DETAILED ACTION
Authorization for Internet Communications
The examiner encourages Applicant to submit an authorization to communicate with the examiner via the Internet by making the following statement (from MPEP 502.03):
“Recognizing that Internet communications are not secure, I hereby authorize the USPTO to communicate with the undersigned and practitioners in accordance with 37 CFR 1.33 and 37 CFR 1.34 concerning any subject matter of this application by video conferencing, instant messaging, or electronic mail. I understand that a copy of these communications will be made of record in the application file.”
Please note that the above statement can only be submitted via Central Fax (not Examiner's Fax), Regular postal mail, or EFS Web using PTO/SB/439.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Election/Restrictions
Applicant's election with traverse of claims 1 – 4 and 6 - 10 in the reply filed on 05/22/2026 is acknowledged. The traversal of the restriction requirement has been fully considered but is not found persuasive because of the followings;
Applicant argues that the elected and non-elected claims are directed to complementary aspects of the same distributed asymmetric decryption protocol, that subsequentially the same prior art would be searched for both groups of claims, and that the Office has not identified specific classifications, search fields, prior art, or examination issues supporting the restriction requirement.
The Examiner respectfully disagrees with this argument because the restriction requirement was made because the claims are directed to patentably distinct species. As set forth in the restriction requirement, the elected species is directed to a second-party/network-device implementation, whereas the non-elected species is directed to a first-party/client-device implementation. Although the claims are related toa common distributed asymmetric decryption protocol, they define different claimed subject matter by reciting different participants performing different operations using different respective shares of the secret key. More particularly, the elected claims are directed to operations including receiving a zero-knowledge proof of knowledge, determining whether the proof was generated based on another party’s share of the secret key, and providing information derived from the second party’s own secret-key share. In contrast, the non-elected claims are directed to generating the zero-knowledge proof of knowledge, transmitting the proof together with ciphertext-related inputs, receiving information from another party, and generating the decryption using the first party’s secret-key share. Thus, each species is directed to a different claimed invention from the perspective of a different participant in the distributed cryptographic protocol. Applicant’s argument that both species operate within the same protocol does not establish that they constitute a single invention for purposes of restriction practice. The determination of patentable distinctness is based upon the inventions as claimed. Although the claims share certain common subject matter, including the use of distributed asymmetric decryption, zero-knowledge proofs, and ciphertext processing, each species recites a different combination of limitations directed to different participants performing different functions. The presence of common limitations does not precludes a restriction where the claimed inventions are otherwise distinct.
Applicant further argues that substantially the same references would be searched for both species.
The Examiner respectfully disagrees with this argument because the restriction requirement was based on the Examiner’s determination that examination of the different claimed inventions would present a serious search and/or examination burden because the invention have acquired a separate status in the art, as stated in the restriction requirement. The fact that certain references may be relevant to both species does not, by itself, establish that the search and examination required for the respective claimed inventions would be the same. The Examiner maintains that the differences in the claimed subject matter support the determination that separate examination of the patentably distinct species would impose the search and examination burden set forth in the restriction requirement.
Applicant also argues that the Office did not identify specific classifications, search fields, prior art, or examination issues.
The Examiner respectfully disagrees with this argument because the restriction requirement identified the basis upon which the Examiner determined that the claimed specifies are distinct and that a serious search and/or examination burden exists. Applicant has not presented persuasive argument or evidence demonstrating that the Examiner’s determination was in error.
The requirement is still deemed proper and is therefore made FINAL.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 12/20/2024 and 03/07/2025 are being considered by the examiner.
Claim Objections
Claims 3 – 4, 6 – 10 are objected to because of the following informalities:
Regarding claim 3, the limitations “the power of a randomly generated number” and “the size of the cyclic group” lack proper antecedent basis.
Claims 4 and 6 – 8 are dependent claims and thus also objected.
Regarding claim 6, the limitation “the power of the second value” lacks proper antecedent basis. Further, there appears to be a missing “and” at the end of line 14.
Regarding claims 6 and 8; the phrases “optionally comprises” in claim 6 and “optionally further comprising” in claim 8 render the claim awkward and is not positive claim language. Applicant is requested to amend the claim to positively recite the claimed subject matter.
Regarding claim 8; the phrase “and/or” renders the claim awkward and is not positive claim language. Applicant is requested to amend the claim to positively recite the claimed subject matter.
Regarding claim 9, the limitation “the party” lacks proper antecedent basis because there is multiple different citation “a first party”, “a second party”, and “a party” earlier in the claim.
Regarding claim 10, the limitation “the secret key” in line 7 lacks proper antecedent basis because there is multiple different recitation “a first share of a secret key” and “a second share of a secret key” earlier in the claim.
Appropriate correction is required.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1 – 2 and 9 - 10 are rejected under 35 U.S.C. 103 as being unpatentable over the prior art of record, Badrinarayanan et a., (US 2021/0391987 A1) (hereinafter “Badrinarayanan”) (submitted by the applicant via IDS 12/30/2024) in view of JOYE et al., (US 2015/0381350 A1) (hereinafter “JOYE”).
Regarding claim 1, Badrinarayanan discloses; a computer-implemented method for distributed asymmetric decryption between a first party and a second party, each of the first and second parties holding a different respective share of a secret key [i.e., distributed threshold decryption using multiple parties processing different secret-key shares (see abstract), (para 0470 - 0471), (para 0482 - 0484), (para 0486), and (0487), (see figures 1, 3, and 4)], the method comprising:
receiving, at the second party: (i) a zero-knowledge proof of knowledge [i.e., receipt of accompanying proof (para 0470 - 0471), (para 0474) and (para 0483), (see figures 1, 3, and 4)]; and (ii) a plurality of inputs associated with a ciphertext to be decrypted, wherein the ciphertext is encrypted with a public key associated with the secret key [i.e., receipt of ciphertext (para 0470 – 0471), (para 0473), (para 0482 – 0484), (para 0486 – 0487), (see figures 1, 3, and 4)];
checking, by the second party, that the zero-knowledge proof of knowledge was generated [i.e., verification of proof (para 0471), (para 0474) and (para 0483), (see figures 1, 3, and 4)]; and
in response to determining that the zero-knowledge proof of knowledge was generated, sending, by the second party, information derived from the second party's share of the secret key [i.e., generating and transmitting a partial decryption/share after successful verification (para 0471), (para 0474), (para 0483) and (para 0487), (see figures 1, 3, and 4)].
Badrinarayanan do not disclose;
based on the first party’s share of the secret key.
However, JOYE discloses;
checking based on a first party’s share of a secret key [i.e., generating a non-interactive proof of knowledge for the secret element associated with the private-key share (para 0032) i.e., generating a partial decryption share including that proof (para 0033) i.e., verifying validity of the non-interactive proof before accepting the decryption share (para 0034 – 0039), (para 0066 – 0072), and (para 0107 – 0116)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Badrinarayanan by adapting the teaching of JOYE to provide a scheme that is secure against chose ciphertext attacks, non-interactive and that should retain the decryption consistency property (See JOYE; page 2, para 0015).
Regarding claim 2, Badrinarayanan discloses; the method of claim 1, wherein the information derived from the second party's share of the secret key is calculated by applying the second party's share of the secret key to an element of the ciphertext [i.e., computing a partial decryption from the local secret share and ciphertext (para 0470 – 0471), (para 0473), (para 0482 – 0484), (para 0486 – 0487), (see figures 1, 3, and 4)].
Regarding claim 9, Badrinarayanan discloses; the method of claim 1, further comprising blacklisting a party from which a zero-knowledge proof of knowledge was received, when it is determined that the zero knowledge proof of knowledge received from the party was not generated based on the first party's share of the secret key [i.e., rejecting invalid participant (para 0482 - 0484), (para 0486), and (0487), (see figures 1, 3, and 4)].
Regarding claim 10, Badrinarayanan discloses; a network device configured for performing distributed asymmetric decryption with a client device holding a first share of a secret key, the network device comprising a memory storing a second share of the secret key [i.e., distributed threshold decryption using multiple parties processing different secret-key shares (see abstract), (para 0470 - 0471), (para 0482 - 0484), (para 0486), and (0487), (see figures 1, 3, and 4)], and being configured to perform the steps:
receiving, at the network device: (i) a zero-knowledge proof of knowledge [i.e., receipt of accompanying proof (para 0470 - 0471), (para 0474) and (para 0483), (see figures 1, 3, and 4)]; and (ii) a plurality of inputs associated with a ciphertext to be decrypted, wherein the ciphertext is encrypted with a public key associated with the secret key [i.e., receipt of ciphertext (para 0470 – 0471), (para 0473), (para 0482 – 0484), (para 0486 – 0487), (see figures 1, 3, and 4)];
checking, by the network device, that the zero-knowledge proof of knowledge was generated [i.e., verification of proof (para 0471), (para 0474) and (para 0483), (see figures 1, 3, and 4)]; and
in response to determining that the zero-knowledge proof of knowledge was generated, sending, by the network device, information derived from the second party's share of the secret key [i.e., generating and transmitting a partial decryption/share after successful verification (para 0471), (para 0474), (para 0483) and (para 0487), (see figures 1, 3, and 4)].
Badrinarayanan do not disclose;
based on the client device's share of the secret key.
However, JOYE discloses;
checking based on the client device's share of the secret key [i.e., generating a non-interactive proof of knowledge for the secret element associated with the private-key share (para 0032) i.e., generating a partial decryption share including that proof (para 0033) i.e., verifying validity of the non-interactive proof before accepting the decryption share (para 0034 – 0039), (para 0066 – 0072), and (para 0107 – 0116)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Badrinarayanan by adapting the teaching of JOYE to provide a scheme that is secure against chose ciphertext attacks, non-interactive and that should retain the decryption consistency property (See JOYE; page 2, para 0015).
Allowable Subject Matter
Claims 3 – 4, 6 – 8 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
The following is a statement of reasons for the indication of allowable subject matter:
Regarding claim 3;
the prior art of record, Badrinarayanan and JOYE discloses the method of claim 2,
However, Badrinarayanan and JOYE do not disclose “wherein the ciphertext comprises at least three elements: a first element, comprising a generator of a cyclic group raised to the power of a randomly generated number within the size of the cyclic group; a second element, comprising an encryption of a plaintext based on the public key, a hashing function, and the randomly generated number; a third element, comprising a non-interactive zero-knowledge proof of knowledge which is based on the randomly generated number”.
These claimed limitations are not present in the prior arts of record and would not have been obvious. They in combination with other elements cited present subject matter that is novel and nonobvious. Thus, claim 3 is objected being dependent upon rejected base claim.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SYED A RONI whose telephone number is (571)270-7806. The examiner can normally be reached M-F 9:00-5:00 pm (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SYED A RONI/Primary Examiner, Art Unit 2432