Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This action is in response to the communication filed on 5/29/2025.
Claims 1-20 are examined.
Claims 1-10, 12-14, 17-19 are rejected.
Claims 11, 15, 16 are objected.
Claim 20 is allowed.
Allowable Subject Matter
Claims 11, 15, 16 and 20 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Examiner notes that ‘Reason for Allowance’ will be described upon selection of claims.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 5/29/2025.
Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-10, 12-14, 17-19 are rejected under 35 U.S.C. 103 as being unpatentable by U.S Publication 2024/0311515 to Goodman et al. (hereinafter known as "Goodman”) and U.S Publication 2023/0388278 to Crabtree et al. (hereinafter known as “Crabtree”).
As per claim 1 Goodman teaches, a computer-implemented method comprising:
maintaining attestation data for a source system;
generating an attestation result using a result of verifying, using an attestation process, the attestation data for the source system (Goodman Fig 4 para 61-62 teaches auditing system 405 can rely on processes such as remote attestation, by which data 470 is collected from systems under audit 400);
generating, using a cryptographic proving key and data for the verification process, a cryptographic proof that indicates whether the verification process was correctly executed (Goodman Fig 5 para 63-64 teaches Kernel 550 is a third-party verifiable, auditable, cryptographically certified, trust-rooted entity, providing a more-secured source of information); and
providing, to a recipient system, the attestation result and the cryptographic proof (Goodman Fig 6 element 690 para 74 teaches auditing logic 680 applies rules 682 to the data 670 in order to determine some kind of a decision 690, such as a decision about whether the data is trustworthy).
Although Goodman teaches secure attestation Crabtree further teaches detection / mitigating of forged authentication using attestation (Crabtree – Fig 1 – para 73 and 92-94 teaches Attestation verifies the identity of a device or entity to ensure it is what it claims to be along with attestation process ensures that the device or entity has not been tampered with or compromised further it validates that the system's software and hardware components are in a trusted and unaltered state along with cryptographic techniques).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Goodman-Crabtree before him or her, to combine Goodman’s secure key based attestation process (Goodman Fig 1) with Crabtree’s teaching of detection / mitigating of forged authentication using attestation (Crabtree Fig 1 and abstract). The suggestion/motivation for doing so would have been to enhance detecting and mitigating attacks involving forged authentication objects in multi-cloud and hybrid environments (Crabtree para 19).
As per claim 2 combination of Goodman-Crabtree teaches, the method of claim 1, wherein providing the cryptographic proof comprises providing the cryptographic proof that comprises a cryptographic primitive and enables the recipient system to verify, using the cryptographic primitive, the verification process for the attestation data (Goodman Fig 5 para 63-64 teaches Trust-rooted and trustworthiness of the processes by which a modern kernel is booted and secured such as “Silicon Root of Trust” 510 (which can go by different names such as TrustZone or BootGuard, etc.) can verify the BIOS 520 signature).
As per claim 3 combination of Goodman-Crabtree teaches, the method of claim 2, wherein the cryptographic proof comprises a zero-knowledge proof (Goodman Fig 5 para 63 teaches Trust-rooted refers to the trustworthiness of the processes).
As per claim 4 combination of Goodman-Crabtree teaches, the method of claim 1, wherein providing the cryptographic proof comprises providing, to the recipient system, the cryptographic proof to cause the recipient system to verify the cryptographic proof using a cryptographic verification key (Goodman Fig 6 para 75-76 teaches verification of collected data 670 is coming from the kernel 640 itself verifiable by the auditing system 605 and requiring only knowledge of the system under audit's public device key).
As per claim 5 combination of Goodman-Crabtree teaches, the method of claim 4, wherein providing the cryptographic proof comprises providing, to the recipient system, the cryptographic proof to cause the recipient system to verify the cryptographic proof using the cryptographic verification key that was previously provided to the recipient system (Goodman Fig 6 para 76 and 79 teaches where auditing system receives, from the IHS, a response comprising information regarding the IHS and a cryptographic signature, where the information and the cryptographic signature was provided by a kernel of the IHS).
As per claim 6 combination of Goodman-Crabtree teaches, the method of claim 4, wherein providing the cryptographic proof comprises providing, to the recipient system, the cryptographic proof to cause the recipient system to verify the cryptographic proof using that cryptographic verification key that was retrieved from a public source (Goodman Fig 6 para 79 teaches where auditing system receives, from the IHS, a response comprising information regarding the IHS and a cryptographic signature, where the information and the cryptographic signature was provided by a kernel of the IHS).
As per claim 7 combination of Goodman-Crabtree teaches, the method of claim 6, comprising uploading the cryptographic verification key to the public source (Goodman Fig 6 para 79 teaches cryptographic signature was provided by a kernel of the IHS, and where the cryptographic signature was produced using a private key of the IHS).
As per claim 8 combination of Goodman-Crabtree teaches, the method of claim 4, comprising generating the cryptographic proving key and the cryptographic verification key (Goodman Fig 6 para 75-76 and 79 teaches Fig 7 element 730 where the auditing system receives, from the IHS, a response comprising information regarding the IHS and a cryptographic signature, where the information and the cryptographic signature was provided by a kernel of the IHS, and where the cryptographic signature was produced using a private key of the IHS).
As per claim 9 combination of Goodman-Crabtree teaches, the method of claim 8, wherein generating the cryptographic proving key and the cryptographic verification key occurs before generating the attestation result (Goodman Fig 3 para 59 teaches audit 300 with drift detection logic 310 which is security auditing and/or attack prevention in a larger-scale system by generating pre-key validation).
As per claim 10 combination of Goodman-Crabtree teaches, the method of claim 1, wherein:
the source system comprises trusted hardware that performed one or more computations for the recipient system (Goodman Fig 4 para 61-62 teaches auditing logic 480 where auditing assessments with audit 400 based upon collected data 470 (system under audit 400) which the auditing system 405 is trying to assess the security); and
generating the attestation result verifies the attestation data for the one or more computations the source system performed for the recipient system (Goodman Fig 4 and 5 para 63-64 teaches standard secure boot process where the kernel 550 is a third-party verifiable, auditable, cryptographically certified, trust-rooted entity, providing a more-secured source of information).
As per claim 12 Goodman teaches, a computer-implemented method comprising:
receiving, from a verifier system, i) an attestation result that the verifier system generated by verifying, using an attestation process, attestation data for a source system, and ii) a cryptographic proof that indicates whether the verification process was correctly executed (Goodman Fig 6 para 66-67 teaches system architecture block diagram generally depicting a secured, remote kernel auditing data collection system);
before determining whether the attestation result passes, determining, using a cryptographic verification key, whether the cryptographic proof passes providing an indication that the attestation result is trusted (Goodman Fig 6 para 65-66 teaches kernel 640 as securable, trusted entity, which fundamentally has access to all low-level data of a system along with secure device onboarding with cryptographic credentials such as (including a keys which could be held and managed by the TPM 642)); and
performing one or more operations using a result of the determination whether the cryptographic proof passes (Goodman Fig 6 element 690 para 74 teaches auditing logic 680 applies rules 682 to the data 670 in order to determine some kind of a decision 690, such as a decision about whether the data is trustworthy).
Although Goodman teaches secure attestation Crabtree further teaches detection / mitigating of forged authentication using attestation (Crabtree – Fig 1 – para 73 and 92-94 teaches Attestation verifies the identity of a device or entity to ensure it is what it claims to be along with attestation process ensures that the device or entity has not been tampered with or compromised further it validates that the system's software and hardware components are in a trusted and unaltered state along with cryptographic techniques).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Goodman-Crabtree before him or her, to combine Goodman’s secure key based attestation process (Goodman Fig 1) with Crabtree’s teaching of detection / mitigating of forged authentication using attestation (Crabtree Fig 1 and abstract). The suggestion/motivation for doing so would have been to enhance detecting and mitigating attacks involving forged authentication objects in multi-cloud and hybrid environments (Crabtree para 19).
Claim 13,
Claim 13 is rejected in accordance with claim 2.
As per claim 14 combination of Goodman-Crabtree teaches, the method of claim 13, wherein performing the one or more second operations comprises:
in response to determining that the attestation result does not pass, discarding output generated by the source system (Goodman Fig 6 element 690 para 74 teaches auditing logic 680 applies rules 682 to the data 670 in order to determine some kind of a decision 690, such as a decision about whether the data is trustworthy).
Claim 17,
Claim 17 is rejected in accordance with claim 4.
Claim 18,
Claim 18 is rejected in accordance with claim 6.
As per claim 19 combination of Goodman-Crabtree teaches, the method of claim 12, wherein the verifier system and source system both comprise subsystems of the same cloud system (Goodman para 44 and 53 teaches IHS 100 as cloud based operation of workspaces, each operating using resources of IHS 100 with respective workspace definition).
Prior Art
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Goodman et al US Publication 20240311515
Crabtree et al US Publication 20230388278
Wentz et al US Publication 20200153627
Dutta et al US Publication 20210097000
Guccione et al US Publication 20210266309
Sibert et al US Patent 11790119
Soriente et al US Patent 11361069
Wentz et al US Patent 10735205
Lai et al US Patent 12256020
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to VIRAL S LAKHIA whose telephone number is (571)270-3363. The examiner can normally be reached on 8 am - 6 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/VIRAL S LAKHIA/Primary Examiner, Art Unit 2431