Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
This communication is in response to the amendment filed on 7/20/2026. The Examiner acknowledges elected and amended claims 1-14. Claims 15-20 have been withdrawn. No claims have been cancelled or added. Claims 1-20 are pending and claims 1-14 are rejected. Claims 1, 10, and 15 is/are independent, and claim 15 is withdrawn.
The rejection(s) of claims under 35 U.S.C. § 112 are withdrawn in view of Applicant's amendments.
The rejection(s) of claims under 35 U.S.C. § 102/103 have been updated based on new grounds of rejection as indicated below.
Response to Arguments
Applicant's arguments filed 7/20/2026 have been fully considered. Applicant argues (see Remarks, page 7, top paragraph through page 8, bottom paragraph) that the references cited in the previous rejection fail to disclose the newly amended claim features. This argument is persuasive. Therefore, the rejections are withdrawn. However, upon further consideration, a new ground of rejection is made in view of Langhammer et al. U.S. Patent No. 10237066 (hereinafter “Langhammer ‘066”) in view of Langhammer et al. U.S. Patent No. 9519807 (hereinafter “Langhammer ‘807”).
Langhammer ‘066 teaches the multiple sequences of hash values that are created by the authentication pipeline processing block 350 (9:8 and 9:15; 9:30-31). Langhammer ‘807 teaches an adder to combine multiple partial hash states to create the final hash state (2:13-29; 2:38-40). The combination of references discloses the amended limitations of claim 1.
Independent claim 10 is also disclosed by the same combination of references as claim 1, as detailed below. Regarding applicant’s arguments with respect to the dependent claims 2-14, applicant’s amendments to the independent claims have necessitated a new ground of rejection with respect to the independent claims from which the dependent claims depend, thereby requiring new grounds of rejection for the dependent claims also.
Accordingly, Applicant's argument is persuasive, the rejection is withdrawn, and new ground(s) of rejection are presented herein. Note that this action is made FINAL. See MPEP § 706.07(a).
Subject Matter Eligibility
Claims 1-14 recite eligible subject matter. The claims are directed to an improvement to a hashing circuit.
Regarding claim 1, the claim recites a Galois field multiplier, which generates one or more values, and there is a multiplication operation involved, which is a mathematical concept. Alternatively, the claim recites a mental process because a person can also create a value. However, the claim recites a practical application and/or significantly more because the Galois field multiplier is pipelined, which is an improvement based on the description of the problem in the specification at para. 4, which states “individual hash functions may not be pipelined”, and the pipelining is described at para. 28.
Regarding claim 10, claim 10 recites performing multiplication operations, which is reciting a mathematical concept. The storing of the output in the first pipeline stage and the recitation of the transitioning from first pipeline stage to the second pipeline stage reflects the improvement of utilizing the pipelines, which is a practical application and/or significantly more.
Because each of claims 1.and 10 recite a practical application and/or significantly more, the claims are reciting eligible subject matter.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claime d invention as a whole would have been obvious before the effective filing date of the claimed invention t/o a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1, 7, 10-11, 13, and 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Langhammer et al. U.S. Patent No. 10237066 (hereinafter “Langhammer ‘066”) in view of Langhammer et al. U.S. Patent No. 9519807 (hereinafter “Langhammer ‘807”).
As per claim 1, Langhammer ‘066 discloses
An integrated circuit comprising:
2:39-47 (7) Therefore, in accordance with embodiments of the present invention, systems and methods are provided for processing data using deeply-pipelined algorithms and circuitries. In one embodiment, a scalable and efficient cryptographic architecture may be implemented as circuitry in a fixed logic device, or may be configured into a programmable integrated circuit device. The same top-level design may be used for different choices of data channels, processing depth, parallelism level, and/or system throughput.
selection circuitry [selection circuitries, 1 9:1-23] configurable to provide one of a plurality of powers [ providing channel values H and powers thereof, 9:1-23; providing hash values X and powers thereof, 9:14-15 ] of a hash key;[ combining channel values H and hash values X, 9:1-23; hash subkey value H, 9:24-31; channel values H, 9:1-23; 10:12-14 The authentication pipeline processing block 350 may receive the hash subkey value or power thereof corresponding to the first channel a ]
Langhammer ‘066 9:1-23 (30) FIG. 3 is a simplified block diagram of one possible implementation 300 of an authentication key pipeline block according to some embodiments. FIG. 3 describes authentication using a number x of virtual channels for data incoming from 3 physical channels a, b, and c. This exemplary implementation may be used to implement authentication key pipeline block 170 of FIG. 1. Implementation 300 includes an authentication pipeline processing block 350 for combining channel values H and hash values X as explained in more detail below, to generate an authentication tag value. As shown on the right, implementation 300 includes register circuitries 301a, 301b, 301c, through 301x, register circuitries 302a, 302b, 302c, through 302x, and register circuitries 303a, 303b, 303c, through 303x, for providing hash values X and powers thereof. As shown on the left, implementation 300 includes register circuitries 361a, 361b, 361c, through 361x, register circuitries 362a, 362b, 362c, through 362x, and register circuitries 363a, 363b, 363c, through 363x, for providing channel values H and powers thereof. Implementation 300 includes selection circuitries 301, 302, 303, 361, 362, 363, 310, and 370 to implement selection of an appropriate value from the register circuitries to be input to the authentication pipeline processing block 350.
9:24-31 (31) In some authentication algorithms such as the GCM mode of AES, encrypted data, e.g., generated by AES, is repeatedly processed using a hash function to generate a hash (or pre-tag) value X. This hash function may implement multiplication within a binary Galois field, by a hash subkey value H, which is generally though not necessarily constant during an authentication session. The final hash value X is retained as the authentication tag.
Langhammer ‘066 10:3-24 (36) Going back to FIG. 3, implementation 300 allows authentication pipeline processing block 350 to assemble the appropriate multiplication operands, e.g., according to at least parts of equation EQ. 1, EQ. 2, and/or EQ. 3 above, in order to generate a final authentication tag. For example, authentication pipeline processing block 350 may receive a hash subkey value H.sub.1 from register circuitry 361a, or a v.sup.th power H.sub.1.sup.v thereof (v=1, . . . , x) from one of register circuitries 361b, 361c, through 361x, all corresponding to channel a. The authentication pipeline processing block 350 may receive the hash subkey value or power thereof corresponding to the first channel a. The authentication pipeline processing block 350 may combine this received hash subkey value or power thereof with an intermediate hash value X.sub.1, received from register circuitry 301a or a power therefor X.sub.1.sup.x, also corresponding to the first channel a, using multiplication, adder and any suitable combination circuitry. The same may be done with authentication parameters for a second channel b (using hash subkey value H.sub.2, intermediate hash value X.sub.2, and/or powers of H.sub.2 and/or X.sub.2) and a third channel c (using hash subkey value H.sub.3 and intermediate hash value X.sub.3, and/or powers H.sub.3 and/or X.sub.3).
a Galois field multiplier [multiplication within a binary Galois field, 9:24-31; Galois field multiplier can be disclosed by authentication pipeline processing block 350, element 50, figure 3; authentication pipeline processing block 350 to assemble the appropriate multiplication operands, e.g., according to at least parts of equation EQ. 1, EQ. 2, and/or EQ. 3 above, in order to generate a final authentication tag, 10:3-7; support complex logic structure (such as 128-bit Galois Field operations) and customizable multiplier input structures, 13:7-11; authentication pipeline processing block 350 may combine… using multiplication, 10:14-19] configurable to receive the one of the plurality [see figure 3 which shows multiple powers (exponents) being received from the hashes H and also the hashes X ] of powers of the hash key [authentication pipeline processing block 350 may receive a hash subkey value H.sub.1 from register circuitry 361a, or a v.sup.th power H.sub.1.sup.v thereof, 10:8-10;10:12-14 The authentication pipeline processing block 350 may receive the hash subkey value or power thereof corresponding to the first channel a; ] and a hash sequence [see all the hashes H, and hashes X being received at authentication pipeline processing block 350, in figure 3; authentication pipeline processing block 350 may receive a hash subkey value H.sub.1, H.sub.1, etc. thereby disclosing hash sequence, 10:3-24] and generate a plurality of partial hash sequences, [a plurality of partial hash sequences can be disclosed by the sequences of hash values that are created by the authentication pipeline processing block 350 shown in figure 3 where the arrow is coming out the bottom of the block 350 and these are sequences of hashes, each hash is the authentication tag (“the final hash value X is retained as the authentication tag”, 9:30-31), each hash such as hash values X (9:8 and 9:15), thereby disclosing a plurality of partial hash sequences. Note that you only need two hashes to disclose a hash sequence.] wherein the Galois field multiplier comprises multiple levels of pipeline stages; [see Figure 3 which depicts authentication pipeline processing block 350 with four pipelines (rounds); authentication pipeline processing block 160 may implement an authentication pipeline 165, 5:59-63; figure 1 authentication pipeline processing block 160] and
Langhammer ‘066 5:63-6:1 authentication pipeline processing block 160 may implement any suitable authentication process, for example, GCM which takes a plaintext bit string as an input and combines it with an initialization vector (IV) to produce an encrypted bit string (i.e., ciphertext) and an authentication tag,
4:15-24 (8) FIG. 1 is a block diagram of an encryption and authentication core architecture 100 according to some embodiments. Architecture 100 includes an encryption pipeline processing block 130 and an encryption key pipeline block 110. Architecture 100 also includes an authentication pipeline processing block 160 and an authentication key pipeline block 170. As shown, architecture 100 processes data incoming from a plurality of channels 105, of which only three channels are shown as channels a, b, and c.
5:59-63 (17) Turning to the authentication aspect of architecture 100, authentication pipeline processing block 160 may implement an authentication pipeline 165 for authenticating the data block incoming from one of the channels 105 or the encryption pipeline processing block 130.
(11) In some embodiments, the circuitry further includes an authentication pipeline processing block for performing authentication rounds upon said data block. The authentication pipeline processing block may receive a respective hash key value for each authentication round upon said data block. The circuitry may further include an authentication key pipeline block for providing the respective hash key value for each authentication round upon said data block, by selecting, for each authentication round, the respective hash key value from at least a first hash key value corresponding to the first channel and a second hash key value corresponding to the second channel. The authentication key pipeline block may include a first set of storage circuitries for storing a plurality of powers of a first hash key value corresponding to the first channel and a second set of storage circuitries for storing a plurality of powers of a second hash key value corresponding to the first channel.
2:48-52 (8) In one embodiment, circuitry for processing data incoming from at least a first channel and a second channel is provided. The circuitry includes an encryption pipeline processing block for performing rounds of processing upon a block of said data using an encryption process. The encryption pipeline processing block receives a respective round encryption key for each round of processing upon the block of data. The circuitry also includes an encryption key pipeline block for providing the respective round encryption key for each round of processing upon the block of data. The encryption key pipeline block provides a round encryption key by selecting, for each round of processing, the respective round encryption key from at least a first round encryption key corresponding to the first channel and a second round encryption key corresponding to the second channel.
10:3-24 (36) Going back to FIG. 3, implementation 300 allows authentication pipeline processing block 350 to assemble the appropriate multiplication operands, e.g., according to at least parts of equation EQ. 1, EQ. 2, and/or EQ. 3 above, in order to generate a final authentication tag. For example, authentication pipeline processing block 350 may receive a hash subkey value H.sub.1 from register circuitry 361a, or a v.sup.th power H.sub.1.sup.v thereof (v=1, . . . , x) from one of register circuitries 361b, 361c, through 361x, all corresponding to channel a. The authentication pipeline processing block 350 may receive the hash subkey value or power thereof corresponding to the first channel a. The authentication pipeline processing block 350 may combine this received hash subkey value or power thereof with an intermediate hash value X.sub.1, received from register circuitry 301a or a power therefor X.sub.1.sup.x, also corresponding to the first channel a, using multiplication, adder and any suitable combination circuitry. The same may be done with authentication parameters for a second channel b (using hash subkey value H.sub.2, intermediate hash value X.sub.2, and/or powers of H.sub.2 and/or X.sub.2) and a third channel c (using hash subkey value H.sub.3 and intermediate hash value X.sub.3, and/or powers H.sub.3 and/or X.sub.3).
Langhammer ‘066 13:7-11 (56) By supporting pipelining and multiplier input structures as described above, systems and methods described herein may support complex logic structure (such as 128-bit Galois Field operations) and customizable multiplier input structures.
However, Langhammer ‘066 does not expressly disclose an adder configurable to receive the plurality of partial hash sequences and output a hash value based on a summation of the plurality of partial hash sequences.
Langhammer ‘807 discloses
an adder configurable to receive the plurality of partial hash sequences and output a hash value based on a summation of the plurality of partial hash sequences.
Langhammer ‘807 discloses an adder to combine multiple partial hash states to create the final hash state
[Under broadest reasonable interpretation partial can describe the hash or partial can describe the sequence
]
2:13-29 (9) Similarly, in the authentication portion, a partial hash state would be calculated for whatever channels are being worked on in the various pipes at a given time. A partial hash state is the current state of the calculation of the final hash state, updated using the last text value. In some cases, there will be multiple partial hash states valid at any time. All partial hash states, whether one or many, may be combined once text input has completed, to create the final hash state. The partial hash states would be accumulated on a per channel basis, so that, by the end of the process, complete hash state values for each channel are available. This requires keeping track of which track the hash values are currently being calculated for, as in the case of the encryption keys. But in addition, if the number of clocks between occurrences of a particular channel is too small, multiple partial hash states would have to be calculated for each channel, and those also would have to be kept track of.
2:38-40 (10) Wind-down mode detection circuitry also is provided, where wind-down is a multi-step process that combines multiple partial hashes into a final hash as described below.
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Langhammer ‘066 with the technique for an adder to combine multiple partial hash states to create the final hash state of Langhammer ‘807 to include
an adder configurable to receive the plurality of partial hash sequences and output a hash value based on a summation of the plurality of partial hash sequences.
One of ordinary skill in the art would have made this modification to improve the ability of the system to combine the hash values, such as when computing a checksum over multiple hashes. The system of the primary reference can be modified to combine multiple partial hash sequences to create a hash value, such as combining authentication tags which are final hash values that are generated by the authentication pipeline processing block 350 in figure 3 of the primary reference.
As per claim 7, the rejection of claim 1 is incorporated herein.
Langhammer ‘066 discloses wherein each of the multiple levels of pipeline stages stores an independent hash sequence.[as each round in authentication pipeline processing block 350 receives the respective hash key values, that, at least over time, creates an independent hash sequence being stored; “may receive a respective hash key value for each authentication round” 3:24-25: storage circuitries for storing a plurality of powers of a first hash key value 3:32-34; if a plurality of powers is stored, that means there is a plurality of hashes being stored also]
Langhammer ‘066 3:21-36 (11) In some embodiments, the circuitry further includes an authentication pipeline processing block for performing authentication rounds upon said data block. The authentication pipeline processing block may receive a respective hash key value for each authentication round upon said data block. The circuitry may further include an authentication key pipeline block for providing the respective hash key value for each authentication round upon said data block, by selecting, for each authentication round, the respective hash key value from at least a first hash key value corresponding to the first channel and a second hash key value corresponding to the second channel. The authentication key pipeline block may include a first set of storage circuitries for storing a plurality of powers of a first hash key value corresponding to the first channel and a second set of storage circuitries for storing a plurality of powers of a second hash key value corresponding to the first channel.
`
As per claim 10, Langhammer ‘066 discloses A method [methods for providing encryption and/or authentication architectures for processing data incoming from multiple channels, 2:33-35] comprising:
decomposing a hash sequence, [in figure 3 there is a H hash sequence and also X hash sequence, these hashes are incoming data from one or more channels, 2:33-35; as shown in the figure, the hash values are organized by 4 powers, e.g. powers (exponents) 0-3, therefore disclosing decomposing ] wherein the hash sequence is decomposed into a sum [all the Langhammer ‘066 grouped hashes together would be the original hash sequence as shown in figure 3] of multiple independent hash sequences;[ multiple independent hash sequences as seen in figure 3, where the hashes are grouped by 4 powers, e.g. powers (exponents) 0-3]
iteratively performing [repeatedly processed to generate a hash or pre-tag value, 9:25-27; the iteration can also read on X (intermediate hash value 10:16-17) being repeatedly applied to combine with H (10:12-24), and then the output X value is written to the registers such as register circuitry 301a in figure 3] Galois field multiplication operations [this hash function may implement multiplication within the binary Galois field, 9:27-28] using integrated circuitry [may be configured into a programmable integrated circuit device 2:44-45] over a plurality of iterations [repeatedly processed to generate a hash or pre-tag value, 9:25-27] on each of the multiple independent hash sequences;[as shown in figure 3, the groupings of hashes H, and the groupings of hashes X, are input into the authentication pipeline processing block 350]
2:42-45 a scalable and efficient cryptographic architecture may be implemented as circuitry in a fixed logic device, or may be configured into a programmable integrated circuit device
after a first of the plurality of iterations has completed, [authentication round generating intermediate hash (or pre-tag) value X 9:32-33] storing a first partial hash sequence of the first of the plurality of iterations in a first pipeline stage; [the authentication rounds generate the intermediate hash (or pre-tag value) 9:32-37; generating will disclose storing the output (intermediate hash (or pre-tag) value X 9:32-33) at least temporarily until the next round. For example, the authentication round 351 as depicted in FIG. 3 generating intermediate hash, the pre-tag (9:32-33); intermediate hash that is stored in the authentication round discloses partial hash sequence because it is part of the sequence occurring over time that is stored at that authentication round. The intermediate hashes that are stored at a particular authentication round over time is a hash sequence]
after a second [repeatedly processed to generate a hash or pre-tag value, 9:25-27] of the plurality of iterations has completed, [authentication round generating intermediate hash (or pre-tag) value X 9:32-33] storing a second partial hash sequence of the second of the plurality of iterations in the first pipeline stage [repeatedly processed to generate a hash or pre-tag value, 9:25-27; generating will disclose storing the output (Langhammer ‘066 intermediate hash (or pre-tag) value X 9:32-33) at least temporarily until the next round; intermediate hash that is stored in the authentication round discloses partial hash sequence because it is part of the sequence occurring over time that is stored at that authentication round. The intermediate hashes that are stored at a particular authentication round over time is a hash sequence], wherein the first partial hash sequence transitions to a second pipeline stage;[ in Langhammer ‘066, to generate the pre-tag, which requires addition and multiplication as shown in any one of the equations 1, 2, or 3 at 9:42, 9:51, and 9:63, respectively, the generated output from each of the rounds (the first partial hash sequence) must move to the next round in order to generate the final authentication tag 10:8; note that all the information from the various rounds must be assembled (10:4), to generate a final authentication tag (10:7)]
However, Langhammer ‘066 does not expressly disclose
performing addition operations on the first partial hash sequence and the second partial hash sequence to output a hash value.
Langhammer ‘807 discloses
Langhammer ‘807 discloses an adder to combine multiple partial hash states to create the final hash state
2:13-29 (9) Similarly, in the authentication portion, a partial hash state would be calculated for whatever channels are being worked on in the various pipes at a given time. A partial hash state is the current state of the calculation of the final hash state, updated using the last text value. In some cases, there will be multiple partial hash states valid at any time. All partial hash states, whether one or many, may be combined once text input has completed, to create the final hash state. The partial hash states would be accumulated on a per channel basis, so that, by the end of the process, complete hash state values for each channel are available. This requires keeping track of which track the hash values are currently being calculated for, as in the case of the encryption keys. But in addition, if the number of clocks between occurrences of a particular channel is too small, multiple partial hash states would have to be calculated for each channel, and those also would have to be kept track of.
2:38-40 (10) Wind-down mode detection circuitry also is provided, where wind-down is a multi-step process that combines multiple partial hashes into a final hash as described below.
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Langhammer ‘066 with the technique for an adder to combine multiple partial hash states to create the final hash state of Langhammer ‘807 to include
performing addition operations on the first partial hash sequence and the second partial hash sequence to output a hash value.
One of ordinary skill in the art would have made this modification to improve the ability of the system to combine the hash values, such as when computing a checksum over multiple hashes. The system of the primary reference can be modified to combine multiple partial hash sequences to create a hash value, such as combining authentication tags which are final hash values that are generated by the authentication pipeline processing block 350 in figure 3 of the primary reference.
As per claim 11, the rejection of claim 10 is incorporated herein.
Langhammer ‘066 discloses wherein iteratively performing the Galois field multiplication operations is carried out using programmable logic and digital signal processing (DSP) blocks of a field programmable gate array.
2:33-38 (6) The present disclosure relates to systems and methods for providing encryption and/or authentication architectures for processing data incoming from multiple channels. These architectures can be implemented as circuitry in a fixed logic device, or can be configured into a programmable integrated circuit device such as a programmable logic device (PLD).
13:34-45 (59) various elements of this invention can be provided on in a fixed logic device, or can be configured into a programmable integrated circuit device such as a programmable logic device (PLD) in any desired number and/or arrangement. For example, it should be understood that embodiments of the present invention may be used in numerous types of integrated circuits, including field programmable gate array device (FPGAs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), programmable logic arrays (PLAs), digital signal processors (DSPs) and application specific integrated circuits (ASICs).
As per claim 13, the rejection of claim 10 is incorporated herein.
Langhammer ‘066 discloses where a number of iterations of the plurality of iterations is at least four. [repeatedly processed to generate a hash or pre-tag value, 9:25-27; the iteration can also read on X (intermediate hash value 10:16-17) being repeatedly applied to combine with H (10:12-24), and then the output X value is written to the registers such as register circuitry 301a in figure 3; as shown in figure 3, there appears to be a long stream of hashes which would cause the iteration to be greater than four; also hash value X is repeatedly generated and updated in the registries and re-received to regenerate in authentication pipeline processing block 350, as depicted in figure 3]
As per claim 14, the rejection of claim 13 is incorporated herein.
Langhammer ‘066 discloses wherein a number of pipeline stages corresponds [as shown in Langhammer ‘066 figure 3, there are 4 pipeline stages (rounds) 351, 252, 353, and 350 inside authentication pipeline processing block 350, also the word corresponds under broadest reasonable interpretation can be just simply that the pipeline stages have some relationship such as interaction with the multiple independent hash sequences;]
to a number of multiple independent hash sequences.
[a number of multiple independent hash sequences can be disclosed by each independent hash sequence is, for example, X with the same subscript and four different exponents: (no exponent), exponent is 1, exponent is 2, and exponent is 3, as these are input into the authentication pipeline processing block 350 ]
Claim 2-5, 8, and 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Langhammer ‘066 in view of Langhammer ‘807, further in view of Filseth et al. U.S. Publication 20100057823 (hereinafter “Filseth”).
As per claim 2, the rejection of claim 1 is incorporated herein.
However, the combination of Langhammer ‘066 and Langhammer ‘807 does not expressly disclose wherein the multiple levels of pipelined stages use a plurality of registers, wherein the plurality of registers operate on different clock cycles.
Filseth discloses pipelining with registers to store intermediate results from one clock cycle to the next
[wherein the plurality of registers operate on different clock cycles is disclosed because as the data moves down the pipeline between the registers, the registers each take turns storing the data at a different clock cycle]
[0072] The overall AES calculation is generally a serial process involving hundreds of levels of logic gates, each depending on the previous level. An integrated circuit (die or chip) in which a non-pipelined AES implementation is embedded may therefore be clocked sufficiently slowly for the entire calculation to finish by the combinational propagation of signals. In some embodiments, the circuitry may be pipelined with registers (or flip-flops) included in the data path to store intermediate results from one clock cycle to the next. The registers may be added in sufficient numbers and optimal positions, depending on the clock period and on when various external control signals become available. As shown in FIG. 5, pipeline registers may be added before each alternate Galois Field inversion and after each matrix 1/D multiplication.
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified the combination of Langhammer ‘066 and Langhammer ‘807 with the technique for pipelining with registers to store intermediate results from one clock cycle to the next of Filseth to include wherein the multiple levels of pipelined stages use a plurality of registers, wherein the plurality of registers operate on different clock cycles.
One of ordinary skill in the art would have made this modification to improve the ability of the system to store intermediate results between the stages of the pipeline to implement the pipeline. The system of the primary reference can be modified to include the registers between the pipeline stages to store intermediate results between pipeline stages.
As per claim 3, the rejection of claim 2 is incorporated herein.
Langhammer ‘066 discloses wherein the multiple levels of pipelined stages corresponds [as shown in Langhammer ‘066 figure 3, there are 4 pipeline stages (authentication rounds) 351, 252, 353, and 350 inside authentication pipeline processing block 350, and looking at hashes H or X, there are four powers for each hash; also the word corresponds under broadest reasonable interpretation can be just simply that the pipeline stages have some relationship such as interaction with the plurality of powers] to the plurality of powers of the hash key. [authentication pipeline processing block 350 may receive a hash subkey value H.sub.1 from register circuitry 361a, or a v.sup.th power H.sub.1.sup.v thereof, 10:8-10;10:12-14 The authentication pipeline processing block 350 may receive the hash subkey value or power thereof corresponding to the first channel a; ]
As per claim 4, the rejection of claim 3 is incorporated herein.
Langhammer ‘066 discloses wherein a number of the plurality of powers of the hash key is four. [as shown in Langhammer ‘066 figure 3, there are 4 pipeline stages 351, 352, 353, and 354 inside authentication pipeline processing block 350, and looking at hashes H or X, there are four powers for each hash]
As per claim 5, the rejection of claim 4 is incorporated herein.
Langhammer ‘066 discloses wherein a number of the multiple levels of pipelined stages is four. [as shown in Langhammer ‘066 figure 3, there are 4 pipeline stages 351, 352, 353, and 354 inside authentication pipeline processing block 350]
As per claim 8, the rejection of claim 2 is incorporated herein.
Langhammer ‘066 discloses wherein the integrated circuit is implemented in programmable logic and digital signal processing (DSP) blocks of a field programmable gate array.
2:33-38 (6) The present disclosure relates to systems and methods for providing encryption and/or authentication architectures for processing data incoming from multiple channels. These architectures can be implemented as circuitry in a fixed logic device, or can be configured into a programmable integrated circuit device such as a programmable logic device (PLD).
13:34-45 (59) various elements of this invention can be provided on in a fixed logic device, or can be configured into a programmable integrated circuit device such as a programmable logic device (PLD) in any desired number and/or arrangement. For example, it should be understood that embodiments of the present invention may be used in numerous types of integrated circuits, including field programmable gate array device (FPGAs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), programmable logic arrays (PLAs), digital signal processors (DSPs) and application specific integrated circuits (ASICs).
As per claim 8, the rejection of claim 2 is incorporated herein.
Langhammer ‘066 discloses wherein the integrated circuit is implemented in programmable logic and digital signal processing (DSP) blocks of a field programmable gate array.
2:33-38 (6) The present disclosure relates to systems and methods for providing encryption and/or authentication architectures for processing data incoming from multiple channels. These architectures can be implemented as circuitry in a fixed logic device, or can be configured into a programmable integrated circuit device such as a programmable logic device (PLD).
13:34-45 (59) various elements of this invention can be provided on in a fixed logic device, or can be configured into a programmable integrated circuit device such as a programmable logic device (PLD) in any desired number and/or arrangement. For example, it should be understood that embodiments of the present invention may be used in numerous types of integrated circuits, including field programmable gate array device (FPGAs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), programmable logic arrays (PLAs), digital signal processors (DSPs) and application specific integrated circuits (ASICs).
As per claim 12, the rejection of claim 10 is incorporated herein.
However, the combination of Langhammer ‘066 and Langhammer ‘807 does not expressly disclose wherein the first pipeline stage uses a first register and the second pipeline stage uses a second register.
Filseth discloses pipelining with registers to store intermediate results from one clock cycle to the next
[wherein the first pipeline stage uses a first register and the second pipeline stage uses a second register is disclosed because as the data moves down the pipeline between the registers, the registers each take turns storing the data at a different clock cycle]
[0072] The overall AES calculation is generally a serial process involving hundreds of levels of logic gates, each depending on the previous level. An integrated circuit (die or chip) in which a non-pipelined AES implementation is embedded may therefore be clocked sufficiently slowly for the entire calculation to finish by the combinational propagation of signals. In some embodiments, the circuitry may be pipelined with registers (or flip-flops) included in the data path to store intermediate results from one clock cycle to the next. The registers may be added in sufficient numbers and optimal positions, depending on the clock period and on when various external control signals become available. As shown in FIG. 5, pipeline registers may be added before each alternate Galois Field inversion and after each matrix 1/D multiplication.
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified the combination of Langhammer ‘066 and Langhammer ‘807 with the technique for pipelining with registers to store intermediate results from one clock cycle to the next of Filseth to include wherein the first pipeline stage uses a first register and the second pipeline stage uses a second register.
One of ordinary skill in the art would have made this modification to improve the ability of the system to store intermediate results between the stages of the pipeline to implement the pipeline. The system of the primary reference can be modified to include the registers between the pipeline stages to store intermediate results between pipeline stages.
Claim 6 is/are rejected under 35 U.S.C. 103 as being unpatentable over Langhammer ‘066 in view of Langhammer ‘807, further in view of Mueller et al. U.S. Publication 20240053963 (hereinafter “Mueller”).
As per claim 6, the rejection of claim 1 is incorporated herein.
However, the combination of Langhammer ‘066 and Langhammer ‘807 does not expressly disclose wherein the Galois field multiplier comprises polynomial multiplication circuitry and modular reduction circuitry.
Mueller discloses wherein the Galois field multiplier comprises polynomial multiplication circuitry and modular reduction circuitry.
[0005] The present disclosure appreciates that multiple commonly used encryption functions, such as AES (Advanced Encryption Standard)-GCM (Galois Counter Mode) and AES-XTS (XEX-based tweaked-codebook mode with ciphertext stealing), utilize Galois multiplication (i.e., carryless multiplication and modular reduction) to logically combine encryption operands. For example, AES-GCM and AES-XTS both use a Galois multiplication in the GF(2{circumflex over ( )}128) field defined by the fixed polynomial g(x)=1+X+x{circumflex over ( )}2+x{circumflex over ( )}7+x{circumflex over ( )}128. In AES-GCM, Galois multiplications are used to generate a signature for an encrypted message, which can be utilized during decryption to detect whether the ciphertext or signature has been tampered with. In AES-XTS, the Galois multiplications are employed as part of the encryption and decryption of the message itself. The present disclosure discloses various embodiments of circuits for implementing Galois multiplication in hardware and an associated Galois multiplication instruction.
[0053] Galois multiplication, for example, as employed in GCM multiply function 524 of FIG. 5, involves a carryless multiply followed by a modular reduction. For example, in one embodiment, a carryless multiplication of two 128-bit input operands A and B produces a 255-bit product P. Modular reduction modulo polynomial g(x) reduces P to a 128-bit number through an iterative process.
[0056] Given this understanding of the process of modular reduction, reference is now made to FIG. 6, which is a block diagram of a modular reduction circuit 600 for performing modular reduction in the Galois Field with polynomial g(x) in accordance with one embodiment.
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified the combination of Langhammer ‘066 and Langhammer ‘807 with the technique for providing circuitry that implements a Galois field multiplier that includes polynomial multiplication and modular reduction of Mueller to include wherein the Galois field multiplier comprises polynomial multiplication circuitry and modular reduction circuitry.
One of ordinary skill in the art would have made this modification to improve the ability of the system to perform polynomial multiplication and modular reduction, to facilitate encryption and other applications. The system of the primary reference can be modified so that the Galois field multiplier (e.g., authentication pipeline processing block 350) can include the multiplication and modular reduction capabilities.
Claim 9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Langhammer ‘066 in view of Langhammer ‘807, in view of Filseth, further in view of Langhammer et al. U.S. Publication 20210216318 (hereinafter “Langhammer ‘318”).
As per claim 9, the rejection of claim 8 is incorporated herein.
However, the combination of Langhammer ‘066, Langhammer ‘807, and Filseth does not expressly disclose wherein the DSP blocks of the field programmable gate array comprises the plurality of registers.
Langhammer ‘318 discloses wherein the DSP blocks of the field programmable gate array comprises the plurality of registers [wherein the plurality of DSP blocks comprises at least a portion of the plurality of vector registers., para. 545; digital signal processing (DSP) blocks) that are included in an FPGA., Para. 92 ]
[0092] More specifically, this disclosure discusses vector processing systems (e.g., vector processors) that can be implemented on integrated circuit devices, including programmable logic devices such as field-programmable gate arrays (FPGAs). As discussed herein, the vector processing systems may harness hard logic and soft logic of an FPGA to perform vector processing. As used herein, “hard logic” generally refers to portions of an integrated circuit device (e.g., a programmable logic device) that are not programmable by an end user, and the portions of the integrated circuit device that are programmable by the end user are considered “soft logic.” For example, hard logic elements in an FPGA may include arithmetic units (e.g., digital signal processing (DSP) blocks) that are included in an FPGA and unchangeable by the end user. Vector processing units that perform operations (e.g., vector math operations) may be implemented as hard logic on an FPGA that is able to perform the specific operations at a relatively higher efficiency (e.g., compared to performing the operations using soft logic). Values to be processed, such as vectors or scalars, may be read from and stored in memory that is included in the FPGA. That is, an integrated circuit device may include memory that is a “hard” feature, meaning the memory is included on the integrated circuit device (e.g., when provided to an end user). As also discussed below, routing between the vector processing units and memory may be implemented using a combination of hard logic and soft logic. Accordingly, the techniques described below harness the flexibility of soft logic and hard features (e.g., hard logic and memory blocks) of FPGAs to provide customizable and efficient vector processing architectures capabilities.
[0259] Having discussed various memory considerations the compiler 16 may make, the discussion will now turn to intra-lane connectivity patterns and how the compiler 16 may select which patterns will be used in a hardware implementation of a vector processing system 26. For instance, many applications may involve steps in which results are aggregated across lanes 82 of the vector processing system 26. One example from AI applications may include summing together all of the individual lane results (e.g., performing an additive reduction or accumulation) and then selecting the maximum value across the lanes. Another example is combining elements with a bitwise operation (e.g., XOR to compute a summation in a Galois field) or selectively combining elements (e.g., performing a conditional operation to determine a sum if a corresponding flag is present).
[0545] The integrated circuit device of clause 80, comprising a plurality of digital signal processing (DSP) blocks, wherein the plurality of DSP blocks comprises at least a portion of the plurality of vector registers.
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified the combination of Langhammer ‘066, Langhammer ‘807, and Filseth with the technique for including registers within DSP blocks of a field programmable gate array of Langhammer ‘318 to include wherein the DSP blocks of the field programmable gate array comprises the plurality of registers.
One of ordinary skill in the art would have made this modification to improve the ability of the system to utilize registers for storing data in the DSP blocks, to facilitate pipelining. The system of the primary reference can be modified to include registers in the DSP blocks of the field programmable gate array.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HOWARD H LOUIE whose telephone number is (571)272-0036. The examiner can normally be reached on Monday-Friday 9 AM-5 PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung W. Kim can be reached on 571-272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HOWARD H. LOUIE/Examiner, Art Unit 2494
/THEODORE C PARSONS/Primary Examiner, Art Unit 2494
1 Emphasis is additional throughout.