DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 are pending for examination in instant application.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 03/02/2022 is/are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or non-obviousness.
Claim(s) 1-11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Dawoud et al. (Pub. No.: US 2018/0124026 A1), hereinafter “Daw” in view of Kamal et al. (Secure Computation by Secret Sharing Using Input Encrypted with Random Number), hereinafter “Kamal”.
As to claim 1. Daw discloses, a confidential computation system that executes computation related to data representing information in a state where the information is kept confidential by encryption (Daw, [0025], [0033-0035], describes encryption of documents/data before cloud storage, encrypted at rest cloud content, and retrieval/decryption through the network intermediary. [0036] describes searchable operation on encrypted documents through an encrypted database/search index.), the confidential computation system comprising:
a registration machine, an analyzer, and a provision server, each of which is a computer at least having a processor and a storage device, and which are connected to each other via a network to be capable of performing data communication (Daw, [0029-0030] discloses, enterprise network 10, user device 18, network intermediary /proxy 25, public network 20, and cloud service provider 30. Fig.7, [0061-0063], further disclose user device 18, proxy server 25 with encryption service 80, cloud service provider 30, and an encrypted search index that may reside on a different network connected physical machine.),
wherein the registration machine is configured to derive a data key by using a plaintext word representing a word which is not encrypted (Daw, [0041-0043], disclose deriving per keyword bytes K1 and K2 using enterprise secret key K, plaintext keyword W, and pseudorandom function F. [0051] repeats this derivation in the upload flow. [0070-0072], disclose the same in the document type embodiment.)
create encrypted data obtained by encrypting, by using the derived data key, plaintext data representing data which is not encrypted (Daw, [0036], states that the document can be encrypted using a bulk encryption algorithm such as AES-256. [0051] teaches encrypting the document and transmitting it to the cloud service provider, AES-256-GCM encryption uses secret key K. [0064] similarly teaches document encryption using secret key K, e.g., AES-256-GCM.)
encrypt the plaintext word and the shares with searchable encryption to create an encrypted word (Daw, [0041], identifies pseudorandom labels as encrypted keyword labels. [0042-0045] disclose using K1 and F to generate pseudorandom labels based on plaintext keyword W, and mapping those labels to encrypted document indices. [0051] states that Fk1N is the encrypted keyword label. [0068], [0070-0074] repeat the encrypted keyword label structure.),
the analyzer is configured to encrypt, with the searchable encryption, a plaintext query representing a query which is not encrypted to create an encrypted query (Daw, [0036] explicitly teaches user device 2 sending search term W1, encryption service 4 encrypting it under exact match searchable encryption to generate token t, and sending token t to cloud service provider 6. [0039] describes encryption of a search term. [0053-0054] disclose receiving search term W and rederiving K1/K2, then recomputing the associated pseudorandom labels. [0066] likewise states that encryption service 80 encrypts the search term.), and
the provision server is configured to acquire the created encrypted word and the created encrypted data to register the encrypted word and the created encrypted data in a database (Daw, [0036] discloses, documents stored at cloud service provider 6 and encrypted database EDB search index 8. [0038] specifies that the search index maps encrypted keyword labels to encrypted document indices. [0045-0048], disclose creating entries mapping pseudorandom/encrypted keyword labels to encrypted document indices as documents are encrypted. [0051] discloses generating the search index entry and encrypting /transmitting the document. [0061-0065], describes encrypted database EDB, search index 90, and cloud storage registration.),
acquire the created encrypted query to compare the created encrypted query with the registered encrypted word (Daw, [0039], expressly discloses cloud service comparison of encrypted search term with encrypted keyword labels in search index 8, finding a match only upon exact match. [0054-0055], disclose recomputing labels from the search term and searching the encrypted search index for a matching label. [0066] describes exact matching between encrypted search term and encrypted keyword label in an index entry.), and
acquire the shares if a comparison result indicates a match (Daw, [0039], says that after encrypted document index(es) are returned. [0056] describes the method retrieves encrypted document indices of matching entries. [0066] describes retrieval of the encrypted document index associated with the matching encrypted keyword label.),
and
decrypt the encrypted data into the plaintext data by using the reconstructed data key (Daw, [0034], discloses retrieval of encrypted files/data and decryption at network intermediary 25. [0036] describes decryption of the retrieved encrypted document after token match. [0056] teaches using decrypted document indices to retrieve corresponding encrypted documents, which are then decrypted and provided to the user. [0066], describes decrypting retrieved documents and sending the plaintext result to user device 18.).
Daw however is silent to disclose explicitly, distribute the data key to a plurality of shares; reconstruct, if the number of the acquired shares is a certain number or more, the data key having a correspondence relationship with the plurality of shares including the certain number or more of the shares by using the certain number or more of the shares.
Kamal however teaches the similar concept in the same field of endeavor including, distribute the data key to a plurality of shares (Kamal, section 2.3, cited discussion explains conventional secret sharing as diving a single secret/input into multiple shares distributed to multiple users.).
reconstruct, if the number of the acquired shares is a certain number or more, the data key having a correspondence relationship with the plurality of shares including the certain number or more of the shares by using the certain number or more of the shares (Kamal, section 2.3, any K and above number of shares will allow for the reconstruction of the original secret information.).
Therefor, before the effective filing date of the instant application it would have been obvious to one of the skilled in the art to incorporate the teaching of “Kamal” into those of “Daw” to provide method to overcome the concern among individuals about the privacy, security, and confidentiality of their information. Therefore, to solve this problem, there is a need for a technology that allows their information to be used without infringing their privacy. Kamal provides such scheme to permit a secure computation, wherein a set of parties with private inputs wish to compute a joint function of their inputs, without revealing anything but the output.
As to claim 2. The combined system of Daw and Kamal discloses the invention as applied above including, wherein the registration machine encrypts a word key and the plaintext word to create the encrypted word, and the analyzer encrypts a query key and the plaintext query to create the encrypted query (Daw, [0041-0043], for each keyword W in the documents, the keys K.sub.1 and K.sub.2 are derived using the secret key K and the pseudorandom function F as follows: K.sub.1←F.sub.K(1∥W); and K.sub.2←F.sub.K(2∥W), where the symbol “∥” denotes the concatenate operation. For example, “1∥W” denotes the string of “1” concatenated with W, resulting in a string “1W”. “encrypts a word key and the plaintext word” is construed as using a word dependent key/cryptographic operation on the plaintext word. It is not literal encryption of the key itself. Also see [0043-0045] and [0051]).
As to claim 3. The combined system of Daw and Kamal discloses the invention as applied above including, wherein the provision server acquires a share from the encrypted data if the encrypted word and the encrypted query are evaluated to be the same, and reconstructs the data key from the share if the number of shares is a predetermined threshold or more (Daw, [0061-0063], performs encrypted search and retrieval. [0039], [0056], [0066], after a match, system retrieves an encrypted documents index associated with a matching encrypted keyword label. Reconstruction is disclosed in Kamal section 2.3.).
As to claim 4. The combined system of Daw and Kamal discloses the invention as applied above including, wherein the registration machine generates a share in which the data key is embedded by using the plaintext word (Daw, [0030], [0033-0036, [0061-0065]).
As to claim 5. The combined system of Daw and Kamal discloses the invention as applied above including, wherein the registration machine generates a polynomial by using the plaintext word (Kamal, section 2.3, Shamir type threshold secret sharing.).
As to claim 6. The combined system of Daw and Kamal discloses the invention as applied above including wherein the provision server collects the share for each of designated tables (Daw, fig.11, 12 and 16a-16b, [0068-0069], [0074].).
As to claim 7. The combined system of Daw and Kamal discloses the invention as applied above including, wherein the provision server performs name identification on the plaintext data by using a common attribute for each of the tables (Daw, [0061-0066], the proxy/encryption service searches the encrypted index and retrieves documents from cloud provider 30. [0036, 0038], [0045-0046]. The encrypted search index maps encrypted keyword labels to encrypted document indices/identifiers.).
As to claim 8. The combined system of Daw and Kamal discloses the invention as applied above including, wherein a threshold is set for each of the tables, and the provision server is configured to acquire the share from the encrypted data for each of the tables, and reconstruct confidential information if the number of the shares is the threshold or more for each of the tables (Daw, [0044], [0054-0055], for each plaintext keyword W, the system uses a counter N for occurrences of the keyword, incrementing N until no corresponding encrypted index entry is found. [0038], The encrypted search index maps encrypted keyword labels to encrypted document indexes. Fig.12 and 16a-16b [0069], all document types process iterates through document types t and retrieves matching encrypted document indexes across types. [0056], [0066], reconstruct confidential information.).
As to claim 9. The combined system of Daw and Kamal discloses the invention as applied above including, wherein the provision server at least includes a first provision server and a second provision server, the first provision server acquires a share from the encrypted data if the encrypted word and the encrypted query are evaluated to be the same, and the second provision server reconstructs the data key from the share (Daw, [0029-0030], [0061-0063], teaches a multi-component searchable encryption architecture including a proxy/encryption service and cloud service provider. [0039], [0066], the proxy/encryption service encrypts a search term and searches an encrypted index. Upon an exact match between the encrypted search term and an encrypted keyword label, the system retrieves the encrypted document index associated with the matching entry. [0056], [0066], the retrieved document index enables retrieval of a corresponding encrypted document from the cloud provider.).
As to claim 10 and 11 are rejected for same rationale as applied to claim 1 above.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Please see the attached PTO-892.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAUQIR HUSSAIN whose telephone number is (571)270-1247. The examiner can normally be reached M-F 7:00 - 8:00 with IFP.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Vivek Srivastava can be reached at 571 272-7304. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Tauqir Hussain/Primary Examiner, Art Unit 2449