End-to-end double-ratchet encryption with epoch key exchange
patentswarm.com
patentswarm.com
I would think that an academic professor should know better than to try patent something that is already known publicly so well. I can't help but wonder if this is just pure cynicism at work: gaming a broken patent system (for profit), at the expense of (and to hell with) any academic/scientific authority/credibility/reputation. Or is there something I'm completely missing here?
Regardless of whether the patent is granted or not, and unless I'm misunderstanding the whole situation, this professor should probably be deeply ashamed of himself and maybe even be ousted from academia altogether.
EDIT: Not to even start the discussion of how mathematical algorithms shouldn't be patentible in the first place.
EDIT #2: Changed CEO to CTO (typo mistake)
From [1] it says: "Kevin and Denis have hand-selected a talented team of seasoned leaders in engineering, physics, and cryptography to build Qrypt’s patented solution." I guess they can add "patent pending", too.
[1] https://www.qrypt.com/about
[2] https://www.ornl.gov/news/qrypt-licenses-ornls-quantum-rando...
I would call that claim first and foremost convoluted, more than specific and detailed, but that is a rather normal practice in patents (IFAIK).
From what I've read (so far), I didn't see anything particularly innovative; not within the field of crypto at least. I'm quite confident that this is nothing particularly new to a crypto expert. I'd say it's all rather well known. Maybe not to Joe next door, but that's irrelevant.
I'd say that this patent should never have been granted, but I can't say that I'm surprised that it did. However, those who filed for this patent must have known what they were doing. Unless my current view on this radically changes, I sincerely hope that it will (somehow, eventually) cost the people involved dearly. I have no sympathy for anyone who would game a broken system like that, as it so far appears they did. Even if not criminal, legally speaking, I still consider it moral corruption to a high degree.
There's a difference between not asking for something, and asking for something not to happen.
Besides.. There are many cases where it's a he-said-she-said debate with no clear truth, or where the ethics aren't entirely clear to begin with. But sometimes you're just dealing with the identity killer[0].
The relevant part of the patent application:
> The Axolotl Ratchet aka the Double Ratchet Algorithm is modeled on the Diffie-Hellman asymmetric ratchet in the Off-the-Record (OTR) messaging system and symmetric key ratchets used by the Silent Circle messaging protocol, resulting in the currently ubiquitous Signal Protocol.
It goes on to say "While there are a limited number of security proofs of specific implementations, there are none for the generalized protocol". So even if the patent were to be granted on the basis of that this is general instead of specific, then the specific Signal protocol should not be in violation of this patent.
You might remember "But X" patents from when they were all for the Internet. You know "It's a bookshop but Internet" or "It's paying for a magazine subscription but Internet". Some of these patents were subsequently invalidated, many made their "Inventors" plenty of money anyway.
Most of today's sensible crypto designs can be mechanically transformed into something safe for a post-quantum world by sprinkling the right post-quantum ingredients in the right places and putting a XOR somewhere.
The "great" thing about patents is that you can be vague about parts that you don't specifically claim, to the point where they aren't even invented yet, and still succeed in the application. You have to guess that the missing pieces will get discovered, doesn't matter who by, before you stop being able to incrementally file modified patents for the same "invention" and then you can collect all the money because your "invention" is essential.
So they won't even need to propose a specific post quantum algorithm anywhere, they can leave that as a black box. When something gets invented, their patent covers it being used in the obvious way.
This sort of nonsense is another reason patents should be scrapped rather than reformed.
If you look at a patent and say: "This isn't valid because of patent X," but you see patent X in the list of citations, then it means the patent office has already said: "Oh yes it is."
> ... following CANNOT be considered as inventions within the meaning of the act. "A mathematical or business method or a computer program or algorithms"
This doesn't mean I'm in favor of or against software patents, I know too little about the topic. I just wanted to say that this isn't that trivial, and if it were, it would not be patentable: https://en.wikipedia.org/wiki/Patentability
Generalized patent for using post-quantum cipher together with double ratchet takes two hard things that have taken a ton of hard work and basically makes the claim they were the first ones to discover they are compatible and that it's a good idea -- which is not the case, key exchange algorithms are trivial to plug into protocols. They are implemented separately to be used together. It's like trying to patent portable music player, but with open design headphones! It took the industry a lot of time to come up with portable music players, and good headphones also took time and effort, but a generalized patent for using them together is just nonsense.
We aren't complaining about the system as it is supposed to work, but rather how it works in practice.
If you want to say what you think is important about an article, do not do so by cherry-picking a detail to put in the title. Instead, post it is a comment in the thread. Then your view will be on a level playing field with everyone else's.
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
https://news.ycombinator.com/newsguidelines.html
Edit: since https://twitter.com/AlecMuffett/status/1213356702399115267 was the context for this, it would have been ok to submit that itself. Note how that tweet doesn't make the same claim. It just asks the question. So even the tweet was editorialized here.
The original title signalled the context of this article which is far more important than the premise. The new title reveals nothing of the context and a layman interpretation changes from 'is someone is trying to patent an existing crypto algorithm?' to 'some article about some crypto algorithm'.
There's a pretty clear cut line between editorialising (injecting spin or opinion) and clarifying the context of the title.
In this case the change of title was objectively harmful and the traffic to this post died after the admins made the change, because most readers had no indication as to the importance of this anymore.
The original title did not reflect that.
The application was already granted in 2019-09, and is set to expire 20 years from filing, 2039-02-05.
ps: other people have simply said to "read the claims", which is fine but does not help clarify anything.
My concern with patents like this is that, since many of the terms are non-standard and thus defined by the specification, any vagueness in the spec leaves room for future interpretations in an infringement case that may, in fact, lead to de facto Signal implementations being found to infringe.
ETA: I’ll read the spec later this weekend and see how they define all these terms.
I have seen a patent to use SSH to administer a storage system! It was just depressing and sad to see such patents granted and the inventors bragging about it.
People should be embarrassed.
So many nerds have this self-image of being a change-the-world conquering intellect, and then spend their day trying to game a bullshit system to pull a few bucks from their neighbor's pocket. And they're not capable of actually making anything, so they try to patent bog-standard uses of other people's tools.
Their bragging about it is a blessing, though. Makes them easier to avoid.
Sent from my i-branded device
Why should they? This doesn’t affect them.
if Signal is using the technology, and the technology is patented, then Signal will be affected?
Now if you're working on an invention in your basement, and haven't disclosed it yet, someone else can take the same idea to the patent office.
While not all that much relevant in this particularly case (or at least not likely), I've heard from several patent lawyers (granted, this is still hearsay) that it is a rather common practice for big companies to patent any potentially relevant new technologies from smaller players (often when still under development), only to bully these potential competitors.
Considering the high price of patent lawyers, this is sadly a rather effective method for protecting a dominant market position, but it's also very destructive to innovation as a whole (because apparently many of these patents are subsequently never used to actually produce anything).
It's a rather cynical abuse of the system, and one that goes directly against its stated goal: to promote innovation. However, it could also be argued, from the (early) history of patents and how they have been used throughout time, that this has always been a charade, and it really was always more about controlling innovation and technological progress, rather than actually stimulating it.
The title is also misleading as the patent has already been approved apparently.
If I were in the bulk signals collection business, I would also file a patent that legally discouraged the implementation of the best known scheme for end to end encryption as well. Patent office may grant it under pressure.
You can keep doing this back and forth forever as you have time, ratcheting up both variables forever and always assuring any concerned citizens that your goal isn't "really" to just make the variables go up and steal from them, it's just "international agreements" force your hand.
Nobody should fall for this.