DETAILED ACTION
The Examiner acknowledges the applicant's submission of the amendment dated 8/7/2026.
REJECTIONS BASED ON PRIOR ART
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC ' 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-3, 11, 12, and 20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Liljeberg (US 2014/0108701).
Regarding Claim 1, Liljeberg teaches a system comprising:
a memory management unit (MMU 250 of Fig. 7, containing memory protection unit/MPU 360) configured to perform a multi-stage address translation (the first stage corresponding to taking a virtual page number at step S100 of Fig. 5 and translating it to a Real/Virtual Physical Page Number at steps S140-S150, and a second stage corresponding to taking the Real/Virtual Physical Page Number and translating it to a physical page number at step S190 of Fig. 5),
wherein a first stage of the multi-stage address translation performs address translation from virtual addresses to intermediate physical addresses (the first stage corresponding to taking a virtual page number at step S100 of Fig. 5 and translating it to a Real/Virtual [intermediate] Physical Page Number at steps S140-S150), and wherein a second stage of the multi-stage address translation performs address translation from intermediate physical addresses to physical addresses (a second stage corresponding to taking the Real/Virtual Physical Page Number and translating it to a physical page number at step S190 of Fig. 5),
wherein the memory management unit is configured to maintain a plurality of forbidden mappings between intermediate physical addresses and physical addresses for which memory access is not permitted (permission table 320 of Fig. 7, shown within the memory management unit, and the table is shown on Fig. 6, with allowed and forbidden mapping shown between virtual [intermediate] physical addresses and physical addresses),
wherein the memory management unit is configured to operate in a forbidden mapping mode to perform multi-stage address translation by performing operations comprising:
translating a virtual address into an intermediate physical address (“The virtual page number 400 [virtual address] is hence translated into the real [intermediate physical] address,” Paragraph 0082, step S140 of Fig. 5),
determining that the plurality of forbidden mappings does not include a mapping for the intermediate physical address (“The real (virtual physical) base addresses stored in the set [of the permission table] are then compared against the real [intermediate] (virtual physical) address that is being translated,” and it is determined if the intermediate address is out of boundaries/forbidden or allowed, and if it is allowed, there is no forbidden mapping for the intermediate physical address, see steps S160 and S170 of Fig. 5), and
in response to determining that the plurality of forbidden mappings does not include a mapping for the intermediate physical address, returning a physical address for the intermediate physical address (if “the real [intermediate physical] address 420 is within the legal memory boundaries assigned to the currently operating virtual machine (VM),” Paragraph 0085, i.e., if the intermediate physical address is not included in a forbidden mapping, “The physical address resulting from the physical page number 440 and the offset 410 may then used [returned] to address the physical system memory,” Paragraph 0085, and “the physical address is calculated by adding the corresponding physical base address to the offset [which corresponds to the intermediate physical address],” Paragraphs 0092-0094).
Regarding Claim 2, the cited prior art teaches the system of claim 1, wherein the system comprises multiple virtual machines that are configured to issue virtual addresses to the memory management unit (see various virtual machines with VM IDs of Fig. 6).
Regarding Claim 3, the cited prior art teaches the system of claim 1, wherein the system comprises multiple client devices that are configured to issue virtual addresses to the memory management unit (see various virtual machines/clients with VM IDs of Fig. 6).
Regarding Claim 11, Liljeberg teaches a method, comprising:
translating, by a memory management unit (MMU 250 of Fig. 7, containing memory protection unit/MPU 360) configured to maintain a forbidden mapping between intermediate physical addresses and physical addresses for which memory access is not permitted (see permission table 320 of Fig. 7, shown within the memory management unit, and the table is shown on Fig. 6, with allowed and forbidden mapping shown between virtual [intermediate] physical addresses and physical addresses), a virtual address into an intermediate physical address (see Fig. 5, where a virtual page number [address] at step S100 is translated to a Real/Virtual [intermediate] Physical Page Number at steps S140-S150);
determining, by the memory management unit, that the plurality of forbidden mappings does not include a forbidden mapping for the intermediate physical address (“The real (virtual physical) base addresses stored in the set [of the permission table] are then compared against the real [intermediate] (virtual physical) address that is being translated,” and it is determined if the intermediate address is out of boundaries/forbidden or allowed, and if it is allowed, there is no forbidden mapping for the intermediate physical address, see steps S160 and S170 of Fig. 5); and
in response to determining that the plurality of forbidden mappings does not include a mapping for the intermediate physical address, returning, by the memory management unit, a physical address for the intermediate physical address (if “the real [intermediate physical] address 420 is within the legal memory boundaries assigned to the currently operating virtual machine (VM),” Paragraph 0085, i.e., if there is a miss in the mappings forbidden to the VM, “The physical address resulting from the physical page number 440 and the offset 410 may then used [returned] to address the physical system memory,” Paragraph 0085, and “the physical address is calculated by adding the corresponding physical base address to the offset [which corresponds to the intermediate physical address],” Paragraphs 0092-0094).
Regarding Claim 12, the cited prior art teaches the method of claim 11, further comprising:
receiving, by the memory management unit, the virtual address from one of a plurality of virtual machines (see various virtual machines with VM IDs of Fig. 6).
Claim 20 is the computer storage medium corresponding to the method of claim 11, and is rejected under similar rationale.
Claim Rejections - 35 USC ' 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 4-7, 9, 13-16, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Liljeberg (US 2014/0108701) in view of Rushing et al (US 2023/0107660).
Regarding Claim 4, the cited prior art teaches the system of claim 1, but does not explicitly teach wherein the memory management unit comprises:
a translation lookaside buffer and a memory storing a page table,
wherein the translation lookaside buffer and the page table store intermediate physical address to physical address mappings.
Rushing teaches a translation lookaside buffer (TLB 108 of Fig. 1) and a memory storing a page table (Page Table 122 of Fig. 1),
wherein the translation lookaside buffer and the page table store intermediate physical address to physical address mappings (“The MMU 106 includes a TLB 108, which provides TLB entries 110(0)-110(T) for caching recent translations of…intermediate physical addresses to physical memory addresses, Paragraph 0023, and “page table entries (captioned as “PTE” in FIG. 1) 124(0)-124(P) that each store a mapping between a virtual memory address (or an intermediate physical address) and a corresponding physical memory address,” Paragraph 0025).
It would have been obvious to a person having ordinary skill in the art at the time the invention was filed to have implemented the TLB and page table of Rushing in the cited prior art in order to easily and quickly translate between intermediate physical addresses and physical addresses.
Regarding Claim 5, the cited prior art teaches the system of claim 4, wherein:
the memory management unit further comprises a forbidden mapping cache that stores intermediate physical address to physical address mappings (shown on Fig. 6);
determining that the plurality of the forbidden mappings does not include a mapping for the intermediate physical address comprises:
reading the forbidden mapping cache using the intermediate physical address (“The real (virtual physical) base addresses stored in the set [of the permission table] are then compared against the real [intermediate] (virtual physical) address that is being translated,” and “If the offset [found using the intermediate/guest physical address] is out of boundaries [within the forbidden mapping], a protection fault is generated, also see steps S160 and S170 of Fig. 5); and
determining that the intermediate physical address misses in the forbidden mapping cache (if “the real [intermediate physical] address 420 is within the legal memory boundaries assigned to the currently operating virtual machine (VM),” Paragraph 0085, i.e., if there is a miss in the mappings forbidden to the VM, “The physical address resulting from the physical page number 440 and the offset 410 may then used [returned] to address the physical system memory,” Paragraph 0085, and “the physical address is calculated by adding the corresponding physical base address to the offset [which corresponds to the intermediate physical address],” Paragraphs 0092-0094).
Regarding Claim 6, the cited prior art teaches the system of claim 5, wherein returning a physical address for the intermediate physical address comprises:
determining the physical address for the intermediate physical address based on a mapping for the intermediate physical address stored in either the translation lookaside buffer or the page table, and
in response to determining that the plurality of forbidden mappings does not include a mapping for the intermediate physical address, returning the physical address for the intermediate physical address (if “the real [intermediate physical] address 420 is within the legal memory boundaries assigned to the currently operating virtual machine (VM),” Paragraph 0085, i.e., if there is a miss in the mappings forbidden to the VM, “The physical address resulting from the physical page number 440 and the offset 410 may then used [returned] to address the physical system memory,” Paragraph 0085, and “the physical address is calculated by adding the corresponding physical base address to the offset [which corresponds to the intermediate physical address],” Paragraphs 0092-0094, also see TLB 108 and Page Table 122 of Rushing).
Regarding Claim 7, the cited prior art teaches the system of claim 4, wherein:
determining that the plurality of forbidden mappings does not include a mapping for the intermediate physical address comprises:
reading the translation lookaside buffer using the intermediate physical address (“The MMU 106 includes a TLB 108, which provides TLB entries 110(0)-110(T) for caching recent translations of…intermediate physical addresses to physical memory addresses, Paragraph 0023 of Rushing);
determining that the intermediate physical address misses in the translation lookaside buffer (“The MMU 106 includes a TLB 108, which provides TLB entries 110(0)-110(T) for caching recent translations of…intermediate physical addresses to physical memory addresses, Paragraph 0023 of Rushing, therefore if there is no recent translation for the intermediate physical address, there will be a miss in the TLB);
in response to determining that the intermediate physical address misses in the translation lookaside buffer, reading the page table using the intermediate physical address (“page table entries (captioned as “PTE” in FIG. 1) 124(0)-124(P) that each store a mapping between a virtual memory address (or an intermediate physical address) and a corresponding physical memory address,” Paragraph 0025 of Rushing); and
in response to determining that the plurality of forbidden mappings does not include a mapping for the intermediate physical address, returning the physical address for the intermediate physical address comprises:
determining that the intermediate physical address hits in the translation lookaside buffer or that the page table does not store the intermediate physical address; and
in response to determining that the intermediate physical address hits in the translation lookaside buffer or that the page table does not store the intermediate physical address, returning the physical address for the intermediate physical address (“The MMU 106 includes a TLB 108, which provides TLB entries 110(0)-110(T) for caching recent translations of…intermediate physical addresses to physical memory addresses, Paragraph 0023 of Rushing, and thus if there is a hit in the TLB for the intermediate address, the corresponding physical address will be returned).
Regarding Claim 9, the cited prior art teaches the system of claim 4, wherein the memory management unit can operate in an allowed mapping mode to perform multi-stage address translation by:
translating a virtual address into an intermediate physical address (“The virtual page number 400 [virtual address] is hence translated into the real [intermediate physical] address,” Paragraph 0082, step S140 of Fig. 5),
reading the translation lookaside buffer using the intermediate physical address, and returning a physical address for the intermediate physical address if the intermediate physical address hits in the translation lookaside buffer (“The MMU 106 includes a TLB 108, which provides TLB entries 110(0)-110(T) for caching recent translations of…intermediate physical addresses to physical memory addresses, Paragraph 0023 of Rushing) or if the page table stores a mapping for the intermediate physical address.
Regarding Claim 13, the cited prior art teaches the method of claim 11, but does not explicitly teach wherein the memory management unit comprises:
a translation lookaside buffer and a memory storing a page table,
wherein the translation lookaside buffer and the page table store intermediate physical address to physical address mappings.
Rushing teaches:
a translation lookaside buffer (TLB 108 of Fig. 1) and a memory storing a page table (Page Table 122 of Fig. 1),
wherein the translation lookaside buffer and the page table store intermediate physical address to physical address mappings (“The MMU 106 includes a TLB 108, which provides TLB entries 110(0)-110(T) for caching recent translations of…intermediate physical addresses to physical memory addresses, Paragraph 0023, and “page table entries (captioned as “PTE” in FIG. 1) 124(0)-124(P) that each store a mapping between a virtual memory address (or an intermediate physical address) and a corresponding physical memory address,” Paragraph 0025).
It would have been obvious to a person having ordinary skill in the art at the time the invention was filed to have implemented the TLB and page table of Rushing in the cited prior art in order to easily and quickly translate between intermediate physical addresses and physical addresses.
Regarding Claim 14, the cited prior art teaches the method of claim 13, wherein:
the memory management unit further comprises a forbidden mapping cache that stores intermediate physical address to physical address mappings (shown on Fig. 6);
determining, by the memory management unit, that the plurality of the forbidden mapping does not include a mapping for the intermediate physical address comprises:
reading, by the memory management unit, the forbidden mapping cache using the intermediate physical address (“The real (virtual physical) base addresses stored in the set [of the permission table] are then compared against the real [intermediate] (virtual physical) address that is being translated,” and “If the offset [found using the intermediate/guest physical address] is out of boundaries [within the forbidden mapping], a protection fault is generated, also see steps S160 and S170 of Fig. 5); and
determining that the intermediate physical address misses in the forbidden mapping cache (if “the real [intermediate physical] address 420 is within the legal memory boundaries assigned to the currently operating virtual machine (VM),” Paragraph 0085, i.e., if there is a miss in the mappings forbidden to the VM, “The physical address resulting from the physical page number 440 and the offset 410 may then used [returned] to address the physical system memory,” Paragraph 0085, and “the physical address is calculated by adding the corresponding physical base address to the offset [which corresponds to the intermediate physical address],” Paragraphs 0092-0094).
Regarding Claim 15, the cited prior art teaches the method of claim 14, wherein returning, by the memory management unit, the physical address for the intermediate physical address comprises:
determining, by the memory management unit, the physical address for the intermediate physical address based on a mapping for the intermediate physical address stored in either the translation lookaside buffer or the page table, and
in response to determining that the plurality of forbidden mappings does not include a mapping for the intermediate physical address, returning, by the memory management unit, the physical address for the intermediate physical address (if “the real [intermediate physical] address 420 is within the legal memory boundaries assigned to the currently operating virtual machine (VM),” Paragraph 0085, i.e., if there is a miss in the mappings forbidden to the VM, “The physical address resulting from the physical page number 440 and the offset 410 may then used [returned] to address the physical system memory,” Paragraph 0085, and “the physical address is calculated by adding the corresponding physical base address to the offset [which corresponds to the intermediate physical address],” Paragraphs 0092-0094, also see TLB 108 and Page Table 122 of Rushing).
Regarding Claim 16, the cited prior art teaches the method of claim 13, wherein:
determining, by the memory management unit, that the plurality of forbidden mapping does not include a mapping for the intermediate physical address comprises:
reading, by the memory management unit, the translation lookaside buffer using the intermediate physical address (“The MMU 106 includes a TLB 108, which provides TLB entries 110(0)-110(T) for caching recent translations of…intermediate physical addresses to physical memory addresses, Paragraph 0023 of Rushing);
determining that the intermediate physical address misses in the translation lookaside buffer (“The MMU 106 includes a TLB 108, which provides TLB entries 110(0)-110(T) for caching recent translations of…intermediate physical addresses to physical memory addresses, Paragraph 0023 of Rushing, therefore if there is no recent translation for the intermediate physical address, there will be a miss in the TLB);;
in response to determining that the intermediate physical address misses in the translation lookaside buffer, reading, by the memory management unit, the page table using the intermediate physical address (“page table entries (captioned as “PTE” in FIG. 1) 124(0)-124(P) that each store a mapping between a virtual memory address (or an intermediate physical address) and a corresponding physical memory address,” Paragraph 0025 of Rushing); and
determining whether the page table stores the intermediate physical address; and in response to determining that the plurality of forbidden mappings does not include a mapping for the intermediate physical address, returning, by the memory management unit, the physical address for the intermediate physical address comprises:
in response to determining that the intermediate physical address hits in the translation lookaside buffer or that the page table does not store the intermediate physical address, returning, by the memory management unit, the physical address for the intermediate physical address (“The MMU 106 includes a TLB 108, which provides TLB entries 110(0)-110(T) for caching recent translations of…intermediate physical addresses to physical memory addresses, Paragraph 0023 of Rushing, and thus if there is a hit in the TLB for the intermediate address, the corresponding physical address will be returned).
Regarding Claim 18, the cited prior art teaches the method of claim 13, wherein the memory management unit can operate in an allowed mapping mode to perform multi-stage address translation by:
translating a virtual address into an intermediate physical address (“The virtual page number 400 [virtual address] is hence translated into the real [intermediate physical] address,” Paragraph 0082, step S140 of Fig. 5),
reading the translation lookaside buffer using the intermediate physical address, and returning a physical address for the intermediate physical address if the intermediate physical address hits in the translation lookaside buffer (“The MMU 106 includes a TLB 108, which provides TLB entries 110(0)-110(T) for caching recent translations of…intermediate physical addresses to physical memory addresses, Paragraph 0023 of Rushing) or if the page table stores a mapping for the intermediate physical address.
or if the page table stores a mapping for the intermediate physical address.
Claims 10 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Liljeberg (US 2014/0108701) in view of Rushing et al (US 2023/0107660) and Jacobson et al (US 2006/0064567).
Regarding Claim 10, the cited prior art teaches the system of claim 9, but does not explicitly teach wherein the memory management unit can determine whether to operate in the forbidden mapping mode or the allowed mapping mode based on an access identifier.
Jacobson teaches to determine whether to operate in the forbidden mapping mode or the allowed mapping mode based on an access identifier (the access identifier corresponding to the “Privileged” bit, which indicates if a mapping will only be allowed in a privileged/allowed mapping mode, Paragraph 0069, also see TABLE 2 of page 6).
It would have been obvious to a person having ordinary skill in the art at the time the invention was filed to have implemented the allowed and forbidden mapping modes of Jacobson in the cited prior art in order to protect certain translations from malicious programs.
Regarding Claim 19, the cited prior art teaches the method of claim 18 but does not explicitly teach wherein the memory management unit can determine whether to operate in the forbidden mapping mode or the allowed mapping mode based on an access identifier.
Jacobson teaches to determine whether to operate in the forbidden mapping mode or the allowed mapping mode based on an access identifier.(the access identifier corresponding to the “Privileged” bit, which indicates if a mapping will only be allowed in a privileged/allowed mapping mode, Paragraph 0069, also see TABLE 2 of page 6).
It would have been obvious to a person having ordinary skill in the art at the time the invention was filed to have implemented the allowed and forbidden mapping modes of Jacobson in the cited prior art in order to protect certain translations from malicious programs.
ARGUMENTS CONCERNING NON-PRIOR ART REJECTIONS/OBJECTIONS
Rejections - USC 101
Applicant's arguments/amendments with respect to claim 20 has been considered and have overcome the Examiner’s prior rejections and thus are withdrawn.
ARGUMENTS CONCERNING PRIOR ART REJECTIONS
Rejections - USC 102/103
Applicant's argument that the cited prior art fails to teach the claims as amended has been considered but is not persuasive, as the examiner maintains the cited prior art teaches the limitations of the claims as noted in the rejection above.
Further, the examiner notes the mapping table of Fig. 6 of Liljeberg contains a plurality of mappings between intermediate physical address and physical addresses for which memory access is not permitted, because Liljeberg teaches a range of addresses which are permitted, and thus any intermediate address outside of the permitted range belongs to a “forbidden mapping” in the broadest reasonable interpretation. If the intermediate address belongs to the permitted range, there is no forbidden mapping included for the intermediate physical address.
For the above reasons, the examiner has maintained the rejection of claims 1-7, 9-16, and 18-20.
RELEVANT ART CITED BY THE EXAMINER
The following prior art made of record and not relied upon is cited to establish the level of skill in the applicant's art and those arts considered reasonably pertinent to applicant's disclosure. See MPEP 707.05(c).
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. These references include:
Koufaty et al (US 2020/0019515) teaches SECURE ADDRESS TRANSLATION SERVICES USING A PERMISSION TABLE.
CLOSING COMMENTS
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
STATUS OF CLAIMS IN THE APPLICATION
The following is a summary of the treatment and status of all claims in the application as recommended by M.P.E.P. ' 707.07(i):
SUBJECT MATTER CONSIDERED ALLOWABLE
Claims 8 and 17 contain allowable subject matter for reasons given in the Non-Final Rejection mailed 4/21/2026, Pages 15-16.
CLAIMS REJECTED IN THE APPLICATION
Per the instant office action, claims 1-7, 9-16, and 18-20 have been rejected in the application.
DIRECTION OF FUTURE CORRESPONDENCES
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Mark Giardino whose telephone number is (571) 270-3565 and can normally be reached on M-F 9:00-5:00- 5:30pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Mr. Jared Rutz can be reached on 571-272-5535. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300.
/MARK A GIARDINO JR/Primary Examiner, Art Unit 2135