DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to the Preliminary Amendment
Applicant’s first and second preliminary amendments to the claims, specification, drawings, and abstract, dated June 6, 2025 and June 20, 2025, respectfully, have been fully considered and are entered. Claims 1-10 and 12 are examined while claim 11 has been canceled.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1-10 and 12 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention.
As to claims 1, 10, and 12, it is unclear how simulating implementation of a target process and detecting whether said attack is attempted accomplishes the step of protecting a terminal. It appears that the claim doesn’t go beyond detection of the attack falling short of protecting, as the claim requires, rendering the step of protecting indefinite.
The limitation “when said terminal is likely to be subject to said attack” is a conditional statement that does not require detecting that said terminal is likely to be subject to said attack or explaining how the likelihood is established or determined rendering the step of simulating optional since there is no requirement for the terminal to be the subject of the attack. Having the step of “simulating” conditional and optional, it is unclear what is actually required by the claim as an active step(s).
In the step of detecting, it is unclear how an attempted attack is detected based on the modified data descriptive of the state of the battery. There is nothing in claim 1 or the dependent claims that would explain how the attempted attack is detected.
Dependent claims are rejected for the same reasons as incorporating all the features of the corresponding independent claim.
As to claim 3, it is unclear what is being done. In particular, “simulating being implemented during the entry of said code by a user on said interface” is ambiguous because it is unclear whether it implies that the code will appear to be entered twice or some other variation of simultaneous entry, one entry being the actual entry by the user and one entry being the simulation. Appropriate explanation is required.
As to claims 5 and 6, the language “or to be temporarily deactivated” and “controlled not to be activated” is contrary to the express language of the preceding claims that require the simulating to be positively performed and the data descriptive of the state of the battery modified when the terminal is likely to be subject of the attack. It is further unclear what constitutes “a dummy manner” rendering the scope of the claim indefinite.
As to claim 8, the language “software blocking of the data descriptive of the state of the battery” is ambiguous because it is unclear what “software blocking” entails.
As to claim 10, the language “the data processor being configured to” is ambiguous because it is unclear whether the processor is configured in hardware being a specific purpose processor (i.e., FPGA) or is configured in software by executing code instructions such as those disclosed in claim 12. If implemented in hardware, the specification is lacking description of how this implementation is accomplished, which would result in 35 U.S.C. 112(a) rejection. If implemented in software, the claim is missing a memory storing code instructions that, when executed by the processor, configure the processor to perform the method steps. Appropriate correction and/or explanation is required.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-10 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Smith et al. (US 2024/0106839 A1) in view of Liu et al. (High-Confidence Computing) Cite U and in further view of Sun et al. (VISIBLE: Video-Assisted Keystroke Inference from Tablet Backside Motion) Cite V.
As to claim 1, X teaches a method comprising:
protecting a terminal [computing terminal 1750 that can be a mobile device] (par. [0218]) comprising a data processor, a battery (Fig. 17) and a battery gauge [battery monitor 1778] providing the data processor with data descriptive of a state of the battery (par. [0233]), against a side-channel attack using said data descriptive of the state of the battery [performing data substitution as a countermeasure against the side-channel attack] (par. [0032], [0255], [0266]), the protecting comprising implementing by the data processor:
when said terminal is likely to be subject to said attack (par. [0078], Table 1), simulating implementation of a target process on the terminal so as to modify the data and obtain a same data as the data that would be obtained for said target process [simulating correct functioning of the system, so if the attacker uses the stolen dummy secret, they can be traced] (par. [0086]); and
detecting whether said attack is attempted based on the modified data descriptive of the state of the battery [detecting if the attacker used the stolen dummy secret via tracing] (par. [0086]).
Smith fails to teach that simulating implementation of a target process on the terminal is performed by controlling at least one energy-consuming component of the terminal so as to modify the data descriptive of the state of the battery provided by the battery gauge and obtain a same data descriptive of the state of the battery as the data that would be obtained for said target process.
Liu discloses a survey of side-channel threats and countermeasures (abstract, Table 1). In particular, Liu teaches detecting a keystroke recognition attack (section 6.1.2) and interaction inference attack (section 6.2.4) and performing countermeasures (section 7) that includes controlling at least one energy-consuming component of the terminal so as to modify the data descriptive of the state of the battery provided by the battery gauge [performing randomization of the current drawn by changing load resistors and performing random usage patterns (Table 2). Liu also discloses in section 7.2 a solution to counter power side-channel attacks for smartphones. The hardware countermeasure consists of a scrambler unit to be deployed at the host side. Such a countermeasure relies on a micro-controller that randomly switches several load resistors to variate the current draw, thus masking the signal properties. Similarly, the software countermeasure perturbs the current draw by the user activities via a background service that generates random patterns of CPU and memory resources usage. The authors prove that both solutions are effective to counter user activity inference attacks].
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system of Smith by simulating implementation of a target process on the terminal being performed by
controlling at least one energy-consuming component of the terminal so as to modify the data descriptive of the state of the battery provided by the battery gauge, in order to counter user activity inference attacks (section 7.2 in Liu).
While Liu teaching switching several load resistors to variate the current flow and generating random patterns of CPU and memory resources usage (section 7.2), Liu fails to teach that these countermeasures obtain a same data descriptive of the state of the battery as the data that would be obtained for said target process.
Sun discloses a keystroke inference framework (abstract) and corresponding countermeasure. In particular, Sun teaches controlling at least one energy-consuming component of the terminal so as to modify the data descriptive of the state of the battery provided by the battery gauge and obtain a same data descriptive of the state of the battery as the data that would be obtained for said target process [controlling on-board vibrators to generate vibrations during the typing process of the user such as to mask the motions caused by the user’s typing process] (section VII, page 14 left column).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system of Smith in view of Liu by having the countermeasures of Liu control at least one energy-consuming component of the terminal (vibrator in Sun) so as to modify the data descriptive of the state of the battery provided by the battery gauge obtain a same data descriptive of the state of the battery as the data that would be obtained for said target process in order to mask user actions and signal properties generated by the user actions, as suggested by both Liu and Sun’s disclosures.
As to claim 2, Smith in view of Liu and Sun teaches that said energy-consuming component is a vibrator (section VII, page 14 left column in Sun).
As to claim 3, Smith in view of Liu and Sun teaches requesting entry of a code on an interface of the terminal, the simulating being implemented during the entry of said code by a user on said interface (section 7.2 in Liu; section VII, page 14 left column in Sun).
As to claim 4, Smith in view of Liu and Sun teaches that said energy-consuming component is a vibrator and wherein the data processor is configured to activate said vibrator each time a character of said code is entered on the interface (section VII, page 14 left column in Sun).
As to claim 5, Smith teaches that the simulating, said energy-consuming component of the terminal is controlled either to be activated at least once in a dummy manner (par. [0086]), or to be temporarily deactivated.
As to claim 6, Smith in view of Liu and Sun teaches that in the simulating, said energy-consuming component of the terminal is controlled either to be activated at least once in a dummy manner (par. [0086] in Smith), or to be temporarily deactivated, and either said vibrator or another energy-consuming component of the terminal is controlled to be activated in a dummy manner outside of an entry of a character of said code on the interface (par. [0086] in Smith; section 7.2 in Liu), or said vibrator is controlled not to be activated when entering at least one character of said code on the interface.
As to claim 7, Smith in view of Liu and Sun teaches that the target process is the entry of a code on an interface of the terminal section VII, page 14 left column in Sun).
As to claim 8, Smith teaches implementing a response measure based on a result of the detecting [countermeasure] (par. [0032], [0255], [0266]).
As to claim 9, Smith in view of Liu and Sun teaches that said response measure comprises a software blocking of the data descriptive of the state of the battery provided by the battery gauge [disabling access] (par. [0114]).
As to claim 10, Smith in view of Liu and Sun teaches a terminal [computing device 1750] (Figs. 16 and 17 in Smith) comprising:
data processor (Figs. 16 and 17 in Smith),
at least one energy-consuming component (Figs. 16 and 17 in Smith),
a battery (Figs. 16 and 17 in Smith), and
a battery gauge [battery monitor 1778] which provides the data processor with data descriptive of a state of the battery (par. [0233] in Smith), the data processor being configured to perform the method steps as discussed above with respect to claim 1.
As to claim 12, Smith in view of Liu and Sun teaches a non-transitory computer readable storage medium on which is recorded a computer program product comprising code instructions for execution of a method when instructions are executed by a data processor of a terminal (par. [0235] in Smith), wherein the method comprises steps as discussed per claim 1 above.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to OLEG SURVILLO whose telephone number is (571)272-9691. The examiner can normally be reached 9:00am - 5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ario Etienne can be reached at 571-272-4001. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/OLEG SURVILLO/Primary Examiner, Art Unit 2457