[105674] in Cypherpunks
Re: Rivest Patent
daemon@ATHENA.MIT.EDU (Eric Cordian)
Wed Nov 18 20:47:57 1998
From: Eric Cordian <emc@wire.insync.net>
To: cryptography@c2.net, cypherpunks@cyberpass.net
Date: Wed, 18 Nov 1998 19:31:19 -0600 (CST)
Reply-To: Eric Cordian <emc@wire.insync.net>
Vin McLellan <vin@shore.net> writes:
> Eric Michael Cordian <emc@wire.insync.net> -- the "Nym" or pseudonym
> for someone who says he is a group of people, and who has been
> collecting $500 donations from folks willing to help the Cordian Group
> sponsor an algebraic attack on the DES (See the "DES Analytic Crack
> Project" at http://www.cyberspace.org/~enoch/crakfaq.html) -- spun
> off an individual voice to respond:
What does the above have to do with the RSA patent? Although I must
admit that baiting Matt Blaze into falsely believing that his name was
being used to solicit funds for the project was a clever and
perfidious touch, and illuminating of the type of shenanigans persons
of your ilk are likely to engage in.
[Poll of two people who have not seen modular exponentiation described
as a cryptographic technique prior to 1977 deleted.]
> In the commercial world, on the other hand, it's hard to think of
> priceless information being kept secret (particularly when it is only
> worth something if it is on a bargaining table.)
The thing which has made RSA "priceless" is RSADSI's aggressive
litigation posture. Indeed, patents are not by any stretch of the
imagination "peer-reviewed" documents, as is evidenced by patents on
things such as byte-ordering, XOR encryption, and schemes which claim
to compress any string of bits into a smaller string of bits.
If you patent something, even something obvious, sue at the drop of
the hat, and argue anyone who criticizes it into the ground, you can
generally enforce a patent on virtually anything, especially if you
license the technology for a reasonable fee, with the patent holder
spending his own money to hold customers harmless over any legal
challenges which may arise.
Ones legal position is of course enhanced, and one is more likely to
prevail in court, if ones patents reign in the free proliferation of
technology the government would rather keep under closer control.
>>>> Only a complete moron would place himself in the
>>>> position of trying to prove such an all-encompassing
>>>> negative.
> (Not light of hand, our Mr. Cordian. Yet not all negative
> propositions are impossible to prove.
True, but assertions about which strings of English text have not been
stamped on paper over the past century are amongst the more difficult.
Unless, of course, you are employing the time-honored "poll three
people" technique. :)
> For the rest, I'll leave it to the List and other readers to decide
> which of us deserves a Dunce Cap for placing himself in an untenable
> position.)
My comment about there being obvious prior art for RSA was one line
made in passing in a thread about a different subject. Had I known I
would be pounced upon by an troll who rarely posts to the Cypherpunks
list, apparently with copious funded time on his hands to write
voluminous essays on the topic, I would of course have come prepared
with a complete bibliography of all references to modular
exponentiation-based encryption prior to 1977.
> Since 1981, the US Courts have allowed a process which includes a
> mathematical algorithm to be patented -- if the algorithm is merely
> part of an otherwise patentable process. For the RSA cryptosystem,
> this seems reasonably straightforward to those without a religious
> bias.
Goodness gracious, the US Courts have allowed practically anything to
be patented, as long as the words "method and apparatus" are thrown in
there somewhere, with the possible exception of self-described
perpetual motion machines.
> "Taken as a whole, the RSA patent is entitled to patent protection.
> The claims of the patent make use of known structures, a
> communications channel, an encoding device and a decoding device, to
> produce a practical invention, i.e. a means for securely transmitting
> messages across an insecure line. The messages are comprised of word
> signals that are transformed from one state, plaintext, to another
> state, ciphertext, by the patented invention. The word signals are
> then transmitted across an insecure line and transformed by the
> decoding device from ciphertext into plaintext. As such, the claimed
> invention is not merely a disembodied mathematical concept but rather
> a specific machine designed to transform and transmit word signals."
There is nothing specific to RSA in the section you quote, and such an
argument could be applied to almost any cryptographic transformation.
> If, as Mr. Cordian claimed, there was "a description of that which is
> now known as RSA Public Key Cryptography" published in some book years
> before the 1976 (re)discovery of the RSA cryptosystem by Rivest,
> Shamir, and Adleman, it would have -- and clearly should have --
> invalidated the RSA patent under that rule.
Not necessarily. The RSA patent contains many elements, the central
mathematical formula which is only one of them. Absent the other
claims of permitting the secure transmission of data across insecure
lines by parties who have not performed a secure key exchange, and of
a suitable "method and apparatus" incarnation of the mathematics into
some described device, collections of mathematical algorithms could
wax elequently on the usefulness of trap-door functions in
cryptography, and give examples of encryption by modular
exponentation, and still not contain anything you or other interested
parties would admit was a "description of RSA Public Key
Cryptography."
> Patrick J. Flinn! Hey, what a surprise!
[Paragraphs of character assassination against Mr. Flinn deleted]
> (A nymed net-gent like Mr. Cordian -- who hides his real identity
> behind the Cordian pseudonym -- can perhaps risk his reputation a
> little more carelessly than the rest of us. If he soils this one,
> after all, he can just pony up for a new identity.)
Will you be billing RSA Labs for this tirade?
>> "There are a number of references in the prior art, moreover,
>> to using the problem of factoring composite numbers in
>> cryptography, dating back to the 19th century.
>> "In 1870, a book by William S. Jevons described the
>> relationship of one-way functions to cryptography and went
>> on to discuss specifically the factorization problem used
>> to create the "trap-door" in the RSA system."
> Thus, Jevons anticipated a key feature of the RSA Algorithm for public
> key cryptography, though he certainly did not invent the concept of
> public key cryptography.
It is of course obvious that this cite references Jevons' work as the
earliest reference to something RSA-related in a span of material
dating from the late 19th century.
Neither I, nor I assume, Mr. Flinn, is suggesting that this particular
reference constitutes some definitive description of RSA Public Key
Cryptography.
My own recollection is that a description of modular exponentiation
based encryption appeared in a collection of algorithms published in
the 1940's. This was what I was referring to in my first mention of
"a description of that which is now known as RSA." This is a vague
recollection, and I would not be too surprised if I have not recalled
the date or topic of the book with great accuracy.
There were a couple of messages on the Net discussing the book around
the time of the Cylink/RSA festivities. Perhaps someone else recalls
the book in more detail. I do not plan to turn my life into a
unending quest to find the cite in question, however, if I stumble
across it again, I will certainly post it.
> I think it is appropriate to note, however, that Prof. Golomb did
> _not_ conclude that the functionality of the RSA public key
> cryptosystem was "obvious" to anyone familiar with Jevons' work.
No one has suggested that was the case. Clearly, the "obvious"
argument for RSA arises out of a number of things. The utility of
trap-door functions in cryptography. The use of modular
exponentiation for encryption and decryption. The recognition that
factoring composite numbers is difficult and can be exploited for
cryptographic purposes. I would consider the publication of the math
for encryption by modular exponentiation to be the smoking gun for
prior art, even in the absence of accompanying material describing the
concept of a "public key." Clearly, the courts will not rule the
patent invalid based solely upon the math being published, so
naysayers are probably safe in sticking to their claims.
--
Sponsor the DES Analytic Crack Project
http://www.cyberspace.org/~enoch/crakfaq.html