DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Drawings
The drawings submitted on June 16, 2025 are acceptable.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on June 24, 2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Amendment
The amendment filed on April 9, 2026 has been entered. Applicant has amended claims 1, 5 and 20. Claims 1-20 are now pending, have been examined and currently stand rejected.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention recites and is directed to a judicial exception to patentability (i.e., an abstract idea) and does not provide an integration of the recited abstract idea into a practical application nor include an inventive concept that is “significantly more” than the recited abstract idea to which the claim is directed. MPEP §2106.
In determining subject matter eligibility in an Alice rejection under 35 U.S.C. §101, it is first determined as Step 1 whether the claims are directed to one of the four statutory categories of an invention (i.e., a process, a machine, a manufacture, or a composition of matter). MPEP §2106.03.
Here, the claims are directed to the statutory category of a process (Claims 1-19) and a system (claim 20). Therefore, we proceed to Step 2A, Prong 1. MPEP §2106.
Under a Step 2A, Prong 1 analysis, it must be determined whether the claims recite an abstract idea that falls within one or more enumerated categories of patent ineligible subject matter that amounts to a judicial exception to patentability. MPEP §2106.04. Independent Claim 5 is selected as being representative of the independent claims in the instant application. Claim 5 recites:
A computer-implemented method comprising:
receiving a first blinded data element, the first blinded data element based on a data element associated with a first private key share;
receiving a second blinded data element based on a data element associated with a second private key share, wherein the first private key share and the second private key share are both associated with a distributed key generation (DKG) protocol;
combining the first blinded data element with the second blinded data element to compute a blinded result;
confirming a validity of the blinded result by confirming that the blinded result satisfies a verification condition associated with a public key corresponding to the DKG protocol; and
facilitating a transaction based on the validity of the blinded result.
Here, the claims recite an abstract idea, or combination of abstract ideas of facilitate a transaction based on a validated result of combined data. The claim achieves this by receiving first and second data elements associated with first and second keys, combining first and second data elements to compute a blinded result, confirming the result and facilitating a transaction based on the result. This concept/abstract idea, which is identified in the bolded sections seen above, falls within the Certain Methods of Organizing Human Activity grouping because it describes a commercial or legal interactions (e.g., information processing for financial transactions). Additionally, the blinded data (e.g., encrypted data) falls within a Mathematical Concept (e.g., mathematical formula). Furthermore, the claims recite a Mental Process which can be performed in human mind with pen and paper (e.g., receiving and combining data).
Accordingly, it is determined that the claims recite an abstract idea since they fall within one or more of the three enumerated categories of patent ineligible subject matter. MPEP §2106.04.
Since it is determined that the claim(s) contain a judicial exception, it must then be determined, under Step 2A, Prong 2, whether the judicial exception is integrated into a practical application of the exception. MPEP §2106.04. In order to make this determination, the additional element(s) are analyzed to determine if the claim as a whole integrates the recited judicial exception into a practical application of that exception. Here claim 5 recites the additional elements of public keys and public key shares. Independent claim 1 recites the additional elements of public keys and public key shares. Independent claim 20 recite the additional elements of public keys and public key shares, a system at least one memory and at least one processor. These additional elements are all recited at a high-level of generality such that they amount to no more than mere instructions to apply the exception, or a portion thereof, using a generic computer component. See MPEP 2106.05(f). Additionally, Examiner finds no indication in the Specification, that the operations recited in the independent claims require any specialized computer hardware or other inventive computer components, i.e., a particular machine, invoke any allegedly inventive programming, or that the claimed invention is implemented using other than generic computer components to perform generic computer functions. Furthermore, there is no indication in the claim(s) that the use of public keys and public key shares, a system at least one memory and at least one processor in combination with the abstract idea leads to an improvement of the processor, memory, another technology, or to a technical field. Accordingly, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Looking at the elements as a combination does not add anything more than the elements analyzed individually. Examiner further notes that even though the claims may not preempt all forms of the abstraction, this alone, does not make them any less abstract.
When analyzed under step 2B, the claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a generic computing component (e.g., public keys and public key shares, a system at least one memory and at least one processor) to implement the abstract idea amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept or significantly more than the judicial exception. Considered as an ordered combination, the additional elements recited in the claim(s) add nothing that is not already present when the steps are considered separately.
Therefore, claim 1, 5 and 20 are rejected under 35 U.S.C. §101 and are not patent eligible. Dependent claims 2-4 and 6-19 when analyzed are held to be patent ineligible under 35 U.S.C. §101 because the additional recited limitation(s) fail to establish that the claim(s) is/are not directed to an abstract idea.
Dependent claims 2 and 9 further refine the abstract idea by describing the first blinded data element. These claims fail to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
Dependent claims 3-4, 6, 9-10, 12, 16 and 19 further refine the abstract idea by describing the first and second blinded data element. These claims fail to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
Dependent claim 7 further refine the abstract idea by verify a validity of the first blinded data. This claims fails to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
Dependent claim 8 further refine the abstract idea by sending the blinded result to a device and receiving a confirmation of the validity of the blinded result from the device. This claims fails to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
Dependent claim 11 further refine the abstract idea by sending data to a device and receiving confirmation of the validity from the device. This claims fails to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
Dependent claim 13 further refine the abstract idea by describing an asset transfer. This claims fails to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
Dependent claim 14 further refine the abstract idea by describing a second transaction (e.g., UTXO) of at least one asset relative to a wallet. This claims fails to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea
Dependent claim 15 further refine the abstract idea by describing first and second UTXO. This claims fails to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
Dependent claims 17 and 18 further refine the abstract idea by describing aspects of the UTXO. These claims fail to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
In summary, the dependent claims considered both individually and as an ordered combination do not provide meaningful limitations to transform the abstract idea into a patent eligible application of the abstract idea such that the claims amount to significantly more than the abstract ideas itself. The claims do not recite an improvement to another technology or technical field, an improvement to the functioning of the computer itself, or provide meaningful limitations beyond generally linking an abstract idea to a particular technological environment. Therefore, the dependent claims are also not patent eligible.
Accordingly, it is determined that all claims are directed to non-statutory subject matter under 35 U.S.C. 101 and are ineligible.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 1 and 3 is/are rejected under 35 U.S.C. 103 as being unpatentable by Ma et al. (US 2019/0251554 A1), in view of Kang et al (US 2024/0144254 A1), in view of De Caro et al. (US 2023/0252482 A1).
Regarding claim 1: A computer-implemented method for improved privacy in multi-party computation (MPC) system through blinded computations, the computer-implemented method comprising:
receiving a first blinded data element, the first blinded data element based on a data element associated with a first private key share; (See at least Ma, Fig. 3; [0007-0008]; receiving, from a first account, a digitally signed copy of a commitment value of a first amount of a transaction amount; Generating a commitment value of a transaction amount based on a first random number, and encrypting, based on homomorphic encryption; a public key of the first account corresponding to a private key).
receiving a second blinded data element based on a data element associated with a second private key share; (See at least Ma, Fig. 7; Ma disclose receiving a seconf blinded data element (i.e., second/third random number) a data element associated with a second private key share (i.e., public key of the second account).)
combining the first blinded data element with the second blinded data element to compute a blinded result; (See at least Ma, [0044]; At 320, the blockchain node determines that the first random number, the second random number, and the third random number are the same based on the set of values.)
verifying of the blinded result and (See at least Ma, [0048] At 404, the user node A 402 can add digital signature to the proofs used to validate the transaction, and submit the digitally signed copy to the blockchain network 408.)
authorizing spending of a transaction associated with the public key upon verification of the blinded result without reconstructing a full private key from the private key shares. (See at least Ma, [0007] and updating the balance of the first account and a balance of the second account based on the first amount of the balance transfer if the first amount and the second amount are the same and the first random number and the second random number are the same.)
Ma discloses the blockchain node determines that the first random number, the second random number, and the third random number are the same based on the set of values. Validate a blinded result (e.g., user node A 402 can add digital signature to the proofs used to validate the transaction, and submit the digitally signed copy to the blockchain network). Ma, [0044]; [0048]. However, Ma does not explicitly disclose wherein the first private key share and the second private key share are both associated with a distributed key generation (DKG) protocol. Verifying of the blinded result by confirming that the blinded result satisfies a verification condition associated with a public key corresponding to the DKG protocol and authorizing spending of a transaction associated with the public key upon verification of the blinded result without reconstructing a full private key from the private key shares.
Kang, on the other hand teaches; wherein the first private key share and the second private key share are both associated with a distributed key generation (DKG) protocol. (See at least Kang, [0007]; [0038]; [0042]; the first private key share and the second private key share (i.e., the individual private key pieces) are both associated with a distributed key generation (DKG) protocol (i.e., Multi-party computation (MPC).)
Verifying of the blinded result by confirming that the blinded result satisfies a verification condition associated with a public key corresponding to the DKG protocol (See at least Kang, [0126]; Verifying of the blinded result (i.e., verify the combined signature) by confirming that the blinded result satisfies a verification condition associated with a public key corresponding to the DKG protocol (i.e., verify the combined signature value with the common public key).)
and authorizing spending of a transaction associated with the public key upon verification of the blinded result without reconstructing a full private key from the private key shares. (See at least Kang, [0126]; When the verification of the combined signature value is completed by the second MPC server and the third MPC server, an automatic transfer is made from a parent account of the bank to a bank account of the subscription business).)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Ma and include Kang’s teachings in order to prevent individual distribution keys from being exposed. Kang, [0012].
The combination of Ma and Kang does not explicitly disclose; however De Caro teaches authorizing spending of an unspent transaction output (UTXO). (See at least De Caro, [0126]; In some embodiments, each step corresponds to an unspent transaction output (UTXO) operation. In some embodiments, the committee may not send ( e.g., spend) the tokens to anyone but the parties involved in the operation.)
It would have been obvious to one of ordinary skill in the art at the time of the invention to have the authorizing spending of an unspent transaction output (UTXO) as in the improvement discussed in De Caro in the system executing the method of the above combination. As in De Caro, it is within the capabilities of one of ordinary skill in the art that the transaction corresponds to an unspent transaction output (UTXO).
Regarding claim 3: The combination of Ma, Kang and De Caro disclose the computer-implemented method of claim 1. The combination further disclose:
receiving the second blinded data element, wherein the first blinded data element is a blinded nonce commitment, wherein the second blinded data element is a blinded challenge hash, and wherein the blinded result is a blinded signature. (See at least Ma, Fig 8; [0005]; [0008]; [0027]; [0033]; blockchain node 304 , also referred to as a consensus node . A transaction , such as a transfer of value , can be made from the user node A 302 to the user node B . To protect account privacy , the user node A 302 can generate a commitment of a transaction amount t using a commitment scheme, such as PC, based on a random number r.)
Applicant is reminded that the portion which recites, “wherein the first blinded data element is a blinded nonce commitment, wherein the second blinded data element is a blinded challenge hash, and wherein the blinded result is a blinded signature” is non-functional descriptive material as it only describes, at least in part, the first and second blinded elements. For example, this description of the blinded data elements do not affect the positively recited steps of claim 1.
Claim(s) 2 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ma, Kang and De Caro as applied to claims 1, and further in view of Jin (CN110533417A).
Regarding claim 2: The combination of Ma, Kang and De Caro disclose the computer-implemented method of claim 1. The combination further disclose wherein the first blinded data element is associated with a key (See at least Ma, Abs.; [0007]; [0033] the first amount of the balance transfer and the first random number encrypted using a public key of the first account).
The combination does not explicitly disclose; however Jin teaches:
wherein the second blinded data element is a key tweak, wherein the key tweak is one of a Bitcoin Improvement Proposal 32 (BIP32) tweak or a Taproot tweak. (See at least Jin, p. 2 lines 29-30; p.4 lines 3-10; The machine identification code is combined with the root private key of the issuing server, and the parent private key and parent public key are generated according to the BIP32 recommendation method.)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the above combination and include Jin’s teachings in order to provide deterministic and hierarchical key derivation form the blinded elements, thereby improving cryptographic key management.
Applicant is reminded that the portion which recites, “wherein the first blinded data element is associated with a key, wherein the second blinded data element is a key tweak, wherein the key tweak is one of a Bitcoin Improvement Proposal 32 (BIP32) tweak or a Taproot tweak” is non-functional descriptive material as it only describes, at least in part, the first and second blinded elements. For example, the blinded data elements being a key tweak does not affect the positively recited steps of claim 1.
Claim(s) 4 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ma, Kang and De Caro as applied to claim 1, and further in view of Maxwell (US 2016/0358165 A1).
Regarding claim 4: The combination of Ma, Kang and De Caro disclose the computer-implemented method of claim 1. The combination further disclose wherein the first blinded data element is a first commitment associated with a first transaction, wherein the second blinded data element is a second commitment associated with a second transaction and wherein the blinded result is associated with a total amount of assets without a vault status in a wallet. (See at least Ma, Fig. 1; [0006]; More particularly , implementations of the present disclosure are directed to validating transactions between blockchain users based on commitment schemes, and homomorphic encryption without revealing transaction amount , account balances , or random numbers.)
Ma, does not explicitly disclose, however Maxwell teaches the first blinded data element is a first commitment associated with a first unspent transaction output (UTXO), wherein the second blinded data element is a second commitment associated with a second unspent transaction output (UTXO). (See at least Maxwell, [0004]; A processor may add a blinding amount to an input value being transacted to create an encrypted input value. An output value corresponding to the input value may be generated and encrypted to create an encrypted output value. The encrypted output value may include a corresponding blinding amount such that the input value blinding amount and the generated output value blinding amount cancel each other out when added together.)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Ma and include Maxwell’s teachings in order to provide validation of UTXO transactions while maintaining privacy of transaction amounts.
Claim(s) 5-8, 10-11 and 19-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ma et al. (US 2019/0251554 A1), in view of Kang et al (US 2024/0144254 A1).
Regarding claim 5: Ma disclose: A computer-implemented method comprising:
receiving a first blinded data element, the first blinded data element based on a data element associated with a first private key share; (See at least Ma, Fig. 3; [0007-0008]; receiving, from a first account, a digitally signed copy of a commitment value of a first amount of a transaction amount; Generating a commitment value of a transaction amount based on a first random number, and encrypting, based on homomorphic encryption; a public key of the first account corresponding to a private key).
receiving a second blinded data element based on a data element associated with a second private key share; (See at least Ma, Fig. 7; Ma disclose receiving a seconf blinded data element (i.e., second/third random number) a data element associated with a second private key share (i.e., public key of the second account).)
combining the first blinded data element with the second blinded data element to compute a blinded result; (See at least Ma, [0044]; At 320, the blockchain node determines that the first random number, the second random number, and the third random number are the same based on the set of values.)
confirming a validity of the blinded result and (See at least Ma, [0048] At 404, the user node A 402 can add digital signature to the proofs used to validate the transaction, and submit the digitally signed copy to the blockchain network 408.)
facilitating a transaction based on the validity of the blinded result. (See at least Ma, [0007] and updating the balance of the first account and a balance of the second account based on the first amount of the balance transfer if the first amount and the second amount are the same and the first random number and the second random number are the same.)
Ma discloses the blockchain node determines that the first random number, the second random number, and the third random number are the same based on the set of values. Validate a blinded result (e.g., user node A 402 can add digital signature to the proofs used to validate the transaction, and submit the digitally signed copy to the blockchain network). Ma, [0044]; [0048]. However, Ma does not explicitly disclose wherein the first private key share and the second private key share are both associated with a distributed key generation (DKG) protocol. Verifying of the blinded result by confirming that the blinded result satisfies a verification condition associated with a public key corresponding to the DKG protocol.
Kang, on the other hand teaches; wherein the first private key share and the second private key share are both associated with a distributed key generation (DKG) protocol. (See at least Kang, [0007]; [0038]; [0042]; the first private key share and the second private key share (i.e., the individual private key pieces) are both associated with a distributed key generation (DKG) protocol (i.e., Multi-party computation (MPC).)
Verifying of the blinded result by confirming that the blinded result satisfies a verification condition associated with a public key corresponding to the DKG protocol (See at least Kang, [0126]; Verifying of the blinded result (i.e., verify the combined signature) by confirming that the blinded result satisfies a verification condition associated with a public key corresponding to the DKG protocol (i.e., verify the combined signature value with the common public key).)
facilitating a transaction based on the validity of the blinded result. (See at least Kang, [0126]; When the verification of the combined signature value is completed by the second MPC server and the third MPC server, an automatic transfer is made from a parent account of the bank to a bank account of the subscription business).)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Ma and include Kang’s teachings in order to prevent individual distribution keys from being exposed. Kang, [0012].
Regarding claim 6: The combination of Ma and Kang disclose the computer-implemented method of claim 5. The combination further disclose wherein the first blinded data element is a variant of a data element that is encrypted using homomorphic encryption, wherein the second blinded data element is a variant of a second data element that is encrypted using homomorphic encryption. (See at least Ma, [0008]; [0061] If true, it can be indicated that the random number and the transaction amount in the commitment are, respectively , the same as the random numbers and the transaction amounts homomorphically encrypted using the public key of the user node A 502 and user node B , and the transaction is valid.
Regarding claim 7: The combination of Ma and Kang disclose the computer-implemented method of claim 5. The combination further disclose wherein verifying the validity of the blinded result is configured to verify a validity of the first blinded data element and the second blinded data element. (See at least Ma, [0048] At 404, the user node A 402 can add digital signature to the proofs used to validate the transaction, and submit the digitally signed copy to the blockchain network 408.)
Regarding claim 8: The combination of Ma and Kang disclose the computer-implemented method of claim 5. The combination further disclose:
sending the blinded result to a device; and (See at least Ma, [0058]; [0068] At 702 , a consensus node receives , from a first account , a digitally signed copy of a commitment value of a transaction amount to be transferred from the first account to a second account generated based on a first random number .At 516 , the blockchain node 504 verifies the digital signature using a public key of the user node A 502)
receiving a confirmation of the validity of the blinded result from the device based on the device unblinding the blinded result, wherein verifying the validity of the blinded result is based on the confirmation received from the device. (See at least Ma, [0058]; [0068] At 702 , a consensus node receives , from a first account , a digitally signed copy of a commitment value of a transaction amount to be transferred from the first account to a second account generated based on a first random number .At 516 , the blockchain node 504 verifies the digital signature using a public key of the user node A 502 . The blockchain node 504 can be a consensus node that can prove the validity of transactions on the blockchain network).
Regarding claim 10: The combination of Ma and Kang disclose the computer-implemented method of claim 5. The combination further disclose:
receiving the second blinded data element, wherein the first blinded data element is a blinded nonce commitment, wherein the second blinded data element is a blinded challenge hash, and wherein the blinded result is a blinded signature. (See at least Ma, Fig 8; [0005]; [0008]; [0027]; [0033]; blockchain node 304 , also referred to as a consensus node . A transaction , such as a transfer of value , can be made from the user node A 302 to the user node B . To protect account privacy , the user node A 302 can generate a commitment of a transaction amount t using a commitment scheme, such as PC, based on a random number r.)
Applicant is reminded that the portion which recites, “wherein the first blinded data element is a blinded nonce commitment, wherein the second blinded data element is a blinded challenge hash, and wherein the blinded result is a blinded signature” is non-functional descriptive material as it only describes, at least in part, the first and second blinded elements. For example, this description of the blinded data elements do not affect the positively recited steps of claim 5.
Regarding claim 11: The combination of Ma and Kang disclose the computer-implemented method of claim 10. The combination further disclose:
sending a nonce commitment to a device, wherein the blinded nonce commitment is received from the device and is a blinded variant of the nonce commitment; (See at least Ma, [0058]; [0068] At 702 , a consensus node receives, from a first account, a digitally signed copy of a commitment value of a transaction amount to be transferred from the first account to a second account generated based on a first random number .At 516 , the blockchain node 504 verifies the digital signature using a public key of the user node A 502).
sending the blinded signature to the device; and (See at least Ma, [0058]; [0068] At 702, a consensus node receives, from a first account, a digitally signed copy of a commitment value of a transaction amount to be transferred from the first account to a second account generated based on a first random number .At 516 , the blockchain node 504 verifies the digital signature using a public key of the user node A 502)
receiving a confirmation of the validity of the blinded signature from the device based on the device unblinding the blinded signature, wherein verifying the validity of the blinded result is based on the confirmation. (See at least Ma, [0058]; [0068] At 702. The blockchain node 504 can be a consensus node that can prove the validity of transactions on the blockchain network).
Regarding claim 19: The combination of Ma and Kang disclose the computer-implemented method of claim 5. The combination further disclose further disclose wherein the first blinded data element is a first commitment associated with a first total amount of assets in a wallet before the transaction, wherein the second blinded data element is a second commitment associated with an amount of assets to be withdrawn from the wallet to conduct the transaction, and wherein the blinded result is associated with a second total amount of assets in the wallet after the transaction. (See at least Ma, Abs.; [0073]; [0080]; )) a first amount of a transaction amount generated based on a first random number , the first amount of the balance transfer and the first random number encrypted using a public key of the first account; At 810 , the consensus node updates a balance of the first account and a balance of the second account based on the first amount of the balance transfer , if the first amount and the second amount are the same , and the first random number and the second random number are the same . In some implementations, updating the balance of the first account and a balance of the second account is performed based on HE. At 710 , the consensus node updates the balance of the first account and a balance of the second account based on the transaction amount , if the first random number, the second random number , and the third random number are the same . In some implementations , updating the balance of the first account and the balance of the second account is performed based on HE.)
Regarding claim 20: Ma disclose; A system comprising:
at least one memory storing instructions; and at least one processor, wherein execution of the instructions by the at least one processor causes the at least one processor to:
receiving a first blinded data element, the first blinded data element based on a data element associated with a first private key share; (See at least Ma, Fig. 3; [0007-0008]; receiving, from a first account, a digitally signed copy of a commitment value of a first amount of a transaction amount; Generating a commitment value of a transaction amount based on a first random number, and encrypting, based on homomorphic encryption; a public key of the first account corresponding to a private key).
receiving a second blinded data element based on a data element associated with a second private key share; (See at least Ma, Fig. 7; Ma disclose receiving a second blinded data element (i.e., second/third random number) a data element associated with a second private key share (i.e., public key of the second account).)
combine the first blinded data element with second blinded data element to compute a blinded result; (See at least Ma, [0044]; At 320, the blockchain node determines that the first random number, the second random number, and the third random number are the same based on the set of values.)
confirm a validity of the blinded result (See at least Ma, [0048] At 404, the user node A 402 can add digital signature to the proofs used to validate the transaction, and submit the digitally signed copy to the blockchain network 408.)
facilitate a transaction based on the validity of the blinded result. (See at least Ma, [0007] and updating the balance of the first account and a balance of the second account based on the first amount of the balance transfer if the first amount and the second amount are the same and the first random number and the second random number are the same.)
Ma discloses the blockchain node determines that the first random number, the second random number, and the third random number are the same based on the set of values. Validate a blinded result (e.g., user node A 402 can add digital signature to the proofs used to validate the transaction, and submit the digitally signed copy to the blockchain network). Ma, [0044]; [0048]. However, Ma does not explicitly disclose wherein the first private key share and the second private key share are both associated with a distributed key generation (DKG) protocol. Verifying of the blinded result by confirming that the blinded result satisfies a verification condition associated with a public key corresponding to the DKG protocol.
Kang, on the other hand teaches; wherein the first private key share and the second private key share are both associated with a distributed key generation (DKG) protocol. (See at least Kang, [0007]; [0038]; [0042]; the first private key share and the second private key share (i.e., the individual private key pieces) are both associated with a distributed key generation (DKG) protocol (i.e., Multi-party computation (MPC).)
Verifying of the blinded result by confirming that the blinded result satisfies a verification condition associated with a public key corresponding to the DKG protocol (See at least Kang, [0126]; Verifying of the blinded result (i.e., verify the combined signature) by confirming that the blinded result satisfies a verification condition associated with a public key corresponding to the DKG protocol (i.e., verify the combined signature value with the common public key).)
facilitating a transaction based on the validity of the blinded result. (See at least Kang, [0126]; When the verification of the combined signature value is completed by the second MPC server and the third MPC server, an automatic transfer is made from a parent account of the bank to a bank account of the subscription business).)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Ma and include Kang’s teachings in order to prevent individual distribution keys from being exposed. Kang, [0012].
Claim(s) 9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ma and Kang as applied to claims 5 above, and further in view of Jin (CN110533417A).
Regarding claim 9: The combination of Ma and Kang disclose the computer-implemented method of claim 5. The combination further disclose wherein the first blinded data element is associated with a key (See at least Ma, Abs.; [0007]; [0033] the first amount of the balance transfer and the first random number encrypted using a public key of the first account).
The combination does not explicitly disclose; however Jin teaches:
wherein the second blinded data element is a key tweak, wherein the key tweak is one of a Bitcoin Improvement Proposal 32 (BIP32) tweak or a Taproot tweak. (See at least Jin, p. 2 lines 29-30; p.4 lines 3-10; The machine identification code is combined with the root private key of the issuing server, and the parent private key and parent public key are generated according to the BIP32 recommendation method.)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the above combination and include Jin’s teachings in order to provide deterministic and hierarchical key derivation form the blinded elements, thereby improving cryptographic key management.
Applicant is reminded that the portion which recites, “wherein the first blinded data element is associated with a key, wherein the second blinded data element is a key tweak, wherein the key tweak is one of a Bitcoin Improvement Proposal 32 (BIP32) tweak or a Taproot tweak” is non-functional descriptive material as it only describes, at least in part, the first and second blinded elements. For example, the blinded data elements being a key tweak does not affect the positively recited steps of claim 1.
Claim(s) 12-14 and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ma and Kang as applied to claim 5, and further in view of Maxwell (US 2016/0358165 A1).
Regarding claims 12 and 16: The combination of Ma and Kang disclose the computer-implemented method of claim 5. The combination further disclose wherein the first blinded data element is a first commitment associated with a first transaction, wherein the second blinded data element is a second commitment associated with a second transaction and wherein the blinded result is associated with a total amount of assets without a vault status in a wallet. (See at least Ma, Fig. 1; [0006]; More particularly , implementations of the present disclosure are directed to validating transactions between blockchain users based on commitment schemes, and homomorphic encryption without revealing transaction amount , account balances , or random numbers.)
Ma, does not explicitly disclose, however Maxwell teaches the first blinded data element is a first commitment associated with a first unspent transaction output (UTXO), wherein the second blinded data element is a second commitment associated with a second unspent transaction output (UTXO). (See at least Maxwell, [0004]; A processor may add a blinding amount to an input value being transacted to create an encrypted input value. An output value corresponding to the input value may be generated and encrypted to create an encrypted output value. The encrypted output value may include a corresponding blinding amount such that the input value blinding amount and the generated output value blinding amount cancel each other out when added together.)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Ma and include Maxwell’s teachings in order to provide validation of UTXO transactions while maintaining privacy of transaction amounts.
Regarding claim 13: The combination of Ma, Kang and Maxwell disclose the computer-implemented method of claim 12. The combination further disclose wherein the transfer is at least one of a deposit of the at least one asset into the wallet or a withdrawal of at least one asset from the wallet. (See at least Ma, Fig. 8; [0027]; Receiving, from a first account, a digitally signed copy of a commitment value of a first amount of a transaction amount to be transferred from a first account to a second account)
Maxwell further disclose wherein a transfer of at least one asset relative to the wallet corresponds to at least one of the first UTXO or the second UTXO (See at least Maxwell, [0004]; [0007]; [0019]; [0021] the transacted amount value; output value.)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Ma and include Maxwell’s teachings in order to provide validation of UTXO transactions while maintaining privacy of transaction amounts.
Regarding claim 14: The combination of Ma, Kang and Maxwell disclose the computer-implemented method of claim 12. The combination further disclose wherein a second transaction corresponds to at least one of the first UTXO or the second UTXO, wherein the transaction involves the wallet and at least one asset. (See at least Ma, Fig. 7-8; [0007]; [0027]; first and second accounts and amount values.)
Claim(s) 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ma, Kang and Maxwell as applied to claim 12 above, and further in view of Trock (WO 2024116092 A1).
Regarding claim 15: The combination of Ma, Kang and Maxwell disclose the computer-implemented method of claim 12, The combination does not explicitly disclose wherein the first UTXO and the second UTXO are associated with a Pay-to-Taproot (P2TR) UTXO set. However, this limitation is found as non-functional descriptive material language that does not affect the steps of claim 5.
For the purposes of compact prosecution, Trock teaches wherein the first UTXO and the second UTXO are associated with a Pay-to-Taproot (P2TR) UTXO set. (See at least Trock, p. 71 line 26).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Ma and include Trock’s teachings in order to provide alternative UTXO addressing format without altering the underlying transaction processing steps.
Claim(s) 17-18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ma, Kang and Maxwell as applied to claims 16 above, and further in view of Langschaedel (US 10,755,241 B2).
Regarding claim 17: The combination of Ma, Kang and Maxwell disclose the computer-implemented method of claim 16.
The combination does not explicitly disclose, however Langschaedel teaches wherein an assignment of the vault status to at least one asset in the wallet corresponds to at least one of the first UTXO or the second UTXO. (See at least Langschaedel, Col. 18 lines 19-21; The values of the Bitcoin addresses 76 and 78 of the first transfer set are transferred into the first vault 64A, as represented by "Value" in the first vault 64A.)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the above combination and include Langschaedel in order to provide controlled storage of assets within a vault.
Regarding claim 18: The combination of Ma and Maxwell disclose the computer-implemented method of claim 16. The combination does not explicitly disclose, however Langschaedel teaches wherein a removal of the vault status from at least one asset in the wallet corresponds to at least one of the first UTXO or the second UTXO. (See at least Langschaedel, Col. 18 lines 5-7; The local controller 58 restores the respective value of the Bitcoin addresses 76 and 78 in the vault 64 to the Bitcoin addresses 76 and 78 in the wallet 42.)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the above combination and include Langschaedel in order to provide controlled storage of assets within a vault.
Response to Arguments
Claim Rejections - 35 USC § 101
Applicant's arguments regarding the rejections under 35 USC § 101 have been fully considered but they are not persuasive.
Regarding Step 2A, Prong One, Applicant asserts that The present claims do not fall within any of these enumerated sub-groupings (e.g., fundamental economic principles or practices, commercial or legal interactions, and managing personal behavior or relationships between people) (Remarks, p. 9). Examiner respectfully disagrees. The claim recite the abstract idea of facilitate a transaction based on a validated result of combined data. The claim achieves this by receiving first and second data elements associated with first and second keys, combining first and second data elements to compute a blinded result, confirming the result and facilitating a transaction based on the result.
Applicant further asserts that "blinded result" generated by "combining the blinded data element with the second blinded data element" in claim 1 is analogous in certain respect to the "security profile" in Finjan, in that it represents "a new kind of file that enables a computer security system to do things it could not do before," (Remarks, p. 10). Further, Applicant argues like CosmoKey, the currently amended claims "improve upon the prior art by providing a simple method that yields higher security." Id. (Remarks, p. 12). Applicant is reminded that the Office has shifted its approach from the case-comparison approach in determining whether a claim recites an abstract idea and instead uses numerated groupings of abstract ideas. MPEP 2106.04(a). Examiner has used the MPEP to evaluate the instant claims, and has not, and will not, evaluate the claims based on individual case law.
Regarding Step 2A, Prong Two, Applicant asserts that the claims integrate any alleged mathematical operations into a concrete application within a blockchain system-specifically, distributed key custody and blinded-result-based authorization of UTXO spending without full key reconstruction. Examiner respectfully disagrees. These elements merely apply the judicial exception in the blockchain transaction. The claims use these elements to preform mathematical calculations and apply the determination to authorize the transaction.
Applicant further argues that the claims improve blockchain transaction authorization by requiring distributed private key shares and verification of a blinded result tied to a DKG-generated public key, while explicitly preventing reconstruction of a full private key (Remarks, p.11). Examiner respectfully disagrees. These limitations merely define the manner in which the abstract idea is performed and under which conditions a transaction is authorized.
Applicant asserts that the similarities between the Applicant's currently amended claims and those at issue in Finjan also supports "integrat[ion] [ ... ] into a practical application at Step 2A Prong Two" for at least the reasons discussed above with respect toFinjan. MPEP § 2106.04(d)(III). (Remarks, p.12). Examiner respectfully disagrees. The claims in “Finjan” were directed to method that generates a security profile that identifies both hostile and potentially hostile operations, and can protect the user against both previously unknown viruses and "obfuscated code. This enabled the system to operate in an improved manner. In contrast, the current claims does not recite a specific improvement to the operation of a computer, blockchain network or any technical field.
Regarding Step 2B, Applicant argues that that claim 1 contains elements that, when considered in combination, amount to "significantly more." (Remarks, pp. 12-13). Examiner respectfully disagrees. The use of distributed key generation (DKG), generating and maintaining distributed private key shares, computing and verifying a blinded result based on those shares, and authorizing spending of a UTXO based on that verification without reconstructing a full private key from the private key shares, are combines to performed mathematical computations, verify results and authorize transaction. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Claim Rejections - 35 USC§ 102
Applicant asserts that Ma fails to describe generation of multiple private key shares corresponding to a single public key via a DKG protocol. (Remarks, p. 14) Examiner agrees. However, upon further consideration of the newly introduced language, a new ground(s) of rejection is made in view of Ma, Kang and De Caro (claim 1) and Ma and Kang (claims 5 and 20).
Applicant asserts that Jin, Maxwell, Trock and Langschaedel do not remedy the above-described deficiencies of Ma, including the failure to disclose or suggest (i) use of private key shares generated via a distributed key generation (DKG) protocol and (ii) authorizing spending of a UTXO based on a blinded result without reconstructing a full private key from the private key shares. (Remarks, pp. 15-17). Examiner agrees. However, upon further consideration of the newly introduced language, a new ground(s) of rejection is made in view of Ma, Kang and De Caro (claim 1) and Ma and Kang (claims 5 and 20).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KARLYANNIE M GARCIA whose telephone number is (571)272-6950. The examiner can normally be reached Monday - Friday 7:30am - 4:30-pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Patrick McAtee can be reached at (571) 272-7575. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/K.G.M/Examiner, Art Unit 3698
/PATRICK MCATEE/Supervisory Patent Examiner, Art Unit 3698