DETAILED ACTION
Claims 1-12, 15-17, 19-22, and 26 are presented for examination. Claims 13-14, 18, and 23-25 have been canceled.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The Information Disclosure Statement(s) submitted by applicant on 01/15/2025 has/have been considered. The submission is in compliance with the provisions of 37 CFR § 1.97. Form PTO-1449 signed and attached hereto.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-12, 15-17, 19-22, and 26 are rejected under 35 U.S.C. 103 as being unpatentable over Sebastien et al. (EP 3917078 A1) (Hereinafter Sebastien) in view of Acar et al. (US Patent Application No. US 20140281525 A1) (Hereinafter Acar).
As per claim 1, Sebastien discloses computer-implemented method for proving ownership and/or possession of data m, the method comprising:
generating, based on a secret value r and the data m, a data commitment value (para 23, 34, c.sub.i = g.sup.di ∗ h.sup.xi, wherein g and h are prime order generators, d.sub.i represents a hah of the personal data i and x.sub.i represents as associated secret required to open the commitment);
generating a challenge solution π associated with a designated verifier (para 15,16,24, 35, interactive Schnorr protocol between user (prover and verifier, The prover generates the proof messages exchanged with verifier), wherein the challenge solution π is a zero-knowledge proof proving knowledge of the secret value r (para 15, 16, 19 24, zero knowledge proof is a Schnorr proof, prover proves knowledge of secret value without revealing it); and
making the data m, the challenge solution π , and the data commitment value available to the designated verifier (para 27, 34-35, user sends data and commitment to verifier, user send a proof message);
wherein the secret value r is not known by, or made available to, the designated verifier (para 15, 34-36, zero knowledge proof where verifier learns no secret).
Sebastien does not explicitly disclose a designated verifier. However, Acar discloses a designated verifier
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combining the teachings of Sebastien and Acar. The motivation would have been to improve security by binding the proof to a specific verifier and enhancing privacy-preserving authentication during verification of committed data. so that the proof is cryptographically bound to particular verifier.
The Examiner notes that this motivation applies to all dependent and/or otherwise subsequently addressed claims.
As per claim 2, Acar discloses wherein the step of generating the challenge solution π associated with the designated verifier comprises generating a verifier commitment value associated with the designated verifier, wherein the challenge solution π comprises the verifier commitment value (para 17, 20, 24, Challenge solution/ZKP, Verifier-generated challenge)
As per claim 3, Acar discloses wherein the method further comprises receiving, from the designated verifier, a verifier commitment key associated with the designated verifier, wherein the zero-knowledge proof associated with the designated verifier is generated based on the verifier commitment key (para 17,20,21, verifier designated key, verifier generated challenge, designated verifiable proof/signature).
As per claim 4, Acar discloses wherein the method further comprises generating a hash of the data commitment value and making the hash of the data commitment value available to the designated verifier (para 20, the credential's commitment to generate a hash value for comparison with the presentation proof).
As per claim 5, Sebastien discloses wherein the method further comprises: generating a proof blockchain transaction which, when stored on a blockchain, renders the hash of the data commitment value available (para 21,26, 30-34, user registered to blockchain, commitment committed to blockchain, indication written to blockchain) ; and
causing the proof blockchain transaction to be made available to one or more nodes of the blockchain (para 21,26, 30-34, user registered to blockchain, commitment committed to blockchain, indication written to blockchain, the commitment is uploaded on the blockchain).
As per claim 6, Sebastien discloses wherein the data commitment value is derived based on a data owner commitment key (para 9, 34, the users would be able to register their public key on the blockchain along with commitments of their personal data).
As per claim 7, Sebastien discloses wherein the method further comprises: providing, to a notary, the data commitment value and the data m (para 20, 42-43, a private key for presenting/signing the attributes and the transaction related data. One example implementation may utilize, in part, the credential's commitment to generate a hash value for comparison with the presentation proof); and receiving, from the notary, a signed version of the data (para 5, 42-43,verifier-generated challenge is signed by the user with the credential's private key and returned to the verifier for verification; para 20, a private key for presenting/signing the attributes and the transaction related data. One example implementation may utilize, in part, the credential's commitment to generate a hash value for comparison with the presentation proof).
As per claim 8, Sebastien discloses wherein the signed version of the data is generated by signing the data commitment value (para 20, 42-43, a private key for presenting/signing the attributes and the transaction related data. One example implementation may utilize, in part, the credential's commitment to generate a hash value for comparison with the presentation proof).
As per claim 9, Sebastien discloses wherein the signed version of the data is generated by signing a hash of the data commitment value, wherein the hash of the data commitment value is received from the notary (para 5, verifier-generated challenge is signed by the user with the credential's private key and returned to the verifier for verification; para 20, a private key for presenting/signing the attributes and the transaction related data. One example implementation may utilize, in part, the credential's commitment to generate a hash value for comparison with the presentation proof).
As per claim 10, Sebastien discloses wherein the method further comprises generating a notarisation blockchain transaction which, when stored on the blockchain, renders the signed version of the data received from the notary available (para 5, 42-43, verifier-generated challenge is signed by the user with the credential's private key and returned to the verifier for verification; para 20, a private key for presenting/signing the attributes and the transaction related data. One example implementation may utilize, in part, the credential's commitment to generate a hash value for comparison with the presentation proof).
As per claim 11, Sebastien discloses wherein the method further comprises generating a notarisation blockchain transaction which, when stored on the blockchain, renders the hash of the data commitment value received from the notary available (para 38, fig 2, can be open only to one hash of data (so an adversary can find two different hashes such that the protocol works). The commitment "commitment" is therefore shared first on the blockchain/public platform).
As per claim 12, Sebastien discloses wherein the method is implemented by a notary, the method further comprising: receiving, from a data owner of the data m, the data m (para 10, 23, 34, 42-43, c.sub.i = g.sup.di ∗ h.sup.xi, wherein g and h are prime order generators, d.sub.i represents a hah of the personal data i and x.sub.i represents as associated secret required to open the commitment) ; and
generating a signature associated with the data m (para 10,t he registration takes as input the public keys of the users, commitments of their personal data and a signature to ensure the integrity of the previous fields).
As per claims 15-17 and 19-22, claims are rejected for the same reasons and motivations as claims 1-12, above.
As per claim 26, claims is rejected for the same reasons and motivations as claim 1, above.
Conclusion
Please see the attached PTO-892 for the prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMAD A SIDDIQI whose telephone number is (571)272-3976. The examiner can normally be reached Monday-Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl G Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MOHAMMAD A SIDDIQI/Primary Examiner, Art Unit 2493