DETAILED ACTION
This Non Final Office Action is in response to Application filed on 07/30/2025.
Claims 1-15 filed on 07/30/2025 are being considered on the merits.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Drawings
The drawings filed on 07/30/2025 are accepted.
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 07/30/2025 and 03/17/2026 have been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly an initialed and dated copy of Applicant's IDS form 1449 filed 07/30/2025 and 03/17/2026 are attached to the instant Office action.
Claim Objections
Claims 2 and 9 objected to because of the following informalities:
Claim 2 recites “…a number of the PSKs” implying a plurality of PSKs with no antecedent basis. For examination purpose, the above number pertains to the PSK.
Claim 9 recites “QKD” without reciting the actual words of the abbreviation.
Appropriate correction is required.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1, 5, 7-8, 10-15 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Feng (CN 118413389).
Regarding claim 1, 5, 7-8 and 10-15 Feng teaches a key management device connected to a first application by a wired communication scheme or a wireless communication scheme (Feng second device, i.e. key management device, connected to the first device, i.e. first application, where the connection is either wired or wireless), the key management device comprising:
a processor implemented by at least one processing device and configured to transmit a response including an application key and PSK information indicating a pre-shared key (PSK) used to establish a first communication session between the first application and the key management device to the first application (Feng [0093-0094, 0106] the second device, i.e. key management device, transmits a second message, i.e. response, including: second shared key and third shared key corresponding to the application key, and pre-shared key identifier corresponding to the PSK information and indicating pre-shared quantum key, where the pre-shared key identifier is used by the first device, i.e. first application, to retrieve quantum pre-shared key and using the quantum pre-shared key to establish session key and session communication between the first device, i.e. first application, and the second device, i.e. key management device), when receiving a request for the application key used to encrypt or decrypt communication in the first application (Feng Figure 3 the response with the second message S317 is in response to the first message/request S307, which is used to request/receive second and third pre-shard keys used to encrypt and decrypt communication by means of the session key).
Regarding claim 5, Feng teaches the key management device according to claim 1, wherein the PSK information includes at least one of identification information of the PSK and key data indicating the PSK (Feng [0106] “…quantum key identifier as a pre-shared key identifier.”).
Regarding claim 7, Feng teaches the key management device according to claim 1, wherein the processor transmits, to another key management device connected to a second application as a communication destination of the first application by a wired communication scheme or a wireless communication scheme, an update request of a PSK used to establish a second communication session between the second application and the another key management device (Feng discloses devices in the quantum-safe zero-trust network initiating communication with each other and establishing session keys illustrated in e.g. Figure 3, [0057, 0069]).
Regarding claim 8, Feng teaches the key management device according to claim 7, wherein the update request of the PSK includes specific information indicating at least one of identification information of the PSK used to establish the first communication session and key data indicating the PSK used to establish the first communication session, and the second communication session is established by using the specific information (Feng [0057, 0062, 0069] discloses updating the session key, which includes updates to the process in Figure 3, including a PSK identifier, which corresponds to random and quantum key).
Regarding claim 10, a quantum cryptographic communication system comprising: the key management device according to claim 1; and an information processing device in which the first application operates (Rationale in claim 1 applies, [0062] the system in Figure 1 further comprises QKD, where the system in Figure 1 corresponds to the quantum cryptographic communication system ).
Regarding claim 11, claim 11 recites similar limitations to claim 1, therefore rejected with the same rationale applied to claim 1.
Regarding claim 12, claim 12 recites similar limitations to claim 1, therefore rejected with the same rationale applied to claim 1.
Regarding claim 13, claim 13 recites similar limitations to claim 1, therefore rejected with the same rationale applied to claim 1.
Regarding claim 14, claim 14 recites similar limitations to claim 1, therefore rejected with the same rationale applied to claim 1.
Regarding claim 15, claim 15 recites similar limitations to claim 1, therefore rejected with the same rationale applied to claim 1.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 2-4, and 6 are rejected under 35 U.S.C. 103 as being unpatentable over Feng (CN 118413389) in view of Bisbee (US 20020184217 A1).
Regarding claim 2, Feng teaches the key management device according to claim 1.
Feng does not disclose the below limitation.
Bisbee discloses wherein the request for the application key includes specific information specifying a number of the PSKs, a size of the PSK, and a cryptographic algorithm for which the PSK is used, and the PSK information includes identification information of the PSK based on the specific information and key data indicating the PSK based on the specific information (Bisbee [0059] “Application Server-side components can therefore be stateless since all the information needed to authenticate a User's request is communicated in the Security Context that is included in the User's request. After a Stateless System Component 535 finishes a task, it is free to service another User's request.”, [0053, 0063] and Figure 4a-c illustrates specific information of the security context included in the request, including known or random number pertaining to the security context and its associated key, i.e. number, key size, keys algorithms identifiers, a Security Context ID, public key, symmetric key and time related information, i.e. key data).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Feng to incorporate the teaching of Bisbee to utilize the above feature, with the motivation of utilizing security contexts to eliminate the risk of interception, modification, or unauthorized use., as recognized by (Bisbee [0019]).
Regarding claim 3, Feng teaches the key management device according to claim 1.
Feng does not disclose the below limitation.
Bisbee discloses wherein the request for the application key includes identification information for identifying key data used for the PSK and specific information specifying a cryptographic algorithm for which the PSK is used, and the PSK information includes at least one of information indicating permission or refusal of using the PSK based on the specific information, identification information of the PSK based on the specific information, and key data indicating the PSK based on the specific information (Bisbee [0059] “Application Server-side components can therefore be stateless since all the information needed to authenticate a User's request is communicated in the Security Context that is included in the User's request. After a Stateless System Component 535 finishes a task, it is free to service another User's request.”, [0053, 0063] and Figure 4a-c illustrates specific information of the security context included in the request, including known or random number pertaining to the security context and its associated key, i.e. number, key size, keys algorithms identifiers, a Security Context ID, public key, symmetric key and time related information, and role and authorization/permission access information).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Feng to incorporate the teaching of Bisbee to utilize the above feature, with the motivation of utilizing security contexts to eliminate the risk of interception, modification, or unauthorized use., as recognized by (Bisbee [0019]).
Regarding claim 4, Feng in view of Bisbee teaches the key management device according to claim 3. wherein the key management device according to wherein the specific information further includes key data indicating the PSK (Feng [0093-0094, 0106] the second device, i.e. key management device, transmits a second message, i.e. response, including: second shared key and third shared key corresponding to the application key, and pre-shared key identifier corresponding to the PSK information and indicating pre-shared quantum key, where the pre-shared key identifier is used by the first device, i.e. first application, to retrieve quantum pre-shared key and using the quantum pre-shared key to establish session key and session communication between the first device, i.e. first application, and the second device, i.e. key management device, and Bisbee further discloses specific information in the security context and include key data pertaining to different keys as disclosed above in claim 3 and illustrated in Figures 4a-c, motivation in claim 3 applies).
Regarding claim 6, Feng in view of Bisbee teaches the key management device according to claim 2.
Feng does not disclose the below limitation.
Bisbee discloses wherein the key data indicating the PSK is a random number different from the application key or an application key shared with another key management device by encryption transfer using a link key generated between opposing QKD devices by Quantum Key Distribution (QKD) (Feng illustrates, in Figure 1, the quantum key, which is part of the communication key, securely transferred from opposing QKD devices to different communicating party within the network as disclosed in [0062, 0106], Bisbee discloses in [0053] the security context includes key data comprising a random number different from public key and symmetric key, note that the above limitation is recited in the alternative).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Feng to incorporate the teaching of Bisbee to utilize the above feature, with the motivation of utilizing security contexts to eliminate the risk of interception, modification, or unauthorized use., as recognized by (Bisbee [0019]).
Claims 9 is rejected under 35 U.S.C. 103 as being unpatentable over Feng (CN 118413389) in view of Morchon (US 12712712 B2).
Regarding claim 9, Feng discloses the key management device according to claim 1, wherein the application key is shared with another key management device by encrypted transfer using a link key generated between opposing QKD devices by QKD (Feng illustrates, in Figure 1, the quantum key, which is part of the communication key, securely transferred from opposing QKD devices to different communicating party within the network as disclosed in [0062, 0106]).
Feng does not explicitly disclose the below limitation.
Morchon discloses the processor increases an update frequency of the PSK as an accumulation amount of the application key increases (Morchon Col. 24 line 56-67 “The entity protecting the MBS traffic, e.g., a NF or a number of NFs interacting with each other would manage the key hierarchy and a policy in charge of determining how frequently the keys are to be updated and under which circumstances: regular key update of the group key, including, e.g., frequency or maximum usage. regular key update of the transport “common” key, including, e.g., frequency or maximum usage. update of a transport “set” key when a UE leaves or joins. update of the transport “common” key and/or group key when a UE leaves or joins.”, where the entity updates they key according to frequency or maximum usage, therefore, e.g. the faster the maximum usage is reached, the more frequent key updates is being performed).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Feng to incorporate the teaching of Morchon to utilize the above feature, with the motivation of protect contents against attacks triggered by compromised keys used for too long, as recognized by (Morchon Col. 8 line 5-10, Col. 24 line 56-67).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
Hirahara (US 20180205721 A1) discloses [0081] “Setting of an encryption provider, a key size, a digital signature algorithm, and the like related to security levels of the issued server certificates is decided by both the system setting and the initial setting retained in advance.”
Resch (US 20180034639 A1) discloses [0043] “ security parameters may include one or more of a share number N, a value of security algorithm constant p (a prime number), a value of security algorithm constant q (a prime number), one or more shared secret algorithm parameters, an encryption algorithm indicator, a key generator function indicator, a key size, a random number generator function, a random number size, a hash function type indicator, a security package structure indicator, a number of passwords, and any other parameter to specify the operation of the storing of the access information package data. The obtaining may be based on one or more of retrieving the security parameters from a local memory, sending a query to a dispersed storage (DS) managing unit”
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BASSAM A NOAMAN whose telephone number is (571)272-2705. The examiner can normally be reached Monday-Friday 8:30 AM-5:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BASSAM A NOAMAN/ Primary Examiner, Art Unit 2497