Prosecution Insights
Last updated: October 01, 2026
Application No. 19/310,256

Access Control Method and Apparatus

Non-Final OA §102§103
Filed
Aug 26, 2025
Priority
Feb 27, 2023 — CN 202310209421.4 +1 more
Examiner
DRAKMIH, OMAR REFAT
Art Unit
Tech Center
Assignee
Huawei Technologies Co., Ltd.
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-60.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
1 currently pending
Career history
2
Total Applications
across all art units
This examiner has no resolved cases yet (career too new); statute-level performance unavailable. The Grant Probability card shows Tech Center averages instead.

Office Action

§102 §103
DETAILED ACTION Claims 1-20 are pending and are under examination. Claims 1-20 are rejected under 35 U.S.C 102 and 103 as discussed below. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1, 2, 4, 7, 8, 13, 14, 16, 19, and 20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Boyd (US20040049600A1). As per claim 1, Boyd teaches a method, comprising: receiving an access request requesting to access a first storage subspace in a first storage space of a first node [A remote direct memory access (RDMA) read work request provides a memory semantic operation to read a virtually contiguous memory space on a remote node…. A memory window references a set of virtually contiguous memory addresses that have been bound to a previously registered region; (para. 64)]; The incoming RDMA request (access request) is received at the destination node (first node) and targets a memory window (first storage subspace) bound within a previously registered memory region (first storage space). wherein the access request comprises space access information and a first access type [The Stag is part of each RDMA access; (para. 68)]; Additionally, [virtual address 1216 specified in the work request or remote operation packet header; (para. 114)]; The request carries the Stag and a virtual address (space access information) together with a message identifier of read RDMA or write RDMA (first access type). wherein the space access information indicates the first storage space and the first storage subspace [the Tag_Index portion of the DDP Header's STag is used to index into the Memory Region/Window Table; (para. 177)]; The Stag directly identifies the memory window entry (first storage subspace), and because the window exists only as bound to a previously registered memory region whose translation structure its entry indexes, the same information indicates the containing memory region (first storage space). controlling, based on the space access information and the first access type, access to the first storage subspace [the following checks are performed on the entry that has been indexed by the Tag_Index portion of the incoming DDP Header's STag: … e) the base address of the incoming DDP Segment is within the range of addresses associated with the MWE; and f) the type of access is valid (i.e. the MWE has remote write access enabled). If all the checks pass, then processing continues, otherwise a Terminate Message is generated describing the cause of the error; (para. 178)]; Access to the window (first storage subspace) is allowed or terminated based on the Stag-indexed entry and address bounds (space access information) and the enabled access type (first access type). As per claim 2 and 14, Boyd teaches allowing access to the first storage subspace when the first storage space and the first storage subspace are valid, and the first access type belongs to one or more second access types corresponding to the first storage subspace [the Valid Entry field is set… e) the base address (Target Offset) and length (MPA Header Length) of the incoming DDP Segment is within the range of addresses associated with the MWE; and f) the type of access is valid; (para. 175)]; Additionally, [If all the checks pass, the IPSOE creates the RDMA Read Responses by reading the Memory Window referenced by the RDMA Read Request; (para. 176)]; The adapter looks up the windows table entry: a set valid bit shows the window (first storage Subspace) and that region (first storage space) are valid, and each window entry lists which access types are enabled for it (the one or more second access types). When the entry is valid and the requested read or write is among the windows enabled types. rejecting access to the first storage subspace when either the first storage space and the first storage subspace are invalid, or the first access type does not belong to the one or more second access types [Otherwise a Terminate Message is generated describing the cause of the error; (para. 176)]; Otherwise refers to failure of any checks of A through F in paragraph 175, which include the valid entry and address range checks. As per claim 4 and 16, Boyd teaches allowing access to the first storage subspace when the first access credential matches a second access credential corresponding to the first storage subspace [the portion of the DDP Header's STag that is the Tag_Instance matches Tag_Instance in the MWE; e)…. If all the checks pass, the IPSOE creates the RDMA Read Responses by reading the Memory Window referenced by the RDMA Read Request…. The Tag_Instance provides access control when the definitions of memory regions change; (para. 175, 176, and 119)]; Access to the memory window is granted when request’s Tag_Instance matches the Tag_Instance stored in the memory window entry. rejecting access to the first storage subspace when the first access credential does not match the second access credential [Otherwise a Terminate Message is generated describing the cause of the error; (para. 176)]; As per claim 7, Boyd teaches sending an access request requesting to access a first storage subspace in a first storage space of a first node [A memory space can either be a portion of a memory region or portion of a memory window…. The RDMA read work request reads a virtually contiguous memory space on a remote end node; (para. 64 and 65 see 84 for more details)]; The requester builds the work request, and its engine sends it as data frames through the fabric directed to memory of the remote node (first node) that is a portion of a memory window (first storage subspace) bound within a previously registered memory region (first storage space). wherein the access request comprises space access information and a first access type [The STag is part of each RDMA access and is used to validate that the remote process has permitted access to the buffer…. Example message identifiers include, for example, send, write RDMA, and read RDMA; (para. 68 and 80)]; The sent request carries the Stag together with the virtual address of the remote space (space access information) and a read RDMA or write RDMA message identifier (first access type). wherein the space access information indicates the first storage space and the first storage subspace [the Tag_Index portion of the DDP Header's STag is used to index into the Memory Region/Window Table; (para. 177)]; The Stag identifies the memory window entry (first storage subspace), and because the window exists only as bound to a previously registered memory region whose translation structure its entry indexes, the same information indicates the containing memory region (first storage space). accessing the first storage subspace when the first node allows access to the first storage subspace [If all the checks pass, the IPSOE creates the RDMA Read Responses by reading the Memory Window referenced by the RDMA Read Request…. the destination process previously grants permission for the source process to access its memory; (para. 176 and 51)]; When the first node’s check pass, the requester’s read is fulfilled, the requester accesses the memory window (first storage subspace) only when the first node allows it . As per claim 8, Boyd teaches wherein accessing the first storage subspace comprises accessing the first storage subspace [If all the checks pass, the IPSOE creates the RDMA Read Responses by reading the Memory Window referenced by the RDMA Read Request and issuing the RDMA Read Responses; (para. 176)]; when the first storage space and the first storage subspace are valid [the Valid Entry field is set…. Valid Entry 1312 denotes whether the entry is valid or invalid; (para. 175 and 123)]; when the first access type belongs to one or more second access types corresponding to the first storage subspace [the type of access is valid (i.e. the MWE has remote read access enabled). Additionally, [The Type of Access Control 1330 field contains four distinct access types: local read, local write, remote read, and remote write access. These distinct access types can be encoded as four bits, where if a bit is set, the access type associated with the bit is enabled; (para. 125)]; As per claim 13, Boyd teaches A first node [Host processor node 102 also includes central processing units 126-130 and a memory 132 interconnected by bus system 134]; (para. 44)]; a first storage space comprising a first storage subspace [A remote direct memory access (RDMA) read work request provides a memory semantic operation to read a virtually contiguous memory space on a remote node…. A memory window references a set of virtually contiguous memory addresses that have been bound to a previously registered region; (para. 64)]; a memory configured to store instructions [ a memory 132…. the processes of the present invention are capable of being distributed in the form of a computer readable medium of instructions or other functional descriptive material and in a variety of other forms and that the present invention is equally applicable regardless of the particular type of signal bearing media actually used to carry out the distribution. Examples of computer readable media include recordable-type media, such as a floppy disk, a hard disk drive, a RAM; (para. 44 and 186)]; one or more processors coupled to the first storage space and the memory and configured to execute the instructions to cause the first node to [central processing units 126-130 and a memory 132 interconnected by bus system 134…. an IP Suite Offload Engine is implemented in hardware or a combination of hardware and offload microprocessor(s); (para. 44 and 46)]; receive, from a second node, an access request requesting to access the first storage subspace, wherein the access request comprises space access information and a first access type, and wherein the space access information indicates the first storage space and the first storage subspace [Data frames are generated by source endnodes and consumed by destination endnodes; (para. 84 also see claim 1)]; control, based on the space access information and the first access type, access of the second node to the first storage subspace [the following checks are performed on the entry that has been indexed by the Tag_Index portion of the incoming DDP Header's STag: … e) the base address (Target Offset) and length (MPA Header Length) of the incoming DDP Segment is within the range of addresses associated with the MWE; and f) the type of access is valid (i.e. the MWE has remote write access enabled). If all the checks pass, then processing continues to step 1824, otherwise a Terminate Message is generated describing the cause of the error; (para. 178)]; As per claim 19, Boyd teaches wherein the first storage space further comprises a plurality of second storage subspaces, and wherein the plurality of second storage subspaces comprises the first storage subspace [Window Binding Control 1332 field contains a single bit denoting whether Memory Windows can be bound to the Memory Region or not. If the bit is set, Memory Windows can be bound to the Memory Region; (para. 126)]; Additionally, [A memory window references a set of virtually contiguous memory addresses that have been bound to a previously registered region; (para. 64)]; As per claim 20, Boyd Teaches The first node of claim 19, wherein at least two of the plurality of second storage subspaces correspond to different second access types [These distinct access types can be encoded as four bits, where if a bit is set, the access type associated with the bit is enabled. If a bit is not set, the access type associated with the bit is disabled… a Memory Window Entry would only have two distinct access types: remote read access and remote write access…. both MREs and MWEs contain the same fields; (para. 125 and 117)]; Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 3, 9, 10, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Boyd (US20040049600A1) in view of Liu, HongKuan (WO2016172862A1). As per claims 3 and 15, wherein before receiving the access request, receiving a registration request requesting to register a second storage subspace in the first node; wherein the registration request comprises a second access type, and wherein the second access type comprises the first access type; And sending, in response to the registration request, a registration response indicating the first storage space and the first storage subspace. Boyd Teaches [A bind (unbind) remote access key (STag) work queue element provides a command to the IP Suite Offload Engine hardware to modify (destroy) a memory window by associating (disassociating) the memory window to a memory region; (para. 68)]; Additionally, [Consumer 1140 requests the IPSOE 1192 to create an entry in the Memory TPT 1172 by posting a Send Queue (SQ) Work Request (WR); (para. 108)]; Boyds engine receives a request (registration work request) to establish a memory window (storage subspace) in the node. Furthermore, [The Verbs interface immediately returns the STag associated with the Memory Registration WR…. The STag of the memory region are included in the Bind WQE; (para. 108 and 118)]; Boyd returns an Stag identifying the registered region or window. Boyd does not teach receiving the registration request from the node that will send the access request. Secondly that the access type in the registration request comprises the access type of the subsequently received request. A registration response indicating both the first storage space and the first storage subspace. Liu teaches these features [ 402: The second computing device sends an RDMA operation request to the first computing device over the network 102. 404: The first computing device performs a memory application in the local memory according to the RDMA operation request. 406: The first computing device sends the requested registration memory area message to the second computing device. 408: The second computing device performs an RDMA operation on the first computing device; (Fig. 4 steps 402-408)]; The first computing device (first node) receives the request from the second device and, in response, registers a memory area in its own local memory (the requested storage subspace). Additionally [Optionally, the RDMA operation request carries an RDMA operation type requested by the second computing device to the first computing device, and a memory size required for the RDMA operation; (Fig. 4 description)]; The registration request carries the set of operation types to be allowed for the registered area (second access type). Furthermore [610: The memory controller 504 generates information about the registered memory area according to the application response message of the M memory nodes 506, and sends a memory registration response message to the computing node 502 through the unified memory resource interface; (Fig. 6 description)]; It would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to modify Boyd’s memory window registration so that the registration request is received from the remote node that will access the window, carries the operation type the node will use and is answered with a response identifying the memory region and the memory window. Applying this registration exchange is the use of a known technique to improve a similar device yielding the predictable result of on demand access typed provisioning of memory windows. As per claim 9, wherein before sending the access request, the method further comprises: sending a registration request requesting to register a second storage subspace in the first node, wherein the registration request comprises a second access type, and wherein the second access type comprises the first access type; and receiving a registration response indicating the first storage space and the first storage subspace. Boyd teaches [The Type of Access Control 1330 field contains four distinct access types: local read, local write, remote read, and remote write access. These distinct access types can be encoded as four bits, where if a bit is set, the access type associated with the bit is enabled; (para. 125)]; Additionally [Upon receiving the immediate return, Consumer 1140 may begin using the STag in local or remote WRs; (para. 108)]; Boyd does not teach the requesting node sending to register a storage subspace in the first node. Also that the access type in the registration request comprises the access type of the subsequently received request. A registration response indicating both the first storage space and the first storage subspace. Liu teaches this [402: The second computing device sends an RDMA operation request to the first computing device over the network 102. 404: The first computing device performs a memory application in the local memory according to the RDMA operation request. (Fig. 4 steps 402-408)]; Additionally, [The computing node is configured to send a memory registration request to the memory management device by using the unified memory resource interface; (Summary of invention para. 39); furthermore, [the memory registration request further includes a permission identifier, where the permission identifier is used to represent an operation type allowed by the registration memory area; and the memory application message further includes the permission identifier. Optionally, the operation type includes at least one of the following: local read, local write, remote read, remote write, atomic operation, or binding; (detailed description para. 67)]; Also [the RDMA operation request carries an RDMA operation type requested by the second computing device to the first computing device, and a memory size required for the RDMA operation; (detailed desc. para. 10)]; It would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to modify Boyd with Liu as it is the combination of prior art elements with known methods and the use of known techniques to improve a similar system in the same way to get the predictable results of on demand access type provisioning. As per claim 10, Boyd teaches wherein the access request further comprises a first access credential [The STag is part of each RDMA access…. the portion of the DDP Header's STag that is the Tag_Instance; (para. 68, 175)]; wherein accessing the first storage subspace comprises accessing the first storage subspace when the first access credential is consistent with a second access credential corresponding to the first storage subspace [the portion of the DDP Header's STag that is the Tag_Instance matches Tag_Instance in the MWE….. If all the checks pass, the IPSOE creates the RDMA Read Responses by reading the Memory Window referenced by the RDMA Read Request and issuing the RDMA Read Responses; (para. 175, 176)]; Claim 10 is fully taught by Boyd, no new modification. Claims 5, 6, 17, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Boyd (US20040049600A1) in view of Gibson (US20210250167A1). As per claims 5 and 17, Boyd does not teach generating the first access credential based on at least one of: the first storage space, a second access type corresponding to the first storage space, the first storage subspace, a third access type corresponding to the first storage subspace, or a random number wherein the first access credential is a message authentication code or a key; and sending the first access credential. Gibson teaches generating the first access credential based on at least one of: the first storage space, a second access type corresponding to the first storage space, the first storage subspace, a third access type corresponding to the first storage subspace, or a random number [Each derived key may be generated transiently using the following equation (1): Kd=AESGCMKDF(Kr,ADDRESSINITIATOR,GEIINITIATOR,TOKENS . . . )…. where Kd is the derived key, Kr is the region key associated with the application-specific memory region, ADDRESSINITIATOR is the identifier of the requesting host, GEIINITIATOR is the process ID of the requesting application, TOKENS are an arbitrary arrangement of bits…. the host can provide a derived key, and select TOKENS as offset fields of the request, such that the derived key provided only successfully authenticates for requests limited to a particular offset range…. the host may provide several derived keys (Kds), one for each granted operation type which include the primitives that the network interfaces can perform, such as read, write, short read etc; (para. 47, 49, 50, 51)]; wherein the first access credential is a message authentication code or a key [ where Kd is the derived key; (para. 51)]; sending the first access credential [the host 205 a may respond to the RPC with a derived key, Kd, specific to the client application; (para. 47)]; It would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to modify Boyd, as the modification is a substitution of a known credential generation technique for another yielding the predictable results of spoof resistant sub region bound access credentials. As per claims 6 and 18, Boyd does not teach updating the first access credential to a third access credential when an access permission of at least one of a plurality of second nodes registered to the first storage subspace is terminated; and sending, to a third node in the plurality of second nodes other than the at least one of the plurality of second nodes, the third access credential. Gibson teaches updating the first access credential to a third access credential when an access permission of at least one of a plurality of second nodes registered to the first storage subspace is terminated [different remote hosts requesting RMA access to the same application-specific registered memory region can all use the same shared region key corresponding to that application-specific registered memory region…. examining the rate at which access requests are granted and throttling or revoking access to high-rate requestors (which can signal certain forms of attack)…. The derived keys may continue to function until the host rekeys the application-specific memory region. In this regard, by rekeying the application-specific memory region, the region key associated with that memory region may be altered, thereby invalidating all Kds generated from the previous region key; (para. 27, 48, 52)]; sending, to a third node in the plurality of second nodes other than the at least one of the plurality of second nodes, the third access credential [The host 205 a may then admit or deny the remote host's RPC based on defined policies. In the event the host 205 a admits the client application, the host 205 a may respond to the RPC with a derived key, Kd, specific to the client application; (para. 47)]; It would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to further modify Boyd for Gibson’s known revoke and rekey technique to the credential combination. This is a use of a known technique to improve the access control system yielding the predictable results that revoked nodes credentials don’t work while the remaining nodes are getting their credentials. Claims 11 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Boyd (US20040049600A1) in view of Liu, HongKuan (WO2016172862A1) and further in view of Gibson (US20210250167A1). As per claim 11, Boyd in view of Liu teaches claim 10 but does not teach further comprising receiving the first access credential, wherein the first access credential is based on at least one of: the first storage space, the first storage subspace, a third access type corresponding to the first storage subspace, or a random number, and wherein the first access credential is a message authentication code or a key. Gibson teaches further comprising receiving the first access credential [the host 205 a may respond to the RPC with a derived key, Kd, specific to the client application…. Using the derived key, the host of the application may request RMA access to the application-specific registered memory region; (para. 47, 28)]; wherein the first access credential is based on at least one of: the first storage space, the first storage subspace, a third access type corresponding to the first storage subspace, or a random number wherein the first access credential is a message authentication code or a key [Each derived key may be generated transiently using the following equation (1): Kd=AESGCMKDF(Kr,ADDRESSINITIATOR,GEIINITIATOR,TOKENS . . . )…. where Kd is the derived key, Kr is the region key associated with the application-specific memory region, ADDRESSINITIATOR is the identifier of the requesting host, GEIINITIATOR is the process ID of the requesting application, TOKENS are an arbitrary arrangement of bits…. the host can provide a derived key, and select TOKENS as offset fields of the request, such that the derived key provided only successfully authenticates for requests limited to a particular offset range…. the host may provide several derived keys (Kds), one for each granted operation type which include the primitives that the network interfaces can perform, such as read, write, short read etc; (para. 47, 49, 50, 51)]; It would have been obvious to one of the ordinary skill in the art to combine Boyd in view of Liu with Gibson as it is the application of a known technique to a known system yielding the predictable result of spoof resistant, sub region bound credentials to the resting node. As per claim 12, Boyd as modified teaches claim 11 but does not teach further comprising: receiving a third access credential; and updating the first access credential to the third access credential. Gibson teaches further comprising: receiving a third access credential; and updating the first access credential to the third access credential [the host 205 a may respond to the RPC with a derived key, Kd, specific to the client application…. The client NIC 2240 b may then sign all operations (Op), such as read, writes, rekeys, etc., using the received Kd…. The derived keys may continue to function until the host rekeys the application-specific memory region. In this regard, by rekeying the application-specific memory region, the region key associated with that memory region may be altered, thereby invalidating all Kds generated from the previous region key; (para. 63, 42, and 52)]; It would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to further provide in the combination, that the requesting node receives a new derived key following the hosts rekey of the memory region and updates its credentials. This yields to the predictable result that the requesting nodes access continues under the current credential while keys derived from the previous region key cease to function. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to OMAR DRAKMIH whose telephone number is (571)270-0579. The examiner can normally be reached Monday - Friday 8am-4PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /O.R.D./Examiner, Art Unit 2431 /SHIN-HON (ERIC) CHEN/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Aug 26, 2025
Application Filed
Sep 15, 2026
Non-Final Rejection mailed — §102, §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month