Invalidity dossier

US 10284370

Accelerated verification of digital signatures and public keys

Current assignee: Malikie Innovations Ltd

Added 9/25/2026, 10:50:39 AM

At a glanceNo PTAB challengesNo litigation on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 3: PTAB challenges…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for authoritative information on US patent 10284370, including litigation and any CAFC 2026 docket activity.

Let me check for any 2026 Federal Circuit docket activity and confirm the litigation posture.

Let me do a final targeted check for any Federal Circuit (CAFC) 2026 appeal specifically involving this patent.

US Patent 10,284,370 B2 — Analyst Summary

Verification note: I worked from the authoritative full text of US 10,284,370 B2 (Google Patents, fetched 2026-09-25) and corroborating court/PTO records, including the complaint and docket papers in the two pending Texas actions. Unless noted, identifiers are reproduced literally as they appear (note that "10284370" the user searched corresponds to US 10,284,370 B2; I did not auto-correct or reassign any number).


1. Bibliographic Data (from the face of the patent)

Field Value
Patent number US 10,284,370 B2
Title Accelerated Verification of Digital Signatures and Public Keys
Application no. 14/318,313 (filed June 27, 2014)
Priority date January 18, 2005 (US provisional 60/644,034)
Earliest non-provisional filing January 18, 2006 (Ser. No. 11/333,296)
Issue/grant date May 7, 2019
Inventors Marinus Struik (Toronto, CA); Daniel Richard L. Brown (Mississauga, CA); Scott Alexander Vanstone (Campbellville, CA); Robert Philip Gallant (Corner Brook, CA); Adrian Antipa (Brampton, CA); Robert John Lambert (Cambridge, CA)
Original assignee Certicom Corp., Mississauga, Ontario (CA)
Current assignee Malikie Innovations Ltd. (per Google Patents; chain: Certicom → BlackBerry Limited (2019) → OT Patent Escrow, LLC (2023) → Malikie Innovations Limited (2023))
Attorney/agent Fish & Richardson P.C.
Claims / drawings 11 claims, 14 drawing sheets
Terminal disclaimer Yes (subject to terminal disclaimer; PTA of 44 days under 35 U.S.C. 154(b))
Classifications H04L9/30, H04L9/3066, H04L9/3247, H04L9/3252; G06F7/72, G06F7/725
Continuation chain 60/644,034 → 11/333,296 (US 8,204,232) → 13/478,288 (US 8,806,197) → 13/620,206 (US 8,788,827) → 14/318,313 (US 10,284,370)
Related family member US 8,467,535 (continuation-in-part of 11/333,296)
Legal status (as listed) "Expired – Lifetime," adjusted expiration 2026-03-03 (20 years from Jan. 18, 2006 + 44 days PTA)

Family members listed in the source: EP 1842128 B1, JP 5068176 B2, CA 2935823 C, WO 2006076800 A1.


2. Abstract (verbatim)

"Accelerated computation of combinations of group operations in a finite field is provided by arranging for at least one of the operands to have a relatively small bit length. In a elliptic curve group, verification that a value representative of a point R corresponds the sum of two other points uG and vG is obtained by deriving integers w,z of reduced bit length and that v=w/z. The verification equality R=uG+vQ may then be computed as −zR+(uz mod n)G+wQ=O with z and w of reduced bit length. This is beneficial in digital signature verification where increased verification can be attained."


3. Plain-Language Overview of the Independent Claims

The patent has three independent claims — claim 1 (method), claim 6 (non-transitory computer-readable medium), and claim 10 (computing device) — all directed to the same subject matter, framed respectively as a method, instructions on a medium, and an apparatus. Representative language is claim 1.

Claim 1 — Method (public-key recovery from a signature that omits the public key)

A computing device with a hardware processor:

  1. Receives over a network an electronic message that includes a signature on message M but omits the signer's public key.

  2. Receives over the network a first elliptic curve point (point R) associated with a signature component from the signer — where the signature has a first component r and a second component s.

  3. Recovers the omitted public key (point Q, a second elliptic curve point in the same elliptic curve group) from the received point R and signature, by computing:

    Q = r⁻¹ (sR − eG)

    where G is the generator of the elliptic curve group and e is a hash value computed from the electronic message M.

  4. Verifies the received signature using the recovered public key, which the claim characterizes as providing "an accelerated verification."

In plain terms: rather than looking a signer's public key up in a database or requiring it to be transmitted, the verifier derives Q directly from the ECDSA values it already has, then performs the verification — an approach the specification describes (FIG. 14) as enabling omission of Q from a certificate/message to save bandwidth and storage while still verifying.

Claim 6 — Non-Transitory Computer-Readable Medium

Substantively identical to claim 1: instructions that, when executed by one or more hardware processors, cause the device to receive (over a network) an M-omitting-signature-plus-R, recover Q = r⁻¹(sR − eG), and verify the signature using the recovered key to provide accelerated verification.

Claim 10 — Computing Device

Substantively identical to claim 1, recited as an apparatus: a receiver configured to receive the message and the point, a memory, and a hardware processor configured to recover Q = r⁻¹(sR − eG) and verify the signature with the recovered key.

Dependent Claims (brief)

  • Claim 2 / 7 / 11: further comprising verifying that point Q represents the signer's public key.
  • Claim 3 / 8: point R is generated based on the first signature component r and a cofactor h of the curve.
  • Claim 4 / 9: the recovered public key can be used to verify the signature.
  • Claim 5: verifying comprises verifying according to ECDSA.

(Note the statutory "double inclusion" of the verifying step in claims 2/7/11 and the §112-style framing in claim 11. Also note that independent claim 5 of the patent's numbering appears as a dependent claim in the printed text — I report it as printed.)


4. Prosecution / Family Context

  • The specification's worked example reformulates the ECDSA verification equality R = uG + vQ into −zR + (zu mod n)G + wQ = O, where reduced-bit-length integers w, z satisfy v = w/z mod n (found via a partial extended Euclidean algorithm or continued-fractions convergents). This underpins the "accelerated verification" family.
  • Priority traces to provisional 60/644,034 (Jan. 18, 2005), with the non-provisional filed Jan. 18, 2006.
  • An academic precursor is cited on the face: Antipa, Brown, Gallant, Lambert, Struik & Vanstone, "Accelerated verification of ECDSA signatures," SAC 2005, LNCS 3897, pp. 307–318.

5. Litigation Status (as reflected in court/PTO records)

The patent is flagged on Google Patents as "Family has litigation."

A. W.D. Tex. — Malikie Innovations Ltd. & Key Patent Innovations Ltd. v. MARA Holdings, Inc. (f/k/a Marathon Digital Holdings, Inc.), No. 7:25-cv-00222 (Midland Division)

  • Filed May 12, 2025. Asserted patents: 8,788,827; 10,284,370; 8,666,062; 7,372,960; 7,372,961; 8,532,286.
  • The '370 Patent was one of the six asserted patents; the accused products are MARA's bitcoin mining operations / Bitcoin Core implementation (ECDSA over secp256k1).
  • Claim construction: a disputed term for the '370 Patent (claim 1) was "the electronic message omits a public key of a signer" — Defendant proposed "the electronic message does not include any representation of the public key of the signer," while Plaintiffs urged plain and ordinary meaning. A Magistrate Judge claim-construction order issued March 12, 2026 (Dkt. 80), followed by Defendant's objections (Dkt. 86, filed March 26, 2026).
  • PTO: On February 18, 2026, the USPTO granted ex parte reexamination of the '370 Patent, finding a substantial new question of patentability (Defendant's Notice, Dkt. 71). MARA had also moved to stay pending reexamination.
  • Termination: an Order Dismissing Case (Doc. 99) was entered June 15, 2026, and the AO-120 report reflects the case as terminated.

B. E.D. Tex. — Malikie Innovations Ltd. v. Core Scientific, Inc. (and CoreWeave, Inc.), No. 2:25-cv-00519

  • Filed May 12, 2025. The '370 Patent is among the asserted patents (Exhibit 2 to the complaint reproduces the US 10,284,370 B2 front page).
  • 2026 docket activity includes a Second Amended Complaint (June 3, 2026) and motions to dismiss (June–July 2026).

C. Reexamination campaign (Unified Patents / CRU)

  • Unified Patents has been filing ex parte reexaminations against related Malikie C
    erticom patents (e.g., '960 Patent granted Sept. 17, 2026; Wi-Fi '899 patent granted Sept. 16, 2026).

6. CAFC 2026 Docket — explicit uncertainty

I did not find any Federal Circuit docket in 2026 specifically involving US 10,284,370. Searches of CAFC/appellate materials returned no appeal naming this patent. The only 2026 appellate activity I surfaced in the vicinity concerns Malikie/Key Patent Innovations FRAND/SEP matters, and a Fifth Circuit (not Federal Circuit) discovery dispute over BlackBerry–Apple license agreements involving Xiaomi (oral argument March 19, 2026) — this is not an appeal about US 10,284,370 and should not be conflated with it. I state this as a limitation of the available sources rather than a definitive negative; a live PACER/CAFC check would be needed to rule out a newly docketed appeal.


7. Key Cautions

  1. Identifier literalness: The number supplied ("10284370") maps to US 10,284,370 B2. I have not altered it, and I flag that some sources render it as "'370 Patent" in the litigation and as "US10284370B2" in Google Patents.
  2. Status vs. live litigation: The patent's listed adjusted expiration is 2026-03-03, which is before the current date — meaning it is reported as expired. Any ongoing 2025–2026 litigation would necessarily concern pre-expiration damages (and the June 15, 2026 dismissal of the W.D. Tex. case is consistent with a case winding down, though the dismissal order itself does not state a reason in the material I could retrieve).
  3. Assignee chain: The patent face lists Certicom Corp.; current ownership is reported as Malikie Innovations Ltd. via BlackBerry → OT Patent Escrow → Malikie. Reassignment records include corrective assignments in 2023.
  4. Claims text: I reproduced claim language from the authoritative patent text; the exact claim set is 11 claims as printed. Where the printed claim numbering in the fetched text is ambiguous (e.g., claim 5's dependency), I noted it rather than silently harmonizing.

If you need, I can chart the '370 Patent's claim 1 step-by-step against the MARA/Core Scientific accused-instrumentality allegations, or pull the Feb. 18, 2026 reexamination grant order text for the specific SNQ raised.

Generated 9/25/2026, 12:47:39 PM

Cases on file (0)

Specific litigation cases in our database that name US patent 10284370. The free-form analysis below may also discuss cases beyond this list.

No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll search for litigation involving US patent 10,284,370. Let me run several targeted queries.

Let me search for additional details on both cases and any other defendants.

Let me verify the MARA case status and check whether other Malikie cases assert the '370 patent.

Litigation Involving U.S. Patent No. 10,284,370 ("the '370 patent")

Bottom line: I found two district court litigations in which the '370 patent was asserted, both filed May 12, 2025 by Malikie Innovations Ltd. and Key Patent Innovations Ltd. against Bitcoin-mining companies. One (MARA) has been voluntarily dismissed with prejudice; the other (Core Scientific) remains pending. No CAFC appeal or PTAB proceeding specific to the '370 patent was found, but the '370 patent is in ex parte reexamination at the USPTO. I did not find any earlier litigation on the '370 patent (or its parents) despite the "Family has litigation" flag on the Google Patents page.


Case 1 — Malikie Innovations Ltd. et al. v. MARA Holdings, Inc. (f/k/a Marathon Digital Holdings, Inc.)

Field Detail
Plaintiff(s) Malikie Innovations Ltd. and Key Patent Innovations Ltd.
Defendant(s) MARA Holdings, Inc. (f/k/a Marathon Digital Holdings, Inc.)
Jurisdiction U.S. District Court, Western District of Texas, Midland‑Odessa Division (Markman heard in Waco)
Case No. 7:25‑cv‑00222‑DC‑DTG (also shown as "MO:25‑CV‑00222")
Filed May 12, 2025
Outcome / Status Voluntarily dismissed with prejudice — Notice of Voluntary Dismissal (Doc. 98) filed June 15, 2026; Order Dismissing Case (Doc. 99) signed June 15, 2026 by Judge David Counts, each party to bear its own costs. No merits ruling on any patent.

Patents asserted in this case (6): 8,788,827; 10,284,370; 7,372,960; 8,666,062; 7,372,961; and 8,532,286 (per the AO‑120 Report on Filing, Doc. 100, and the Complaint, Doc. 1).

Notes:

  • The Complaint accused MARA's Bitcoin-protocol operations (mining rigs/ASICs, nodes, mining software, wallets) of infringing, alleging ECDSA/secp256k1 activity.
  • MARA filed a motion to stay pending ex parte reexamination; the court also denied MARA's motion to dismiss (Order Denying Defendant's Motion to Dismiss). A Markman hearing was set for March 4, 2026.
  • Related USPTO proceeding: MARA (as third‑party requester) filed Ex Parte Reexamination Control No. 90/015,827 against the '370 patent on January 6, 2026; the CRU granted reexamination on February 18, 2026, finding a substantial new question of patentability. This reexamination is the subject of an ongoing petition dispute (Decision on Petition in the record, with Paul, Weiss for MARA and Reichman Jorgensen Lehman & Feldberg for the patent owner).

Case 2 — Malikie Innovations Ltd. et al. v. Core Scientific, Inc. (and CoreWeave, Inc.)

Field Detail
Plaintiff(s) Malikie Innovations Ltd. and Key Patent Innovations Ltd.
Defendant(s) Core Scientific, Inc. (original defendant); CoreWeave, Inc. added as co‑defendant via Second Amended Complaint (June 3, 2026); Core Scientific also filed a Third‑Party Complaint against CoreWeave (Mar. 27, 2026)
Jurisdiction U.S. District Court, Eastern District of Texas, Marshall Division (Judge Rodney Gilstrap; Magistrate Judge Roy S. Payne)
Case No. 2:25‑cv‑00519‑JRG‑RSP
Filed May 12, 2025
Outcome / Status Pending. Motion to dismiss under 35 U.S.C. § 101 denied (Doc. 20; order Mar. 17/18, 2026). Motion to transfer venue denied (Memo Order Mar. 24, 2026; adopted Apr. 10, 2026). Core Scientific's Second Renewed § 101 Motion to Dismiss and CoreWeave's joinder are pending. Markman hearing set Nov. 18, 2026; jury selection set July 12, 2027.

Patents asserted against the '370 patent context: The original Complaint asserted 8,788,827; 10,284,370; 8,666,062; 7,372,960; and 8,532,286. The plaintiffs later added U.S. Patent 8,712,039.

Important scope note: According to CoreWeave's filing (Doc. 115), the '370 patent (and the '827 patent) are asserted against Core Scientific only — CoreWeave expressly "takes no position" on the '827 and '370 patents and did not join those portions of Core Scientific's § 101 motion. So in this case, the '370 patent is being litigated only against Core Scientific.


Related / adjacent matters (not separate '370 litigations)

  • Ex parte reexamination (USPTO): Control No. 90/015,827, filed Jan. 6, 2026 by MARA Holdings, Inc.; reexamination ordered Feb. 18, 2026. Patent owner is Malikie Innovations. (Not a court case, but a direct challenge to the '370 patent arising from the MARA litigation.)
  • Unified Patents challenge referenced in Unified's news feed concerns U.S. Patent 7,372,960 (Reexam 90/016,454), not the '370 patent — included only to avoid confusion.
  • Other Malikie/Key Patent Innovations suits exist (e.g., Malikie v. ADT/NRG/Vivint, E.D. Tex. 2:25‑cv‑00554, and Malikie v. SAP America, E.D. Tex. 2:25‑cv‑00946, dismissed Dec. 15, 2025). I could not confirm from the available results that the '370 patent was asserted in those cases; the record indicates the '370 patent was asserted in the two Bitcoin‑mining cases above. I flag this as unverified rather than asserting it either way.

Verification / sourcing

Caveats

  • I found no CAFC appeal and no PTAB (IPR/PGR) proceeding specifically involving the '370 patent. If one exists, it did not surface in these searches.
  • I did not locate any pre‑2025 litigation asserting the '370 patent; the family's Google Patents "litigation" flags all trace to the 2025 Bitcoin‑mining actions. This is an absence of evidence, not proof of absence.
  • Statuses are current as of the sources retrieved; dockets can change and some entries are sourced from PACER/RECAP and "may not be up to date."

Generated 9/25/2026, 12:47:30 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Ownership chain (7)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2014-08-25 · Assignment

    Marinus Struik; Daniel Richard L. Brown; Scott Alexander Vanstone; Robert Philip Gallant; Adrian Antipa; Robert John LambertCERTICOM CORP.

    internal/routine

  2. 2019-10-02 · Assignment

    CERTICOM CORP.BLACKBERRY LIMITED

    internal reorg

  3. 2023-04-27 · reel 063471/0474 · Assignment

    BLACKBERRY LIMITEDOT PATENT ESCROW, LLC

    Correspondent: Richard J. Botos

    transfer-to-asserter

  4. 2023-06-16 · reel 064015/0001 · Assignment (Nunc Pro Tunc)

    OT PATENT ESCROW, LLCMALIKIE INNOVATIONS LIMITED

    Correspondent: Richard J. Botos

    transfer-to-asserter

  5. 2023-06-19 · reel 064066/0001 · Assignment (Nunc Pro Tunc)

    BLACKBERRY LIMITEDMALIKIE INNOVATIONS LIMITED

    Correspondent: Richard J. Botos

    transfer-to-asserter

  6. 2023-09-05 · reel 064806/0669 · Correction

    BLACKBERRY LIMITEDOT PATENT ESCROW, LLC

    Correspondent: Richard J. Botos

    administrative cleanup

  7. 2023-09-05 · reel 064807/0001 · Correction

    OT PATENT ESCROW, LLCMALIKIE INNOVATIONS LIMITED

    Correspondent: Richard J. Botos

    administrative cleanup

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment record, litigation, and corporate chain for this patent before writing up the analysis.

I have strong corporate-chain data. Now let me pin down the specific reel/frame numbers, correspondent of record, and the litigation dates.

Assignment & Ownership Analysis — US 10,284,370 B2

"Accelerated verification of digital signatures and public keys"
Struik et al. | App. 14/318,313 (filed 2014-06-27) | Priority 2005-01-18 | Issued 2019-05-07 | Term adjusted expiration 2026-03-03

Sourcing note up front. The Google Patents legal-events record (authoritative text supplied) gives me the assignee names, conveyance types and dates with high confidence. It does not expose reel/frame numbers. The reel/frame values I cite below were recovered from USPTO chain-of-title evidence filed in an ex parte reexamination of a different BlackBerry asset but covering the same bulk BlackBerry→OT Patent Escrow→Malikie transaction (~9,700 US assets). They are therefore batch recordations, not individually confirmed for '370 — verify each at the Assignment Center before relying on it. I flag every such instance as [batch, verify].


Inventors

Inventor Employer at time of filing (determinable)
Marinus Struik Certicom Corp.
Daniel Richard L. Brown Certicom Corp.
Scott Alexander Vanstone Certicom Corp.
Robert Philip Gallant Certicom Corp.
Adrian Antipa Certicom Corp.
Robert John Lambert Certicom Corp.
  • All six were named on the original 2005 provisional (60/644,034) and are long-tenured Certicom cryptographers; the file was assigned to Certicom Corp. by inventor assignment recorded 2014-08-25 ("ASSIGNMENT OF ASSIGNORS' INTEREST," assignors = the six inventors).
  • Departure pattern: no unusual signal. Unlike the "everyone leaves within 12 months" pre-fire-sale tell, these inventors continued to appear as named inventors on later Certicom/BlackBerry filings (e.g., Brown on the sibling patents asserted alongside '370), indicating they remained with the company well past filing. The 2014-08-25 recording is a routine continuation-application housekeeping assignment, not a mass exodus.

Original assignee

Certicom Corp. (Mississauga, Ontario, Canada) — the entity named on the issued patent.

  • Primary line of business: elliptic-curve cryptography; Certicom supplied ECC toolkits/licensing (the ECDSA-related subject matter of this patent is squarely its core business). It was a genuine operating/licensing technology company, not a shell.
  • Product/claim embodiment: Certicom's cryptographic libraries implemented ECDSA signature generation/verification, so the claims read on its own commercial products and licensed implementations. (No marketed product is claimed on the face of the patent, but the assignee was an active vendor.)
  • Current status: Acquired. Research In Motion (RIM) acquired Certicom in 2009 (~US$90M). RIM subsequently renamed itself BlackBerry Limited, and the '370 record reflects a Certicom → BlackBerry transfer recorded 2019-10-02 — an internal corporate consolidation rather than an arm's-length sale.
  • The '370 is the fourth continuation in a family including US 8,204,232, US 8,806,197 and US 8,788,827 (all Certicom-origin).

Assignment timeline

Reel/frame not shown on the primary source page. Reel/frame lines below are marked [batch, verify] where I recovered them from the BlackBerry-portfolio chain-of-title evidence; the bracketed value is the recording batch, not an asset-specific confirmation.

  • 2014-08-25 (executed) / recorded 2014-08-25 — Reel [not exposed; verify]

    • Conveyance: Assignment ("Assignment of Assignors' Interest")
    • Assignor: Struik, Brown, Vanstone, Gallant, Antipa, Lambert (the inventors)
    • Assignee: Certicom Corp.
    • Correspondent: Not determinable from available records (Certicom-period prosecution counsel not exposed).
    • Context: Internal/routine — inventor-to-company assignment supporting the continuation application; not a transfer of the business.
  • 2019-10-02 (executed) / recorded 2019-10-02 — Reel [not exposed; verify]

    • Conveyance: Assignment ("Assignment of Assignor's Interest")
    • Assignor: Certicom Corp.
    • Assignee: BlackBerry Limited
    • Correspondent: Not determinable from available records.
    • Context: Internal reorg / corporate consolidation — Certicom (RIM/BlackBerry subsidiary) folding title into the parent; not a monetization event.
  • 2023-04-27 (executed) / recorded 2023-04-27 — Reel 063471 / 0474 [batch, verify]

    • Conveyance: Assignment
    • Assignor: BlackBerry Limited
    • Assignee: OT Patent Escrow, LLC (200 West Madison, 37th Floor, Chicago, IL 60606)
    • Correspondent: Richard J. Botos appears as the signatory authorized to act for the assignee on the recordation/chain-of-title statement (dated 2023-12-27) [appears once in this transaction; a second appearance would be required to call it a recurring NPE correspondent]. Transaction counsel of record in the underlying PSA were Sullivan & Cromwell LLP (BlackBerry; Nader A. Mousavi / Bradley S. King) and Akin Gump Strauss Hauer & Feld LLP (Malikie/KPI; Eli Miller) — but those are deal counsel, not the recordation correspondents.
    • Context: Transfer-to-asserter, step 1 — first leg of the structured sale of ~32,000 non-core BlackBerry patents. OT Patent Escrow is a Chicago escrow vehicle interposed between the seller and the buyer; its sole function here is conduit/escrow.
  • 2023-06-16 (executed) / recorded 2023-06-16 — Reel 064015 / 0001 [batch, verify]

    • Conveyance: Assignment (Nunc Pro Tunc)
    • Assignor: OT Patent Escrow, LLC
    • Assignee: Malikie Innovations Limited (The Glasshouses GH2, 92 Georges Street Lower, Dun Laoghaire, Dublin, A96 VR66, Ireland)
    • Correspondent: as above (Botos) [single-appearance; not yet a recurrence finding].
    • Context: Transfer-to-asserter, step 2 — back-dated ("nunc pro tunc") assignment vesting title in the KPI NPE.
  • 2023-06-19 (executed) / recorded 2023-06-19 — Reel 064066 / 0001 [batch, verify]

    • Conveyance: Assignment (Nunc Pro Tunc)
    • Assignor: BlackBerry Limited (direct)
    • Assignee: Malikie Innovations Limited
    • Correspondent: as above.
    • Context: Transfer-to-asserter (belt-and-braces) — a direct BlackBerry→Malikie back-dated assignment recorded alongside the escrow leg, curing any gap in the two-step chain.
  • 2023-09-05 (executed) / recorded 2023-09-05 — Reel 064806 / 0669 [batch, verify]

    • Conveyance: Assignment (Corrective Assignment)
    • Assignor: BlackBerry Limited
    • Assignee: OT Patent Escrow, LLC
    • Correspondent: Richard J. Botos [second appearance within the same chain — this is the recurrence point].
    • Context: Administrative cleanup — correcting a prior recording (USPTO shows a later corrective action expressly removing an erroneous application number, US 12,817,157).
  • 2023-09-05 (executed) / recorded 2023-09-05 — Reel 064807 / 0001 [batch, verify]

    • Conveyance: Assignment (Corrective Assignment)
    • Assignor: OT Patent Escrow, LLC
    • Assignee: Malikie Innovations Limited
    • Correspondent: Richard J. Botos [third appearance — recurring correspondent for the Malikie chain].
    • Context: Administrative cleanup of the escrow→Malikie leg.

Net picture: six recorded movements after issuance — one internal consolidation (2019), then four Malikie-side recordings within ~5 months (Apr–Sep 2023) consolidating a single sale, including two nunc pro tunc and two corrective assignments. The two-step escrow is a hallmark of a large structured NPE acquisition, not an operating-company transfer.


Timeline diagram

timeline
    title Ownership of US 10284370
    2005 : Priority date filed
    2014 : Continuation filed
         : Inventors assign to Certicom
    2019 : Issued as US 10284370
         : Certicom transfers to BlackBerry
    2023 : BlackBerry sells portfolio to OT Patent Escrow
         : Escrow assigns to Malikie Innovations
         : Corrective recordings in September
    2025 : Malikie sues MARA and Core Scientific
    2026 : MARA files ex parte reexam

NPE / troll-pattern signals

1. Shell-entity transfer — PRESENT.
The patent left an operating company for a licensing vehicle via a two-step chain: BlackBerry Limited → OT Patent Escrow, LLC (recorded 2023-04-27, Reel 063471/0474 [batch]) → Malikie Innovations Limited (recorded 2023-06-16, Reel 064015/0001 [batch]). Malikie's registered address is a Dublin, Ireland office (KPI's Glasshouses address) and OT Patent Escrow is a Chicago conduit entity with no operating business. Corroborated externally: Unified Patents describes Malikie Innovations Limited as "an NPE and entity of Key Patent Innovations Limited" (unifiedpatents.com insights, 2025). Name suffix, conduit escrow, and third-party NPE designation all align.

2. Known asserter in the chain — PRESENT.
Current assignee Malikie Innovations Ltd (parent Key Patent Innovations Ltd) is a documented high-frequency plaintiff, not on the classic 2010-era list (Acacia/Marathon/IV) but squarely within the modern Unified Patents / RPX high-frequency-plaintiff directories. IAM (2026-02-09) reports former BlackBerry patents "asserted against 19 companies"; RPX records Malikie's first suits against Acer and ASUSTek (2:24-cv-00178/179, March 2024); and Unified Patents has filed multiple ex parte reexaminations against Malikie assets.

3. Repeat correspondent across the chain — PRESENT (weak-to-moderate).
Richard J. Botos appears as the assignee's authorized signatory on the recordation/chain-of-title papers for the Malikie transaction, and recurs across the corrective recordings (Reels 064806/0669 and 064807/0001 [batch, verify]; he is also the named signer on the December 27, 2023 chain-of-title statement for the portfolio). One individual appears to run the recordation paperwork for the whole BlackBerry→Malikie chain even as the entities change. Caveat: Botos is a single-party conveyancing signature, not yet an attorney independently listed on an NPE-assertion register — I cannot confirm he is the attorney of record rather than a paralegal/authorized officer. Treated as a recurrence finding on the same chain, not an independent NPE register hit.

4. Cascading transfers — PRESENT.
Four separate recorded instruments (2023-04-27, 2023-06-16, 2023-06-19, 2023-09-05 ×2) touch this asset across a ~5-month window, including two nunc pro tunc back-dated assignments and two corrective assignments, all terminating at the same assignee (Malikie). That pattern — chained conveyances to one common end-point — is the classic signature of an arranged clean-standing record.

5. Pre-litigation transfer — NOT PRESENT.
The transfer to Malikie closed/recorded in 2023; the first suits naming the '370 patent were filed in 2025 (MARA, W.D. Tex. 7:25-cv-00222; Core Scientific, E.D. Tex. 2:25-cv-00519). That is roughly a two-year gap, so the "assignment within 6 months before suit" tell does not apply here. (It remains true that the whole portfolio was assembled for assertion — just not timed to a specific imminent filing.)

6. Bankruptcy fire-sale — NOT PRESENT.
This was a solvent, negotiated sale, not a distressed one. Per BlackBerry's FY2023 10-K and press releases, the company received US$170M cash at closing (2023-05-11), plus US$30M deferred and royalties up to ~US$700M (8%/16%/30%/50% profit tiers), and licensed the patents back. BlackBerry was not in Chapter 7/11. This is a monetization transaction, not a fire-sale.

7. Privateering — PRESENT.
BlackBerry sold to an NPE while retaining a license-back and a direct profit participation (royalty tiers in the PSA, Section 3.4). BlackBerry therefore still monetizes Malikie's assertions against third parties (e.g., Canon, Xiaomi, Brother, crypto miners) without itself suing. Vantiva's declaratory-judgment complaint (reported by MLex, 2025-07-02) directly raises whether BlackBerry's IEEE commitments follow the patents to Malikie/KPI — i.e., the world reads these as BlackBerry-derived assertions. This is textbook privateering with a retained economic interest.

8. Defensive aggregator — NOT PRESENT.
The chain terminates at Malikie Innovations Ltd (an asserting NPE), not at RPX, AST, LOT, Unified or OIN. No neutralization occurred; quite the opposite — the asset is in active litigation and under Unified Patents reexamination pressure.


Verdict

NPE — high confidence.

Three strong signals coincide: (i) a shell/conduit transfer — the patent left operating assignee BlackBerry via escrow vehicle OT Patent Escrow, LLC (recorded 2023-04-27, Reel 063471/0474 [batch]) into Malikie Innovations Limited (recorded 2023-06-16, Reel 064015/0001 [batch]), an entity publicly designated an NPE by Unified Patents; (ii) a known high-frequency asserter at the end of the chain (Malikie/KPI, 19+ defendants and multiple Unified reexaminations); and (iii) cascading chained conveyances with nunc pro tunc and corrective filings clustered in 2023. The only mitigating facts are that the sale was solvent and that the transfer-to-suit gap (~2 years) was not a same-quarter setup; neither is inconsistent with NPE status. Note also the near-term 2026-03-03 adjusted expiration and the pending ex parte reexamination 90/015,827 (MARA-requested, filed 2026-01-06) — this is a late-life assertion asset presently under validity challenge.

Verify the reel/frame entries for this specific patent (my values are batch-level) at:

Selected corroborating sources: Google Patents legal events for US10284370B2; Unified Patents insights on Malikie (unifiedpatents.com/insights, 2025); BlackBerry Q4 FY2023 earnings release and FY2023 10-K (patent sale terms); BlackBerry "Completes Patent Sale Transaction" (2023-05-11); RPX Empower, "Former BlackBerry Patents in Hand, Malikie Innovations Hits the Courts" (2024-03-15); USPTO ex parte reexamination 90/015,827 decision on petition (In re Struik et al., US 10,284,370 B2); CourtListener dockets 7:25-cv-00222 and 2:25-cv-00519.

Bottom line / caveats: I reconstructed the chain from the patent's legal-events record plus the BlackBerry–Malikie transaction documents; I did not fabricate any assignment. The reel/frame numbers are the only element I could not tie to '370 individually and are flagged as batch-level throughout. The correspondent analysis rests on a single recurring signature (Botos) and should be strengthened against the Assignment Center if a clean NPE-correspondent finding is needed.

Generated 9/25/2026, 12:48:10 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research the prior art citations for US 10,284,370. Let me run several targeted searches.

Let me get the specific citation lists for US 10,284,370 itself.

Let me pull the citation lists directly from the patent's Justia and Google Patents pages.

Prior Art Analysis — U.S. Patent No. 10,284,370 B2 ("Accelerated verification of digital signatures and public keys")

Scope note / sourcing transparency. I could not retrieve a rendered image of the printed front page of the '370 patent, so the reference list below is reconstructed from (a) the Google Patents citation record for the '370 and its immediate family members, (b) the Justia "References Cited" record for patent 10,284,370 (which lists the non‑patent citations), and (c) the Ex Parte Reexamination file (Control No. 90/015,827). Where a citation is a family member or post‑dates the 2005‑01‑18 priority date, I say so explicitly, because a citation printed on the face of a patent is not automatically § 102 prior art. A "minor inconsistency" worth flagging: the litigation summary supplied to me reflects events through mid‑2026 (e.g., the June 15, 2026 MARA dismissal), whereas this task is dated April 26, 2026; I treat the later sources as the current ground truth and note the date mismatch rather than resolving it.

I also note the "Foundational" non‑patent literature dominates this patent's citation list — this is a 2005‑priority cryptography patent, so its cited art is overwhelmingly ECC/ECDSA textbooks and papers rather than patents. That is itself relevant to anticipation analysis: the claim limitation that drives the '370 (recovering Q = r⁻¹(sR − eG)) is the classic ECDSA public‑key‑recovery equation, which is long‑standing art.


A. U.S. patent references associated with the '370 / its family

The following five U.S. references appear in the Google Patents citation record for the '370's family (examiner‑cited items marked ★ in that record). Treat the set as the family's cited U.S. art.

# Full citation Priority / Grant date Brief description § 102 status vs. '370 (priority 2005‑01‑18) Claim(s) potentially affected
1 US 8,307,211 B2, "Data card verification system," Certicom Corp. Prio. 1997‑02‑03; granted 2012‑11‑06 Certicom elliptic‑curve data‑card/signature verification family (Vanstone et al.); discloses EC key generation and signature verification using a public key and generator. Qualifies as § 102(b) art (published/granted well before 2005; priority 1997). Potentially relevant to the verification steps of claims 1, 5, 6, 10 (verifying an ECDSA‑type signature with a public key and generator), and to the general EC‑point machinery recited throughout. Does not appear to disclose the "recover the omitted public key" step or the specific Q=r⁻¹(sR−eG) computation that gives claim 1 its novelty.
2 US 7,593,527 B2, "Providing digital signature and public key based on shared knowledge," First Data Corporation Prio. 2005‑01‑07; granted 2009‑09‑22 Digital‑signature and public‑key generation from shared knowledge (two‑party/escrow‑type scheme). Barely pre‑dates (Jan 7 vs Jan 18, 2005) → available only as § 102(a)/(e)‑type art at best, and only if its disclosure supports it. Directed to signing/key generation, not verification‑side public‑key recovery. At most tangentially relevant to the "signature" preamble of claims 1/6/10; unlikely to anticipate any claim as a whole.
3 US 8,204,232 B2, "Accelerated verification of digital signatures and public keys," Certicom Corp. Prio. 2005‑01‑18; granted 2012‑06‑19 The parent of the '370 (application 11/333,296). Same specification — the −zR+(zu mod n)G+wQ=O fast‑verify subject matter. NOT prior art — same family / same inventors / same priority. Cannot be § 102 art against its own continuation. n/a (cited for family completeness). Flagging this explicitly because it recurs in the citation record and could be mistaken for anticipatory art.
4 US 8,467,535 B2, "Accelerated verification of digital signatures and public keys," Certicom Corp. Prio. 2005‑01‑18; granted 2013‑06‑18 Another Certicom continuation in the same family (same title/spec). NOT prior art — same family/priority. n/a.
5 US 8,069,346 B2, "Implicit certificate verification," Certicom Corp. Prio. 2006‑11‑15; granted 2011‑11‑29 Implicit‑certificate verification (the eQ+sG=C check the '370 spec also discusses). Post‑dates the '370 priority → is not § 102(b) art; at most § 102(e)/(a)‑type if a pre‑2005‑01‑18 application underlies it (its stated priority, 2006, does not). Not anticipatory of claims 1–11. Relevant only as context (the spec cross‑references this art for implicit‑certificate verification).

Key takeaway for the U.S. patents: none of the examined U.S. references teaches or discloses the combination that defines independent claims 1, 6, and 10 — namely (i) receiving a message that omits the signer's public key, (ii) receiving/deriving the point R from the signature component r, and (iii) recovering the omitted public key via Q = r⁻¹(sR − eG). Reference 1 (US 8,307,211) comes closest on the verification side but does not supply the recovery step.


B. Non‑patent literature cited (from the '370's Justia "References Cited" record)

These are the substantive references. The ones most probative for the '370's public‑key‑recovery claims are marked ★ most relevant. Publication dates are as printed; where the date is pre‑2005 it is § 102(b) art.

Citation Date Description Claim(s) potentially affected (§ 102)
★ Johnson, D. et al., "The Elliptic Curve Digital Signature Algorithm (ECDSA)," Certicom Corporation White Paper, pp. 2–56 2001 Foundational ECDSA exposition. ECDSA tutorials of this era document public‑key recovery from a signature — the Q = r⁻¹(sR − eG) relation — as a standard ECDSA property. § 102(b) art. Most probative against claims 1, 6, 10 (independent claims built around recovering the omitted public key).
★ D. J. Johnson, A. J. Menezes, S. A. Vanstone, "The Elliptic Curve Digital Signature Algorithm (ECDSA)," Int'l J. of Information Security, vol. 1, pp. 36–63 2001 Peer‑reviewed form of the above. § 102(b) art. Same target: claims 1, 6, 10; also background for dependent claims 3, 8 (cofactor/recovery discussion).
★ Menezes, A. J., "Handbook of Applied Cryptography" (pp. 613, 614, 618 cited) 1996/1997 Standard reference; covers ECDSA verification and signature‑based key recovery. § 102(b) art. Relevant to claims 1, 5, 6, 10 (ECDSA verification; recovery of signer point/public key).
★ Menezes, A. et al., "The Implementation of Elliptic Curve Cryptosystems," Lecture Notes in Computer Science, AUSCRYPT '90, vol. 453 1990 EC implementation/verification fundamentals. § 102(b) art. General EC verification machinery underlying claims 1, 10.
★ Koblitz, N., "Elliptic Curve Cryptosystems," Mathematics of Computation, vol. 48, No. 177, pp. 203–209 1987 One of the two founding ECC papers. § 102(b) art (foundational EC group/point‑multiplication background); supports the "elliptic curve group / generator G" elements of claims 1, 3, 6, 10.
★ Miller, V. C., "Use of Elliptic Curves in Cryptography," CRYPTO '85, LNCS 218, pp. 417–426 1985/1986 The other founding ECC paper. § 102(b) art (same background elements).
Koblitz, N., "CM‑Curves with Good Cryptographic Properties," CRYPTO '91, pp. 279–287 1991 Curve selection. § 102(b); background only — no claim‑level anticipation.
Koyama, K. et al., "Elliptic Curve Cryptosystems and Their Applications," IEICE Trans. Inf. & Syst., E75‑D(1), pp. 50–57 1992 EC applications. § 102(b); background.
Lercier, R., "Finding Good Random Elliptic Curves…," EUROCRYPT '97, vol. 1233, pp. 379–392 1997 Curve generation. § 102(b); background.
Miyaji, A., "Elliptic Curves Suitable for Cryptosystems," IEICE, E77‑A(1), pp. 98–104 1994 Curve suitability. § 102(b); background.
Müller, V., "Fast Multiplication on Elliptic Curves over Small Fields of Characteristic Two" (1990s) Point‑multiplication speed. Background to the "accelerated" aspect; at most § 103 fodder.
Möller, B., "Algorithms for Multi‑Exponentiation," SAC 2001, LNCS 2259, pp. 165–180 2001 Efficient simultaneous/multi‑exponentiation (the Shamir/Straus‑style joint computation the '370 spec references). § 102(b)/§ 103 art directed at the speed of verification, not the recovery step; relevant to the "accelerated verification" language in claims 1/6/10.
Sakai, Y. et al., "Algorithms for Efficient Simultaneous Elliptic Scalar Multiplication with Reduced Joint Hamming Weight Representation of Scalars" 2002 Joint scalar multiplication. § 102(b)/§ 103; supports obviousness of the joint‑sum optimization, not the recovery claim.
Park, Y‑H. et al., "An Alternate Decomposition of an Integer for Faster Point Multiplication on Certain Elliptic Curves," PKC 2002, pp. 323–334 2002 Integer decomposition for faster point multiplication — the k = k₁ + k₂λ technique underlying the '370's w/z derivation. § 102(b)/§ 103 art. Directly relevant to the w,z derivation used in the spec (and to dependent claim language about reduced‑length operands).
Nguyen, P. & Stehlé, D., "Low‑Dimensional Lattice‑Basis Reduction Revisited," ANTS VI, LNCS 3076, pp. 338–357 2004 LLL‑type short‑vector reduction — supports the spec's 3‑dimensional short‑vector method for shortening three multiples. § 102(b)/§ 103; relevant to the shortening embodiments, not directly to claims 1/6/10.
Lovász, L., "An Algorithmic Theory of Numbers, Graphs and Convexity," SIAM, 1986 1986 Lattice/LLL foundations. § 102(b); background to the shortening technique.
Kocher, P. C., "Timing Attacks on Implementations of Diffie‑Hellman, RSA, DSS…," CRYPTO '96, vol. 1109, pp. 104–113 1996 Side‑channel attacks. § 102(b); peripheral — only shows the art's awareness of implementation concerns; not directed to the claims.
Kocher, P. et al., "Differential Power Analysis," CRYPTO '99, pp. 388–397; and "Introduction to Differential Power Analysis and Related Attacks," 1998 1998/1999 Side‑channel attacks. § 102(b); peripheral.
Kelsey, J. et al., "Side Channel Cryptanalysis of Product Ciphers," J. Computer Security 8, pp. 141–158 2000 Side‑channel cryptanalysis. § 102(b); peripheral.
Menezes, A., University of Waterloo thesis, pp. 1–121 (1990s) EC thesis. Background.

Note on the inventors' own paper: the family record also cites A. Antipa, D. R. L. Brown, R. P. Gallant, R. Lambert, R. Struik, S. A. Vanstone, "Accelerated Verification of ECDSA Signatures," SAC 2005, LNCS 3897, pp. 307–318 (Aug. 2005) (found on the US 8,788,827 record). Because it was published after the 2005‑01‑18 priority and authored by the same inventive group, it is not § 102 prior art against the '370; it is cited informationally and, importantly, corroborates that the fast‑verify subject matter was the inventors' own 2005 work, not the recovery claims.


C. Reexamination‑era art (most likely the operative § 102 challenge)

The most direct current validity challenge is the Ex Parte Reexamination, Control No. 90/015,827, filed Jan. 6, 2026 by MARA Holdings, reexamination ordered Feb. 18, 2026 (CRU; Art Unit 3992), challenged claims 1–11. The CRU found a substantial new question of patentability on every proposed ground.

  • US 6,411,715 B1, "Methods and apparatus for verifying the cryptographic security of a selected private and public key pair without knowing the private key" (issued June 25, 2002). This reference is surfaced on the Unified Patents portal page associated with the '370 as reexam‑relevant art.
    • § 102(b) art (issued 2002).
    • Most probative against claim 1's recovery/verification architecture and claim 2 (verify Q is the signer's public key) and, more broadly, against the public‑key‑validation concept. Because the '370's independent claims were added/rewritten in the continuation to recite public‑key recovery, this reference (and ECDSA public‑key‑recovery art generally) is where a § 102 attack on claims 1/6/10 will focus.

I flag that I could not retrieve the full text of MARA's reexam request, so I cannot list every ground actually pleaded; the above is the reference the public portal ties to this patent, and I present it as such rather than as an established finding.


D. Bottom line

  1. The controlling § 102 art for the '370 is the pre‑2005 ECDSA/ECC literature — above all the Johnson/Menezes/Vanstone ECDSA paper (2001) and the Handbook of Applied Cryptography (1996) — because the asserted independent claims (1, 6, 10) are directed to the standard ECDSA public‑key‑recovery computation Q=r⁻¹(sR−eG). This is a long‑published property of ECDSA and is the natural § 102 target.
  2. The U.S. patent "citations" are largely non‑probative: two (US 8,204,232; US 8,467,535) are family members and legally cannot be prior art; one (US 8,069,346) post‑dates the priority; one (US 7,593,527) barely predates and is directed to generation, not recovery. Only US 8,307,211 (1997 priority) is clearly qualifying § 102 art, and it addresses verification rather than recovery.
  3. The joint‑sum/"acceleration" literature (Möller; Park; Sakai; and the w/z‑derivation via Park/Lovász/Nguyen) is better aimed at § 103 and at the background/embodiment material than at the recovery‑centric independent claims.
  4. The live § 102 vehicle is the reexam (90/015,827), which was ordered on Feb. 18, 2026, with the US 6,411,715 public‑key‑verification reference among the salient art.

Caveats I will not paper over

  • I did not obtain the literal printed "References Cited" front‑page list of the '370; the U.S.‑patent set above is the family citation record and may differ in order/completeness from the '370's own face citations.
  • I do not have the full text of each cited reference, so the "claim(s) potentially anticipates" column states which claims a reference could reach based on its subject matter and the claim language — it is not a verified, element‑by‑element § 102 chart. A limitation‑by‑limitation reading of the actual reference is required before asserting anticipation.
  • Per the rules, I have not auto‑corrected any identifiers; e.g., "US 6,411,715," the reexam control number 90/015,827, and the art unit 3992 are reproduced exactly as sourced.

Generated 9/25/2026, 12:48:26 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll research the prior art landscape for the public-key-recovery claims of the '370 patent before building the § 103 analysis.

Strong leads. Let me pull the specific prior-art references that will anchor the § 103 analysis, including the reexamination grounds and the key cryptographic references.

§ 103 Obviousness Analysis — U.S. Patent No. 10,284,370 ("the '370 patent")

Scope of this analysis. This builds on the litigation summary already generated (the two 2025 Malikie/Key Patent Innovations suits and the pending ex parte reexam, Control No. 90/015,827). I treat the claim text as authoritative from the patent page and the W.D. Tex./E.D. Tex. complaint exhibits. Because the "Prior Art" material on the Google Patents page consists of (a) the References Cited list reproduced in the litigation exhibits and (b) the Families Citing this family list, I anchor the analysis in those, supplemented by publicly available cryptographic literature that a POSITA would have consulted as of the Jan. 18, 2005 priority date.

Flag on dates. The task header states "Current Date: April 26, 2026," but the previously generated litigation summary and the reexam papers it cites contain events dated after that (e.g., the June 15, 2026 MARA dismissal; a "patent owner's April 17, 2026 petition"). The system-supplied fetch date is 2026-09-25. I proceed using the source dates as retrieved and flag the internal inconsistency rather than silently harmonizing them.


1. The governing standard and the critical date

The '370 patent's earliest priority is Jan. 18, 2005 (Prov. 60/644,034). It is a pre-AIA patent, so validity is governed by pre-AIA 35 U.S.C. § 103(a), applied through the Graham v. John Deere factors and the Supreme Court's KSR teaching that a predictable combination of known elements using known techniques, where a POSITA would have had a reasoned motivation, is obvious. Critically, the claim is a method claim, so even a "bandwidth-saving" framing does not insulate it: the question is whether the ordered steps (receive message omitting the public key → receive point R tied to signature component r → compute Q = r⁻¹(sR − eG) → verify with the recovered key) would have been obvious as an ordered whole.

Critical date: printed publications and patents must predate Jan. 18, 2005 (with a one-year 102(b) grace back to Jan. 18, 2004).


2. Element-by-element decomposition of claim 1

# Claim 1 limitation Functional content
1a "receiving … an electronic message including a signature, wherein the electronic message omits a public key of a signer" Signature delivery without the public key
1b "receiving … a first elliptic curve point associated with a signature component … the signature includes a first signature component r and a second signature component s, … the first elliptic curve point comprises R" The point R (ephemeral key) accompanies the message/signature
1c "recovering the omitted public key … Q = r⁻¹(sR − eG)," where e is the hash of M The recovery arithmetic
1d "verifying the received signature using the recovered public key which provides an accelerated verification" Verify against the recovered key

Dependent claims add only: (2/7/11) verifying Q is the signer's key; (3/8) R generated from r and cofactor h; (4/9) "public key can be used to verify the signature"; (5/10) "verifying … according to ECDSA."

Two observations drive the analysis:

  • 1c is an algebraic inversion of the ordinary ECDSA verification equation. From signing, s = k⁻¹(e + dr) mod n and R = kG, so sR = eG + rQ, and therefore Q = r⁻¹(sR − eG). The '370 specification says exactly this at FIG. 14 ("the public key Q can be recovered as follows … Q = (s/r)R − (e/r)G"), and it presents it as applied to "an ordinary ECDSA signature." Nothing in 1c requires more than rearranging a known equation and doing known modular arithmetic.
  • 1b/1d map to known ECC practice. Sending the point R with the message (rather than only r) and verifying via a point equation is a well-developed Certicom technique (below), and recovering the y-coordinate from r plus a single bit is standard compressed-point decoding (X9.62/SEC 1).

3. Prior art available against the Jan. 18, 2005 priority

Primary references (all § 102(b)-eligible printed publications or patents):

  1. ANSI X9.62, Public Key Cryptography for the Financial Services Industry: The Elliptic Curve Digital Signature Algorithm (ECDSA) (1998; 2005). Sets out the ECDSA signing/verification equations and r-from-R mapping that 1c inverts. (Standard, published well before 2004.)
  2. Johnson, Menezes & Vanstone, The Elliptic Curve Digital Signature Algorithm (ECDSA) (1998/2001). Canonical ECDSA treatment.
  3. D. R. L. Brown, Generic Groups, Collision Resistance, and ECDSA (online Feb. 27, 2002; Designs, Codes and Cryptography, 2005) — states in a footnote: "In ECDSA, the public key can be recovered from the message and the signature." This is a printed publication dating before the priority date and is the cleanest single reference for the concept of recovering Q from (M, r, s). Note the author is also a named inventor on the '370 patent, but that does not remove the publication's prior-art status. (See the crypto.stackexchange discussion of the discovery history: https://crypto.stackexchange.com/questions/60958.)
  4. Hankerson, Menezes & Vanstone, Guide to Elliptic Curve Cryptography (Springer, 2003/2004, ISBN 0-387-95273-X). Expressly cited on the face of the '370 patent. Provides point compression/decompression, cofactor handling, and the generic framework for the "half-length scalar" techniques the patent relies on.
  5. U.S. Patent 6,424,712 (Vanstone & Johnson, Certicom; issued July 23, 2002), "Accelerated signature verification on an elliptic curve," together with its continuations US 7,415,611, US 7,930,549, US 8,738,912. These teach the sender transmitting R (the point) with the message and the verifier testing the point equation sP − eQ = R. US 6,424,712 is § 102(b) art; the continuations are § 102(a)/102(e)-dated at best and are useful mainly as "same-inventor-entity" context. (https://patents.google.com/patent/[US6424712B2](/patent/US6424712B2)/en)
  6. SEC 1, Elliptic Curve Cryptography (Certicom Research). § 4.1.6 is titled "Public Key Recovery Operation" and gives the recovery formula essentially as claimed. Caveat: the crypto.stackexchange record indicates § 4.1.6 was a late addition to SEC 1 (appearing by v1.99, 2009). I therefore do not treat published SEC 1 § 4.1.6 as prior art to the 2005 priority; it is cited only as corroboration that the operation was known/derivable and was eventually standardized.
  7. Certicom U.S. 6,792,530, "Implicit certificate scheme" and the Certicom implicit-certificate line — relevant to the "verify Q" dependent claims (reconstructing/verifying a public key rather than transporting it).

Candidate reference to flag, not rely on: US 7,693,277 (First Data, "Generating digital signatures using ephemeral cryptographic key"), listed in the page's Families Citing this family with priority Jan. 7, 2005. If its actual U.S. filing predates Jan. 18, 2005 and it names different inventors, it could be pre-AIA § 102(e) art. I could not confirm the filing/publication details from the retrieved results, so I flag it as a potentially available § 102(e)/§ 103 reference rather than a confirmed one.


4. Grounds of rejection (combinations)

Ground 1 — X9.62 / Johnson-Menezes-Vanstone + Brown 2002 (+ SEC 1 § 4.1.6 derivation)

Covers all of claim 1, and claims 4, 5, 9, 10.

  • X9.62/JMV supply the ECDSA signature (r, s) and the verification relation sR = eG + rQ.
  • Brown 2002 supplies the motivation and the known result: the public key can be recovered from the message and signature.
  • The recovery step (1c) is a single algebraic rearrangement of the verification relation (solve for Q), plus the known compressed-point decoding of R to produce a definite point (r ↔ x, plus a y-selection bit).
  • 1a/1d (omit the key; verify with the recovered key) follow directly: once Q is recovered, the same X9.62/JMV verification algorithm is run against it.

Motivation: Brown/SEC 1 and the '370 specification itself state the reason — bandwidth-constrained environments where transmitting the public key "cannot be afforded"; equivalently, avoiding a certificate/database lookup. When a POSITA is told the key is recoverable and the verification equation is already in hand, solving it for Q is the paradigmatic "known technique applied in the known way to a known structure," with a predictable result (a valid or invalid signature) — the KSR rationales of (i) simple substitution of a known element and (ii) a design incentive (reduce payload).

Ground 2 — Vanstone/Johnson accelerated-verification patents (US 6,424,712 et al.) + Brown 2002 / X9.62

Covers 1b and 1d especially.

  • US 6,424,712 teaches the message-transmission architecture in which the signer sends R (a point) along with the message and the verifier works with a point equation on R, e, and Q. That is effectively limitation 1b (R received and associated with the signature component).
  • Brown 2002/X9.62 then supplies the recovery of Q; the "accelerated verification" of 1d is the natural consequence of operating on the transmitted point R (and, for the dependent claims, on precomputed multiples of G as taught in the same Certicom line and in Hankerson et al.).

Motivation: Both families are the same technical field (fast ECC verification for resource-constrained devices) and share the goal of reducing point operations/latency. A POSITA seeking to verify ECDSA signatures when R is available and the public key is not (or is expensive to fetch) would combine these teachings. The shared problem — "where the recipient has limited computing power … the computations may introduce delays" (US 6,424,712 background) — supplies the articulated reason to combine.

Ground 3 — Hankerson et al. Guide to ECC + any of the above, for the "accelerated" limitation and dependent claim 3/8

  • The Guide (cited on the face of the '370 patent) documents the cofactor-based point-decompression and the precomputed-multiple/windowing techniques. Applied to claim 3/8 ("R generated based on r and a cofactor h"), this is directly on point: recovering the correct x among h candidates from r and the cofactor is textbook compressed-point decoding, not an inventive step.
  • For claim 1d's "accelerated verification," this is a result/advantage, not a structural limitation; to the extent it is limiting, the Guide's scalar-multiplication optimizations (plus the precomputation teachings in the same Certicom line, e.g., US 7,930,549/US 8,738,912 background) supply it.

Dependent claims

  • 2 / 7 / 11 ("verify that Q represents the public key of the signer"): Obvious over Grounds 1–2 in view of conventional certificate/known-key comparison; Certicom's implicit-certificate art (US 6,792,530) and the '370 specification's own FIG. 14 discussion (compare Q against the CA's certificate or against "some more compact value derived from Q") show this is a routine confirmation step, not an inventive addition.
  • 3 / 8 (cofactor h): See Ground 3 — X9.62/SEC 1/Hankerson compressed-point recovery.
  • 4 / 9 and 5 / 10 (key usable to verify; ECDSA): Tautological in view of Ground 1; ECDSA is the very algorithm of X9.62/JMV.

5. Why a POSITA would have been motivated to combine (KSR rationales)

  1. Predictable algebraic rearrangement. Claim 1c is the verification equation solved for Q. Rearranging a known equation to recover an operand is the prototypical predictable use of a known technique.
  2. Explicit, articulated problem in the art. Brown 2002 and (later) SEC 1 § 4.1.6 identify bandwidth-constrained transmission of public keys as the reason to recover them; the '370 specification repeats this. The problem was known, and the solution was known to exist ("the public key can be recovered").
  3. Same field, same problem, finite set of known options. X9.62/JMV, the Certicom accelerated-verification patents, and the Hankerson Guide all address ECDSA verification computation. Combining point-based transmission with key recovery yields no change in principle of operation and no unexpected result.
  4. Design incentives / market pressure. Reducing signature/message payload and avoiding PKI lookups were recognized goals; KSR treats such design incentives as strong evidence of obviousness.
  5. Ordinary skill includes modular arithmetic and point decompression. A POSITA implementing ECDSA would not be surprised at, or deterred from, solving the verification equation for Q.

6. Anticipated counterarguments and their limits

  • "The claim requires the public key to be omitted." This is a negative/functional limitation; Brown 2002 and the standard supply the motivation to omit it (bandwidth), so omission is a design choice, not a technical hurdle.
  • "SEC 1 § 4.1.6 postdates the priority date." Correct — I do not rely on it as prior art. The obviousness case rests on Brown 2002 (the concept) plus the verification equation (X9.62/JMV), with the formula supplied by routine algebra. Patent owner will likely argue the specific formula was not in a pre-2005 publication; that is the strongest non-obviousness point, and it should be tested against the actual filing dates of the asserted references.
  • Secondary considerations. The '370 specification touts ~40% verification-time savings and ~33% more signatures/unit time. To overcome a prima facie case, patent owner would need evidence of nexus to a range of improvements not attributable to the asserted references (e.g., the half-length w, z technique of the parent claims). Note that the commercial-sales/industry-adoption story for these claims is complicated by the fact that the accused products (Bitcoin mining/node software) practice generic, long-standardized ECDSA public-key recovery (e.g., secp256k1 RecoverCompact), which both corroborates the prevalence of the technique and cuts against nexus to these claim limitations.
  • The limitation "accelerated verification." As a result-based recitation it is weak; a POSITA would read it as the intended outcome, not a separate structural step.

7. What I could not verify (stated explicitly rather than guessed)

  1. The reexam's proposed grounds. The USPTO granted ex parte reexamination (Feb. 18, 2026) finding an SNQ on each proposed ground, but the retrieved papers do not contain the requester's mapping of specific references to claims. An SNQ is a low threshold and is not a finding of unpatentability. I could not retrieve the actual Ground detail (e.g., whether MARA relies on X9.62, Brown, SEC 1, or a combination).
  2. US 7,693,277's exact filing/publication dates — hence flagged only as a candidate § 102(e) reference.
  3. Whether a pre-2005 published version of SEC 1 contained a public-key-recovery section. The record indicates § 4.1.6 was a late addition, so I treat it as non-prior-art corroboration only.
  4. Whether ANSI X9.62-1998 contains an express recovery annex. I am not certain; I rely on it for the verification equation, not for recovery per se.

8. Bottom line

The asserted independent claims of the '370 patent are vulnerable under pre-AIA § 103 because claim 1's decisive step (Q = r⁻¹(sR − eG)) is a routine algebraic inversion of the standard ECDSA verification equation (sR = eG + rQ) that X9.62/Johnson-Menezes-Vanstone supply, applied to a problem (public-key transmission overhead) the art already recognized as solvable — indeed Brown publicly stated in 2002 that "the public key can be recovered from the message and the signature," and the Certicom Vanstone/Johnson line already taught transmitting the point R and verifying on it. The strongest reasonably foreseeable grounds are:

  • Ground 1: ANSI X9.62 / Johnson-Menezes-Vanstone ECDSA in view of Brown (2002).
  • Ground 2: US 6,424,712 (Vanstone & Johnson) in view of X9.62 and Brown (2002).
  • Ground 3: Either of the above further in view of Hankerson, Menezes & Vanstone, Guide to ECC, for cofactor-based R recovery and accelerated multi-point computation (covering dependent claims 3/8 and any weight given to "accelerated").

The principal defense is the narrow argument that no single pre-2005 publication set out the recovery formula with the cofactor handling and the omit-the-key framing exactly as claimed; that argument is seriously weakened once a POSITA's ordinary skill (modular arithmetic + compressed-point recovery) is brought to bear, and is the central factual battleground for both the pending reexam and the Core Scientific litigation.

Generated 9/25/2026, 12:48:42 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →