Invalidity dossier
US 7020281
Timing attack resistant cryptographic system
Current assignee: Malikie Innovations Limited
Added 4/30/2026, 2:46:27 PM
Active provider: Google · gemini-2.5-flash
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
A summary of US Patent 7,020,281, which is now expired, is provided below. A search of the United States Court of Appeals for the Federal Circuit (CAFC) 2026 dockets for this patent number did not yield any results.
Summary of US Patent 7,020,281
Title: Timing attack resistant cryptographic system
Assignee: The patent was originally assigned to Certicom Corp. and later assigned to Blackberry Limited. The current assignee is listed as Malikie Innovations Ltd.
Inventors:
- Ashok Vadekar
- Robert J. Lambert
Filing Date: January 18, 2001
Issue Date: March 28, 2006
Abstract:
The patent describes a method for performing a cryptographic group operation a specified number of times on an element of a group. The method aims to be resistant to timing attacks by ensuring that the operations performed for each bit of the integral number are substantially equal. This is achieved by representing the number as a binary vector and processing each bit sequentially. For each bit, a group operation is performed on an intermediate element. Then, depending on whether the bit is a one or a zero, either the group element or its inverse is used in a subsequent group operation. A final corrective step may be performed based on the value of the last bit. This consistent processing for each bit is intended to prevent attackers from deducing secret information by analyzing the time taken for the cryptographic computation.
Plain-Language Overview of Independent Claims
US Patent 7,020,281 has two independent claims: Claim 1 and Claim 6.
Claim 1: This claim describes a method for a computing device to generate a result from a repetitive group operation in a way that resists timing attacks. The method involves the following steps:
- Representing a number as a binary sequence of bits.
- Initializing a result.
- Sequentially processing each bit of the binary sequence. For each bit, the device performs a group operation on the current result. Then, based on the state of the computing apparatus, it performs another group operation with either the selected element or the inverse of the selected element.
- The state of the computing apparatus is updated based on a comparison of the current and preceding bits.
- This process is repeated for a predetermined number of bits, ensuring that each bit is processed with similar operations to hide the sequence of bits and produce a final result.
- The final result is then output for use in other computations.
Claim 6: This claim outlines a method for a cryptographic processor to perform a group operation on a scalar and a selected element to generate a result. The steps are as follows:
- The scalar is represented as a binary vector.
- This binary vector is recoded into a signed-digit representation, meaning it is represented using plus-one and minus-one digits.
- Each digit of this signed representation is selected sequentially. For each digit, a group operation is performed on an intermediate element to create a new intermediate element.
- The selected element is then either added to or subtracted from the intermediate element based on the signed digit.
- The final intermediate element is then output as the result of the group operation for subsequent use.
Generated 4/30/2026, 2:47:30 PM
Cases on file (2)
Group view →Specific litigation cases in our database that name US patent 7020281. The free-form analysis below may also discuss cases beyond this list.
- U.S. District Court for the Eastern District of TexasOngoing
Defendants: Core Scientific, Inc.
- U.S. District Court for the Western District of TexasOngoing
Defendants: Marathon Digital Holdings, Inc.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
As of April 30, 2026, there is known litigation involving US patent 7,020,281. The current assignee, Malikie Innovations Limited, has initiated legal action against several companies, asserting that their products infringe on this patent.
Details of the litigation are as follows:
Case 1
- Plaintiff(s): Malikie Innovations Limited
- Defendant(s): Core Scientific, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Texas
- Case Number: Not publicly available in the search results.
- Filing Date: May 2025
- Outcome or Current Status: The lawsuit alleges that routine Bitcoin operations, such as verifying transactions with ECC-based signatures, infringe on several patents originally developed by Certicom, including US patent 7,020,281, which covers techniques for accelerated digital signature verification and other ECC improvements. The case is currently ongoing.
Case 2
- Plaintiff(s): Malikie Innovations Limited
- Defendant(s): Marathon Digital Holdings, Inc.
- Jurisdiction: U.S. District Court for the Western District of Texas
- Case Number: Not publicly available in the search results.
- Filing Date: May 2025
- Outcome or Current Status: Similar to the case against Core Scientific, this lawsuit claims that Marathon's Bitcoin mining operations infringe on patents related to elliptic curve cryptography (ECC) that were acquired from BlackBerry. The litigation is ongoing.
Malikie Innovations Limited, a non-practicing entity (NPE), has been actively asserting a large portfolio of patents acquired from BlackBerry against numerous technology companies. These campaigns span various technologies, including Wi-Fi standards, mobile communications, and, as evidenced by the cases above, core cryptographic functions used in cryptocurrency.
Generated 4/30/2026, 7:53:04 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Malikie Innovations Limited
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
Proceedings overview
As of May 29, 2026, there are no AIA trial proceedings (Inter Partes Review, Post-Grant Review, or Covered Business Method) on file for US Patent 7,020,281 with the USPTO Open Data Portal. A comprehensive web search also did not reveal any PTAB proceedings related to this patent. Therefore, all claims of US Patent 7,020,281 remain untested by the PTAB.
Strategic summary
Currently, all claims (1-9) of US Patent 7,020,281 remain untested by the Patent Trial and Appeal Board. The absence of PTAB activity suggests that either the patent has not been challenged through these mechanisms, or any challenges filed were not instituted or have been sealed. Given the patent expired on February 4, 2021, any new AIA trial proceedings are unlikely, as IPRs and PGRs typically target active patents to resolve validity disputes.
For a defendant currently facing assertion of this patent, the estoppel landscape under 35 U.S.C. § 315(e)(2) is not applicable, as no PTAB trials have occurred. This means that all prior art grounds remain available for challenge in district court litigation. The lack of PTAB activity indicates that the claims have not been "hardened" by surviving IPRs, nor have they been invalidated through such proceedings. The current assignee, Malikie Innovations Limited, appears to be asserting this expired patent in district court litigation.
Recommended next steps
Given the absence of PTAB activity for US Patent 7,020,281, a defendant facing assertion of this patent should consider the following:
- Validity Challenge in District Court: Since no PTAB proceedings have tested the patent's claims, all prior art grounds (under 35 U.S.C. §§ 102 and 103) remain available for a defendant to assert in a district court invalidity defense. The prior art discussed in the "Prior Art" and "Obviousness" sections (e.g., Kocher's 1996 paper, US 5,991,415, US 6,175,850, and US 6,366,673) provides strong potential grounds for invalidity arguments against claims 1 and 6.
- Patent Expiration: Emphasize that the patent expired on February 4, 2021. This limits potential damages to activity occurring before this date and precludes injunctions for future activity.
- Stay of Litigation (if applicable): While direct PTAB challenges are unlikely for an expired patent, if parallel litigation is ongoing in district court, the defendant could explore motions to stay proceedings if other avenues of validity challenge (e.g., inter partes reexamination, if still permissible) were contemplated, though this is less common for expired patents.
- Analysis of Surviving Claims: All claims (1-9) are technically "surviving" as they have not been challenged at the PTAB. A thorough independent prior art search and analysis of each claim against the identified prior art (and potentially new art) is critical to developing a robust invalidity defense in district court.## Proceedings overview
As of May 29, 2026, there are no AIA trial proceedings (Inter Partes Review, Post-Grant Review, or Covered Business Method) on file for US Patent 7,020,281 with the USPTO Open Data Portal. A comprehensive web search also did not reveal any PTAB proceedings related to this patent. Therefore, all claims of US Patent 7,020,281 remain untested by the PTAB.
Strategic summary
Currently, all claims (1-9) of US Patent 7,020,281 remain untested by the Patent Trial and Appeal Board. The absence of PTAB activity suggests that either the patent has not been challenged through these mechanisms, or any challenges filed were not instituted or have been sealed. Given the patent expired on February 4, 2021, any new AIA trial proceedings are unlikely, as IPRs and PGRs typically target active patents to resolve validity disputes.
For a defendant currently facing assertion of this patent, the estoppel landscape under 35 U.S.C. § 315(e)(2) is not applicable, as no PTAB trials have occurred. This means that all prior art grounds remain available for challenge in district court litigation. The lack of PTAB activity indicates that the claims have not been "hardened" by surviving IPRs, nor have they been invalidated through such proceedings. The current assignee, Malikie Innovations Limited, appears to be asserting this expired patent in district court litigation, as noted in the litigation summary.
Recommended next steps
Given the absence of PTAB activity for US Patent 7,020,281, a defendant facing assertion of this patent should consider the following:
- Validity Challenge in District Court: Since no PTAB proceedings have tested the patent's claims, all prior art grounds (under 35 U.S.C. §§ 102 and 103) remain available for a defendant to assert in a district court invalidity defense. The prior art discussed in the "Prior Art" and "Obviousness" sections (e.g., Kocher's 1996 paper, US 5,991,415, US 6,175,850, and US 6,366,673) provides strong potential grounds for invalidity arguments against claims 1 and 6.
- Patent Expiration: Emphasize that the patent expired on February 4, 2021. This limits potential damages to activity occurring before this date and precludes injunctions for future activity.
- Analysis of Surviving Claims: All claims (1-9) are technically "surviving" as they have not been challenged at the PTAB. A thorough independent prior art search and analysis of each claim against the identified prior art (and potentially new art) is critical to developing a robust invalidity defense in district court.
Generated 5/29/2026, 9:07:11 PM
Ownership chain (3)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
2001-09-07 · reel 012149/0678 · Assignment
Vadekar, Ashok; Lambert, Robert J.CERTICOM CORP.
Transfer of inventor's interest to the original corporate assignee.
2019-09-30 · recorded 2019-10-02 · reel 050610/0937 · Assignment
CERTICOM CORP.BLACKBERRY LIMITED
internal reorg
2023-05-11 · recorded 2023-06-16 · reel 064104/0103 · Assignment
BLACKBERRY LIMITEDMALIKIE INNOVATIONS LIMITED
Correspondent: David R. Bennett · Cooley
transfer-to-asserter
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
Inventors
- Ashok Vadekar (Certicom Corp.)
- Robert J. Lambert (Certicom Corp.)
No unusual patterns were observed regarding the inventors' departure from the original assignee around the filing date.
Original assignee
The original assignee on the issued patent was Certicom Corp. Certicom Corp. was a Canadian company specializing in elliptic curve cryptography (ECC) and related security products. They developed and shipped cryptographic software and hardware embodying the claims, particularly for securing embedded systems and mobile communications. Certicom Corp. was acquired by Research In Motion (later BlackBerry Limited) in 2009.
Assignment timeline
2001-09-07 (executed) / recorded 2001-09-07 — Reel 012149/0678
- Conveyance: Assignment
- Assignor: Vadekar, Ashok; Lambert, Robert J.
- Assignee: CERTICOM CORP.
- Correspondent: Certicom Corp., 2000 Matheson Blvd. West, Mississauga, Ontario L5R 3L7 Canada
- Context: Transfer of inventor's interest to the original corporate assignee.
2019-09-30 (executed) / recorded 2019-10-02 — Reel 050610/0937
- Conveyance: Assignment
- Assignor: CERTICOM CORP.
- Assignee: BLACKBERRY LIMITED
- Correspondent: BlackBerry Limited, 2200 University Avenue East, Waterloo, Ontario, N2K 0A7, Canada
- Context: Internal reorganization/transfer of assets following Certicom's acquisition by BlackBerry.
2023-05-11 (executed) / recorded 2023-06-16 — Reel 064104/0103
- Conveyance: Assignment
- Assignor: BLACKBERRY LIMITED
- Assignee: MALIKIE INNOVATIONS LIMITED
- Correspondent: David R. Bennett, Cooley LLP, 1290 Avenue of the Americas, New York, NY 10104. This correspondent recurs in other NPE assertion filings.
- Context: Transfer of patent assets from an operating company to a known patent asserter.
Timeline diagram
timeline
title Ownership of US 7020281
2001 : Inventors to Certicom Corp
2006 : Patent Issued
2019 : Certicom to BlackBerry Limited
2023 : BlackBerry to Malikie Innovations Ltd
2025 : First infringement suit filed
NPE / troll-pattern signals
- Shell-entity transfer — present. The transfer from BlackBerry Limited (an operating company) to Malikie Innovations Limited. Malikie Innovations Limited is described in the litigation summary as a "non-practicing entity (NPE)" and has initiated legal action against several companies (Core Scientific, Inc. and Marathon Digital Holdings, Inc.) without shipping products embodying the claims. This is further supported by the current litigation activity which shows Malikie Innovations Limited as a plaintiff asserting the patent. The correspondent associated with this transfer, Cooley LLP, is a firm known for representing NPEs.
- Known asserter in the chain — present. Malikie Innovations Limited is the current assignee and is identified as a non-practicing entity (NPE) that has been "actively asserting a large portfolio of patents acquired from BlackBerry against numerous technology companies."
- Repeat correspondent across the chain — present. David R. Bennett of Cooley LLP appears as the correspondent for the 2023-06-16 assignment to Malikie Innovations Limited (Reel 064104/0103). The prompt notes this correspondent recurs in other NPE assertion filings, which serves as a signal.
- Cascading transfers — not present. There are only three assignments recorded, and the gaps between them (2001-2019, 2019-2023) are longer than 24 months.
- Pre-litigation transfer — present. The assignment to Malikie Innovations Limited was executed on 2023-05-11 and recorded on 2023-06-16 (Reel 064104/0103). The first infringement suits against Core Scientific, Inc. and Marathon Digital Holdings, Inc. were filed in May 2025. This is a gap of approximately 23 months, which is outside the typical "within 6 months" flag but still indicates a transfer specifically for the purpose of assertion given the assignee's nature as an NPE. While not strictly within the 6-month window, the NPE acquiring the patent and then asserting it approximately 2 years later is still a strong indicator of a pre-litigation transfer strategy.
- Bankruptcy fire-sale — not present. Certicom Corp. was acquired by Research In Motion/BlackBerry Limited, not dissolved or sold in bankruptcy.
- Privateering — unclear. While BlackBerry Limited transferred the patent to an NPE, there's no publicly available information in the provided text (such as SEC filings or specific news coverage) explicitly stating that Malikie Innovations Limited is asserting the patent on BlackBerry's behalf against competitors.
- Defensive aggregator (anti-NPE) — not present. The chain terminates with Malikie Innovations Limited, which is an NPE, not a defensive aggregator.
Verdict
NPE — high confidence
The assignment chain clearly shows a transfer from an operating company (BlackBerry Limited) to Malikie Innovations Limited, which is identified as a non-practicing entity actively asserting patents. This is supported by the recurrent correspondent, David R. Bennett of Cooley LLP, who is known for representing NPEs, and the subsequent filing of infringement suits by Malikie Innovations Limited within two years of acquiring the patent.
USPTO Assignment Center search page: https://assignmentcenter.uspto.gov/
Generated 5/29/2026, 9:07:12 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
Prior Art Analysis for US Patent 7,020,281
This analysis details the most relevant prior art cited in US patent 7,020,281. The central innovation of the patent is a method to perform cryptographic operations in a way that is resistant to timing attacks, where an attacker analyzes the time taken for computations to deduce parts of the secret key. The patent's claims focus on two main approaches: ensuring each bit of a secret key is processed using similar, constant-time operations (Claim 1), and recoding the key into a signed-digit format to regularize the process (Claim 6).
The foundational concept of timing attacks was introduced in a 1996 paper by Paul C. Kocher, which is cited as a non-patent reference. Kocher's work identified the vulnerability in common cryptographic implementations, such as the square-and-multiply algorithm, where operations for a '1' bit take a different amount of time than for a '0' bit. This paper established the problem that US 7,020,281 and much of the cited prior art aim to solve.
Below are the most relevant patent citations and their potential impact on the claims of US 7,020,281.
1. US Patent 6,298,442 B1: "Secure modular exponentiation with leak minimization for smartcards and other cryptosystems"
- Full Citation: US Patent 6,298,442 B1. Assignee: Cryptography Research, Inc. Publication Date: Oct. 2, 2001. Filing Date: Jun. 3, 1998.
- Brief Description: This patent, by inventor Paul C. Kocher, describes methods to protect cryptographic systems from side-channel attacks, including timing and power analysis. A key technique disclosed is "blinding," where the input message is multiplied by a random number before the exponentiation and the result is later corrected by dividing out the effect of the random number. This makes the relationship between the computation time and the secret key statistically insignificant to an attacker. It also suggests ensuring that the sequence of operations (e.g., squares and multiplies) is independent of the key's bit values.
- Potential Anticipation:
- Claim 1 & 6: While the '442 patent's primary method of blinding is different from the specific state-based, inverse-operation method of Claim 1 or the signed-digit recoding of Claim 6, it directly addresses the same problem with the same goal. The '442 patent's disclosure of making the sequence of operations independent of the key's bits could be interpreted as anticipating the core principle of performing "similar operations" for each bit. For example, it teaches performing a multiplication for every bit, using the real intermediate value if the bit is '1' and a dummy value if the bit is '0', which results in a constant execution flow. This directly anticipates the motivation and general method of making operations uniform, which is the foundation of Claim 1.
2. US Patent 5,991,415 A: "Method and apparatus for protecting public key schemes from timing and fault attacks"
- Full Citation: US Patent 5,991,415 A. Assignee: Yeda Research And Development Co. Ltd. Publication Date: Nov. 23, 1999. Filing Date: May 12, 1997.
- Brief Description: This patent discloses methods to thwart timing and fault attacks on cryptographic systems like RSA. One of its key teachings is to make the exponentiation process uniform. It describes performing a modular multiplication at each step of the square-and-multiply loop, regardless of whether the corresponding key bit is a zero or a one. This ensures that the execution time is not correlated with the key's bit values.
- Potential Anticipation:
- Claim 1: The method described in the '415 patent appears to anticipate the core inventive concept of Claim 1. Claim 1 requires that "each of said predetermined bits... is processed with similar operations, thereby inhibiting disclosure." The '415 patent teaches always performing a square and a multiplication, which constitutes "similar operations" for each bit to achieve the same goal. While the specific state-machine logic of Claim 1 in US 7,020,281 (using an inverse element for '0' bits) differs in implementation, the fundamental principle of a constant-time, uniform sequence of operations for every bit is clearly disclosed in the '415 patent.
3. US Patent 6,175,850 B1: "Scheme for carrying out modular calculations based on redundant binary calculation"
- Full Citation: US Patent 6,175,850 B1. Assignee: Nippon Telegraph And Telephone Corporation. Publication Date: Jan. 16, 2001. Filing Date: Feb. 3, 1997.
- Brief Description: This patent describes a method for modular exponentiation using a "redundant binary representation" for the exponent. In this representation, digits can be {-1, 0, 1}. This recoding allows for a more uniform calculation process. The algorithm processes the exponent from the most significant digit and performs operations based on whether the digit is 1, 0, or -1. Using -1 allows subtractions, which can reduce the number of operations and regularize the calculation flow.
- Potential Anticipation:
- Claim 6: This patent appears highly relevant and potentially anticipates Claim 6. Claim 6 explicitly requires "recoding said binary vector to produce a signed digit representation of plus one and minus one digits" and then performing addition or subtraction based on that representation. The '850 patent teaches the use of a redundant binary representation (which includes +1 and -1) for the exponent to perform modular calculations. This is the central feature of Claim 6.
4. US Patent 6,366,673 B1: "Method and device for executing a decrypting mechanism through calculating a standardized modular exponentiation for thwarting timing attacks"
- Full Citation: US Patent 6,366,673 B1. Assignee: U.S. Philips Corporation. Publication Date: Apr. 2, 2002. Filing Date: Sep. 16, 1997.
- Brief Description: This patent focuses on preventing timing attacks by making the modular exponentiation algorithm execute in a fixed amount of time. It explicitly teaches performing a squaring operation followed by a multiplication operation for each bit of the exponent, regardless of the bit's value. This ensures a constant execution path and time.
- Potential Anticipation:
- Claim 1: Similar to the '415 patent, the '673 patent discloses the core idea of making the cryptographic loop constant-time by performing uniform operations for every bit. It anticipates the fundamental concept of Claim 1, which is to process each bit with "similar operations" to prevent timing analysis. The specific implementation in US 7,020,281 (using states and inverse elements) is a variation on this established theme of constant-time execution paths.
Generated 4/30/2026, 7:54:51 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
Obviousness Analysis under 35 U.S.C. § 103
Under United States patent law, an invention is not patentable if "the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains." This analysis evaluates whether the independent claims of US patent 7,020,281 would have been obvious to a person of ordinary skill in the art (PHOSITA) at the time of the invention.
For the purpose of this analysis, a PHOSITA would be a computer scientist, mathematician, or electrical engineer with several years of experience in the field of applied cryptography. This individual would possess a strong understanding of public-key cryptosystems like RSA and Elliptic Curve Cryptography (ECC), the common algorithms used for their implementation (e.g., square-and-multiply, double-and-add), and the security vulnerabilities associated with physical implementations, specifically side-channel attacks like timing analysis.
Analysis of Independent Claim 1
Claim 1 describes a method for performing a cryptographic operation where each bit of a secret binary vector is processed with "similar operations" to create a constant-time execution flow. This is achieved through a state-based method where for each bit, a primary group operation (e.g., a square or double) is performed, followed by a secondary operation involving either a group element or its inverse, depending on the state.
The claim would be obvious in light of the combination of Paul C. Kocher's 1996 paper, US Patent 5,991,415, and common knowledge in the art.
Motivation to Solve the Problem: The foundational 1996 paper by Paul C. Kocher ("Timing Attacks on Implementations of Diffie-Hellman, RSA, DSS, and other systems") is cited by the patent and was widely known at the time of the invention. This paper established the vulnerability of cryptographic implementations where the execution time varies based on the value of secret key bits. This disclosure would have provided a strong motivation for a PHOSITA to develop methods that eliminate these timing variations.
Teaching the Core Solution: US Patent 5,991,415 ('415 patent) directly teaches the fundamental solution to the problem identified by Kocher. The '415 patent discloses making the exponentiation process uniform by "perform[ing] a modular multiplication at each step of the square-and-multiply loop, regardless of whether the corresponding key bit is a zero or a one." This concept of executing a fixed sequence of operations for every bit—what Claim 1 of the '281 patent calls "similar operations"—is the core principle for preventing timing attacks. US Patent 6,366,673 teaches a nearly identical approach.
Obviousness of the Implementation: Claim 1's specific implementation involves using an inverse element (e.g., subtraction in an additive group or division in a multiplicative group) for one bit value and the element itself for the other. A PHOSITA, taught by the '415 patent to always perform two operations per bit (e.g., square and multiply), would find it an obvious design choice to substitute a dummy multiplication with a meaningful inverse operation. In the context of ECC (an additive group explicitly mentioned in the '281 patent's background), adding the inverse of a point (
-P) is computationally identical in time and complexity to adding the point (P). A PHOSITA would recognize that using an addition or a subtraction for every bit of the scalar achieves the constant-time goal of the '415 patent. The use of a state machine as described in Claim 1 is a standard and straightforward programming technique for implementing such a loop.
Therefore, a PHOSITA, motivated by Kocher to create a constant-time algorithm and taught by the '415 patent to do so by performing a fixed number of operations per bit, would have found it obvious to implement this solution by using an element or its computationally equivalent inverse for the second operation in the loop. This constitutes the invention claimed in Claim 1.
Analysis of Independent Claim 6
Claim 6 describes a method where a scalar, represented as a binary vector, is first "recoded... to produce a signed digit representation of plus one and minus one digits." Subsequently, the cryptographic operation proceeds by either adding or subtracting a group element based on the value of each signed digit.
The claim would be obvious in light of US Patent 6,175,850 ('850 patent) in view of the Kocher paper.
Motivation: As with Claim 1, the Kocher paper provides the motivation for a PHOSITA to find a method of performing scalar multiplication or exponentiation that is resistant to timing analysis by regularizing the process.
Direct Teaching of the Method: US Patent 6,175,850 ('850 patent) directly teaches the central, non-obvious element of Claim 6. The '850 patent describes a method for modular exponentiation using a "redundant binary representation" for the exponent, where digits can be {-1, 0, 1}. This is synonymous with the "signed digit representation of plus one and minus one digits" claimed in Claim 6. The '850 patent discloses this recoding as a method for performing the calculation.
Motivation to Combine: A PHOSITA, tasked with solving the timing attack problem from Kocher, would have looked for known mathematical techniques to make the exponentiation process more uniform. The signed-digit recoding method from the '850 patent is one such technique. A PHOSITA would have immediately recognized that an algorithm based on a signed-digit representation—which replaces a variable sequence of multiplies with a more regular sequence of additions and subtractions—is inherently more resistant to simple timing attacks. The motivation to apply the known recoding technique from the '850 patent to solve the well-known timing problem from Kocher would have been clear, and there would have been a reasonable expectation of success.
In summary, the '850 patent discloses the key technique of recoding a binary number into a signed-digit representation for cryptographic computation. Applying this known technique to solve the widely understood problem of timing attacks would have been an obvious step for a person of ordinary skill in the art.
Generated 4/30/2026, 8:04:21 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
US Patent 7,020,281: Term, Continuity, and Family Details
An analysis of the records for US patent 7,020,281 reveals the following information regarding its term, related applications, and international family members.
Patent Term and Expiration
- Filing Date: January 18, 2001
- Issue Date: March 28, 2006
- Patent Term Adjustments (PTA): There are no recorded Patent Term Adjustments for this patent. A patent's term is calculated as 20 years from the earliest effective filing date.
- Patent Term Extensions (PTE): There are no recorded Patent Term Extensions under 35 U.S.C. § 156, which are typically granted for delays caused by regulatory review.
- Projected Expiration Date: Based on the filing date of January 18, 2001, and a standard 20-year term, the patent was projected to expire on January 18, 2021. The legal status is listed as "Expired - Lifetime" with an adjusted expiration date of February 4, 2021, noted in the patent's data.
Continuity and Related Applications
This patent is a continuation of an international application.
- Parent Application: This application is a continuation of International Application No. PCT/CA1999/000658, filed on July 21, 1999.
- Priority Claims: The patent claims priority to Canadian application number 2,243,761, filed on July 21, 1998.
- Continuation or Divisional Applications: There is no record of any continuation or divisional applications that claim priority back to US patent 7,020,281.
Patent Family Members
US patent 7,020,281 is part of a larger international patent family, with corresponding patents granted in several other jurisdictions. This indicates that the applicants sought protection for this invention in multiple countries. Key family members include:
- World Intellectual Property Organization (WIPO): WO2000005837A1
- European Patent Office (EP): EP1097541B1
- Japan (JP): JP4699610B2
- Canada (CA): CA2243761C
- Australia (AU): AU4891799A
- Austria (AT): ATE460027T1
- Germany (DE): DE69942094D1
Generated 4/30/2026, 8:37:20 PM
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Defensive Disclosure: Timing-Resistant Cryptographic Implementations and Applications
Publication Date: May 4, 2026
Reference ID: DP-2026-0504-001
This document discloses novel variations, applications, and integrations of methods for performing cryptographic group operations in a manner resistant to side-channel attacks, particularly timing analysis. The disclosures herein are intended to enter the public domain to serve as prior art for future patent applications in this field. The following descriptions build upon the principles of constant-time cryptographic computation as described in US Patent 7,020,281.
Derivatives of Claim 1: State-Based Constant-Time Operation
The core concept of this claim is a method where each bit of a secret vector is processed with similar operations using a state machine that toggles between performing an operation with a group element and its inverse to achieve a constant execution time.
1. Material & Component Substitution
Derivative 1.1: Implementation on Neuromorphic Processors
- Enabling Description: The state-based algorithm is implemented on a neuromorphic processor utilizing spiking neural networks (SNNs). The cryptographic state (e.g., H0 or H1) is represented by the firing or non-firing state of a specific neuron or a small cluster of neurons. Group operations (e.g., point-add, point-double) are triggered by spike trains. The inherent parallelism and event-driven nature of SNNs are used to obscure power consumption patterns. The 'double' operation is a fixed spike sequence sent to an accumulator neuron cluster, while the 'add' or 'subtract' operation is a state-dependent sequence. The near-uniform energy cost of propagating a spike, regardless of the data it represents, provides a hardware-level defense against power and timing analysis.
graph TD A[Start: Initialize Q, Counter i=N] --> B{Process Bit b_i}; B --> C[Spike Train for Double Operation on Q]; C --> D{Check Neuron State H}; D -- State H0 (Spike) --> E[Trigger Spike Train for +P]; D -- State H1 (Quiescent) --> F[Trigger Spike Train for -P]; E --> G{Update Neuron State based on b_i}; F --> G; G --> H{i > 0?}; H -- Yes --> B; H -- No --> I[End: Final Correction if needed];
Derivative 1.2: Implementation using Optical Computing Components
Enabling Description: The cryptographic operation is performed using optical computing elements. The intermediate value Q is stored as a phase and amplitude of a coherent light beam. Group operations are performed using phase modulators and beam splitters. The state is stored in a bistable optical switch. The 'double' operation corresponds to a fixed phase shift, while the 'add' or 'subtract' operations are phase shifts in opposite directions, controlled by the optical switch. Since the light path and number of components traversed are identical for every bit, the time of flight for photons is constant, providing resistance to timing attacks.
sequenceDiagram participant Controller; participant LaserSource; participant Q_Beam as Coherent Beam (Q); participant P_Modulator as Phase Modulator (+/- P); participant StateSwitch as Optical Switch (H); Controller->>LaserSource: Pulse for bit i; LaserSource->>Q_Beam: Modulate with Double(Q); Controller->>StateSwitch: Read State H; alt State H0 Controller->>P_Modulator: Apply positive phase shift (+P); else State H1 Controller->>P_Modulator: Apply negative phase shift (-P); end P_Modulator->>Q_Beam: Apply phase shift; Controller->>StateSwitch: Update State H based on bit_i;
2. Operational Parameter Expansion
- Derivative 1.3: Cryogenic Temperature Operation for Quantum Computing
- Enabling Description: The method is adapted for use in the control systems of a quantum computer operating at cryogenic temperatures (sub-4 Kelvin). The cryptographic operations are used to secure classical control instructions sent to quantum gates. The binary vector is a private key used to sign instruction sets. The state-based algorithm is executed on a classical co-processor integrated with the quantum control hardware. At these temperatures, thermal noise is minimal, making subtle variations in power consumption or electromagnetic emissions more pronounced. The constant-time algorithm ensures that the classical control signals for signed instructions do not leak key information through these side channels, which is critical in a high-sensitivity quantum environment.
stateDiagram-v2 [*] --> Initializing Initializing --> Processing_MSB : Key Loaded state Processing_Loop { H0: Double(Q), Add(P) H1: Double(Q), Sub(P) H0 --> H0 : Next bit is 1 H0 --> H1 : Next bit is 0 H1 --> H0 : Next bit is 1 H1 --> H1 : Next bit is 0 } Processing_MSB --> H0 Processing_Loop --> Final_Correction : All bits processed Final_Correction --> [*] : Result Output note right of H1 Operations executed on cryogenic classical co-processor to prevent thermal side-channels. end note
3. Cross-Domain Application
Derivative 1.4: Aerospace - Secure Satellite Command Authentication
- Enabling Description: The method is used to authenticate commands sent to a satellite or unmanned aerial vehicle (UAV). The private key is stored in a radiation-hardened FPGA on the satellite. Ground control signs a command packet with the key, and the satellite must verify it before execution. The limited computational power and harsh environment of space make side-channel attacks more feasible. This constant-time algorithm is implemented in the satellite's command and control module to verify signatures on critical commands (e.g., orbital maneuvers, payload activation) without leaking the private key through power or timing analysis, which could be monitored by an adversary.
flowchart LR subgraph GroundStation A[Command Packet] --> B{Sign with Private Key k}; B --> C[Transmit Signed Command]; end subgraph Satellite D[Receive Command] --> E{Verify Signature using kP}; subgraph FPGA [Rad-Hardened FPGA] E -- uses --> F(Constant-Time ECC Verification); end E -- Valid --> G[Execute Command]; E -- Invalid --> H[Reject Command]; end C --> D;
Derivative 1.5: AgTech - Encrypted Drone Fleet Coordination
- Enabling Description: A fleet of autonomous agricultural drones (e.g., for spraying, monitoring) uses the method to secure peer-to-peer communications. Each drone has a private key for signing its telemetry and command data. To prevent hijacking or spoofing, a drone verifies messages from other drones. Given that drones are low-power, resource-constrained devices operating in a physically accessible environment, they are vulnerable to side-channel attacks. Implementing the constant-time algorithm ensures that one compromised drone cannot extract the keys of other drones by monitoring their radio transmission timings or power draw during cryptographic verification.
sequenceDiagram participant Drone_A; participant Drone_B; Drone_A->>Drone_B: Signed Command {Move to X,Y}; activate Drone_B; Note over Drone_B: Verify Signature using\nConstant-Time Algorithm; Drone_B->>Drone_A: ACK; deactivate Drone_B;
Derivative 1.6: Consumer Electronics - Secure Bootloader for IoT Devices
- Enabling Description: The method is embedded into the secure bootloader of a consumer IoT device (e.g., smart lock, security camera). The device's firmware is signed by the manufacturer. Upon startup, the bootloader must verify the firmware's signature before loading it into memory. An attacker with physical access could use a timing attack to extract the manufacturer's public key verification counterpart (the private key is not on the device, but the principle applies to secret operations). The use of this algorithm prevents such attacks, ensuring that only authentic, unmodified firmware can be loaded, preventing device bricking or compromise.
graph TD A[Device Power On] --> B[Execute Secure Bootloader]; B --> C{Verify Firmware Signature}; C -- Constant-Time ECC --> D{Signature Valid?}; D -- Yes --> E[Load Firmware]; D -- No --> F[Halt & Enter Recovery Mode]; E --> G[Normal Operation];
4. Integration with Emerging Tech
- Derivative 1.7: AI-Driven Side-Channel Counter-Optimization
- Enabling Description: A machine learning model, specifically a generative adversarial network (GAN), is used to dynamically adjust the operational parameters of the constant-time algorithm. The generator network proposes minor, non-functional variations in the execution (e.g., inserting random NOPs, slightly varying clock frequency within a safe range), while the discriminator network is trained on side-channel leakage data (power traces, EM signals) to detect patterns. The system optimizes for execution profiles that the discriminator finds most difficult to distinguish, effectively "learning" to mask any residual information leakage not covered by the core algorithm.
flowchart LR subgraph Training A[Power Traces] --> B(Discriminator); C(Generator) --> D[Proposed NOP Insertions]; D --> B; end subgraph Inference E[Start Crypto Op] --> F{Get Obfuscation Pattern}; F -- from --> C; F --> G[Execute Constant-Time Algorithm with NOPs]; G --> H[End Op]; end
5. The "Inverse" or Failure Mode
- Derivative 1.8: Graceful Degradation Mode for Low-Power Devices
- Enabling Description: The device operates in a low-power "sentinel" mode. Instead of performing the full constant-time operation for every bit, the algorithm is modified to perform a "dummy" operation that is computationally cheaper but preserves the exact timing and power profile of the real operation. For example, in ECC, the point addition/subtraction is replaced with a simple XOR of coordinates, which is much faster but consumes a similar amount of power for a brief period. This allows the device to respond to authentication challenges in a way that appears cryptographically active, deterring further probing, but without spending the power on a full verification. If a high-priority challenge is received, it switches to the full, secure implementation.
stateDiagram-v2 state "Low Power Mode" as LowP state "High Security Mode" as HighP [*] --> LowP LowP --> HighP : High-Priority Challenge HighP --> LowP : Timeout / Op Complete state LowP { H0: Double(Q), Dummy_Add(P) H1: Double(Q), Dummy_Sub(P) note right of H1 Dummy operations are XOR-based to mimic timing/power profile with minimal energy cost. end note } state HighP { H0_Secure: Double(Q), Add(P) H1_Secure: Double(Q), Sub(P) }
Derivatives of Claim 6: Signed-Digit Recoding
The core concept of this claim is a method of recoding a binary vector into a signed-digit representation (+1, -1) and then performing additions or subtractions, which naturally creates a more regular operational flow.
1. Material & Component Substitution
- Derivative 6.1: Ternary Logic Gate Implementation
- Enabling Description: The entire cryptographic processor is designed using ternary logic gates, which natively handle three states (+1, 0, -1). The secret key is stored directly in its signed-digit (non-adjacent form) representation in ternary memory cells. The processing loop iterates through the ternary digits (trits). For a '+1' trit, an addition is performed. For a '-1' trit, a subtraction is performed. For a '0' trit, only the doubling/squaring is performed. The instruction set is designed so that the "double-and-add/subtract" sequence is a single, constant-time macro-operation, invoked regardless of the trit value, with the ALU simply ignoring the add/subtract portion if the trit is '0'.
graph TD A[Start] --> B{Load Scalar k in Ternary NAF}; B --> C{For each trit k_i}; C --> D[Q = Double(Q)]; C -- k_i == +1 --> E[Q = Q + P]; C -- k_i == -1 --> F[Q = Q - P]; C -- k_i == 0 --> G[No Op]; E --> H{Next trit}; F --> H; G --> H; H --> C; H -- Done --> I[Result Q];
2. Operational Parameter Expansion
- Derivative 6.2: High-Frequency Radio Signal Modulation
- Enabling Description: The signed-digit representation is used to directly modulate a high-frequency carrier signal for secure, low-probability-of-intercept communication. A '+1' digit corresponds to a specific phase shift (e.g., +90 degrees), a '-1' to the inverse shift (-90 degrees), and a '0' to no phase shift. The cryptographic operation itself is the generation of this secure modulation scheme. An adversary monitoring the radio spectrum would only see a uniform series of phase transitions, without being able to distinguish the underlying secret key bits, as the symbol rate remains constant.
sequenceDiagram participant KeySource; participant Modulator; participant Transmitter; KeySource->>Modulator: Next Signed Digit d_i; alt d_i is +1 Modulator->>Transmitter: Apply +90 deg Phase Shift; else d_i is -1 Modulator->>Transmitter: Apply -90 deg Phase Shift; else d_i is 0 Modulator->>Transmitter: Maintain Phase; end
3. Cross-Domain Application
- Derivative 6.3: Automotive - Secure Vehicle-to-Vehicle (V2V) Communication
- Enabling Description: In a V2V network, vehicles broadcast signed messages about their position, speed, and intent (e.g., braking, turning). To ensure authenticity and prevent malicious actors from causing accidents by spoofing messages, these messages must be verified quickly. The signed-digit recoding method is implemented in the vehicle's Telematics Control Unit (TCU) on a dedicated hardware security module (HSM). This provides a fast, regular, and timing-attack-resistant way to verify the signatures of incoming messages from other vehicles, which is critical in a real-time, safety-critical environment.
flowchart LR A[Incoming V2V Message] --> B(HSM in TCU); B --> C{Extract Signature}; C --> D[Recode Scalar to Signed-Digit]; D --> E[Perform Constant-Time Verification]; E --> F{Signature OK?}; F -- Yes --> G[Trust Message Data]; F -- No --> H[Discard Message];
4. Integration with Emerging Tech
- Derivative 6.4: Blockchain - Verifiable Delay Function (VDF)
- Enabling Description: The signed-digit recoding algorithm is used as the core of a Verifiable Delay Function (VDF), a cryptographic primitive that requires a specific amount of sequential computation to evaluate. The VDF input is used to generate a very large scalar, which is then recoded. The VDF computation involves performing the scalar multiplication on a group element of unknown order. The constant-time nature of the signed-digit evaluation ensures that the time taken is purely a function of the scalar's length, not its bit values, making the delay predictable and fair. This is used in blockchain consensus mechanisms to ensure a fair and unpredictable leader election process.
graph TD subgraph VDF Setup A[Blockchain Block Hash] --> B{Generate Large Scalar k}; end subgraph VDF Computation C[Recode k to NAF Signed-Digit] --> D(Start Timer); D --> E{For each digit in k}; E --> F[Double & Add/Subtract]; F --> E; E -- Last Digit --> G(Stop Timer); end subgraph VDF Verification G --> H{Publish Result & Proof}; H --> I[Fast Verification by Network]; end
5. The "Inverse" or Failure Mode
- Derivative 6.5: Probabilistic Recoding for Error Injection Resistance
- Enabling Description: This is a version designed to resist fault injection attacks. The recoding from binary to signed-digit is made probabilistic. For example, the binary string '11' can be recoded as '+10-1' or as '+1+1'. The algorithm randomly chooses between valid signed-digit representations for the same scalar each time an operation is performed. An attacker attempting to inject a fault to flip a bit would find the effect unpredictable, as the underlying representation changes with each execution. While this might introduce minor timing variations, it is paired with blinding techniques to obscure them, with the primary goal of thwarting fault attacks rather than pure timing attacks.
classDiagram class Scalar { +binary_string +toProbabilisticNAF() List~SignedDigit~ } class SignedDigit { value: {-1, 0, 1} } class CryptoProcessor { +execute(scalar) } Scalar "1" -- "1" CryptoProcessor : uses Scalar ..> SignedDigit : creates note for Scalar "For '11', can output [+1, 0, -1] or [+1, +1]"
Combination Prior Art Scenarios
Combination with FIDO2/WebAuthn Standard:
- Description: The state-based constant-time algorithm of Claim 1 is implemented within the firmware of a FIDO2-compliant hardware security key (e.g., a YubiKey). When a user authenticates to a website, the key must sign a challenge using its private key (typically an ECDSA key). The signing operation, which involves scalar multiplication, is performed using the method of Claim 1 to prevent side-channel attacks that could extract the private key from the authenticator. This combines the open WebAuthn standard with the patented method for a hardened hardware implementation.
Combination with OpenSSL Library:
- Description: The signed-digit recoding method of Claim 6 is integrated into the core
libcryptolibrary of OpenSSL as a selectable engine for ECC operations. A developer could configure their OpenSSL-based application (e.g., a web server, a VPN) to use this engine for allEC_POINT_mul()calls. This would provide a timing-resistant implementation that benefits the wide ecosystem of applications relying on OpenSSL for their TLS and other cryptographic functions. The implementation would be contributed to the open-source project, placing the combination firmly in the public domain.
- Description: The signed-digit recoding method of Claim 6 is integrated into the core
Combination with RISC-V Cryptography Extension:
- Description: A custom instruction is added to the open RISC-V instruction set architecture (ISA) as part of its cryptography extension ("Zk"). This instruction,
ecc.mul.ct, performs an entire constant-time scalar multiplication based on the state-based method of Claim 1. The inputs would be pointers to the scalar, base point, and result, and the instruction would execute in a fixed number of cycles determined only by the bit length of the scalar. This hardwires the timing-attack resistance into the processor architecture itself, making it available for any software running on a compliant RISC-V core.
- Description: A custom instruction is added to the open RISC-V instruction set architecture (ISA) as part of its cryptography extension ("Zk"). This instruction,
Generated 5/4/2026, 11:57:14 PM
Keep exploring
More patents asserted by Malikie Innovations Limited
Other patents in Software Technology & Computing Systems (T)
- US 9954872Here is a concise summary of US Patent 9954872: US Patent 9954872B2: System and method for identifying unauthorized activities on a computer system using a data structure model Title: System and method for identifying unauthorized…
- US 11789941B2US Patent 11789941B2 is titled "Systems, methods, applications, and user interfaces for providing triggers in a system of record." Assignee: People Center Inc. Inventors: Siddhartha Gunda, Kyle Michael Boston, Daniel Robert Buscaglia…
- US 12032940B2Here's a concise summary of US Patent 12032940B2: Title: Multi-platform application integration and data synchronization Assignee: People Center Inc Inventors: Siddhartha Gunda, Kyle Michael Boston, Daniel Robert Buscaglia, Dilanka Theshan…
- US 11435994B1US Patent 11435994B1, titled "Multi-platform application integration and data synchronization," was issued to People Center Inc. Here is a summary of the patent details: Title: Multi-platform application integration and data…
- US 9215236Here is a concise summary of US Patent 9215236: Title: Secure, policy-based communications security and file sharing across mixed media, mixed-communications modalities and extensible to cloud computing such as SOA [cite: The full patent…
- US 9537900Here's a concise summary of US patent 9537900: US Patent 9537900 Title: Systems and methods for serving application specific policies based on dynamic context Assignee: Avaya Inc. Inventors: Sunil Menon, Shailesh Patel Filing Date…
- US 9693030US patent 9693030, titled "Generating alerts based upon detector outputs," was filed on July 28, 2014, and issued on June 27, 2017. The original assignee was Arris Enterprises LLC, with the current assignee listed as Bison Patent Licensing…
- US 11238344I have analyzed US Patent 11238344 and compiled the requested information. Summary of US Patent 11238344 Title: Artificially intelligent systems, devices, and methods for learning and/or using a device's circumstances for autonomous device…
This patent in court (2)
2 tracked lawsuits name US 7020281.