Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 03/19/2025 has been considered by the examiner.
Drawings
The drawings submitted on 02/21/2025 has been accepted.
Specification
The specification submitted on 02/21/2025 has been accepted.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-10 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1, 5, 6 and 10 recite “parameter value then being transmitted…” and “then detecting errors”. Use of the term “then” rendered the limitation indefinite because it introduced unspecified condition or sequence.
Claims 1, 5, 6 and 10 recite “its rank” rendered the limitation indefinite because the pronoun “its” introduces unspecified reference instead of using a proper antecedent basis.
Claims 5, 6 and 10 recite “being referred to hereinafter” rendered the limitation indefinite because the phrase “being referred to hereinafter” introduces unspecified reference instead of using a proper antecedent basis.
Claims 1, 5, 6 and 10 recite the limitation "the basis" in line 11, 10, 13 and 12.
Claims 4 and 9 recite the limitation “the memory” in line 1.
There is insufficient antecedent basis for this limitation in the claim.
Claims 2-4 and 7-8 failed to remedy deficiencies their respective independent claims and therefore 1-10 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 4 and 9 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter because claims 4 and 9 are directed to and calls for a computer program intended to be stored in the memory of a first device and the second device respectively. A computer program intended to be stored in the memory is not a useful process, a machine, a manufacture, or composition of matter. It is a program per se. and does not fall within at least one of the four categories of patent eligible subject matter. Therefor claims 4 and 9 are rejected under 35 U.S.C. 101.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-10 are rejected under 35 U.S.C. 103 as being unpatentable over Jacobs (US 20130315395 A1) in view of VERSCHOOR et al. (US 20220166606 A9—hereinafter—“VERSCHOOR”).
As per claim 1:
Jacobs discloses a method for quantum secret key distribution between a first and a second telecommunications device (D_ALICE, D_BOB) connected by a first and a second telecommunications link (Figure 1-4; System 102 (Alice) and System 104 (Bob)), said first link being an optical transmission link and being a quantum channel (Quantum Channel 113);
said second remote transmission link being a classical channel (Communication channel 116);
said method comprising the following steps, implemented by the first device (D_ALICE):
the first device generating a random sequence of bits (Figure 1 & 4: 108 Random Events (Bits 107 and bases)
for each bit successively considered in the generated sequence,
coding said bit at least by way of a value of a parameter defining a quantum state of a respective light pulse comprising at least one photon, said value of the parameter being determined on the basis of at least the value of said bit, a light pulse having said parameter value then being transmitted on the quantum channel and to the second device following said coding (Figure 1 & 4: Quantum Tx 110; [0060-0062] System 102 includes a quantum transmitter 110 to encode bits 107 as quantum states or quantum bits (qubits) 112 in accordance with bases 109, and to transmit qubits 112 over a quantum communication channel 113, each during a corresponding transmission interval. Quantum transmitter 110 may include a photon transmitter to transmit qubits 112 as polarized photons, and quantum communication channel 113 may include an optical communication channel such as an optical fiber. Quantum transmitter 110 may control polarization with voltages applied to three Pockels cells, and may drive two of the Pockels cells in parallel with one another);
at least one step out of steps j and jj below:
a step j comprising at least calculating parity bits on the basis of bits of the generated sequence ([0035] The first and second systems perform error detection based on values generated from the corresponding modified authentication keys. The modified authentication keys may be used to seed identical pseudo-random number generators, outputs of which may be used to pseudo-randomly arrange bits of the corresponding sifted keys. Parity values may be computed for the pseudo-randomly arranged bits, in private, based on pre-provisioned technique or algorithm. The parity information may be openly disclosed, and errors may be detected and corrected/eliminated privately, to provide corresponding first and second corrected keys); and
transmitting information relating to the calculated parity bits to the second device ([0066-0068]: Transmitter 110 and receiver 114 may be implemented to control voltages of corresponding Pockels cells via digital to analog converters (DACs). A sequence of voltages may be applied to a set of Pockels cells by filling memory buffers with the appropriate values and executing a transfer. Systems 102 and 104 may be implemented to coordinate communication and/or control parameters with one another, such as clock rate, number of transfers, and/or other parameters. One or more of the parameters may be user-controllable and/or may be established by software at each of systems 102 and 104. Systems 102 and 104 may communicate with one another over another communication channel 116, such as an Ethernet link, to coordinate transmission parameters. Systems 102 and 104 may communicate openly over channel 116, such as without encryption and/or user authentication);
a step jj comprising at least:
receiving information from the second device and relating to parity bits calculated by said second device on the basis of the receipt, by the second device, of the light pulses transmitted by the first device ([0098] SEDs 220 and 222 privately compute column and row parities of the corresponding matrices, disclose the parity values over channel 116 as parity information 165, and privately compute parity mismatches based on disclosed parity information 165); and
then detecting errors in said sequence of bits on the basis of the values of said received information relating to the parity bits [0101] In FIG. 2, SEDs 220 and 222 or constructors 240 and 242 may include identical pre-provisioned error elimination algorithms to correct and/or eliminate errors in respective sifted keys 214 and 216. In FIG. 3, error correction algorithms may change bit 312 sifted key 214 or sifted key 216. Error elimination algorithms may discard bit 312 from sifted keys 214 and 216. Alternatively, error elimination algorithms may discard all bits of the affected row and column from sifted keys 214 and key 216);
wherein the following steps are furthermore implemented by the first device (D_ALICE):
distributing at least certain bits of the bits of the generated sequence into 3 distinct sets of bits: a first set of bits for defining the secret key, a second set of bits equal to 0 and a third set of bits equal to 1 ([0083-0088]] In FIG. 2, encryption key managers 180 and 182 include respective encryption key generators 203 and 205 to generate corresponding initial encryption keys, illustrated here as raw keys 202 and 204. Raw key 202 is generated from transmit event information 124. Raw key 204 is generated from detection event information 126. Raw keys 202 and 204 may include bit values, polarization bases, and transmission/detection interval information. Raw key 202 may represent every polarization transmitted during an authentication session. Raw key 204 may represent all detected polarizations. Raw keys 202 and 204 may differ from one another. For example, system 104 may not detect every event transmitted by system 102 due to low transmission intensity, channel loss, detection inefficiencies, and/or coupling inefficiencies. In addition, system 104 optionally inserts fictitious events at random detection intervals to valid detection events 126, such as described further below with reference to FIG. 4. Where system 104 adds fictitious events to detection events 126, the fictitious events may be included in raw key 204 but not raw key 202. Encryption key manager 180 modifies raw key 202 based on detection bases 206. This may include comparison of detection interval information 208 to transmission interval information of raw key 202, and discarding events from raw key 202 for which there are no corresponding detection events in raw key 204. In addition, authentication key managers 140 and 142 modify corresponding authentication keys 144 and 146 based on detection interval information 208. Encryption key managers 180 and 182 include respective sifters 210 and 212 to sift or discard events from raw keys 202 and 204 based on mismatches or non-correlations of transmission and detection bases, also referred as basis-sifting);
each bit of at least the second and third sets being associated, in a memory of the first device, with its index number ([0099] For example, FIG. 3 is a depiction of a 5-by-5 matrix 300 of sifted bits. FIG. 3 further includes a column 302 of corresponding row parity bits and a row 304 of corresponding column parity bits. Where a row parity bit 308 and a column parity bit 310 do not match corresponding row and column parity bits of reference matrix, intersecting bit 312, or the corresponding bit of the reference matrix may be in error);
if step j is implemented, said step j comprises the following steps:
(j0) the parity bits are calculated on the basis of bits of the first set; (j1) in accordance with a predetermined code, coding the value of each calculated parity bit by way of a series of bits b1 b2 . . . bn of length n greater than or equal to 1; (j2) for each bit bi, i=1 to n: if and only if bi=0, selecting one of the bits of the second set and, if and only if bi=1, selecting one of the bits of the third set ([0102] Pseudo-random matrix-based arranging, and parity-based error detection, and error elimination may be performed repeatedly with subsequently smaller sets of remaining sifted bits until no parity errors or mismatches are detected in one or more iterations. A minimum number of error-free iterations may be user-configurable);
(j3) said transmission of information relating to the calculated parity bits comprises transmitting, on the classical channel and for each calculated parity bit, a series ind1 ind2 . . . indn, where indi, i=1 to n, indicates the index number associated with said bit selected in the second or third set in step j2 for the bit bi; if step jj is implemented ([0109] PAs 228 and 230 may be implemented to generate corresponding PA keys 236 and 238 based on parity values computed from corrected encryption keys 224 and 226, or subsets of bits of corrected keys 224 and 226. As an example, where parities of 10 bits of corrected keys 224 and 226 are used to form PA keys 236 and 238, an adversary would need to know all 10 bits in order to know the parity values used to for PA keys 236 and 238);
said step jj comprises the following steps:
jj0/the information received from the second device comprising, for each of said parity bits, a series ind1 ind2 . . . indn, where indi, i=1 to n with n≥1,indicates an index number associated with a bit in the second or third set ([0111] For additional privacy amplification, PAs 228 and 230 may repeat the pseudo-random matrix-arranging of bits of corrected keys 224 and 226 with subsequent values 232 and 234, accumulate parity values over multiple repetitions, and construct corresponding PA keys 236 and 238 based on the accumulated parities);
for each parity bit:
determining the value of the bit bi associated, in the memory of the first device, with the index number indi for i=1 to n, and decoding, in accordance with a determined code, the value of each parity bit on the basis of the series of bits b1 b2 . . . bn determined for said parity bit ([0112] For additional privacy amplification, with each repetition, a column and row of each matrix may be discarded between repetitions until the matrices fall below a threshold size. The threshold size may set based on a known or perceived security risk, and may be user-configurable. [0113] PA keys 236 and 238 may represent final or authenticated encryption keys 184 and 186, convergence of which may inherently or implicitly authenticate systems 102 and 104 with respect to one another. [0114] In addition to authenticating systems 102 and 104 with respect to one another, authenticated encryption keys 184 and 186, may be used for other purposes, such as encryption/decryption of messages, while authentication keys 144 and 146 (modified and/or unmodified) may remain un-disclosed or secret, and may be re-used in subsequent authentication session);
jj 1/said error detection is an error detection carried out in the first set of bits to define the secret key and is performed on the basis of said values of the parity bits thereby decoded ([0115] Under the BB84 protocol, authenticated encryption keys 184 and 186 may be used to encode and decode a message with a one-time pad technique, such as a Vernam Cipher, where individual bits of authenticated encryption key 184 are used a single time to encode one bit of the message, and individual bits of authenticated encryption key 186 are used a single time to decode one bit of the received message).
Jacobs does not explicitly disclose each bit being associated with an index number dependent on its rank within at least said certain bits. VERSCHOOR, in analogous art however, discloses each bit being associated with an index number dependent on its rank within at least said certain bits ([0085] Alice and Bob compute, a number indicating how many keys were lost, from the indices sent in the first messages and sample d, the number of decoy rounds, from the last bits of the QKD output k.sub.q, as described in detail below. A few of the fresh bits of k.sub.q will possibly be consumed by the decoy round scheduling, depending on how many keys are left: k.sub.q′ denotes the bits that are not used for computing d. In rounds d and d+1 Alice and Bob will send real ITS authentication tags, while for rounds r with 0≤r<d they will send decoy tags. [0092] both Alice and Bob send the indices j.sub.a and j.sub.b to indicate how many keys they were able to replenish already. If it turns out one party replenished more keys than the other, these indices tell them those keys are not shared and they should be overwritten by future replenishments. Although FIG. 7 shows that the indices are sent alongside m.sub.1 and m.sub.2, they could be sent alongside any post-processing message). Therefore, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the invention to modify the claimed limitations of the bits disclosed by Jacobs to include each bit being associated with an index number dependent on its rank within at least said certain bits. This modification would have been obvious because a person having ordinary skill in the art would have been motivated by the desire to provide ways to keep a quantum key distribution or similar key-exchange protocol from being drained of all of its secret authentication keys and to avoid spending information-theoretic authentication keys too early, before the parties know whether the exchange actually produced fresh shared key material. The parties first use computational authentication to confirm the post-processing exchange, and only then use the information-theoretic tags. Alternatively the real information-theoretic authentication message is hidden among decoy authentication messages so an attacker cannot easily target it. The parties also keep their local protocol state synchronized so that aborted or interrupted sessions do not cause the parties to get out of step, where these are suggested by VERSCHOOR ([0016-0019).
As per claim 2: Jacobs in view of VERSCHOOR discloses the method for quantum secret key distribution as claimed in claim 1, wherein: if the value of bi is 0, the transmitted information relating to bi indicates the index number of the selected bit of the second set and, if the value of bi is 1, the transmitted information relating to said bit thus indicates the index number of the selected bit of the third set; said selection being made by a draw (VERSCHOOR [0095] First Alice and Bob determine the number of lost keys, which can be derived from the indices sent in the first two messages. Let N be the size of key stores K.sub.a and K.sub.b when they are full, where N is a sufficiently large public parameter).
As per claim 3: Jacobs in view of VERSCHOOR discloses method for quantum secret key distribution as claimed in claim 1, wherein:
the first device (D_ALICE) comprises at least two distinct coding bases between values of said parameter and the values 0 or 1 of a bit; the first device (D_ALICE) randomly selects, for each bit under consideration in the generated sequence, one base out of the at least two distinct bases to perform said bit coding by way of said value of said light pulse parameter and stores, for each bit of the sequence, an indication of the selected base (Jacobs [0115] Under the BB84 protocol, authenticated encryption keys 184 and 186 may be used to encode and decode a message with a one-time pad technique, such as a Vernam Cipher, where individual bits of authenticated encryption key 184 are used a single time to encode one bit of the message, and individual bits of authenticated encryption key 186 are used a single time to decode one bit of the received message.
after the transmission of a light pulse, the first device (D_ALICE) transmitting, to the second device (D_BOB) and on the classical channel, the indication of the base that the first device (D_ALICE) has selected for each bit of the sequence and receiving, from said second device (D_BOB) and on the classical channel, the indication, for each bit of the sequence, of the base that said second device (D_BOB) has selected to evaluate the value of said bit of the sequence (Jacobs [0116] As an example, at system 102, bits of authenticated encryption key 184 are arranged into bytes as the bits become available. The bytes are applied to an exclusive-OR (XOR) operation, along with bits of the message, to generate an encoded message, which may be transmitted over channel 116. At system 104, the bytes of the encrypted message are received and applied to an identical XOR operation, along with bytes of authenticated encryption key 186, to decode the bytes. The encoding and decoding may be repeated until the entire message has been transferred).
comparing, for each bit of the sequence, the stored and received base indications and identifying the bits of the sequence for which the base selected by the first device and the second device are identical; the first, second and third sets of bits consist of bits thereby identified (Jacobs [0089] Sifter 210 compares detection bases 206 to transmission bases of raw key 202 to identify mismatches. Sifter 210 discards uncorrelated transmission events from raw key 202 to provide a sifted key 214. Sifter 210 also discloses a keep/discard indication 150 over channel 116 for each detection basis 206. Sifter 212 discards uncorrelated detection events from raw key 204 based on keep/discard indications 150 to provide a sifted key 216).
As per claim 4: Claim 4 is directed to a computer program intended to be stored in the memory of a first device and furthermore comprising a microcomputer, said computer program comprising instructions that, when they are executed on the microcomputer, orchestrate the steps of a method as claimed in claim 1, and therefore claim 4 is rejected with the same rationale given above to reject corresponding limitations of claim 1.
As per claim 5: Claim 5 is directed to a telecommunications device (D_ALICE) designed to be connected to another telecommunications device (D_BOB) via a first and a second telecommunications link, claim 5 having substantially similar corresponding limitations of method claim 1 and therefore claim 5 is rejected with the same rationale given above to reject claim 1.
As per claims 6-10: Claims 6-10 are directed to a telecommunications device (D_ALICE) designed to be connected to another telecommunications device (D_BOB) via a first and a second telecommunications link, where claims 6-10 are from telecommunications device (D_BOB) aspect having substantially similar features of claims 1-5 the telecommunications device (D_ALICE), and therefore claims 6-10 are rejected with the same rationale given above to reject claims 1-5 respectively.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Djordjevic US 20220014362 A1 describes a secure key-sharing system that combines quantum key distribution with post-quantum cryptography. Two parties, Alice and Bob, first create a raw secret key using a quantum channel. They then compare and “sift” the raw key to keep only matching portions. Instead of sending ordinary error-correction parity bits in the clear over a public channel, the system encrypts those parity bits using a PQC method. Bob sends the encrypted syndrome to Alice, and Alice decrypts it and uses LDPC decoding to correct errors in her key. Djordjevic says this reduces how much information could leak during reconciliation. It also says the approach can improve secret-key rate and transmission distance compared with conventional QKD.
AHN et al. US 20230299950 A1 describes a way for two quantum-cryptography devices to estimate how many bit errors occurred in shared key material before using that key to decrypt data. In a quantum key distribution (QKD) system, the devices first exchange quantum signals to create sifted key bits, then use a public channel to exchange parity information. Instead of revealing actual key bits, AHN compares two-dimensional parity information so the devices can estimate the quantum bit error rate (QBER) with less key leakage. The method also chooses a group size for parity checking that is large enough to reduce leaked information but still small enough to keep the estimate accurate. AHN says a one-dimensional parity method can miss even numbers of errors in a group, so the two-dimensional version helps detect more error patterns. The method may update the group size based on a previous QBER estimate. The application also places the QBER-estimation process in a broader device workflow that includes random access, RRC connection setup, data reception, and decryption. The goal is to continue using the key if QBER is acceptable, or discard it if the error level suggests possible eavesdropping.
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TECHANE GERGISO whose telephone number is (571)272-3784. The examiner can normally be reached 9:30am to 6:30pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, LINGLAN EDWARDS can be reached at (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/TECHANE GERGISO/ Primary Examiner, Art Unit 2408