Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claims 1-20 are presented for examination.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by BOLIS (US Pat. App. Pub. 20250156528).
As per claim 1, BOLIS teaches a method, comprising: executing, by at least one processing resource, a first confidential virtual machine (CVM) in a trusted execution environment (TEE) at a first privilege level, the first CVM comprising a guest operating system (OS) kernel stored in a private memory, wherein the private memory is inaccessible via direct memory access (paragraphs: 32-38, and 8-11, wherein it emphasizes a first virtual machine is executed in a TEE with a certain privilege level wherein a guest operating system kernel in a memory which is inaccessible by direct access); executing, by the at least one processing resource, a second CVM in the TEE at a different, second privilege level, wherein, based on the second privilege level, the private memory is accessible to the second CVM; accessing, by an integrity scanning application of the second CVM, the private memory to determine a current measurement of the guest OS kernel (paragraphs: 5-7, 52-56, wherein it elaborates a second VM is executed in a different TEE with the different privilege level and the memory is accessible to the second VM. The scanning application of the second VM determines the current criteria of the guest OS system of the memory); and determining, by the integrity scanning application of the second CVM, whether the guest OS kernel is compromised based on a comparison of the current measurement and an initial measurement of the guest OS kernel (paragraphs: 24-29. And 65-70, wherein it deliberates that scanning application of the second VM determine if the OS system kernel is compromised by comparing the current criteria to the initial criteria).
6. As per claim 2, BOLIS teaches the method, further comprising: sharing a set of virtual resources between the first CVM and the second CVM by multiplexing, by the at least one processing resource, between execution of the first CVM and execution of the second CVM in the TEE (paragraphs: 11, 25, 28).
7. As per claim 3, BOLIS teaches the method, wherein the integrity scanning application of the second CVM is stored in an additional private memory, and wherein, based on the first privilege level, the additional private memory is inaccessible to the first CVM (paragraphs: 42-43).
8. As per claim 4, BOLIS teaches the method, further comprising: executing, by the at least one processing resource, a hypervisor; triggering, by the hypervisor, execution of the second CVM responsive to a hyper call from the first CVM (paragraphs: 67, 71, 73).
9. As per claim 5, BOLIS teaches the method, further comprising: accessing, by the integrity scanning application of the second CVM, the private memory to determine the current measurement responsive to the execution of the second CVM triggered by the hypervisor (paragraphs: 32-34).
10. As per claim 6, BOLIS teaches the method, further comprising: measuring, by an intrusion monitoring driver of the first CVM, the guest OS kernel to determine the initial measurement; writing, by the intrusion monitoring driver of the first CVM, the initial measurement to a memory location communicated to the first CVM by the second CVM; and transmitting, by an intrusion monitoring driver of the first CVM, the hypercall to the hypervisor based on writing the initial measurement to the memory location (paragraphs: 59, 63, 65).
11. As per claim 7, BOLIS teaches the method, further comprising: executing, by the at least one processing resource, a virtual processor in the first CVM; and responsive to the hypervisor triggering the execution of the second CVM: halting, by the at least one processing resource, execution of the virtual processor in the first CVM; and executing, by the at least one processing resource, the virtual processor in the second CVM (paragraphs: 5-7).
12. As per claim 8, BOLIS teaches the method, further comprising: executing, by the at least one processing resource, a first virtual processor in the first CVM; and responsive to the hypervisor triggering the execution of the second CVM: continuing, by the at least one processing resource, execution of the first virtual processor in the first CVM; and executing, by the at least one processing resource, a different, second virtual processor in the second CVM (paragraphs: 51-53).
13. As per claim 9, BOLIS teaches the method, further comprising: accessing, by the integrity scanning application of the second CVM, the private memory to determine the current measurement responsive to an inspection signal from the first CVM (paragraphs: 57-58).
14. As per claim 10, BOLIS teaches the method, further comprising: accessing, by the integrity scanning application of the second CVM, the private memory to determine the current measurement responsive to an interrupt scheduled by the second CVM (paragraphs: .
15. As per claim 11, BOLIS teaches the method, further comprising: receiving, by an attestation agent of the first CVM, a challenge from a verifier system; transmitting, by the attestation agent of the first CVM, a request for a status report from the integrity scanning application of the second CVM based on the challenge; and forwarding, by the attestation agent of the first CVM, a signed status report received from the integrity scanning application of the second CVM to the verifier system (paragraphs: 36, and 39-40).
16. As per claim 12, BOLIS teaches the method, further comprising: responsive to determining the guest OS kernel is compromised, updating, by the integrity scanning application of the second CVM, an issue interface; and responsive to receiving the request for the status report, producing, by the integrity scanning application of the second CVM, the signed status report based on the issue interface, the challenge, and a signature (paragraphs: 100, 102, and 115).
17. As per claim 13, BOLIS teaches a non-transitory machine-readable storage medium comprising instructions executable by at least one processing resource of a computing device to: execute a first confidential virtual machine (CVM) in a trusted execution environment (TEE) at a first privilege level, the first CVM comprising a guest operating system (OS) kernel stored in a private memory, wherein the private memory is inaccessible via direct memory access; execute a hypervisor outside the TEE, the hypervisor to, responsive to receipt of a hypercall from the first CVM, trigger execution of a second CVM (paragraphs: 32-38, and 8-11); execute the second CVM in the TEE at a different, second privilege level, wherein, based on the second privilege level, the private memory is accessible to the second CVM; access, using an integrity scanning application of the second CVM, the private memory to determine a current measurement of the guest OS kernel (paragraphs: 5-7, 52-56); and determine, using the integrity scanning application of the second CVM, whether the guest OS kernel is compromised based on a comparison of the current measurement and an initial measurement of the guest OS kernel (paragraphs: 24-29. And 65-70).
18. As per claim 14, BOLIS teaches the non-transitory machine-readable storage medium, wherein, based on the TEE, the private memory is further inaccessible to the hypervisor (paragraphs: 78, and 80).
19. As per claim 15, BOLIS teaches the non-transitory machine-readable storage medium, wherein the instructions are further executable to: responsive to determining that the guest OS kernel is not compromised, transmit, using the integrity scanning application of the second CVM, an additional hyper call to the hypervisor; and responsive to receipt of the additional hyper call, trigger, using the hypervisor, execution of the first CVM (paragraphs: 54-56).
20. As per claim 16, BOLIS teaches the non-transitory machine-readable storage medium, wherein the instructions are further executable to: prior to execution of the first CVM: set, using the second CVM, access rights to the private memory; and transmit, using the second CVM, an additional hyper call to the hypervisor; and responsive to receipt of the additional hyper call, trigger, using the hypervisor, the execution of the first CVM (paragraphs: 89, 92, and 97).
21. As per claim 17, BOLIS teaches a system comprising: at least one processing resource; and a non-transitory machine-readable storage medium comprising instructions executable by the at least one processing resource to: execute a first confidential virtual machine (CVM) in a trusted execution environment (TEE) at a first privilege level, the first CVM comprising a guest operating system (OS) kernel stored in a private memory, wherein the private memory is inaccessible via direct memory access; using an intrusion monitoring driver of the first CVM: measure the guest OS kernel to determine an initial measurement (paragraphs: 32-38, and 8-11); and write the initial measurement to a predetermined memory location; execute a second CVM in the TEE at a different, second privilege level, wherein, based on the second privilege level, the private memory is accessible to the second CVM; using an integrity scanning application of the second CVM: retrieve the initial measurement from the predetermined memory location (paragraphs: 5-7, 52-56); access the private memory to determine a current measurement of the guest OS kernel; and determine whether the guest OS kernel is compromised based on a comparison of the current measurement and the initial measurement (paragraphs: 24-29. And 65-70).
22. As per claim 18, BOLIS teaches the system, wherein the instructions are further executable to: communicate, using the second CVM, the predetermined memory location to the first CVM (paragraphs: 40-42).
23. As per claim 19, BOLIS teaches the system, wherein the intrusion monitoring driver is stored in the private memory (paragraphs: 25, 28, and 32).
24. As per claim 20, BOLIS teaches the system, wherein the second CVM comprises a secure virtual machine service module (paragraphs: 56-58).
Citation of References
25. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following references are cited but not been replied upon for this office action:
VAN SCHAIK et al (US pat. app. Pub. 20240311171): discusses providing access to one or more execution environments. For example, a process can include receiving a listen call from a first virtual machine (VM) and registering a listener call context of the first VM with a callback service of a trusted execution environment (TEE). A return code indicating no callback requests are available causes the first VM to put the listener call context to sleep. A call from a second VM raises a service request for a VM service of the first VM. A wake return code to the second VM wakes the listener call context of the first VM. A callback request transmitted to the VM service of the first VM corresponds to the service request raised by the second VM. A response call received from the VM service of the first VM is indicative of a callback response to the callback request.
Mai et al (US pat. App. Pub. 20240394359): elaborates that providing a trusted execution environment (“TEE”) for one or more graphic processing units (“GPUs”) include a secure hypervisor, application sandbox virtual machine (VM), secure VM service module (SVSM), and security monitor (SM). In one embodiment, the secure hypervisor is running on a central processing unit (CPU) to regulate all interactions between software stacks and hardware. The application sandbox VM is running on top the hypervisor that hosts applications. The SVSM is running at virtual machine privilege level 0 (VMPLO) in a VM to regulate interactions between the applications and a GPU, wherein the SVSM includes a validator for verifying security and integrity of one or more GPU executions running on the GPU. The SM is configured to regulate interactions between VMs and the GPU in accordance with security properties.
Conclusion
26. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMAD W REZA whose telephone number is (571)272-6590. The examiner can normally be reached on Monday-Friday 8:30-5:30 ET.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Cathy Thiaw can be reached on 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/MOHAMMAD W REZA/Primary Examiner, Art Unit 2407