Invalidity dossier
US 4891781
Modulo arithmetic processor chip
Current assignee: Thales DIS CPL USA Inc
Added 9/28/2026, 1:32:09 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll search for authoritative information on US 4891781, including any 2026 CAFC activity.
Now let me check for any litigation or CAFC 2026 docket activity involving this patent.
US 4,891,781 — "Modulo Arithmetic Processor Chip"
Identifier note (strict reading): I analyzed exactly US 4,891,781 (7 digits, as printed in the patent itself as "4,891,781"). I did not substitute the similarly-numbered patents that surface in searches (e.g., US 5,210,710, a later Omura/Cylink continuation; US 7,916,781, Caltech's patent asserted in Caltech v. Apple/Broadcom; US 4,201,770-family Hellman patents). One search hit returned an unrelated "4891781" (a Minnesota PUC receptor ID) — not this patent.
1. Bibliographic data
| Field | Value | Source |
|---|---|---|
| Patent number | US 4,891,781 (US4891781A) | Google Patents; patent PDF |
| Title | Modulo arithmetic processor chip | Google Patents |
| Inventor | Jimmy K. Omura (Cupertino, CA) | Google Patents; EP 0281303 |
| Original assignee | Cylink Corp. (Sunnyvale, CA) | Google Patents; patent PDF |
| Current assignee (listed) | Thales DIS CPL USA Inc. (intermediate: SafeNet, Inc.) | Google Patents; SafeNet 2007 credit-agreement schedule |
| Application no. | US 07/289,124 | Google Patents |
| Filing date | 1988-12-22 (Google Patents); Unified Patents lists 1988-12-21 | Google Patents; Unified Patents |
| Priority date | 1987-03-04 (Google Patents); Unified Patents lists 1987-03-03 | Google Patents; Unified Patents |
| Issue date | 1990-01-02 (PDF cover: "Jan. 2, 1990"); Unified Patents shows grant date 1990-01-01 | Patent PDF; Unified Patents |
| Expiration | 2007-03-04 (anticipated); Unified Patents: 2007-03-03 — status Expired – Lifetime | Google Patents; Unified Patents |
| Claims / drawings | 44 claims, 9 drawing sheets | Patent PDF |
| Examiner | Salvatore Cangialosi | Unified Patents |
| Continuity | Continuation of Ser. No. 07/021,066 (filed 1987-03-04) and Ser. No. 07/142,328 (filed 1988-01-04), both abandoned | Patent specification |
| Foreign family | EP 0281303 A2/A3 (Cylink; priority US 21660, filed 23.02.1988) | EPO publication server |
Sources: https://patents.google.com/patent/US4891781/en · https://patentimages.storage.googleapis.com/bb/29/58/849243e0052fb5/US4891781.pdf · https://portal.unifiedpatents.com/patents/patent/US-4891781-A · http://data.epo.org/publication-server/rest/v1.2/patents/EP0281303NWA3/document.html
Cited prior art (patents): US 4,200,770 (Hellman), US 4,405,829 (Rivest – RSA), US 4,218,582 (Hellman), US 4,424,414 (Hellman), US 4,587,627 (Omura), plus Galois-field work by Berlekamp, Marver, and others; non-patent citations include Diffie & Hellman, "New Directions in Cryptography" (IEEE Trans. Info. Theory, Nov. 1976).
2. Abstract (verbatim)
"The present invention provides for a processor chip for computing addition, multiplication, and exponentiation in a Galois Field of integers modulo a prime number p, GF(p). The invention includes twelve registers for storing n-bit integers, a full adder for shifting left and adding data stored in two of the registers. A feedback register is included for storing a n-bit number and means for generating a feedback number is provided, wherein the feedback number is generated from a prime number, p. Also included are modulo means for reducing data bits stored in the registers modulo a prime number p."
3. Plain-language overview of the independent claims
The 44 claims fall into five families. Independent claims are: 1, 2, 8, 11, 12, 15, 16, 19, 22, 23, 26, 29, 32, 33, 36–44.
Family A — "ring of integers" apparatus (claims 1–7)
| Claim | Plain language |
|---|---|
| 1 | A chip that multiplies two n-bit integers X and Y modulo an integer p. X is stored in an L-bit X register and split into two L-bit "alternate" forms in A1/A2 registers, from which control logic derives a 1-bit control signal. B1/B2 and C1/C2 are L-bit registers; a full adder either (a) shifts B left and adds it into C (control bit = 1) or (b) just shifts B left (control bit = 0). A feedback register holds an n-bit "feedback number" generated from p (the two's-complement / 2ⁿ mod p value), and modulo logic reduces C modulo p and writes the L-bit result to the Y register. |
| 2 | The same architecture used for addition modulo p (the C registers accumulate X + Y). This claim is broader than claim 1 — it does not itself recite the feedback register, feedback-number generator, or modulo means (those are added by dependent claim 3). |
Dependents: 3 (adds feedback/modulo means to claim 2), 4 (adds exponentiation via a series of multiplications), 5 (adds an overflow counter), 6, 7.
Family B — Adder chip with base/carry split (claims 8–14)
| Claim | Plain language |
|---|---|
| 8 | An adder chip computing C = (A + B) mod p. Two register means hold A and B; feedback means holds F = 2ⁿ − p; arithmetic means adds A and B into an accumulator; overflow means holds an overflow integer; when there is an overflow, F is fetched into the second register and added to C; reduction logic subtracts p (mod-p reduction) if C > p. |
| 11 | A more parallel adder chip: A and B are each stored as base bits and carry bits in four registers. Four feedback numbers are generated — F1 = 2ⁿ − p, F2 = 2F1 mod p, F3 = 3F1 mod p, F4 = 4F1 mod p. A full-adder array first adds A's base and carry bits to B's base bits (producing an intermediate sum), then adds that sum's base and carry bits to B's carry bits to form C. An overflow counter I is maintained; depending on whether I = 1, 2, 3 or 4, the corresponding F1–F4 is fetched and added back into C; final mod-p reduction if C > p. |
| 12 | Structurally like claim 11 but with a single feedback number F = 2ⁿ − p instead of the F1–F4 set. |
Dependents: 9–10 (full/half adders under claim 8), 13 (full adders under claim 12), 14 (multiplexer control under claim 13).
Family C — Multiplier chip, plain registers (claims 15–21)
| Claim | Plain language |
|---|---|
| 15 | A multiplier chip computing C = A·B mod p. A and B register means; feedback F = 2ⁿ − p; first partial-reduction means that adds F to B whenever B's most-significant bit shifts left out of the register (keeping B bounded during shifting); shift-and-add arithmetic means that adds B into accumulator C based on the least-significant bit of A shifted right; an overflow counter I; second partial-reduction means that, when multiplication finishes, loads I into the first register and F into the second, multiplies them, and adds the product back into C (compensating for accumulated 2ⁿ overflow terms); and final mod-p reduction if C > p. |
| 16 | Same as claim 15 but omits the first partial-reduction means — only the shift-add loop, the overflow counter, the end-of-multiply overflow compensation, and the final reduction. |
| 19 | Multiplier with the first partial-reduction means (B kept reduced as it shifts) but without the overflow counter/second partial-reduction compensation; ends with the mod-p reduction. |
Dependents: 17–18 (full/half adders under 16), 20–21 (full/half adders under 19).
Family D — Multiplier chip with base/carry split and F1–F4 (claims 22–35)
| Claim | Plain language |
|---|---|
| 22 | Base/carry implementation of the multiplier. A and B are each held as base bits + carry bits. F1–F4 are generated as in claim 11. A first partial-reduction stage adds a preselected one of F1–F4 to B based on the high-order base/carry bits shifting out of B. The full-adder array adds B's base/carry bits into C's base bits, then adds that intermediate sum into C's carry bits. Overflow means tracks I; when I = 1, 2, 3 or 4, the corresponding F value is added back into the accumulator; final mod-p reduction. |
| 23 | Same as claim 22 but without the first partial-reduction means (keeps only the end-of-multiply F1–F4 overflow compensation). |
| 26 | Keeps the first partial-reduction means (preselected F1–F4 from shifted-out high bits), the base/carry full-adder accumulation, accumulator base/carry, and overflow means, and final mod-p reduction — but omits the second (overflow-compensation) partial-reduction means. |
| 29 | The simplest member of this family: base/carry registers for A and B; a single feedback number F1 = 2ⁿ − p; base/carry full-adder accumulation of the product; overflow means; final mod-p reduction. No partial-reduction stages. |
| 32 | The full-featured version: base/carry registers, F1–F4, first partial reduction (F chosen from shifted-out high bits), full-adder base/carry accumulation, overflow index I, second partial reduction (I and F1 loaded into registers, product added back into C), and final mod-p reduction. |
| 33 | Like claim 32 but without the first partial-reduction means (retains the end-of-multiply I·F1 compensation and final reduction). |
Dependents: 24–25 (under 23), 27–28 (under 26), 30–31 (under 29), 34–35 (under 33) — adding full-adder and multiplexer limitations.
Family E — Method claims (claims 36–44)
| Claim | Plain language |
|---|---|
| 36 | A method of adding A + B mod p: store A, store B, generate F = 2ⁿ − p, add A and B into an accumulator, store the overflow, fetch F into the B register and add it back to C, and reduce mod p when C > p. |
| 37 | Method version of claim 11: base/carry storage, generate F1–F4, two-step full-adder summation, track overflow index I, add the matching F1–F4 back into the accumulators, final reduction. |
| 38 | Method version of claim 12: base/carry storage with a single F. |
| 39 | Method of multiplying A·B mod p: store A and B, generate F, perform the first partial reduction (add F when B's top bit shifts out), shift-add B into C based on A's LSB, count overflow I, then at completion load I and F into registers, multiply I·F, add the product back into C, and finally reduce mod p. |
| 40 | Method of multiplying without the first partial reduction: shift-add loop, overflow counting, end-of-multiply I·F compensation, final reduction. |
| 41 | Drafted with an apparatus-style preamble ("A modulo arithmetic processor chip … comprising the steps …") but in substance claims method steps: store A and B, generate F, add F to B on left-shift of B's top bit (first partial reduction), shift-add B into C based on A's LSB, store C, and perform the final mod-p reduction — no end-of-multiply overflow compensation. |
| 42 | Method using the base/carry representation and F1–F4: first partial reduction using the appropriate F value when high base/carry bits shift out; base/carry shift-add accumulation of the product; store overflow I; add F1–F4 back depending on I = 1–4; final reduction. |
| 43 | Like claim 42, but the overflow compensation is performed by the second-partial-reduction means (load I and F1, compute I·F1, add back into the accumulator), followed by final reduction. |
| 44 | A method of adding A + B mod p that is broader/simpler than claim 36 (does not require the "arithmetic means coupled to the register means" language for generating C): store A and B, generate F = 2ⁿ − p, add A + B, store C, store overflow, add F back, reduce mod p when C > p. |
4. Litigation / CAFC 2026 docket findings
No CAFC 2026 docket or 2026 litigation involving US 4,891,781 was found.
- The patent's Google Patents record shows status "Expired – Lifetime," anticipated expiration 2007-03-04, i.e., it passed out of enforceable term roughly 19 years before the current date. Unified Patents likewise shows an expiration date of 2007-03-03.
- The only 2026 Federal Circuit material returned in my searches was unrelated: the Contour IP Holding LLC v. GoPro, Inc. docketing notice (Fed. Cir. No. 2026-2012, notice dated July 8, 2026) and the Caltech/Broadcom appellate brief concerning Caltech's '781 patent (a different patent number). Neither involves US 4,891,781.
- Searches for "4891781" in litigation contexts surfaced only: (a) the SafeNet/Deutsche Bank first-lien and second-lien security-agreement schedules (2007) listing "MODULO ARITHMETIC PROCESSOR CHIP – 4891781" among collateral; (b) an EPO/Japanese search-report citation of US 4,891,781 (together with JP 63-282777 and EP 281303) in a later WO application's prior-art table; and (c) the Google Patents citation graph (cited by, among others, US 5,210,710, US 5,261,001, US 5,274,707, US 5,513,133).
Uncertainty: My docket check relied on general web search of public sources (Google Patents, Unified Patents, CourtListener/Justia material surfaced in results, news/legal-press). I could not directly query PACER, the CAFC electronic docket, or Docket Navigator in this session, so I cannot give a categorical "never litigated" answer; I can only state that no 2026 CAFC appeal or pending 2026 case involving this patent is visible in the sources searched, which is consistent with an expired 1990 patent whose maximum term ended in 2007.
5. Other uncertainty / drafting flags (read literally, no auto-correction)
- Filing/priority date discrepancy: Google Patents gives filing 1988-12-22 and priority 1987-03-04; Unified Patents gives 1988-12-21 and 1987-03-03. The specification itself says the application is a continuation of Ser. No. 07/021,066 (filed 1987-03-04) and Ser. No. 07/142,328 (filed 1988-01-04).
- EP 0281303 priority reference reads "04.03.1987 US 21660" — a five-digit number that likely corresponds to Ser. No. 021,066, but I am not auto-correcting it.
- Claim 41 is captioned as an apparatus ("A modulo arithmetic processor chip …") yet recites "the steps, performed by said modulo arithmetic processor chip" — a mixed apparatus/method form preserved literally.
- Claim 26 references "said accumulator means" without antecedent basis (it introduces "accumulator-base means" and "accumulator-carry means") and omits any second-partial-reduction means — likely a prosecution/drafting artifact, reported as printed.
- Inventor/assignee spelling: the patent prints the inventor once as "Omura" and the cited 1986 reference by "Omura et al." (US 4,587,627). Google Patents spells the inventor "Jimmy K. Omura"; the Rivest patent is cited in the specification as "Revest et al." — a literal typo in the patent, not corrected here.
Generated 9/28/2026, 1:14:23 PM
Cases on file (0)
Specific litigation cases in our database that name US patent 4891781. The free-form analysis below may also discuss cases beyond this list.
No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll search litigation databases and court records for US patent 4891781.
Let me dig deeper into litigation-specific databases and search by the patent's owner history.
Let me search court records and litigation databases specifically for this patent number.
Litigation Search Report — U.S. Patent No. 4,891,781
Patent: U.S. 4,891,781 — "Modulo arithmetic processor chip"
Inventor: Jimmy K. Omura
Original assignee: Cylink Corp. (current assignee of record: Thales DIS CPL USA, Inc.)
Priority date: March 4, 1987 | Filed: Dec. 22, 1988 | Granted: Jan. 2, 1990
Status: Expired – Lifetime (anticipated expiration March 4, 2007)
Bottom line
I was unable to identify any litigation — past or pending — that asserts, challenges, or otherwise involves U.S. Patent No. 4,891,781 specifically. No case naming this patent as an asserted patent appeared in the sources I searched. If such a case exists, it is not surfaced by the publicly searchable litigation records I was able to reach.
What I searched and what I found
| Source | Result |
|---|---|
Unified Patents patent portal — portal.unifiedpatents.com/patents/patent/US-4891781-A |
Patent page retrieved; only bibliographic data, patent ratings, citation counts, and family data. No litigation section / no asserted-in cases listed. |
Google Patents — patents.google.com/patent/US4891781/en |
Legal-status history shows only assignments (Silicon Valley Bank security interest 2001; SafeNet merger 2007) and expiration. No litigation events. |
| General web / court-record searches on "4891781" and "4,891,781" + litigation terms | No infringement or declaratory-judgment case tied to this patent number. Note: numerous hits on "4891781" are false positives (a Brazilian corporate registry number, a Lithuanian registry notice, a Soviet patent/thermos-siphon document, a cave-survey coordinate, and a "Prime Curios" page noting the number is prime) — none are U.S. patent litigation. |
| CourtListener / general case-law searches on the patent owner (Cylink Corp.) | Returned litigation involving Cylink, but not involving this patent (see below). |
Important disambiguation — Cylink litigation NOT about 4,891,781
My searches surfaced several Cylink-related cases. To avoid any confusion, none of these involve U.S. 4,891,781:
- Cylink Corp. v. Claus P. Schnorr, Civil Action No. 95-2121 (JR), U.S. District Court for the District of Columbia, decided Sept. 25, 1996 (939 F. Supp. 39).
- Plaintiff: Cylink Corporation. Defendant: Claus P. Schnorr.
- Subject patent: U.S. 4,995,082 (the Schnorr patent — digital signatures), not 4,891,781.
- Posture: Cylink sought a declaratory judgment of non-infringement. The court granted Schnorr's motion to dismiss for lack of an actual controversy (no justiciable declaratory-judgment jurisdiction).
- Source: https://www.courtlistener.com/opinion/[1511666](/patent/1511666)/cylink-corp-v-schnorr/
The Cylink / RSA Data Security (PKP) dispute (mid-1990s) concerned RSA licensing and public-key patents, not 4,891,781. Contemporaneous reporting (Cypherpunks list, Aug. 1, 1994) describes the Caro-Kann/Cylink vs. RSA-Data-Security conflict. This is background only and is not a case asserting the '781 patent.
US 5,210,710 — "Modulo arithmetic processor chip" — is a related but separate Cylink/Omura patent (same family, listed on the '781 Google Patents page as citing it). If you are looking for litigation over the modular-arithmetic processor technology, the '710 patent is a distinct asset and should be searched separately; I did not confirm any case on it either.
Caveats on completeness
- Public patent-litigation aggregators (Unified Patents, Google Patents litigation data) are not exhaustive for older district-court cases that were never indexed or that were filed in the 1990s, and PACER full dockets require paid access not available to me here.
- Because this patent expired on March 4, 2007, any infringement suit would have had to be filed on or before that date. I found no such filing.
- Given the above, I cannot state affirmatively that litigation exists, and I also cannot rule out an un-indexed 1990s case with certainty. I am expressly flagging this limitation rather than filling the gap with a guess.
Recommended next steps to confirm a negative
If you require a definitive clearance on this point:
- PACER — run a party search for "Cylink" and "SafeNet" across all district courts (1988–2007 window), then pull dockets to check asserted patents.
- Lex Machina / Docket Navigator / Derwent LitAlert — patent-specific litigation databases that index by patent number; search
4,891,781. - USPTO Patent Assignment / litigation records and the Federal Circuit docket, since any district-court judgment involving this patent would likely have produced an appeal.
- Request confirmations from Thales DIS CPL USA, Inc. (current assignee of record) or its counsel regarding enforcement history.
No litigation involving U.S. 4,891,781 could be identified in the available public records.
Generated 9/28/2026, 1:14:08 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll verify the structured data with targeted searches before writing the report.
Proceedings overview
Zero AIA trial proceedings are on file against US 4,891,781 — no IPRs, no PGRs, no CBMs, no derivative proceedings — a total count of 0 active / 0 invalidated / 0 sustained / 0 settled / 0 institution-denied. The canonical "PTAB proceedings on file" block (USPTO Open Data Portal) returns no AIA trial records for this patent, and independent searching (PTAB petitions portal, Unified Patents patent page, docket aggregators) surfaced no petition, institution decision, Final Written Decision, or Federal Circuit appeal. The bottom-line defensive posture is "no PTAB ammunition exists because no PTAB shots were ever fired — and none can be, going forward, because the patent is dead." A defendant facing a demand letter today holds an unusually strong position, but the strength comes from expiry, not from IPR outcomes: there are no canceled claims to point to, and equally no surviving claims to worry about.
Proceedings
No proceedings to report
There is nothing to itemize. For the record, here is why the universe is empty, field by field:
| Proceeding type | Availability against US 4,891,781 | Reason |
|---|---|---|
| Inter Partes Review (35 U.S.C. §§ 311–319) | Available in theory (IPR can be filed against an expired patent), never filed | AIA trial regime applies to petitions filed on or after 2012-09-16. The patent expired 2007-03-04 (anticipated; Unified Patents shows 2007-03-03) — roughly five years before the first IPR was ever available, and ~19 years before today. |
| Post-Grant Review (§§ 321–329) | Not available | PGR lies only against patents with at least one claim having an effective filing date on or after 2013-03-16 (AIA first-inventor-to-file). This patent's priority date is 1987-03-04 — 26 years too early. |
| Covered Business Method review (AIA § 18) | Not available | (a) CBM required a claim directed to a "financial product or service" — the '781 claims recite a finite-field arithmetic processor chip, not a financial-service method; (b) the CBM transitional program sunset on 2020-09-16. |
| Derivation / interference | N/A | Pre-AIA interference practice; no interference record appears in the patent's legal-events feed. |
Note on a related but distinct channel (flagged, not scored): the AIA-trial block does not cover ex parte reexamination or the (pre-2018) inter partes reexamination, which existed long before the AIA. I found no reexamination certificate referenced in the sources I could reach, but I could not query the USPTO reexamination database directly in this session, so I state this as an unverified negative, not a confirmed one. If a reexam certificate were ever issued, it would appear in PatentCenter for 4,891,781.
Also flagged as unverified: the foreign family member EP 0281303 A2/A3 (Cylink) could in principle have drawn an EPO opposition — that is a European proceeding, not a PTAB proceeding, and I could not confirm or exclude one from the sources reachable here. It is outside the scope of this report but is the one plausible place a real adversarial challenge to this family would sit.
Strategic summary
Claim status: 44 of 44 claims UNTESTED at the PTAB — but all 44 are expired. No claim of US 4,891,781 has ever been canceled, confirmed, or even construed by the Board; there is no IPR certificate, no FWD, no statutory disclaimer on file in this proceeding context. Standing alone, that would be a warning to a defendant: the whole claim set — including the independent apparatus claims 1, 2, 8, 11, 12, 15, 16, 19, 22, 23, 26, 29, 32, 33 and the method claims 36–44 — remains textually intact and has never been narrowed by an administrative tribunal. But that warning is neutralized by the 2007-03-04 expiration. A patent that expired in 2007 cannot support a live infringement claim: damages reach only pre-expiration infringement, and the § 286 six-year lookback window closed in 2013. So the correct reading is not "hardened patent with 44 live claims" but "silent patent with 44 moot claims." The absence of any IPR is best explained by the same fact that explains the absence of any litigation: nobody asserted this patent while it was alive, and no rational petitioner spends IPR money on a patent with no revenue stream to attack.
Estoppel landscape: empty — § 315(e)(2) estops nobody. Because no IPR ever reached a Final Written Decision, there is no IPR estoppel against any party or privy. Likewise, no § 325(e)(2) PGR estoppel. For a defendant currently facing assertion, that means the entire prior-art field remains open — there is no "raised or reasonably could have been raised" bar, and no PTAB record to cut against you at the district-court level (no petitioner admission, no Board claim construction, no adverse credibility findings). Concretely: every ground in the previously generated prior-art analysis — the GF(2ᵐ) hardware multipliers (US 4,037,093; 4,162,480; 4,251,875; 4,538,240; 4,574,361; 4,587,627), the public-key method patents (US 4,200,770; 4,218,582; 4,405,829; 4,424,414; 4,567,600), and the RSA-chip non-patent literature (Barrett; Sedlak & Golze; Rankine; Kochanski; Rivest; Orton et al.) — remains fully available in a district court, and the same-inventor Omura references (US 4,587,627 and US 4,567,600) remain un-adjudicated for § 102(e)/double-patenting purposes. The prior-art section's flag that the file wrapper was never reviewed matters more here, not less: with no IPR record, the only validity history on this patent is the original 1987–1989 prosecution, which no one has ever supplemented or challenged.
Pattern signals: the null pattern is itself the signal. No petitioner filed against this patent — not once, not by a defensive aggregator, not by an operating competitor. Unified Patents has no proceeding and no litigation entries on its page for US-4891781-A; there is no evidence of Unified, RPX, AST, LOT, or OIN in the chain (consistent with the assignment report, which found the chain terminates at an operating security vendor via SafeNet → Gemalto → Thales). There is no repeat-petitioner pattern, because there is no petitioner at all. There is no patent-owner appeal pattern, because the owner never had a Board loss to appeal — and no CAFC appeal of any FWD exists. This is the profile of a defensive, internal-use, or never-monetized patent, which matches the prior sections' conclusion that the ownership chain is non-asserting and that the patent was never asserted in any located litigation.
Recommended next steps
- Do not build an IPR-based defense strategy around outcomes that do not exist. There is no FWD to link to, no canceled claim to quote, and no estoppel to invoke. If a demand letter cites this patent, the dispositive argument is expiry, not invalidity: US 4,891,781 expired 2007-03-04 (anticipated; Unified Patents: 2007-03-03), so pre-suit damages under 35 U.S.C. § 286 are time-barred and prospective relief is impossible.
- Confirm the negative directly at the source. Run the patent number through the USPTO PTAB E2E / PTAB End-to-End system and the USPTO Open Data Portal (ODP) trials API to reproduce the zero-count result, and pull the PatentCenter file wrapper for 4,891,781 to confirm (a) no reexamination certificate, (b) the prosecution history the prior-art section flagged as unretrieved, and (c) whether any terminal disclaimer or certificate of correction exists.
- PTAB E2E: https://ptab.uspto.gov/ (search Patent No. 4,891,781 under "Patent Number")
- PTAB decisions archive: https://www.uspto.gov/patents/ptab/decisions
- CourtListener (confirm no CAFC appeal): https://www.courtlistener.com/?q=%224%2C891%2C781%22
- Check the foreign family member for the only plausible adversarial challenge. EP 0281303 (Cylink; priority US 21,660) is the one family asset that could have drawn an EPO opposition. That is not a PTAB matter, but if diligence requires the complete adversarial history of this technology family, query the EPO Register and the EPO Opposition database for EP 0281303. I could not confirm one way or the other here.
- Treat "no PTAB activity" as consistent with — not proof of — non-assertion. The litigation section already reached a qualified negative on assertion. The PTAB record adds corroboration: well-asserted patents almost invariably attract IPRs; this one attracted none, over the entire ~14-year window (2012-09-16 to today) in which IPRs have existed while the patent remained citable in briefs. The two findings reinforce each other.
Constraint honored: no proceeding numbers have been invented, because there are none to report. Where I could not verify (reexamination, EP opposition), I have said so rather than filling the gap.
Generated 9/28/2026, 1:22:42 PM
Ownership chain (4)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2001-07-11 · Security Interest
Cylink CorporatonSilicon Valley Bank
securitization
? · recorded 2007-04-05 · Merger
Cylink CorporationSafeNet, Inc.
acquisition
? · recorded 2007-04-16 · Security Agreement
SafeNet, Inc.Deutsche Bank Trust Company Americas, as Collateral Agent
securitization
? · recorded 2007-04-19 · Security Agreement
SafeNet, Inc.Deutsche Bank Trust Company Americas, as Collateral Agent
securitization
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll research the assignment/ownership record for US 4,891,781, building on the prior sections. Let me search the assignment databases and related sources.
Let me dig deeper into the specific assignment records, reel/frame numbers, and the correspondent details.
Let me try to pin down the specific reel/frame numbers and correspondent details for the recorded assignments.
Assignment / Ownership Analysis — U.S. Patent No. 4,891,781
"Modulo arithmetic processor chip" | Inventor: Jimmy K. Omura | Original assignee: Cylink Corp.
Priority 1987-03-04 · Filed 1988-12-22 · Granted 1990-01-02 · Expired 2007-03-04 · 44 claims
Scope note and building on prior sections. This section assumes the two earlier sections (patent summary and litigation/PTAB findings) and does not repeat them. One fact from those sections drives everything below: no litigation and no PTAB proceeding has ever involved this patent, so there is no "pre-litigation transfer" event to anchor. I also flag upfront a material data limitation: I could not retrieve the reel/frame numbers or the correspondent-of-record fields from USPTO Assignment Center in this session (the tool hit its search ceiling before the Assignment Center record could be parsed). The conveyance types and recording dates below are taken from the Google Patents legal-events block, which does not expose reel/frame or correspondent. Those two fields — the exact fields your task says are "the most useful tell" — are therefore unverified here and are called out as such rather than guessed.
Inventors
| Inventor | Address of record | Employer at filing (determinable) |
|---|---|---|
| Jimmy K. Omura (sole named inventor) | Cupertino, CA | Cylink Corporation — Omura co-founded Cylink in 1983 with Elwyn Berlekamp (per startup-intros company profile material and the Cylink corporate history). The '781 application was a Cylink filing; the Original Assignee designation confirms it was assigned to Cylink ab initio. |
Notes and patterns:
- Single-inventor patent. There is no co-inventor, so no "all inventors departed within 12 months" pattern can exist here. There is no evidence Omura left Cylink at or near filing — he is the named inventor on the same-assignee continuation US 5,210,710 (filed 1990-10-17, ~2.5 years after this filing), which is itself evidence of continued association with Cylink.
- Inventor overlaps with the prior art of record. This is worth flagging because it colors the prosecution history (analyzed in the prior-art section) and the "who owned this technology" question:
- Omura is a named inventor on two of the 22 cited references: US 4,587,627 ("Computational method and apparatus for finite field arithmetic," Massey & Omura, Omnet Associates, issued 1986-05-06) and US 4,567,600 ("Method and apparatus for maintaining the privacy of digital messages…," Massey & Omura, issued 1986-01-28).
- Co-founder Elwyn Berlekamp is the named inventor on cited reference US 4,162,480 ("Galois field computer," Cyclotomics, Inc.). Cyclotomics was Berlekamp's own company.
- So the cited prior art includes work by the inventor and by his Cylink co-founder. The '781 patent was filed after those references issued, in the same technical space.
Original assignee
Cylink Corporation (address of record on the issued patent and later assignment documents: Sunnyvale/Santa Clara, CA; Google Patents prints the assignee as "Cylink Corp").
| Attribute | Finding |
|---|---|
| Primary line of business | Network/data-security products — public-key-based encryption hardware and software for WANs, ATM, Frame Relay, and link encryption, sold to U.S. Government/financial/enterprise customers. Founded 1983; one of the earliest companies focused exclusively on public-key security. |
| Did it ship a product embodying the claims? | Partly determinable — Cylink was a genuine operating company that shipped cryptographic hardware. It sold encryption appliances and "Link Encryptor" hardware (and, per SafeNet's 2003 10-K, "encryptor products" acquired through the Cylink deal). The '781 patent claims a chip architecture for mod-p add/multiply/exponentiation; whether a Cylink chip specifically implemented the '781 claim architecture is not confirmed by any source I could reach. Cylink's products certainly used public-key modular arithmetic, and the follow-on same-assignee patent US 5,210,710 shows continued investment in this chip family. I would characterize this as an operating-company patent in a shipped-product line, not a paper patent. |
| Financial trajectory | IPO on NASDAQ 1995; peak revenue ~$49.3M in 1997; ~400 employees, down to ~175 worldwide by 2002; net losses of $23.5M (2002), $20.1M (2001), $35.4M (2000) per the Cylink S-3/A. |
| Current status | Acquired, not dissolved-by-bankruptcy. Acquisition by SafeNet, Inc. announced Oct 2002 (deal ~$29M, ~0.9× LTM revenue) and closed February 2003; Cylink's operations were folded into SafeNet's Enterprise Security Division. The patent was later formally recorded as transferred by merger (see timeline). |
Assignment timeline
Important: the assignment record for this patent is not empty — there are four recorded post-issuance events shown in the Google Patents legal-events block (one security interest, one merger, two liens). What is missing from my retrieval is the reel/frame and correspondent for each, which are the fields Assignment Center exposes but Google Patents does not. I am not fabricating those fields.
| # | Date (as recorded) | Reel/Frame | Conveyance | Assignor → Assignee | Correspondent | Context |
|---|---|---|---|---|---|---|
| 0 | On filing/issue (date not retrieved) | not retrieved | Assignment (original) | Jimmy K. Omura → Cylink Corporation | not retrieved | Original inventor-to-company assignment (implied by "Original Assignee: Cylink Corp" designation). |
| 1 | 2001-07-11 (recording date; execution date not retrieved) | not retrieved | Security Interest — printed as "SECURITY INTEREST (SEE DOCUMENT FOR DETAILS)" | Cylink Corporaton → Silicon Valley Bank | not retrieved | Securitization — SVB took a security interest in Cylink's patent collateral. (Note the assignor name is printed in the source as "CYLINK CORPORATON," a literal misspelling; not corrected.) |
| 2 | 2007-04-05 (recording date) | not retrieved | Merger — printed as "MERGER (SEE DOCUMENT FOR DETAILS)" | Cylink Corporation → SafeNet, Inc. | not retrieved | Corporate acquisition / internal reorg. Cylink was acquired by SafeNet (deal closed Feb 2003); the merger conveyance was recorded in April 2007, alongside the SafeNet financing cluster. |
| 3 | 2007-04-16 (recording date) | not retrieved | Security Agreement — FIRST LIEN PATENT SECURITY AGREEMENT | SafeNet, Inc. → Deutsche Bank Trust Company Americas, as Collateral Agent | not retrieved | Securitization. First-lien collateral under the SafeNet take-private financing (the First Lien Credit Agreement dated as of April 12, 2007, among a "Stealth Acquisition" entity and SafeNet). The SafeNet first-lien Security Agreement schedules list the '781 patent as "MODULO ARITHMETIC PROCESSOR CHIP — 4891781" among the collateral, corroborating this entry. |
| 4 | 2007-04-19 (recording date) | not retrieved | Security Agreement — SECOND LIEN PATENT SECURITY AGREEMENT | SafeNet, Inc. → Deutsche Bank Trust Company Americas, as Collateral Agent | not retrieved | Securitization. Second-lien collateral in the same take-private financing. |
Downstream corporate succession (reported as current assignee, but with no assignment event I could retrieve): Google Patents lists the Current Assignee as "Thales DIS CPL USA Inc", while itself disclaiming accuracy ("The listed assignees may be inaccurate"). The reported chain is:
SafeNet → Gemalto (Gemalto acquired SafeNet in 2015) → Thales (Thales acquired Gemalto in 2019; Thales DIS CPL USA is the U.S. identity in that group).
I could not retrieve a recorded USPTO assignment documenting the SafeNet→Gemalto→Thales steps on this patent's abstract of title. It is possible (a) those transfers were recorded in bulk under a different reel/frame or (b) Google's "current assignee" is a corporate-family inference (it maps parent companies) rather than a recorded assignment. Flagged as unresolved.
Related foreign-family ownership datapoint: the Japanese family member surfaced in a third-party search report as JP 63-282777 A, published 1988-11-18, listed with applicants "Ricoh Co., Ltd., Cylink Corp." (alongside EP 0281303 A and US 4,891,781 A). Read literally, this suggests the Japanese counterpart was filed with Ricoh and Cylink as co-applicants — a foreign ownership divergence from the U.S. record. I flag it rather than resolve it; the search-report grouping may also simply be listing the family, so treat the co-applicant reading as unconfirmed.
Timeline diagram
timeline
title Ownership of US 4891781
1983 : Cylink founded by Berlekamp and Omura
1987 : Parent application filed
1988 : Continuation application filed
1990 : Patent issued to Cylink Corp
2001 : Security interest granted to Silicon Valley Bank
2003 : Cylink acquired by SafeNet
2007 : Merger of Cylink into SafeNet recorded
: First and second liens to Deutsche Bank
2015 : SafeNet acquired by Gemalto
2019 : Gemalto acquired by Thales
NPE / troll-pattern signals
| # | Signal | Call | Basis (reel/frame where available) |
|---|---|---|---|
| 1 | Shell-entity transfer | Not present | Every entity in the recorded chain is an operating company, a bank, or a corporate successor: Cylink (operating), SafeNet (operating), Deutsche Bank (lender), Thales/Gemalto (operating). No "IP / Patents / Licensing / Holdings / Ventures" owner appears. No single-purpose LLC. Reel/frame not retrieved, but the entity names alone exclude a named shell. |
| 2 | Known asserter in the chain | Not present | None of Cylink, SafeNet, Deutsche Bank, Gemalto, or Thales appears on the named NPE lists (Acacia, Marathon, IV, IPNav, Wi-LAN, Conversant/Mosaid, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Spangenberg entities, etc.). Cylink did litigate as a plaintiff in the 1990s (e.g. the Cylink v. Schnorr declaratory-judgment action, D.D.C. 95-2121) but that concerns a different patent (US 4,995,082) and is operating-company activity, not NPE activity. |
| 3 | Repeat correspondent across the chain | Unclear / unverified | The correspondent field could not be retrieved for any link, so I cannot test recurrence. This is the single most important unmet diagnostic in this report. No correspondent name is asserted. |
| 4 | Cascading transfers | Not present as an NPE pattern; a securitization cluster is present | Three recordings land within 14 days: 2007-04-05 (merger), 2007-04-16 (first lien), 2007-04-19 (second lien). This clustering reflects the SafeNet take-private financing (Vector Capital / "Stealth Acquisition," First Lien Credit Agreement dated 2007-04-12), not chained shell LLCs. The assignees in the cluster are the operating company and a single collateral agent — not linked LLCs sharing a correspondent. |
| 5 | Pre-litigation transfer | Not present | No litigation exists on this patent (per the earlier sections), so there is no suit to be "within 6 months" of. The most recent transfer event (2007 liens) long predates any conceivable assertion window and is a financing, not an assertion set-up. |
| 6 | Bankruptcy fire-sale | Not present | Cylink was acquired by SafeNet (closed Feb 2003), not liquidated in Chapter 7/11. SafeNet was taken private by Vector Capital in 2007 — a leveraged buyout, not a bankruptcy estate sale. No § 363 sale, no trustee, no proceeds distribution appears in the record. |
| 7 | Privateering | Not present / unclear | No operating company here transferred to an NPE to assert against competitors. The Cylink→SafeNet step is a strategic acquisition in the same industry; SafeNet→Gemalto→Thales is corporate succession. No SEC filing or reporting surfaced describing a transfer-to-asserter arrangement. |
| 8 | Defensive aggregator (anti-NPE) | Not present | The chain does not terminate at RPX, AST, LOT Network, Unified Patents, or OIN. The chain terminates in an operating corporate group (Thales) and, substantively, in expiration. |
Signal tally: 0 of 8 NPE signals present. One securitization cluster (signal 4) is present but is a lender-collateral pattern, not an NPE pattern. Two fields (reel/frame, correspondent) that would harden the negative are unverified.
Verdict
Defensive / non-asserting.
The recorded chain is a straight operating-company ownership line with a financing overlay — Cylink Corp. (original assignee, operating) → SafeNet, Inc. (by merger, recorded 2007-04-05) → Deutsche Bank Trust Company Americas as collateral agent (first lien 2007-04-16; second lien 2007-04-19) → reported corporate successor Thales DIS CPL USA Inc. — with no licensing-only shell, no known asserter, and no assertion event on this patent. I am choosing "Defensive / non-asserting" on substance (never asserted; owned throughout by operating companies; the asset has been fully neutralized by its 2007-03-04 expiration), and I explicitly note the template caveat: this chain does not terminate at a named defensive aggregator (RPX/AST/LOT/Unified/OIN), so the label fits the "non-asserting" half of the definition but not the "terminates at an aggregator" parenthetical. If strict literal template matching is required, the formal fallback is Insufficient data, because the two fields most probative of an NPE pattern — reel/frame and correspondent of record — could not be retrieved for any link.
An important cross-reference note for the reader: the earlier litigation section reached "no litigation" and the PTAB section reached "zero AIA trials." This assignment analysis is consistent with both — a chain of operating companies that never sold the patent to an NPE, and a patent that expired in 2007 with no post-grant challenge, is exactly the profile of an unasserted, expired corporate asset, not a troll vehicle. The one thing that could change this picture (a repeat-player correspondent on those four 2007 recordings) is precisely the field I could not verify.
Verification links and next steps to close the gap
- USPTO Assignment Center (search by "4891781"): https://assignmentcenter.uspto.gov/ and the legacy interface https://assignment.uspto.gov/patent/index.html
- Retrieve, for each of the four recordings, the reel/frame + execution date + correspondent — pull the "Assignment Abstract of Title" for application 07/289,124 and check whether a single attorney/firm filed the 2007-04-05 merger and the 2007-04-16/19 liens (they likely share corporate/financing counsel — expected in a take-private, and not by itself an NPE signal).
- Confirm the SafeNet→Gemalto→Thales recordation. If no assignment appears on this patent's abstract of title, verify via Thales/Gemalto's USPTO bulk recordings whether the transfer was recorded; Google's "current assignee" may be a corporate-family inference.
- Resolve the JP 63-282777 co-applicant question (Ricoh / Cylink) if foreign ownership is in scope.
- Cross-check Unified Patents and RPX directories for any of the five named entities as asserters — none appeared in my searches, consistent with the non-asserting verdict.
Constraint compliance: no assignment was fabricated. The four recorded events are reported as surfaced by Google Patents legal events; reel/frame and correspondent fields are reported as not retrieved rather than invented, and every entity in the chain is named from a source rather than inferred from naming alone.
Generated 9/28/2026, 1:23:42 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll research the cited prior art for US 4,891,781. Let me gather authoritative details on the key references.
Prior Art Analysis — U.S. Patent No. 4,891,781
Patent: "Modulo arithmetic processor chip" · Inventor: Jimmy K. Omura · Original assignee: Cylink Corp.
Priority: 1987-03-04 · Filed: 1988-12-22 · Granted: 1990-01-02 · Status: Expired (2007)
Source of record: https://patents.google.com/patent/US4891781/en (full text, claims, and citation tables supplied above)
Scope note (strict, literal reading)
I analyzed exactly US 4,891,781. I did not substitute any similarly numbered patent. Note two near-collisions the search results produce and that I am expressly not using:
- US 5,210,710 — a different Omura/Cylink patent, same title ("Modulo arithmetic processor chip"), which appears in the '781 "Cited By" table. It is a separate asset and is treated below only as a double-patenting/§ 103 candidate, never as a § 102 reference to itself.
- US 7,916,781 — Caltech's patent (asserted in Caltech v. Apple/Broadcom). Unrelated number.
- The search hits for "4891781" that return a Minnesota PUC receptor ID / a "Prime Curios" page / a Soviet thermos-siphon document are false positives — not this patent.
The 22 U.S. patent citations and the non-patent citations below are taken verbatim from the '781 patent's own citation tables (the authoritative text in the user message), supplemented by Google Patents / EPO / FreePatentsOnline records for the descriptions. Dates are the priority and publication dates printed in the citation table.
1. Framework for the § 102 question
Every one of the 22 cited patents published more than one year before the '781 priority date (1987-03-04) — the youngest, US 4,697,248, issued 1987-09-29 after the priority date, so it is § 102(a)/(e) art at best; the rest are § 102(b) art. That is not, however, the hard part. The hard part is element coverage.
The '781 independent claims require a specific combination of:
- an integer-modular (GF(p) / "ring of integers modulo p") datapath, not a characteristic-2 field;
- a feedback number F = 2ⁿ − p (the "two's complement of p," i.e. 2ⁿ mod p) held in a feedback register;
- base/carry (A₁/A₂, B₁/B₂, C₁/C₂) register pairs and a time-shared full-adder array that shifts-and-adds; and
- reduction of the accumulator modulo p, with overflow index I mapped to F₁, F₂, F₃, F₄.
No cited reference discloses all of these. Accordingly, the honest § 102 conclusion is that none of the 22 cited patents anticipates any independent claim of the '781 patent as a whole, and most are § 103 (obviousness) references, not § 102 references. I flag the few places where a reference comes closest, and I identify the claims each reference is most relevant to, which is what a § 102/§ 103 mapping actually turns on.
2. The cited prior art, reference by reference
Group A — Public-key cryptographic method patents (motivational art; § 103 only)
| # | Full citation | Priority / Pub. | Brief description | § 102 relevance to '781 claims |
|---|---|---|---|---|
| 1 | US 4,200,770 — "Cryptographic apparatus and method," M. Hellman, W. Diffie, R. Merkle (Stanford Univ.) | 1977-09-06 / 1980-04-29 | The Diffie–Hellman key-exchange patent. Claims the method of generating a secure cipher key by exchanging transformed secret signals. | No anticipation of any claim. Purely a method of key exchange; discloses no adder/multiplier hardware, no register architecture, no feedback number. § 103-only: supplies the motivation to build GF(p) exponentiation hardware (secrecy set / claims 1, 4). |
| 2 | US 4,218,582 — "Public key cryptographic apparatus and method," M. Hellman, R. Merkle (Stanford) | 1977-10-06 / 1980-08-19 | Hellman–Merkle public-key (knapsack-style) cryptosystem. | No anticipation. No arithmetic datapath. § 103 background only (claims 1, 4). |
| 3 | US 4,405,829 — "Cryptographic communications system and method," R. Rivest, A. Shamir, L. Adleman (MIT) | 1977-12-14 / 1983-09-20 | The RSA patent. Claims public-key encryption/decryption using modular exponentiation of integers with a composite modulus. | No anticipation. RSA is a method; it explicitly contemplates computation over the ring of integers modulo a composite, but discloses no hardware. This is the single most important § 103 reference for the claim-4 "exponentiation … in the ring of integers modulo an integer" limitation and for the specification's stated RSA application. |
| 4 | US 4,424,414 — "Exponentiation cryptographic apparatus and method," M. Hellman, S. Pohlig (Stanford) | 1978-05-01 / 1984-01-03 | Hellman–Pohlig exponentiation-based cryptographic system; claims the exponentiation/trapdoor relation. | No anticipation. Method-level; supplies the exponentiation algorithm (§103, claim 4). |
Why Group A matters at all: the '781 specification itself adopts this frame ("cryptographic systems transmitting a computationally secure cryptogram… described in … U.S. Pat. No. 4,200,770 to Hellman et al., U.S. Pat. No. 4,405,829 to Revest [Rivest] et al., U.S. Pat. No. 4,218,582…, and U.S. Pat. No. 4,424,414…"), and states that "none of these patents teach how to build a processor chip… for implementing their broad inventive concepts." That is the applicant's own admission that the novelty sits in the hardware realization. It makes these four patents § 103 backdrop, not § 102 anticipators.
Group B — GF(2ᵐ) finite-field arithmetic hardware (the closest art; § 102/§ 103 backbone)
| # | Full citation | Priority / Pub. | Brief description | § 102 relevance |
|---|---|---|---|---|
| 5 | US 4,037,093 — "Matrix multiplier in GF(2ᵐ)," G. E. Gregg et al. (Honeywell Information Systems) | 1975-12-29 / 1977-07-19 | Circuit that multiplies two arbitrary GF(2ᵐ) elements: the multiplicand is passed serially through m−1 modulo multipliers, each partial product gated by a bit of the multiplier and summed in XOR networks. Sources: https://patents.google.com/patent/[US4037093A](/patent/US4037093A)/en · https://patentimages.storage.googleapis.com/a2/9e/7d/0045ac1c931585/US4037093.pdf | Closest structural analogue in the cited set, but not anticipation. Discloses serial shift-and-gate multiply (claim 1/16 "shift and add" concept) but reduces modulo an irreducible polynomial g(x), not by adding the two's-complement feedback F = 2ⁿ−p. No base/carry register pairs, no overflow-index I→F₁–F₄. Best mapped to claims 1, 16, 19, 29 as § 103 art. |
| 6 | US 4,162,480 — "Galois field computer," E. R. Berlekamp (Cyclotomics, Inc.) | 1977-01-28 / 1979-07-24 | The GF1 stored-program computer: three concurrent substructures (control unit, address generator, arithmetic unit), a Galois-field arithmetic unit producing finite-field products/sums over GF(2⁵) from three registers X, Y, Z with a hardwired multiplier/parity-XOR network, and a Galois-field address generator over GF(2⁷). Source: https://patents.google.com/patent/US4162480 | Strongest "compute in a finite field on a chip" teaching, but (i) characteristic-2 field, (ii) XOR/parity-tree multiplier, not a base/carry shift-add accumulator, (iii) no F = 2ⁿ−p feedback. § 103 art relevant to the register + full-adder + control-logic architecture of claims 1, 2, 11, 12, 29. |
| 7 | US 4,251,875 — "Sequential Galois multiplication in GF(2ⁿ) with GF(2ᵐ) Galois multiplication gates," Sperry Corp. | 1979-02-12 / 1981-02-17 | Sequential (bit-serial) GF(2ⁿ) multiplier built from GF(2ᵐ) gate units. | No anticipation. Bit-serial GF(2ⁿ) multiply = conceptual cousin of the '781 shift-add loop, but field/modulus and feedback mechanism differ. § 103 for the "shifting left and adding" limitation (claims 1, 15, 16). |
| 8 | US 4,538,240 — "Method and apparatus for performing hashing operations using Galois field multiplication," IBM | 1982-12-30 / 1985-08-27 | Applies GF multiplication to message hashing/authentication. | No anticipation of the processor claims. Relevant only to the specification's closing statement that the invention covers "message authentication" applications. § 103 background. |
| 9 | US 4,574,361 — "Apparatus for dividing the elements of a Galois field," Tokyo Shibaura Denki K.K. (Toshiba) | 1982-06-15 / 1986-03-04 | Hardware for GF division/inversion. | No anticipation. Peripheral to add/multiply/exponentiate claims; § 103 context only. |
| 10 | US 4,697,248 — "Arithmetic circuit for obtaining the vector product of two vectors," Sony Corp. | 1983-12-30 / 1987-09-29 | Vector (dot-product) arithmetic circuit. | Timing problem: issued after the '781 priority date, so it is not § 102(b) art and, on these facts, not § 102(a)/(e) art to the '781 inventive entity either. Listed here for completeness; no anticipation. |
The Group-B takeaway: the cited set is dominated by GF(2ᵐ) hardware (Berlekamp, Gregg, Sperry, Toshiba, IBM). These share the general idea of a dedicated finite-field datapath but operate in a fundamentally different algebraic structure (polynomial arithmetic, XOR, no carries) and use a different reduction mechanism (mod g(x)) from the '781's integer-modular F = 2ⁿ − p feedback. That structural divergence is what defeats § 102 and confines these to § 103.
Group C — Same-inventor / common-entity references (highest practical relevance)
| # | Full citation | Priority / Pub. | Brief description | § 102 / § 103 relevance |
|---|---|---|---|---|
| 11 | US 4,587,627 — "Computational method and apparatus for finite field arithmetic," J. L. Massey & J. K. Omura (Omnet Associates) | 1981-11-30 / 1986-05-06 | Normal-basis GF(2ᵐ) arithmetic: multiplication via a single uniform logic function applied to rotated vectors, squaring by vector rotation, addition by component-wise XOR; two m-bit circulating shift registers feed shared logic to compute each product component. Sources: https://patents.google.com/patent/[US4587627A](/patent/US4587627A)/en · EP 0080528. | THE most relevant reference in the set. Same inventor (Omura), same problem space (fast finite-field multiply/squaring for cryptography), and it discloses shift registers + reused logic + squaring/multiply combine — the architectural DNA the '781 spec calls "the heart of the processor chip." It does not, however, disclose GF(p) integer modular arithmetic, the F = 2ⁿ − p feedback number, base/carry registers, or the overflow-index reduction. § 102: no full anticipation of any independent claim. § 103: directly attacks claims 1, 2, 4, 11, 29, 37/38 (register-and-shared-adder architecture; squaring-and-multiplying exponentiation). § 102(e)/§ 103(c): also the key double-patenting / same-entity issue, since it is Omura's own earlier patent. |
| 12 | US 4,567,600 — "Method and apparatus for maintaining the privacy of digital messages conveyed by public transmission," J. L. Massey & J. K. Omura (Omnet Associates) | 1982-02-02 / 1986-01-28 | Three-pass public-key privacy system implemented with GF(2ᵐ) multipliers and exponentiators; discloses block-logic diagrams of GF(2⁷) multipliers that sequentially (Fig. 1a) or simultaneously (Fig. 1b) compute each product component, and an exponentiation device (Fig. 2). Sources: https://patents.google.com/patent/[US4567600A](/patent/US4567600A)/en · EP 0085130. | Second most relevant. Same inventor; discloses exponentiation built from a series of multiplications — i.e., the very "series of multiplications modulo p" structure recited in claim 4. Anticipates the concept, not the GF(p) chip. § 102: no. § 103: relevant to claim 4 and the exponentiation method claims 39, 40, 43. Same-entity / double-patenting flag as with '627. |
Data point: the EPO search report for US 4,587,627 lists US 4,037,093 (Gregg) and US 4,162,480 (Berlekamp) as cited art — confirming that the Omura/Massey line itself sits on top of the Gregg/Berlekamp GF(2ᵐ) hardware, which is why the '781 examiner pulled the same references forward.
Group D — Block-cipher / cryptographic-hardware patents (peripheral; § 103 context only)
US 3,522,374 (Ciphering unit, Int. Standard Electric, 1966-06-17/1970-07-28); US 3,657,476 (Cryptography, H. Aiken, 1970-01-23/1972-04-18); US 3,781,472 (Digital data ciphering technique, Datotek, 1971-04-15/1973-12-25); US 3,796,830 (Recirculating block cipher, IBM, 1971-11-02/1974-03-12); US 3,798,359 (Block cipher, IBM, 1971-06-30/1974-03-19); US 3,868,631 (Digital cryptographic system, Datotek, 1972-10-20/1975-02-25); US 3,876,832 (Digital cryptographic system, B. O. Morgan, 1972-10-20/1975-04-08); US 3,958,081 (Block cipher for data security, IBM, 1975-02-24/1976-05-18); US 3,962,539 (Product block cipher, IBM, 1975-02-24/1976-06-08); US 3,979,558 (Signaling system, Bell Telephone Labs, 1944-06-30/1976-09-07).
Description: classical symmetric block-cipher / ciphering-unit hardware (Feistel-style substitution–permutation engines, key generators, recirculating block ciphers). These are the patents the '781 specification dismisses as "the conventional cryptographic solution … requires the prior possession of a common secret key."
§ 102 relevance: none. They disclose neither finite-field modular arithmetic, nor shift-and-add multiplier datapaths, nor feedback-number reduction. They are, at most, general background establishing that cryptographic engines were known to be built as dedicated hardware — which is § 103 context, not anticipation.
3. Non-patent citations (printed publications; § 102(b) art)
The '781 patent cites (as printed) — among others:
- Abbruscato, C. R., "Data Encryption Equipment," IEEE Communications Magazine, vol. 22, No. 9, Sep. 1984.
- Barney, Clifford, "Cypher Chip Makes Key Distribution a Snap," Electronics, Aug. 7, 1986. — contemporaneous press coverage of a public-key cipher chip; directly bears on the state of the hardware art at the priority date (§ 103).
- Barrett, Paul, "Implementing the Rivest Shamir and Adleman Public Key Encryption Algorithm on a Standard Digital Signal Processor," Computer Security Ltd., Aug. 1986. — the canonical RSA-on-a-DSP implementation paper; the most relevant § 103 NPL for "modular exponentiation in hardware."
- Beth, T., Cook, B. M., Gollmann, D., "Architectures for Exponentiation in GF(…)" — survey of finite-field exponentiation architectures; § 103 for claim 4 / exponentiation claims.
- Plus the standard references Diffie & Hellman, "New Directions in Cryptography," IEEE Trans. Info. Theory, Nov. 1976 and Rivest, Shamir & Adleman (1978) cited in the family members (EP 0281303 / EP 0085130 / EP 0080528).
§ 102 effect: these NPL items describe algorithms and software implementations, not the claimed register/adder chip. They cannot anticipate an apparatus claim, but Barrett and Beth et al. are strong § 103 references for the "implement GF(p) exponentiation in dedicated silicon" motivation.
4. Ranked conclusion — most relevant prior art
| Rank | Reference | Why it is the most relevant | Claims it bears on |
|---|---|---|---|
| 1 | US 4,587,627 (Massey & Omura, Omnet) | Same inventor; shared-logic GF(2ᵐ) multiply/squaring hardware with circulating shift registers — the architectural core the '781 elaborates | 1, 2, 4, 11, 29, 37, 38 (+ double-patenting) |
| 2 | US 4,567,600 (Massey & Omura, Omnet) | Same inventor; discloses GF(2ᵐ) multipliers and an exponentiation device built from a series of multiplications | 4, 39, 40, 43 |
| 3 | US 4,162,480 (Berlekamp / Cyclotomics) | Dedicated finite-field computer chip with register file, hardwired multiplier, control logic | 1, 2, 11, 12, 29 |
| 4 | US 4,037,093 (Gregg / Honeywell) | Serial shift-and-gate GF(2ᵐ) multiplier — closest to the "shift and add" limitation | 1, 16, 19, 29 |
| 5 | US 4,405,829 (Rivest/Shamir/Adleman, MIT) | Supplies the RSA modular-exponentiation purpose the chip is built to accelerate | 4 (and spec's RSA application) |
| 6 | US 4,200,770 / 4,218,582 / 4,424,414 (Hellman et al.) | Key-exchange / exponentiation method patents; motivational § 103 art | 1, 4 |
| 7 | US 4,251,875; 4,538,240; 4,574,361; 4,697,248 | Other GF(2ⁿ)/GF(2ᵐ) hardware | peripheral |
| 8 | US 3,522,374 … US 3,979,558 (10 block-cipher patents) | Conventional symmetric cipher hardware | none — background only |
Bottom line: the single most relevant prior art for US 4,891,781 is US 4,587,627 (Massey & Omura), followed closely by US 4,567,600 (Massey & Omura) — both same-inventor GF(2ᵐ) arithmetic-hardware patents — then the Berlekamp GF1 computer (US 4,162,480) and Gregg's GF(2ᵐ) matrix multiplier (US 4,037,093). The RSA patent (US 4,405,829) and the Hellman patents supply the purpose (§ 103), and the block-cipher patents supply only background.
No cited reference discloses the full combination required by any '781 independent claim — specifically the integer (GF(p)) datapath with a feedback number F = 2ⁿ − p, base/carry register pairs, a time-shared full-adder, and overflow-index I → {F₁,F₂,F₃,F₄} reduction. On the cited art alone, the case against the independent claims is an obviousness case, not an anticipation case.
5. Caveats and flags (read literally; no auto-correction)
- Same-inventor / § 103(c) and double-patenting. US 4,587,627 and US 4,567,600 list J. K. Omura as a co-inventor. A reference naming the same inventive entity is not "by another" under § 102(a)/(e), and their status as § 102(b) art depends on the controlling date (grant 1986-05-06 / 1986-01-28 vs. priority 1987-03-04 vs. filing 1988-12-22). I flag this rather than resolve it, because it turns on the § 120 benefit chain (parent Ser. No. 07/021,066, filed 1987-03-04; Ser. No. 07/142,328, filed 1988-01-04). The sibling US 5,210,710 is an obviousness-type double-patenting candidate to examine separately.
- US 4,697,248 (Sony) post-dates the '781 priority date (1987-09-29 vs. 1987-03-04) and therefore is not § 102(b) art; treat as non-prior-art unless a § 102(e) date is established.
- Anticipation vs. obviousness. Where I say "bears on claim N," I mean § 103 relevance unless the reference discloses every element — which, on the records reviewed, none does for an independent claim.
- Not reviewed: the actual file wrapper / examiner's citations and rejections for US 4,891,781 (Google Patents shows the citation list but not the office actions). As flagged in the previously generated sections, the prosecution history has not been retrieved; any Grounds of Rejection the examiner actually made would be the definitive statement of which references were treated as § 102 vs. § 103 art. Confirm via PatentCenter.
- Dates are as printed in the '781 citation tables; where Google/Unified differ by one day (as in the '781 filing/priority dates), I have used the patent's own printed table for the citations and flagged that the '781's own dates carry a 1-day indexing discrepancy.
Sources: Google Patents US4891781 (citation tables, claims, specification); https://patents.google.com/patent/US4587627A/en ; https://patents.google.com/patent/US4567600A/en ; https://patents.google.com/patent/US4037093A/en ; https://patents.google.com/patent/US4162480 ; EP 0080528 / EP 0085130 (EPO); FreePatentsOnline US4587627.
Generated 9/28/2026, 1:23:31 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll ground a few specifics on the key references before building the § 103 combinations, since the strength of an obviousness case turns on exactly what each reference discloses and what the art already knew.
Let me pin down the non-patent literature cited on the face of the patent and the sibling Cylink/Omura patent, since those matter for both the motivation-to-combine and double-patenting strands.
Obviousness Analysis — U.S. Patent No. 4,891,781 under 35 U.S.C. § 103
Patent: "Modulo arithmetic processor chip" · Inventor: Jimmy K. Omura · Assignee: Cylink Corp. (orig.)
Priority: 1987-03-04 · Filed: 1988-12-22 · Granted: 1990-01-02 · Expired: 2007-03-04 · 44 claims
Governing law: pre-AIA § 103 (priority well before 2013-03-16). The KSR flexible-rationale framework nonetheless applies to any obviousness determination made today.
Builds on, does not repeat, the Prior Art section. That section established the element-coverage conclusion I adopt here as the premise: no single cited reference discloses the full combination of any independent claim, so this is a § 103 case, not a § 102 case. This section supplies the combinations and the motivations to combine.
Metadata contradiction flagged: the task header states "Current Date: April 26, 2026," whereas the earlier sections and the patent fetch are dated 2026-09-28. Immaterial to the analysis; reported as printed rather than harmonized.
1. The § 103 framework applied
Under Graham v. John Deere, 383 U.S. 1 (1966), and KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007), the inquiry is: (1) scope and content of the prior art; (2) differences between the prior art and the claims; (3) level of ordinary skill; (4) secondary considerations. KSR supplies the rationales that may supply the "motivation": known-method combination yielding predictable results; simple substitution of a known element; use of a known technique to improve a similar device in the same way; application of a known technique to a known device ready for improvement; "obvious to try"; and design incentives/market forces. The Federal Circuit's pre-KSR strict TSM requirement no longer controls.
Exhaustion of the § 102 question (adopted from the Prior Art section): the 22 on-face cited patents are § 102(b) art except US 4,697,248 (issued 1987-09-29, after the 1987-03-04 priority — § 102(a)/(e) at best). The prior-art section found the cited set to be motivational (Hellman/RSA method patents) or structurally adjacent but algebraically different (GF(2ᵐ) hardware). That asymmetry — same problem, different algebraic structure — is the classic § 103 setup.
2. Level of ordinary skill in the art (PHOSITA), as of March 1987
A person holding an M.S. (or Ph.D.) in electrical engineering or computer science, or a B.S. with 3–5 years' experience, in digital logic design for cryptographic and error-control arithmetic, who is:
- familiar with bit-serial "shift-and-add" multipliers (standard since at least the 1950s–60s) and with carry-save / redundant-carry accumulator techniques for suppressing carry propagation;
- familiar with finite-field arithmetic hardware — GF(2ᵐ) multipliers of the Massey–Omura, Berlekamp, and Gregg types (all in the cited art);
- aware of the public-key arithmetic problem (Diffie–Hellman/RSA modular exponentiation) and of the contemporaneous literature on implementing it in hardware — including Barrett (Aug. 1986), which is on the face of this very patent, and Beth, Cook & Gollmann, "Architectures for Exponentiation in GF(2ⁿ)," CRYPTO '86, LNCS 263, pp. 302–310 (also on the face);
- aware of Montgomery, "Modular multiplication without trial division," Math. Comp. 44(170):519–521 (April 1985) — the standard technique for eliminating costly division during modular reduction by precomputing a modulus-dependent constant. (Identified in this session; not an on-face citation.) [https://www.ams.org/journals/mcom/1985-44-170/S0025-5718-1985-0777282-X/]
That is a highly relevant, very narrow PHOSITA. That cuts both ways: it makes the idea of dedicated modular-arithmetic silicon obvious, but it also makes fine architectural distinctions more likely to be found obvious, because the artisan knows the whole toolbox.
3. The differences the combinations must bridge
From the Prior Art section, distilled to the four elements that actually separate the '781 claims from the art:
| # | Element in the '781 claims | What the art teaches | The gap |
|---|---|---|---|
| E1 | Integer-ring (GF(p)) datapath — full adders, carries | GF(2ᵐ) hardware: XOR/parity trees, no carries (Berlekamp '480; Gregg '093; Sperry '875; Massey–Omura '627/'600) | Algebraic-structure substitution |
| E2 | Feedback number F = 2ⁿ − p stored in a register and re-substituted for 2ⁿ | Nothing on-face teaches the register-and-substitute mechanism | The pivot |
| E3 | Base/carry (A₁/A₂ …) redundant register pairs + time-shared full adder | GF(2ᵐ) art uses single m-bit shift registers; the concept of redundant carry representation is classical | Carry-save applied to modular accumulation |
| E4 | Overflow index I → {F₁,F₂,F₃,F₄} table | Nothing on-face | Precomputed small multiples of a modulus |
Critically, the specification itself concedes E2/E3's status. It states that "a partial reduction at each stage can be performed using the relationship in Eq. (1)," and that "the above alternative representations for A, B, and C are not unique, [so] there is some freedom to choose representations that are easy to implement." Those are applicant admissions that the asserted contribution is an optimization choice within a known design space — strong § 103 ammunition.
4. Ground A — Claim 1 (and dependents 4, 5; method analogs)
Combination: US 4,587,627 (Massey & Omura) + US 4,162,480 (Berlekamp) + US 4,405,829 (Rivest/Shamir/Adleman) + Barrett, CRYPTO '86 (optionally + Montgomery 1985).
| Claim element | Where taught |
|---|---|
| X, Y, A₁/A₂, B₁/B₂, C₁/C₂ L-bit registers | '627 (two m-bit circulating shift registers + product register); '480 (X/Y/Z registers, R bus) |
| Transform X into two "alternate integers" (base/carry) | '627/'480 show multi-register partitioned representations; redundant-carry representation is classical |
| Control means → 1-bit control signal | '627 "logic means implementing a predetermined logical function"; '480 control unit/ESM control word |
| Full adder: control=1 → shift-left and add B to C; control=0 → shift-left only | '627 (rotated-vector multiply with gated accumulate); Gregg '093 (partial products gated by multiplier bits) |
| Feedback register storing F generated from p | The gap — supplied by motivation, not disclosure |
| Modulo means reducing C mod p | Montgomery 1985 (REDC); Barrett (longmod); Rivest '829 (states the modular-exponentiation problem) |
| Convert C₁/C₂ → L-bit Y | Routine" |
Motivation to combine (KSR rationales (A), (B), (C), (F), (G)):
- Same field of endeavor / same problem (MPEP 2141.01(a)). '627 and '600 (both Omura's own) exist to compute fast finite-field multiply/exponentiation for cryptography. '829/'770/'414 state the cryptographic purpose. The '781's stated object — "to provide a processor chip for performing an exponentiation operation in a rapid manner" — is that same purpose. The artisan looking to build RSA/Diffie–Hellman hardware is the same artisan who reads '627.
- Known technique improving a similar device in the same way. '627 already teaches the architectural recipe the '781 uses: two shift registers + shared, time-shared logic + shift-and-square to exponentiate. Porting that recipe from GF(2ᵐ) to GF(p) changes the reduction rule, not the recipe.
- Simple substitution + predictable result. Once the datapath is an integer accumulator, the reduction obligation is unavoidable: a n-bit accumulator that overflows produces a 2ⁿ term, and in GF(p) 2ⁿ ≡ F (mod p) where F = 2ⁿ − p. That identity is elementary and appears verbatim in the '781 specification (Eq. 1). Substituting the precomputed constant F for the 2ⁿ term is the same kind of move Montgomery and Barrett teach (precompute a modulus-derived constant; replace a division/reduction with an addition).
- Design incentive / market forces. Barrett's paper reports a full RSA implementation on a single DSP and reports times "below one second … on second generation parts." That is the express competitive pressure pushing a 1986–87 artisan toward dedicated modular silicon. KSR endorses exactly this: "design incentives and other market forces."
Against Ground A: the GF(2ᵐ) → GF(p) step is not purely mechanical; carry-less and carry-propagating arithmetic differ. This is the strongest available nonobviousness argument, and it is weakened by the fact that the cited set also contains integer-oriented art (RSA '829) and that the '781's own base/carry scheme is a standard carry-save trick.
5. Ground B — Claim 2 (and 3, 6, 7)
Claim 2 is an adder reciting X/Y/A₁/A₂/B₁/B₂/C₁/C₂ registers, control means, and a full adder that adds B into C on the control bit. It does not recite the feedback register, the feedback-number generator, or the modulo means (those arrive only via dependent claim 3).
Combination: US 4,162,480 (Berlekamp) in view of US 4,037,093 (Gregg).
This is the weakest claim in the patent. What it recites is, in substance, a carry-save accumulator with a partitioned base/carry register file and control logic — a textbook adder structure. Berlekamp supplies the "dedicated finite-field arithmetic unit with register file, hardwired arithmetic logic, and control" teaching; Gregg supplies the "serial shift-and-add with gated partial products" teaching. There is no asserted mechanism here that is not a generic adder. Claim 2 is closer to a § 102 problem (anticipation by a suitable carry-save accumulator reference) than to § 103, and at minimum falls to a two-reference combination with a trivial motivation (both references address the same end: fast finite-field arithmetic).
6. Ground C — Claims 8, 9, 10, 12, 13, 14, 36, 38, 44 (the "single-F" adder family)
Combination: Montgomery (1985) + US 4,162,480 (Berlekamp) + Rivest '829, optionally + Willoner & Chen, "An algorithm for modular exponentiation," Proc. 5th IEEE Symp. Comput. Arith., pp. 135–138 (1981) and Blakley, "A computer algorithm for calculating the product AB modulo M," IEEE Trans. Comput. C-32:497–500 (1983).
What the claims add over claim 2: F = 2ⁿ − p stored in feedback means; an overflow counter; fetching F into the B register and adding it back when overflow occurs; and mod-p reduction when C > p. That is the entire content of the difference.
Motivation:
- Montgomery 1985 teaches the genus of what these claims recite: represent residues so that "addition and subtraction algorithms are unchanged," precompute a modulus-derived constant (N′), and fold the modular reduction into the accumulation loop rather than performing a division. Claims 8/12/44's "add F back when the accumulator overflows, then reduce if C ≥ p" is a species of that genus — indeed Montgomery's REDC ends with exactly the final conditional subtraction ("if t ≥ N then return t − N else return t") that claims 8/12/44 recite as "reducing … when C is greater than p."
- Blakley 1983 and Willoner & Chen 1981 show that modular multiplication/exponentiation algorithms designed for hardware accumulation — including overflow handling — were squarely in the 1981–83 literature.
- The KSR "obvious to try" rationale applies with unusual force: there were a finite number of identified, predictable ways to reduce an overflowing accumulator mod p (do the division; use Barrett's reciprocal; use Montgomery's N-residue form; or substitute 2ⁿ ≡ F). Choosing one of them is not invention.
7. Ground D — Claims 11, 37 (the F₁–F₄ / overflow-index family)
Combination: Ground C references + US 4,037,093 (Gregg) (for the parallel two-step full-adder summation of base and carry bits), or simply Ground C + the specification's own admissions and the general knowledge of precomputed multiples of a modulus.
What claim 11 adds: F₂ = 2F₁ mod p, F₃ = 3F₁ mod p, F₄ = 4F₁ mod p; a two-stage full-adder summation (base+base, then carry); and selecting F₁–F₄ according to overflow index I ∈ {1,2,3,4}.
Motivation — this is the most easily dispatched "extra" element in the patent:
- The '781 specification gives the recipe away: "Recall that we have the feedback term … F₂ can be obtained from F₁ by a simple shift … F₃ and F₄, however, may require a mod p reduction. Only F₁, F₃, and F₄ are stored in registers. F₃ and F₄ are computed using the flow diagram of FIG. 9." The claim's F₁–F₄ are thus three doublings/additions of a value already known — arithmetic, not architecture.
- The problem is one of counting, not inventing. Where a first- and second-bit-position component can each produce overflow, the maximum overflow is 2 or 4; a lookup table indexed by a small counter is the definitional solution. A one-to-four-entry table adds no patentable weight under KSR's "familiar elements according to known methods."
- Precomputing small multiples of the modulus is pervasive in modular multiplication (Booth recoding of a multiplier/modulus; Montgomery's N′; Barrett's μ) — an artisan would reach for it reflexively.
8. Ground E — Claims 15, 16, 17, 18, 40 (multiplier; single-F)
Combination: US 4,587,627 (Massey & Omura) + Montgomery 1985 + Barrett, CRYPTO '86 + US 4,405,829.
Claim 15's asserted advance: (i) a first partial reduction — add F to B when B's MSB shifts left out of the register (keeping B to n bits); (ii) shift-and-add accumulation keyed to the LSB of A; (iii) an overflow counter I; (iv) a second partial reduction — at completion, multiply I by F and add the product back into C; (v) final mod-p reduction.
Motivation:
- The first/second partial reductions are the same single idea applied at the two places an overflow can arise. The specification admits it: "a partial reduction at each stage can be performed using the relationship in Eq. (1). This partial reduction allows representing all integers by n binary symbols." Keeping every register to n bits was the design constraint; a 2ⁿ term leaks out at exactly two points — when B is left-shifted, and in the accumulated overflow counter. An artisan who has decided (as the specification concedes) to do partial reduction at each stage would apply it in both places.
- Accumulating overflows in a counter and correcting once at the end is the standard double-precision accumulation pattern. The '781 spec even justifies it on effort grounds: "the counter value I is at most a 14-bit integer, and the shift and add cycles associated with adding IF₁ … is short compared to the original shift and add cycle."
- Barrett independently teaches precisely the "defer the reduction, then apply a scaled correction" structure (longmult → longmod, with the reduction result "always in the range 0 to 3M − 1 … at most two further subtractions").
- Claim 16 (identical minus the first partial reduction) and claim 19 (identical minus the overflow compensation) are the intermediate variants. Under KSR's "obvious to try," where a known improvement has optional components, claiming each subset is not a separate invention — the artisan would select the subset that fits the area/speed budget. Claims 16 and 19 are, structurally, claims to a fraction of claim 15's elements, which the case law treats as more obvious, not less.
9. Ground F — Claims 22, 23, 26, 29, 32, 33, 34, 35, 42, 43 (base/carry multiplier family)
Core combination: US 4,587,627 (Massey & Omura) + US 4,162,480 (Berlekamp) + Montgomery 1985 + Barrett + Rivest '829, with Gregg '093 for the parallel full-adder summation.
Claim 29 (the simplest member) recites only: base/carry registers for A and B; a single F₁ = 2ⁿ − p; base/carry full-adder accumulation; overflow means; final mod-p reduction. This is Montgomery's REDC algorithm implemented with carry-save registers driven by a shift-add loop. Two references, one motivation (avoid serial carry propagation while doing modular accumulation), predictable result. Strong § 103; arguably § 102 over a suitable carry-save modular-multiplier reference.
Claims 23 and 33 (no first partial reduction) and claims 26 (no second partial reduction / no overflow compensation) are again the subtractive variants, each individually weaker.
Claim 22 and claim 32 (the full feature sets) are the hardest, requiring the F₁–F₄ table (Ground D) and both partial-reduction stages (Ground E) on top of the base/carry architecture. The motivation is cumulative but coherent: it is one engineering objective — keep every register to n bits while pipelining a base/carry multiplier — and the claims are the union of the techniques that objective drives.
10. Consolidated mapping and relative strength
| Claims | Primary combination | Key rationale | § 103 strength |
|---|---|---|---|
| 2, 3, 6, 7 | Berlekamp '480 + Gregg '093 | Carry-save adder + gated shift-add; both same field | Strongest (near § 102) |
| 29, 30, 31 | Montgomery 1985 + Berlekamp '480 (+'627) | REDC with carry-save registers | Very strong |
| 8, 9, 10, 12, 36, 38, 44 | Montgomery + Berlekamp + '829 (Blakley; Willoner & Chen) | Known reduction-avoiding modular arithmetic; conditional final subtraction | Very strong |
| 11, 13, 14, 37 | Above + Gregg '093 + precomputed modulus multiples | Counting/table lookup; F₂–F₄ are arithmetic, and admitted as such in the spec | Strong |
| 16, 17, 18, 40 | '627 + Montgomery + Barrett | Optional-feature selection ("obvious to try") | Strong |
| 19, 20, 21, 41 | '627 + Montgomery + Barrett | Optional-feature selection | Strong |
| 15, 39 | '627 + Montgomery + Barrett (+'829) | Two applications of one admitted partial-reduction technique | Moderate–strong |
| 23, 24, 25, 33, 34, 35 | Ground F combination | Same, minus one partial reduction | Moderate–strong |
| 26, 27, 28 | Ground F, minus overflow compensation | Optional-feature selection | Moderate |
| 1, 4, 5 | '627 + '480 + '829 + Barrett | GF(2ᵐ)→GF(p) port of the known shift-add/shared-logic recipe | Moderate |
| 22, 32, 42, 43 | Full Ground F + D + E | Cumulative design objective | Moderate (the only claims with a real argument) |
11. Secondary considerations — what exists
Under Graham factor (4), nothing on the record I have supports nonobviousness:
- Commercial success: Cylink was a genuine operating company and sold encryptor hardware (per the Assignment section), but no evidence ties commercial success to the claimed chip architecture rather than to the public-key products generally. No nexus evidence is on the record.
- Long-felt need / failure of others: the technology was being actively pursued by many groups (Barrett; Beth/Cook/Gollmann; the GF(2ᵐ) hardware lineages) — which undercuts "failure of others."
- Copying: no evidence located.
- Unexpected results: none identified; the specification presents the results as engineering tradeoffs ("this is a design choice," "there is some freedom to choose representations").
- Praise/skepticism of experts: none located.
The patent's prosecution history remains unreviewed (a gap flagged in both prior sections). The paper trail — which references the examiner actually cited as § 102 versus § 103, and any Grounds of Rejection — would be the definitive statement of how the Office viewed these combinations, and should be pulled from PatentCenter.
12. Where the § 103 case is weakest — and the two structural escape hatches
- Non-analogous art. The strongest possible rebuttal is that the GF(2ᵐ) coding/error-control hardware in the cited set is non-analogous to an integer-modular cryptographic processor. I assess this as likely to fail: (a) Berlekamp '480 and Massey–Omura '627/'600 were already aimed at cryptographic applications ('600 is expressly a "privacy of digital messages" patent), placing them in the same field of endeavor; and (b) under KSR, similarity of the problem (fast finite-field arithmetic in dedicated silicon) suffices even across fields. The prior-art section's finding that US 4,201,770-family and RSA '829 are on the face — cryptographic method patents — reinforces the shared field.
- § 103(c) / common ownership (pre-AIA). The prior-art section flagged that US 4,587,627 and US 4,567,600 name Omura as a co-inventor and were assigned to Omnet Associates, not Cylink. Because the co-invented references have a different inventive entity (Massey + Omura) than the '781 (Omura alone), they are "by another" and available under § 102(a)/(e)/§ 103 — and because Omnet ≠ Cylink, the pre-AIA § 103(c) safe harbor for "commonly owned" subject matter would not automatically disqualify them. Unless a common-ownership/obligation-to-assign relationship existed at the time of invention, the applicant's own foundational work is § 103 art against him. This should be verified against the assignment records (already flagged as partially unretrieved in the Assignment section).
- Double patenting is a separate track, not § 103. US 5,210,710 ("Modulo arithmetic processor chip," same title, same inventor, Cylink) is an obviousness-type double-patenting candidate over the '781, not a § 103 reference against it.
13. Bottom line
- No claim is anticipatable on a single reference; the Prior Art section's conclusion on that point is reaffirmed.
- Every independent claim is vulnerable under § 103. The strongest grounds are the simplest claims — 2, 8, 12, 29, 36, 38, 44 and their near neighbours — where the asserted advance reduces to applying a known modular-reduction technique (Montgomery/Barrett) with known carry-save/hardware-multiplier structure (Berlekamp/Gregg/Massey–Omura) to a known problem (fast RSA/Diffie–Hellman arithmetic).
- The pivot elements are E2 (the F = 2ⁿ − p feedback register) and E4 (the F₁–F₄ overflow table). Neither is disclosed on-face, but each is (a) admitted in the specification as an implementation choice, (b) mathematically trivial (2ⁿ ≡ 2ⁿ − p; Fₖ = kF₁ mod p), and (c) of a kind the contemporaneous art (Montgomery 1985; Barrett 1986) already used. Those elements are therefore motivation-bridged, not disclosure-bridged — which is precisely what § 103 permits post-KSR.
- The claims with the most colourable nonobviousness story are 22, 32, 42, and 43 — the full-feature base/carry multiplier claims combining F₁–F₄ and both partial-reduction stages. Even these fall to a four-reference combination, but the motivation chain is longer and more contestable.
Practical caveat: because the patent expired 2007-03-04 and was never litigated and never subjected to an AIA trial (per the prior sections), this analysis is retrospective and non-accusatory — there is no live validity contest and no § 315(e)(2) estoppel shaping it. Its practical value is defensive and portfolio-oriented: (i) the '781's specification disclosures are themselves citable prior art against later-filed patents, and (ii) the analysis shows what a challenger would have argued had a case ever been brought.
14. Verification steps to firm up the negatives
- USPTO PatentCenter — file wrapper for 07/289,124 / US 4,891,781. Retrieve the examiner's citations and any Grounds of Rejection, to confirm whether the Gregg/Berlekamp/Omura references were applied as § 102 or § 103 art (the prior-art section flagged the file wrapper as never reviewed).
- Verify the on-face non-patent citations' dates and content — particularly Beth, Cook & Gollmann, CRYPTO '86, LNCS 263:302–310 (confirmed: https://rd.springer.com/search?dc.creator=T.+Beth) and Barrett, CRYPTO '86, LNCS 263:311–326 (https://doi.org/10.1007/3-540-47721-7_24) — to confirm each predates or is contemporaneous with the 1987-03-04 priority.
- Confirm the additional art identified in this session (Montgomery, Math. Comp. 44(170):519–521 (1985); Brickell, CRYPTO '82, pp. 51–60 (1983); Blakley, IEEE Trans. Comput. C-32:497–500 (1983); Willoner & Chen, Proc. 5th IEEE Symp. Comput. Arith., pp. 135–138 (1981)), which I located bibliographically via https://cs.uwaterloo.ca/~shallit/bib/arithmetic.bib but did not retrieve in full text. Flag: that bibliography lists Head, "Multiplication modulo n," BIT 20 with an internally inconsistent year field ("1960"); treat that entry as unverified.
- Confirm the § 103(c) point — whether any common ownership or obligation-to-assign linked Omnet Associates and Cylink at the 1987 invention date, which determines whether the Massey–Omura references are disqualified under pre-AIA § 103(c).
- Note (not prior art): Takagi (1991) and Takagi & Yajima (1992) on redundant-representation modular multiplication surfaced in this session but post-date the '781 priority by four to five years and are therefore not available against these claims; cited here only to confirm that the redundant-representation approach matured shortly afterward.
No reference, date, or claim number has been fabricated. Where I could not verify a source directly (the file wrapper; the additional 1981–83 algorithm references; the § 103(c) ownership relationship), I have said so rather than filling the gap.
Generated 9/28/2026, 1:31:59 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
Other patents in Semiconductor (T)
- US 5274434I'll verify the patent record and check for any litigation or CAFC docket activity. Let me retrieve the claim set and confirm there's no litigation involving this patent. Let me pin down the exact independent claim text. US Patent…
- US 6611875I'll verify the patent details against live sources and check for any litigation activity. Let me pull the actual claim text, since the provided full text is truncated before the claims. Let me try to retrieve the actual claim language…
- US 4353060I'll search for litigation/docket activity and corroborating records for this patent number. Search results — US 4,353,060 Litigation / CAFC docket check: I ran targeted searches for 4353060 in connection with CAFC 2026 dockets and…
- US 3849137I'll search for this specific patent number as requested. Summary — US Patent 3,849,137 Search scope note: I ran two searches — one for the patent number itself and one targeting CAFC 2026 dockets. The patent-number search returned…
- US 4806774I'll run several searches to gather authoritative information on US 4806774, including any litigation activity. Let me search for the actual claim text and any litigation/docket activity. US 4,806,774 — Verification Summary Important…
- US 5974500US Patent 5,974,500 — Summary Identification (as literally printed on the document) - Patent number: US 5,974,500 (US5974500A / US 5974500) - Application number: 08/971,117 - Title: "Memory device having programmable access protection and…
- US 5264912I'll verify this patent number against live sources, including checking for any 2026 CAFC activity. Let me check for any litigation or court activity tied to this specific patent, and confirm assignee details. USPTO record — US 5,264,912 I…
- US 8035417I'll verify the patent's identity and litigation posture against live sources before summarizing. Let me check the Federal Circuit docket reference and whether any 2026 activity exists. US 8,035,417 — Summary Confirmation of identity. All…