, lines 8-20; column 2, lines 12-35, where the system of Yeow may be embodied as fixed storage media (i.e., memory devices) that may be locked and unlocked in order to store data securely. Yeow therefore substantially teaches a memory device to store data);
and a controller to identify at least one logical zone associated with the memory device, establish a first data restriction policy associated with a logical zone to enforce access rules when the storage device is unlocked, set at least one bit in a command structure to establish a data protection policy for the logical zone: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that the system of Yeow restructures a 32-byte directory entry field (i.e., a command structure) in order to lock the specified file or directory, which means that at least one bit of the 32-byte directory entry field has been set in order to establish that the specified file or directory is locked and therefore subject to a locked data protection policy. The Examiner further notes that the operations of locking a storage device described by Yeow are performed in conjunction with a controller to control operations of the storage device. Yeow therefore substantially teaches and a controller to identify at least one logical zone associated with the memory device, establish a first data restriction policy associated with a logical zone to enforce access rules when the storage device is unlocked, set at least one bit in a command structure to establish a data protection policy for the logical zone).
Yeow does not appears to explicitly teach the other limitations of this claim beyond those taught above; however, in an analogous art, Braithwaite teaches read/write protect scheme for a disk cartridge and drive.
As per claim 1, Braithwaite particularly teaches:
execute the first data restriction policy when the storage device receives a request to access data in the logical zone: (Braithwaite, Abstract; FIG. 6A; FIG. 6B; and column 9, line 30, to column 12, line 7, where the system of Braithwaite protects data stored on a drive by using a password. The drive may be protected from read operations, write operations, or both. When the password is entered, it is compared to a stored password on the drive to determine whether access to the drive should be granted or denied. If the password and the stored password match, the protected data may be accessed; conversely, if the password and the stored password do not match, the data protected by the password remains inaccessible. Braithwaite therefore particularly teaches execute the first data restriction policy when the storage device receives a request to access data in the logical zone).
It would have been obvious to a person having ordinary skill in the art, having the teachings of Braithwaite and Yeow before them before the instant application was effectively filed, to modify the system of Yeow to include the principles of Braithwaite of locking and unlocking files based on received access requests.
The modification would have been obvious because a person having ordinary skill in the art would be motivated to increase system security by implementing a read/write protect method for inhibiting unauthorized and/or inadvertent reading from, and writing to, a storage medium (Braithwaite, column 1, lines 6-11).
As per claim 2, the rejection of claim 1 is incorporated, and Yeow further substantially teaches:
wherein the controller sets a first bit in the command structure to one of enable and disable read protection control: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that the static lock of Yeow prevents read access to the specified file or directory; since the static lock may be enabled or disabled, restructuring the 32-byte directory entry enables or disables read access control for the specified file or directory. Yeow therefore substantially teaches wherein the controller sets a first bit in the command structure to one of enable and disable read protection control).
As per claim 3, the rejection of claim 1 is incorporated, and Yeow further substantially teaches:
wherein the controller sets a first bit in the command structure to one of enable and disable write protection control: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that the static lock of Yeow prevents write access to the specified file or directory; since the static lock may be enabled or disabled, restructuring the 32-byte directory entry enables or disables write access control for the specified file or directory. Yeow therefore substantially teaches wherein the controller sets a first bit in the command structure to one of enable and disable write protection control).
As per claim 4, the rejection of claim 1 is incorporated, and Yeo further substantially teaches:
wherein the controller sets a first bit in the command structure to one of enable and disable read protection control and sets a second bit in the command structure to one of enable and disable write protection control: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that while Yeow does not appear to explicitly teach setting a first bit to control read protection and a second bit to control write protection, it would have been obvious to a person having ordinary skill in the art before the instant application was effectively filed to use different bits for controlling read protection and write protection. The modification would have been obvious because a person having ordinary skill in the art would be motivated to increase system reliability by using different bits to control different operational settings in order to reduce a likelihood of erroneously setting bits to incorrectly control operations. Yeow therefore substantially teaches wherein the controller sets a first bit in the command structure to one of enable and disable read protection control and sets a second bit in the command structure to one of enable and disable write protection control).
As per claim 5, the rejection of claim 1 is incorporated, and Yeow further substantially teaches:
wherein the controller sets at least one third bit in the command structure to identify a number associated with the logical zone: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that while Yeow does not appear to explicitly teach setting a third bit to identify a number associated with the logical zone, it would have been obvious to a person having ordinary skill in the art before the instant application was effectively filed, to use a third bit to identify a number associated with the logical zone. The modification would have been obvious because a person having ordinary sill in the art would be motivated to increase system flexibility by making use of bits in the 32-byte directory entry to provide additional information about security measures implemented for the specified file or directory. Yeow therefore substantially teaches wherein the controller sets at least one third bit in the command structure to identify a number associated with the logical zone).
As per claim 6, the rejection of claim 1 is incorporated, and Yeow further substantially teaches:
wherein the controller uses a byte in the command structure to identify a number associated with the logical zone: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that while Yeow does not appear to explicitly teach using a byte of the command structure to identify a number associated with the logical zone, it would have been obvious to a person having ordinary skill in the art before the instant application was effectively filed, to use byte of the command structure to identify a number associated with the logical zone. The modification would have been obvious because a person having ordinary sill in the art would be motivated to increase system flexibility by making use of bytes in the 32-byte directory entry to provide additional information about security measures implemented for the specified file or directory. Yeow therefore substantially teaches wherein the controller uses a byte in the command structure to identify a number associated with the logical zone).
As per claim 7, the rejection of claim 1 is incorporated, and Braithwaite further particularly teaches:
wherein when the storage device receives a read request for data in the logical zone, the controller identifies the logical zone, obtains the first data restriction policy for the logical zone, prompts a requestor of the data for authentication credentials to access the data in the logical zone, and reads the data if the authentication credentials are valid: (Braithwaite, Abstract; FIG. 6A; FIG. 6B; and column 9, line 30, to column 12, line 7, where the system of Braithwaite protects data stored on a drive by using a password. The drive may be protected from read operations, write operations, or both. When the password is entered, it is compared to a stored password on the drive to determine whether access to the drive should be granted or denied. If the password and the stored password match, the protected data may be accessed; conversely, if the password and the stored password do not match, the data protected by the password remains inaccessible. Braithwaite therefore particularly teaches wherein when the storage device receives a read request for data in the logical zone, the controller identifies the logical zone, obtains the first data restriction policy for the logical zone, prompts a requestor of the data for authentication credentials to access the data in the logical zone, and reads the data if the authentication credentials are valid).
As per claim 8, the rejection of claim 1 is incorporated, and Braithwaite further particularly teaches:
wherein when the storage device receives a write request to write data to the logical zone, determines that write protection control is enabled for the logical zone, prompts a requestor of the data for authentication credentials to write the data <to?> the logical zone, writes the data to the memory device if the authentications credentials are valid and associates a logical block address for the data with the logical zone: (Braithwaite, Abstract; FIG. 6A; FIG. 6B; and column 9, line 30, to column 12, line 7, where the system of Braithwaite protects data stored on a drive by using a password. The drive may be protected from read operations, write operations, or both. When the password is entered, it is compared to a stored password on the drive to determine whether access to the drive should be granted or denied. If the password and the stored password match, the protected data may be accessed; conversely, if the password and the stored password do not match, the data protected by the password remains inaccessible. Braithwaite therefore particularly teaches wherein when the storage device receives a write request to write data to the logical zone, determines that write protection control is enabled for the logical zone, prompts a requestor of the data for authentication credentials to write the data to the logical zone, writes the data to the memory device if the authentications credentials are valid and associates a logical block address for the data with the logical zone).
As per claim 12, the rejection of claim 1 is incorporated, and Yeow further substantially teaches:
wherein a number of logical zones associated with the memory device and a size of the logical zone are stored in a zone table: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that the system of Yeow restructures a 32-byte directory entry field (i.e., a command structure) in order to lock the specified file or directory, which means that at least one bit of the 32-byte directory entry field has been set in order to establish that the specified file or directory is locked and therefore subject to a locked data protection policy. The Examiner further notes that the operations of locking a storage device described by Yeow are performed in conjunction with a controller to control operations of the storage device. Finally, the Examiner notes that information about a lock status rewrites File Allocation Table (FAT) information (i.e., information stored in a zone table for the storage device) for the specified file or directory. Yeow therefore substantially teaches wherein a number of logical zones associated with the memory device and a size of the logical zone are stored in a zone table).
As per claim 13, Yeow substantially teaches a method in a storage device for securing data stored on a memory device when the storage device is unlocked, the storage device comprises a controller to execute the method comprising:
a storage device for securing data stored on a memory device when the storage device is unlocked, the storage device comprises a controller to execute: (Yeow, Abstract; FIGURE 1; column 1, lines 8-20; column 2, lines 12-35, where the system of Yeow may lock individual files and directories of a storage device while leaving other portions of the storage device unlocked. This means that the storage device is unlocked. The Examiner notes that both files and directories are logical zones that contain data. Yeow therefore substantially teaches a storage device for securing data stored on a memory device when the storage device is unlocked);
the storage device comprises a controller to execute the method comprising: identifying at least one logical zone associated with the memory device; establishing a first data restriction policy associated with a logical zone to enforce access rules when the storage device is unlocked; setting at least one bit in a command structure to establish a data protection policy for the logical zone: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that the system of Yeow restructures a 32-byte directory entry field (i.e., a command structure) in order to lock the specified file or directory, which means that at least one bit of the 32-byte directory entry field has been set in order to establish that the specified file or directory is locked and therefore subject to a locked data protection policy. The Examiner further notes that the operations of locking a storage device described by Yeow are performed in conjunction with a controller to control operations of the storage device. Yeow therefore substantially teaches the storage device comprises a controller to execute the method comprising: identifying at least one logical zone associated with the memory device; establishing a first data restriction policy associated with a logical zone to enforce access rules when the storage device is unlocked; setting at least one bit in a command structure to establish a data protection policy for the logical zone).
Yeow does not appears to explicitly teach the other limitations of this claim beyond those taught above; however, in an analogous art, Braithwaite teaches read/write protect scheme for a disk cartridge and drive.
As per claim 13, Braithwaite particularly teaches:
receiving an access request to access data associated with the logical zone; and executing the first data restriction policy: (Braithwaite, Abstract; FIG. 6A; FIG. 6B; and column 9, line 30, to column 12, line 7, where the system of Braithwaite protects data stored on a drive by using a password. The drive may be protected from read operations, write operations, or both. When the password is entered, it is compared to a stored password on the drive to determine whether access to the drive should be granted or denied. If the password and the stored password match, the protected data may be accessed; conversely, if the password and the stored password do not match, the data protected by the password remains inaccessible. Access to data stored on the drive is thus restricted based on comparison of the password and the stored password. Braithwaite therefore particularly teaches receiving an access request to access data associated with the logical zone; and executing the first data restriction policy).
It would have been obvious to a person having ordinary skill in the art, having the teachings of Braithwaite and Yeow before them before the instant application was effectively filed, to modify the system of Yeow to include the principles of Braithwaite of locking and unlocking files based on received access requests.
The modification would have been obvious because a person having ordinary skill in the art would be motivated to increase system security by implementing a read/write protect method for inhibiting unauthorized and/or inadvertent reading from, and writing to, a storage medium (Braithwaite, column 1, lines 6-11).
As per claim 14, the rejection of claim 13 is incorporated, and Yeow further substantially teaches further comprising:
one of setting a first bit in the command structure to one of enable and disable read protection controller and setting the first bit in the command structure to one of enable and disable write protection control: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that the static lock of Yeow prevents read and write access to the specified file or directory; since the static lock may be enabled or disabled, restructuring the 32-byte directory entry enables or disables read and write access control for the specified file or directory. Yeow therefore substantially teaches one of setting a first bit in the command structure to one of enable and disable read protection controller and setting the first bit in the command structure to one of enable and disable write protection control).
As per claim 15, the rejection of claim 13 is incorporated, and Yeow further substantially teaches further comprising:
setting a first bit in the command structure to one of enable and disable read protection control and setting a second bit in the command structure to one of enable and disable write protection control: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that while Yeow does not appear to explicitly teach setting a first bit to control read protection and a second bit to control write protection, it would have been obvious to a person having ordinary skill in the art before the instant application was effectively filed to use different bits for controlling read protection and write protection. The modification would have been obvious because a person having ordinary skill in the art would be motivated to increase system reliability by using different bits to control different operational settings in order to reduce a likelihood of erroneously setting bits to incorrectly control operations. Yeow therefore substantially teaches setting a first bit in the command structure to one of enable and disable read protection control and setting a second bit in the command structure to one of enable and disable write protection control).
As per claim 16, the rejection of claim 13 is incorporated, and Yeow further substantially teaches further comprising:
one of setting at least one third bit in the command structure to identify a number associated with the logical zone and using a byte in the command structure to identify a number associated with the logical zone: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that while Yeow does not appear to explicitly teach setting a third bit to identify a number associated with the logical zone, it would have been obvious to a person having ordinary skill in the art before the instant application was effectively filed, to use a third bit to identify a number associated with the logical zone. The modification would have been obvious because a person having ordinary sill in the art would be motivated to increase system flexibility by making use of bits in the 32-byte directory entry to provide additional information about security measures implemented for the specified file or directory. Yeow therefore substantially teaches one of setting at least one third bit in the command structure to identify a number associated with the logical zone and using a byte in the command structure to identify a number associated with the logical zone).
As per claim 17, the rejection of claim 13 is incorporated, and Braithwaite further particularly teaches further comprising:
receiving a read request for data in the logical zone; identifying the logical zone; obtaining the first data restriction policy for the logical zone; determining that read protection control is enabled for the logical zone; prompting a requestor of the data for authentication credentials to access the data in the logical zone; and reading the data if the authentication credentials are valid: (Braithwaite, Abstract; FIG. 6A; FIG. 6B; and column 9, line 30, to column 12, line 7, where the system of Braithwaite protects data stored on a drive by using a password. The drive may be protected from read operations, write operations, or both. When the password is entered, it is compared to a stored password on the drive to determine whether access to the drive should be granted or denied. If the password and the stored password match, the protected data may be accessed; conversely, if the password and the stored password do not match, the data protected by the password remains inaccessible. Braithwaite therefore particularly teaches receiving a read request for data in the logical zone; identifying the logical zone; obtaining the first data restriction policy for the logical zone; determining that read protection control is enabled for the logical zone; prompting a requestor of the data for authentication credentials to access the data in the logical zone; and reading the data if the authentication credentials are valid).
As per claim 18, the rejection of claim 13 is incorporated, and Braithwaite further particularly teaches further comprising:
receiving a write request to write data to the logical zone; obtaining the first data restriction policy for the logical zone; determining that write protection control is enabled for the logical zone; prompting a requestor of the data for authentication credentials to write the data <to?> the logical zone; and writing the data to the memory device if the authentication credentials are valid and associating a logical block address for the data with the logical zone: (Braithwaite, Abstract; FIG. 6A; FIG. 6B; and column 9, line 30, to column 12, line 7, where the system of Braithwaite protects data stored on a drive by using a password. The drive may be protected from read operations, write operations, or both. When the password is entered, it is compared to a stored password on the drive to determine whether access to the drive should be granted or denied. If the password and the stored password match, the protected data may be accessed; conversely, if the password and the stored password do not match, the data protected by the password remains inaccessible. Braithwaite therefore particularly teaches receiving a write request to write data to the logical zone; obtaining the first data restriction policy for the logical zone; determining that write protection control is enabled for the logical zone; prompting a requestor of the data for authentication credentials to write the data to the logical zone; and writing the data to the memory device if the authentication credentials are valid and associating a logical block address for the data with the logical zone).
Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over U.S. Patent No. 5,557,674 (“Yeow”) in view of U.S. Patent No. 5,644,444 (“Braithwaite”) and further in view of U.S. Patent No. 9,501,222 (“Murphy”).
As per claim 9, the rejection of claim 1 is incorporated, but neither Yeow nor Braithwaite appears to explicitly teach the other limitations of this claim beyond those taught above; however, in an analogous art, Murphy teaches virtualized physical addresses for reconfigurable memory systems.
As per claim 9, Murphy particularly teaches:
wherein when data to be written to the memory device is associated with multiple logical zones, the controller uses a starting logical block address to identify the first data restriction policy: (Murphy, Abstract; FIG. 8; and paragraphs 0065-0069, where the system of Murphy enables mapping data to be written in multiple protection zones by using a predetermined starting address. Murphy therefore particularly teaches wherein when data to be written to the memory device is associated with multiple logical zones, the controller uses a starting logical block address to identify the first data restriction policy).
It would have been obvious to a person having ordinary skill in the art, having the teachings of Murphy, Braithwaite, and Yeow before them before the instant application was effectively filed, to modify the combination of Braithwaite with Yeow to include the principles of Murphy of using multiple protection zones.
The modification would have been obvious because a person having ordinary skill in the art would be motivated to increase system flexibility by implementing techniques that improve load balancing and enable disaggregation of storage (Murphy, paragraph 0005).
Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over U.S. Patent No. 5,557,674 (“Yeow”) in view of U.S. Patent No. 5,644,444 (“Braithwaite”) and further in view of USPGPUB 2024/0143509 (“Sela”).
As per claim 10, the rejection of claim 1 is incorporated, but neither Yeow nor Braithwaite appears to explicitly teach the other limitations of this claim beyond those taught above; however, in an analogous art, Sela teaches data storage device and method for handling write commands in zoned storage.
As per claim 10, Sela particularly teaches:
wherein during garbage collection the controller updates a logical zone password associated with relocated data: (Sela, Abstract; and paragraphs 0020, 0036, and 0048, where the system of Sela performs garbage collection by relocating valid data from old blocks and then designating the old blocks as eligible for erasure and reuse. The Examiner notes that when valid data is relocated from an old block to a new block, a password for accessing the new block would necessarily need to be updated at least because the new block did not previously use a password. Sela therefore particularly teaches wherein during garbage collection the controller updates a logical zone password associated with relocated data).
It would have been obvious to a person having ordinary skill in the art, having the teachings of Sela, Braithwaite, and Yeow before them before the instant application was effectively filed, to modify the combination of Braithwaite with Yeow to include the principles of Sela of performing storage space management operations.
The modification would have been obvious because a person having ordinary skill in the art would be motivated to increase system performance by implementing zoned namespaces, which improve throughput and latency (Sela, paragraph 0035).
Claims 11 and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Patent No. 5,557,674 (“Yeow”) in view of U.S. Patent No. 5,644,444 (“Braithwaite”) and further in view of non-patent literature “Planning for Multilevel Security and the Common Criteria” (“IBM”).
As per claim 11, the rejection of claim 1 is incorporated, but neither Yeow nor Braithwaite appears to explicitly teach the other limitations of this claim beyond those taught above; however, in an analogous art, IBM teaches multilevel security.
As per claim 11, IBM particularly teaches:
wherein the controller sets a second data restriction policy for data in the logical zone, wherein the controller provides a start logical block address and an end logical block address for the data in the command structure: (IBM, pages 22-23, sections “Access controls,” “Subjects and objects,” “Mandatory access control (MAC),” and “Discretionary access control,” where the system of IBM uses access control policies that place users at specific clearance levels and objects in specific categories; placing users at specific clearance levels and objects in specific categories constitutes a first data restriction policy. When a given user requests to access (e.g., via a second access request) a given object, the system of IBM uses Access Control Lists (ACLs) and labels to determine whether to grant or deny the given user access to the given file. The grant or denial based on ACLs and labels is enforcement of a second data restriction policy. The Examiner notes that a given file (i.e., object) is a collection of logical block addresses, so restricting access to the given file is enforcing a security policy that restricts access to data stored within a range from a starting logical block address to an ending logical block address of the given file. IBM therefore particularly teaches wherein the controller sets a second data restriction policy for data in the logical zone, wherein the controller provides a start logical block address and an end logical block address for the data in the command structure).
It would have been obvious to a person having ordinary skill in the art, having the teachings of IBM, Braithwaite, and Yeow before them before the instant application was effectively filed, to modify the combination of Braithwaite with Yeow to include the principles of IBM of using multilevel security to control access to a system.
The modification would have been obvious because a person having ordinary skill in the art would be motivated to increase system security by implementing security policies that include controls to prevent unauthorized individuals from accessing information as a higher classification level than their authorization while prevents individuals from declassifying information (IBM, page 21, section “Chapter 1. What is multilevel security?”, paragraph 4).
As per claim 19, the rejection of claim 13 is incorporated, but neither Yeow nor Braithwaite appears to explicitly teach the other limitations of this claim beyond those taught above; however, in an analogous art, IBM teaches multilevel security.
As per claim 19, IBM particularly teaches further comprising:
using a starting logical block address to identify the first data restriction policy when data to be written to the memory device is associated with multiple logical zones: (IBM, pages 22-23, sections “Access controls,” “Subjects and objects,” “Mandatory access control (MAC),” and “Discretionary access control,” where the system of IBM uses access control policies that place users at specific clearance levels and objects in specific categories; placing users at specific clearance levels and objects in specific categories constitutes a first data restriction policy. When a given user requests to access (e.g., via a second access request) a given object, the system of IBM uses Access Control Lists (ACLs) and labels to determine whether to grant or deny the given user access to the given file. The grant or denial based on ACLs and labels is enforcement of a second data restriction policy. The Examiner notes that a given file (i.e., object) is a collection of logical block addresses, so restricting access to the given file is enforcing a security policy that restricts access to data stored within a range from a starting logical block address to an ending logical block address of the given file. IBM therefore particularly teaches using a starting logical block address to identify the first data restriction policy when data to be written to the memory device is associated with multiple logical zones).
It would have been obvious to a person having ordinary skill in the art, having the teachings of IBM, Braithwaite, and Yeow before them before the instant application was effectively filed, to modify the combination of Braithwaite with Yeow to include the principles of IBM of using multilevel security to control access to a system.
The modification would have been obvious because a person having ordinary skill in the art would be motivated to increase system security by implementing security policies that include controls to prevent unauthorized individuals from accessing information as a higher classification level than their authorization while prevents individuals from declassifying information (IBM, page 21, section “Chapter 1. What is multilevel security?”, paragraph 4).
As per claim 20, Yeow substantially teaches a method in a storage device for securing data stored on a memory device when the storage device is unlocked, the storage device comprises a controller to execute the method comprising:
a storage device for securing data stored on a memory device when the storage device is unlocked, the storage device comprises a controller: (Yeow, Abstract; FIGURE 1; column 1, lines 8-20; column 2, lines 12-35, where the system of Yeow may lock individual files and directories of a storage device while leaving other portions of the storage device unlocked. This means that the storage device is unlocked. The Examiner notes that both files and directories are logical zones that contain data. Yeow therefore substantially teaches a storage device for securing data stored on a memory device when the storage device is unlocked, the storage device comprises a controller);
identifying at least one logical zone associated with the memory device; establishing a first data restriction policy associated with a logical zone to enforce access rules when the storage device is unlocked; setting at least one bit in a command structure to establish a data protection policy for the logical zone: (Yeow, Abstract; FIGURE 1; “FIGURE 1: continued”; and column 3, line 44, to column 6, line 5, where the process of locking a user-specified file or directory to be locked is described. In the system of Yeow, a specified file or directory (i.e., a specified logical zone) is identified from input information and located. The specified file or directory is then locked by restructuring a 32-byte directory entry filed into an absolute static lock format in order to lock the specified file or directory and thus establish a data restriction policy for (i.e., associated with) the specified file or directory. The Examiner notes that the system of Yeow restructures a 32-byte directory entry field (i.e., a command structure) in order to lock the specified file or directory, which means that at least one bit of the 32-byte directory entry field has been set in order to establish that the specified file or directory is locked and therefore subject to a locked data protection policy. The Examiner further notes that the operations of locking a storage device described by Yeow are performed in conjunction with a controller to control operations of the storage device. Yeow therefore substantially teaches identifying at least one logical zone associated with the memory device; establishing a first data restriction policy associated with a logical zone to enforce access rules when the storage device is unlocked; setting at least one bit in a command structure to establish a data protection policy for the logical zone).
Yeow does not appears to explicitly teach the other limitations of this claim beyond those taught above; however, in an analogous art, Braithwaite teaches read/write protect scheme for a disk cartridge and drive.
As per claim 20, Braithwaite particularly teaches:
receiving a first access request to access the logical zone; executing the first data restriction policy: (Braithwaite, Abstract; FIG. 6A; FIG. 6B; and column 9, line 30, to column 12, line 7, where the system of Braithwaite protects data stored on a drive by using a password. The drive may be protected from read operations, write operations, or both. When the password is entered, it is compared to a stored password on the drive to determine whether access to the drive should be granted or denied. If the password and the stored password match, the protected data may be accessed; conversely, if the password and the stored password do not match, the data protected by the password remains inaccessible. Access to data stored on the drive is thus restricted based on comparison of the password and the stored password. Braithwaite therefore particularly teaches receiving a first access request to access the logical zone; executing the first data restriction policy).
It would have been obvious to a person having ordinary skill in the art, having the teachings of Braithwaite and Yeow before them before the instant application was effectively filed, to modify the system of Yeow to include the principles of Braithwaite of locking and unlocking files based on received access requests.
The modification would have been obvious because a person having ordinary skill in the art would be motivated to increase system security by implementing a read/write protect method for inhibiting unauthorized and/or inadvertent reading from, and writing to, a storage medium (Braithwaite, column 1, lines 6-11).
Neither Yeow nor Braithwaite appears to explicitly teach the other limitations of this claim beyond those taught above; however, in an analogous art,
As per claim 20, IBM particularly teaches:
and establishing a second data restriction policy associated with data in the logical zone; receiving a second access request to access the data in the logical zone; and executing the second data restriction policy: (IBM, pages 22-23, sections “Access controls,” “Subjects and objects,” “Mandatory access control (MAC),” and “Discretionary access control,” where the system of IBM uses access control policies that place users at specific clearance levels and objects in specific categories; placing users at specific clearance levels and objects in specific categories constitutes a first data restriction policy. When a given user requests to access (e.g., via a second access request) a given object, the system of IBM uses Access Control Lists (ACLs) and labels to determine whether to grant or deny the given user access to the given file. The grant or denial based on ACLs and labels is enforcement of a second data restriction policy. IBM therefore particularly teaches and establishing a second data restriction policy associated with data in the logical zone; receiving a second access request to access the data in the logical zone; and executing the second data restriction policy).
It would have been obvious to a person having ordinary skill in the art, having the teachings of IBM, Braithwaite, and Yeow before them before the instant application was effectively filed, to modify the combination of Braithwaite with Yeow to include the principles of IBM of using multilevel security to control access to a system.
The modification would have been obvious because a person having ordinary skill in the art would be motivated to increase system security by implementing security policies that include controls to prevent unauthorized individuals from accessing information as a higher classification level than their authorization while prevents individuals from declassifying information (IBM, page 21, section -“Chapter 1. What is multilevel security?”, paragraph 4).
Response to Arguments
In the Remarks dated 5/19/2026, Applicant substantially argues:
Yeow explicitly discloses that its absolute static lock may be applied at the media level to files and directories stored within a FAT-based storage medium and that application of the absolute static lock requires copying files or directories to be locked into host memory of a host system. Yeow thus fails to teach or suggest a storage device that is separate from the host system, as required by the instant application. Furthermore, it would be inefficient for a controller on a storage device to copy files or directories from a memory device to host memory and then to a storage device in order to perform the absolute static lock of Yeow. The absolute static lock of Yeow is thus performed on the host by the host controller rather than by a controller on a separate storage device. There is no teaching or suggestion in Yeow of a controller on a storage device to identify a logical zone associated with the memory device, establish a first data restriction policy associated with the logical zone to enforce access rules when the storage device is unlocked, set at least one bit in a command structure to establish a data protection policy for the logical zone, and execute the first data restriction policy when the storage device receives a request to access data in the logical zone, as presently claimed. The controller of Yeow does not establish a first data restriction policy associated with the logical zone to enforce access rules when the storage device is unlocked, and set at least one bit in a command structure to establish a data protection policy for the logical zone, as recited in the pending claims; instead, a user determines whether a file is to be locked, and an ASCII character is added to a filename or path to easily identify locked file attributes.
Applicant’s arguments dated 5/19/2026 have been fully considered, but they are not persuasive. The Examiner first notes that the claims do not appear to require a storage device that is separate from a host system; Applicant thus appears to be arguing unclaimed features. Such arguments are not persuasive. See MPEP 2145(VI).
The Examiner further notes that the operations of Yeow, in combination with the other prior art of record, reasonably yield a data protection system and scheme that read on the claims of the instant application. Exemplary independent claim 1 of the instant application requires a storage device to secure data stored on a memory device when the storage device is unlocked. The storage device of the instant application comprises a memory device to store data and a controller to perform as least the following functions:
identify a logical zone associated with the memory device;
establish a first data restriction policy associated with the logical zone to enforce access rules when the storage device is unlocked;
set at least one bit in a command structure to establish a data protection policy for the logical zone; and
execute the first data restriction policy when the storage device receives a request to access data in the logical zone.
Putting aside Applicant’s focus on Yeow or Braithwaite individually instead of considering what the combination of prior art references as a whole teaches,
The Examiner notes that the storage device of the combination of the prior art relied upon in the non-final Office action dated 2/19/2026 teaches at least the following:
Individual files and directories stored within memory of a storage device may be locked (i.e., secured) while the storage device is accessible (i.e., unlocked). The Examiner notes that a storage device may be considered to be a logical zone of storage; locking given files and directories stored in the memory of the storage device requires that the given files and directories to be locked have been identified;
The memory of the storage device is used to store given files and directories. Given files may be locked, which makes the locked given files inaccessible. Locking given, selected files stored within the memory of the storage device to make the given, selected files inaccessible implements a first data restriction policy of restricting access to the given, selected locked files stored within (i.e., associated with) the memory of the storage device;
For files and directories stored within the memory of the storage device, restructuring a 32-byte directory entry is performed in order to lock a given file. As evidenced by the attached definition of “restructure,” which is not relied upon by the Examiner for any rejection but is merely and only provided as evidence, “restructure” may mean “to change the makeup, organization, or pattern of.” Restructuring a 32-byte directory entry thus by definition requires changing the makeup, organization, or pattern of the 32-byte directory entry; since the 32-byte directory entry consists of bits, restructuring the 32-byte directory entry requires setting at least one bit of the 32-byte directory entry. As noted in the non-final Office action dated 2/19/2026, the 32-byte directory entry corresponding to a given, selected file controls storage of and access to the given, selected file and is thus a command structure associated with the given, selected file stored in the memory of the of the storage device. Since at least one bit within the 32-byte directory entry associated with the given, selected file to be locked is changed during restructuring of the 32-byte directory entry, at least one bit of a command structure associated with the given, selected file is set in order to lock the given, selected file to implement a first data protection policy for the memory of the storage device in which access to given, selected files that are locked is restricted; and
The storage device of the combination of the prior art relied upon in the non-final Office action dated 2/19/2026 executes the restructuring of the 32-byte directory entry in order to implement the data protection policy that access to locked files and directories within the storage device is restricted. When a request to access locked data is received, the storage device of the combination of the prior art relied upon in the non-final Office action dated 2/19/2026 compares inputted information with stored security information in order to allow or deny access.
For at least the above reasons in sections 33-36 of the instant Office action, Applicant’s arguments dated 5/19/2026 are not persuasive.
The protection offered in Braithwaite is for an entire disk cartridge rather than for access to data in a logical zone, and the password-based protection of Braithwaite allows or denies access to the entire disk cartridge instead of implementing a first data restriction policy when a storage device receives a request to access data in the logical zone.
Applicant’s arguments dated 5/19/2026 have been fully considered, but they are not persuasive. The Examiner notes that this argument appears to be arguing against the Braithwaite reference individually instead of against the combination of prior art (including Braithwaite) as a whole. As noted in MPEP 2145(IV), “[o]ne cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. … Where a rejection of a claim is based on two or more references, a reply that is limited to what a subset of the applied references teaches or fails to teach, or that fails to address the combined teaching of the applied references may be considered to be an argument that attacks the reference(s) individually. … [‘][T]he test for obviousness is what the combined teachings of the references would have suggested to [a PHOSITA].’" Since Applicant appears to address the Braithwaite reference in isolation from what the combination of references as a whole would teach or suggest to a person having ordinary skill in the art, Applicant appears to be attacking the Braithwaite reference individually. Such arguments are not persuasive. See MPEP 2145(IV).
None of the prior art, alone or in combination, teaches or suggests the claim features defined in independent claims 1, 13, and 20 and claims ultimately dependent therefrom.
Applicant’s arguments dated 5/19/2026 have been fully considered, but they are not persuasive. The Examiner incorporates the responses given above in sections 33-37 and 39 of the instant Office action in response to this argument.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Daniel C. Chappell whose telephone number is (571)272-5003. The examiner can normally be reached 1000-1800, Eastern.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jared I. Rutz can be reached at (571)272-5535. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Daniel C. Chappell
Primary Examiner
Art Unit 2135
/Daniel C. Chappell/Primary Examiner, Art Unit 2135