DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This Office Action is in response to application 18/327,102 filed on 6/1/2023.
The examiner notes the IDS(s) filed on 6/1/2023 has been considered.
Claim Interpretation
The examiner notes the following claim interpretation: Regarding Claim(s) 11; “computer readable storage medium” is noted to be statutory based on the definition found in Applicant’s Specification ⁋[0028] – “A computer readable storage medium, as that term is used in the present disclosure, is not to be construed as storage in the form of transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide, light pulses passing through a fiber optic cable, electrical signals communicated through a wire, and/or other transmission media..” Therefore, the examiner construes that “computer readable storage medium” is statutory under 35 U.S.C. 101.
Claim Objections
Claim(s) 19 and 20 is/are objected to because of the following informalities:
Regarding Claim(s) 19 and 20; claims 19 and 20 recite in the preamble “The system of claim 10,...” however claim 10 is a method claim. The examiner notes for better clarity to further amend the preamble to “The system of claim 12, ...”. Appropriate correction is required. For the purposes of examination the examiner will consider claim(s) 19 and 20 to depend off of claim 12.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim(s) 1-10, 13 and 14 is/are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding Claim 1; Claim 1 recites the limitation "the principal evaluation key" in limitation 3. There is insufficient antecedent basis for this limitation in the claim.
Regarding Claim(s) 2-10; claim(s) 2-10 are dependent on claim 1, and therefore inherit 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, issues of the independent claims.
Regarding Claim(s) 3-4 and substantially similar Claim(s) 13-14; claim(s) 3-4 and substantially similar claim(s) 13-14 recites the limitation "the department HE rotation keys" in limitation. There is insufficient antecedent basis for this limitation in the claim. The examiner notes this should be “the plurality of department HE rotation keys”
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claim(s) 1, 5, 9-12, 15, 19 and 20 is/are rejected under 35 U.S.C. 102(a)(2) as being anticipated by No et al. (US 2023/0254125 A1).
Regarding Claim 1;
No discloses a low bandwidth homomorphic encryption (HE) key generation method ([0039] – a homomorphic encryption operation... low specification client), comprising:
generating, at a principal instance of an organization unit, a principal HE key set, wherein the principal HE key set comprises a principal public key, a principal secret key, and a plurality of principal rotation keys (FIG. 2 and [0039]-[0040] - For a homomorphic encryption operation, several GB to several hundred GB of operation keys (for example, rotation operation keys, key switching keys, etc.) are required for each client... The homomorphic encryption operation key management system 100 according to an embodiment may store the public key (operation key) received from the client 200, generate a derived key (another operation key) based on the stored public key, and transmit the stored public key and derived keys to the server 300 requiring the homomorphic encryption operation in relation to the client 200 and [0047] and [0075] - In an embodiment, the homomorphic encryption operation key management system 100 may generate a plurality of homomorphic rotation operation keys using one or more public keys received from the client 20. The one or more public keys may include a public key generated using a secret key of the client 200 and one or more hierarchical Galois keys. A public key for a homomorphic encryption operation may be expressed as a polynomial);
generating a department HE key set for each of a plurality of departments in the organization unit, wherein the set of department HE encryption keys each comprises a department public key, a department secret key, and department key switching keys (FIG. 2 and [0039]-[0040] - For a homomorphic encryption operation, several GB to several hundred GB of operation keys (for example, rotation operation keys, key switching keys, etc.) are required for each client... The homomorphic encryption operation key management system 100 according to an embodiment may store the public key (operation key) received from the client 200, generate a derived key (another operation key) based on the stored public key, and transmit the stored public key and derived keys to the server 300 requiring the homomorphic encryption operation in relation to the client 200 and [0047]and [0075] - In an embodiment, the homomorphic encryption operation key management system 100 may generate a plurality of homomorphic rotation operation keys using one or more public keys received from the client 20. The one or more public keys may include a public key generated using a secret key of the client 200 and one or more hierarchical Galois keys. A public key for a homomorphic encryption operation may be expressed as a polynomial]);
transmitting the principal public key, the principal evaluation key, and the plurality of principal rotation keys to a data processor ([0039] - For a homomorphic encryption operation, several GB to several hundred GB of operation keys (for example, rotation operation keys, key switching keys, etc.) are required for each client. Generating, storing, and transmitting all operation keys, each of which is a type of public key, from the client to the server, to which an operation is delegated, causes a cost problem in a relatively low-specification client and [0040] - The homomorphic encryption operation key management system 100 according to an embodiment may store the public key (operation key) received from the client 200, generate a derived key (another operation key) based on the stored public key, and transmit the stored public key and derived keys to the server 300 requiring the homomorphic encryption operation in relation to the client 200 and [0064] - In response to a request for an operation key from the server 300, the processor 110 may first search the memory 120 for the operation key, and may immediately transmit the operation key to the server 300 when the operation key is stored. When the operation key is not found in the memory 120, the processor 110 may generate an operation key using one or more public keys of the client 200),
transmitting, by at least one of the plurality of departments to the data processor, at least one department public key, and department key switching keys to the data processor ([0039] - For a homomorphic encryption operation, several GB to several hundred GB of operation keys (for example, rotation operation keys, key switching keys, etc.) are required for each client. Generating, storing, and transmitting all operation keys, each of which is a type of public key, from the client to the server, to which an operation is delegated, causes a cost problem in a relatively low-specification client and [0040] - The homomorphic encryption operation key management system 100 according to an embodiment may store the public key (operation key) received from the client 200, generate a derived key (another operation key) based on the stored public key, and transmit the stored public key and derived keys to the server 300 requiring the homomorphic encryption operation in relation to the client 200 and [0064] - In response to a request for an operation key from the server 300, the processor 110 may first search the memory 120 for the operation key, and may immediately transmit the operation key to the server 300 when the operation key is stored. When the operation key is not found in the memory 120, the processor 110 may generate an operation key using one or more public keys of the client 200); and
transmitting, by the at least one of the plurality of departments to the data processor, an encrypted data file to be processed at least in part using a department rotation key generated at the data processor (FIG. 2 – Cipher Text and [0003] - a plaintext obtained by decrypting the ciphertext is the same as an operation result of original data before encryption and [0039]-[0040] – rotation operation keys and [0064]).
Regarding Claim 5;
No discloses the method to claim 1.
No further discloses wherein the department key set is generated at the principal instance of the organization unit keys (FIG. 2 and [0039]-[0040] - For a homomorphic encryption operation, several GB to several hundred GB of operation keys (for example, rotation operation keys, key switching keys, etc.) are required for each client... The homomorphic encryption operation key management system 100 according to an embodiment may store the public key (operation key) received from the client 200, generate a derived key (another operation key) based on the stored public key, and transmit the stored public key and derived keys to the server 300 requiring the homomorphic encryption operation in relation to the client 200 and [0047] and [0075] - In an embodiment, the homomorphic encryption operation key management system 100 may generate a plurality of homomorphic rotation operation keys using one or more public keys received from the client 20. The one or more public keys may include a public key generated using a secret key of the client 200 and one or more hierarchical Galois keys. A public key for a homomorphic encryption operation may be expressed as a polynomial and);
Regarding Claim 9;
No discloses the method to claim 1.
No further discloses wherein the data processor comprises an untrusted cloud computing provider ([0003] - ...data may be outsourced to a commercial cloud service in an encrypted state and processed in the encrypted state.)
Regarding Claim 10;
No discloses the method to claim 1.
No further discloses wherein: the principal HE key set further comprises a principal HE evaluation key (FIG. 2 and [0039]-[0040] - For a homomorphic encryption operation, several GB to several hundred GB of operation keys (for example, rotation operation keys, key switching keys, etc.) are required for each client... and [0047] and [0061] - The hierarchical Galois key is a type of public key capable of generating an operation key (evaluation key) for a rotation operation of a homomorphic ciphertext); the sets of department HE encryption keys each further comprise a department HE evaluation key (FIG. 2 and [0039]-[0040] - For a homomorphic encryption operation, several GB to several hundred GB of operation keys (for example, rotation operation keys, key switching keys, etc.) are required for each client... and [0047] and [0061] - The hierarchical Galois key is a type of public key capable of generating an operation key (evaluation key) for a rotation operation of a homomorphic ciphertext); and the department HE key switching keys comprise a dept-to-org key switching key and an org-to-dept key switching key (FIG. 2 and [0039]-[0040] - For a homomorphic encryption operation, several GB to several hundred GB of operation keys (for example, rotation operation keys, key switching keys, etc.) are required for each client... and [0047] and [0061] - The hierarchical Galois key is a type of public key capable of generating an operation key (evaluation key) for a rotation operation of a homomorphic ciphertext). The examiner respectfully notes that “dept-to-org” and “org-to-dept” labeling is noted to be non-functional descriptive material as it does not impart any functionally to the key switching keys.
Regarding Claim(s) 11; claim(s) 11 is/are directed to a/an program product associated with the method claimed in claim(s) 1. Claim(s) 11 is/are similar in scope to claim(s) 1, and is/are therefore rejected under similar rationale.
Regarding Claim(s) 12, 15, 19, and 20; claim(s) 12, 15, 19, and 10 is/are directed to a/an system associated with the method claimed in claim(s) 1, 5, 9, and 10. Claim(s) 12, 15, 19, and 20 is/are similar in scope to claim(s) 1, 5, 9, and 10, and is/are therefore rejected under similar rationale.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 2-3 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over No et al. (US 2023/0254125 A1) in view of Lee et al. (US 2023/0246807 A1).
Regarding Claim 2;
No discloses the method to claim 1.
No further discloses a plurality of department HE rotation keys and plurality of principal rotation keys and department key switching keys (FIG. 2 and [0039]-[0040] and [0047]).
No fails to explicitly disclose wherein [a rotation key] is generated at the data processor from [a] rotation key and [a] switching key.
However, in an analogous art, Lee teaches herein [a rotation key] is generated at the data processor from [a] rotation key and [a] switching key ([0101]-[0102] - The processor 200 may analyze the automorphism existing in the homomorphic encryption using a key switching key and the blind rotation key for the automorphism operation to minimize the computational amount... The processor 200 may generate a blind rotation key and a key switching key based on the comparison result.)
Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Lee to the rotation/switching keys of No to include wherein [a rotation key] is generated at the data processor from [a] rotation key and [a] switching key.
One would have been motivated to combine the teachings of Lee to No to do so as it provides / allows to reduce the size of public keys used in homomorphic encryption schemes (Lee, [0006]).
Regarding Claim 3;
No in view of Lee discloses the method to claim 2.
No further discloses wherein the data processor is enabled to perform calculations on the encrypted data file using the department HE rotation keys (FIG. 2 – Cipher Text and [0003] - a plaintext obtained by decrypting the ciphertext is the same as an operation result of original data before encryption and [0039]-[0040] – rotation operation keys and [0064]).
Regarding Claim(s) 13; claim(s) 13 is/are directed to a/an system associated with the method claimed in claim(s) 2-3. Claim(s) 13 is/are similar in scope to claim(s) 2-3, and is/are therefore rejected under similar rationale.
Claim(s) 4 and 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over No et al. (US 2023/0254125 A1) in view of Lee et al. (US 2023/0246807 A1) and further in view of Polyakov et al. (US 2021/0399874 A1).
Regarding Claim 4;
No in view of Lee discloses the method to claim 3.
No further discloses the department HE rotation keys (FIG. 2 and [0039]-[0040] and [0047]).
No in view of Lee fails to explicitly disclose wherein the ... rotation keys permit each calculation of the encrypted data file to use a different key.
However, in an analogous art, Polyakov teaches wherein the ... rotation keys permit each calculation of the encrypted data file to use a different key ([0029] - Embodiments of the invention may provide a distributed evaluation key generation procedure for rotation/automorphism operations. These evaluation keys may be used to perform encrypted rotations and various permutations and [0039] - To decrypt, embodiments of the invention may input a linear ciphertext of the form (c.sub.0, c.sub.1)=c.sub.0+sc.sub.1+e (e.g., the re-linearized multiplication result ciphertext (c.sub.0*, c.sub.1**)). First, party A computes its partial decryption d.sub.A=c.sub.0+s.sub.Ac.sub.1+e.sub.A, where e.sub.A is a generated error ring element. All other j parties compute their respective partial decryptions d.sub.j=s.sub.jc.sub.1+e.sub.j. Then all partial decryptions may be added up as d=Σ.sub.j=1.sup.Nd.sub.j equal to the fully decrypted result. In some embodiments, a scheme-specific decoding procedure may be applied to d to get the fully decrypted result (e.g., as it is done in the case of single-key FHE)).
Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Polyakov to the rotation keys of No in view of Lee to include wherein the ... rotation keys permit each calculation of the encrypted data file to use a different key.
One would have been motivated to combine the teachings of Polyakov to No in view of Lee to do so as it provides / allows secure collaborative key generation techniques that support multiplication within a collaborative multiparty computational protocol such as threshold FHE (Polyakov, [0005]).
Regarding Claim(s) 14; claim(s) 14 is/are directed to a/an system associated with the method claimed in claim(s) 4. Claim(s) 14 is/are similar in scope to claim(s) 4, and is/are therefore rejected under similar rationale.
Allowable Subject Matter
Upon review of the evidence at hand, it is hereby concluded that the evidence obtained and made of record, alone or in combination, neither anticipates, reasonably teaches, nor renders obvious the below noted features of applicant’s invention as the noted features amount to more than a predictable use of elements in the prior art.
Regarding Claim 6, and substantially similar Claim 16, the prior art of record as cited within this Office Action, nor those cited, in the additional references cited , alone or in combination, neither anticipates, reasonably teaches, nor renders obvious “wherein the principal instance of the organization unit comprises a HEkeygen_local component that comprises a plurality of application programming interfaces (“APIs”), including: (i) a GeneratePrincipleKeys API adapted to generate a principle set of HE keys; (ii) a UploadPrincipleKeys API adapted to upload the principal set of HE keys to a HEkeygen_cloud component of the remote data provider; and (iii) a GenerateEphemeralKeys API adapted to generate an ephemeral set of HE keys without storing it.”
Thus, claim 6 is being objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims; however as allowable subject matter has been indicated, applicant's reply must either comply with all formal requirements or specifically traverse each requirement not complied with. See 37 CFR 1.111(b) and MPEP § 707.07(a).
Dependent Claim(s) 7-8, and substantially similar Claim(s) 17-18, inherit the allowability of claim 6 and/or and substantially similar claim 16, as they depend off of claim 6 and substantially similar claim 16.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892 attached.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KARI L SCHMIDT whose telephone number is (571)270-1385. The examiner can normally be reached Monday-Friday 10am - 6pm (MDT).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KARI L SCHMIDT/ Primary Examiner, Art Unit 2439