DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Acknowledgment is made of priority based on US provisional patent application filed on May 20, 2024.
Drawings
The drawings submitted on April 30, 2025 have been considered and accepted.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-7, 10, 13-25 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Hulton et al. (Pub. No. US 2022/0222384), hereinafter Hulton.
Claim 1. Hulton discloses a memory system, comprising: one or more non-volatile memory devices; and one or more controllers coupled with the one or more non-volatile memory devices and configured to cause the memory system (See Parag. [0036]; … executable instructions may be stored on one of the non-volatile memory devices 210 and retrieved by a memory controller 202 for the processor 206 to execute the executable instructions for performing the method 300 …) to:
receive, from a host system, a command for a set of data, and an address payload comprising an indication of a register, of the host system, that stores cryptography instructions for the set of data (See Parag. [0037]; Block 302 includes receiving, from a host computing device, a memory access request for a memory device. The memory access request may be or include a command and a memory address. Accordingly, block 302 may include receiving, from a host computing device, a command and an address for one or more memory devices);
transmit, to a cryptography engine of the host system, an indication of the command for the set of data, and the address payload comprising the indication of the register that stores the cryptography instructions (See Parag. [0037]; In an example of memory access request including a write command, the host computing device 204 of FIG. 2 may provide a memory access request, including a memory address and data to be written, to the memory controller 202, e.g., to the host interface 212 via the host bus 220. For example, as described with respect to memory system 200, in the example of an received memory access request including a read command, the memory system 200, advantageously, the memory controller 202 facilitates the retrieval 8 to read data on the non-volatile memory devices 210. Accordingly, the processor 206 may receive the memory access request for generation or retrieval of an encrypted key for data access associated with the memory address request); and
communicate, between the memory system and the host system, the set of data based at least in part on transmitting the indication of the command and the address payload comprising the indication of the register that stores the cryptography instructions, wherein the set of data is encrypted according to the cryptography instructions (See Parag. [0038]; responsive to the memory access request, encrypting, at encryption logic, a key for data associated with the memory access request. For example, encryption logic 208 may identify a memory address in the received memory access request that corresponds to a memory address of a non-volatile memory device. Once identified, the encryption logic 208 may generate an encrypted key for data associated with that memory access request. In the example of the write operation, the encrypted key may be generated to secure the data written to the memory address at a non-volatile memory device. To encrypt the key, the encryption logic 208 uses an pseudorandom value as an IV for an authenticated stream cipher (e.g., an AES-GCM pipeline) and a provisioned key, like a DEK. The encryption logic 208 encrypts the provisioned key based at least on the pseudorandom value to associate the encrypted key with the memory access request and/or the memory address of the memory address request. Accordingly, in the context of a write operation in a received memory access request, an encrypted key may be used to encrypt the data to be written as plaintext to ciphertext. Advantageously, based on a received memory access request, data read or written by a host computing device to various non-volatile memory devices may be accessed in an authenticated manner, e.g., using the generated encrypted key … See Parag. [0040]; In block 308, the method includes providing, to the non-volatile memory device, the encrypted key for accessing data associated with the memory access request).
Claim 2. Hulton discloses the memory system of claim 1,
Hulton further discloses wherein the address payload comprises an address, for a volatile memory of the host system, from which the host system is to retrieve the set of data (See Parag. [0037]; block 302 may include receiving, from a host computing device, a command and an address for one or more memory devices. In an example of memory access request including a write command, the host computing device 204 of FIG. 2 may provide a memory access request, including a memory address and data to be written, to the memory controller 202, e.g., to the host interface 212 via the host bus 220. For example, as described with respect to memory system 200, in the example of an received memory access request including a read command, the memory system 200, advantageously, the memory controller 202 facilitates the retrieval of encrypted keys to read data on the non-volatile memory devices 210. Accordingly, the processor 206 may receive the memory access request for generation or retrieval of an encrypted key for data access associated with the memory address request).
Claim 3. Hulton discloses the memory system of claim 2,
Hulton further discloses wherein the command is a command to write the set of data, and wherein communication of the set of data comprises the set of data being received from the host system (See Parag. [0037]; block 302 may include receiving, from a host computing device, a command and an address for one or more memory devices. In an example of memory access request including a write command, the host computing device 204 of FIG. 2 may provide a memory access request, including a memory address and data to be written, to the memory controller 202, e.g., to the host interface 212 via the host bus 220 …).
Claim 4. Hulton discloses the memory system of claim 2,
Hulton further discloses wherein the one or more controllers is further configured to cause the memory system to: receive a logical address associated with the encrypted set of data; and write the encrypted set of data to a set of memory cells, of the one or more non-volatile memory devices, mapped to the logical address (See Parag. [0037]; block 302 may include receiving, from a host computing device, a command and an address for one or more memory devices. In an example of memory access request including a write command, the host computing device 204 of FIG. 2 may provide a memory access request, including a memory address and data to be written, to the memory controller 202, e.g., to the host interface 212 via the host bus 220 … See Parag. [0039]; In block 306, the method includes writing, to a cache of a memory controller, the encrypted key for the non-volatile memory device. In the example implementation, the processor 206 may write the generated encrypted key 228 to the cache 214, e.g., to access data stored on non-volatile memory devices 210 responsive to memory access requests from the host computing device 204. In an example, any data accessed, whether read or written, to a particular non-volatile memory device may use the generated encrypted key. See Parag. [0038]).
Claim 5. Hulton discloses the memory system of claim 1,
Hulton further discloses wherein the address payload comprises an address, for a volatile memory of the host system, at which the host system is to store the set of data (See Parag. [0037]; block 302 may include receiving, from a host computing device, a command and an address for one or more memory devices. In an example of memory access request including a write command, the host computing device 204 of FIG. 2 may provide a memory access request, including a memory address and data to be written, to the memory controller 202, e.g., to the host interface 212 via the host bus 220. See Parag. [0035]; the non-volatile memory devices 210 may operate as persistent storage for the cache 214, which may be a volatile memory device and/or operate as persistent storage for any volatile memory on the memory controller 202 or the host computing device 204).
Claim 6. Hulton discloses the memory system of claim 5,
Hulton further discloses wherein the command is a command to read the set of data, and wherein communication of the set of data comprises the set of data being transmitted to the host system (See Parag. [0037]; … received memory access request including a read command, the memory system 200, advantageously, the memory controller 202 facilitates the retrieval of encrypted keys to read data on the non-volatile memory devices 210. Accordingly, the processor 206 may receive the memory access request for generation or retrieval of an encrypted key for data access associated with the memory address request).
Claim 7. Hulton discloses the memory system of claim 5,
Hulton further discloses wherein the one or more controllers is further configured to cause the memory system to: receive a logical address associated with the encrypted set of data; and read the encrypted set of data from a set of memory cells, of the one or more non-volatile memory devices, mapped to the logical address (See Parag. [0037]; Block 302 includes receiving, from a host computing device, a memory access request for a memory device. The memory access request may be or include a command and a memory address. Accordingly, block 302 may include receiving, from a host computing device, a command and an address for one or more memory devices … as described with respect to memory system 200, in the example of an received memory access request including a read command, the memory system 200, advantageously, the memory controller 202 facilitates the retrieval of encrypted keys to read data on the non-volatile memory devices 210. Accordingly, the processor 206 may receive the memory access request for generation or retrieval of an encrypted key for data access associated with the memory address request).
Claim 10. Hulton discloses a host system, comprising: one or more volatile memory devices; and one or more controllers coupled with the one or more volatile memory devices and configured to cause the host system (See Parag. [0036]; … executable instructions may be stored on one of the non-volatile memory devices 210 and retrieved by a memory controller 202 for the processor 206 to execute the executable instructions for performing the method 300 …) to:
transmit, to a memory system, a command for a set of data, and an address payload comprising an indication of a register, of the host system, that stores cryptography instructions for the set of data (See Parag. [0037]; Block 302 includes receiving, from a host computing device, a memory access request for a memory device. The memory access request may be or include a command and a memory address. Accordingly, block 302 may include receiving, from a host computing device, a command and an address for one or more memory devices);
receive, at a cryptography engine of the host system, an indication of the command for the set of data, and the address payload comprising the indication of the register that stores the cryptography instructions (See Parag. [0037]; In an example of memory access request including a write command, the host computing device 204 of FIG. 2 may provide a memory access request, including a memory address and data to be written, to the memory controller 202, e.g., to the host interface 212 via the host bus 220. For example, as described with respect to memory system 200, in the example of an received memory access request including a read command, the memory system 200, advantageously, the memory controller 202 facilitates the retrieval 8 to read data on the non-volatile memory devices 210. Accordingly, the processor 206 may receive the memory access request for generation or retrieval of an encrypted key for data access associated with the memory address request); and
perform a cryptography operation on the set of data according to the cryptography instructions based at least in part on receiving the indication of the command and the address payload comprising the indication of the register that stores the cryptography instructions (See Parag. [0038]; responsive to the memory access request, encrypting, at encryption logic, a key for data associated with the memory access request. For example, encryption logic 208 may identify a memory address in the received memory access request that corresponds to a memory address of a non-volatile memory device. Once identified, the encryption logic 208 may generate an encrypted key for data associated with that memory access request. In the example of the write operation, the encrypted key may be generated to secure the data written to the memory address at a non-volatile memory device. To encrypt the key, the encryption logic 208 uses an pseudorandom value as an IV for an authenticated stream cipher (e.g., an AES-GCM pipeline) and a provisioned key, like a DEK. The encryption logic 208 encrypts the provisioned key based at least on the pseudorandom value to associate the encrypted key with the memory access request and/or the memory address of the memory address request. Accordingly, in the context of a write operation in a received memory access request, an encrypted key may be used to encrypt the data to be written as plaintext to ciphertext. Advantageously, based on a received memory access request, data read or written by a host computing device to various non-volatile memory devices may be accessed in an authenticated manner, e.g., using the generated encrypted key … See Parag. [0040]; In block 308, the method includes providing, to the non-volatile memory device, the encrypted key for accessing data associated with the memory access request).
Claim 13. The applicant is directed to the rejections to claim 2 set forth above, as it is rejected based on the same rationale.
Claim 14. Hulton discloses the host system of claim 13,
Hulton further discloses wherein the command is a command to write the set of data, and wherein the one or more controllers is further configured to cause the host system to: retrieve the set of data from the volatile memory based at least in part on the address, and wherein performing the cryptography operation comprises: encrypt the set of data retrieved from the volatile memory (See Parag. [0038]; … in the context of a write operation in a received memory access request, an encrypted key may be used to encrypt the data to be written as plaintext to ciphertext. Advantageously, based on a received memory access request, data read or written by a host computing device to various non-volatile memory devices may be accessed in an authenticated manner, e.g., using the generated encrypted key … See Parag. [0040]; In block 308, the method includes providing, to the non-volatile memory device, the encrypted key for accessing data associated with the memory access request. See also Parag. [0037]).
Claim 15. Hulton discloses the host system of claim 14,
Hulton further discloses wherein the one or more controllers is further configured to cause the host system to: transmit a logical address associated with the encrypted set of data; and transmit the encrypted set of data to the memory system based at least in part on transmitting the logical address (See Parag. [0037]; The memory access request may be or include a command and a memory address. Accordingly, block 302 may include receiving, from a host computing device, a command and an address for one or more memory devices. In an example of memory access request including a write command, the host computing device 204 of FIG. 2 may provide a memory access request, including a memory address and data to be written, to the memory controller 202, e.g., to the host interface 212 via the host bus 220. For example, as described with respect to memory system 200, in the example of an received memory access request including a read command, the memory system 200, advantageously, the memory controller 202 facilitates the retrieval of encrypted keys to read data on the non-volatile memory devices 210. Accordingly, the processor 206 may receive the memory access request for generation or retrieval of an encrypted key for data access associated with the memory address request).
Claim 16. The applicant is directed to the rejections to claim 5 set forth above, as it is rejected based on the same rationale.
Claim 17. Hulton discloses the host system of claim 16,
Hulton further discloses wherein the set of data is encrypted and the command is a command to read the encrypted set of data, and wherein performing the cryptography operation comprises: decrypt the encrypted set of data from the memory system (See Parag. [0037]; … received memory access request including a read command, the memory system 200, advantageously, the memory controller 202 facilitates the retrieval of encrypted keys to read data on the non-volatile memory devices 210. Accordingly, the processor 206 may receive the memory access request for generation or retrieval of an encrypted key for data access associated with the memory address request. See Parag. [0030]; ... once the read data is retrieved from the non-volatile memory devices 210, the processor 206 may use the encryption logic 208 and the key 228 to decrypt the read data …).
Claim 18. Hulton discloses the host system of claim 17,
Hulton further discloses wherein the one or more controllers is further configured to cause the host system to: transmit a logical address associated with the encrypted set of data; and receive the encrypted set of data from the memory system based at least in part on transmitting the logical address (See Parag. [0037]; … received memory access request including a read command, the memory system 200, advantageously, the memory controller 202 facilitates the retrieval of encrypted keys to read data on the non-volatile memory devices 210. Accordingly, the processor 206 may receive the memory access request for generation or retrieval of an encrypted key for data access associated with the memory address request).
Claim 19. Hulton discloses a method at a memory system, comprising:
receiving, from a host system, a command for a set of data, and an address payload comprising an indication of a register, of the host system, that stores cryptography instructions for the set of data (See Parag. [0037]; Block 302 includes receiving, from a host computing device, a memory access request for a memory device. The memory access request may be or include a command and a memory address. Accordingly, block 302 may include receiving, from a host computing device, a command and an address for one or more memory devices);
transmitting, to a cryptography engine of the host system, an indication of the command for the set of data, and the address payload comprising the indication of the register that stores the cryptography instructions (See Parag. [0037]; In an example of memory access request including a write command, the host computing device 204 of FIG. 2 may provide a memory access request, including a memory address and data to be written, to the memory controller 202, e.g., to the host interface 212 via the host bus 220. For example, as described with respect to memory system 200, in the example of an received memory access request including a read command, the memory system 200, advantageously, the memory controller 202 facilitates the retrieval 8 to read data on the non-volatile memory devices 210. Accordingly, the processor 206 may receive the memory access request for generation or retrieval of an encrypted key for data access associated with the memory address request); and
communicating, between the memory system and the host system, the set of data based at least in part on transmitting the indication of the command and the address payload comprising the indication of the register that stores the cryptography instructions, wherein the set of data is encrypted according to the cryptography instructions (See Parag. [0038]; responsive to the memory access request, encrypting, at encryption logic, a key for data associated with the memory access request. For example, encryption logic 208 may identify a memory address in the received memory access request that corresponds to a memory address of a non-volatile memory device. Once identified, the encryption logic 208 may generate an encrypted key for data associated with that memory access request. In the example of the write operation, the encrypted key may be generated to secure the data written to the memory address at a non-volatile memory device. To encrypt the key, the encryption logic 208 uses an pseudorandom value as an IV for an authenticated stream cipher (e.g., an AES-GCM pipeline) and a provisioned key, like a DEK. The encryption logic 208 encrypts the provisioned key based at least on the pseudorandom value to associate the encrypted key with the memory access request and/or the memory address of the memory address request. Accordingly, in the context of a write operation in a received memory access request, an encrypted key may be used to encrypt the data to be written as plaintext to ciphertext. Advantageously, based on a received memory access request, data read or written by a host computing device to various non-volatile memory devices may be accessed in an authenticated manner, e.g., using the generated encrypted key … See Parag. [0040]; In block 308, the method includes providing, to the non-volatile memory device, the encrypted key for accessing data associated with the memory access request).
Claim 20. The applicant is directed to the rejections to claim 2 set forth above, as it is rejected based on the same rationale.
Claim 21. The applicant is directed to the rejections to claim 3 set forth above, as it is rejected based on the same rationale.
Claim 22. The applicant is directed to the rejections to claim 4 set forth above, as it is rejected based on the same rationale.
Claim 23. The applicant is directed to the rejections to claim 5 set forth above, as it is rejected based on the same rationale.
Claim 24. The applicant is directed to the rejections to claim 6 set forth above, as it is rejected based on the same rationale.
Claim 25. The applicant is directed to the rejections to claim 7 set forth above, as it is rejected based on the same rationale.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Hulton et al. (Pub. No. US 2022/0222384), hereinafter Hulton, in view of Chritz et al. (Pub. No. US 2023/0126741), hereinafter Chritz.
Claim 8. Hulton discloses the memory system of claim 1,
Hulton doesn’t explicitly disclose wherein the address payload is encrypted, and wherein the one or more controllers is further configured to cause the memory system to: transmit the address payload to the host system without decrypting the address payload.
However, Chritz discloses wherein the address payload is encrypted (See Parag. [0043]; the obtained memory address at authentication logic 134 may be processed at various stages of authentication logic 134. For example, stage 1 136, stage2 138, and stage n 140 may represent stages of an AES-GCM pipeline in which the memory address is encrypted and generated as an access code for the plaintext 132 to be written to the memory device 148), and wherein the one or more controllers is further configured to cause the memory system to: transmit the address payload to the host system without decrypting the address payload (See Parag. [0014]; The encrypted access code may be used to provide authenticated access between the memory controller and data associated with the memory access request. Accordingly, data read or written by a host computing device to various memory devices may be accessed in an authenticated manner, e.g., using the generated access code that is encrypted by a stream cipher based on the memory address associated with that data).
It would have been obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the teaching, taught by Hulton, to include wherein the address payload is encrypted, and wherein the one or more controllers is further configured to cause the memory system to: transmit the address payload to the host system without decrypting the address payload, as taught by Chritz. This would be convenient because the generated access code may provide security for the data read or written by the computing device to that specific memory address of one of the memory devices (Chritz, Parag. [0014]).
Claims 9 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Hulton et al. (Pub. No. US 2022/0222384), hereinafter Hulton, in view of Song et al. (Pub. No. US 2022/0398042), hereinafter Song.
Claim 9. Hulton discloses the memory system of claim 1,
Hulton doesn’t explicitly disclose wherein the address payload comprises a set of bits for routing the address payload between the host system and the memory system.
However, Song discloses wherein the address payload comprises a set of bits for routing the address payload between the host system and the memory system (See Parag. [0014]; device may use dirty bits that indicate whether an address (e.g., a column address, a row address) has been accessed (e.g., written to, read from). Dirty bits may be a subset of tag bits, which may refer to bits that provide status information for a memory … See Parag. [0133]; receive a command for an address of a memory array, read, from the memory array based at least in part on the command, a first set of tag bits indicating access information for a set of addresses that includes the address, determine a second set of tag bits based at least in part on the command and the address, the second set of tag bits indicating updated access information for the address).
It would have been obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the teaching, taught by Hulton, to include wherein the address payload comprises a set of bits for routing the address payload between the host system and the memory system, as taught by Song. This would be convenient to efficiently manage access information (Song, Parag. [0071]).
Claim 11. The applicant is directed to the rejections to claim 9 set forth above, as it is rejected based on the same rationale.
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Hulton et al. (Pub. No. US 2022/0222384), hereinafter Hulton, in view of Liang et al. (Pub. No. US 2022/0113970), hereinafter Liang.
Claim 12. Hulton discloses the host system of claim 10,
Hulton doesn’t explicitly disclose wherein the address payload is encrypted, and wherein the one or more controllers is further configured to cause the host system to: decrypt the address payload before performing the cryptography operation on the set of data and based at least in part on second cryptography instructions associated with address payloads.
However, Liang discloses wherein the address payload is encrypted, and wherein the one or more controllers is further configured to cause the host system to: decrypt the address payload before performing the cryptography operation on the set of data and based at least in part on second cryptography instructions associated with address payloads (See Parag. [0035-0036]; mapping information of the storage device can optionally be provided to a host. In some examples, the mapping information can allow the host to, at least initially, determine where data is stored on the memory of the storage device. In certain examples, portions of the mapping information, such as the physical addresses of the memory of the storage device, can be encrypted to prevent malicious information from being stored on the storage device. At 203, a read command can be received at the storage device. The read command can include read information. In certain examples, the read information can include a LBA of the host. In some examples, the read information can include a PA of the memory of the storage device … either a LBA or a PA within the read information can be used to determine the location of the read data within the memory of the storage device. In some examples, a L2P table may be used to identify the physical address of the memory location of the data on the storage device. In some examples, an encrypted PA (i.e., address) may be decrypted to identify the location of the read data within the memory of the storage device. See claim 3; the first address, and the set of additional addresses are encrypted, and wherein the method further comprises decrypting the first address and the set of additional addresses).
It would have been obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the teaching, taught by Hulton, to include wherein the address payload is encrypted, and wherein the one or more controllers is further configured to cause the host system to: decrypt the address payload before performing the cryptography operation on the set of data and based at least in part on second cryptography instructions associated with address payloads, as taught by Liang. This would be convenient to prevent malicious information from being stored on the storage device (Song, Parag. [0035]).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure (see PTO-form 892).
Szubbocsev et al. (Pub. No. US 2020/0004694) - related to systems and methods for managing a memory system. The memory system may generate a first encrypted physical address using a first clear physical address. The memory system may generate a first encrypted logical-to-physical (L2P) pointer indicating the first logical address and a first encrypted physical address. The memory system may send the first encrypted L2P pointer to a host device for storage at a host memory (see Abstract).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to GHIZLANE MAAZOUZ whose telephone number is (571)272-8118. The examiner can normally be reached Telework M-F 7:30-5 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip J Chea can be reached on 571-272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/GHIZLANE MAAZOUZ/Examiner, Art Unit 2499
/PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499