Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
DETAILED ACTION
This action is in response to applicant’s submittal made on 03/03/2025. Claims 1-20 are pending.
Specification (Title)
The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed.
Claim Objections
Claims 13 and 14 objected to because of the following informalities: “Remote Direct Access Memory” and “RDMA”. Appropriate correction is required.
Double Patenting
The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a non-statutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1, 12 and 17 are rejected on the ground of non-statutory double patenting as being unpatentable over claim 1 of U.S. Patent No. 12,284,162 and 162’ hereinafter. Although the claims at issue are not identical, they are not patentably distinct from each other because both sets of claims are drawn to the following:
(19/068544) one or more processing circuits to: pair with a local root of trust of a host device to enable the NIC to perform a root of trust function on behalf of the local root of trust, the local root of trust being a hardware-assisted entity that allows system software to secure an identity of a platform on which the system software runs; generate a key as the root of trust function performed on behalf of the local root of trust of the host device; and send the key to an encryption device of the host device to enable the encryption device to encrypt data of one or more host device applications using the key; maps to (162’) processing circuitry configured to: pair with a local root of trust of a host device connected to the NIC to enable the NIC to perform a root of trust function on behalf of the local root of trust of the host device, the local root of trust being a hardware-assisted entity that allows running system software to secure an identity of a platform on which the system software is running; generate a key as the root of trust function performed on behalf of the local root of trust of the host device; provide, via the local root of trust, the key to an encryption device of the host device to enable encryption of data of one or more host device applications using the key, the encrypted data being stored in host device memory; share the key with a remote endpoint to enable the remote endpoint to decrypt the encrypted data; and forward the encrypted data from the host device memory to the remote endpoint.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 17 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 17 recites …computer processing complex. The examiner contends that the metes and bound of applicant's claim limitation(s) elements of, " computer processing complex ", cannot be readily determined. The examiner notes that the claim language of, " computer processing complex ", creates uncertainty about what is being claimed.
Claim 17 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 17 recites …”perform a root of trust function”. The examiner contends that the metes and bound of applicant's claim limitation(s) elements of, "perform a root of trust function", cannot be readily determined. The examiner notes that the claim language of, " perform a root of trust function", creates uncertainty about what is being claimed.
Claim Rejections - 35 USC § 112
Claim 17 is rejected under 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph, because the claim purports to invoke 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, but fails to recite a combination of elements as required by that statutory provision and thus cannot rely on the specification to provide the structure, material or acts to support the claimed function. As such, the claim recites a function that has no limits and covers every conceivable means for achieving the stated function, while the specification discloses at most only those means known to the inventor. Accordingly, the disclosure is not commensurate with the scope of the claim.
The associated dependent claims 18 – 20 do not correct the 112 deficiencies and are therefore rejected under 35 USC § 112.
Claim Rejections - 35 USC § 101 – “Lack of Hardware Element”
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claim 12 is rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter.
Claim 12 is directed towards a system comprising a “network interface controller“ and “remote endpoint”. A person of ordinary skill in the art will reasonably define the network interface controller and remote endpoint to be implemented in software. Therefore, the claim lacks at least one hardware element.
Claims 13-16 don't cure the deficiency of claim 12 and are rejected under 35 USC 101 for their dependency upon claim 12.
Claim 17 is rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter.
Claim 17 is directed towards a network interface controller comprising a “computer processing complex“. A person of ordinary skill in the art will reasonably define the network interface controller to be implemented in software. Therefore, the claim lacks at least one hardware element.
Claims 18-20 don't cure the deficiency of claim 17 and are rejected under 35 USC 101 for their dependency upon claim 17.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-3, 6, 8, 10, 12-14 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Sakakibara (NPL “Accelerating Blockchain Transfer System Using FPGA-Based NIC” and Sakaibara hereinafter) in view of TOYOIZUMI et al. (US Patent Publication No. 2017/0186342 and TOYOIZUMI hereinafter) and further in view of Biehl et al. (US Patent Publication No. 2018/0324547 and Biehl hereinafter).
As to claim 1, SAKAKIBARA teaches a Network Interface Controller (NIC), comprising:
one or more processing circuits to: pair with a local root of trust of a host device to enable the NIC to perform a root of trust function on behalf of the local root of trust (i.e., …teaches root of trust function in SECTION III:
PNG
media_image1.png
946
1012
media_image1.png
Greyscale
PNG
media_image2.png
439
1105
media_image2.png
Greyscale
),
generate a key as the root of trust function performed on behalf of the local root of trust of the host device (i.e., …”create a new key-value pair” …illustrates in Table 1 the following:
PNG
media_image2.png
439
1105
media_image2.png
Greyscale
).
SAKAKIBARA does not expressly teach:
and send the key to an encryption device of the host device to enable the encryption device to encrypt data of one or more host device applications using the key.
In this instance the examiner notes teachings of prior art reference TOYOIZUMI.
With regards to applicant’s claim limitation element of, “and send the key to an encryption device of the host device to enable the encryption device to encrypt data of one or more host device applications using the key”, TOYOIZUMI teaches in par. 0057 the following: “The communicator 14 includes, for example, a Network Interface Card (NIC), and transmits the encryption key utilized by the controller 13 and the generated conversion character code string to the sentence recognition device 20 via the network N.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA with the teachings of TOYOIZUMI by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means to maintain key related data within a network, wherein the enhanced key management process helps facilitate communication integrity within the network and makes it easier to configure devices for network communication.
The system of SAKAKIBARA and TOYOIZUMI does not expressly disclose:
the local root of trust being a hardware-assisted entity that allows system software to secure an identity of a platform on which the system software runs.
In this instance the examiner notes the teachings of prior art reference Biehl.
With regards to applicant’s claim limitation element of, “the local root of trust being a hardware-assisted entity that allows system software to secure an identity of a platform on which the system software runs”, Biehl teaches in par. 0068 the following: “to increase the trustworthiness of the anchor device 107, existing security features present on the types of ARM-based platforms described above, which are used in implementing the anchor device 107, are leveraged. Specifically, in one embodiment, the anchor device 107 uses a trusted execution environment (TEE) enabled by ARM TrustZone”. These technologies allow for the secure generation, storage, and use of cryptographic keys needed by the anchor device 107, thereby preventing the exfiltration of cryptographic material from the anchor device 107. They further enable the use of trusted boot, which provides a cryptographic mechanism for ensuring the integrity of code running on the platform. In the case of the anchor device 107, this would enable assurances that only an unmodified software image of the anchor device 107 could be loaded into the memory of the anchor device 107 to help limit the effects of tampering attacks carried out against the anchor device 107.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA and TOYOIZUMI with the teachings of Biehl by having their system comprise an enhanced device boot authentication process. One would have been motivated to do so to provide simple and effective means to secure device operations, wherein the enhanced device boot authentication process helps provide device security and makes it easier to configure a safe boot operation for a device.
As to claim 2, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 1 above teaches cryptographic processing, specifically SAKAKIBARA does not expressly teach a NIC of claim 1, wherein the key is sent to the encryption device of the host device through the local root of trust.
In this instance the examiner notes teachings of prior art reference TOYOIZUMI.
TOYOIZUM teaches in par. 0057 the following: “The communicator 14 includes, for example, a Network Interface Card (NIC), and transmits the encryption key utilized by the controller 13 and the generated conversion character code string to the sentence recognition device 20 via the network N.”).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA with the teachings of TOYOIZUMI by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means to maintain key related data within a network, wherein the enhanced key management process helps facilitate communication integrity within the network and makes it easier to configure devices for network communication.
As to claim 3, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 1 above teaches cryptographic processing, specifically SAKAKIBARA does not expressly teach a NIC of claim 1, wherein the one or more processing circuits are to: share the key with a remote endpoint to enable the remote endpoint to decrypt the encrypted data of the one or more host device applications.
In this instance the examiner notes teachings of prior art reference TOYOIZUMI.
TOYOIZUMI teach in par. 0057 the following: “The communicator 14 includes, for example, a Network Interface Card (NIC), and transmits the encryption key utilized by the controller 13 and the generated conversion character code string to the sentence recognition device 20 via the network N.”).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of SAKAKIBARA with the teachings of TOYOIZUMI by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means to maintain key related data within a network, wherein the enhanced key management process helps facilitate communication integrity within the network and makes it easier to configure devices for network communication.
As to claim 6, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 3 above teaches cryptographic processing, specifically SAKAKIBARA does not expressly teach a NIC of claim 3, further comprising: a designated channel that enables the one or more processing circuits to share the key with the remote endpoint.
In this instance the examiner notes teachings of prior art reference TOYOIZUMI.
TOYOIZUMI teach in par. 0057 the following: “The communicator 14 includes, for example, a Network Interface Card (NIC), and transmits the encryption key utilized by the controller 13 and the generated conversion character code string to the sentence recognition device 20 via the network N.”).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA with the teachings of TOYOIZUMI by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means to maintain key related data within a network, wherein the enhanced key management process helps facilitate communication integrity within the network and makes it easier to configure devices for network communication.
As to claim 8, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 1 above teaches cryptographic processing, specifically neither SAKAKIBARA nor TOYOIZUMI expressly teaches a NIC of claim 1, wherein the one or more processing circuits are to pair with the local root of trust over an isolated channel.
In this instance the examiner notes the teachings of prior art reference Biehl.
Biehl teaches in par. 0068 the following: “to increase the trustworthiness of the anchor device 107, existing security features present on the types of ARM-based platforms described above, which are used in implementing the anchor device 107, are leveraged. Specifically, in one embodiment, the anchor device 107 uses a trusted execution environment (TEE) enabled by ARM TrustZone”. These technologies allow for the secure generation, storage, and use of cryptographic keys needed by the anchor device 107, thereby preventing the exfiltration of cryptographic material from the anchor device 107. They further enable the use of trusted boot, which provides a cryptographic mechanism for ensuring the integrity of code running on the platform. In the case of the anchor device 107, this would enable assurances that only an unmodified software image of the anchor device 107 could be loaded into the memory of the anchor device 107 to help limit the effects of tampering attacks carried out against the anchor device 107.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA and TOYOIZUMI with the teachings of Biehl by having their system comprise an enhanced device boot authentication process. One would have been motivated to do so to provide simple and effective means to secure device operations, wherein the enhanced device boot authentication process helps provide device security and makes it easier to configure a safe boot operation for a device.
As to claim 10, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 1 above teaches cryptographic processing, specifically SAKAKIBARA nor TOYOIZUMI does not expressly teach a NIC of claim 1, wherein the one or more processing circuits are to pair with the local root of trust of the host device upon connection of the NIC to the host device.
In this instance the examiner notes the teachings of prior art reference Biehl.
Biehl teaches in par. 0068 the following: “to increase the trustworthiness of the anchor device 107, existing security features present on the types of ARM-based platforms described above, which are used in implementing the anchor device 107, are leveraged. Specifically, in one embodiment, the anchor device 107 uses a trusted execution environment (TEE) enabled by ARM TrustZone”. These technologies allow for the secure generation, storage, and use of cryptographic keys needed by the anchor device 107, thereby preventing the exfiltration of cryptographic material from the anchor device 107. They further enable the use of trusted boot, which provides a cryptographic mechanism for ensuring the integrity of code running on the platform. In the case of the anchor device 107, this would enable assurances that only an unmodified software image of the anchor device 107 could be loaded into the memory of the anchor device 107 to help limit the effects of tampering attacks carried out against the anchor device 107.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA and TOYOIZUMI with the teachings of Biehl by having their system comprise an enhanced device boot authentication process. One would have been motivated to do so to provide simple and effective means to secure device operations, wherein the enhanced device boot authentication process helps provide device security and makes it easier to configure a safe boot operation for a device.
As to claim 12, SAKAKIBARA teaches a system, comprising:
a remote endpoint (i.e., …illustrates in Table I remote over the network communication:
PNG
media_image1.png
946
1012
media_image1.png
Greyscale
);
and a Network Interface Controller (NIC) to: pair with a local root of trust of a host device to enable the NIC to perform a root of trust function on behalf of the local root of trust (i.e., …teaches root of trust function in SECTION III:
PNG
media_image1.png
946
1012
media_image1.png
Greyscale
PNG
media_image2.png
439
1105
media_image2.png
Greyscale
),
generate a key as the root of trust function performed on behalf of the local root of trust of the host device (i.e., …”create a new key-value pair” …illustrates in Table 1 the following:
PNG
media_image2.png
439
1105
media_image2.png
Greyscale
).
The system of SAKAKIBARA does not expressly teach:
and send the key to an encryption device of the host device that enables the encryption device to encrypt data destined for the remote endpoint using the key.
In this instance the examiner notes teachings of prior art reference TOYOIZUMI.
With regards to applicant’s claim limitation element of, “and send the key to an encryption device of the host device that enables the encryption device to encrypt data destined for the remote endpoint using the key”, …teach in par. 0057 the following: “The communicator 14 includes, for example, a Network Interface Card (NIC), and transmits the encryption key utilized by the controller 13 and the generated conversion character code string to the sentence recognition device 20 via the network N.”).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA with the teachings of TOYOIZUMI by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means to maintain key related data within a network, wherein the enhanced key management process helps facilitate communication integrity within the network and makes it easier to configure devices for network communication.
The system of SAKAKIBARA and TOYOIZUMI does not expressly disclose:
the local root of trust being a hardware-assisted entity that allows system software to secure an identity of a platform on which the system software runs.
In this instance the examiner notes the teachings of prior art reference Biehl.
With regards to applicant’s claim limitation element of, “the local root of trust being a hardware-assisted entity that allows system software to secure an identity of a platform on which the system software runs”, Biehl teaches in par. 0068 the following: “to increase the trustworthiness of the anchor device 107, existing security features present on the types of ARM-based platforms described above, which are used in implementing the anchor device 107, are leveraged. Specifically, in one embodiment, the anchor device 107 uses a trusted execution environment (TEE) enabled by ARM TrustZone”. These technologies allow for the secure generation, storage, and use of cryptographic keys needed by the anchor device 107, thereby preventing the exfiltration of cryptographic material from the anchor device 107. They further enable the use of trusted boot, which provides a cryptographic mechanism for ensuring the integrity of code running on the platform. In the case of the anchor device 107, this would enable assurances that only an unmodified software image of the anchor device 107 could be loaded into the memory of the anchor device 107 to help limit the effects of tampering attacks carried out against the anchor device 107.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA and TOYOIZUMI with the teachings of Biehl by having their system comprise an enhanced device boot authentication process. One would have been motivated to do so to provide simple and effective means to secure device operations, wherein the enhanced device boot authentication process helps provide device security and makes it easier to configure a safe boot operation for a device.
As to claim 13, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 12 above teaches cryptographic processing, specifically SAKAKIBARA does not expressly teach system of claim 12, wherein the NIC enables Remote Direct Access Memory (RDMA) operations to send the encrypted data.
In this instance the examiner notes teachings of prior art reference TOYOIZUMI.
TOYOIZUMI teach in par. 0077 the following: “a character code decryption process illustrated in FIG. 6, first, the controller 23 generates the conversion character code table coincide with the conversion character code table generated by the character code conversion device 10 based on the received encryption key by the communicator 21,”).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA with the teachings of TOYOIZUMI by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means to maintain key related data within a network, wherein the enhanced key management process helps facilitate communication integrity within the network and makes it easier to configure devices for network communication.
As to claim 14, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 12 above teaches cryptographic processing, specifically SAKAKIBARA does not expressly teach a system of claim 13, wherein the encrypted data remain encrypted throughout the RDMA operations.
In this instance the examiner notes teachings of prior art reference TOYOIZUMI.
TOYOIZUMI teach in pars. 0076 & 0077 the following: “When the communicator 21 receives the transmitted conversion character code string from the character code conversion device 10 via the network N, the sentence recognition device 20 starts a sentence recognition process illustrated in FIG. 6.
[0077] In a character code decryption process illustrated in FIG. 6, first, the controller 23 generates the conversion character code table coincide with the conversion character code table generated by the character code conversion device 10 based on the received encryption key by the communicator 21, and the stored standard character code table in the memory 22 (step S11)”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA with the teachings of TOYOIZUMI by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means to maintain key related data within a network, wherein the enhanced key management process helps facilitate communication integrity within the network and makes it easier to configure devices for network communication.
As to claim 16, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 12 above teaches cryptographic processing, specifically SAKAKIBARA does not expressly teach a system of claim 12, wherein the NIC is to: share the key with the remote endpoint to enable the remote endpoint to decrypt the encrypted data and forward the encrypted data received from memory of the host device to the remote endpoint.
In this instance the examiner notes teachings of prior art reference TOYOIZUMI.
With regards to applicant’s claim limitation element of, “wherein the NIC is to: share the key with the remote endpoint to enable the remote endpoint to decrypt the encrypted data”, TOYOIZUMI teach in par. 0077 the following: “a character code decryption process illustrated in FIG. 6, first, the controller 23 generates the conversion character code table coincide with the conversion character code table generated by the character code conversion device 10 based on the received encryption key by the communicator 21,”).
With regards to applicant’s claim limitation element of, “forward the encrypted data received from memory of the host device to the remote endpoint”, TOYOIZUMI teach in par. 0077 the following: “a character code decryption process illustrated in FIG. 6, first, the controller 23 generates the conversion character code table coincide with the conversion character code table generated by the character code conversion device 10 based on the received encryption key by the communicator 21,”). The examiner contends once the data is decrypted it will be cache/stored.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA with the teachings of TOYOIZUMI by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means to maintain key related data within a network, wherein the enhanced key management process helps facilitate communication integrity within the network and makes it easier to configure devices for network communication.
Claim(s) 4, 5, 9, 11 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Sakakibara and TOYOIZUMI in view of Biehl as applied to claims 3 and 15 above and further in view of Jowett et al. (US Patent No. 10,771,439 and Jowett hereinafter).
As to claims 4 and 15, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 3 above teaches cryptographic processing, specifically neither reference expressly teaches a NIC of claim 3, wherein the one or more processing circuits are to share the key and a key identifier of the key with the remote endpoint.
In this instance the examiner notes the teachings of prior art reference Jowett.
Jowett teaches in col. 7 lines 1-10 the following: “… determining that the remote node is authorized to access the VM's key (e.g., the remote node is on the VM's whitelist), releasing the key to the remote node,”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA, TOYOIZUMI and Biehl with the teachings of Jowett by having their system comprise an enhanced key distribution process. One would have been motivated to do so to provide a simple and effective means to distribute key related data, wherein the enhanced key distribution process helps facilitate key security within the network and makes it easier to configure devices with keys within the network.
As to claim 5, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 4 above teaches cryptographic processing, specifically neither reference expressly teaches a NIC of claim 4, wherein, after sharing the key and the key identifier with the remote endpoint, the one or more processing circuits are to send the key identifier to a hypervisor of the host device through the local root of trust for use by the hypervisor when opening the one or more host device applications.
In this instance the examiner notes the teachings of prior art reference Jowett.
Jowett illustrates in figure 8 key related information released into the virtualization layer of the host.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA, TOYOIZUMI and Biehl with the teachings of Jowett by having their system comprise an enhanced key distribution process. One would have been motivated to do so to provide a simple and effective means to distribute key related data, wherein the enhanced key distribution process helps facilitate key security within the network and makes it easier to configure devices with keys within the network.
As to claim 9, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 1 above teaches cryptographic processing, specifically neither reference expressly teaches a NIC of claim 1, wherein the one or more processing circuits are to pair with the local root of trust based on a root certificate that associates the host device with the NIC.
In this instance the examiner notes the teachings of prior art reference Jowett.
Jowett teaches in col. 5 lines 50-67 the following: “A hash of the health certificate may be signed by a private key of the guardian service 152, which allows the host to use the service's public key to conform the signature of the health certificate. The health certificate may have information defining its expiration time, its scope of validity (e.g., the particular host for which it was issued), types/levels of privilege authorized by the certificate, etc.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA, TOYOIZUMI and Biehl with the teachings of Jowett by having their system comprise an enhanced attestation process. One would have been motivated to do so to provide a simple and effective means to verify system health, wherein the enhanced attestation process helps facilitate system security and makes system verification easier.
As to claim 11, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 1 above teaches cryptographic processing, specifically neither reference expressly teaches a NIC of claim 1, wherein the one or more processing circuits are to share the key with a remote endpoint in response to a request from a hypervisor of the host device that passes through the local root of trust.
In this instance the examiner notes the teachings of prior art reference Jowett.
Jowett illustrates in figure 8 key related information released into the virtualization layer of the host.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA, TOYOIZUMI and Biehl with the teachings of Jowett by having their system comprise an enhanced key distribution process. One would have been motivated to do so to provide a simple and effective means to distribute key related data, wherein the enhanced key distribution process helps facilitate key security within the network and makes it easier to configure devices with keys within the network.
Claim(s) 7 rejected under 35 U.S.C. 103 as being unpatentable over Sakakibara and TOYOIZUMI in view of Biehl as applied to claim 6 above and further in view of Armstrong (WO 2012139174 A1).
As to claim 7, the system of SAKAKIBARA, TOYOIZUMI and Biehl as applied to claim 6 above teaches cryptographic processing, specifically neither reference expressly teaches a NIC of claim 6, wherein the designated channel is configured for Quantum Key Distribution (QKD).
In this instance the examiner notes the teachings of prior art reference Armstrong.
Armstrong teaches in par. 0015 the following: “Quantum key distribution (QKD) blocks 108 and 1 18 provide for quantum key distribution. Each block provides a quantum channel interface 128 and 132, and a classical channel interface 130 and 134. The quantum channel interface 128 on the transmitting node 102 is implemented as an electro-optical modulator that converts an electrical signal into an optical signal. The quantum channel interface 132 on the receiving node 1 12 is implemented as a photo- detector that converts an optical signal into an electrical signal. The classical channel interfaces 130 and 134 are system calls that relay data through the operating system's network stack onto network interface cards (NICs). Quantum key distribution 108 receives a stream of random bits from the random bit source 1 10. These bits are encoded onto quadrature observables of the quantum states of light, and then transmitted to QKD node 1 18 over the optical quantum channel 140. The receiving QKD node 1 18 makes measurements of the quadrature observables of the received quantum states of light using homodyne detectors.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA, TOYOIZUMI and Biehl with the teachings of Armstrong by having their system comprise an enhanced key distribution process. One would have been motivated to do so to provide a simple and effective means to distribute key related data, wherein the enhanced key distribution process helps facilitate key security within the network and makes it easier to configure devices with keys within the network.
Claim(s) 17 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Sakakibara (NPL “Accelerating Blockchain Transfer System Using FPGA-Based NIC” and Sakaibara hereinafter) in view of Biehl.
As to claim 17, Sakakibara teaches a Network Interface Controller (NIC), comprising:
a computer processing complex to: pair with a local root of trust of a host device (i.e., …illustrates a computer processing component in association with a local root of trust of a host device.
PNG
media_image1.png
946
1012
media_image1.png
Greyscale
),
and perform a root of trust function on behalf of the local root of trust (i.e., …illustrates in table I performing a root of trust function of creating a new key-value pairs;
PNG
media_image2.png
439
1105
media_image2.png
Greyscale
).
The system of Sakakibara does not expressly teach:
the local root of trust being a hardware-assisted entity that allows system software to secure an identity of a platform on which the system software runs.
In this instance the examiner notes the teachings of prior art reference Biehl.
With regards to applicant’s claim limitation element of, “the local root of trust being a hardware-assisted entity that allows system software to secure an identity of a platform on which the system software runs”, Biehl teaches in par. 0068 the following: “to increase the trustworthiness of the anchor device 107, existing security features present on the types of ARM-based platforms described above, which are used in implementing the anchor device 107, are leveraged. Specifically, in one embodiment, the anchor device 107 uses a trusted execution environment (TEE) enabled by ARM TrustZone”. These technologies allow for the secure generation, storage, and use of cryptographic keys needed by the anchor device 107, thereby preventing the exfiltration of cryptographic material from the anchor device 107. They further enable the use of trusted boot, which provides a cryptographic mechanism for ensuring the integrity of code running on the platform. In the case of the anchor device 107, this would enable assurances that only an unmodified software image of the anchor device 107 could be loaded into the memory of the anchor device 107 to help limit the effects of tampering attacks carried out against the anchor device 107.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA with the teachings of Biehl by having their system comprise a enhanced device boot authentication process. One would have been motivated to do so to provide a simple and effective means to secure device operations, wherein the enhanced device boot authentication process helps provide device security and makes it easier to configure safe boot of a device.
As to claim 18, the system of SAKAKIBARA and Biehl as applied to claim 17 above teaches cryptographic processing, specifically SAKAKIBARA teaches a NIC of claim 17, wherein the root of trust function includes generating a key for encrypting data (i.e., …illustrates in table I performing a root of trust function of creating a new key-value pairs;
PNG
media_image2.png
439
1105
media_image2.png
Greyscale
).
Claim(s) 19 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Sakakibara in view of Biehl as applied to claim 17 above and further in view of TOYOIZUMI.
As to claim 19, the system of SAKAKIBARA and Biehl as applied to claim 18 above teaches cryptographic processing, specifically SAKAKIBARA nor Biehl expressly teaches a NIC of claim 18, wherein the computer processing complex is to:send the key to the host device to enable the host device to encrypt data of one or more host device applications using the key.
In this instance the examiner notes teachings of prior art reference TOYOIZUMI.
With regards to applicant’s claim limitation element of, “send the key to the host device to enable the host device to encrypt data of one or more host device applications using the key”, …teach in par. 0057 the following: “The communicator 14 includes, for example, a Network Interface Card (NIC), and transmits the encryption key utilized by the controller 13 and the generated conversion character code string to the sentence recognition device 20 via the network N.”).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA and Biehl with the teachings of TOYOIZUMI by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means to maintain key related data within a network, wherein the enhanced key management process helps facilitate communication integrity within the network and makes it easier to configure devices for network communication.
As to claim 20, the system of SAKAKIBARA and Biehl as applied to claim 19 above teaches cryptographic processing, specifically SAKAKIBARA nor Biehl expressly teaches a NIC of claim 19, wherein the computer processing complex is to: share the key with a remote endpoint to enable the remote endpoint to decrypt the encrypted data; and forward the encrypted data stored in memory of the host device to the remote endpoint.
In this instance the examiner notes teachings of prior art reference TOYOIZUMI.
With regards to applicant’s claim limitation element of, “wherein the computer processing complex is to: share the key with a remote endpoint to enable the remote endpoint to decrypt the encrypted data”, …teach in par. 0057 the following: “The communicator 14 includes, for example, a Network Interface Card (NIC), and transmits the encryption key utilized by the controller 13 and the generated conversion character code string to the sentence recognition device 20 via the network N.” …teach in par. 0077 the following: “In a character code decryption process illustrated in FIG. 6, first, the controller 23 generates the conversion character code table coincide with the conversion character code table generated by the character code conversion device 10 based on the received encryption key by the communicator 21, and the stored standard character code table in the memory 22 (step S11).”).).
With regards to applicant’s claim limitation element of, “and forward the encrypted data stored in memory of the host device to the remote endpoint”, …teach in par. 0077 the following: “In a character code decryption process illustrated in FIG. 6, first, the controller 23 generates the conversion character code table coincide with the conversion character code table generated by the character code conversion device 10 based on the received encryption key by the communicator 21, and the stored standard character code table in the memory 22 (step S11).”).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teachings of SAKAKIBARA and Biehl with the teachings of TOYOIZUMI by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means to maintain key related data within a network, wherein the enhanced key management process helps facilitate communication integrity within the network and makes it easier to configure devices for network communication.
Art Made of Record
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Wentz (US Patent Publication No. 2020/0153627).
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRYAN F WRIGHT whose telephone number is (571)270-3826.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni Shiferaw can be reached on (571)272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BRYAN F WRIGHT/Examiner, Art Unit 2497