DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claims 1, 2, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PG Pub No.20210311643-A1) in view of Trikalinou et al. (US PGPub No. 20220100911-A1) and Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)).
With respect to claim 1, Shanbhogue teaches a compute express link (CXL) device, comprising: an integrity and data encryption (IDE) component configured with an encryption engine for encrypting protocol data against an interposer security threat or a malicious extension security threat, wherein the IDE component is associated with: a CXL IDE included in a CXL controller, and a peripheral component interconnect (PCI) express (PCIe) IDE included in the CXL controller; (¶0038: Figure 1 illustrates an example of a system 100 according to some embodiments. A CXL type 2 and 3 memory device 122 that includes an MEE 130 provide MEE configuration interface 126 to configure and control the MEE. To protect the transactions from being eavesdropped or tampered with on the I/O bus such as CXL.io, TSM 116 first enables encryption of the transactions on the I/O bus (e.g., PCIe link 118) using protocols such as the PCI-SIG defined Integrity and Data Encryption (IDE). The IDE scheme may be applied to all transactions on the bus or may be applied selectively to some transactions on the bus such as those targeting the registers forming the MEE configuration interface );
a central controller that includes an advanced encryption standard (AES) Xor- encrypt-xor-based tweaked-codebook mode with ciphertext stealing (AES-XTS) component; (¶0006: MEE 130 provides memory confidentiality and integrity properties to data stored in memory device 122. Memory encryption involves using a cryptographic cipher to enforce confidentiality of the data stored in the memory devices. Devices that support memory encryption capability may support MEE 130. One example of a memory encryption scheme that provides this property is advanced encryption standard (AES-XTS) using the physical address where the data is stored as the tweak value as described in (Standard for Cryptographic Protection of Data on Block-Oriented Memory Devices, May 2007 (IEEE P1619/D16). );
a secure execution environment that includes one or more encryption components and one or more central processing units (CPUs), (¶0006: Figure 2A illustrates an example of interactions between a virtual machine manager (VMM), a trusted environment security manager (TSM), a device security manager (DSM), and a memory encryption environment (MEE). Further in ¶0020 TEE security manager (TSM) 116 is a logical security agent in the host computing system 102 that is responsible for establishing the security isolations and access controls to protect the confidentiality and integrity of TEE VMs 104, 106, . . . 108. TSM 116 is inside the trust boundary of all TEE VMs. In one embodiment, in a host computing system 102 including a processor (one or more processing units) supporting Trust Domain Extensions (TDX) provided by Intel Corporation, the TSM functionality is realized by a digitally signed security services module (not shown in Figure 1) (called the Intel TDX-module) that executes in a secure processor mode called the secure arbitration mode (SEAM).);
wherein the secure execution environment interfaces with the CXL IDE, the PCIe IDE, and the AES-XTS component, and (¶0017-0019: VMM 110 (also known as hypervisor) is system software that is used to create, edit, start, and stop virtual machines. The VMM typically holds the administrative interfaces to devices in the host computing system. Such administrative interfaces may be in the form of a PF in a PCIe or CXL device. The VMM includes PF driver 114 that provides an interface to the VMM configuration and control software stack (e.g., device interface configuration 112) to establish device configurations and administer the device capabilities (e.g., for memory device 122)).
Shanbhogue does not disclose:
a central controller that includes an advanced encryption standard (AES) Xor- encrypt-xor-based tweaked-codebook mode with ciphertext stealing (AES-XTS) component;
It is noted Shanbhogue that discloses an AES-XTS component, but Shanbhogue does not explicitly disclose encryption standard (AES) Xor-encrypt-xor based tweaked-codebook mode. However, Trikalinou teaches a central controller that includes an advanced encryption standard (AES) Xor- encrypt-xor-based tweaked-codebook mode with ciphertext stealing (AES-XTS) component; (¶0043: Cryptographic isolation may utilize new ciphers, as well as others, introducing novel computer architecture concepts including, but not limited to: a variety of encryption modes that are tweakable can be used for this purpose of including metadata (e.g., counter mode (CTR) and XOR-encrypt-XOR (XEX)-based tweaked-codebook mode with ciphertext stealing (XTS)));
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Trikalinou with regards to an advanced encryption standard (AES) Xor-encrypt-xor based tweaked-codebook mode to the method of Shanbhogue in order to provide data confidentiality and allow the processor to determine if the data is being properly decrypted using the correct keystream and tweak (Trikalinou ¶0043).
Shanbhogue in view of Trikalinou does not disclose:
wherein the one or more CPUs provide cryptographic functionality for a device identifier composition engine (DICE) architecture; and
a CPU, exterior to the secure execution environment, that provides device key attestation and key exchange in accordance with a security protocol and data model (SPDM) framework,
wherein the CXL device is configured to implement an attestation protocol, via the SPDM framework, with a cryptographic identity using the DICE architecture.
However, Yao teaches wherein the one or more CPUs provide cryptographic functionality for a device identifier composition engine (DICE) architecture; and (Chapter 7: Trusted Boot, Device Identifier Composition, Pages 207-209 discloses: “Even the tiniest microcontrollers can afford support to establish the device identity and perform attestation and secure firmware update Figure 7-8 shows the fundamental idea the DICE. The immutable ROM-DICE hardware engine combines a unique device secret (UDS) and the hash of the startup code to create a hash-based message authentication code (HMAC). This HMAC is used as the Compound Device Identity (CDI) of the device...The DICE core implementation can be easily extended to a multilayered boot. Each layer creates a new alias key and an alias certificate for the next layer. The alias certificates issued to the next the layer are signed with the alias key granted to the current layer” as illustrated in Figure 7-11 DICE Key Protection);
a CPU, exterior to the secure execution environment, (Chapter 8: Device Security, EDK 11 Device Security, Page 266: “CPU may communicate with device to do the authentication and measurement via SPDM messages over PCIe or USB. ); that provides device key attestation and key exchange in accordance with a security protocol and data model (SPDM) framework, (Chapter 8: Device Security, Security Protocol and Data Model (SPDM), Page 261-262: “As such, the SPDM 1.1 specification adds a special command for a secure communication channel platform... See Table 8-2. In the handshake phase, the two entities may use certificate-based asymmetric key session creation or pre-shared key (PSK)-based session creation. ” );
wherein the CXL device is configured to implement an attestation protocol, via the SPDM framework, (Chapter 8: Device Security, PCI Express Integrity and Data Encryption, Pages 263: “Selective IDE Stream means the IDE TLPs flow through switches without affecting their security, while Link IDE Streams mean that two ports must be connected without intervening switches. The SPDM secure session messages are used to establish IDE stream and programming keys. Other hardware interfaces, such as Computer Express Link (CXL), are also adopting SPDM messages… ” ) with a cryptographic identity using the DICE architecture. (Chapter 8: Device Security, Device Identifier Composition Engine, Pages 260-266: “Here the Active Component RoT (AC-RoT) could be a DICE device. Each DICE device includes a unique device secret (UDS). This DICE certificate can be used as the identity of the device. Figure 7-9 in Chapter 7 shows the DICE certification generation… ” As specifically seen in SPDM over Management Component Transport Protocol (MCTP) Page 264: “SPDM messages can also be transported over MTCP...SPDM messages can be transported over MTCP. As such, MCTP devices can exchange SPDM messages. As we discussed in Chapter 7, the Cerberus project uses this mechanism to let the Platform Active Root-of-Trust (PA-RoT) authenticate the device Active Component Root-of-Trust (AC-RoT).” )
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Yao with regards to the implementation of a device identifier composition engine (DICE) architecture and SPDM framework to the method of Shanbhogue in view of Trikalinou in order to enhance security and privacy with minimal silicon requirements and enable device authentication over a secure communication channel (Yao: Chapter 7: Trusted Boot, Device Identifier Composition Engine (DICE), Page 207 & Chapter 8: Device Security, Security Protocol and Data Model (SPDM), Page 261 ).
With respect to claim 2, the combination of Shanbhogue in view of Trikalinou and Yao teaches the CXL device of claim 1 (see rejection of claim 1 above), further comprising: an attestation component, that implements one or more of the SPDM framework or the DICE architecture, configured to provide a secure handshake verification of an identity of the CXL device. (Yao Chapter 8: Device Security, Security Protocol and Data Model (SPDM), Pages 261-262: “As such, the SPDM 1.1 specification adds a special command for a secure communication channel on the platform… See Table 8-2. In the handshake phase, the two entities may use certificate based asymmetric key session creation or pre-shared key (PSK)-based session creation...” As seen in Table 8-2: SPDM 1.1 Command List for Secure Communication Channel shows a Session Handshakes intended to authenticate the responder (providing a secure handshake verification of an identity of the CXL device). And as further seen in Chapter 8: Device Security, Device Identifier Composition Engine (DICE), Page 260: “Here the Active Component Rot (AC-RoT) could be a DICE device. Each DICE device includes a unique device (UDS), and the DICE core generates the DICE certificate based upon the UDS. This DICE certificate can be used as the identity of the device (identity of the CXL device)…” )
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Yao with regards to the implementation of a device identifier composition engine (DICE) architecture and SPDM framework to the method of Shanbhogue in view of Trikalinou in order to enhance security and privacy with minimal silicon requirements and enable device authentication over a secure communication channel (Yao: Chapter 7: Trusted Boot, Device Identifier Composition Engine (DICE), Page 207 & Chapter 8: Device Security, Security Protocol and Data Model (SPDM), Page 261 ).
With respect to claim 18, the combination of Shanbhogue in view of Yao teaches the CXL device of claim 17 (see rejection of claim 17 above), further comprising: a CXL controller that includes: a CXL IDE that interfaces with the secure execution environment, and a peripheral component interconnect (PCI) express (PCIe) IDE that interfaces with the secure execution environment; and (¶0017-0019: VMM 110 (also known as hypervisor) is system software that is used to create, edit, start, and stop virtual machines. The VMM typically holds the administrative interfaces to devices in the host computing system. Such administrative interfaces may be in the form of a PF in a PCIe or CXL device. The VMM includes PF driver 114 that provides an interface to the VMM configuration and control software stack (e.g., device interface configuration 112) to establish device configurations and administer the device capabilities (e.g., for memory device 122)).
Shanbhogue in view of Yao does not disclose:
a controller that includes an advanced encryption standard (AES) Xor-encrypt- xor-based tweaked-codebook mode with ciphertext stealing (AES-XTS) component that interfaces with the secure execution environment.
It is noted Shanbhogue that discloses an AES-XTS component, as seen in ¶0026, but Shanbhogue does not explicitly disclose encryption standard (AES) Xor-encrypt-xor based tweaked-codebook mode. However, Trikalinou teaches a central controller that includes an advanced encryption standard (AES) Xor- encrypt-xor-based tweaked-codebook mode with ciphertext stealing (AES-XTS) component; (¶0043: Cryptographic isolation may utilize new ciphers, as well as others, introducing novel computer architecture concepts including, but not limited to: a variety of encryption modes that are tweakable can be used for this purpose of including metadata (e.g., counter mode (CTR) and XOR-encrypt-XOR (XEX)-based tweaked-codebook mode with ciphertext stealing (XTS)));
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Trikalinou with regards to an advanced encryption standard (AES) Xor-encrypt-xor based tweaked-codebook mode to the method of Shanbhogue in view of Yao in order to provide data confidentiality and allow the processor to determine if the data is being properly decrypted using the correct keystream and tweak (Trikalinou ¶0043).
Claims 3 and 4 are rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Trikalinou et al. (US PGPub No. 20220100911-A1), Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)), and Gulati et al. (US PGPub No. 20190356529-A1).
With respect to claim 3, the combination of Shanbhogue in view of Trikalinou and Yao teaches the CXL device of claim 1 (see rejection of claim 1 above), but does not disclose further comprising: a secure boot and secure field firmware update component to enforce a chain of trust rooted in hardware of the CXL device against a malicious change or execution of code on the CXL device.
However, Gulati teaches comprising: a secure boot and secure field firmware update component (¶0193: For example, the OEM development premise 940 can include OEM certificate key material 904, an OEM security boot loader 906, the OEM firmware development system 908, an OEM mastering tool 910, a Firmware update service 912, and an OEM management 924 .) to enforce a chain of trust rooted in hardware of the CXL device against a malicious change or execution of code on the CXL device. (¶0501-0511: Referring to Figure 19, illustrates an example of gathering credentials 1902. The gathering credential stage 1902 can show a process for gathering and defining data structure for the secure programming system 100. The optional step of 1930, the OEM chain-of-trust certificate can be created at the trust certificate 1948 back to the root certificate. The chain-of-trust is the verifiable linkage between a secure object having an end-entity certificate and a root certificate from a trusted certificate authority. Each link in the change can be individually validated. The combination of linkages can show an unbroken chain of trust reaching all the way back to the root certificate from the trusted certificate authority. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Gulati with regards to the enforcement of a chain of trust of rooted in hardware to the method of Shanbhogue in view of Trikalinou and Yao in order to enhance security by preventing unauthorized manufacture and reducing a probability of counterfeit products (Gulati ¶0135 & ¶00567).
With respect to claim 4, the combination of Shanbhogue in view of Trikalinou, Yao, and Gulati teaches the CXL device of claim 3 (see rejection of claim 3 above), wherein the secure boot and secure field firmware update component is configured to encrypt a firmware image stored on or transmitted to the CXL device. (Gulati ¶0450: The Provisioning FW Protection use case 1422. In this use case the wrapped OEM content 1426 can include encrypted firmware images 914 and a firmware decryption key 1674. The OEM content 1424 can then be unwrapped and imported into the security controller 114, such as hardware security module. The provisioning algorithm 1468 running on the programmer 112 receives (stored or transmitted) the encrypted firmware images 914 and the firmware encryption key from the security controller 114 and provisions the device by programming the encrypted firmware images 1914 and the encryption key 1622 at write once read protected storage on the device. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Gulati with regards to the encryption of firmware image to the method of Shanbhogue in view of Trikalinou and Yao in order to enhance security by preventing unauthorized manufacture and reducing a probability of counterfeit products (Gulati ¶0135 & ¶00567).
Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Trikalinou et al. (US PGPub No. 20220100911-A1), Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)), and Letey et al. (US PGPub No. 20180341584-A1).
With respect to claim 5, the combination of Shanbhogue in view of Trikalinou and Yao teaches the CXL device of claim 1 (see rejection of claim 1 above), but does not disclose further comprising: a memory access restriction component configured to restrict access to an area of memory that stores security data for verified or secured processes against a data exfiltration security threat.
However, Letey teaches further comprising: a memory access restriction component configured to restrict access to an area of memory that stores security data for verified or secured processes against a data exfiltration security threat. (¶0075: In some examples, hardware is used to prevent access to the restricted memory bank, so that it is not possible to for software to overwrite the access protection in such as a way as to allow access );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Gulati with regards to the memory access restriction to the method of Shanbhogue in view of Trikalinou and Yao in order to prevent a rollback attack from being access secure portion of the memory and prevent unauthorized access (Letey ¶0005).
Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Trikalinou et al. (US PGPub No. 20220100911-A1), Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)), and Pitta et al. (US Pat No. 10498606-B1).
With respect to claim 6, the combination of Shanbhogue in view of Trikalinou and Yao teaches the CXL device of claim 1 (see rejection of claim 1 above), but does not does not disclose further comprising: an interface control component configured to: receive a secure command to disable a set of interfaces of the CXL device; and disable the set of interfaces of the CXL device as a response to receiving the secure command.
However, Pitta teaches further comprising: an interface control component configured to: receive a secure command to disable a set of interfaces of the CXL device; and disable the set of interfaces of the CXL device as a response to receiving the secure command. (¶0018: The system (e.g., the network device entering maintenance mode) is configured to transmit the first LLDP message ( ¶0021: The neighboring devices may use the LLDP message to trigger a protocol command to enable, disable, or adjust routing parameters (receiving a secure command) for protocol interfaces having an association with the isolating system ) upon entry into maintenance mode and, in some embodiments to wait finalize isolation sequence (i.e., to disable its network interfaces) until all acknowledgement messages are received from network device to which the first LLDP message is sent. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Pitta with regards to a secure command to disable set of interfaces to the method of Shanbhogue in view of Trikalinou and Yao in order to prevent intrusions and disruptions (Pitta ¶0002 & ¶0035).
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Trikalinou et al. (US PGPub No. 20220100911-A1), Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)), and Sweet et al. (US PGPub No. 20180309747-A1).
With respect to claim 7, the combination of Shanbhogue in view of Trikalinou and Yao teaches the CXL device of claim 1 (see rejection of claim 1 above), but does not disclose further comprising: a security set-up component configured to perform a security self-check and set up a set of security features of the CXL device against a device lifecycle type of security threat.
However, Sweet teaches further comprising: a security set-up component configured to perform a security self-check and (¶0176: As seen in Figure 4A, Block 409. Block 409 begins process of self-verification. In block 409, the agent executive 48 collections information for self-evaluation for integrity of the agent executive 48 as dictated by the agent self-verification factors 68. ) set up a set of security features of the CXL device against a device lifecycle type of security threat. (¶0187-0188: Figure 5 illustrates a method by which command sets 58 that check the security, compliance, and integrity of various data structures, processes, file systems, or states associated with a container 74 can be created using the grid computer system 2000 and communicated in a secure manner to a server computer 100. Block 502. In block 502 command sets 58 and corresponding rule sets 59 for processing command sets 58 are set up.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Sweet with regards to performing a security self-check and set up a set of security features to the method of Shanbhogue in view of Trikalinou and Yao in order to prevent vulnerabilities and to improve security (Sweet ¶0004-0008).
Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Trikalinou et al. (US PGPub No. 20220100911-A1), Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)), Sweet et al. (US PGPub No. 20180309747-A1), and Kurkowski et al. (US PGPub No. 20140281484-A1).
With respect to claim 8, the combination of Shanbhogue in view of Trikalinou, Yao, and Sweet teaches the CXL device of claim 7 (see rejection of claim 7 above), but does not disclose wherein the security set-up component is configured to reject a command that is not authenticated.
However, Kurkowski teaches wherein the security set-up component is configured to reject a command that is not authenticated. (¶0049: In one embodiment, protocol interface 404 receives data comprising a command and a MAC sent by a host. Both are loaded into SAHA 406 and hash operation is performed on the command using a secret embedded in SAHA 406. The hash data resulting from the operation is compared to the MAC. If the hash data and the MAC match, state logic 408 determines that the command is authentic and forwards the authenticated command to signal converter 410 to commence a signal conversion. Conversely, if protocol interface 404 fails to receive the correct MAC, such that the comparison fails to produce an appropriate match, state logic 408 determines that the data is invalid and rejects the command. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Kukowski with regards to rejecting a command that is not authenticated to the method of Shanbhogue in view of Trikalinou, Yao, and Sweet in order to prevent attacks by unsecure data while ensuring data integrity and trust (Kurkowski ¶0004-0006).
Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Trikalinou et al. (US PGPub No. 20220100911-A1), Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)), and Chen et al. (US Pat No. 8245192-B11).
With respect to claim 9, the combination of Shanbhogue in view of Trikalinou and Yao teaches the CXL device of claim 1 (see rejection of claim 1 above), but does not disclose comprising: a mode control component configured to switch the CXL device from a first mode associated with development code to a second mode associated with production code and to erase production code when transitioning to the first mode.
However, Chen teaches comprising: a mode control component configured to switch the CXL device from a first mode associated with development code (¶0042: At block 302, the virtual server management component 122 creates a first development zone 144 (first mode) on the staging server 140 upon receiving a request from the first client device 150. At ) to a second mode associated with production code (¶0042: At block 310, the master production build 132 and staging build 142 are again locked (second mode)) and to erase production code when transitioning to the first mode. (¶0032: The independent development zones application 120 creates a date stamp and timestamp record of all of the files and folders in the master production build 132 and stands ready to make notations of any files that are changed or deleted as well as mark new files and folders that are added by the client device 150 while the first development zone 144 is in effect (erasing production code when transition to first mode further corroborated in ¶0010 a development zone is created when a developer requests a current virtual copy of the master production build to write new software code to be added to the master production build and change and delete previously existing software code in the master production build. ). );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Chen with regards to the modes to the method of Shanbhogue in view of Trikalinou and Yao in order to better resolve conflicts and increase reliability (Chen ¶0008).
Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Trikalinou et al. (US PGPub No. 20220100911-A1), Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)), and Walmsley et al. (US PGPub No. 20040221287-A1).
With respect to claim 10, the combination of Shanbhogue in view of Trikalinou and Yao teaches the CXL device of claim 1 (see rejection of claim 1 above), but does not disclose wherein a signal trace component, for one or more signals conveying security data, is disposed in a metal layer below at least one other layer of the CXL device.
However, Walmsley teaches wherein a signal trace component, for one or more signals conveying security data, is disposed of a metal layer below at least one other layer of the CXL device. (¶6301: Wherever possible, the connections along which the key or secret data flows, should be made in the polysilicon layers. Where necessary, they can be in metal 1, but must never be in the top metal layer (containing the Tamper Detection Lines). ). );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Walmsley with regards to for one or more signals conveying security data, is disposed in metal layer to the method of Shanbhogue in view of Trikalinou and Yao in order to thwart SEPM attacks (Walmsley ¶6338).
Claims 11 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Trikalinou et al. (US PGPub No. 20220100911-A1), Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)), and Kono et al. (US PGPub No. 20190054939-A1).
With respect to claim 11, the combination of Shanbhogue in view of Trikalinou and Yao teaches the CXL device of claim 1 (see rejection of claim 1 above), but does not disclose further comprising: a voltage or electromagnetic interference detection component configured to detect an anomaly on a power supply or a device logic and trigger a configured counter measure.
However, Kono teaches further comprising: a voltage or electromagnetic interference detection component configured to detect an anomaly on a power supply or a device logic and trigger a configured counter measure. (¶0164: Figure 14 is an illustrative diagram showing an example of an order in which the anomaly determination unit 291 determines whether or not there is an anomaly. When the anomaly determination unit 291 determines that there is an anomaly in voltage (step S11: YES), the anomaly determination unit 291 performs a process at the time of failure of the power supply (step S12). For example, the anomaly determination unit 291 causes the display unit 230 to display a message indicating that the anomaly occurrence place is estimated to be the power supply and that there is a possibility of failure of the power supply. The message herein corresponds to the alarm described above.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Kono with regards to the detection an anomaly on a power supply and triggering a configured counter measure to the method of Shanbhogue in view of Trikalinou and Yao in order to ensure safety of the device (Kono ¶0003).
With respect to claim 12, the combination of Shanbhogue in view of Trikalinou and Yao teaches the CXL device of claim 12 (see rejection of claim 12 above), wherein the configured counter measure includes at least one of: aborting a compromised secure boot, disabling a feature of the CXL device, or outputting an alert. (Kono ¶0164: Figure 14 is an illustrative diagram showing an example of an order in which the anomaly determination unit 291 determines whether or not there is an anomaly. When the anomaly determination unit 291 determines that there is an anomaly in voltage (step S11: YES), the anomaly determination unit 291 performs a process at the time of failure of the power supply (step S12). For example, the anomaly determination unit 291 causes the display unit 230 to display a message indicating that the anomaly occurrence place is estimated to be the power supply and that there is a possibility of failure of the power supply (outputting an alert) . The message herein corresponds to the alarm described above.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Kono with regards to the detection an anomaly on a power supply and triggering a configured counter measure of outputting an alert to the method of Shanbhogue in view of Trikalinou and Yao in order to ensure safety of the device (Kono ¶0003).
Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Ayoub et al. (US PGPub No. 20220400123-A1) and Trikalinou et al. (US PGPub No. 20220100911-A1).
With respect to claim 13, Shanbhogue teaches a system, comprising: a set of servers configured to establish a set of virtual machines to provide a computing environment; (¶0016-0019: Figure 1 illustrates an example of a system 100 according to some embodiments. One or more trusted execution environment (TEE) virtual machines (TEE VMs) are used for confidential computing. The example system of FIG. 1 shows TEE VM1 104, TEE VM2 106, . . . TEE VMN 108, where N is a natural number.);
a set of compute express link (CXL) interface components configured to communicate with the set of servers via a set of CXL interconnects; a secure execution environment that includes one or more encryption components and one or more processing components; one or more other processing components not included in the secure execution environment; a CXL controller that includes: a CXL IDE that interfaces with the secure execution environment, and a peripheral component interconnect (PCI) express (PCIe) IDE that interfaces with the secure execution environment; and a (¶0038: Figure 1 illustrates an example of a system 100 according to some embodiments. A CXL type 2 and 3 memory device 122 that includes an MEE 130 provide MEE configuration interface 126 to configure and control the MEE. To protect the transactions from being eavesdropped or tampered with on the I/O bus such as CXL.io, TSM 116 first enables encryption of the transactions on the I/O bus (e.g., PCIe link 118) using protocols such as the PCI-SIG defined Integrity and Data Encryption (IDE). The IDE scheme may be applied to all transactions on the bus or may be applied selectively to some transactions on the bus such as those targeting the registers forming the MEE configuration interface );
wherein the controller or the CXL controller, in combination with one or more other components of the system, is configured to: encrypt protocol data against a security threat associated with the set of CXL interconnects or a malicious extension security threat, provide a secure handshake verification of an identity of the set of CXL interface components, enforce a chain of trust rooted in hardware of the set of CXL interface components; restrict access to an area of memory of the set of CXL interface components that stores security data for verified or secured processes; or perform a security check and set up a set of security features of the set of CXL interface components. (¶0013-0014: As contemplated in the present disclosure, a memory encryption engine (MEE) is provided to support memory encryption for CXL devices. A memory mapped input/output (MMIO)-based configuration and capability enumeration interface is defined to support accessing the MEE by other devices in a computing system );
Shanbhogue does not disclose:
a set of servers configured to establish a set of virtual machines to provide a computing environment;
It is noted that Shanbhogue does disclose a set of virtual machines, but Shanbhogue does not disclose a set of servers. However, Ayoub teaches a set of servers configured to establish a set of virtual machines to provide a computing environment; (¶0026: In at least one embodiment, server 912 may be composed of one or more general purpose computers, specialized server computers (including, by way of example, PC (personal computer) servers, UNIX® servers, mid-range servers, mainframe computers, rack-mounted servers, etc.), server farms, server clusters, or any other appropriate arrangement and/or combination. In at least one embodiment, server 912 can include one or more virtual machines running virtual operating systems, or other computing architectures involving virtualization.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Ayoub with regards to a set of servers to the method of Shanbhogue in order to prevent unauthorized or dangerous transmission or reception of data (Ayoub ¶0058 ).
Shanbhogue in view of Ayoub does not disclose:
controller that includes an advanced encryption standard (AES) Xor-encrypt- xor-based tweaked-codebook mode with ciphertext stealing (AES-XTS) component that interfaces with the secure execution environment,
It is noted Shanbhogue that discloses an AES-XTS component ¶0026 , but Shanbhogue does not explicitly disclose encryption standard (AES) Xor-encrypt-xor based tweaked-codebook mode. However, Trikalinou teaches controller that includes an advanced encryption standard (AES) Xor-encrypt- xor-based tweaked-codebook mode with ciphertext stealing (AES-XTS) component that interfaces with the secure execution environment, (¶0043: Cryptographic isolation may utilize new ciphers, as well as others, introducing novel computer architecture concepts including, but not limited to: a variety of encryption modes that are tweakable can be used for this purpose of including metadata (e.g., counter mode (CTR) and XOR-encrypt-XOR (XEX)-based tweaked-codebook mode with ciphertext stealing (XTS)));
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Trikalinou with regards to an advanced encryption standard (AES) Xor-encrypt-xor based tweaked-codebook mode to the method of Shanbhogue in view of Ayoub in order to provide data confidentiality and allow the processor to determine if the data is being properly decrypted using the correct keystream and tweak (Trikalinou ¶0043).
Claims 14 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Ayoub et al. (US PGPub No. 20220400123-A1), Trikalinou et al. (US PGPub No. 20220100911-A1), and Kono et al. (US PGPub No. 20190054939-A1).
With respect to claim 14, the combination of Shanbhogue in view of Ayoub and Trikalinou teaches the system of claim 13 (see rejection of claim 13 above), but does not disclose further comprising: a voltage or electromagnetic interference detection component, wherein the controller is configured to: detect an anomaly on a power supply or a device logic using the voltage or electromagnetic interference detection component; and trigger a configured counter measure.
However, Kono teaches further comprising: a voltage or electromagnetic interference detection component configured to detect an anomaly on a power supply or a device logic and trigger a configured counter measure. (¶0164: Figure 14 is an illustrative diagram showing an example of an order in which the anomaly determination unit 291 determines whether or not there is an anomaly. When the anomaly determination unit 291 determines that there is an anomaly in voltage (step S11: YES), the anomaly determination unit 291 performs a process at the time of failure of the power supply (step S12). For example, the anomaly determination unit 291 causes the display unit 230 to display a message indicating that the anomaly occurrence place is estimated to be the power supply and that there is a possibility of failure of the power supply. The message herein corresponds to the alarm described above.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Kono with regards to the detection an anomaly on a power supply and triggering a configured counter measure to the method of Shanbhogue in view of Ayoub and Trikalinou in order to ensure safety of the device (Kono ¶0003).
With respect to claim 15, the combination of Shanbhogue in view of Ayoub, Trikalinou, and Kono teaches the system of claim 14 (see rejection of claim 14 above), wherein the configured counter measure includes at least one of: aborting a compromised secure boot, disabling a feature of a CXL device associated with at least one of the set of CXL interface components, or outputting an alert. (Kono ¶0164: Figure 14 is an illustrative diagram showing an example of an order in which the anomaly determination unit 291 determines whether or not there is an anomaly. When the anomaly determination unit 291 determines that there is an anomaly in voltage (step S11: YES), the anomaly determination unit 291 performs a process at the time of failure of the power supply (step S12). For example, the anomaly determination unit 291 causes the display unit 230 to display a message indicating that the anomaly occurrence place is estimated to be the power supply and that there is a possibility of failure of the power supply (outputting an alert) . The message herein corresponds to the alarm described above.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilizes the teachings of Kono with regards to the detection an anomaly on a power supply and triggering a configured counter measure of outputting an alert to the method of Shanbhogue in view of Ayoub and Trikalinou in order to ensure safety of the device (Kono ¶0003).
Claims 16 is rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Ayoub et al. (US PGPub No. 20220400123-A1), Trikalinou et al. (US PGPub No. 20220100911-A1), and Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)).
With respect to claim 16, the combination of Shanbhogue in view of Ayoub and Trikalinou teaches the system of claim 13 (see rejection of claim 13 above), but does not disclose wherein, to provide the secure handshake verification of the identity of the set of CXL interface components, the controller or the CXL controller, in combination with one or more other components of the system, is configured to: implement an attestation protocol, via a security protocol and data model (SPDM) framework, with a cryptographic identity using a device identifier composition engine (DICE) architecture, wherein the SPDM framework is associated with the one or more other processing components and the DICE architecture is associated with the one or more processing components.
However, Yao teaches wherein, to provide the secure handshake verification of the identity of the set of CXL interface components, ( Chapter 8: Device Security, Security Protocol and Data Model (SPDM), Pages 261-262: “As such, the SPDM 1.1 specification adds a special command for a secure communication channel on the platform… See Table 8-2. In the handshake phase, the two entities may use certificate based asymmetric key session creation or pre-shared key (PSK)-based session creation...” As seen in Table 8-2: SPDM 1.1 Command List for Secure Communication Channel shows a Session Handshakes intended to authenticate the responder (providing a secure handshake verification of an identity of the CXL device). And as further seen in Chapter 8: Device Security, Device Identifier Composition Engine (DICE), Page 260: “Here the Active Component Rot (AC-RoT) could be a DICE device. Each DICE device includes a unique device (UDS), and the DICE core generates the DICE certificate based upon the UDS. This DICE certificate can be used as the identity of the device (identity of the CXL device)…” )
the controller or the CXL controller, in combination with one or more other components of the system, is configured to: implement an attestation protocol, via a security protocol and data model (SPDM) framework, (Chapter 8: Device Security, PCI Express Integrity and Data Encryption, Pages 263: “Selective IDE Stream means the IDE TLPs flow through switches without affecting their security, while Link IDE Streams mean that two ports must be connected without intervening switches. The SPDM secure session messages are used to establish IDE stream and programming keys. Other hardware interfaces, such as Computer Express Link (CXL), are also adopting SPDM messages… ” ) with a cryptographic identity using a device identifier composition engine (DICE) architecture, wherein the SPDM framework is associated with the one or more other processing components and the DICE architecture is associated with the one or more processing components. (Chapter 8: Device Security, Device Identifier Composition Engine, Pages 260-266: “Here the Active Component RoT (AC-RoT) could be a DICE device. Each DICE device includes a unique device secret (UDS). This DICE certificate can be used as the identity of the device. Figure 7-9 in Chapter 7 shows the DICE certification generation… ” As specifically seen in SPDM over Management Component Transport Protocol (MCTP) Page 264: “SPDM messages can also be transported over MTCP...SPDM messages can be transported over MTCP. As such, MCTP devices can exchange SPDM messages. As we discussed in Chapter 7, the Cerberus project uses this mechanism to let the Platform Active Root-of-Trust (PA-RoT) authenticate the device Active Component Root-of-Trust (AC-RoT).” )
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Yao with regards to the implementation of a device identifier composition engine (DICE) architecture and SPDM framework to the method of Shanbhogue in view of Ayoub and Trikalinou in order to enhance security and privacy with minimal silicon requirements and enable device authentication over a secure communication channel (Yao: Chapter 7: Trusted Boot, Device Identifier Composition Engine (DICE), Page 207 & Chapter 8: Device Security, Security Protocol and Data Model (SPDM), Page 261 ).
Claims 17, 19, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Shanbhogue et al. (US PGPub No.20210311643-A1) in view of Yao et al. (Building secure firmware. Apress: New York, NY, USA, 197-307. (Year: 2020)).
With respect to claim 17, Shanbhogue teaches a compute express link (CXL) device, comprising: a secure execution environment that includes one or more encryption components and one or more processing components, (¶0038: Figure 1 illustrates an example of a system 100 according to some embodiments. A CXL type 2 and 3 memory device 122 that includes an MEE 130 provide MEE configuration interface 126 to configure and control the MEE. To protect the transactions from being eavesdropped or tampered with on the I/O bus such as CXL.io, TSM 116 first enables encryption of the transactions on the I/O bus (e.g., PCIe link 118) using protocols such as the PCI-SIG defined Integrity and Data Encryption (IDE). The IDE scheme may be applied to all transactions on the bus or may be applied selectively to some transactions on the bus such as those targeting the registers forming the MEE configuration interface );
Shanbhogue but does not disclose:
wherein the one or more processing components provide cryptographic functionality for a device identifier composition engine (DICE) architecture; and one or more other processing components, exterior to the secure execution environment, that provide device key attestation and key exchange in accordance with a security protocol and data model (SPDM) framework, wherein the CXL device is configured to implement an attestation protocol, via the SPDM framework, with a cryptographic identity using the DICE architecture.
However, Yao teaches wherein the one or more processing components provide cryptographic functionality for a device identifier composition engine (DICE) architecture; and (Chapter 7: Trusted Boot, Device Identifier Composition, Pages 207-209 discloses: “Even the tiniest microcontrollers can afford support to establish the device identity and perform attestation and secure firmware update Figure 7-8 shows the fundamental idea the DICE. The immutable ROM-DICE hardware engine combines a unique device secret (UDS) and the hash of the startup code to create a hash-based message authentication code (HMAC). This HMAC is used as the Compound Device Identity (CDI) of the device...The DICE core implementation can be easily extended to a multilayered boot. Each layer creates a new alias key and an alias certificate for the next layer. The alias certificates issued to the next the layer are signed with the alias key granted to the current layer” as illustrated in Figure 7-11 DICE Key Protection);
one or more other processing components, exterior to the secure execution environment, (Chapter 8: Device Security, EDK 11 Device Security, Page 266: “CPU may communicate with device to do the authentication and measurement via SPDM messages over PCIe or USB. ); that provide device key attestation and key exchange in accordance with a security protocol and data model (SPDM) framework, (Chapter 8: Device Security, Security Protocol and Data Model (SPDM), Page 261-262: “As such, the SPDM 1.1 specification adds a special command for a secure communication channel platform... See Table 8-2. In the handshake phase, the two entities may use certificate-based asymmetric key session creation or pre-shared key (PSK)-based session creation. ” );
wherein the CXL device is configured to implement an attestation protocol, via the SPDM framework, (Chapter 8: Device Security, PCI Express Integrity and Data Encryption, Pages 263: “Selective IDE Stream means the IDE TLPs flow through switches without affecting their security, while Link IDE Streams mean that two ports must be connected without intervening switches. The SPDM secure session messages are used to establish IDE stream and programming keys. Other hardware interfaces, such as Computer Express Link (CXL), are also adopting SPDM messages… ” ) with a cryptographic identity using the DICE architecture. (Chapter 8: Device Security, Device Identifier Composition Engine, Pages 260-266: “Here the Active Component RoT (AC-RoT) could be a DICE device. Each DICE device includes a unique device secret (UDS). This DICE certificate can be used as the identity of the device. Figure 7-9 in Chapter 7 shows the DICE certification generation… ” As specifically seen in SPDM over Management Component Transport Protocol (MCTP) Page 264: “SPDM messages can also be transported over MTCP...SPDM messages can be transported over MTCP. As such, MCTP devices can exchange SPDM messages. As we discussed in Chapter 7, the Cerberus project uses this mechanism to let the Platform Active Root-of-Trust (PA-RoT) authenticate the device Active Component Root-of-Trust (AC-RoT).” )
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Yao with regards to the implementation of a device identifier composition engine (DICE) architecture and SPDM framework to the method of Shanbhogue in order to enhance security and privacy with minimal silicon requirements and enable device authentication over a secure communication channel (Yao: Chapter 7: Trusted Boot, Device Identifier Composition Engine (DICE), Page 207 & Chapter 8: Device Security, Security Protocol and Data Model (SPDM), Page 261 ).
With respect to claim 19, the combination of Shanbhogue in view of Yao and Trikalinou teaches the CXL device of claim 18 (see rejection of claim 18 above),wherein the controller or the CXL controller, in combination with one or more other components of the CXL device, is configured to: encrypt data against a security threat, provide a secure handshake verification of an identity of the CXL device, enforce a chain of trust rooted in hardware of the CXL device; restrict access to an area of memory of the CXL device; or perform a security check and set up a set of security features of the CXL device. (Shanbhogue ¶0013-0014: As contemplated in the present disclosure, a memory encryption engine (MEE) is provided to support memory encryption for CXL devices. A memory mapped input/output (MMIO)-based configuration and capability enumeration interface is defined to support accessing the MEE by other devices in a computing system );
With respect to claim 20, the combination of Shanbhogue in view of Yao teaches the CXL device of claim 17 (see rejection of claim 17 above), further comprising: an attestation component, that implements one or more of the SPDM framework or the DICE architecture, configured to provide a secure handshake verification of an identity of the CXL device. (Yao Chapter 8: Device Security, Security Protocol and Data Model (SPDM), Pages 261-262: “As such, the SPDM 1.1 specification adds a special command for a secure communication channel on the platform… See Table 8-2. In the handshake phase, the two entities may use certificate based asymmetric key session creation or pre-shared key (PSK)-based session creation...” As seen in Table 8-2: SPDM 1.1 Command List for Secure Communication Channel shows a Session Handshakes intended to authenticate the responder (providing a secure handshake verification of an identity of the CXL device). And as further seen in Chapter 8: Device Security, Device Identifier Composition Engine (DICE), Page 260: “Here the Active Component Rot (AC-RoT) could be a DICE device. Each DICE device includes a unique device (UDS), and the DICE core generates the DICE certificate based upon the UDS. This DICE certificate can be used as the identity of the device (identity of the CXL device)…” )
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Yao with regards to the implementation of a device identifier composition engine (DICE) architecture and SPDM framework to the method of Shanbhogue in order to enhance security and privacy with minimal silicon requirements and enable device authentication over a secure communication channel (Yao: Chapter 7: Trusted Boot, Device Identifier Composition Engine (DICE), Page 207 & Chapter 8: Device Security, Security Protocol and Data Model (SPDM), Page 261 ).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Vijayrao et al. (US PGPub No. 20220358208-A1) discloses an accelerator having an internal physical processor communicating within an external processor via an expansion-bust interface, and wherein a secure execution zone comprises an additional internal physical processor to execute a sensitive application within the zone and make a result of executing the application accessible to the external processor. Additionally, Vijayrao discloses a restricted memory by making the memory accessible and inaccessible to certain processors.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAYLOR P VU whose telephone number is (703)756-1218. The examiner can normally be reached MON - FRI (7:30 - 5:00).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/T.P.V./Examiner, Art Unit 2437
/MENG LI/Primary Examiner, Art Unit 2437