DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
Claims 1-10, 21-30 are pending. Claims 11-20 are cancelled.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 7/2/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-4, 8-9, 21-24, 28-29 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Reece (US 7,006,633).
Regarding Claims 1 and 21:
Reece teaches an apparatus and a method for sharing encrypted entropy information ([abstract] a system and method for encryption, transmission and decryption of data based on a publicly or other wide area broadcast random number sequence), the apparatus comprising:
at least one memory ([col 10 line 19-35] a microprocessor 1002 connected to the common bus, a random-access memory RAM); and
at least one processor coupled to the at least one memory and configured to ([col 10 line 19-35] a microprocessor 1002 connected to the common bus, a random access memory RAM):
sample, by a reference device, an entropy associated with the reference device ([col 7 line 14-17] Random Data Stream (RDS) - the continuous stream of random bits to be received by the parties using the present invention to encrypt their communications; [col 22 line 45-col 23 line 15] the agent will generate a new random number, in most cases using the RDS (512); this random number will then be encrypted using Alice's Random Number Reservoir (RNR) (514) and sent to Alice (516); the same random number will also be encrypted using Bob's RNR (518) and sent to Bob (520));
encrypt the entropy based on hardware information of the reference device ([col 7 line 29-41] the RNR is a file of r bits or set of files on the storage device of the users' computers; [col 21 line 56-67] Zeke generates a random number A that he encrypts using the RNR he has in common with Bob, and passes the new random number to Bob; [col 22 line 45-col 23 line 15] the agent will generate a new random number, in most cases using the RDS (512); this random number will then be encrypted using Alice's RNR (514) and sent to Alice (516); the same random number will also be encrypted using Bob's RNR (518) and sent to Bob (520)); and
transmit a message including the encrypted entropy ([col 21line 56-67] Zeke generates a random number A that he encrypts using the RNR he has in common with Bob, and passes the new random number to Bob).
Regarding Claims 2 and 22:
Reece teaches the apparatus of claim 1 and the method of claim 21. In addition, Reece teaches wherein the at least one processor is configured to:
communicating with a plurality of peer devices based on at least one of a public key and a private key, wherein each of the plurality of peer devices includes the hardware information ([col 12 line 64-col 13 line 8] private key k; [col 13 line 18-37] the most crucial variable that k (or a sub key) and z will determine is the time t when the First User Computer 108a and Second User Computer 108b, referenced collectively as User Computer 108, will sample the RDS; [col 14 line 4-11] referring to FIG. 2, step 214 finishes, for this example, by downloading the samples (SMP) to the appropriate Random Number Reservoir RNR in the storage of the User Computer 108; the term "appropriate" is used because it is contemplated that the User Computer 108 can maintain a plurality of Random Number Reservoirs, RNR, each associated with a particular party in communication and its particular private key k).
Regarding Claims 3 and 23:
Reece teaches the apparatus of claim 1 and the method of claim 21. In addition, Reece teaches wherein the hardware information comprises an encryption key stored in an integrated circuit of the reference device ([col 11 line 5-21] User Computing System 108n must have the capability to store segments of the RDS data; the means for such storage covers a wide number of potential devices, including… flash memory (i.e. “an integrated circuit”); [col 21line 56-67] Zeke generates a random number A that he encrypts using the RNR he has in common with Bob, and passes the new random number to Bob).
Regarding Claims 4 and 24:
Reece teaches the apparatus of claim 3 and the method of claim 23. In addition, Reece teaches wherein the encryption key is symmetric ([col 21line 56-67] Zeke generates a random number A that he encrypts using the RNR he has in common with Bob (i.e. “symmetric”), and passes the new random number to Bob).
Regarding Claims 8 and 28:
Reece teaches the apparatus of claim 1 and the method of claim 21. In addition, Reece teaches wherein the at least one processor is configured to:
receive group information including the hardware information ([col 12 line 64-col 13 line 8] private key k; [col 13 line 18-37] the most crucial variable that k (or a sub key) and z will determine is the time t when the First User Computer 108a and Second User Computer 108b, referenced collectively as User Computer 108, will sample the RDS; [col 14 line 4-11] referring to FIG. 2, step 214 finishes, for this example, by downloading the samples (SMP) to the appropriate Random Number Reservoir RNR in the storage of the User Computer 108; the term "appropriate" is used because it is contemplated that the User Computer 108 can maintain a plurality of Random Number Reservoirs, RNR, each associated with a particular party in communication and its particular private key k).
Regarding Claims 9 and 29:
Reece teaches the apparatus of claim 1 and the method of claim 21. In addition, Reece teaches wherein the entropy comprises a pair of entropy values ([col 7 line 14-17] Random Data Stream (RDS) - the continuous stream of random bits to be received by the parties using the present invention to encrypt their communications; [col 22 line 45-col 23 line 15] the agent will generate a new random number, in most cases using the RDS (512); [col 22 line 1-7] Alice could generate two random numbers and pass one to Zeke as an encrypted message and one to Yvonne as encrypted message).
Claim(s) 10, 30 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Reece, and as further evidenced by FIPS 203 (“Module-Lattice-Based Key-Encapsulation Mechanism Standard”).
Regarding Claims 10 and 30:
Reece teaches the apparatus of claim 9 and the method of claim 29. In addition, Reese teaches wherein the entropy values are smaller than Module-Lattice Key Encapsulation Mechanism (ML-KEM) lattices ([col 22 line 45-col 23 line 15] this random number will then be encrypted using Alice's RNR (514) and sent to Alice (516); the same random number will also be encrypted using Bob's RNR (518) and sent to Bob (520); Alice and Bob will each decrypt this message from the trusted agent revealing the trusted agent's random number; this process will be repeated for the other trusted agent; then Bob and Alice will XOR the two random numbers to obtain a new and unique random number that may function as a secure private key (i.e. the private key will be the size of the random numbers); [col 17 line 31-37] the private key k may be variable in size; [col 18 line 2] k could be as short as a single bit; note: the smallest variant of ML-KEM, ML-KEM-512, has an encapsulation key of 800 bytes, a decapsulation key of 1632 bytes, and a shared secret key of 32 bytes, See FIPS 203, “Module-Lattice-Based Key-Encapsulation Mechanism Standard”, page 39, Table 3).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 5, 25 is/are rejected under 35 U.S.C. 103 as being unpatentable over Reece, and further in view of Griffin et al (PGPUB 2023/0283456).
Regarding Claims 5 and 25:
Reece teaches the apparatus of claim 1 and the method of claim 21.
Reece does not explicitly teach wherein an algorithm used to encrypt the entropy is compliant with Federal Information Processing Standards (FIPS).
However, Griffin teaches the concept wherein an algorithm used to encrypt an entropy is compliant with Federal Information Processing Standards (FIPS) ([0085]-[0086] DBESKM enhances DBEKM by adding encryption of the seed 132 and/or other elements exchanged between the database server 116 and the HSM 118 using asymmetric cryptography (e.g. RSA) and digital signatures (e.g. RSA, DSA, and/or ECDSA); DBESKM makes use of currently known encryption algorithms (e.g. AES 256, FIPS 197), the keyed hash message authentication code (HMAC) algorithm (FIPS 198-1) using currently known hash algorithms (e.g., SHA 256, FIPS 180-4), a suitable key derivation algorithm (e.g. SHA 256, FIPS 180-4), and currently known methods for digital signatures (e.g. RSA, X9.31, DSA, FIPS 186-4, ECDSA, X9.62); in some embodiments, cryptographically protected items are packaged into X9.73 messages, such as SignedData and NamedKey EncryptedData; according to various embodiments, DBESKM may incorporate additional asymmetric cryptography (e.g. Signcryption, X9.73, ISO/IEC 29150) and quantum resistant algorithms (e.g. Lattice-Based Polynomial Public Key Establishment Algorithm, X9.98) to cryptographically protect the seed 132 and/or other elements).
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the FIPS approved encryption algorithm teachings of Griffin with the global encryption system of Reece, in order to incorporate FIPS approved algorithms for use in the transfer of entropy material, thereby improving the security environment by relying on security standards which have been thoroughly vetted by standards organizations to verify that they meet a minimum level of security and contain no obvious vulnerabilities or exploits.
Claim(s) 6-7, 26-27 is/are rejected under 35 U.S.C. 103 as being unpatentable over Reece, and further in view of Lee et al (PGPUB 2025/0337567).
Regarding Claims 6 and 26:
Reece teaches the apparatus of claim 1 and the method of claim 21.
Reece does not explicitly teach wherein the at least one processor is configured to:
generate a private key and a public key based on the entropy based on providing the entropy to a random number generator of the reference device.
However, Lee teaches the concept of generating a private key and a public key based on an entropy based on providing the entropy to a random number generator of a reference device ([0010] hash sampler module configured to generate a pseudo-random number using an arbitrary input or a public seed input from a key decoder and to output the same through a squeeze function; [0033] module-lattice-based key encapsulation mechanism (ML-KEM) post-quantum cryptography system presented herein is a lattice-based PKE/KEM public key encryption method; a lattice-based encryption algorithm is an NP-hard-based encryption algorithm that makes it difficult to find a specific vector on a lattice present in an n-dimensional space and uses a Ring-learning with error (LWE) method; [0034] public key encryption method, Ring-LWE, includes a public key used for encryption and a private key used for decryption; Ring-LWE is as shown in (Equation 1-2) and generates a public key and a private key using random values, such as public matrix a, a secret key s, and an error value e with a Gaussian distribution; [0042] the hash sampler module 110 according to an example embodiment is implemented using an f-permutation function of a Keccak algorithm, generates a pseudo-random number using an arbitrary input or a public seed input from a key decoder, and outputs the same through a squeeze function; [0043] the rejection sampler module 122 that is one of sampler modules according to an example embodiment refers to a sampling method using the principle of probability distribution, and is used to generate a polynomial matrix and a transpose matrix for public key generation and encryption using a method of receiving the pseudo-random number and performing extraction and rejection for corresponding sampling).
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the use of entropy to generate public/private keys teachings of Lee with the global encryption system of Reece. Reece is concerned with the secure exchange of random numbers; however, the techniques and algorithms used to set up the exchange have limitations: the RNR of Reece comprises numbers broadcast from a common source, and is thus vulnerable to interception. Using the collected random number data as a seed in an ML-KEM algorithm, such as in Lee, incorporates the benefit of dramatically improving the overall entropy of the system, and take advantage of algorithms which are approved to be quantum-secure, thus elevating the system to the standards of post-quantum cryptography.
Regarding Claims 7 and 27:
Reece in view of Lee teaches the apparatus of claim 6 and the method of claim 26. In addition, Lee teaches wherein the private key and the public key comprise Module-Lattice Key Encapsulation Mechanism (ML-KEM) lattices ([0033] module-lattice-based key encapsulation mechanism (ML-KEM) post-quantum cryptography system presented herein is a lattice-based PKE/KEM public key encryption method; a lattice-based encryption algorithm is an NP-hard-based encryption algorithm that makes it difficult to find a specific vector on a lattice present in an n-dimensional space and uses a Ring-learning with error (LWE) method).
The rationale to combine Reece and Lee is the same as provided for claims 6 and 26 due to the overlapping subject matter between claims 6 and 7, 26 and 27.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FORREST L CAREY whose telephone number is (571)270-7814. The examiner can normally be reached 9:00AM-5:30PM M-F.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at (571) 272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/FORREST L CAREY/Examiner, Art Unit 2491
/WILLIAM R KORZUCH/Supervisory Patent Examiner, Art Unit 2491