DETAILED ACTION
Claims 1-20 are presented on 06/30/2023 for examination on merits. Claims 1, 8, and 15 are independent base claims.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Examiner's Instructions for filing Response to this Office Action
When the Applicant submits amendments regarding to the claims in response the Office Action, the Examiner would appreciate Applicant if a clean copy of the claims is provided to facilitate the prosecution which otherwise requires extra time for editing the marked-up claims from OCR.
Please submit two sets of claims:
Set #1 as in a typical filing which includes indicators for the status of claim and all marked amendments to the claims; and
Set #2 as an appendix to the Arguments/Remarks for a clean version of the claims which has all the markups removed for entry by the Examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(B) CONCLUSION—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 5, 12, and 18 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
The rejection(s) under 35 U.S.C. 112(b) is/are determined by the following reasons:
Claims 5, 12, and 18 each recite a limitation “the outputs of the SHA-3 engines” unclearly or lacking sufficient antecedent basis.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claims 1-3, 8-10, and 15-16 are rejected under 35 U.S.C. 103 as being unpatentable over ABDULGADIR (US 20240421993 A1; hereinafter “Abdul”) in view of GARCIA MORCHON (WO 2021197841 A1; hereinafter “Garcia”).
As per claim 1, Abdul teaches a system on chip comprising:
a processor core (Abdul par. 0006-0007: a processor; a protected, specialized coprocessor is a processor core); and
a Kyber hardware accelerator, the Kyber hardware accelerator (Abdul par. 0008: an efficient hardware accelerator for Kyber key encapsulation) comprising:
two or more Secure Hash Algorithm (SHA)-3 engines, … to perform in parallel an independent operation on the same seed for one or more operations to generate a key for Kyber public-key encryption (Abdul par. 0035-0039: perform the algorithms that compose the KYBER-KEM algorithms; par. 0039-0041: SHA3 operations in parallel to improve speed; the SHA3 unit 101 is operably configured to perform the hashing operations and operably configured to transfer sampling input data to at least one sampling unit 102. FIG. 4 shows the hash and sampling modules run in three PISO in parallel with the SHA3 unit).
However, Abdul does not explicitly disclose a same seed is received for the parallel operations. This aspect of the claim is identified as a further difference.
In a related art, Garcia teaches:
each SHA-3 engine to receive a same seed in parallel (Garcia, page 13, lines 24-34 and page 14, lines 1-8: the same seed can be used; For example, a process i may be initiated with a seed s.sub.t = (s, cq), wherein a.sub.t is a unique number. …, one may initiate a first data vector with t copies of seed, wherein t is the number of parallel process supported by the size of a data vector.)
Abdul and Garcia are analogous art to the claimed invention in the same field of endeavor as the claimed invention, or reasonably pertinent to the problem faced by the inventor, which may be in a different field. Thus, it would have been obvious to one of ordinary in the art, before the effective filing date of the claimed invention, to modify Abdul’s system with Garcia’s teachings of receiving a same seed for the paralleled processing at the SHA3 engine. For this combination, the motivation would have been to improve the level of security in the parallel key generation.
As per claim 2, the references as combined above teach the system on chip of claim 1, wherein the one or more operations to generate the key for Kyber public-key encryption comprises operations performed on the two or more SHA-3 engines to generate Matrix A (Garcia, page, lines 23-26: generate the same random matrix, e.g., by generating from the same seed).
As per claim 3, the references as combined above teach the system on chip of claim 2, wherein a number of SHA-3 engines is four, each SHA-3 engine to
receive a respective counter value, each respective counter value concatenated with the seed to generate a unique pseudorandom stream for different polynomials of the Matrix A (Garcia, page 9, lines 5-14: the random number initiation function, which generates the random number and bits to fill a part of matrix; page 9, line 22-29: deriving a random number, For example, this may update the seed to a new seed and produce a new random number. The bit-size of the random number may be the same as the bit-size of matrix element. Note that the 1-bit random number acts as a counter for the matrix element).
Regarding claims 8-10, they are similar to claims 1-3 in terms of recited features, respectively; and thus, claims 8-10 are rejected for the same reasons.
Regarding claims 15-16, they are similar to claims 1-2 in terms of recited features, respectively; and thus, claims 15-16 are rejected for the same reasons.
Claims 4, 6-7, 11, 13-14, 17 and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Abdul and Garcia, as applied to claim 1, and further in view of Cheon (US 20240178992 A1).
As per claim 4, the references as combined above teach the system on chip of claim 3, but do not explicitly disclose that an extendable output function (XOF) is used to process an element of Matrix A. This aspect of the claim is identified as a further difference.
In a related art, Cheon teaches:
wherein each of the SHA-3 engines is to perform an extendable output function (XOF) to process an element of Matrix A (Cheon par. 0009 and 0016: applying an extendable-output function (XOF) for the pre-stored seed, obtaining the random matrix (A) by applying a random matrix sampler function).
Cheon is analogous art to the claimed invention in the same field of endeavor as the claimed invention, or reasonably pertinent to the problem faced by the inventor, which may be in a different field. Thus, it would have been obvious to one of ordinary in the art, before the effective filing date of the claimed invention, to modify the Abdul-Garcia system with Cheon’s teachings of an extendable output function (XOF). For this combination, the motivation would have been to improve the generation of matrix with higher predictability of the number of bytes needed in the stream cipher.
As per claim 6, the references as combined above teach the system on chip of claim 1, and, but do not explicitly disclose the two portions are used for generating secret vectors wherein a first operation to generate secret vector a is performed on a first portion of the two or more SHA-3 engines and a second operation to generate secret vector e is performed on a second portion of the two or more SHA-3 engines, secret vector a and secret vector e used to generate the key for Kyber public-key encryption. This aspect of the claim is identified as a further difference.
In a related art, Cheon teaches:
wherein a first operation to generate secret vector a is performed on a first portion of the two or more SHA-3 engines and a second operation to generate secret vector e is performed on a second portion of the two or more SHA-3 engines, secret vector a and secret vector e used to generate the key for Kyber public-key encryption (Cheon, par. 0015-0016: The generating the public key may include obtaining a random matrix (A) composed of randomly decided vectors, which also include vector b. Cheon discloses at least vectors a and b are used for generating the public key; see par. 0018-0019, 0106, and 0116-0123.).
Cheon is analogous art to the claimed invention in the same field of endeavor as the claimed invention, or reasonably pertinent to the problem faced by the inventor, which may be in a different field. Thus, it would have been obvious to one of ordinary in the art, before the effective filing date of the claimed invention, to modify the Abdul-Garcia system with Cheon’s teachings of using multiple parallel vectors or execution units for fast processing. For this combination, the motivation would have been to improve the speed of generation of matrix with multiple parallel vectors or execution units.
As per claim 7, the references as combined above teach the system on chip of claim 6, and Abdul also teaches:
wherein a number of SHA-3 engines is four, the first portion is two and the second portion is two (Abdul, par. 0039-0041: The datapath submodules can run in parallel to improve speed; note that the submodules are mapped to a number of SHA-3 engines running in parallel; par. 0040: the RAM BANK 1-3 submodules are [used]. Parallel-In-Serial-Out (PISO) subfunctions are used; par. 0043: This submodule 122 beneficially utilizes two butterfly units 109, 110 to process two operations in parallel to improve speed, the two butterfly units are functionally equivalent to the first portion is two and the second portion. Note that the features that a number of SHA-3 engines is four and that the first portion is two and the second portion is two are also a design choice). Abdul is similarly combined for the reasons as indicated above.
Regarding claims 11 and 13-14, they are similar to claims 4 and 6-7 in terms of recited features, respectively; and thus, claims 11 and 13-14 are rejected for the same reasons.
Regarding claims 17 and 19-20, they are similar to claims 4 and 6-7 in terms of recited features, respectively; and thus, claims 17 and 19-20 are rejected for the same reasons.
Allowable Subject Matter
Claims 5, 12, and 18 are objected to as being dependent upon a rejected base claims but would be allowable if rewritten in independent form including all of the limitations of the base claims and any intervening claims.
Claims 5, 12, and 18 each recite elements of “wherein coefficient outputs of a parse function performed in parallel on each of the outputs of the SHA-3 engines are written to a same memory location in a memory in the Kyber hardware accelerator”. These elements and the features thereof in combination with the other limitations in the limitations of the base claims and any intervening claims, are not anticipated by, nor made obvious over the prior art of record.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure as the prior art additionally discloses certain parts of the claim features (See “PTO-892 Notice of Reference Cited”).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DON ZHAO whose telephone number is (571)272.9953. The examiner can normally be reached on Monday to Friday, 7:30 A.M to 5:00 P.M EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl G Colin can be reached on 571.272.3862. The fax phone number for the organization where this application or proceeding is assigned is 571.273.8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866.217.9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800.786.9199 (IN USA OR CANADA) or 571.272.1000.
/Don G Zhao/Primary Examiner, Art Unit 2493 08/26/2026