DETAILED ACTION
Claims 1-9 are presented for examination.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Examiner’s Note
Based on the definitions provided in the specification, a cryptosystem is interpreted as a system that implements a cryptographic algorithm and a crypto operation is interpreted as a cryptographic operation. Leaky data is interpreted as sensitive data.
Specification
The specification is objected to because the title provided in the specification is different from the title provided in the application data sheet. Correction is required in order for the title to be consistent with the application data.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1-9 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1 recites “generate a randomized representation of the leaky external data: as a data input for a crypto operation……; and updating the segment of the internal state memory…..”. A conjunction joins two sentences of the same form however the first sentence “as a data input…” is missing a verb. In addition, it is not clear what the colon “ : ” before that sentence indicates. Are these steps part of the randomizing or part of the generating?
For the purpose of examination, the claim is interpreted without the “ : ” and the updating step is in conjunction with the randomizing step.
Claims 2-9 depend on claim 1 and therefore inherit this rejection.
Claim 8 recites the terms “the at least one hashing algorithm” which lack antecedent basis. For the purpose of examination, claim 8 as being interpreted as being dependent on claim 7.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1- 9 are rejected under 35 U.S.C. 101 because they are directed to an abstract idea not integrated into a practical application and without significantly more.
Step 1: Statutory Category
Claims 1-9 satisfy the statutory category requirement because they are directed to processes and therefore, they are statutory under 35 U.S.C. 101.
Step 2A, Prong 1 – Judicial Exception (Abstract Idea)
Claim 1 recites sending/receiving data, randomizing (i.e. manipulating) data to generate more data, providing data as input and updating data, for example the claims recite instructions for providing a current internal state memory with a segment of randomized data and operating within a cryptosystem; receiving leaky external data and the segment of randomized data from the current internal state memory at a randomizer module; and randomizing the leaky external data with the randomizer module utilizing the segment of randomized data from the current internal state memory to generate a randomized representation of the leaky external data as a data input for a crypto operation within the cryptosystem; and updating the segment of the internal state memory for use by the randomizer module when receiving next incoming leaky external data. All these features correspond to mental steps with intended use recitations such as “for use by the randomizer” .
The dependent claims also recite similar mental steps including defining a first interface and a second interface that share a module, performing a mathematical function on the randomized data, performing a hash algorithm (another mathematical function), and a recitation of particular algorithms to perform the hash.
Step 2A, Prong 2 – Integration into a practical Application
The judicial exception is not integrated into a practical application. Although, the preamble indicates that it is for enhancing resistance against side-channel attacks, it is not clear how the randomizing, alone, integrates the judicial exception into a practical application.
Step 2B- “Significantly More”
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. In particular, some claims recite a hardware-based, software-based and cryptosystem at a high-level of generality, however these are generic computer components, thus the claims are mere instructions to implement the judicial exception on generic computer components. Mere recitations of applying an exception using a generic computer do not amount to significantly more than the abstract idea. Therefore, the claims are not patent eligible.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1 and 3-9 are rejected under 35 USC 103 as being unpatentable over Ghosh (US Pub.No.2022/0416998) in view of Van Der Sluis (US Pub.No. 2014/0040338) (hereinafter, Sluis).
Re Claim 1. Ghosh discloses A hardware-based and software-based method for enhancing resistance against side- channel attacks in a cryptosystem (paragraph 61 plurality of round datapath circuits within one clock period is a fundamental mechanism described herein in FIG.7 and FIG.8 that protects the SHA3 implementation against side channel attacks [enhancing resistance from side-channel attacks using SHA3) comprising: providing a current internal state memory with a segment of randomized data and operating within a cryptosystem (paragraph 58 input state register 810 communicatively coupled to a first multi-round datapath circuit 840A, which is in turn communicatively coupled to a pipeline register 850A. The first multi-round datapath circuit 840A comprises a firstround data path 820 which comprises components to perform a first Keccak round including a first section to perform a 0 step of a SHA3 calculation, [i.e. internal state register or memory for holding the randomized SHA3 values] paragraph 69 processor 1102 can have a single internal cache or multiple levels of internal cache. In some embodiments, the cache memory is shared among various components of the processor 1102. In some embodiments, the processor 1102 also uses an external cache paragraph 47 the public key 364 may be provided to verifier device 350 in a previous exchange. The public key, p.sub.k, is configured to contain a number L of public key elements, i.e., p.sub.k=[p.sub.k1,p.sub.kL]. The public key 364 may be stored, for example, to memory 362 [i.e. storing randomized data such as keys in memory]); receiving leaky external data and the segment of randomized data from the current internal state memory at a randomizer module (paragraph 62 In one example plurality of the round datapath circuits breaks the direct correlation between input data and the specific underlying target operation within the first round. In another example plurality of the round datapath circuits breaks the direct correlation between output data and the specific underlying target operation within the last round[using random data to protect the side-channel] and paragraph 31 One area that is being explored to counter quantum computing challenges is hash-based signatures (HBS) since these schemes have been around for a long while and possess the necessarily basic ingredients to counter the quantum counting and post-quantum computing challenges. HBS schemes are regarded as fast signature algorithms working with fast platform secured-boot, which is regarded as the most resistant to quantum and post-quantum computing attacks); and randomizing the leaky external data with the randomizer module utilizing the segment of randomized data from the current internal state memory (paragraph 59 At operation 935 it is determined whether the SHA3 calculation is complete. If, at operation 935 the SHA3 calculation is not complete then control passes to operation 940 and the output of the second round datapath circuit 730 is fed back to the state register [i.e. randomized data of the SHA3 in the internal state register/memory] paragraph 61 in one example plurality of the round datapath circuits breaks the direct correlation between input data and the specific underlying target operation within the first round [i.e. breaking correlation prevents leakage]. In another example plurality of the round datapath circuits breaks the direct correlation between output data and the specific underlying target operation within the last round) to generate a randomized representation of the leaky external data: as a data input for a crypto operation within the cryptosystem (paragraph 61, as used herein, the phrase "side channel" refer to power consumptions of the device during execution of SHA3, and/or EM emission and photon emanations from the device);
Ghosh does not explicitly disclose whereas Sluis discloses: and updating the segment of the internal state memory for use by the randomizer module when receiving next incoming leaky external data (Sluis, paragraph 49, the random number generating system according to the invention comprises an internal state memory for storing an internal state and a generating unit configured for generating a random number of the sequence of random numbers from the current internal state in conjunction with deriving a new internal state from a current internal state stored in the internal state memory, wherein the generating unit is configured for deriving the new internal state from the current internal state before generating a random number of the sequence of random numbers from the current internal state, and wherein the over-writing unit is configured for over-writing the at least part of the memory with random numbers derived from the new internal state before generating a random number of the sequence of random numbers from the current internal state).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Ghosh with Sluis because by pre-computing the new internal state and using that for over-writing the memory before the current state is used to generate a next random number in the sequence, one can be sure that whenever a reset occurs, the values in the memory have never been used to generate
output. Hence it is assured that state information is never re-used (Sluis, para.0050).
Re Claim 3. Ghosh in view of Sluis discloses providing a secondary interface handling a pre-randomized representation of the leaky external data as the data input for the crypto operation within the cryptosystem (paragraph 48 Second device 350 further comprises authentication logic 370 which includes hash Logic 372, signature logic and verification logic 376. As described above, hash logic 372 is configured to hash (i.e., to apply a hash function to) a message(m))M) paragraph 57 comprise an input state register 710 communicatively coupled to a first round datapath circuit 720, which is in turn communicatively coupled to a second round datapath circuit 730. having Multiple Rounds starting with Pre-randomized data and Adding SHA3 calculation to randomized the data) wherein the randomization of the leaky external data with the randomizer module utilizing the segment of randomized data from the current internal state memory is a primary interface (paragraph 47 the public key 364 may be provided to verifier device 350 in a previous exchange. The public key, p.sub.k, is configured to contain a number L of public key elements, i.e., p.sub.k=[p.sub.k1,p.sub.kL]. The public key 364 may be stored, for example, to memory 362 paragraph 61 plurality of the round datapath circuits breaks the direct correlation between input data and the specific underlying target operation within the first round. In another example plurality of the round datapath circuits breaks the direct correlation between output data and the specific underlying target operation within the last round).
Re Claim 4, Ghosh in view of Sluis discloses the primary interface and the secondary interface share at least one module (paragraph 56 for value and the authentication path are used to compute the root of the Merkle tree and compare with the shared public key PK to verify the message (sharing public key information)).
Re Claim 5. Ghosh in view of Sluis discloses the current internal state memory and the leaky external data are from different invocations of the cryptosystem (paragraph 54 involves 67 parallel chains of 16 SHA2-256 HASH functions, each with the secret key sk[66:0] as input. Each HASH operation in the chain consists of 2 pseudo-random functions PRF using SHA2-256 to generate a bitmask and a key. The bitmask is XOR-ed with the previous hash and concatenated with the key as input message to a 3rd SHA2-256 hash operation) [Note: using multiple hashing operations or invocations in the system as described in applicant's specification page 9, lines 18-22].
Re Claim 6. Ghosh in view of Sluis discloses subjecting the segment of randomized data to a mathematical function (paragraph 20 XMS S-specific hash functions include a Pseudo- Random Function PRF [using mathematical functions], a chain hash F, a tree hash H and message hash function Hmsg. As used herein, the term WOTS shall refer to the WOTS signature scheme and or a derivative scheme such as WOTS).
Re Claim 7. Ghosh in view of Sluis discloses the cryptosystem is operably configured to perform at least one hashing algorithm (paragraph 61 plurality of round datapath circuits within one clock period is a fundamental mechanism described herein in FIG. 7 and FIG. 8 that protects the SHA3 implementation against side channel attacks -protection of side-channel attacks using SHA3 hash).
Re Claim 8, Ghosh in view of Sluis discloses the at least one hashing algorithm includes SHA-3 or its derivatives (paragraph 61 a plurality of round datapath circuits within one clock period is a fundamental mechanism described herein in FIG. 7 and FIG. 8 that protects the SHA3 implementation against side channel attacks -protection of side-channel attacks using SHA3 hash).
Re Claim 9, Ghosh in view of Sluis discloses the cryptosystem includes a Keccak algorithm (paragraph 57 first round data path 720 comprises components to perform a first keccak round including a first section 721 to perform a step of a SHA3 calculation, a second section 722 to perform a step of a SHAS calculation, a third section 723 to perform a 1 step of a SHA3 calculation).
Claim 2 is rejected under 35 USC 103 as being unpatentable over Ghosh (US Pub. No. 2022/0416998) in view of Van Der Sluis (US Pub.No.2014/0040338) (hereinafter, Sluis) and further in view of Chen (US Pub. No. 2021/0184831).
Re Claim 2, Ghosh in view of Sluis discloses the features of claim 1, however fails to explicitly disclose utilizing the segment of randomized data from the current internal state memory with a random number generator.
Chen has a process for obfuscating a cryptographic parameter of cryptographic operations(abstract) and teaches: utilizing the segment of randomized data from the current internal state memory with a random number generator (paragraph 84 random number generation may involve a non-recursive random number generator on chip, a linear-feedback shift register, random number generation software, and combinations thereof Non-limiting examples of random number generation including deterministic random number generation, non-deterministic random number generation).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Ghosh in view of Sluis with the obfuscating a cryptographic parameter of cryptographic operations teaching of Chen for the purpose of creating cryptographic operations using randomized expression (Chen, para.0083).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to NOURA ZOUBAIR whose telephone number is (571)270-7285. The examiner can normally be reached Monday - Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/NOURA ZOUBAIR/Primary Examiner, Art Unit 2434