DETAILED ACTION
This Office Action is in response to the application 19/085,401 filed on March 20th, 2025.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claims 1-25 are pending and herein considered.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-25 are rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter.
Regarding claims 1, 11 and 21; claims 1, 11 and 21 are/is rejected under 35 USC 101 because the claims are/is directed to an abstract idea without being integrated into a practical application nor being significantly more.
The claims reciting the limitations “generat[ing] a device identifier of the memory system based on a cryptographic representation of a software image in the memory system and a cryptographic representation of a hardware layer of the memory system,” “generat[ing] a first key using the device identifier based on applying a first function to the device identifier,” “generat[ing] an asymmetric key pair based on applying a second function to a value generated using a random number generator” and “encrypt[ing] the asymmetric key pair using the first key” are directed to an abstract idea as the claims recite mental processes. Accordingly, the claims recite an abstract idea. This judicial exception is not integrated into a practical application. It’s noted that the claims recite additional element(s) (i.e, a memory system). However, said additional element is recited at a high-level of generality (i.e., as a generic processor performing a generic computer function of generating/generating/generating/encrypting) such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, the claims are not integrated into a practical application.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As mentioned above, although the claims recite additional element, said element taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic computer content distributing functions routinely used in information technology field. Encrypting the asymmetric key pair using the first key is conventional, well know routing in view of Berkeeimer memo here. Generic computer components recited as performing generic computer functions that are well understood, routine and conventional activities amount to no more than implementing the abstract idea with a computerized system. Therefore, the claim is directed to non-statutory subject matter.
Regarding claims 2-10, 12-20 & 22-25; claims 2-10, 12-20 & 22-25 are also rejected under 35 U.S.C 101 as being directed to non-statutory subject matter for the same reasons addressed above as the claims are directed to abstract idea without being integrated into a practical application nor being significantly more.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-25 are rejected under 35 U.S.C 103 as being unpatentable over Ding et al. (Ding), U.S. Pub. Number 2018/0152293, in view of Brownlee et al. (Brownlee), U.S. Pub. Number 2019/0253254.
Regarding claim 1; Ding discloses a method by a memory system, comprising:
generating a device identifier of the memory system based on a cryptographic representation of a software image in the memory system and a cryptographic representation of a hardware layer of the memory system (pars. 0037, 0106-0112 & 0117; send a device identification request to the server, generate the device identification information after receiving the first public key and the first random number sent from the server; acquiring a device identifier of the terminal device; the terminal device may be configured with a hardware device that may generate a unique device identification code, and a unique code identification code generated by the hardware device that may generate a unique device identification code is determined as the device identifier of the terminal device.);
generating a first key using the device identifier based on applying a first function to the device identifier (par. 0138; using the device characteristic value generated by using the device identifier, the first public key may generate the same device characteristic value for the same service in different applications installed on the same terminal device.);
encrypting the asymmetric key pair using the first key (par. 0050; performing asymmetric encryption/decryption.).
Ding fails to explicitly disclose generating an asymmetric key pair.
However, in the same field of endeavor, Brownlee discloses system and method for securing a resource comprising generating an asymmetric key pair (Brownlee: par. 0737; perform an asymmetric key generation algorithm to generate a public key private key pair.).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Brownlee into the method, apparatus, and system of Ding comprising generating an asymmetric key pair to secure the content of a resource (Brownlee: par. 0009).
Regarding claim 2; Ding and Brownlee disclose the method of claim 1, Brownlee further discloses comprising: generating a certificate based on the asymmetric key pair, wherein the certificate is associated with attesting the memory system to a host system (Brownlee: 0746; generate the certificate signing request.); and transmitting the certificate to the host system (Brownlee: par. 0746; communicate the request to a signing authority, and receive a digitally signed certificate.).
Regarding claim 3; Ding and Brownlee disclose the method of claim 2, wherein Brownlee further discloses attesting the memory system to the host system is in accordance with a Security Protocol and Data Model (SPDM) (Brownlee: par. 0445; the data can identify the types of security that may be required over those protocols, such as only providing a key of a certain length can be used, and could moreover provide said key from within the data stored in the optical identifier.).
Regarding claim 4; Ding and Brownlee disclose the method of claim 1, Ding further discloses comprising: generating a second key using the device identifier based on applying a third function to the device identifier and a second cryptographic representation of the software image of the memory system; generating a second asymmetric key pair based on applying a fourth function to a second value generated using the random number generator; and encrypting the second asymmetric key pair using the second key (Ding: par. 0085; decrypting the encrypted information by using a preset asymmetric decryption algorithm and a private key in a preset asymmetric key pair to obtain a user identifier, a random number and a current device characteristic value, determining the user identifier obtained by decrypting as a second user identifier, and determining the random number obtained by decrypting as the second random number.).
Regarding claim 5; Ding and Brownlee disclose the method of claim 4, Brownlee further discloses comprising: generating a certificate based on the second asymmetric key pair, wherein the certificate is associated with attesting the memory system to a host system; and transmitting the certificate to the host system (Brownlee: par. 0787; generating a response including a digital certificate including an identifier representative of said IOT-Listing.).
Regarding claim 6; Ding and Brownlee disclose the method of claim 1, wherein Ding further discloses applying the second function comprises: performing a signature algorithm on the value, wherein encrypting the asymmetric key pair using the first key is based on performing the signature algorithm on the value (Ding: par. 0354; the first panel data can be used to computationally produce an asymmetric key pair; a first key of the key pair can be used to computationally generate a digital signature of a representation of the second digital resource; the second key can be registered with an online web service; the digital signature can be included as a component of the second digital resource.).
Regarding claim 7; Ding and Brownlee disclose the method of claim 1, wherein Ding further discloses the cryptographic representation of the software image is based on a digest of the software image (Ding: par. 0081; calculating history device characteristic values and digest values of the first random number by using a preset message digest algorithm.).
Regarding claim 8; Ding and Brownlee disclose the method of claim 1, wherein Brownlee further discloses the software image comprises initialization instructions for a computing system comprising the memory system (Brownlee: par. 0473; checksum of the boot image can be used by the microprocessor to compare to a current checksum of Non-Volatile Memory to ensure proper reading of the optical identifier OI has occurred.).
Regarding claim 9; Ding and Brownlee disclose the method of claim 1, wherein Brownlee further discloses the software image comprises an operating system for a computing system comprising the memory system (Brownlee: par. 0473; checksum of the boot image can be used by the microprocessor to compare to a current checksum of Non-Volatile Memory to ensure proper reading of the optical identifier OI has occurred.).
Regarding claim 10; Ding and Brownlee disclose the method of claim 1, wherein Brownlee further discloses the hardware layer of the memory system comprises a physically unclonable function of the memory system (Brownlee: par. 0473; perform machine code enabling optical reader to read and copy digital data of optical identifier to Non-Volatile Memory.).
Regarding claim 11; Claim 11 is directed to a non-transitory computer-readable medium which has similar scope as claim 1. Therefore, claim 11 remains un-patentable for the same reasons.
Regarding claims 12-20; Claims 12-20 are directed to the non-transitory computer-readable medium of claim 11 which have similar scope as claims 2-10. Therefore, claims 12-20 remain un-patentable for the same reasons.
Regarding claim 21; Claim 21 is directed to a memory system which has similar scope as claim 1. Therefore, claim 21 remains un-patentable for the same reasons.
Regarding claims 22-25; Claims 22-25 are directed to the memory system of claim 21 which have similar scope as claims 2-10. Therefore, claims 22-25 remain un-patentable for the same reasons.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KHOI V LE whose telephone number is (571)270-5087. The examiner can normally be reached 9:00 AM - 5:00 PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached on 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KHOI V LE/
Primary Examiner, Art Unit 2436