DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-8 rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,489,737 in view of Langham et al, (U.S. Pub. No. 2012/0036363 A1).
Instant Application
U.S. Patent No. 12,489,737
Claim 1. (Currently Amended) A communication system comprising: a plurality of communication apparatuses,
wherein each of the communication apparatuses includes: a memory storing an application program configured to perform encrypted communication with another communication apparatus;
and a processor coupled to the memory and configured to: switch a key sharing scheme for generating a shared key to be used for the encrypted communication,
the processor is configured to switch to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present.
Claim 1. A communication system comprising a plurality of communication apparatuses,
wherein each one of the plurality of communication apparatuses includes:
a processor; and a memory having instructions stored thereon that, when executed by the processor, cause the processor to function as: an application program unit configured to perform encrypted communication with another communication apparatus;
a protocol conversion unit configured to transmit a message representing a predetermined procedure when a key request for a shared key to be used in the encrypted communication is received from the application program unit; a state management unit configured to receive a message from the protocol conversion unit to manage an execution state of the procedure, and to transmit the message to a protocol driver supporting a predetermined key sharing protocol; and the protocol driver configured to request a key sharing system that executes the key sharing protocol, to generate the shared key, when the message is received from the state management unit.
Claim 6. (Currently Amended) A communication apparatus comprising:
a memory storing an application program configured to perform encrypted communication with another communication apparatus;
and a processor coupled to the memory and configured to: switch a key sharing scheme for generating a shared key to be used for the encrypted communication,
wherein the processor is configured to switch to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present.
Claim 5. A communication apparatus comprising:
a processor; and a memory having instructions stored thereon that, when executed by the processor, cause the processor to function as: an application program unit configured to perform encrypted communication with another communication apparatus;
a protocol conversion unit configured to transmit a message representing a predetermined procedure when a key request for a shared key to be used in the encrypted communication is received from the application program unit; a state management unit configured to receive a message from the protocol conversion unit to manage an execution state of the procedure, and to transmit the message to a protocol driver supporting a predetermined key sharing protocol; and a protocol driver configured to request a key sharing system that executes the key sharing protocol to generate the shared key when the message is received from the state management unit.
Claim 7. (Currently Amended) A method used by a communication apparatus, the communication apparatus comprising a memory storing an application program and a processor coupled to the memory, the method comprising:
performing, by[[ an]] the application program, encrypted communication with another communication apparatus; and
switching, by the processor, a key sharing scheme for generating a shared key to be used for the encrypted communication,
wherein the processor performs switching to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present.
Claim 6. A method for use in a communication apparatus, the method comprising:
performing, by an application program unit, encrypted communication with another communication apparatus;
transmitting, by a protocol conversion unit, a message representing a predetermined procedure when a key request for a shared key to be used in the encrypted communication is received from the application program unit; receiving, by a state management unit, a message from the protocol conversion unit to manage an execution state of the procedure, and transmitting the message to a protocol driver supporting a predetermined key sharing protocol; and requesting, by the protocol driver, a key sharing system that executes the key sharing protocol, to generate the shared key, when the message is received from the state management unit.
Claim 8. (Currently Amended) A non-transitory computer-readable recording medium storing a[[A]] program causing a computer to perform the method of claim 7.
Claim 7. A non-transitory recording medium storing a program that, when executed on a computer, causes the computer to perform the method of claim 6
U.S. patent No. 12,489,737 teaches all the limitation of pending claim s 1, 6 and 7, except for the limitation of the processor switches to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present.
However, an analogous art Langham et al. (US 2012/003636) teaches the processor is configured to switch to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present ([¶¶0032-0033], wherein Langham discloses, a channel monitoring device monitors at least one channel condition and operates a switch responsive to the measured condition. Langham teaches that when a shared key cannot be identified or retrieved using a key identifier, the device falls back to a default key, this allows the message exchange and secure session establishment to continue when the shared key retrieval fails, which reads on the missing limitation of the claim).
It would have been obvious to a person of ordinary skill in the art at the time of the invention to modify claim 1 of U.S. Patent No. 12,489,737 to include Langham’s teaching of switching to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present.. A person of ordinary skill in the art would have been motivated to make the modification in order to maintain reliable cryptographic key generation and encrypted communication even when the current key sharing scheme is affected by link distance or other channel conditions. The combination would have predictably resulted in the communication system of U.S. Patent No. 12,489,737 switching to another key sharing scheme when the current scheme cannot generate a usable shared key.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1 and 4-8 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 1 is rejected under 35 U.S.C. 112(b) as being indefinite because the term “key sharing scheme being used at present” lacks sufficient antecedent basis. Claim 1 first recites “a key sharing scheme for generating a shared key,” but does not clearly introduce a key sharing scheme that is “being used at present.” It is unclear whether “the key sharing scheme being used at present” refers to the previously recited “a key sharing scheme” or to another current key sharing scheme used by the communication apparatus. Therefore, the scope of claim 1 is unclear.
Claim 1 further recites the limitation “and the processor is configured to switch to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present.” However, the phrase “the key sharing scheme being used at present” lacks sufficient antecedent basis because the claim previously recites only “switch a key sharing scheme” and does not clearly identify which key sharing scheme is currently being used. Therefore, the metes and bounds of the claim are unclear.
Claim 4 is rejected under 35 U.S.C. 112(b) as being indefinite because the terms “the error content,” “the error cause,” and the “error occurrence place” lacks sufficient antecedent basis. Claim 4 depends from claim 2. Claim 2 recites “an error,” but does not previously introduce “the error content,” “the error cause,” or “the error occurrence place.” Claim 4 recites “determine the other key sharing scheme or a key storage function to be a switching destination” in accordance with at least one of the error content, the error cause, or the error occurrence place. It is unclear what previously recited limitation is being referenced by each of “the error content,” “the error cause,” and the “error occurrence place.” Therefore, the scope of claim 4 is unclear.
Claim 4 further recites the limitation “determine the other key sharing scheme or a key storage function to be a switching destination from among a plurality of key sharing schemes” does not reasonably apprise a person of ordinary skill in the art of the metes and bounds of the claims. Claim 4 recites selecting, as a switching destination, either, “the other key sharing scheme” or “a key storage function,” but also recites that the switching destination is determined “from among a plurality of key sharing scheme.” It is unclear whether the recited “key storage function” is intended to be one of the plurality of key sharing schemes, or whether it is intended to be a separate alternative switching destination outside the plurality of key sharing schemes. Because a key storage function is not clearly a key sharing scheme, the metes and bounds of the claimed switching destination are unclear.
Claim 5 depends from claim 4 and therefore inherits the indefiniteness of claim 4.
Claim 6 is rejected under 35 U.S.C. 112(b) as being indefinite because the term “key sharing scheme being used at present” lacks sufficient antecedent basis. Claim 6 first recites “a key sharing scheme for generating a shared key,” but does not clearly introduce a key sharing scheme that is “being used at present.” Claim 6 subsequently recites switching to another key sharing scheme when the shared key cannot be generated by “the key sharing scheme being used at present.” It is unclear whether “the key sharing scheme being used at present” refers to the previously recited “a key sharing scheme” or to another current key sharing scheme used by the communication apparatus. Therefore, the scope of claim 6 is unclear.
Claim 7 is rejected under 35 U.S.C. 112(b) as being indefinite because the term “key sharing scheme being used at present” lacks sufficient antecedent basis. Claim 7 first recites “switching, by the processor, a key sharing scheme for generating a shared key to be used for the encrypted communication,” but does not clearly introduce a key sharing scheme that is “being used at present.” Claim 7 subsequently recites that the processor performs switching to another key sharing scheme when the shared key cannot be generated by “the key sharing scheme being used at present.” It is unclear whether “the key sharing scheme being used at present” refers to the previously recited “a key sharing scheme” or to another current key sharing scheme used by the communication apparatus. Therefore, the scope of claim 7 is unclear.
Claim 8 depends from claim 7 and therefore inherits the indefiniteness of claim 7.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-8 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Regarding claims 1, 6, 7, and 8:
Applying Step 1 of the Subject Matter Eligibility Test (SMET), does the claim as a whole fall within one of the four statutory categories of invention? Yes.
Claims 1 and 6 are directed to a communication system and a communication apparatus, respectively, each including a memory and a processor, and therefore fall with the machine category. Claim 7 directed to a method performed by a processor, and therefore falls within the process category. Claim 8 is directed to a non-transitory computer-readable recording medium storing a program, and therefore falls within the manufacture category.
Applying Step 2A of the SMET, also known at this stage as the Alice/Mayo Test, Prong One, is the claim as a whole directed to a law of nature, a natural phenomenon (product of nature) or an abstract idea? Yes.
The claim recites the abstract idea of determining that current key sharing scheme has not produced a desired result, i.e., generation of a shred key, and selecting and switching to an alternative key sharing scheme to obtain that result. This falls within the mental processes grouping because the claim recites evaluation, judgment, and selection of an alternative key sharing scheme when the current scheme does not produce the desired result. (see MPEP 2106.04(a)(2)(iii).
The independent claims recite this result-oriented switching logic at a high level of generality. The claims do not recite a particular technical mechanism for detecting that the shared key cannot be generated, do not recite a particular cryptographic switching algorithm, and do not recite a particular technical implementation of how the processor switches from one key sharing scheme to another. Accordingly, the claims recite an abstract idea in the form of evaluation, judgement, and selection of an alternative process when a current process fails to produce a desired result. (see MPEP 2106.04(a)(2)).
Applying Step 2A, Prong Two, does the claim recite additional elements that integrate the judicial exception into a practical application? No.
The claim recites the additional elements of:
A plurality of communication apparatuses;
A memory storing an application program;
An application program configured to perform encrypted communication;
A processor coupled to the memory;
A shred key;
Encrypted communication; and
A non-transitory computer-readable recording medium.
A claim reciting a judicial exception is not directed to the judicial exception if it also recites additional elements demonstrating that the claim as a whole integrates the exception into a practical application. One way to demonstrate such integration is when the claimed invention improves the functioning of a computer or improves another technology or technical field. However, the additional elements recited above do not do so.
The claimed invention uses generic computer and communication components to apply the abstract idea of detecting that a current key sharing scheme has failed to produce a shared key and switching to an alternative key sharing scheme. The memory stores the application program, the processor executes the application program and performs the switching, and the application program performs encrypted communication using a shared key protocol or cryptographic architecture, such as a articulate implementation of quantum key distribution or post-quantum key exchange, specific switching-destination determination algorithm, improved computer performance, or improvement to computer functionality itself.
Rather, the claims recite the desired result of maintaining encrypted communication by switching from one key sharing scheme to another when the current scheme does not generate the shared key, without reciting the specific technical means for achieving that result. Courts have indicated that merely claiming a desired result, without reciting the specific technical means for achieving that result, may not be sufficient to show an improvement in technology even where the claim is recited in a particular technological environment. See Two-Way Media Ltd. V. Comcast Cable Communications, LLC, 874 F.3d 1329, 1337, 124 USPQ2d 1521, 1526 (Fed. Cir. 2017); Affinity Labs of Texas, LLC v., DIRECTV, LLC, 838 F.3d 1253, 1258-59, 120 USPQ2d 1201, 1204-05 (Fed. Cir. 2016).
Thus, the judicial exception is not integrated into practical application.
Applying Step 2B, do the additional elements amount to significantly more than the judicial exception? No.
The additional element, considered individually and as an ordered combination, do not amount to significantly more than the abstract idea. The claims merely append well-understood, routine, and conventional computer and communication components to the abstract idea, specified at a high-level generality. A generic memory storing a program, a generic processor executing the program, a communication apparatus, encrypted communication, and a n on-transitory computer-readable recording medium storing a program are generic computer and communication components performing their ordinary function.
The specification itself describes the recited memory and processor as generic, conventional computer hardware. For example, paragraphs [0072]-[0077] describes a general purpose computer including an input device, a display device, an external interface, a communication interface, a processor, such as a CPU, and memory devices, such as an HDD, SSD, RAM, ROM, or flash memory. These components are described as ordinary hardware for implementing the claimed functions. The claims do not add any unconventional arrangement of these components or any specific technical implementation that would transform the abstract idea into patent-eligible subject matter.
Simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception is not enough to supply an inventive concept. See Alice Corp. Pty. Ltd. V. CLS Bank Int’l, 573 U.S. 208, 225, 110 USPQ2d 1976, 1982-83 (2014). Accordingly, the additional elements do not amount to significantly more than the abstract idea.
Because claims 1, 6, 7, and 8 are directed to a judicial exception and do not recite additional elements that integrate the exception into a practical application or amount to significantly more than the exception, claims 1, 6, 7, and 8 are ineligible under 35 U.S.C. 101.
Regarding claims 2-5:
The dependent claims do not alter the analysis applied to independent claim 1.
Claim 2 further recites that the switching occurs when an error occurs in a key sharing system.
Claim 3 recites examples of error information, including a communication error, an internal error, key depletion, computation capability depletion, a system error, a tamper abnormality.
Claim 4 recites determining a switching destination based on error content, error cause, or error occurrence place.
Claim 5 recites that the plurality of key sharing schemes includes quantum key distribution and post-quantum key exchange.
These limitations further narrow the type of information evaluated or the technological environment in which the switching logic is applied. However, they do not recite a specific technical mechanism for detecting the error, generating the shared key, or technically carrying out the switching in a way that improves the functioning of the computer or communication apparatus itself. Claim 5 identifies particular types of key sharing schemes, namely quantum key distribution and post-quantum key exchange, but does not recite a specific implementation of either scheme or a specific technical mechanism by which claimed switching is performed.
Accordingly, claims 2-5 do not integrate the abstract idea into a practical application and do not add significantly more than the abstract idea. Therefore, claims 2-5 are also rejected under 35 U.S.C. 101.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-4 and 6-8 are rejected under 35 U.S.C. 103 as being unpatentable over Bucklew et al, (U.S. Pub. No. 2022/0353067 A1, hereinafter “Bucklew”) in view of Langham et al, (U.S. Pub. No. 2012/0036363 A1, hereinafter “Langham”).
As to claim 1, the combination of Bucklew in view of Langham teaches:
(Currently Amended) A communication system comprising: a plurality of communication apparatuses: (see Bucklew, [¶¶ Fig.1, 0019-0020]: “A quantum communication system 20, includes a communications system 22, and a quantum key distribution (QKD) system 24. The QKD system 24 includes a transmitter node 26, a receiver node 28, and a quantum communications channel 30 coupling the transmitter node and receiver node. The transmitter node 26 not only communicates with the receiver node 28 over the quantum communications channel 30, but also communicates via the communications system 22, which may include a non-quantum or conventional communications channel and may be fiber optic, free-space, wired, or another communications channel.”);
(Bucklew discloses a communication system including a transmitter node and a receiver node. The transmitter node and receiver node correspond to the claimed plurality of communication apparatuses.)
wherein each of the communication apparatuses includes: a memory storing an application program configured to perform encrypted communication with another communication apparatus; (see Bucklew, [¶¶0002, 0023, 0030]: “When a secret key is established between the two parties by this QKD system, the two parties may then encrypt data transmitted over any conventional communications channel. The transmitter node 26 includes a controller 44 operatively connected to the laser pulse source 40 and other components at the transmitter node for controlling their operation, such that the laser pulse source is controlled for transmitting a photon in a polarization state defined by the bit and basis, and record the time the photon was transmitted. This process is repeated for the string of bits as a stream of photons. The transmitter node 26 may include a transceiver 46 connected to the controller 44 and operative to communicate with the receiver node 28 via the communications system 22 using, for example, an unencrypted non-quantum communications channel for the key exchange or key sifting process, as key exchange is commonly called. The controller 76 at the receiver node 28 may be connected to a conventional transceiver 78 also located at the receiver node 28.”);
(Bucklew teaches controllers and transceivers in the transmitter and receiver nodes for communication, and teaches encrypting data after a secret key is established. The controllers correspond to processors executing stored instructions/application firmware for encrypted communication.)
and a processor coupled to the memory and configured to: switch a key sharing scheme for generating a shared key to be used for the encrypted communication: (see Bucklew, [¶¶0009, 0025]: “The transmitter node may be configured to transmit to the receiver node a bit stream of optical pulses, and switch between first and second QKD protocols based upon at least one channel condition. The transmitter node 26 is configured to transmit to the receiver node 28 via its output 27, the bit stream of optical pulses and switch between first and second QKD protocols based upon at least one channel condition. As illustrated in FIG. 1, the transmitter node 26 includes a switch 50 for switching between the first and second QKD protocols, which in an embodiment are respectively a continuous-variable QKD (CV-QKD) protocol, and a discrete-variable (DV-QKD) protocol. The transmitter node 26 includes a continuous-variable QKD (CV-QKD) protocol device 54 for generating the CV-QKD protocol and a discrete-variable QKD (DV-QKD) protocol device 56 for generating the DV-QKD protocol.”);
(Bucklew teaches switching between CV-QKD and DV-QKD protocols. These QKD protocols are key sharing schemes for generating or distributing a shared cryptographic key used for encrypted communication.)
the processor is configured to switch to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present: (see Bucklew, [¶¶0026, 0035-0036]: “A channel monitoring device 60 is configured to monitor at least one channel condition and operate the switch 50 responsive to the measured channel condition. The transmitter node 26 may switch from transmitting optical pulses using, for example, the first CV-QKD protocol to the second DV-QKD protocol when the link distance exceed a threshold, for example, 50 kilometers. The maximum SKR may be achieved with either a CV-QKD protocol or a DV-QKD protocol depending on the link distance as illustrated, where at above a link distance of above about 50 km in this one example, the SKR drops quality to almost zero for communications employing CV-QKD, while communications employing DV-QKD maintain a SKR up to about 250 km. The SKR may be guaranteed to lie within a well-defined range of values to equalize the SKR and facilitate communications planning and ensure that the cryptographic keys can be reliably distributed within a narrow operating window.”);
Although Bucklew discloses, A QKD protocol with an SKR of almost zero cannot generate a usable shared key for the intended encrypted communication, Bucklew does not explicitly disclose
the processor is configured to switch to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present. However, in an analogous art, Langham discloses at 306, when the responding device is unable to find a shared key with the embedded identifier, it can fall back to using a default key and attempt to process the request message using this key. Thus, if the key retrieval failed because the initiating device does not support encoding the key identifier into the SPI of the request message but, however, is provisioned (316) with the same default key, then the message exchange and corresponding security session establishment, can still proceed (312) to completion, at 314. But, if the key retrieval failed because the default key was not provisioned (316) into the responding device, session negotiation stops at 308.” (see Langham, [¶¶0032-0033]: “Accordingly, at 306, when the responding device is unable to find a shared key with the embedded identifier, it can fall back to using a default key and attempt to process the request message using this key. Thus, if the key retrieval failed because the initiating device does not support encoding the key identifier into the SPI of the request message but, however, is provisioned (316) with the same default key, then the message exchange and corresponding security session establishment, can still proceed (312) to completion, at 314. But, if the key retrieval failed because the default key was not provisioned (316) into the responding device, session negotiation stops at 308.”);
(Bucklew teaches switching between QKD protocols when the current protocol becomes unable due to monitored channel conditions. Langham further teaches fallback key use when a shared key cannot be found or key retrieval fails. Therefore, it suggests switching to another available key sharing option when the current key process cannot provide the shared key.)
Therefore, it would have been obvious to a person of ordinary skill in the art at the time of the invention to modify Bucklew’s QKD protocol-switching system to switch to another key sharing scheme when the currently used scheme cannot generate or provide a usable shared key, in view of Langham’s fallback-key teaching. Bucklew already teaches switching between QKD protocols to maintain reliable key distribution under changing channel conditions, and Langham teaches using an alternate or default key option when shared key retrieval fails to that secure session establishment can continue. A person of ordinary skill in the art would have been motivated to combine these teachings in order to maintain secure encrypted communication when the current key sharing process fails or becomes unsuitable. The combination would have predictably resulted in a communication system that switches to another available key sharing scheme to continue share-key generation and encrypted communication.
As to claim 2, Bucklew teaches:
(Currently Amended), wherein the processor is configured to switch to the other key sharing scheme when an error occurs in a key sharing system for generating the shared key by the key sharing scheme being used at present: (see Bucklew, [¶¶0026, 0035-0036]: “A channel monitoring device 60 is configured to monitor at least one channel condition and operate the switch 50 responsive to the measured channel condition. The transmitter node 26 may switch from transmitting optical pulses using, for example, the first CV-QKD protocol to the second DV-QKD protocol when the link distance exceed a threshold, for example, 50 kilometers. The maximum SKR may be achieved with either a CV-QKD protocol or a DV-QKD protocol depending on the link distance as illustrated, where at above a link distance of above about 50 km in this one example, the SKR drops quality to almost zero for communications employing CV-QKD, while communications employing DV-QKD maintain a SKR up to about 250 km. The SKR may be guaranteed to lie within a well-defined range of values to equalize the SKR and facilitate communications planning and ensure that the cryptographic keys can be reliably distributed within a narrow operating window.”);
(Bucklew teaches that when link distance exceeds a threshold, the active CV-QKD secret key rate drops to almost zero, automatically triggering a protocol switch to ensure keys can be reliably distributed. Under BRI, an operational state where the key generation rate collapses almost zero constitutes a functional error or processing fault within the key sharing system. Because this failure state directly triggers the automated protocol switch, Bucklew discloses switching to another scheme when an error occurs.)
As to claim 3, Bucklew teaches:
(Original), wherein the error includes at least one of a communication error or an internal error when generating the shared key, key depletion of the shared key, computation capability depletion of the key sharing system, a system error of the key sharing system, or a tamper abnormality related to a communication path of the key sharing system: (see Bucklew, [¶¶0003, 0007-0008, 0026, 0036]: “These changes to the states of the photons may cause errors in the bit values sent between the transmitter node and receiver node. A subset of shared bits used by both parties at the respective transmitter and receiver nodes, e.g., Alice and Bob, may be used to check against eavesdropping by an unauthorized third party, e.g., Eve, which would have introduced errors. QKD techniques are attractive, but they depend on the adaptability of modern communication systems since secure cryptographic communications often use specific types of communication links, including optical fiber and free-space optical (FSO) communications, such as satellite links. These communication links are influenced by atmospheric effects, time of day and different seasons, link distances, and transmitter node and receiver node characteristics. A channel monitoring device 60 is configured to monitor at least one channel condition and operate the switch 50 responsive to the measured channel condition. Also, the channel monitoring device 60 may monitor varying weather and atmospheric conditions and make any switch to an appropriate QKD protocol.”);
(Bucklew teaches that errors may occur in the bit values sent between the transmitter node and receiver node due to disturbance/eavesdropping, and that QKD communication links are affected by atmospheric effects, link distance, and other channel conditions. Bucklew further teaches monitoring these channel conditions and switching to an appropriate QKD protocol. These disclosures correspond to at least a communication error or communication-path abnormality in the key sharing system. Since claim 3 requires only at least one of the listed errors, Bucklew discloses the recited error.)
As to claim 4, Bucklew teaches:
(Currently Amended), wherein the processor is configured to determine the other key sharing scheme or a key storage function to be a switching destination from among a plurality of key sharing schemes in accordance with at least one of the error content, the error cause, or the error occurrence place, and to switch to the determined other key sharing scheme or the key storage function: (see Bucklew, [¶¶0025-0026, 0036]: “The transmitter node 26 is configured to transmit to the receiver node 28 via its output 27, the bit stream of optical pulses and switch between first and second QKD protocols based upon at least one channel condition. As illustrated in FIG. 1, the transmitter node 26 includes a switch 50 for switching between the first and second QKD protocols. A channel monitoring device 60 is configured to monitor at least one channel condition and operate the switch 50 responsive to the measured channel condition. The transmitter node 26 may switch from transmitting optical pulses using, for example, the first CV-QKD protocol to the second DV-QKD protocol when the link distance exceed a threshold, for example, 50 kilometers. Besides just two protocols—one CV-QKD and one DV-QKD, the system may use a plurality of protocols, for example, a bank of protocols could be drawn from based on channel condition. For one channel condition, the system 20 may use all DV-QKD protocols, e.g., four protocols to complete a key transmission or mission objective. For another series of channel conditions, the system may use all CV-QKD and draw from the bank three protocols to meet that mission objective, or for yet another type of fluctuating channel condition, the system could draw, for example, six protocols from the bank that would represent a mix between CV-QKD and DV-QKD resources to satisfy mission objectives in those atmospheric conditions. Also, the channel monitoring device 60 may monitor varying weather and atmospheric conditions and make any switch to an appropriate QKD protocol.”);
(Bucklew teaches determining and switching to an appropriate QKD protocol from among a plurality or bank of QKD protocols based on monitored channel conditions, including link distance, weather, atmospheric conditions, and fluctuating channel conditions. These monitored channel conditions corresponds to error content, error cause, or error occurrence place because they identify the condition causing the current key sharing protocol to fail or become unsuitable for reliable key distribution.)
As to claim 6, Bucklew teaches: A communication apparatus comprising: a memory storing an application program configured to perform encrypted communication with another communication apparatus; (see Bucklew, [¶¶0002, 0023, 0030]: “When a secret key is established between the two parties by this QKD system, the two parties may then encrypt data transmitted over any conventional communications channel. The transmitter node 26 includes a controller 44 operatively connected to the laser pulse source 40 and other components at the transmitter node for controlling their operation, such that the laser pulse source is controlled for transmitting a photon in a polarization state defined by the bit and basis, and record the time the photon was transmitted. This process is repeated for the string of bits as a stream of photons. The transmitter node 26 may include a transceiver 46 connected to the controller 44 and operative to communicate with the receiver node 28 via the communications system 22 using, for example, an unencrypted non-quantum communications channel for the key exchange or key sifting process, as key exchange is commonly called. The controller 76 at the receiver node 28 may be connected to a conventional transceiver 78 also located at the receiver node 28.”);
(Bucklew teaches controllers and transceivers in the transmitter and receiver nodes for communication, and teaches encrypting data after a secret key is established. The controllers correspond to processors executing stored instructions/application firmware for encrypted communication.)
and a processor coupled to the memory and configured to: switch a key sharing scheme for generating a shared key to be used for the encrypted communication: (see Bucklew, [¶¶0009, 0025]: “The transmitter node may be configured to transmit to the receiver node a bit stream of optical pulses, and switch between first and second QKD protocols based upon at least one channel condition. The transmitter node 26 is configured to transmit to the receiver node 28 via its output 27, the bit stream of optical pulses and switch between first and second QKD protocols based upon at least one channel condition. As illustrated in FIG. 1, the transmitter node 26 includes a switch 50 for switching between the first and second QKD protocols, which in an embodiment are respectively a continuous-variable QKD (CV-QKD) protocol, and a discrete-variable (DV-QKD) protocol. The transmitter node 26 includes a continuous-variable QKD (CV-QKD) protocol device 54 for generating the CV-QKD protocol and a discrete-variable QKD (DV-QKD) protocol device 56 for generating the DV-QKD protocol.”);
(Bucklew teaches switching between CV-QKD and DV-QKD protocols. These QKD protocols are key sharing schemes for generating or distributing a shared cryptographic key used for encrypted communication.)
Wherein the processor is configured to switch to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present: (see Bucklew, [¶¶0026, 0035-0036]: “A channel monitoring device 60 is configured to monitor at least one channel condition and operate the switch 50 responsive to the measured channel condition. The transmitter node 26 may switch from transmitting optical pulses using, for example, the first CV-QKD protocol to the second DV-QKD protocol when the link distance exceed a threshold, for example, 50 kilometers. The maximum SKR may be achieved with either a CV-QKD protocol or a DV-QKD protocol depending on the link distance as illustrated, where at above a link distance of above about 50 km in this one example, the SKR drops quality to almost zero for communications employing CV-QKD, while communications employing DV-QKD maintain a SKR up to about 250 km. The SKR may be guaranteed to lie within a well-defined range of values to equalize the SKR and facilitate communications planning and ensure that the cryptographic keys can be reliably distributed within a narrow operating window.”);
Although Bucklew discloses, A QKD protocol with an SKR of almost zero cannot generate a usable shared key for the intended encrypted communication, Bucklew does not explicitly disclose
the processor is configured to switch to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present. However, in an analogous art, Langham discloses at 306, when the responding device is unable to find a shared key with the embedded identifier, it can fall back to using a default key and attempt to process the request message using this key. Thus, if the key retrieval failed because the initiating device does not support encoding the key identifier into the SPI of the request message but, however, is provisioned (316) with the same default key, then the message exchange and corresponding security session establishment, can still proceed (312) to completion, at 314. But, if the key retrieval failed because the default key was not provisioned (316) into the responding device, session negotiation stops at 308.” (see Langham, [¶¶0032-0033]: “Accordingly, at 306, when the responding device is unable to find a shared key with the embedded identifier, it can fall back to using a default key and attempt to process the request message using this key. Thus, if the key retrieval failed because the initiating device does not support encoding the key identifier into the SPI of the request message but, however, is provisioned (316) with the same default key, then the message exchange and corresponding security session establishment, can still proceed (312) to completion, at 314. But, if the key retrieval failed because the default key was not provisioned (316) into the responding device, session negotiation stops at 308.”);
(Bucklew teaches switching between QKD protocols when the current protocol becomes unable due to monitored channel conditions. Langham further teaches fallback key use when a shared key cannot be found or key retrieval fails. Therefore, it suggests switching to another available key sharing option when the current key process cannot provide the shared key.)
Therefore, it would have been obvious to a person of ordinary skill in the art at the time of the invention to modify Bucklew’s QKD protocol-switching communication apparatus to switch to another key sharing scheme when the currently used scheme cannot generate or provide a usable shared key, in view of Langham’s fallback-key teaching. Bucklew already teaches switching between QKD protocols to maintain reliable key distribution under changing channel conditions, and Langham teaches using an alternate or default key option when shared key retrieval fails to that secure session establishment can continue. A person of ordinary skill in the art would have been motivated to combine these teachings in order to maintain secure encrypted communication when the current key sharing process fails or becomes unsuitable. The combination would have predictably resulted in a communication apparatus having a processor configured to switch to another available key sharing scheme to continue share-key generation and encrypted communication.
As to claim 7, Bucklew teaches: A method used by a communication apparatus, the communication apparatus comprising a memory storing an application program and a processor coupled to the memory, the method comprising: (see Bucklew, [¶¶0019, 0023, 0030]: “The QKD system 24 includes a transmitter node 26, a receiver node 28, and a quantum communications channel 30 coupling the transmitter node and receiver node. The transmitter node 26 includes a controller 44 operatively connected to the laser pulse source 40 and other components at the transmitter node for controlling their operation. The controller 76 at the receiver node 28 may be connected to a conventional transceiver 78 also located at the receiver node 28.”);
(Bucklew teaches a method used by a communication apparatus, such as transmitter node 26 or receiver node 28..)
performing, by[[ an]] the application program, encrypted communication with another communication apparatus; (see Bucklew, [¶¶0002, 0023, 0030]: “When a secret key is established between the two parties by this QKD system, the two parties may then encrypt data transmitted over any conventional communications channel. The transmitter node 26 may include a transceiver 46 connected to the controller 44 and operative to communicate with the receiver node 28 via the communications system 22 using, for example, an unencrypted non-quantum communications channel for the key exchange or key sifting process, as key exchange is commonly called. The transmitter node 26, e.g., Alice, may transmit data about the basis in which each photon was transmitted to the receiver node 28, e.g., Bob, using the conventional communication system 22.”);
(Bucklew teaches encrypted communication between the transmitter node and receiver node after a secret key is established.)
switching, by the processor, a key sharing scheme for generating a shared key to be used for the encrypted communication: (see Bucklew, [¶¶0009, 0025]: “The transmitter node may be configured to transmit to the receiver node a bit stream of optical pulses, and switch between first and second QKD protocols based upon at least one channel condition. The transmitter node 26 is configured to transmit to the receiver node 28 via its output 27, the bit stream of optical pulses and switch between first and second QKD protocols based upon at least one channel condition. As illustrated in FIG. 1, the transmitter node 26 includes a switch 50 for switching between the first and second QKD protocols, which in an embodiment are respectively a continuous-variable QKD (CV-QKD) protocol, and a discrete-variable (DV-QKD) protocol. The transmitter node 26 includes a continuous-variable QKD (CV-QKD) protocol device 54 for generating the CV-QKD protocol and a discrete-variable QKD (DV-QKD) protocol device 56 for generating the DV-QKD protocol.”);
(Bucklew teaches switching between CV-QKD and DV-QKD protocols. These QKD protocols are key sharing schemes for generating or distributing a shared cryptographic key used for encrypted communication.)
wherein the processor performs switching to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present: (see Bucklew, [¶¶0026, 0035-0036]: “A channel monitoring device 60 is configured to monitor at least one channel condition and operate the switch 50 responsive to the measured channel condition. The transmitter node 26 may switch from transmitting optical pulses using, for example, the first CV-QKD protocol to the second DV-QKD protocol when the link distance exceed a threshold, for example, 50 kilometers. The maximum SKR may be achieved with either a CV-QKD protocol or a DV-QKD protocol depending on the link distance as illustrated, where at above a link distance of above about 50 km in this one example, the SKR drops quality to almost zero for communications employing CV-QKD, while communications employing DV-QKD maintain a SKR up to about 250 km. The SKR may be guaranteed to lie within a well-defined range of values to equalize the SKR and facilitate communications planning and ensure that the cryptographic keys can be reliably distributed within a narrow operating window.”);
Although Bucklew discloses, A QKD protocol with an SKR of almost zero cannot generate a usable shared key for the intended encrypted communication, Bucklew does not explicitly disclose
the processor is configured to switch to another key sharing scheme when the shared key cannot be generated by the key sharing scheme being used at present. However, in an analogous art, Langham discloses at 306, when the responding device is unable to find a shared key with the embedded identifier, it can fall back to using a default key and attempt to process the request message using this key. Thus, if the key retrieval failed because the initiating device does not support encoding the key identifier into the SPI of the request message but, however, is provisioned (316) with the same default key, then the message exchange and corresponding security session establishment, can still proceed (312) to completion, at 314. But, if the key retrieval failed because the default key was not provisioned (316) into the responding device, session negotiation stops at 308.” (see Langham, [¶¶0032-0033]: “Accordingly, at 306, when the responding device is unable to find a shared key with the embedded identifier, it can fall back to using a default key and attempt to process the request message using this key. Thus, if the key retrieval failed because the initiating device does not support encoding the key identifier into the SPI of the request message but, however, is provisioned (316) with the same default key, then the message exchange and corresponding security session establishment, can still proceed (312) to completion, at 314. But, if the key retrieval failed because the default key was not provisioned (316) into the responding device, session negotiation stops at 308.”);
(Bucklew teaches switching between QKD protocols when the current protocol becomes unable due to monitored channel conditions. Langham further teaches fallback key use when a shared key cannot be found or key retrieval fails. Therefore, it suggests switching to another available key sharing option when the current key process cannot provide the shared key.)
Therefore, it would have been obvious to a person of ordinary skill in the art at the time of the invention to modify Bucklew’s QKD protocol-switching method to switch to another key sharing scheme when the currently used scheme cannot generate or provide a usable shared key, in view of Langham’s fallback-key teaching. Bucklew already teaches switching between QKD protocols to maintain reliable key distribution under changing channel conditions, and Langham teaches using an alternate or default key option when shared key retrieval fails to that secure session establishment can continue. A person of ordinary skill in the art would have been motivated to combine these teachings in order to maintain secure encrypted communication when the current key sharing process fails or becomes unsuitable. The combination would have predictably resulted in a method that switches to another available key sharing scheme to continue share-key generation and encrypted communication.
As to claim 8, Bucklew teaches:
(Currently Amended) A non-transitory computer-readable recording medium storing a[[A]] program causing a computer to perform the method of claim 7: (see Bucklew, [¶0023, 0030]: “The transmitter node 26 includes a controller 44 operatively connected to the laser pulse source 40 and other components at the transmitter node for controlling their operation, such that the laser pulse source is controlled for transmitting a photon in a polarization state defined by the bit and basis, and record the time the photon was transmitted. The controller 76 at the receiver node 28 may be connected to a conventional transceiver 78 also located at the receiver node 28. This transceiver 78 may communicate via the conventional or non-quantum communication system 22 with the transceiver 46 located at the transmitter node 26.”);
(Bucklew teaches transmitter and receiver nodes having controllers that perform QKD protocol-switching operations. It would have been obvious to implement those controller operations as stored program instructions on a non-transitory computer-readable recording medium because this is a conventional way to cause a processor/controller to perform communication and cryptographic operations.)
Claims 5 is rejected under 35 U.S.C. 103 as being unpatentable over Bucklew et al, (U.S. Pub. No. 2022/0353067 A1, hereinafter “Bucklew”) in view of Langham et al, (U.S. Pub. No. 2012/0036363 A1, hereinafter “Langham”), and in further view of Sinha et al, (U.S. Pub. No. 2023/0318818 A1, hereinafter “Sinha”).
As to claim 5, the combination of Bucklew in view of Langham teaches all the limitations recites in claim 4 above
The combination of Bucklew in view of Langham does not teach, but Sinha teaches:
(Original) wherein the plurality of key sharing schemes include at least quantum key distribution and post-quantum key exchange: (see Bucklew, [¶0036]: “Besides just two protocols—one CV-QKD and one DV-QKD, the system may use a plurality of protocols, for example, a bank of protocols could be drawn from based on channel condition. For one channel condition, the system 20 may use all DV-QKD protocols, e.g., four protocols to complete a key transmission or mission objective. For another series of channel conditions, the system may use all CV-QKD and draw from the bank three protocols to meet that mission objective, or for yet another type of fluctuating channel condition, the system could draw, for example, six protocols from the bank that would represent a mix between CV-QKD and DV-QKD resources to satisfy mission objectives in those atmospheric conditions.”);
(see Sinha, [¶¶0012, 0014, 0040]: “One technique that utilizes quantum cryptography is quantum key distribution (QKD) (e.g., QKD is an example of a quantum cryptographic task). QKD uses quantum physics to securely agree on symmetric encryption keys. Some implementations described herein enable quantum cryptography in an IKE procedure. For example, a post-quantum preshared key (PPK) may be used in the IKE protocol. The additional shared secret (e.g., the PPK) may be used to generate keys associated with the IKE protocol. The PPK may be a quantum key obtained via a QKD. As shown by reference number 250, the first network device 210 may generate the key(s) for the IKE procedure based on using the quantum key as the PPK.”);
(Bucklew teaches selecting from a plurality or bank of QKD protocols based on monitored channel conditions. Sinha teaches quantum key distribution (QKD) and also teaches using a post-quantum preshared key (PPK) in an IKE procedure to generate keys for secure communication.)
Therefore, it would have been obvious to a person of ordinary skill in the art at the time of the invention to modify Bucklew’s adaptive protocol switching communication system to include Sinha’s post quantum pre shared key IKE key exchange scheme as one of the available key sharing schemes. Bucklew teaches using a plurality or bank of protocols and selecting an appropriate protocol based on channel condition. Sinha teaches that conventional key asymmetric exchange techniques maybe vulnerable to attacks by quantum computers and that using a post-quantum preshared key in an IKE procedure to improves security for establishing secure communications. A person of ordinary skill in the art would have been motivated to include Sinha’s post quantum key exchange technique in Buckelew’s plurality of available key sharing schemes in order to provide an additional quantum resistant key sharing option for maintaining secure encrypted communication. The combination would have been predictably resulted in Bucklew’s communication system having both QKD based key sharing and post quantum IKE based key exchange options.
Specification
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ARHAM AHMED whose telephone number is (571)272-8950. The examiner can normally be reached Monday-Friday 7:30 am - 5 pm. Alternate Friday off..
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/A.N.A./Examiner, Art Unit 2437
/ALI S ABYANEH/Primary Examiner, Art Unit 2437