DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office Action is in response to Application 19221319 filed on 08/06/2025.
Claims 4-5, 9, 11-12, 15, 17, 19, 23-27, and 30-32 were currently amended via the preliminary amendments. Claims 2-3, 6-8, 13-14, 16, 18, 20, and 28-29 have been canceled. Claims 1, 10, and 21 are independent claims. Claims 1, 4-5, 9-12, 15, 17, 19, 21-27, and 30-32 have been examined and are pending in this application. This Office Action is made Non-Final.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 08/06/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 10-12, 17, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over SUN et al. (CN 114117461 A) in view of Mohamed et al. (US 20090106549).
Regarding Claim 10;
SUN discloses a method comprising:
receiving, by a computing device, an encrypted data file, a policy file, and an encrypted first key (page 3, par 3; the first device encrypts and stores the main key; page 10, par 2; the access control policy of the main directory in the external storage device; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy . such that the external storage device is mounted on the first device, the security of the data in the encryption main directory by double protection policy, namely using the access control policy of the encrypted main directory to ensure only the user access authority of the encrypted main directory can access the encrypted main directory, using the encryption and decryption strategy of the data in the encryption main catalogue to ensure that the data in the encryption main catalogue is stored in the form of cipher text);
decrypting, based on a second key, an encrypted software application, the policy file, and the encrypted first key, wherein the policy file comprises policy information for authenticating access to the encrypted data file (page 7, par 2; a root key receiving unit, for receiving the first account and root key sent by the second device; page, par 3; wherein the data in the encryption main directory of the first account is encrypted and decrypted based on the root key; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy [] using the access control policy of the encrypted main directory to ensure only the user access authority of the encrypted main directory can access the encrypted main directory, using the encryption and decryption strategy of the data in the encryption main catalogue to ensure that the data in the encryption main catalogue is stored in the form of cipher text);
authenticating, based on the policy information, the software application (page 10, par 2; the access control policy of the main directory in the external storage device; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy . such that the external storage device is mounted on the first device, the security of the data in the encryption main directory by double protection policy, namely using the access control policy of the encrypted main directory to ensure only the user access authority of the encrypted main directory can access the encrypted main directory, using the encryption and decryption strategy of the data in the encryption main catalogue to ensure that the data in the encryption main catalogue is stored in the form of cipher text);
decrypting, via the software application, based on the authentication of the software application and based on the first key, the encrypted data file (page 3, par 1; wherein the root key is used for decrypting to obtain the main key encrypted and stored in the external storage device, the data in the encrypted main directory of the first account is encrypted and decrypted based on the main key); and
accessing, based on the decrypted data file, one or more software artifacts (page 3, par 2; when the user needs to access or modify the data in the encrypted main directory, the first device obtains the master key master key from the external storage device based on the root key, so as to obtain the working key for decrypting each file).
SUN discloses receiving, by a computing device, an encrypted data file, a policy file, and an encrypted first key as recited above, but do not explicitly disclose an encrypted policy file.
However, in an analogous art, Mohamed discloses extending encrypting file system/method that includes:
an encrypted policy file (Mohamed: par 0045; provides a key delegation mechanism for specific scenarios such as encrypted policy).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Mohamed with the method/system of SUN to include an encrypted policy file. One would have been motivated to determine if tampering has not occurred enroute and the user is authorized to access the file; the modified header data are returned to the client agent to enable the user to open the file (Mohamed: abstract).
Regarding Claim 11;
The combination of SUN and Mohamed disclosed the method of claim 10,
Mohamed discloses wherein the computing device comprises a destination server, wherein the destination server is configured to receive the encrypted data file, the encrypted policy file, and the encrypted first key from a secure build server (Mohamed: par 0002; a given folder can be marked as encrypted, and files created in the folder can be encrypted without any user intervention. WINDOWS.TM. EFS uses a symmetric file encryption key (FEK) for each file to encrypt and decrypt the file data. The FEK is encrypted with each user encryption public key and stored in the file EFS metadata information; par 0039; a trusted network service that receives requests from the client agents on behalf of corresponding users and grants the users access to encrypted files, based on security information stored in the encryption metadata portions of the encrypted files. While the EFSGS might be implemented on almost any computer, it will likely be implemented on a network or domain server, on using an Internet web server; par 0045; provides a key delegation mechanism for specific scenarios such as encrypted policy).
The motivation is the same as claim 10 above.
Regarding Claim 12;
The combination of SUN and Mohamed disclosed the method of claim 10, further comprising
SUN discloses receiving, by the computing device, the encrypted data file, the policy file, and the encrypted first key via portable storage that is external to the computing device (SUN: page 2, par 6; the data in the encryption main directory of the first account number is encrypted; page 3, par 3; the first device encrypts and stores the main key of the encryption main catalogue; page 2, par 7; the encryption main directory of the first account is further provided with an access control policy. The embodiment of the invention protects the data in the encryption main directory through the access control policy of the encryption main directory and the encryption /decryption policy of the data in the encryption main directory; page 10, par 2; the access control policy of the main directory in the external storage device; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy); wherein the portable storage comprises one or more of USB storage, or secure digital storage (SUN: page 12, par 10; the USB interface used to connect the charger to charge the electronic device, and may also be used to transmit data between the electronic device and the peripheral device).
Mohamed further discloses the encrypted policy file (Mohamed: par 0045; provides a key delegation mechanism for specific scenarios such as encrypted policy).
The motivation is the same as claim 10 above.
Regarding Claim 17;
The combination of SUN and Mohamed disclosed the method of claim 10,
Mohamed discloses wherein the policy information comprises one or more of identifier information of one or more users authorized to access the encrypted data file, identifier information of one or more servers authorized to access the encrypted data file, software authorized to access the encrypted data file, or encryption key information (Mohamed: par 0079; an authorization policy that can be applied to determine if a user should be authorized to access the encrypted file. Next, obtains a security descriptor that is defined by this authorization policy).
The motivation is the same as claim 10 above.
Regarding Claim 19;
The combination of SUN and Mohamed disclosed the method of claim 10, further comprising
SUN discloses wherein the decrypting of the encrypted data file is based on the verifying of the encrypted data file (SUN: page 3, par 1; wherein the root key is used for decrypting to obtain the main key encrypted and stored in the external storage device, the data in the encrypted main directory of the first account is encrypted and decrypted based on the main key).
Mohamed further discloses verifying, based on signature code associated with the policy information and the encrypted data file, the encrypted data file (Mohamed: 0046; creates a temporary encrypted file. The request message also causes a digital signature verification to be carried out by the EFSGS, based on a signing public key that is applied to hash the EFS metadata and the encrypted $SEH data blocks in the request message, producing a resulting test signature that is compared to a signature value that is included in $SEH data blocks of the temporary encrypted file; par 0079; an authorization policy that can be applied to determine if a user should be authorized to access the encrypted file. Next, obtains a security descriptor that is defined by this authorization policy).
The motivation is the same as claim 10 above.
Claims 1, 4-5, 9, 15, 21-27, and 30-32 are rejected under 35 U.S.C. 103 as being unpatentable over SUN et al. (“SUN,” CN 114117461 A, published on 03/01/2022) in view of Mohamed et al. (“Mohamed,” US 20090106549, published on 04/23/2009), and further in view MICHIELS et al. (“MICHIELS,” US 20170373828, published on 12/28/2017).
Regarding Claim 1;
SUN discloses a method comprising:
encrypting, by a first computing device, one or more software artifacts into an encrypted data file (page 2, par 6; the data in the encryption main directory of the first account number is encrypted);
encrypting a key and a policy file associated with the encrypted data file, wherein the policy file comprises policy information for authenticating access to the encrypted data file (page 3, par 3; the first device encrypts and stores the main key of the encryption main catalogue; page 2, par 7; the encryption main directory of the first account is further provided with an access control policy. The embodiment of the invention protects the data in the encryption main directory through the access control policy of the encryption main directory and the encryption /decryption policy of the data in the encryption main directory);
storing the encrypted key via the first computing device (page 3, par 3; the first device encrypts and stores the main key); and
storing the encrypted data file and the policy file via portable storage, wherein a second computing device accesses the encrypted data file via a software application of the second computing device that is authenticated based on the key and the policy information (page 10, par 2; the access control policy of the main directory in the external storage device; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy . such that the external storage device is mounted on the first device, the security of the data in the encryption main directory by double protection policy, namely using the access control policy of the encrypted main directory to ensure only the user access authority of the encrypted main directory can access the encrypted main directory, using the encryption and decryption strategy of the data in the encryption main catalogue to ensure that the data in the encryption main catalogue is stored in the form of cipher text).
SUN discloses a policy file associated with the encrypted data file; storing the encrypted key as recited above, but do not explicitly disclose encrypting a policy file.
However, in an analogous art, Mohamed discloses extending encrypting file system/method that includes:
encrypting a policy file (Mohamed: par 0045; provides a key delegation mechanism for specific scenarios such as encrypted policy).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Mohamed with the method/system of SUN to include encrypting a policy file. One would have been motivated to determine if tampering has not occurred enroute and the user is authorized to access the file; the modified header data are returned to the client agent to enable the user to open the file (Mohamed: abstract).
The combination of SUN and Mohamed disclosed storing the encrypted key via the first computing device as recited above, but do not explicitly disclose storing the encrypted key via a trusted execution environment.
However, in an analogous art, Mohamed discloses extending encrypting file system/method that includes:
storing the encrypted key via a trusted execution environment (MICHIELS: par 0013; storing the encrypted encoded encryption key using the TEE).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of MICHIELS with the method/system of SUN to and Mohamed include storing the encrypted key via a trusted execution environment. One would have been motivated to the encoded encryption key encrypted in a key store in a trusted execution environment (TEE) of the data processing system. The encrypted encryption key encrypted, stored, and decrypted in the key store in the TEE (MICHIELS: abstract).
Regarding Claim 4;
The combination of SUN, Mohamed, and MICHIELS disclosed the method of claim 1,
Mohamed discloses wherein the policy information comprises one or more of identifier information of one or more users authorized to access the encrypted data file, identifier information of one or more servers authorized to access the encrypted data file, software authorized to access the encrypted data file, or encryption key information (Mohamed: par 0079; an authorization policy that can be applied to determine if a user should be authorized to access the encrypted file. Next, obtains a security descriptor that is defined by this authorization policy).
The motivation is the same as claim 1 above.
Regarding Claim 5;
The combination of SUN, Mohamed, and MICHIELS disclosed the method of claim 1,
Mohamed discloses associating signature code with the policy information and the encrypted data file (Mohamed: 0046; creates a temporary encrypted file. The request message also causes a digital signature verification to be carried out by the EFSGS, based on a signing public key that is applied to hash the EFS metadata and the encrypted $SEH data blocks in the request message, producing a resulting test signature that is compared to a signature value that is included in $SEH data blocks of the temporary encrypted file; par 0079; an authorization policy that can be applied to determine if a user should be authorized to access the encrypted file. Next, obtains a security descriptor that is defined by this authorization policy).
The motivation is the same as claim 1 above.
Regarding Claim 9;
The combination of SUN, Mohamed, and MICHIELS disclosed the method of claim 1,
SUN discloses wherein the second computing device is configured to decrypt the encrypted key and the policy file based on a second key associated with the second computing device (SUN: page 7, par 2; a root
key receiving unit, for receiving the first account and root key sent by the second device; page, par 3; wherein the data in the encryption main directory of the first account is encrypted and decrypted based on the root key; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy [] using the access control policy of the encrypted main directory to ensure only the user access authority of the encrypted main directory can access the encrypted main directory, using the encryption and decryption strategy of the data in the encryption main catalogue to ensure that the data in the encryption main catalogue is stored in the form of cipher text).
Mohamed further discloses encrypted policy file (Mohamed: par 0045; provides a key delegation mechanism for specific scenarios such as encrypted policy).
The motivation is the same as claim 1 above.
Regarding Claim 15;
The combination of SUN and Mohamed disclosed the method of claim 10,
SUN discloses wherein the second key is configured to be stored via a trusted execution environment of the computing device (SUN: page 7, par 2; a root key receiving unit, for receiving the first account and root key sent by the second device).
The combination of SUN and Mohamed disclosed wherein the second key is configured to be stored via the computing device as recited above, but do not explicitly disclose a trusted execution environment.
However, in an analogous art, Mohamed discloses extending encrypting file system/method that includes:
storing the encrypted key via a trusted execution environment (MICHIELS: par 0013; storing the encrypted encoded encryption key using the TEE).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of MICHIELS with the method/system of SUN to and Mohamed include a trusted execution environment. One would have been motivated to the encoded encryption key encrypted in a key store in a trusted execution environment (TEE) of the data processing system. The encrypted encryption key encrypted, stored, and decrypted in the key store in the TEE (MICHIELS: abstract).
Regarding Claim 21;
SUN discloses a system comprising:
a first computing device comprising an execution environment, wherein the first computing device is configured to: encrypt one or more software artifacts into an encrypted data file (page 2, par 6; the data in the encryption main directory of the first account number is encrypted; page 3, par 3; the first device encrypts and stores the main key of the encryption main catalogue);
encrypt a first key and a policy file associated with the encrypted data file, wherein the policy file comprises policy information for authenticating access to the encrypted data file (page 3, par 3; the first device encrypts and stores the main key of the encryption main catalogue; page 2, par 7; the encryption main directory of the first account is further provided with an access control policy. The embodiment of the invention protects the data in the encryption main directory through the access control policy of the encryption main directory and the encryption /decryption policy of the data in the encryption main directory);
store the encrypted first key (page 3, par 3; the first device encrypts and stores the main key); and
store the encrypted data file and the policy file via portable storage (page 10, par 2; the access control policy of the main directory in the external storage device; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy . such that the external storage device is mounted on the first device, the security of the data in the encryption main directory by double protection policy, namely using the access control policy of the encrypted main directory to ensure only the user access authority of the encrypted main directory can access the encrypted main directory, using the encryption and decryption strategy of the data in the encryption main catalogue to ensure that the data in the encryption main catalogue is stored in the form of cipher text); and
a second computing device configured to: decrypt, based on a second key, an encrypted software application, the encrypted policy file, and the encrypted first key (page 7, par 2; a root key receiving unit, for receiving the first account and root key sent by the second device; page, par 3; wherein the data in the encryption main directory of the first account is encrypted and decrypted based on the root key; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy [] using the access control policy of the encrypted main directory to ensure only the user access authority of the encrypted main directory can access the encrypted main directory, using the encryption and decryption strategy of the data in the encryption main catalogue to ensure that the data in the encryption main catalogue is stored in the form of cipher text);
authenticate, based on the policy information, the software application (page 10, par 2; the access control policy of the main directory in the external storage device; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy . such that the external storage device is mounted on the first device, the security of the data in the encryption main directory by double protection policy, namely using the access control policy of the encrypted main directory to ensure only the user access authority of the encrypted main directory can access the encrypted main directory, using the encryption and decryption strategy of the data in the encryption main catalogue to ensure that the data in the encryption main catalogue is stored in the form of cipher text);
decrypt, via the software application, based on the authentication of the software application and based on the first key, the encrypted data file (page 3, par 1; wherein the root key is used for decrypting to obtain the main key encrypted and stored in the external storage device, the data in the encrypted main directory of the first account is encrypted and decrypted based on the main key); and
access, based on the decrypted data file, the one or more software artifacts (page 3, par 2; when the user needs to access or modify the data in the encrypted main directory, the first device obtains the master key master key from the external storage device based on the root key, so as to obtain the working key for decrypting each file).
SUN discloses encrypt a first key and a policy file associated with the encrypted data file; store the encrypted data file and the policy file as recited above, but do not explicitly disclose encrypting a policy file.
encrypt a first key and a policy file (Mohamed: par 0045; provides a key delegation mechanism for specific scenarios such as encrypted policy).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Mohamed with the method/system of SUN to include encrypting a policy file. One would have been motivated to determine if tampering has not occurred enroute and the user is authorized to access the file; the modified header data are returned to the client agent to enable the user to open the file (Mohamed: abstract).
The combination of SUN and Mohamed disclosed a first computing device comprising an execution environment; store the encrypted first key as recited above, but do not explicitly disclose a trusted execution environment; storing the encrypted key via a trusted execution environment.
However, in an analogous art, Mohamed discloses extending encrypting file system/method that includes:
a trusted execution environment (MICHIELS: par 0013; storing the encrypted encoded encryption key using the TEE);
storing the encrypted key via a trusted execution environment (MICHIELS: par 0013; storing the encrypted encoded encryption key using the TEE).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of MICHIELS with the method/system of SUN to and Mohamed include a trusted execution environment; storing the encrypted key via a trusted execution environment. One would have been motivated to the encoded encryption key encrypted in a key store in a trusted execution environment (TEE) of the data processing system. The encrypted encryption key encrypted, stored, and decrypted in the key store in the TEE (MICHIELS: abstract).
Regarding Claim 22;
The combination of SUN, Mohamed, and MICHIELS disclosed the system of claim 21,
Mohamed discloses wherein the first computing device comprises a secure build server and the second computing device comprises a destination server (Mohamed: par 0002; a given folder can be marked as encrypted, and files created in the folder can be encrypted without any user intervention. WINDOWS.TM. EFS uses a symmetric file encryption key (FEK) for each file to encrypt and decrypt the file data. The FEK is encrypted with each user encryption public key and stored in the file EFS metadata information; par 0039; a trusted network service that receives requests from the client agents on behalf of corresponding users and grants the users access to encrypted files, based on security information stored in the encryption metadata portions of the encrypted files. While the EFSGS might be implemented on almost any computer, it will likely be implemented on a network or domain server, on using an Internet web server; par 0045; provides a key delegation mechanism for specific scenarios such as encrypted policy).
The motivation is the same as claim 21 above.
Regarding Claim 23;
The combination of SUN, Mohamed, and MICHIELS disclosed the system of claim 21,
MICHIELS discloses wherein the trusted execution environment comprises a hardware-based memory encryption (MICHIELS: par 0013; storing the encrypted encoded encryption key using the TEE).
The motivation is the same as claim 21 above.
Regarding Claim 24;
The combination of SUN, Mohamed, and MICHIELS disclosed the system of claim 21,
SUN discloses wherein the one or more software artifacts comprise one or more of data files, container images, or bioinformatics (SUN: page 2, par 7; the encryption main directory of the first account is further provided with an access control policy. The embodiment of the invention protects the data in the encryption main directory through the access control policy of the encryption main directory and the encryption/decryption policy of the data in the encryption main directory).
Regarding Claim 25;
The combination of SUN, Mohamed, and MICHIELS disclosed the system of claim 21,
Mohamed discloses wherein the policy information comprises one or more of identifier information of one or more users authorized to access the encrypted data file, identifier information of one or more servers authorized to access the encrypted data file, software authorized to access the encrypted data file, or encryption key information (Mohamed: par 0079; an authorization policy that can be applied to determine if a user should be authorized to access the encrypted file. Next, obtains a security descriptor that is defined by this authorization policy).
The motivation is the same as claim 21 above.
Regarding Claim 26;
The combination of SUN, Mohamed, and MICHIELS disclosed the system of claim 21,
Mohamed discloses wherein the first computing device is further configured to associate signature code with the policy information and the encrypted data file (Mohamed: 0046; creates a temporary encrypted file. The request message also causes a digital signature verification to be carried out by the EFSGS, based on a signing public key that is applied to hash the EFS metadata and the encrypted $SEH data blocks in the request message, producing a resulting test signature that is compared to a signature value that is included in $SEH data blocks of the temporary encrypted file; par 0079; an authorization policy that can be applied to determine if a user should be authorized to access the encrypted file. Next, obtains a security descriptor that is defined by this authorization policy).
The motivation is the same as claim 21 above.
Regarding Claim 27;
The combination of SUN, Mohamed, and MICHIELS disclosed the system of claim 26,
SUN discloses wherein the second computing device is further configured to decrypt the encrypted data file based on the verification of the encrypted data file (SUN: page 3, par 1; wherein the root key is used for decrypting to obtain the main key encrypted and stored in the external storage device, the data in the encrypted main directory of the first account is encrypted and decrypted based on the main key).
Mohamed further discloses wherein the second computing device is further configured to verify, based on the signature code associated with the policy information and the encrypted data file, the encrypted data file (Mohamed: 0046; creates a temporary encrypted file. The request message also causes a digital signature verification to be carried out by the EFSGS, based on a signing public key that is applied to hash the EFS metadata and the encrypted $SEH data blocks in the request message, producing a resulting test signature that is compared to a signature value that is included in $SEH data blocks of the temporary encrypted file; par 0079; an authorization policy that can be applied to determine if a user should be authorized to access the encrypted file. Next, obtains a security descriptor that is defined by this authorization policy).
The motivation is the same as claim 21 above.
Regarding Claim 30;
The combination of SUN, Mohamed, and MICHIELS disclosed the system of claim 21,
SUN discloses wherein the portable storage is external to the first computing device and the second computing device, and wherein the portable storage comprises one or more of USB storage, or secure digital storage (SUN: page 2, par 6; the data in the encryption main directory of the first account number is encrypted; page 3, par 3; the first device encrypts and stores the main key of the encryption main catalogue; page 2, par 7; the encryption main directory of the first account is further provided with an access control policy. The embodiment of the invention protects the data in the encryption main directory through the access control policy of the encryption main directory and the encryption /decryption policy of the data in the encryption main directory; page 10, par 2; the access control policy of the main directory in the external storage device; page 12, par 10; the USB interface used to connect the charger to charge the electronic device, and may also be used to transmit data between the electronic device and the peripheral device page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy);
Regarding Claim 31;
The combination of SUN, Mohamed, and MICHIELS disclosed the system of claim 21,
SUN discloses wherein the second computing device is further configured to receive the encrypted data file and the policy file via the portable storage (SUN: page 10, par 2; the access control policy of the main directory in the external storage device; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy . such that the external storage device is mounted on the first device, the security of the data in the encryption main directory by double protection policy, namely using the access control policy of the encrypted main directory to ensure only the user access authority of the encrypted main directory can access the encrypted main directory, using the encryption and decryption strategy of the data in the encryption main catalogue to ensure that the data in the encryption main catalogue is stored in the form of cipher text).
Regarding Claim 32;
The combination of SUN, Mohamed, and MICHIELS disclosed the system of claim 21,
SUN wherein the second computing device comprises a second trusted execution environment, wherein the second computing device is further configured to store the second key via the second trusted execution environment (SUN: page 7, par 2; a root key receiving unit, for receiving the first account and root key sent by the second device; page 7, par 2; a root key receiving unit, for receiving the first account and root key sent by the second device; page, par 3; wherein the data in the encryption main directory of the first account is encrypted and decrypted based on the root key; page 20, par 7; the first account for the first time in the external storage device creating an encryption main directory, based on the root key is the first account of the encryption main directory in the encryption and decryption strategy, based on the second account and the second password is the encryption main directory of the first account set access control policy [] using the access control policy of the encrypted main directory to ensure only the user access authority of the encrypted main directory can access the encrypted main directory, using the encryption and decryption strategy of the data in the encryption main catalogue to ensure that the data in the encryption main catalogue is stored in the form of cipher text).
MICHIELS further discloses via the second trusted execution environment (MICHIELS: par 0013; storing the encrypted encoded encryption key using the TEE).
The motivation is the same as claim 21 above.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHAO WANG whose telephone number is (313)446-6644. The examiner can normally be reached on Monday-Friday 7:30-4:30PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached on (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only.
For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/C.W./Examiner, Art Unit 2439
/LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439
.