Prosecution Insights
Last updated: July 23, 2026
Application No. 18/444,812

WRITE CONTROL DEVICE, UPDATE CONTROL DEVICE, ELECTRONIC CONTROL SYSTEM, SOFTWARE UPDATE CONTROL METHOD, AND STORAGE MEDIUM STORING SOFTWARE UPDATE CONTROL PROGRAM

Final Rejection §103
Filed
Feb 19, 2024
Priority
Feb 21, 2023 — JP 2023-025556
Examiner
CHEN, QING
Art Unit
2191
Tech Center
2100 — Computer Architecture & Software
Assignee
Denso Corporation
OA Round
2 (Final)
80%
Grant Probability
Favorable
3-4
OA Rounds
9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
549 granted / 688 resolved
+24.8% vs TC avg
Strong +53% interview lift
Without
With
+53.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
22 currently pending
Career history
714
Total Applications
across all art units

Statute-Specific Performance

§101
9.3%
-30.7% vs TC avg
§103
81.9%
+41.9% vs TC avg
§102
5.7%
-34.3% vs TC avg
§112
2.5%
-37.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 688 resolved cases

Office Action

§103
DETAILED ACTION This Office action is in response to the amendment submitted on February 23, 2026. Claims 1, 2, and 4-16 are pending. Claims 1, 2, and 4-16 are currently amended. Claim 3 is canceled. The objection to the title of the invention is withdrawn in view of the Applicant’s amendments to the title of the invention. The 35 U.S.C. § 112(b) rejections of Claims 1-14 are withdrawn in view of the Applicant’s amendments to the claims or cancellation of the claim. In the interest of facilitating compact prosecution, the Examiner kindly asks the Applicant’s representative to authorize Internet communications with the Examiner by submitting Form PTO/SB/439 using Patent Center. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55. Response to Amendment Claim Interpretation Under 35 USC § 112(f) In light of the Applicant’s amendments to Claims 1, 2, 4, 6, 7, and 12-14 and further consideration of the claims by the Examiner, Claims 1-14 are no longer being interpreted under 35 U.S.C. § 112(f). Claim Objections Claims 2, 4, 6, 7, and 13 are objected to because of the following informalities: Claims 2, 4, 6, and 7 recite “the circuit and the processor.” It should read -- (i) the circuit and (ii) the processor --. Claim 6 recites “the at least one of […].” It should read -- wherein the at least one of […] --. Claim 13 recites “the second circuit and the second processor.” It should read -- (i) the second circuit and (ii) the second processor --. Claim 13 recites “the scheme of the signature.” It should read -- the specified scheme of the signature --. Appropriate correction is required. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 12, and 14-16 are rejected under 35 U.S.C. 103 as being unpatentable over US 2022/0263662 (hereinafter “Zibuschka”) in view of US 6,862,684 (hereinafter “DiGiorgio”). [Examiner’s Remarks: In order for a reference to be proper for use in an obviousness rejection under 35 U.S.C. 103, the reference must be analogous art to the claimed invention. In re Bigio, 381 F.3d 1320, 1325, 72 USPQ2d 1209, 1212 (Fed. Cir. 2004). A reference is analogous art to the claimed invention if: (1) the reference is from the same field of endeavor as the claimed invention (even if it addresses a different problem); or (2) the reference is reasonably pertinent to the problem faced by the inventor (even if it is not in the same field of endeavor as the claimed invention). Note that the claimed invention is generally directed to an update control device for controlling updating of software mounted in an in-vehicle electronic control system (specification, paragraph [0002]). As for the “same field of endeavor” test, Zibuschka is generally directed to updating a software component of a control unit of a device (Zibuschka, paragraph [0002]). And as for the “reasonably pertinent” test, DiGiorgio is generally directed to securely providing billable multicast data (DiGiorgio, col. 1 lines 7-9). Thus, Zibuschka and DiGiorgio are both analogous art to the claimed invention (even if they address different problems or are not in the same field of endeavor as the claimed invention). See MPEP § 2141.01(a)(I).] As per Claim 1, Zibuschka discloses: An update control device (Figure 2; paragraph [0090], “[…] the first electronic device may be a computer (a laptop or a PC, for example) and/or a mobile electronic device (a mobile telephone, for example) that is situated in the network of the industrial facility.”) controlling updating of software of a device to be updated as a software update target among a plurality of electronic control units which are connected to the update control device, the update control device comprising: [Examiner’s Remarks: Note that the limitation “controlling updating of software of a device to be updated as a software update target among a plurality of electronic control units which are connected to the update control device” in the preamble of the claim is not given any patentable weight because it is merely a statement of purpose or intended use of the claimed invention. See MPEP § 2111.02.] at least one of (i) a circuit and (ii) a processor with a memory (Figure 2: 210 and 220) storing computer program code executable by the processor, the at least one of the circuit and the processor configured to cause the update control device to implement: an update file transfer unit that is configured to obtain an update file for updating the software and a signature generated from the update file from a distribution device, and transmit the update file to the device to be updated (paragraph [0025], “[…] receiving 120 update information for the second electronic device via the first electronic device [transmit the update file to the device to be updated]. The update information is provided with a signature that is generated with the aid of a post-quantum algorithm (PQA) signature. The update information may be transmitted from a data source (for example, a manufacturer of the second electronic device) via a second network (which is of a different type than the first network) [obtain an update file for updating the software and a signature generated from the update file from a distribution device] (emphasis added).”; paragraph [0026], “[…] the update information may contain a useful data portion which contains the information that forms, directly or according to appropriate processing steps, a software component of a device according to the present invention. The update information may also contain metadata (for example, author information about a source of the update information, version information about a version of a software component that pertains to the software update, and/or information that describes the nature or the objective of the software update) [an update file for updating the software].”); and a verification […] determination unit that is configured to (i) obtain the signature generated from the update file from the distribution device […] (paragraph [0025], “[…] receiving 120 update information for the second electronic device via the first electronic device. The update information is provided with a signature that is generated with the aid of a post-quantum algorithm (PQA) signature. The update information may be transmitted from a data source (for example, a manufacturer of the second electronic device) via a second network (which is of a different type than the first network) [obtain the signature generated from the update file from the distribution device] (emphasis added).”) and (iii) […] verify[] the signature from the plurality of electronic control units […] (paragraph [0033], “A further step includes checking 130 the update information by validating the signature by the first electronic device (emphasis added).”; paragraph [0069], “Vehicle 300 contains one or multiple second electronic devices 320, 330 (for the purpose of illustration, FIG. 3 shows two second electronic device 320, 330; in other cases, vehicle 300 contains more than two, more than five, or more than ten second electronic devices according to the present invention). Second electronic devices 320, 330 may be designed to carry out the steps described herein. The one or multiple second electronic devices 320, 330 may be electronic control units (ECUs) 320, 330 (emphasis added).”). Zibuschka does not explicitly disclose: a verification device determination unit that is configured to […] (ii) specify, during operation of the update control device, a scheme of the signature, and (iii) determine a verification device […] based on the specified scheme of the signature; and a verification instruction unit that is configured to transmit the signature and a verification instruction instructing verification of the signature to the verification device. However, DiGiorgio discloses: a verification device determination unit that is configured to […] (ii) specify, during operation of the update control device, a scheme of the signature (col. 6 lines 62-67 to col. 7 lines 1-141, “The process begins when the source of the multicast data (e.g., the multicast server) generates the data that is to be sent via multicast (e.g., step 400). The multicast server then encrypts the stream of data (e.g., step 402) using one of a number of security techniques [specify, during operation of the update control device, a scheme of the signature]. Recipients will be provided with a mechanism to decode this stream of encrypted data. The invention contemplates the use of asymmetric (e.g., Public/Private key schemes) and symmetric encryption schemes [a scheme of the signature]. […] The multicast server may elect to encrypt or sign some or all of the packets sent to the client computers. The data that is sent may be encrypted and digitally signed, or the data may be encrypted or digitally signed (emphasis added).”), and (iii) determine a verification device […] based on the specified scheme of the signature (col. 7 lines 15-272, “Once the data is appropriately encrypted or digitally signed, the multicast server transmits the data to a plurality of client computers (e.g., step 404). The client computer is then tasked with determining what digital signature scheme or encryption scheme was utilized (e.g., step 406) [determine a verification device]. The invention may utilize various algorithms that enable the sender/receiver to identify what type of encryption or signature scheme the multicast server used to encode the data. For example, the sender and receiver may enter an initial negotiation phase to detect the type of security being used. The negotiations would allow the system to identify what encryption of verification mechanism to use in order to decode the multicast data [based on the specified scheme of the signature].”); and [1Examiner’s Remarks: Note that DiGiorgio discloses that the multicast server encrypts the stream of data using one of a number of security techniques. Thus, one of ordinary skill in the art would readily comprehend that the multicast server encrypts the stream of data using an encryption scheme during operation of the multicast server.] [2Examiner’s Remarks: Note that DiGiorgio discloses that the client computer is tasked with determining what digital signature scheme or encryption scheme was utilized. Thus, one of ordinary skill in the art would readily comprehend that the client computer is selected to determine what digital signature scheme or encryption scheme was utilized so that it can decrypt the encrypted data.] a verification instruction unit that is configured to transmit the signature and a verification instruction instructing verification of the signature to the verification device (col. 7 lines 12-193, “The data that is sent may be encrypted and digitally signed, or the data may be encrypted or digitally signed. Once the data is appropriately encrypted or digitally signed, the multicast server transmits the data to a plurality of client computers (e.g., step 404). The client computer is then tasked with determining what digital signature scheme or encryption scheme was utilized (e.g., step 406).” and lines 34-36, “Once the appropriate verification/decryption scheme is identified, each client computer verifies and/or decodes the data (e.g., step 408) (emphasis added).”). [3Examiner’s Remarks: Note that DiGiorgio discloses that the multicast server transmits the encrypted data to a plurality of client computers. And that each client computer verifies and/or decodes the encrypted data. Thus, one of ordinary skill in the art would readily comprehend that a verification/decryption instruction instructing verification/decryption of the signature is transmitted to each client device.] As pointed out hereinabove, Zibuschka and DiGiorgio are both analogous art to the claimed invention. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of DiGiorgio into the teaching of Zibuschka to include “a verification device determination unit that is configured to […] (ii) specify, during operation of the update control device, a scheme of the signature, and (iii) determine a verification device […] based on the specified scheme of the signature; and a verification instruction unit that is configured to transmit the signature and a verification instruction instructing verification of the signature to the verification device.” The modification would be obvious because one of ordinary skill in the art would be motivated to allow a user to verify that requested data came from a source it purports to be from (DiGiorgio, col. 7 lines 9 and 10). As per Claim 12, Zibuschka discloses: An electronic control system (Figure 3) comprising: an update control device (Figure 2; paragraph [0090], “[…] the first electronic device may be a computer (a laptop or a PC, for example) and/or a mobile electronic device (a mobile telephone, for example) that is situated in the network of the industrial facility.”) controlling updating of software of a device to be updated as a software update target among a plurality of electronic control units which are connected (paragraph [0037], “The update information relayed by the first electronic device may be received by the second electronic device. A software component of the second electronic device may be updated 150 using the update information [controlling updating of software of a device to be updated as a software update target].”; paragraph [0060], “[…] the second electronic device is a control unit for a device, for example a dedicated control unit for the device. The device may be a vehicle, a robot, a household appliance, an industrial facility, or an industrial machine.”; paragraph [0069], “Vehicle 300 contains one or multiple second electronic devices 320, 330 (for the purpose of illustration, FIG. 3 shows two second electronic device 320, 330; in other cases, vehicle 300 contains more than two, more than five, or more than ten second electronic devices according to the present invention). Second electronic devices 320, 330 may be designed to carry out the steps described herein. The one or multiple second electronic devices 320, 330 may be electronic control units (ECUs) 320, 330 (emphasis added).”); and the plurality of electronic control units (paragraph [0069], “Vehicle 300 contains one or multiple second electronic devices 320, 330 (for the purpose of illustration, FIG. 3 shows two second electronic device 320, 330; in other cases, vehicle 300 contains more than two, more than five, or more than ten second electronic devices according to the present invention). Second electronic devices 320, 330 may be designed to carry out the steps described herein. The one or multiple second electronic devices 320, 330 may be electronic control units (ECUs) 320, 330 (emphasis added).”), wherein: the update control device comprises at least one of (i) a first circuit and (ii) a first processor with a first memory (Figure 2: 210 and 220) storing first computer program code executable by the first processor, the at least one of the first circuit and the first processor configured to cause the update control device to implement: an update file transfer unit obtaining an update file for updating the software and a signature generated from the update file from a distribution device, and transmitting the update file to the device to be updated (paragraph [0025], “[…] receiving 120 update information for the second electronic device via the first electronic device [transmitting the update file to the device to be updated]. The update information is provided with a signature that is generated with the aid of a post-quantum algorithm (PQA) signature. The update information may be transmitted from a data source (for example, a manufacturer of the second electronic device) via a second network (which is of a different type than the first network) [obtaining an update file for updating the software and a signature generated from the update file from a distribution device] (emphasis added).”; paragraph [0026], “[…] the update information may contain a useful data portion which contains the information that forms, directly or according to appropriate processing steps, a software component of a device according to the present invention. The update information may also contain metadata (for example, author information about a source of the update information, version information about a version of a software component that pertains to the software update, and/or information that describes the nature or the objective of the software update) [an update file for updating the software].”); and a verification […] determination unit (i) obtaining the signature generated from the update file from the distribution device […] (paragraph [0025], “[…] receiving 120 update information for the second electronic device via the first electronic device. The update information is provided with a signature that is generated with the aid of a post-quantum algorithm (PQA) signature. The update information may be transmitted from a data source (for example, a manufacturer of the second electronic device) via a second network (which is of a different type than the first network) [obtain the signature generated from the update file from the distribution device] (emphasis added).”) and (iii) […] verifying the signature from the plurality of electronic control units […] (paragraph [0033], “A further step includes checking 130 the update information by validating the signature by the first electronic device (emphasis added).”; paragraph [0069], “Vehicle 300 contains one or multiple second electronic devices 320, 330 (for the purpose of illustration, FIG. 3 shows two second electronic device 320, 330; in other cases, vehicle 300 contains more than two, more than five, or more than ten second electronic devices according to the present invention). Second electronic devices 320, 330 may be designed to carry out the steps described herein. The one or multiple second electronic devices 320, 330 may be electronic control units (ECUs) 320, 330 (emphasis added).”), and the device to be updated (Figure 2; paragraph [0069], “Vehicle 300 contains one or multiple second electronic devices 320, 330 (for the purpose of illustration, FIG. 3 shows two second electronic device 320, 330; in other cases, vehicle 300 contains more than two, more than five, or more than ten second electronic devices according to the present invention). Second electronic devices 320, 330 may be designed to carry out the steps described herein.”) comprises at least one of (i) a second circuit and (ii) a second processor with a second memory (Figure 2: 210 and 220) storing second computer program code executable by the second processor, the at least one of the second circuit and the second processor configured to cause the device to be updated to implement: an update file reception unit receiving the update file from the update control device (paragraph [0025], “[…] receiving 120 update information for the second electronic device via the first electronic device [receiving the update file from the update control device]. The update information is provided with a signature that is generated with the aid of a post-quantum algorithm (PQA) signature. The update information may be transmitted from a data source (for example, a manufacturer of the second electronic device) via a second network (which is of a different type than the first network).”); a verification result reception unit receiving a verification result of the signature from the verification device or the update control device (paragraph [0033], “A further step includes checking 130 the update information by validating the signature by the first electronic device (emphasis added).”; paragraph [0035], “The method includes relaying 140 the update information to the second electronic device if the update information is deemed to be valid [receiving a verification result of the signature from the verification device or the update control device].”); and a software update unit updating software by using the update file on a basis of the verification result (paragraph [0037], “The update information relayed by the first electronic device may be received by the second electronic device. A software component of the second electronic device may be updated 150 using the update information [updating software by using the update file on a basis of the verification result].”). Zibuschka does not explicitly disclose: a verification device determination unit […] (ii) specifying, during operation of the update control device, a scheme of the signature, and (iii) determining a verification device […] based on the specified scheme of the signature; and a verification instruction unit transmitting the signature and a verification instruction instructing verification of the signature to the verification device. However, DiGiorgio discloses: a verification device determination unit […] (ii) specifying, during operation of the update control device, a scheme of the signature (col. 6 lines 62-67 to col. 7 lines 1-141, “The process begins when the source of the multicast data (e.g., the multicast server) generates the data that is to be sent via multicast (e.g., step 400). The multicast server then encrypts the stream of data (e.g., step 402) using one of a number of security techniques [specifying, during operation of the update control device, a scheme of the signature]. Recipients will be provided with a mechanism to decode this stream of encrypted data. The invention contemplates the use of asymmetric (e.g., Public/Private key schemes) and symmetric encryption schemes [a scheme of the signature]. […] The multicast server may elect to encrypt or sign some or all of the packets sent to the client computers. The data that is sent may be encrypted and digitally signed, or the data may be encrypted or digitally signed (emphasis added).”), and (iii) determining a verification device […] based on the specified scheme of the signature (col. 7 lines 15-272, “Once the data is appropriately encrypted or digitally signed, the multicast server transmits the data to a plurality of client computers (e.g., step 404). The client computer is then tasked with determining what digital signature scheme or encryption scheme was utilized (e.g., step 406) [determining a verification device]. The invention may utilize various algorithms that enable the sender/receiver to identify what type of encryption or signature scheme the multicast server used to encode the data. For example, the sender and receiver may enter an initial negotiation phase to detect the type of security being used. The negotiations would allow the system to identify what encryption of verification mechanism to use in order to decode the multicast data [based on the specified scheme of the signature].”); and [1Examiner’s Remarks: Note that DiGiorgio discloses that the multicast server encrypts the stream of data using one of a number of security techniques. Thus, one of ordinary skill in the art would readily comprehend that the multicast server encrypts the stream of data using an encryption scheme during operation of the multicast server.] [2Examiner’s Remarks: Note that DiGiorgio discloses that the client computer is tasked with determining what digital signature scheme or encryption scheme was utilized. Thus, one of ordinary skill in the art would readily comprehend that the client computer is selected to determine what digital signature scheme or encryption scheme was utilized so that it can decrypt the encrypted data.] a verification instruction unit transmitting the signature and a verification instruction instructing verification of the signature to the verification device (col. 7 lines 12-193, “The data that is sent may be encrypted and digitally signed, or the data may be encrypted or digitally signed. Once the data is appropriately encrypted or digitally signed, the multicast server transmits the data to a plurality of client computers (e.g., step 404). The client computer is then tasked with determining what digital signature scheme or encryption scheme was utilized (e.g., step 406).” and lines 34-36, “Once the appropriate verification/decryption scheme is identified, each client computer verifies and/or decodes the data (e.g., step 408) (emphasis added).”). [3Examiner’s Remarks: Note that DiGiorgio discloses that the multicast server transmits the encrypted data to a plurality of client computers. And that each client computer verifies and/or decodes the encrypted data. Thus, one of ordinary skill in the art would readily comprehend that a verification/decryption instruction instructing verification/decryption of the signature is transmitted to each client device.] As pointed out hereinabove, Zibuschka and DiGiorgio are both analogous art to the claimed invention. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of DiGiorgio into the teaching of Zibuschka to include “a verification device determination unit […] (ii) specifying, during operation of the update control device, a scheme of the signature, and (iii) determining a verification device […] based on the specified scheme of the signature; and a verification instruction unit transmitting the signature and a verification instruction instructing verification of the signature to the verification device.” The modification would be obvious because one of ordinary skill in the art would be motivated to allow a user to verify that requested data came from a source it purports to be from (DiGiorgio, col. 7 lines 9 and 10). Claim 14 is a write control device claim corresponding to the update control device claim hereinabove (Claim 1). Therefore, Claim 14 is rejected for the same reason set forth in the rejection of Claim 1. Claim 15 is a software update control method claim corresponding to the update control device claim hereinabove (Claim 1). Therefore, Claim 15 is rejected for the same reason set forth in the rejection of Claim 1. Claim 16 is a non-transitory computer-readable storage medium claim corresponding to the update control device claim hereinabove (Claim 1). Therefore, Claim 16 is rejected for the same reason set forth in the rejection of Claim 1. Claims 2, 9-11, and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Zibuschka in view of DiGiorgio as applied to Claims 1 and 12 above, and further in view of US 2020/0169417 (hereinafter “Yang”). [Examiner’s Remarks: In order for a reference to be proper for use in an obviousness rejection under 35 U.S.C. 103, the reference must be analogous art to the claimed invention. In re Bigio, 381 F.3d 1320, 1325, 72 USPQ2d 1209, 1212 (Fed. Cir. 2004). A reference is analogous art to the claimed invention if: (1) the reference is from the same field of endeavor as the claimed invention (even if it addresses a different problem); or (2) the reference is reasonably pertinent to the problem faced by the inventor (even if it is not in the same field of endeavor as the claimed invention). Note that the claimed invention is generally directed to an update control device for controlling updating of software mounted in an in-vehicle electronic control system (specification, paragraph [0002]). And as for the “reasonably pertinent” test, Yang is generally directed to a digital signature verification method in a blockchain ledger (Yang, paragraph [0001]). Thus, Yang is an analogous art to the claimed invention (even if it is not in the same field of endeavor as the claimed invention). See MPEP § 2141.01(a)(I).] As per Claim 2, the rejection of Claim 1 is incorporated; and Zibuschka further discloses: wherein: the update file transfer unit transmits the signature and the update file to the device to be updated (paragraph [0025], “[…] receiving 120 update information for the second electronic device via the first electronic device. The update information is provided with a signature that is generated with the aid of a post-quantum algorithm (PQA) signature. The update information may be transmitted from a data source (for example, a manufacturer of the second electronic device) via a second network (which is of a different type than the first network).”). The combination of Zibuschka and DiGiorgio does not explicitly disclose: the at least one of the circuit and the processor is further configured to cause the update control device to implement: a verification request reception unit receiving a verification request as a request to verify the signature transmitted from the device to be updated; and when the verification request reception unit receives the verification request, the verification device determination unit determines the verification device. However, Yang discloses: the at least one of the circuit and the processor (Figure 7: 1010 and 1020) is further configured to cause the update control device to implement: a verification request reception unit receiving a verification request as a request to verify the signature transmitted from the device to be updated (paragraph [0033], “It is worthwhile to note that in this architecture, an individual user can initiate a verification request to a server through a service organization, or can directly initiate a verification request to the server.”; paragraph [0075], “S503. Obtain the to-be-verified object based on the verification object parameter and the hash value, where the type of the to-be-verified object includes a third-party digital signature, a server digital signature, or a time service certificate.”); and when the verification request reception unit receives the verification request, the verification device determination unit determines the verification device (paragraph [0033], “It is worthwhile to note that in this architecture, an individual user can initiate a verification request to a server through a service organization, or can directly initiate a verification request to the server.”; paragraph [0076]1, “S505. Send the to-be-verified object to a client, so the client performs verification.”). [1Examiner’s Remarks: Note that Yang discloses that the to-be-verified object is sent to a client, so that the client can perform verification. Thus, one of ordinary skill in the art would readily comprehend that the server has already determined that the client is performing the verification before sending the to-be-verified object to the client for verification.] As pointed out hereinabove, Yang is an analogous art to the claimed invention. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Yang into the combined teachings of Zibuschka and DiGiorgio to include “the at least one of the circuit and the processor is further configured to cause the update control device to implement: a verification request reception unit receiving a verification request as a request to verify the signature transmitted from the device to be updated; and when the verification request reception unit receives the verification request, the verification device determination unit determines the verification device.” The modification would be obvious because one of ordinary skill in the art would be motivated to perform a validation in order to ensure authenticity of data in an update file (Yang, paragraph [0003]). As per Claim 9, the rejection of Claim 2 is incorporated; and Zibuschka further discloses: wherein: the update file is an update file group including a plurality of pieces of the software for a plurality of devices to be updated, respectively (paragraph [0026], “[…] the update information may contain a useful data portion which contains the information that forms, directly or according to appropriate processing steps, a software component of a device according to the present invention. The update information may also contain metadata (for example, author information about a source of the update information, version information about a version of a software component that pertains to the software update, and/or information that describes the nature or the objective of the software update). In some examples, the update information may contain elements that link it to one or multiple other (for example, earlier) versions of the software component to be updated. For example, this may be a piece of information (a value, for example) which, when it is processed using a cryptographic function (a hash function, for example), corresponds to a piece of information (a value, for example) contained in some other (for example, earlier) piece of update information.”; paragraph [0027], “The update information may contain pieces of information that identify a target device (i.e., the second device) and/or a class of target devices and/or a group of target devices.”). As per Claim 10, the rejection of Claim 2 is incorporated; and Zibuschka further discloses: wherein: the update control device is mounted together with an electronic control unit in a movable object (Figure 3; paragraph [0069], “Vehicle 300 contains one or multiple second electronic devices 320, 330 (for the purpose of illustration, FIG. 3 shows two second electronic device 320, 330; in other cases, vehicle 300 contains more than two, more than five, or more than ten second electronic devices according to the present invention). Second electronic devices 320, 330 may be designed to carry out the steps described herein. The one or multiple second electronic devices 320, 330 may be electronic control units (ECUs) 320, 330.”). As per Claim 11, the rejection of Claim 2 is incorporated; and Zibuschka further discloses: wherein: an electronic control unit is mounted in a movable object (paragraph [0069], “Vehicle 300 contains one or multiple second electronic devices 320, 330 (for the purpose of illustration, FIG. 3 shows two second electronic device 320, 330; in other cases, vehicle 300 contains more than two, more than five, or more than ten second electronic devices according to the present invention). Second electronic devices 320, 330 may be designed to carry out the steps described herein. The one or multiple second electronic devices 320, 330 may be electronic control units (ECUs) 320, 330.”), and the update control device is disposed outside the movable object (Figures 3 and 4). As per Claim 13, the rejection of Claim 12 is incorporated; and Zibuschka further discloses: wherein: the update file transfer unit of the update control device transmits the signature and the update file to the device to be updated (paragraph [0025], “[…] receiving 120 update information for the second electronic device via the first electronic device. The update information is provided with a signature that is generated with the aid of a post-quantum algorithm (PQA) signature. The update information may be transmitted from a data source (for example, a manufacturer of the second electronic device) via a second network (which is of a different type than the first network).”), and the at least one of the second circuit and the second processor (Figure 2: 210 and 220) is further configured to cause the device to be updated to implement: a verification […] generation unit specifying the scheme of the signature from the signature or the update file (paragraph [0031], “In some examples, the PQA signature may be a signature that is based on a hash value. In some examples, the hash value may be computed based on the update information or a portion of the update information. For example, the PQA signature may have been generated using an extended Merkle signature scheme (XMSS) algorithm.”). The combination of Zibuschka and DiGiorgio discloses “on a basis of the scheme of the signature,” but the combination of Zibuschka and DiGiorgio does not explicitly disclose: a verification request generation unit […] generating a verification request as a request to verify the signature on a basis of the scheme of the signature; and a verification request transmission unit transmitting the verification request to the update control device. However, Yang discloses: a verification request generation unit […] generating a verification request as a request to verify the signature […] (paragraph [0033], “It is worthwhile to note that in this architecture, an individual user can initiate a verification request to a server through a service organization, or can directly initiate a verification request to the server.”; paragraph [0075], “S503. Obtain the to-be-verified object based on the verification object parameter and the hash value, where the type of the to-be-verified object includes a third-party digital signature, a server digital signature, or a time service certificate.”); and a verification request transmission unit transmitting the verification request to the update control device (paragraph [0033], “It is worthwhile to note that in this architecture, an individual user can initiate a verification request to a server through a service organization, or can directly initiate a verification request to the server.”). As pointed out hereinabove, Yang is an analogous art to the claimed invention. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Yang into the combined teachings of Zibuschka and DiGiorgio to include “a verification request generation unit […] generating a verification request as a request to verify the signature on a basis of the scheme of the signature; and a verification request transmission unit transmitting the verification request to the update control device.” The modification would be obvious because one of ordinary skill in the art would be motivated to perform a validation in order to ensure authenticity of data in an update file (Yang, paragraph [0003]). Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Zibuschka in view of DiGiorgio and Yang as applied to Claim 2 above, and further in view of US 5,528,490 (hereinafter “Hill”). [Examiner’s Remarks: In order for a reference to be proper for use in an obviousness rejection under 35 U.S.C. 103, the reference must be analogous art to the claimed invention. In re Bigio, 381 F.3d 1320, 1325, 72 USPQ2d 1209, 1212 (Fed. Cir. 2004). A reference is analogous art to the claimed invention if: (1) the reference is from the same field of endeavor as the claimed invention (even if it addresses a different problem); or (2) the reference is reasonably pertinent to the problem faced by the inventor (even if it is not in the same field of endeavor as the claimed invention). Note that the claimed invention is generally directed to an update control device for controlling updating of software mounted in an in-vehicle electronic control system (specification, paragraph [0002]). As for the “reasonably pertinent” test, Hill is generally directed to an improved electronic catalog system capable of providing a customer at a remote location with accurate updated product information from a vendor each time the customer uses the electronic catalog system (Hill, col. 1 lines 7-11). Thus, Hill is an analogous art to the claimed invention (even if it is not in the same field of endeavor as the claimed invention). See MPEP § 2141.01(a)(I).] As per Claim 4, the rejection of Claim 2 is incorporated; and Zibuschka discloses “a signature” and “a plurality of electronic control units,” and the combination of Zibuschka and DiGiorgio discloses “a verification device determination unit determines a verification device,” but the combination of Zibuschka, DiGiorgio, and Yang does not explicitly disclose: wherein: the at least one of the circuit and the processor is further configured to cause the update control device to implement: a verification possibility information management table storage unit in which verification possibility information as information indicating whether or not the signature can be verified is recorded for each of the plurality of electronic control units; and the verification device determination unit determines the verification device on a basis of a verification possibility information management table. However, Hill discloses: wherein: the at least one of the circuit and the processor (Figure 1A: 12 and 18) is further configured to cause the update control device to implement: a verification possibility information management table storage unit in which verification possibility information as information indicating whether or not the [software] can be verified is recorded for each of the plurality of [computers] (col. 13 lines 47-54, “The validation data file also stores the revision level of the software and constant data corresponding to each serial number and an indication of the validation status of each particular serial number. The validation status indicates whether the software stored in the customer's computer 18 is valid or invalid. A "YES" validation status indicates that the software is valid. A "NO" validation status indicates that the software has been pirated.”); and […] on a basis of a verification possibility information management table (col. 13 lines 36-44, “Vendor's computer 12 compares the identification file received from customer's computer 18 with a validation data file stored on hard drive 30 of vendor's computer 12. The validation data file includes each serial number generated by vendor's computer 12 for each customer of the vendor. In other words, each customer that downloads software from vendor's computer 12 has an individual serial number which identifies that particular customer.”). As pointed out hereinabove, Hill is an analogous art to the claimed invention. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Hill into the combined teachings of Zibuschka, DiGiorgio, and Yang to include “wherein: the at least one of the circuit and the processor is further configured to cause the update control device to implement: a verification possibility information management table storage unit in which verification possibility information as information indicating whether or not the signature can be verified is recorded for each of the plurality of electronic control units; and the verification device determination unit determines the verification device on a basis of a verification possibility information management table.” The modification would be obvious because one of ordinary skill in the art would be motivated to track a software of each device separately to determine if the software has been pirated (Hill, col. 13 lines 44-46). Claims 5 and 6 are rejected under 35 U.S.C. 103 as being unpatentable over Zibuschka in view of DiGiorgio and Yang as applied to Claim 2 above, and further in view of US 2010/0175061 (hereinafter “Maeda”). [Examiner’s Remarks: In order for a reference to be proper for use in an obviousness rejection under 35 U.S.C. 103, the reference must be analogous art to the claimed invention. In re Bigio, 381 F.3d 1320, 1325, 72 USPQ2d 1209, 1212 (Fed. Cir. 2004). A reference is analogous art to the claimed invention if: (1) the reference is from the same field of endeavor as the claimed invention (even if it addresses a different problem); or (2) the reference is reasonably pertinent to the problem faced by the inventor (even if it is not in the same field of endeavor as the claimed invention). Note that the claimed invention is generally directed to an update control device for controlling updating of software mounted in an in-vehicle electronic control system (specification, paragraph [0002]). As for the “same field of endeavor” test, Maeda is generally directed to a software update apparatus capable of preventing an install module that has been tampered with from performing malicious operations (Maeda, paragraph [0009]). Thus, Maeda is an analogous art to the claimed invention (even if it addresses a different problem). See MPEP § 2141.01(a)(I).] As per Claim 5, the rejection of Claim 2 is incorporated; and Zibuschka discloses “a signature,” but the combination of Zibuschka, DiGiorgio, and Yang does not explicitly disclose: wherein: the verification instruction unit includes, in the verification instruction, an instruction to transmit a verification result as a result of verification of the signature to the device to be updated. However, Maeda discloses: wherein: a verification instruction unit includes, in a verification instruction, an instruction to transmit a verification result as a result of verification of an [application] to a device to be updated (paragraph [0127], “FIG. 1 shows, in a first embodiment of the present invention, the whole structure of a software update system 1000 to which a software update apparatus relating to the present invention is applied. The software update system 1000 includes, as shown in FIG. 1, an apparatus 100 and an update server 200 that are connected with each other via a network.”; paragraph [0154], “[…] after updating to the replacement protection control module 121, or upon receiving an update completion notification from the other install module, the update control unit 303 verifies whether the protection control module has been correctly updated, using the certificate received from the replacement software distribution module 210, and transmits a result of the verification to the replacement software distribution module 210.”). As pointed out hereinabove, Maeda is an analogous art to the claimed invention. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Maeda into the combined teachings of Zibuschka, DiGiorgio, and Yang to include “wherein: the verification instruction unit includes, in the verification instruction, an instruction to transmit a verification result as a result of verification of the signature to the device to be updated.” The modification would be obvious because one of ordinary skill in the art would be motivated to prevent an install module that has been tampered with from performing malicious operations (Maeda, paragraph [0009]). As per Claim 6, the rejection of Claim 2 is incorporated; and Zibuschka discloses “a signature,” but the combination of Zibuschka, DiGiorgio, and Yang does not explicitly disclose: the at least one of the circuit and the processor is further configured to cause the update control device to implement: a verification result reception unit receiving a verification result as a result of verification of the signature from the verification device; and a verification result transmission unit transmitting the verification result to the device to be updated. However, Maeda discloses: the at least one of the circuit and the processor (Figure 7: 11-13) is further configured to cause the update control device to implement: a verification result reception unit receiving a verification result as a result of verification of the [application] from the verification device (paragraph [0154], “[…] after updating to the replacement protection control module 121, or upon receiving an update completion notification from the other install module, the update control unit 303 verifies whether the protection control module has been correctly updated, using the certificate received from the replacement software distribution module 210, and transmits a result of the verification to the replacement software distribution module 210.”); and a verification result transmission unit transmitting the verification result to the device to be updated (paragraph [0127], “FIG. 1 shows, in a first embodiment of the present invention, the whole structure of a software update system 1000 to which a software update apparatus relating to the present invention is applied. The software update system 1000 includes, as shown in FIG. 1, an apparatus 100 and an update server 200 that are connected with each other via a network.”; paragraph [0154], “[…] after updating to the replacement protection control module 121, or upon receiving an update completion notification from the other install module, the update control unit 303 verifies whether the protection control module has been correctly updated, using the certificate received from the replacement software distribution module 210, and transmits a result of the verification to the replacement software distribution module 210.”). As pointed out hereinabove, Maeda is an analogous art to the claimed invention. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Maeda into the combined teachings of Zibuschka, DiGiorgio, and Yang to include “the at least one of the circuit and the processor is further configured to cause the update control device to implement: a verification result reception unit receiving a verification result as a result of verification of the signature from the verification device; and a verification result transmission unit transmitting the verification result to the device to be updated.” The modification would be obvious because one of ordinary skill in the art would be motivated to prevent an install module that has been tampered with from performing malicious operations (Maeda, paragraph [0009]). Claims 7 and 8 are rejected under 35 U.S.C. 103 as being unpatentable over Zibuschka in view of DiGiorgio and Yang as applied to Claim 2 above, and further in view of US 2013/0311986 (hereinafter “Arrouye”). [Examiner’s Remarks: In order for a reference to be proper for use in an obviousness rejection under 35 U.S.C. 103, the reference must be analogous art to the claimed invention. In re Bigio, 381 F.3d 1320, 1325, 72 USPQ2d 1209, 1212 (Fed. Cir. 2004). A reference is analogous art to the claimed invention if: (1) the reference is from the same field of endeavor as the claimed invention (even if it addresses a different problem); or (2) the reference is reasonably pertinent to the problem faced by the inventor (even if it is not in the same field of endeavor as the claimed invention). Note that the claimed invention is generally directed to an update control device for controlling updating of software mounted in an in-vehicle electronic control system (specification, paragraph [0002]). As for the “reasonably pertinent” test, Arrouye is generally directed to using cloud-based storage to transparently reduce the space requirements of an application installed on a client device (Arrouye, paragraph [0002]). Thus, Arrouye is an analogous art to the claimed invention (even if it is not in the same field of endeavor as the claimed invention). See MPEP § 2141.01(a)(I).] As per Claim 7, the rejection of Claim 2 is incorporated; and Zibuschka further discloses: wherein the at least one of the circuit and the processor (Figure 2: 210 and 220) is further configured to cause the update control device to implement: a storage device determination unit determining a storage device as a destination of storage of the signature and the update file […] (paragraph [0010]1, “An ‘electronic device’ in the present disclosure includes its own hardware resources, which include at least one processor for executing commands and a memory for storing at least one software component.”; paragraph [0025], “[…] receiving 120 update information for the second electronic device via the first electronic device. The update information is provided with a signature that is generated with the aid of a post-quantum algorithm (PQA) signature. The update information may be transmitted from a data source (for example, a manufacturer of the second electronic device) via a second network (which is of a different type than the first network).”); and [1Examiner’s Remarks: Note that Zibuschka discloses that an electronic device includes a memory. Thus, one of ordinary skill in the art would readily comprehend that the electronic device would determine the memory as a storage device for storing the update information and the signature.] a storage instruction unit transmitting the signature, the update file, and a storage instruction instructing storage of the update file to the storage device (paragraph [0010]2, “An ‘electronic device’ in the present disclosure includes its own hardware resources, which include at least one processor for executing commands and a memory for storing at least one software component.”; paragraph [0025], “[…] receiving 120 update information for the second electronic device via the first electronic device. The update information is provided with a signature that is generated with the aid of a post-quantum algorithm (PQA) signature. The update information may be transmitted from a data source (for example, a manufacturer of the second electronic device) via a second network (which is of a different type than the first network).”). [2Examiner’s Remarks: Note that Zibuschka discloses that an electronic device includes a memory. Thus, one of ordinary skill in the art would readily comprehend that the electronic device would transmit a storage instruction to the memory instructing the memory to store the update information.] Zibuschka discloses “a plurality of electronic control units,” but the combination of Zibuschka, DiGiorgio, and Yang does not explicitly disclose: a storage unit information management table storage unit in which storage unit information as information indicating a state of a storage unit in each of the plurality of electronic control units is recorded; and a storage device determination unit determining a storage device as a destination of storage of the signature and the update file on a basis of a storage unit information management table. However, Arrouye discloses: a storage unit information management table storage unit in which storage unit information as information indicating a state of a storage unit in each of the plurality of [computing devices] is recorded (paragraph [0037], “[…] cloud-based storage 126 can include multiple storage devices. In some cases, cloud resources can be distributed across multiple cloud computing systems and/or individual network-enabled computing devices.”; paragraph [0056], “[…] the cloud storage engine 230 can assign different storage capacities for different users based on predefined criteria, e.g. capacity based on user affiliation, capacity based on subscription fee, etc. The maximum storage capacity can be recorded in a user’s account details, such as by passing the information to the account management module 212. However, in some cases, the cloud storage engine 230 can allow unlimited storage capacity.”); and […] on a basis of a storage unit information management table (paragraph [0056], “[…] the cloud storage engine 230 can assign different storage capacities for different users based on predefined criteria, e.g. capacity based on user affiliation, capacity based on subscription fee, etc. The maximum storage capacity can be recorded in a user’s account details, such as by passing the information to the account management module 212. However, in some cases, the cloud storage engine 230 can allow unlimited storage capacity.”). As pointed out hereinabove, Arrouye is an analogous art to the claimed invention. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Arrouye into the combined teachings of Zibuschka, DiGiorgio, and Yang to include “a storage unit information management table storage unit in which storage unit information as information indicating a state of a storage unit in each of the plurality of electronic control units is recorded; and a storage device determination unit determining a storage device as a destination of storage of the signature and the update file on a basis of a storage unit information management table.” The modification would be obvious because one of ordinary skill in the art would be motivated to select one of external network storage devices as a storage location for a data item. The selection can be based on a variety of criteria, such as random, the amount of space available, distance from the cloud storage engine, data item type, user preference, reliability of the external network storage device, etc. (Arrouye, paragraph [0062]). As per Claim 8, the rejection of Claim 7 is incorporated; and Zibuschka further discloses: wherein: the storage device determination unit determines the storage device on a basis of a distribution method of the update file from the distribution device (paragraph [0074], “[…] the data source may be a head unit 360 of a system of vehicle 300 (for example, an infotainment system of vehicle 300). Head unit 360 may be integrated into the second network. In other examples, head unit 360 may be equipped with an interface for a data medium 370 (an USB interface, for example), which may be used as a data source. In other examples, other components of vehicle 300 are equipped with an interface for a data medium (a USB interface, for example), which may be used as a data source.”). Response to Arguments Applicant’s arguments with respect to Claims 1, 12, and 14-16 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Conclusion Applicant’s amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the Examiner should be directed to Qing Chen whose telephone number is 571-270-1071. The Examiner can normally be reached on Monday through Friday from 9:00 AM to 5:00 PM ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, the Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at https://www.uspto.gov/ interviewpractice. If attempts to reach the Examiner by telephone are unsuccessful, the Examiner’s supervisor, Wei Mui, can be reached at 571-272-3708. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for more information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO customer service representative, call 800-786-9199 (in USA or Canada) or 571-272-1000. /Qing Chen/ Primary Examiner, Art Unit 2191
Read full office action

Prosecution Timeline

Feb 19, 2024
Application Filed
Nov 24, 2025
Non-Final Rejection mailed — §103
Jan 15, 2026
Applicant Interview (Telephonic)
Jan 15, 2026
Examiner Interview Summary
Feb 23, 2026
Response Filed
Apr 16, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12670089
METHOD AND SYSTEM FOR TESTING FUNCTIONALITY OF A SOFTWARE PROGRAM USING DIGITAL TWIN
2y 4m to grant Granted Jun 30, 2026
Patent 12663970
DATA PARALLEL PROGRAMMING TASK GRAPH OPTIMIZATION THROUGH DEVICE TELEMETRY
4y 3m to grant Granted Jun 23, 2026
Patent 12663972
COMPILING DEVICE AND METHOD FOR PERFORMANCE SPEED-UP OF A PROGRAM
3y 0m to grant Granted Jun 23, 2026
Patent 12663978
DEVICE PROGRAM CODE MANAGEMENT IN INFORMATION PROCESSING SYSTEM ENVIRONMENT
2y 12m to grant Granted Jun 23, 2026
Patent 12650915
ANALYSIS FUNCTION IMPARTING METHOD, ANALYSIS FUNCTION IMPARTING DEVICE, AND ANALYSIS FUNCTION IMPARTING PROGRAM
2y 1m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+53.0%)
3y 2m (~9m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 688 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month