DETAILED ACTION
The instant application having Application No. 19/230303 filed on June 6, 2025 is presented for examination by the examiner.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Internet Communications
Applicant is encouraged to submit a written authorization for Internet communications (PTO/SB/439, found at http:/www.uspto.gov/sites/default/files/documents/sb0439.pdf) in the instant patent application to authorize the examiner to communicate with the applicant via email. The authorization will allow the examiner to better practice compact prosecution. The written authorization can be submitted via one of the following methods only: (1) Central Fax, which can be found in the Conclusion section of this Office action; (2) regular postal mail; (3) EFS WEB; or (4) the service window on the Alexandria campus. EFS web is the recommended way to submit the form since this allows the form to be entered into the file wrapper within the same day (system dependent). Written authorization submitted via other methods, such as direct fax to the examiner or email, will not be accepted. See MPEP § 502.03.
Applicant is also encouraged to contact the Examiner for an Interview, should the Applicant determine that clarifying and further illustrating the distinguishing features of the instant application may further the prosecution.
Oath/Declaration
The applicant’s oath/declaration has been reviewed by the examiner and is found to conform to the requirements prescribed in 37 C.F.R. 1.63.
Information Disclosure Statement
As required by M.P.E.P. 609(C), the applicant’s submission of the Information Disclosure Statement is acknowledged by the examiner and the cited references have been considered in the examination of the claims now pending. As required by M.P.E.P. 609(C), a copy of the PTOL-1449 initialed and dated by the examiner is attached to the instant office action.
Drawings
The applicant’s drawings submitted are acceptable for examination purposes.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent may not be obtained though the invention is not identically disclosed or described as set forth in section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the manner in which the invention was made.
Claims 1-2, 8-9, and 15-16 are rejected under 35 U.S.C. 103 as being unpatentable over Furukawa (US 2017/0187524) in view of Ho (US 2010/0199095).
As per claims 1, 8, and 15, Furukawa discloses A method, comprising:
establishing, by a first device, a shared secret for secure communication between a first device and a second device using a hybrid password-authenticated key exchange (PAKE), wherein the hybrid PAKE includes:
…
[encapsulating] a public key of a key encapsulation mechanism (KEM) for transmission to the second device (Furukawa, Figure 3 and associated texts such as paragraphs 9, 14, 19, 24, 29, 56, 83, 89, and 145 , teaches device A generating the key encapsulated KEM public key (KemPk) and transmitting KemPk to device B.);
…
decapsulating the shared secret from the … ciphertext using a private key of the KEM (Furukawa, Figure 3 and associated texts such as paragraphs 59, 61, 83, 90-92, and 146, teaches device B generating a ciphertext containing a session key and sending the ciphertext back to device A. Device A then decrypts the ciphertext using the KEM private key (KemSk) to reveal the session key.);
establishing, by the first device, a secure communication channel with the second device using the established shared secret; and providing, by the first device, data to the second device via the established secure communication channel (Furukawa, Figure 3 and associated texts, teaches performing a key exchange to generate a shared session key. The Examiner would note that it is inherent, or at least obvious, that the shared session key will be used to establish a secure channel to be used to exchange data between device A and device B.)
However, Furukawa does not specifically teach “deriving an initial secret using an elliptic-curve key exchange (ECKE) using a generator selected based on a password” or encrypting/decrypting data using the derived initial secret.
Ho discloses deriving an initial secret using an elliptic-curve key exchange (ECKE) using a generator selected based on a password (Ho, abstract, and Figures 4A and 4B and paragraph 43, teaches using an elliptic curve password based key exchange to generate a shared secret key between two devices. Ho, abstract, also teaches that this is performed to generate a shared master key that can be used for securing message communications.);
encrypting, using the initial secret, [data] for transmission to the second device (Ho, abstract, and Figures 4A and 4B and paragraph 43, teaches using an elliptic curve password based key exchange to generate a shared secret key between two devices. Ho, abstract and paragraphs 5 and 74, also teaches that this is performed to generate a shared master key that can be used for securing message communications.);
decrypting, using the initial secret, [data] received from the second device … (Ho, abstract, and Figures 4A and 4B and paragraph 43, teaches using an elliptic curve password based key exchange to generate a shared secret key between two devices. Ho, abstract and paragraphs 5 and 74, also teaches that this is performed to generate a shared master key that can be used for securing message communications.)
It would have been obvious to one of ordinary skill in the art before the effective filing date to have combined the teachings of Ho with the teachings of Furukawa. Furukawa teaches exchanging messages between two devices to perform a key exchange to generate a shared secret. Ho teaches using an elliptic curve password based key exchange to generate a key to be used when exchanging messages between two devices to perform secure communications. Therefore, it would have been obvious for the invention of Furukawa to use the key generated using the elliptic curve password based key exchange of Ho to secure the messages between sent between the devices as this would ensure that no unauthorized users can access the exchanged data.
Furukawa in view of Ho discloses encrypting, using the initial secret, a public key of a key encapsulation mechanism (KEM) for transmission to the second device (Furukawa, Figure 3 and associated texts such as paragraphs 9, 14, 19, 24, 29, 56, 83, 89, and 145 , teaches device A generating the key encapsulated KEM public key (KemPk) and transmitting KemPk to device B. Ho, abstract, and Figures 4A and 4B and paragraphs 5, 43, and 74, teaches using an elliptic curve password based key exchange to generate a shared secret key to secure communications between two devices. The Examiner would note that it would have been obvious to use the elliptic curve generated key to encrypt/decrypt data during transmission between the first device and the second device to ensure no unauthorized user can access the exchanged data.);
decrypting, using the initial secret, a ciphertext received from the second device encapsulating the shared secret using the public key; and decapsulating the shared secret from the decrypted ciphertext using a private key of the KEM (Furukawa, Figure 3 and associated texts such as paragraphs 59, 61, 83, 90-92, and 146, teaches device B generating a ciphertext containing a session key and sending the ciphertext back to device A. Device A then decrypts the ciphertext using the KEM private key (KemSk) to reveal the session key. Ho, abstract, and Figures 4A and 4B and paragraphs 5, 43, and 74, teaches using an elliptic curve password based key exchange to generate a shared secret key to secure communications between two devices. The Examiner would note that it would have been obvious to use the elliptic curve generated key to encrypt/decrypt data during transmission between the first device and the second device to ensure no unauthorized user can access the exchanged data.);
establishing, by the first device, a secure communication channel with the second device using the established shared secret; and providing, by the first device, data to the second device via the established secure communication channel (Furukawa, Figure 3 and associated texts, teaches performing a key exchange to generate a shared session key. The Examiner would note that it is inherent, or at least obvious, that the shared session key will be used to establish a secure channel to be used to exchange data between device A and device B. Ho, abstract and paragraphs 5 and 74, teaches secure communications using a shared secret.)
Claim 8 recites the additional limitations of “A non-transitory computer readable medium having program instructions stored therein that are executable by a first device to perform operations comprising …” (Furukawa, paragraphs 26, 36, 240, and 275, teaches a medium storing program instructions to be executed by a computer.)
Claim 15 recites the additional limitations of “A first device, comprising: one or more processors; and memory having program instructions stored therein that are executable by the one or more processors to cause the device to perform operations including …” (Furukawa, paragraphs 26, 36, 240, and 275, teaches a medium storing program instructions to be executed by a computer.)
As per claims 2, 9, and 16, Furukawa in view of Ho discloses wherein the encrypting uses the initial secret and the password (Ho, abstract, and Figures 4A and 4B and paragraph 43, teaches using an elliptic curve password based key exchange to generate a shared secret key to secure communication between two devices. As the shared secret key is generated using the password, the encrypting/decrypting of the communications using the shared secret key can be considered as using both the shared secret key and the password.)
Claims 3, 10, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Furukawa in view of Ho and further in view of Liu (US 8443194).
As per claims 3, 10, and 17, Furukawa in view of Ho discloses wherein the encrypting includes: … a second encryption of the public key using the initial secret (Furukawa, Figure 3 and associated texts such as paragraphs 9, 14, 19, 24, 29, 56, 83, 89, and 145 , teaches device A generating the key encapsulated KEM public key (KemPk) and transmitting KemPk to device B. Ho, abstract, and Figures 4A and 4B and paragraphs 5, 43, and 74, teaches using an elliptic curve password based key exchange to generate a shared secret key to secure communications between two devices. The Examiner would note that it would have been obvious to use the elliptic curve generated key to encrypt/decrypt data during transmission between the first device and the second device to ensure no unauthorized user can access the exchanged data.)
However, Furukawa in view of Ho does not specifically teach “wherein the encrypting includes: a first encryption of the public key using the password”
Liu discloses wherein the encrypting includes: a first encryption of the public key using the password (Liu, col. 2 lines 42-46 and col. 6 lines 59-62, teaches encrypting the public keys with a shared password.)
It would have been obvious to one of ordinary skill in the art before the effective filing date to have combined the teachings of Liu with the teachings of Furukawa in view of Ho. Furukawa in view of Ho teaches encrypting the public key with the shared secret during transmission. Liu teaches encrypting the public key with the shared password. Therefore, it would have been obvious for the system of Furukawa in view of Ho to encrypt the public key with the initial shared secret and also with the shared password as this would have provided an extra layer of encryption to further help prevent unauthorized access of the data.
Claims 6-7, 13-14, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Furukawa in view of Ho and further in view of Gray (US 2022/0006835).
As per claims 6 and 13, Furukawa in view of Ho discloses wherein the KEM … (Furukawa, Figure 3 and associated texts, teaches using a KEM to perform a key exchange.)
However, Furukawa in view of Ho does not specifically teach wherein the KEM is based on a learning with errors (LWE) algorithm.
Gray discloses wherein the KEM is based on a learning with errors (LWE) algorithm (Gray, paragraph 40, teaches using the learning with errors module lattice based KEM.)
It would have been obvious to one of ordinary skill in the art before the effective filing date to have combined the teachings of Gray with the teachings of Furukawa in view of Ho. Furukawa in view of Ho teaches using a KEM to perform a key exchange to generate a shared secret. Gray teaches using a specific KEM such as learning with errors module lattice. Therefore, it would have been obvious for the system of Furukawa in view of Ho to use the learning with errors module lattice based KEM as this would have been a simple substitution of one known KEM for another to yield the predictable results of using a KEM to perform a key exchange to generate a shared secret.
As per claims 7 and 14, Furukawa in view of Ho and Gray discloses wherein the KEM is Module-Lattice-Based KEM (ML-KEM) (Gray, paragraph 40, teaches using the learning with errors module lattice based KEM.)
As per claim 20. The first device of claim 15, wherein the KEM … (Furukawa, Figure 3 and associated texts, teaches using a KEM to perform a key exchange.)
However, Furukawa in view of Ho does not specifically teach wherein the KEM is based on a learning with errors (LWE) algorithm.
Gray discloses wherein the KEM is Module-Lattice-Based KEM (ML- KEM) (Gray, paragraph 40, teaches using the learning with errors module lattice based KEM.)
It would have been obvious to one of ordinary skill in the art before the effective filing date to have combined the teachings of Gray with the teachings of Furukawa in view of Ho. Furukawa in view of Ho teaches using a KEM to perform a key exchange to generate a shared secret. Gray teaches using a specific KEM such as learning with errors module lattice. Therefore, it would have been obvious for the system of Furukawa in view of Ho to use the learning with errors module lattice based KEM as this would have been a simple substitution of one known KEM for another to yield the predictable results of using a KEM to perform a key exchange to generate a shared secret.
Allowable Subject Matter
Claims 4, 11-12, and 18-19 are objected to as being dependent upon a rejected based claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The following is an examiner’s statement of reasons for allowance: The primary reason for the allowance of the claims is the inclusion of the limitation, inter alia, “wherein the encrypting includes: hashing the initial secret and the password to produce a hashed key; and encrypting, via one-time-pad (OTP), the public key using the hashed key".
Claim 5 is objected to as being dependent upon a rejected based claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The following is an examiner’s statement of reasons for allowance: The primary reason for the allowance of the claims is the inclusion of the limitation, inter alia, “wherein the hybrid PAKE further includes: hashing the decapsulated shared secret with the password to establish the shared secret".
The closest prior art of record includes:
Furukawa (US 2017/0187524) – teaches using a KEM to perform a key exchange between two devices. The steps include device A sending a key encapsulated KEM public key to device B, device B generating a ciphertext containing a session key and sending the ciphertext back to device A, and device A decrypts the ciphertext using the KEM private key to reveal the session key.
Ho (US 2010/0199095) – teaches using an elliptic curve password based key exchange to generate a shared secret key to secure messages being sent between two devices.
Gray (US 2022/0006835) – teaches using the learning with errors module lattice based KEM.
Brander (US 2015/0350250) – teaches using Elliptic Curve Diffie-Hellman (ECDH) to perform a key exchange to generate a shared secret.
Barreras (US 2024/0275582) – teaches generating a shared secret using a juggling password authenticated key exchange protocol using elliptic curve cryptography.
Nix (US 2022/0209944) – teaches Post-Quantum Cryptography Key Encapsulation.
Liu (US 8443194) – teaches encrypting exchanged public key with a shared password.
CAKE – (NPL “GeT a CAKE: Generic Transformations from Key Encapsulation Mechanisms to Password Authenticated Key Exchanges”) (provided in IDS) – teaches encrypting the KEM public key and the KEM ciphertext using a shared password as a secret key during transmission. CAKE also teaches using the learning with errors KEM module.
However, the combination of limitations as currently claimed cannot be found in the cited prior art of record.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOHN B KING whose telephone number is (571)270-7310. The examiner can normally be reached on Monday-Friday 10AM-6PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached on 5712728878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/John B King/
Primary Examiner, Art Unit 2498