Prosecution Insights
Last updated: October 02, 2026
Application No. 18/170,405

MITIGATION OF A MANIPULATION OF SOFTWARE OF A VEHICLE

Non-Final OA §103
Filed
Feb 16, 2023
Priority
Feb 23, 2022 — DE 10 2022 201 895.8
Examiner
CHIANG, JASON
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Robert Bosch GmbH
OA Round
3 (Non-Final)
83%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
464 granted / 558 resolved
+25.2% vs TC avg
Strong +28% interview lift
Without
With
+28.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
14 currently pending
Career history
569
Total Applications
across all art units

Statute-Specific Performance

§101
10.5%
-29.5% vs TC avg
§103
60.8%
+20.8% vs TC avg
§102
10.0%
-30.0% vs TC avg
§112
7.1%
-32.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 558 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 03/11/2026 has been entered. Claims 1-14 are under examination. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-14 are rejected under 35 U.S.C. 103 as being unpatentable over Sorani et al. (US 2022/0394053 A1), Chen et al. (US 2019/0215339 A1) and Huang (US 2023/0017962 A1). Regarding claim 1, Sorani et al. discloses A computer-implemented method, comprising: recognizing a possibility of a manipulation of software of a first component of a plurality of components of a vehicle electrical system of a vehicle in a central device configured to mitigate a manipulation of software [abs, “systems and methods of identifying, analyzing, and remediating vulnerabilities of networked vehicle components to various malicious exploits”, par. 0045, remote code execution], the central device configured to mitigate a manipulation being part of the vehicle electrical system [par. 0057, remediation action for the ECU3 which is the most critical unit (enabling remote code execution by an attacker and is associated with vehicle safety)], and being configured to mitigate a manipulation of software in each component of the plurality of components of the vehicle electrical system [par. 0011, iteratively: selectively modifying attributes of at least one of the plurality of the identified compromised units to overcome at least one vulnerability, par. 0048, buffer overflow (manipulation of software)]; initiating a countermeasure for mitigating the manipulation of the software of the first component by the central device configured to mitigate a manipulation; and carrying out the countermeasure for mitigating the manipulation of the software of the first component, the countermeasure for mitigating the manipulation including a measure for preventing a repetition of the manipulation [par. 0057, Changing the configuration by, for example, inserting message authentication code to ECU3, will eliminate the threat or substantially reduce the probability for the exploit. The system will then highlight the vulnerability pathway and suggest the proper modification, or alternatively, automatically implementing the modification]. Sorani et al. does not explicitly disclose the measure being selected based on an analysis of information concerning data traffic in the vehicle electrical system that took place before the possibility of a manipulation was recognized. However Chen et al. teaches the measure being selected based on an analysis of information concerning data traffic in the vehicle electrical system that took place before the possibility of a manipulation was recognized [abs, “analyzing the monitored data using one or more machine learning models trained to detect threats in data communicated over the communications network of the motor vehicle… performing at least one corrective action based on the security level associated with the detected threat”]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Chen et al. into the teaching of Sorani et al. with the motivation for enforcing network security in a motor vehicle as taught by Chen et al. [Chen et al.: abs.]. They do not explicitly disclose wherein the measure for preventing the repetition of the manipulation includes deactivating an interface via which the first component communicates with the vehicle electrical system while permitting the first component to continue operating. However, Huang teaches wherein the measure for preventing the repetition of the manipulation includes deactivating an interface via which the first component communicates with the vehicle electrical system while permitting the first component to continue operating [par. 0088, “ the denial of service operation can disable a part of the in-vehicle communication network such that some of the functionality of the in-vehicle communication network (and hence functionality of the respective vehicle system(s)) is reduced. The denial of service operation can target the specific part(s) of the in-vehicle communication network that are impacted by the illicit signal such that other parts of the in-vehicle communication network remain functional”]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Huang into the teaching of Sorani et al. and Chen et al. with the motivation to prevent or mitigate the effects of an attack against the in-vehicle communication network) that disables communication on at least part of the in-vehicle communication network affected by the illicit signal as taught by Huang [Huang: par. 0013]. Regarding claim 2, the rejection of claim 1 is incorporated. Sorani et al. further disclose the analysis includes determining a type of manipulation [par. 0048, The vulnerability type can be, for example, at least one of: a coding error, memory corruption, buffer overflow, authentication protocol, authorization protocol…]. Regarding claim 3, the rejection of claim 1 is incorporated. Sorani et al. further disclose the analysis includes finding a weak point of the vehicle electrical system of a vehicle [par. 0048, the term “vulnerability” refers to a weakness in a system or its associated networks' nodes, system security procedures, internal controls, or implementation that could be exploited to obtain unauthorized access to system resources. For instance, an open diagnostic port on an ECU is a vulnerability…]. Regarding claim 4, the rejection of claim 3 is incorporated. Chen et al. further teaches the interface belongs to a plurality of interfaces and wherein determining the type of manipulation includes determining one of the plurality of interface of the vehicle via which data traffic took place before the possibility of a manipulation was recognized [par. 0009, detect, and remedy security threats that originate from the exchange of communications on a vehicles communications network, par. 0016, an attempted access to a user's private data stored in vehicle gateway 120 via user interface 112, an attempted access of the memory of VCU 106 received from an external entity (e.g., via network 130), as well as other potentially non-allowed network based communications, par. 0028, monitoring network communications include between internal systems, external systems, fig. 2, network interface 204]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Chen et al. into the teaching of Sorani et al. with the motivation for enforcing network security in a motor vehicle as taught by Chen et al. [Chen et al.: abs.]. Regarding claim 5, the rejection of claim 3 is incorporated. Chen et al. further teaches the analysis includes finding programming operations in data traffic that took place before the possibility of a manipulation was recognized [par. 0030, a forth security level associated with an ongoing attack that will impact a major vehicle system (e.g., a purposeful misconfiguration of a critical system, such as the vehicles steering, braking, access to secure storage, etc. that could affect the motor vehicle's operator, passengers, or the motor vehicle itself); and a fifth security level associated with a detected system compromise (e.g., an attempt to physically or logically access the security gateway)]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Chen et al. into the teaching of Sorani et al. with the motivation for enforcing network security in a motor vehicle as taught by Chen et al. [Chen et al.: abs.]. Regarding claim 6, the rejection of claim 1 is incorporated. Chen et al. further teaches the analysis includes establishing a temporal relationship between a certain data traffic and recognizing the possibility of a manipulation [par. 0033, one or more MLM(s) may be trained to recognize/detect normal system communications and patterns occurring on a motor vehicles communication network, as well as communications that are indicative of potential threats]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Chen et al. into the teaching of Sorani et al. with the motivation for enforcing network security in a motor vehicle as taught by Chen et al. [Chen et al.: abs.]. Regarding claim 7, the rejection of claim 1 is incorporated. Chen et al. further teaches the measure includes one or multiple of the following: preventing or limiting certain types of data traffic in the vehicle; and switching off or limiting certain components of the vehicle [par. 0031, for critical threats, such as those associated with the fourth and fifth level threats, the security state of the motor vehicle can be raised and more serious corrective actions, such as shutting down motor vehicle 202, restricting communications between components]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Chen et al. into the teaching of Sorani et al. with the motivation for enforcing network security in a motor vehicle as taught by Chen et al. [Chen et al.: abs.]. Regarding claim 8, the rejection of claim 7 is incorporated. Chen et al. further teaches wherein the certain components include an interface of the vehicle electrical system of the vehicle [par. 0011, “each ECU 105 is communicatively coupled via a communications network 107 to a vehicle control unit (VCU) 106. The communications network 107 may be a controller area network (CAN), an Ethernet network, a wireless communications network”, par. 0036, the communications network of the motor vehicle may include a combination of networks, such as a CAN bus, an Ethernet network, a wireless network, or any combination of networks]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Chen et al. into the teaching of Sorani et al. with the motivation for enforcing network security in a motor vehicle as taught by Chen et al. [Chen et al.: abs.]. Regarding claim 9, the rejection of claim 1 is incorporated. Chen et al. further teaches logging results of the analysis of information concerning data traffic in the vehicle electrical system; and providing the logged results for recognizing manipulations [par. 0016, “The data is logged and stored by vehicle gateway 120, such as in a memory or traffic data store, and then analyzed to detect communications, series of communications, etc. that are that indicate a potential security threat within network 107”, par. 0042, “The normal communications and the threat communications are used by processing logic to train a threat detection machine learning model ”]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Chen et al. into the teaching of Sorani et al. with the motivation for enforcing network security in a motor vehicle as taught by Chen et al. [Chen et al.: abs.]. Regarding claim 10, the rejection of claim 1 is incorporated. Sorani et al. further teaches deactivating the measure in response to an update of the vehicle electrical system of the vehicle [par. 0057, “Changing the configuration by, for example, inserting message authentication code to ECU3, will eliminate the threat…”]. Regarding claim 11, it recites limitations similar to claim 1. The reason for the rejection of claim 1 is incorporated herein. Regarding claim 12, it recites limitations similar to claim 1. The reason for the rejection of claim 1 is incorporated herein. Regarding claim 13, it recites limitations similar to claim 1. The reason for the rejection of claim 1 is incorporated herein. Regarding claim 14, it recites limitations similar to claim 1. The reason for the rejection of claim 1 is incorporated herein. Response to Arguments Applicant’s arguments, filed on 03/11/2026, with respect to rejection under 35 USC § 103 have been fully considered but the arguments are directed towards the newly amended limitations. New reference has been provided to address those limitations, and the rejection is incorporated herein. Conclusion The prior art made of record and not relied upon is considered pertinent to Applicant’s disclosure: US 20230262071 A1 METHOD FOR MONITORING DATA TRAFFIC BETWEEN CONTROL DEVICES OF A MOTOR VEHICLE AND VEHICLE EQUIPPED ACCORDINGLY US 20210112094 A1 METHODS TO DETECT SPOOFING ATTACKS ON AUTOMATED DRIVING SYSTEMS US 20190308589 A1 VEHICLE NETWORK INTRUSION DETECTION SYSTEM (IDS) USING VEHICLE STATE PREDICTIONS US 20180196941 A1 SECURITY SYSTEM AND METHODS FOR IDENTIFICATION OF IN-VEHICLE ATTACK ORGINATOR US 9525700 B1 System And Method For Detecting Malicious Activity And Harmful Hardware/software Modifications To A Vehicle US 20160011932 A1 Method For Monitoring Software In A Road Vehicle US 20230267776 A1 VEHICLE MONITORING PROGRAM, VEHICLE-MOUNTED DEVICE, AND VEHICLE MONITORING METHOD Any inquiry concerning this communication or earlier communications from the examiner should be directed to JASON CHIANG whose telephone number is (571)270-3393. The examiner can normally be reached on 9AM to 6 PM. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JASON CHIANG/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Show 2 earlier events
Jun 20, 2025
Response Filed
Sep 11, 2025
Final Rejection mailed — §103
Feb 11, 2026
Interview Requested
Mar 03, 2026
Examiner Interview Summary
Mar 03, 2026
Applicant Interview (Telephonic)
Mar 11, 2026
Request for Continued Examination
Mar 19, 2026
Response after Non-Final Action
Sep 08, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12719867
METHOD AND APPARATUS FOR SELECTING AN AUTHENTICATION TYPE FOR AUTHENTICATION RELATED TO A TERMINAL DEVICE
3y 0m to grant Granted Aug 25, 2026
Patent 12717949
DATA PROVIDING SYSTEM, DATA PROVIDING APPARATUS, AND DATA PROVIDING METHOD
2y 4m to grant Granted Aug 25, 2026
Patent 12711210
IDENTIFYING AND AUTHENTICATING USERS BASED ON PASSIVE FACTORS DETERMINED FROM SENSOR DATA
4y 11m to grant Granted Aug 18, 2026
Patent 12711260
AUTHORIZING AN OPERATION ON SENSITIVE DATA ASSOCIATED WITH A MOBILE DEVICE BY OBTAINING PERMISSION FROM AN AUTHORIZED USER
2y 4m to grant Granted Aug 18, 2026
Patent 12689630
METHOD AND SYSTEM FOR SUPPORTING DUAL PARTY CONTROL AUTHORIZATION FOR SENSITIVE OPERATIONS
2y 2m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+28.4%)
2y 6m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 558 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month