DETAILED ACTION
This is in response to the application filed on March 5, 2025. A preliminary amendment was filed on April 30, 2025, where Claims 1 – 20, of which Claims 1, 12, 15, and 16 are in independent form, are presented for examination.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on March 5, 2025 was filed before the mailing date of the current action. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
101 Analysis
Claims 1 and 12 are directed to generating device specific data used to verify N chained certificates. While the use of hashes and other mathematical computations are generally not considered statutory, the application within the generating and verifying of N chained certificates using a particular key generation method is a particular improvement directed to a particular technological environment [See Specification, Para. 0011-16]. Therefore, the claims integrate the judicial exception into a practical application and satisfies Step 2A, Prong Two of the 2019 Revised 101 Patent Eligibility Guidelines as patent eligible subject matter.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1 – 20 are rejected under 35 U.S.C. 103 as being unpatentable over PGPub. 2022/0038272 (hereinafter “Hershman”), in view of PGPub. 2021/0028933 (hereinafter “Medvinsky”).
1. Regarding Claims 1, 15, and 19, Hershman discloses a computer-implemented method for attesting authenticity of a first computing device [Fig. 1; Para. 0057-58, 0098-99; computing device with code stored in memory to execute functions; device attestation and verification], said first computing device being provisioned with a unique device secret ("UDS") [Fig. 4; Para. 0030], the method comprising, by the first computing device:
generating an N chained certificate(s) [Para. 0091, 0094], the N chained certificate(s) attesting the authenticity of an N set(s) of device-specific data of the first computing device [Fig. 4; Para. 0064, 0091, 0094]; and
transmitting the N chained certificate(s) to a second computing device [Fig. 4; Para. 0035],
wherein the generating the N chained certificate(s) further includes a generation process that includes:
A) deriving, using a key (derivation function)
B) generating an authentication tag from a set of device-specific data, using the key [Para. 0064, 0093];
C) generating a certificate, said certificate including the set of device-specific data and the authentication tag [Fig. 4; Para. 0094];
D) encrypting the set of device-specific data with the key [Fig. 4; Para. 0093]; and
E) providing the encrypted set of device-specific data as an input to the key (derivation function)
Hershman, however, does not specifically disclose that the key generator is a key ladder.
Medvinsky discloses a system and method for generating keys specific to a particular device [Abstract]. Medvinsky further discloses that key ladders are well known to generate a plurality of chip unique keys that are derived from a single root key [Fig. 5; Para. 0003-4]. It would have been obvious to one skilled in the art before the effective date of the current invention to incorporate the teachings of Medvinsky with Hershman since both systems generate multiple device-specific key from the same device-specific base key/secret. The combination enables the Hershman system to use a key ladder to generate subsequent key within the authentication process. The motivation to do so is to use key generation techniques in the art to provide multiple keys from a root secret for quick implementation (obvious to one skilled in the art).
2. Regarding Claim 2, Hershman, in view of Medvinsky, discloses the limitations of Claim 1. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses that the key ladder has at least two levels [Hershman; Fig. 4; Para. 0091-93] and the deriving, using the key ladder, further includes:
receiving a higher-level input value [Hershman; Fig. 4; Para. 0091-93]; and
deriving a higher-level key from the UDS used as a key or from a UDS-derived key with the higher-level input value [Hershman; Fig. 4; Para. 0091-93].
3. Regarding Claim 3, Hershman, in view of Medvinsky, discloses the limitations of Claim 2. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses that the higher-level input value received by the key ladder includes a predetermined constant that is the same for all the generation processes [Hershman; Fig. 4; Para. 0091].
4. Regarding Claim 4, Hershman, in view of Medvinsky, discloses the limitations of Claim 2. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses that the deriving, using the key ladder, further includes:
deriving the key from the higher-level key with a lower-level input value [Hershman; Fig. 4; Para. 0091-3].
5. Regarding Claim 5, Hershman, in view of Medvinsky, discloses the limitations of Claim 4. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses that the deriving further includes:
for a first generation process, receiving, at the key ladder, a predetermined initial value as lower-level input value [Hershman; Fig. 4; Para. 0091-3]; and
for each of subsequent generation processes, receiving, at the key ladder, the encrypted set of device-specific data provided by a preceding generation process as
lower-level input value [Hershman; Fig. 4; Para. 0091-3].
6. Regarding Claim 6, Hershman, in view of Medvinsky, discloses the limitations of Claim 1. Hershman further discloses that the generating the authentication tag from the set of device-specific data, using the key and the encrypting the set of device-specific data with the key are combined by executing an authenticated encryption algorithm to simultaneously encrypt the set of device-specific data and generate the authentication tag from the set of device-specific data with the key derived from the UDS in the deriving [Para. 0091-93].
7. Regarding Claim 7, Hershman, in view of Medvinsky, discloses the limitations of Claim 1. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses that the deriving further includes deriving, using the key ladder, two keys, different from one another, from the UDS used as a key [Hershman; Para. 0091-93; Medvinsky; Para. 0003; different keys for different functions],
the generating the authentication tag further includes generating the authentication tag with one of the two keys [Hershman; Para. 0091-93; Medvinsky; Para. 0003; different keys for different functions], and
the generating the certificate further includes encrypting the set of device-specific data with the other of the two keys [Hershman; Para. 0091-93; Medvinsky; Para. 0003; different keys for different functions].
8. Regarding Claim 8, Hershman, in view of Medvinsky, discloses the limitations of Claim 7. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses that the two keys are separately derived from the UDS by the key ladder using respectively a first higher-level input value and a second higher-level input value, different from one another [Hershman; Para. 0091-93; Medvinsky; Para. 0003; different keys for different functions].
9. Regarding Claim 9, Hershman, in view of Medvinsky, discloses the limitations of Claim 1. Hershman further discloses that, in the generating the authentication, the authentication tag is a block cipher-based message authentication code [Para. 0065].
10. Regarding Claim 10, Hershman, in view of Medvinsky, discloses the limitations of Claim 1. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses of generating a final certificate [Hershman; Para. 0091-94], including:
receiving challenge data from the second computing device [Hershman; Para. 0091-94, 0101-102];
receiving, by the key ladder, the encrypted set of device-specific data
provided by a preceding generation process [Hershman; Para. 0091-94, 0101-102];
deriving, by the key ladder, a key from the UDS using said encrypted set of device-specific data as input data [Hershman; Para. 0091-94, 0101-102];
generating a final tag from the challenge data using the key [Hershman; Para. 0091-94, 0101-102]; and
generating the final certificate including the challenge data and the final tag [Hershman; Para. 0091-94, 0101-102].
11. Regarding Claim 11, Hershman, in view of Medvinsky, discloses the limitations of Claim 1. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses that the deriving further includes executing a cryptographic algorithm including at least one of a decryption algorithm and an encryption algorithm, at each of a plurality of levels of the key ladder [Hershman; Para. 0091-94].
12. Regarding Claims 12, 16, and 20, Hershman discloses of a computer implemented method for attesting the authenticity of a first computing device provisioned with a unique device secret ("UDS") [Fig. 5A-5B; Para. 0030, 0035], by a second computing device provisioned with a key that is derived from the UDS of the first computing device [Para. 0073], the method comprising:
receiving, by the second computing device, from the first computing device, an N
chained certificate(s) generated by the method according to claim 1 [Fig. 4; Para. 0035, 0091-93]; and
verifying, by the second computing device, the validity of the N chained certificate(s) [Fig. 5A-5B; Para. 0107-108],
wherein the verifying the validity of the N chained certificate(s) further includes a verification process, performed by the second computing device [Fig. 5A], that includes:
F) deriving, by a key derivation module, a key from said provisioned key [Fig. 4, 5A-5B; Para. 0106-108];
G) generating a verification tag from a set of device-specific data included in a certificate to be verified using the key [Fig. 4, 5A-5B; Para. 0106-108];
H) comparing the verification tag and an authentication tag included in the certificate to be verified [Fig. 4, 5A-5B; Para. 0106-108];
I) if the verification tag and the authentication tag match, validating the certificate [Fig. 4, 5A-5B; Para. 0106-108];
J) encrypting the set of device-specific data included in the certificate to be verified with the key [Fig. 4, 5A-5B; Para. 0106-108]; and
K) providing the encrypted set of device-specific data as an input to the key derivation module for a subsequent verification process [Fig. 4, 5A-5B; Para. 0106-108].
Hershman, however, does not specifically disclose that the key generator is a key ladder.
Medvinsky discloses a system and method for generating keys specific to a particular device [Abstract]. Medvinsky further discloses that key ladders are well known to generate a plurality of chip unique keys that are derived from a single root key [Fig. 5; Para. 0003-4]. It would have been obvious to one skilled in the art before the effective date of the current invention to incorporate the teachings of Medvinsky with Hershman since both systems generate multiple device-specific key from the same device-specific base key/secret. The combination enables the Hershman system to use a key ladder to generate subsequent key within the authentication process. The motivation to do so is to use key generation techniques in the art to provide multiple keys from a root secret for quick implementation (obvious to one skilled in the art).
13. Regarding Claim 13, Hershman, in view of Medvinsky, discloses the limitations of Claim 12. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses that the said provisioned key corresponds to a higher-level key generated by the key ladder in the deriving the key [Hershman; Fig. 4; Para. 0091].
14. Regarding Claim 14, Hershman, in view of Medvinsky, discloses the limitations of Claim 13. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses that, in a first verification process, the deriving, by the key derivation module, the key from the provisioned key includes receiving as input, by the key derivation module, a predetermined initial value that is the same as the predetermined initial value received by the key ladder as lower-level input in a first generation process [Para. 0091-93].
15. Regarding Claim 17, Hershman, in view of Medvinsky, discloses the limitations of Claim 16. Hershman further discloses of a system comprising the first computing device and the second computing device according to claim 16 [Figs. 1 and 5A-5B].
16. Regarding Claim 18, Hershman, in view of Medvinsky, discloses the limitations of Claim 17. The combination of Hershman and Medvinsky (Para. 0003-4; key ladder) further discloses that the key ladder has at least two levels and the circuitry is further configured to derive the key from the UDS [Hershman; Fig. 4; Para. 0030, 0091-93], using the key ladder, by being configured to:
receive a higher-level input value [Hershman; Fig. 4; Para. 0030, 0091-93], and
derive a higher-level key from the UDS used as a key or from a UDS-derived key with the higher-level input value [Hershman; Fig. 4; Para. 0030, 0091-93]; and
wherein the higher-level input value received by the key ladder includes a predetermined constant that is the same for all the generation processes [Hershman; Fig. 4; Para. 0030, 0091-93].
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. U.S. Patent 10,742,421; PGPub. 2022/0045848.
Contacts
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAE K KIM whose telephone number is (571)270-1979. The examiner can normally be reached M-F 9:30-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached at 5712727642. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/TAE K KIM/Primary Examiner, Art Unit 2496