Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
DETAILED ACTION
Claims 1-20 are presented for examination.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 04/25/2025 has been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Form PTO-1449 is signed and attached hereto.
Drawings
The drawings filed on 04/01/2025 are accepted by the examiner.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement.
Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b).
Claims of Patent # 10924508, 11700277 contains every element of claims of the instant application. Claims of the instant application therefore are not patently distinct from the earlier patent claims and as such are unpatentable over obvious-type double patenting. A later patent claim is not patentably distinct from an earlier claim if the later claim is anticipated by the earlier claim. See the claim comparison below.
“A later patent claim is not patentably distinct from an earlier patent claim if the later claim is obvious over, or anticipated by, the earlier claim. In re Longi, 759 F.2d at 896, 225 USPQ at 651 (affirming a holding of obviousness-type double patenting because the claims at issue were obvious over claims in four prior art patents); In re Berg, 140 F.3d at 1437, 46 USPQ2d at 1233 (Fed. Cir. 1998) (affirming a holding of obviousness-type double patenting where a patent application claim to a genus is anticipated by a patent claim to a species within that genus). “ ELI LILLY AND COMPANY v BARR LABORATORIES, INC., United States Court of Appeals for the Federal Circuit, ON PETITION FOR REHEARING EN BANC (DECIDED: May 30, 2001).
Claim Comparison
Instant Application # 19/097,706
US Patent # 10,924,508
1. (Currently Amended) A method for securely providing access to data in a secure communication session, the method comprising: receiving an indication that a client device is initiating a secure communication connection with a computing device at a first processing core of a multi-core processing system; receiving handle information that includes a virtual address associated with the secured communication connection; storing translation information based on the receipt of the handle information, wherein the stored translation information associates the virtual address and [[the]]a physical memory address with the secure communication connection; allowing access to the physical memory address based on the translation information associating the virtual address with the physical memory address and the secure communication connection[[.]]; and accessing by the first processing core data stored at the physical memory address based on a request that includes the virtual address.
2. (New) The method of claim 1, further comprising storing the handle information in association with the translation information in a first local data store associated with the first processing core.
3. (New) The method of claim 1, further comprising translating the virtual address using a second processing core of the multi-core processing system, the virtual address translated to a second physical memory address.
4. (New) The method of claim 1, wherein accessing the data stored at the physical memory address is only performed by the first processing core in the multi-core processing system.
5. (New) The method of claim 1, further comprising using the first processing core to access secure information and to decrypt secure data included in a received data packet.
6. (New) The method of claim 1, further comprising generating a page fault when the first processing core attempts to access a physical memory location associated with a second processing core of the multi-core processing system.
7. (New) The method of claim 1, further comprising: creating one or more sessions keys related to the secure communication connection; storing the session keys in the physical memory, wherein the session keys are available to decrypt data included in a subsequent data packet associated with the secure communication connection; and creating a second packet based on data included in a first packet sent between the client device and the computing device, wherein the data from the first packet is secured in the second packet based on the created session keys.
8. (New) The method of claim 1, further comprising: maintaining information that cross-references handle information to virtual memory addresses and to physical memory addresses that correspond to each of a plurality of secure communication connections; identifying that one of the secure communication connections has been terminated; and deleting translation information associated with the terminated secure communicated connection in accordance with the cross-reference information at the physical memory address.
9. (New) The method of claim 1, further comprising: allocating a second processing core to receive data packets via a second secure communication connection; requesting new handle information using at least one of a low-level program code or a firmware via an application program interface (API);providing a new request including the new handle information to a second API that includes a descriptor associated with the new handle information; programming information in a secure memory vault (SMV) associated with the new handle based on the new request; and processing the data packets received via the second secure communication connection.
10. (New) The method of claim 9, wherein the API is an open secure socket layer (OpenSSL) API associated with the secure communication connection.
11. (New) A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor for implementing a method for securely providing access to data in a secure communication session, the method comprising: receiving an indication that a client device is initiating a secure communication connection with a computing device at a first processing core of a multi-core processing system; receiving handle information that includes a virtual address associated with the secured communication connection; storing translation information based on the receipt of the handle information, wherein the stored translation information associates the virtual address and a physical memory address with the secure communication connection; allowing access to the physical memory address based on the translation information associating the virtual address with the physical memory address and the secure communication connection; and accessing by the first processing core data stored at the physical memory address based on a request that includes the virtual address.
12. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to store the handle information in association with the translation information in a first local data store associated with the first processing core.
13. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to translate the virtual address using a second processing core of the multi-core processing system, the virtual address translated to a second physical memory address.
14. (New) The non-transitory computer-readable storage medium of claim 11, wherein accessing the data stored at the physical memory address is only performed by the first processing core in the multi-core processing system.
15. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to use the first processing core to access secure information and to decrypt secure data included in a received data packet.
16. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to generate a page fault when the first processing core attempts to access a physical memory location associated with a second processing core of the multi-core processing system.
17. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to: create one or more sessions keys related to the secure communication connection; store the session keys in the physical memory, wherein the session keys are available to decrypt data included in a subsequent data packet associated with the secure communication connection; and create a second packet based on data included in a first packet sent between the client device and the computing device, wherein the data from the first packet is secured in the second packet based on the created session keys.
18. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to: maintain information that cross-references handle information to virtual memory addresses and to physical memory addresses that correspond to each of a plurality of secure communication connections; identify that one of the secure communication connections has been terminated; and delete translation information associated with the terminated secure communicated connection in accordance with the cross-reference information at the physical memory address.
19. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to: allocate a second processing core to receive data packets via a second secure communication connection; request new handle information using at least one of a low-level program code or a firmware via an application program interface (API);provide a new request including the new handle information to a second API that includes a descriptor associated with the new handle information;p rogram information in a secure memory vault (SMV) associated with the new handle based on the new request; and process the data packets received via the second secure communication connection.
20. (New) A multi-core processing system for securely providing access to data in a secure communication session, the system comprising: a plurality of processing cores that includes at least a first processing core that: receives an indication that a client device is initiating a secure communication connection with a computing device, and receives handle information that includes a virtual address associated with the secured communication connection; and memory that: stores translation information based on the receipt of the handle information, wherein the stored translation information associates the virtual address and a physical memory address with the secure communication connection, and allows access to the physical memory address based on the translation information associating the virtual address with the physical memory address and the secure communication connection; wherein the first processing core accesses data stored at the physical memory address based on a request that includes the virtual address.
1. A method for securely providing access to data in a secure communication, the method comprising: receiving an indication that a client device is initiating a secure communication connection with a computing device at a first processing core of a multi-core processing system; receiving a first packet sent between the client device and the computing device via the secure communication connection; receiving handle information that includes a virtual address and a physical memory address; storing translation information based on the receipt of the handle information, wherein the stored translation information associates the virtual address and the physical memory address with the secure communication connection; creating session keys and secure keying material related to the secure communication connection; storing the created session keys and the secure keying material in a physical memory, wherein the created session keys and the secure keying material that are stored in the physical memory are available to decrypt data included in subsequent data packets associated with the secure communication connection; creating a new packet to send to a destination from data included in the first packet, wherein the newly created packet secures the data included in the first packet based at least in part on the created session keys; allowing the newly created packet to be sent to the destination; allowing access to the physical memory address based on the translation information associating the virtual address with the physical memory address and the secure communication connection; and accessing by the first processing core data stored at the physical memory address based on a request that includes the virtual address.
2. The method of claim 1, wherein the secure communication connection was interrupted after the newly created packet was sent to the destination and the method further comprising: receiving an indication from the client device to re-establish the secure connection, matching one or more attributes associated with the client device and a server; creating a fingerprint based on the one or more attributes associated with the client device and the server; retrieving data from a cache memory; identifying that the data retrieved from the cache memory is associated with the fingerprint, thereby, corresponding to a cache hit; accessing the session keys previously stored in the physical memory via a first handle, wherein the previously stored session keys are available for decrypting data included in additional packets associated with the re-established secure connection; and associating a second handle with a new portion of the physical memory for storing information related to the re-established secure connection, wherein the storing of the information related to the re-established secure connection in the new portion of the physical memory allows for the information related to the re-established secure connection to be accessed via the second handle.
3. The method of claim 1, further comprising storing the translation information in a data store, wherein the data store is a transition lookaside buffer (TLB) at the first processing core and the TLB comprises a set of hardware registers coupled to the first processing core.
4. The method of claim 1, wherein the translation information also includes a size.
5. The method of claim 1, further comprising allocating the first processing core to receive data packets associated with the secure communication connection, wherein the receipt of the first packet is based on the first processing core being allocated to receive the data packets associated with the secure communication connection.
6. The method of claim 1, further comprising: receiving data packets relating to a second secure connection at a second processing core of the multi-core processing system; decrypting information included in the received data packets of the second secure connection; and allowing the received data packets of the second secure connection to be sent to the destination or to another destination.
7. The method of claim 1, wherein the destination is at least one of the computing device or the client device.
8. The method of claim 1, wherein the first processing core in the multi-core processing system is the only processing core in the multi-core processing system that accesses the data stored at physical memory addresses associated with the secure connection.
9. The method of claim 2, wherein the first handle and the second handle are associated with handle information that includes a handle identifier.
10. The method of claim 9, wherein the handle information is the handle identifier.
11. A non-transitory computer readable storage medium having embodied thereon a program executable by a processor for implementing a method for securely providing access to data in a secure communication, the method comprising: receiving an indication that a client device is initiating a secure communication connection with a computing device at a first processing core of a multi-core processing system; receiving a first packet sent between the client device and the computing device via the secure communication connection; receiving handle information that includes a virtual address and a physical memory address; storing translation information based on the receipt of the handle information, wherein the stored translation information associates the virtual address and the physical memory address with the secure communication connection; creating session keys and secure keying material related to the secure communication connection; storing the created session keys and the secure keying material in a physical memory, wherein the created session keys and the secure keying material that are stored in the physical memory are available to decrypt data included in subsequent data packets associated with the secure communication connection; creating a new packet to send to a destination from data included in the first packet, wherein the newly created packet secures the data included in the first packet based at least in part on the created session keys; allowing the newly created packet to be sent to the destination; allowing access to the physical memory address based on the translation information associating the virtual address with the physical memory address and the secure communication connection; and accessing by the first processing core data stored at the physical memory address based on a request that includes the virtual address.
12. The non-transitory computer-readable medium of claim 11, wherein the secure communication connection was interrupted after the newly created packet was sent to the destination and the program is further executable to: receive an indication from the client device to re-establish the secure connection, match one or more attributes associated with the client device and a server; create a fingerprint based on the one or more attributes associated with the client device and the server; retrieve data from a cache memory; identify that the data retrieved from the cache memory is associated with the fingerprint, thereby, corresponding to a cache hit; access the session keys previously stored in the physical memory via a first handle, wherein the previously stored session keys are available for decrypting data included in additional packets associated with the re-established secure connection; and associate a second handle with a new portion of the physical memory for storing information related to the re-established secure connection, wherein the storing of the information related to the re-established secure connection in the new portion of the physical memory allows for the information related to the re-established secure connection to be accessed via the second handle.
13. The non-transitory computer-readable storage medium of claim 12, the program further executable to store translation information to be stored in a data store, wherein the data store is a transition lookaside buffer (TLB) at the first processing core and the TLB comprises a set of hardware registers coupled to the first processing core.
14. The non-transitory computer-readable storage medium of claim 12, wherein the handle information also includes a size.
15. The non-transitory computer-readable storage medium of claim 11, the program further executable to allocate the first processing core to receive data packets associated with the secure communication connection, wherein the receipt of the first packet is based on the first processing core being allocated to receive the data packets associated with the secure communication connection.
16. The non-transitory computer-readable storage medium of claim 11, the program further executable to: receive data packets relating to a second secure connection at a second processing core of the multi-core processing system; decrypt information included in the received data packets of the second secure connection; and allow the received data packets of the second secure connection to be sent to the destination or to another destination.
17. The non-transitory computer-readable storage medium of claim 11, wherein the destination is at least one of the computing device or the client device.
18. The non-transitory computer-readable storage medium of claim 11, wherein the first processing core in the multi-core processing system is the only processing core in the multi-core processing system that accesses the data stored in at physical memory addresses associated with the secure communication connection.
19. A multi-core processing system for securely providing access to data in a secure communication, the system comprising: one or more memories; a plurality of processing cores that execute instructions out of the one or more memories; and a plurality of data stores that store translation information, wherein each discrete processing core of the plurality of processing cores is associated with one and only one data store of the plurality of data stores, and a first processing core of the plurality of processing cores: receives an indication that a client device is initiating a secure communication connection with a computing device at a first processing core of a multi-core processing system; receives a first packet sent between the client device and the computing device via the secure communication connection; receives handle information that includes a virtual address and a physical memory address; stores translation information based on the receipt of the handle information, wherein the stored translation information associates the virtual address and the physical memory address with the secure communication connection; creates session keys and secure keying material related to the secure communication connection; stores the created session keys and the secure keying material in a physical memory, wherein the created session keys and the secure keying material that are stored in the physical memory are available to decrypt data included in subsequent data packets associated with the secure communication connection; creates a new packet to send to a destination from the data included in the first packet, wherein the newly created packet secures the data included in the first packet based at least in part on the created session keys; allows the newly created packet to be sent to the destination; allows access to the physical memory address based on the translation information associating the virtual address with the physical memory address and the secure communication connection; and accesses by the first processing core data stored at the physical memory address based on a request that includes the virtual address.
20. The system of claim 19, wherein: the secure communication connection was interrupted after the newly created packet was sent to the destination, an indication from the client device to re-establish the secure connection is received, one or more attributes associated with the client device and a server are matched, a fingerprint based on the one or more attributes associated with the client device and the server is created, data is retrieved from a cache memory, the data retrieved from the cache memory is identified as being associated with the fingerprint, thereby, corresponding to a cache hit, the session keys previously stored in the physical memory are accessed via a first handle, wherein the previously stored session keys are available for decrypting data included in additional packets associated with the re-established secure connection, and a second handle is associated with a new portion of the physical memory for storing information related to the re-established secure connection, wherein the storing of the information related to the re-established secure connection in the new portion of the physical memory allows for the information related to the re-established secure connection to be accessed via the second handle.
Instant Application # 19/097,706
US Patent # 11,700,277
1. (Currently Amended) A method for securely providing access to data in a secure communication session, the method comprising: receiving an indication that a client device is initiating a secure communication connection with a computing device at a first processing core of a multi-core processing system; receiving handle information that includes a virtual address associated with the secured communication connection; storing translation information based on the receipt of the handle information, wherein the stored translation information associates the virtual address and [[the]]a physical memory address with the secure communication connection; allowing access to the physical memory address based on the translation information associating the virtual address with the physical memory address and the secure communication connection[[.]]; and accessing by the first processing core data stored at the physical memory address based on a request that includes the virtual address.
2. (New) The method of claim 1, further comprising storing the handle information in association with the translation information in a first local data store associated with the first processing core.
3. (New) The method of claim 1, further comprising translating the virtual address using a second processing core of the multi-core processing system, the virtual address translated to a second physical memory address.
4. (New) The method of claim 1, wherein accessing the data stored at the physical memory address is only performed by the first processing core in the multi-core processing system.
5. (New) The method of claim 1, further comprising using the first processing core to access secure information and to decrypt secure data included in a received data packet.
6. (New) The method of claim 1, further comprising generating a page fault when the first processing core attempts to access a physical memory location associated with a second processing core of the multi-core processing system.
7. (New) The method of claim 1, further comprising: creating one or more sessions keys related to the secure communication connection; storing the session keys in the physical memory, wherein the session keys are available to decrypt data included in a subsequent data packet associated with the secure communication connection; and creating a second packet based on data included in a first packet sent between the client device and the computing device, wherein the data from the first packet is secured in the second packet based on the created session keys.
8. (New) The method of claim 1, further comprising: maintaining information that cross-references handle information to virtual memory addresses and to physical memory addresses that correspond to each of a plurality of secure communication connections; identifying that one of the secure communication connections has been terminated; and deleting translation information associated with the terminated secure communicated connection in accordance with the cross-reference information at the physical memory address.
9. (New) The method of claim 1, further comprising: allocating a second processing core to receive data packets via a second secure communication connection; requesting new handle information using at least one of a low-level program code or a firmware via an application program interface (API);providing a new request including the new handle information to a second API that includes a descriptor associated with the new handle information; programming information in a secure memory vault (SMV) associated with the new handle based on the new request; and processing the data packets received via the second secure communication connection.
10. (New) The method of claim 9, wherein the API is an open secure socket layer (OpenSSL) API associated with the secure communication connection.
11. (New) A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor for implementing a method for securely providing access to data in a secure communication session, the method comprising: receiving an indication that a client device is initiating a secure communication connection with a computing device at a first processing core of a multi-core processing system; receiving handle information that includes a virtual address associated with the secured communication connection; storing translation information based on the receipt of the handle information, wherein the stored translation information associates the virtual address and a physical memory address with the secure communication connection; allowing access to the physical memory address based on the translation information associating the virtual address with the physical memory address and the secure communication connection; and accessing by the first processing core data stored at the physical memory address based on a request that includes the virtual address.
12. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to store the handle information in association with the translation information in a first local data store associated with the first processing core.
13. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to translate the virtual address using a second processing core of the multi-core processing system, the virtual address translated to a second physical memory address.
14. (New) The non-transitory computer-readable storage medium of claim 11, wherein accessing the data stored at the physical memory address is only performed by the first processing core in the multi-core processing system.
15. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to use the first processing core to access secure information and to decrypt secure data included in a received data packet.
16. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to generate a page fault when the first processing core attempts to access a physical memory location associated with a second processing core of the multi-core processing system.
17. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to: create one or more sessions keys related to the secure communication connection; store the session keys in the physical memory, wherein the session keys are available to decrypt data included in a subsequent data packet associated with the secure communication connection; and create a second packet based on data included in a first packet sent between the client device and the computing device, wherein the data from the first packet is secured in the second packet based on the created session keys.
18. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to: maintain information that cross-references handle information to virtual memory addresses and to physical memory addresses that correspond to each of a plurality of secure communication connections; identify that one of the secure communication connections has been terminated; and delete translation information associated with the terminated secure communicated connection in accordance with the cross-reference information at the physical memory address.
19. (New) The non-transitory computer-readable storage medium of claim 11, further comprising instructions executable to: allocate a second processing core to receive data packets via a second secure communication connection; request new handle information using at least one of a low-level program code or a firmware via an application program interface (API);provide a new request including the new handle information to a second API that includes a descriptor associated with the new handle information;p rogram information in a secure memory vault (SMV) associated with the new handle based on the new request; and process the data packets received via the second secure communication connection.
20. (New) A multi-core processing system for securely providing access to data in a secure communication session, the system comprising: a plurality of processing cores that includes at least a first processing core that: receives an indication that a client device is initiating a secure communication connection with a computing device, and receives handle information that includes a virtual address associated with the secured communication connection; and memory that: stores translation information based on the receipt of the handle information, wherein the stored translation information associates the virtual address and a physical memory address with the secure communication connection, and allows access to the physical memory address based on the translation information associating the virtual address with the physical memory address and the secure communication connection; wherein the first processing core accesses data stored at the physical memory address based on a request that includes the virtual address.
1. A method for securely accessing data, the method comprising: storing a first set of translation data at a first data storage device separate from a system memory that is physically accessible only by a first processor of a multi-processor system, the first set of translation data associated with a first connection, wherein the first set of translation data maps a first virtual address to a first physical memory location that is only accessible to the first processor while servicing the first connection; storing a second set of translation data in a second data storage device separate from the system memory that is physically accessible only by a second processor of the multi-processor system, the second set of translation data associated with a second connection, wherein the second set of translation data maps a second virtual address to a second physical memory location that is only accessible to the second processor while servicing the second connection; accessing the first physical memory location that stores data associated with the first connection by the first processor, the first physical memory location accessed after the first processor translates the first virtual address to a first physical memory address using the first data storage device, wherein data stored at the first physical memory address is secured based on the first set of translation data being accessible only by the first processor; accessing the second physical memory location that stores data associated with the second connection by the second processor, the second physical memory location accessed after the second processor translates the second virtual address to a second physical memory address using the second data storage device, wherein data stored at the second physical memory address is secured based on the second set of translation data being accessible only by the second processor; securely communicating with a first destination associated with the first connection after accessing the first physical memory address; and securely communicating with to a second destination associated with the second connection after accessing the second physical memory location.
2. The method of claim 1, wherein the first virtual address and the second virtual address are a same virtual address that are respectively translated to the first physical memory address and the second physical memory address.
3. The method of claim 1, wherein the first data storage device is associated with a first type of processor and a number of translation entries stored at the first data storage device correspond to the first type of processor.
4. The method of claim 1, wherein program code associated with the first set of translation data is included in a set of firmware.
5. The method of claim 1, wherein program code associated with the first set of translation data is included in a software driver.
6. The method of claim 1, further comprising: identifying that the first processor of the multi-processor system corresponds to a first type of processing core; and assigning a number of translation entries to associate with the first set of translation data based on the identification that the first processor corresponds to the first type of processing core.
7. The method of claim 6, further comprising identifying a size of the first data storage device, wherein the number of translation entries corresponds to the identified size of the first data storage device.
8. The method of claim 6, further comprising identifying a data structure to associate with the first set of translation data.
9. The method of claim 1, further comprising assigning a first entry of the first set of translation data to associate with the first virtual address with the first physical memory address, access permissions, and control permissions.
10. The method of claim 9, wherein the first entry is also associated with a size.
11. The method of claim 1, further comprising assigning a first entry of the first set of translation data to an access permission.
12. The method of claim 1, further comprising assigning a first entry of the first set of translation data to a control permission.
13. A non-transitory computer-readable storage medium having embodied thereon a program executable by processor to perform a method for securely accessing data, the method comprising: storing a first set of translation data at a first data storage device separate from a system memory that is physically accessible only by a first processor of a multi-processor system, the first set of translation data associated with a first connection, wherein the first set of translation data maps a first virtual address to a first physical memory location that is only accessible to the first processor while servicing the first connection; storing a second set of translation data in a second data storage device separate from the system memory that is physically accessible only by a second processor of the multi-processor system, the second set of translation data associated with a second connection, wherein the second set of translation data maps a second virtual address to a second physical memory location that is only accessible to the second processor while servicing the second connection; accessing the first physical memory location that stores data associated with the first connection by the first processor, the first physical memory location accessed after the first processor translates the first virtual address to a first physical memory address using the first data storage device, wherein data stored at the first physical memory address is secured based on the first set of translation data being accessible only by the first processor; accessing the second physical memory location that stores data associated with the second connection by the second processor, the second physical memory location accessed after the second processor translates the second virtual address to a second physical memory address using the second data storage device, wherein data stored at the second physical memory address is secured based on the second set of translation data being accessible only by the second processor; securely communicating with a first destination associated with the first connection after accessing the first physical memory address; and securely communicating with a second destination associated with the second connection after accessing the second physical memory location.
14. The non-transitory computer-readable storage medium of claim 13, wherein the first virtual address and the second virtual address are a same address that are respectively translated to the first physical memory address and the second physical memory address.
15. The non-transitory computer-readable storage medium of claim 13, wherein the first data storage device is associated with a first type of processor and a number of translation entries stored at the first data storage device correspond to the first type of processor.
16. The non-transitory computer-readable storage medium of claim 13, the program further executable to: identify that the first processor of the multi-processor system corresponds to a first type of processing core; and assign a number of translation entries to associate with the first set of translation data based on the identification that the first processor corresponds to the first type of processing core.
17. The non-transitory computer-readable storage medium of claim 16, the program further executable to identify a size of the first data storage device, wherein the number of translation entries corresponds to the identified size of the first data storage device.
18. The non-transitory computer-readable storage medium of claim 16, the program further executable to identify a data structure to associate with the first set of translation data.
19. An apparatus for securely accessing data in a multi-processor system, the apparatus comprising: a first processor of that executes stored instructions; a first storage device separate from a system memory that is physically accessible only by the first processor that stores a first set of translation data, the first set of translation data associated with a first connection from which data is sent and received, wherein: the first processor securely accesses data at a first physical memory location that stores data associated with the first connection, the data securely accessed based on the first storage device only being accessible by the first processor, and the first physical memory location is accessed after the first processor translates a first virtual address to a first physical memory address only accessible to the first processor while servicing the first connection; a second processor that executes stored instructions; and a second storage device separate from the system memory that is physically accessible only by the second processor that stores a second set of translation data, the second set of translation data associated with a second connection from which data is sent and received, wherein: the second processor securely accesses data at a second physical memory location that stores data associated with the second connection based on the second storage device being accessible only by the second processor, and the second physical memory location accessed after the second processor translates a second virtual address to a second physical memory address only accessible to the second processor while servicing the second connection.
20. The apparatus of claim 19, further comprising a system memory that stores the stored instructions executed by the first processor and by the second processor.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US Publication No. 2012/0255003, “a system for protecting an electronic device against malware includes an object-oriented operating system configured to execute on the electronic device and a below-operating-system security agent. The below-operating-system security agent is configured to trap an attempted access of an object manager of the operating system, trap an attempted generation of one or more objects of the operating system, trap an attempted access of one or more object functions of the one or more objects, build a behavioral state map of the trapped actions of the object manager and the one or more objects, and operate at a level below all of the operating systems of the electronic device accessing the object manager”.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MORSHED MEHEDI whose telephone number is (571) 270-7640. The examiner can normally be reached on M - F, 8:00 am to 4:00 pm EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Linglan Edwards can be reach on (571) 270-5440. The fax number for the organization where this application or proceeding is assigned is (571) 273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from their Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (In USA or Canada) or 571-272-1000.
/MORSHED MEHEDI/Primary Examiner, Art Unit 2408