Detailed Action
This is a Non-final Office action in response to communications received on 4/21/2025. Claims 1-10 and claims 15-24 were amended via preliminary amendment. Claims 11-14 and 25-28 were canceled via preliminary amendment. Claims 1-10 and 15-24 are pending and are examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Drawings
The drawings, filed 4/21/2025, are acknowledged.
Preliminary Amendments
The preliminary amendments, filed 4/21/2025, are acknowledged.
Provisional Priority
The provisional priority date of 10/21/2022 is acknowledged.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3, 6-10, 15 and 17, 20-24 are rejected under 35 U.S.C. 103 as being unpatentable over Stark (US 20210194667 A1), in view of Ma (US 20160119136 A1), further in view of Deas (US 20110285420 A1).
Regarding claim 1, Stark teaches the limitations of claim 1 substantially as follows:
A method performed by a processing unit for generating side- channel countermeasures to protect sensitive information, the method comprising: (Stark; Abstract: Methods, systems, and apparatuses for defending against cryptographic attacks using clock period randomization)
supplying a first randomized clock signal to the first circuit; (Stark; [0058]: utilize a randomized, pseudorandomized, or variable clock period to protect the device against cryptographic attacks)
Stark does not teach the limitations of claim 1 as follows:
configuring a first circuit with a first secret;
configuring a countermeasure circuit with a countermeasure secret,
supplying a second randomized clock signal to the countermeasure circuit;
processing an input at the first circuit based on the first randomized clock signal and the first secret to generate a first output and a first side-channel leakage; and
processing the input at the countermeasure circuit based on the second randomized clock signal and the countermeasure secret to generate a countermeasure output and a countermeasure side-channel leakage, wherein the countermeasure side-channel leakage at least partially obscures the first side-channel leakage.
However, in the same field of endeavor, Ma discloses the limitations of claim 1 as follows:
configuring a first circuit with a first secret; (Ma; [0007]: a cryptographic device that protects a secret key of the cryptographic device when processing a message. According to an embodiment of the present invention, the cryptographic device includes: a secret key protection circuit (i.e., first circuit), configured to generate an indecipherable signal according to the message and the secret key by a hash calculation circuit (i.e., first secret))
configuring a countermeasure circuit with a countermeasure secret, (Ma; [0031]: the secret key protection circuit 110 of the present invention may further include a dummy circuit 600. The dummy circuit 600 generates an energy distribution different from that of the shift register processing circuit 300. For example, the dummy circuit 600 generates an opposite energy distribution to that of the shift register processing circuit 300, so as to compensate the energy consumption of the shift register processing circuit 300. As such, it is made even more impracticable for unauthorized interceptors to analyze and obtain a correct value of the secret key through the revealed energy information (i.e., countermeasure secret))
processing the input at the countermeasure circuit based on the second randomized clock signal and the countermeasure secret to generate a countermeasure output and a countermeasure side-channel leakage, wherein the countermeasure side-channel leakage at least partially obscures the first side-channel leakage. (Ma; [0031]: the secret key protection circuit 110 of the present invention may further include a dummy circuit 600. The dummy circuit 600 generates an energy distribution different from that of the shift register processing circuit 300. For example, the dummy circuit 600 generates an opposite energy distribution to that of the shift register processing circuit 300, so as to compensate the energy consumption of the shift register processing circuit 300. As such, it is made even more impracticable for unauthorized interceptors to analyze and obtain a correct value of the secret key through the revealed energy information (i.e., obscures the first side-channel leakage))
Ma is combinable with Stark because all are from the same field of endeavor of protection against cryptographic attacks. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the system of Stark to incorporate generation of signals based on a secret key as in Ma in order to provide information security by protecting information via a secret key.
Stark and Ma do not teach the limitations of claim 1 as follows:
supplying a second randomized clock signal to the countermeasure circuit;
processing an input at the first circuit based on the first randomized clock signal and the first secret to generate a first output and a first side-channel leakage; and
However, in the same field of endeavor, Deas discloses the limitations of claim 1 as follows:
supplying a second randomized clock signal to the countermeasure circuit; (Deas; [0032]: The randomisation of the output clock edges improves the resistance of the logic system to attack methods such as power supply current monitoring, electromagnetic field monitoring or very near field monitoring, as a means to gain an insight to the operation or contents of the system (i.e., second randomized clock signal))
processing an input at the first circuit based on the first randomized clock signal and the first secret to generate a first output and a first side-channel leakage; and (Deas; [0005]: Techniques known as simple power analysis, differential power analysis and higher order differential power analysis have been used to reveal the private encryption key (i.e., side channel leakage))
Deas is combinable with Stark and Ma because all are from the same field of endeavor of protection against cryptographic attacks. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the system of Stark and Ma to incorporate randomization of output clock edges as in Deas in order to in order to improve the resistance of the logic system to attack methods such as current supply monitoring.
Regarding claim 15, Stark teaches the limitations of claim 15 substantially as follows:
A processing unit, comprising: processing circuitry configured to generate side-channel countermeasures to protect sensitive information, wherein the processing circuitry is configured to: (Stark; Abstract: Methods, systems, and apparatuses for defending against cryptographic attacks using clock period randomization)
supply a first randomized clock signal to the first circuit; (Stark; [0058]: utilize a randomized, pseudorandomized, or variable clock period to protect the device against cryptographic attacks)
Stark does not teach the limitations of claim 15 as follows:
configure a first circuit with a first secret; configure a countermeasure circuit with a countermeasure secret;
supply a second randomized clock signal to the countermeasure circuit;
process an input at the first circuit based on the first randomized clock signal and the first secret to generate a first output and a first side-channel leakage; and
process the input at the countermeasure circuit based on the second randomized clock signal and the countermeasure secret to generate a countermeasure output and a countermeasure side-channel leakage, wherein the countermeasure side-channel leakage at least partially obscures the first side-channel leakage.
However, in the same field of endeavor, Ma discloses the limitations of claim 15 as follows:
configure a first circuit with a first secret; (Ma; [0007]: a cryptographic device that protects a secret key of the cryptographic device when processing a message. According to an embodiment of the present invention, the cryptographic device includes: a secret key protection circuit (i.e., first circuit), configured to generate an indecipherable signal according to the message and the secret key by a hash calculation circuit (i.e., first secret))
configure a countermeasure circuit with a countermeasure secret; (Ma; [0031]: the secret key protection circuit 110 of the present invention may further include a dummy circuit 600. The dummy circuit 600 generates an energy distribution different from that of the shift register processing circuit 300. For example, the dummy circuit 600 generates an opposite energy distribution to that of the shift register processing circuit 300, so as to compensate the energy consumption of the shift register processing circuit 300. As such, it is made even more impracticable for unauthorized interceptors to analyze and obtain a correct value of the secret key through the revealed energy information (i.e., countermeasure secret))
process the input at the countermeasure circuit based on the second randomized clock signal and the countermeasure secret to generate a countermeasure output and a countermeasure side-channel leakage, wherein the countermeasure side-channel leakage at least partially obscures the first side-channel leakage. (Ma; [0031]: the secret key protection circuit 110 of the present invention may further include a dummy circuit 600. The dummy circuit 600 generates an energy distribution different from that of the shift register processing circuit 300. For example, the dummy circuit 600 generates an opposite energy distribution to that of the shift register processing circuit 300, so as to compensate the energy consumption of the shift register processing circuit 300. As such, it is made even more impracticable for unauthorized interceptors to analyze and obtain a correct value of the secret key through the revealed energy information (i.e., obscures the first side-channel leakage))
Ma is combinable with Stark because all are from the same field of endeavor of protection against cryptographic attacks. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the system of Stark to incorporate generation of signals based on a secret key as in Ma in order to provide information security by protecting information via a secret key.
Stark and Ma do not teach the limitations of claim 15 as follows:
supply a second randomized clock signal to the countermeasure circuit;
process an input at the first circuit based on the first randomized clock signal and the first secret to generate a first output and a first side-channel leakage; and
However, in the same field of endeavor, Deas discloses the limitations of claim 15 as follows:
supply a second randomized clock signal to the countermeasure circuit; (Deas; [0032]: The randomisation of the output clock edges improves the resistance of the logic system to attack methods such as power supply current monitoring, electromagnetic field monitoring or very near field monitoring, as a means to gain an insight to the operation or contents of the system (i.e., second randomized clock signal))
process an input at the first circuit based on the first randomized clock signal and the first secret to generate a first output and a first side-channel leakage; and (Deas; [0005]: Techniques known as simple power analysis, differential power analysis and higher order differential power analysis have been used to reveal the private encryption key (i.e., side channel leakage))
Deas is combinable with Stark and Ma because all are from the same field of endeavor of protection against cryptographic attacks. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the system of Stark and Ma to incorporate randomization of output clock edges as in Deas in order to in order to improve the resistance of the logic system to attack methods such as current supply monitoring.
Regarding claims 3 and 17, Stark, Ma and Deas teach the limitations of claims 1 and 15.
Stark, Ma and Deas teach the limitations of claims 3 and 17 as follows:
wherein the first circuit and the countermeasure circuit are different circuits and generate respective side-channel leakage profiles that are similar within a predefined threshold. (Ma; [0031]: the secret key protection circuit 110 of the present invention may further include a dummy circuit 600. The dummy circuit 600 generates an energy distribution different from that of the shift register processing circuit 300. For example, the dummy circuit 600 generates an opposite energy distribution to that of the shift register processing circuit 300, so as to compensate the energy consumption of the shift register processing circuit 300. As such, it is made even more impracticable for unauthorized interceptors to analyze and obtain a correct value of the secret key through the revealed energy information (i.e., different circuits))
The same motivation to combine as in claims 1 and 15 are applicable to the instant claims.
Regarding claims 6 and 20, Stark, Ma and Deas teach the limitations of claims 1 and 15.
Stark, Ma and Deas teach the limitations of claims 6 and 20 as follows:
wherein the countermeasure secret is based on an output of a generator component that utilizes the first secret as an input. (Ma; [0031]: the secret key protection circuit 110 of the present invention may further include a dummy circuit 600. The dummy circuit 600 generates an energy distribution different from that of the shift register processing circuit 300. For example, the dummy circuit 600 generates an opposite energy distribution to that of the shift register processing circuit 300, so as to compensate the energy consumption of the shift register processing circuit 300. As such, it is made even more impracticable for unauthorized interceptors to analyze and obtain a correct value of the secret key through the revealed energy information (i.e., based on an output of a generator component that utilizes the first secret as an input))
The same motivation to combine as in claims 1 and 15 are applicable to the instant claims.
Regarding claims 7 and 21, Stark, Ma and Deas teach the limitations of claims 1 and 15.
Stark, Ma and Deas teach the limitations of claims 7 and 21 as follows:
wherein the countermeasure secret is based on an output of a generator component that utilizes the information associated with the first secret as an input. (Ma; [0031]: the secret key protection circuit 110 of the present invention may further include a dummy circuit 600. The dummy circuit 600 generates an energy distribution different from that of the shift register processing circuit 300. For example, the dummy circuit 600 generates an opposite energy distribution to that of the shift register processing circuit 300, so as to compensate the energy consumption of the shift register processing circuit 300. As such, it is made even more impracticable for unauthorized interceptors to analyze and obtain a correct value of the secret key through the revealed energy information (i.e., based on an output of a generator component that utilizes the information associated with the first secret as an input))
The same motivation to combine as in claims 1 and 15 are applicable to the instant claims.
Regarding claims 8 and 22, Stark, Ma and Deas teach the limitations of claims 6 and 20.
Stark, Ma and Deas teach the limitations of claims 8 and 22 as follows:
wherein the generator component is at least one of a pseudo-random number generator, a message authentication code function, or a physical unclonable function, or a hash function. (Stark; [0100]: In an example embodiment, the random number generator 530 is implemented as a true random number generator. In an example embodiment, the m-bit pseudorandom binary sequence generator 515 is implemented as a linear feedback shift register (LFSR))
Regarding claims 9 and 23, Stark, Ma and Deas teach the limitations of claims 1 and 15.
Stark, Ma and Deas teach the limitations of claims 9 and 23 as follows:
wherein the countermeasure secret is based on an input to the processing unit. (Ma; [0036]: an indecipherable signal is generated according to a message and a secret key. This step may be performed by the secret key protection circuit 110 in FIG. 1 or an equivalent circuit)
The same motivation to combine as in claims 1 and 15 are applicable to the instant claims.
Regarding claims 10 and 24, Stark, Ma and Deas teach the limitations of claims 9 and 23.
Stark, Ma and Deas teach the limitations of claims 10 and 24 as follows:
wherein the first secret and the countermeasure secret are configured as a pair. (Ma; [0040]: In step S114, the indecipherable signal is generated according to the at least one hash value or the at least one hash value is utilized as the indecipherable signal)
The same motivation to combine as in claims 1 and 15 are applicable to the instant claims.
Claims 2 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Stark (US 20210194667 A1), in view of Ma (US 20160119136 A1), further in view of Deas (US 20110285420 A1), as applied to independent claims, further in view of Avital (US 20190028263 A1).
Regarding claims 2 and 16, Stark, Ma and Deas teach the limitations of claims 1 and 15.
Stark, Ma and Deas do not teach the limitations of claims 2 and 16 as follows:
wherein the first circuit and the countermeasure circuit are identical circuits.
However, in the same field of endeavor, Avital discloses the limitations of claims 2 and 16 as follows:
wherein the first circuit and the countermeasure circuit are identical circuits. (Avital; [0117]: The RMT.sup.2L concept is implemented using RMT.sup.2L units which have two modes of operation: static and dynamic (i.e., identical circuits))
Avital is combinable with Stark, Ma and Deas because all are from the same field of endeavor of protection against cryptographic attacks. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified system of Stark, Ma and Deas to incorporate using identical units to modally perform functions of the system as in Avital in order to reduce the need for unique components.
Allowable Subject Matter
Claims 4-5 and 18-19 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
The following is a statement of reasons for the indication of allowable subject matter:
As to claims 4 and 18, it contains allowable subject matter when the claim is taken as a whole. See the italicized text indicating aspects that in combination with the remainder of the claim differentiate it from prior art.
wherein the first circuit is a first machine learning model and wherein the first secret is a function of an architecture of the first machine learning model and parameters of the first machine learning model.
Furthermore, claims 5 and 19 contain allowable subject matter based on the virtue of dependency from claims 4 and 18.
Prior Art Considered But Not Relied Upon
Teper (US 10019571 B2) which teaches a logic circuit and delay circuitry for data security, and more specifically, to protection from side-channel attacks.
Venkataramani (US 20170154181 A1) which teaches a system which detects a covert timing channel on a combinational structure or a memory structure.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BLAKE ISAAC NARRAMORE whose telephone number is (303)297-4357. The examiner can normally be reached on Monday - Friday 0700-1700 MT.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Taghi T Arani can be reached on (571) 272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BLAKE I NARRAMORE/Primary Examiner, Art Unit 2438