Prosecution Insights
Last updated: August 17, 2026
Application No. 18/732,142

FLEETWIDE SERVERLESS FUNCTIONAL SAFETY PROTECTION FOR HYBRID CLOUD INTEROPERABILITY

Non-Final OA §103
Filed
Jun 03, 2024
Examiner
PEDERSEN, DAVID RUBEN
Art Unit
3658
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Red Hat Inc.
OA Round
3 (Non-Final)
57%
Grant Probability
Moderate
3-4
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 57% of resolved cases
57%
Career Allowance Rate
66 granted / 116 resolved
+4.9% vs TC avg
Strong +51% interview lift
Without
With
+51.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
22 currently pending
Career history
148
Total Applications
across all art units

Statute-Specific Performance

§101
14.1%
-25.9% vs TC avg
§103
59.1%
+19.1% vs TC avg
§102
11.8%
-28.2% vs TC avg
§112
13.1%
-26.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 116 resolved cases

Office Action

§103
DETAILED ACTION Claims 1-14, 16-21 are currently pending and have been examined in this application. Claim 15 is Canceled. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This action is in response to the “Request for Continued Examination” filed 07/24/2026. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-14, 16-21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen (US20210135883) in view of Guo (US20220026566) further in view of Davidovich (US20200298870). Claim 1: Chen explicitly teaches: A method, comprising: receiving, from a requesting entity, a message comprising an indication of a resource [of a vehicle] and an indication of the requesting entity; (Chen) – “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The message may then be received at the function (block 408).” (Para 0038) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. determining, based on the message and a set of safety rules for a set of resources [of the vehicle], a safety level of the resource, [wherein the set of safety rules is associated with a standard]; and (Chen) – “The identifier of the event source may then be validated (block 410). For example, the proxy controller 122, 124, 302, 322 may validate the identifier of the event source included within the message 142, 144, 200, 304, 324 received from the controller 128, 130. The proxy controller 122, 124, 302, 322 may validate the identifier of the event source using different techniques that depend on the type of the identifier of the event source. For example, if the identifier of the event source is cryptographically generated (e.g., a hash 326 included in the message 142, 144, 200, 304, 324 or encrypting of the message 142, 144, 200, 304, 324), the proxy controller 122, 124, 302, 322 may verify the identifier using a public key 136, 138, 332 associated with the controller 128, 130 (e.g., by processing the hash 326 with the public key 136, 138, 332 or decrypting the message 142, 144, 200, 304, 324 with the public key 136, 138, 332). As another example, if the identifier of the event source is a certificate 162, 166, 306 issued by a trusted authority, the proxy controller may verify the certificate 162, 166, 306 using another certificate 312 that is expected for messages 142, 144, 200, 304, 324 associated with execution of the function 104, 106. Additional details regarding validation of certificates 162, 166, 306 are discussed below in connection with the method 500 and FIG. 5.” (Para 0037) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. Per BRI, validation corresponds with safety level. exposing, by a processing device and to the requesting entity, a serverless function corresponding to the resource [of the vehicle] from amongst a plurality of serverless functions based on the safety level, (Chen) – “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. wherein the serverless function defines a level of access to the resource based on a hazard potential of the resource or trustworthy status of the requesting entity (Chen) – “The unique identifier of the controller 128, 130 may be selected such that only messages 142, 144 generated by the controller 128, 130 could include the unique identifier. In certain implementations, the unique identifier may be a unique cryptographic identifier of the controller 128, 130… In additional or alternative implementations, the controller 128, 130 may include a certificate within the message 142, 144 that corresponds to the controller 128, 130. For example, the authority database 158 includes functions 160, 164 associated with certificates 162, 166. The certificates 162, 166 may be issued (e.g., created by a trusted authority) for each function executed by the serverless computing environment, including the functions 104, 106. For example, the certificates 162, 166 may be issued by a trusted third-party certificate-issuing service and/or by the function 104, 106 itself and stored on the authority database 158.” (Para 0029) “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The identifier of the event source may then be validated (block 410). For example, the proxy controller 122, 124, 302, 322 may validate the identifier of the event source included within the message 142, 144, 200, 304, 324 received from the controller 128, 130. The proxy controller 122, 124, 302, 322 may validate the identifier of the event source using different techniques that depend on the type of the identifier of the event source. For example, if the identifier of the event source is cryptographically generated (e.g., a hash 326 included in the message 142, 144, 200, 304, 324 or encrypting of the message 142, 144, 200, 304, 324), the proxy controller 122, 124, 302, 322 may verify the identifier using a public key 136, 138, 332 associated with the controller 128, 130 (e.g., by processing the hash 326 with the public key 136, 138, 332 or decrypting the message 142, 144, 200, 304, 324 with the public key 136, 138, 332). As another example, if the identifier of the event source is a certificate 162, 166, 306 issued by a trusted authority, the proxy controller may verify the certificate 162, 166, 306 using another certificate 312 that is expected for messages 142, 144, 200, 304, 324 associated with execution of the function 104, 106. Additional details regarding validation of certificates 162, 166, 306 are discussed below in connection with the method 500 and FIG. 5.” (Para 0037) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Chen does not explicitly teach: of a vehicle … of the vehicle … wherein the set of safety rules is associated with a standard … of the vehicle Guo, in the same field of endeavor of connected vehicles, teaches: of a vehicle … of the vehicle … of the vehicle (Guo) – “The specification relates to a location data correction service for connected vehicles. The correction service is serverless and provided by one or more connected vehicles.” (Para 0001) Therefore, it would be obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to have modified the system of Chen with the correction service of Guo. One of ordinary skill in the art would have been motivated to make these modifications, with a reasonable expectation of success, “so that the legacy vehicle receives a benefit by correcting the legacy location data to minimize the variance” (Guo Abstract). Guo does not explicitly teach: wherein the set of safety rules is associated with a standard Davidovich, in the same field of endeavor of connected vehicles, teaches: wherein the set of safety rules is associated with a standard (Davidovich) – “Automotive Safety Integrity Levels (ASIL) refers to a classification of inherent safety risk in an automotive system or elements of such a system. ASIL classifications (levels) are used within ISO 26262 to express the level of risk reduction required to prevent a specific hazard.” (Para 0002) “The one or more safety mechanisms may be of a first safety level (for example ASIL-B compliant) that is higher than a second safety level (for example ASIL QM) of the Linux OS.” (Para 0121) “A memory domain interference safety mechanism is provided that will prevent the interference in the memory domain. The memory domain interference safety mechanism may manage accesses to the memory domain and enforce access rules that will prevent a software element from performing an unauthorized access to (or just an unauthorized modifying of) data or code belonging to another process (e.g. other executing software).” (Para 0140) Therefore, it would be obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to have modified the system of Chen with the method of implementing safety mechanisms of Davidovich. One of ordinary skill in the art would have been motivated to make these modifications, with a reasonable expectation of success, because “There is a need to provide a system that is safe enough despite the usage of Linux OS.” (Davidovich Para 0007). Claim 2: Chen in combination with the references relied upon in Claim 1 teach those respective limitations. Chen further teaches: wherein the serverless function abstracts a capability of the resource from an implementation of the resource. (Chen) – “The computing environments may provision the computing resources from among the computing units to computing systems requesting execution of functions associated with the computing systems. To allocate the computing resources, the computing environments typically rely on virtualization. Virtualizing the computing resources may abstract the specific computing unit and/or specific piece or portion of computing hardware that a requesting computing system is allocated.” (Para 0014) “In such implementations, the serverless computing environment may receive events from event sources that specify the functions for execution. In response to receiving such events, the serverless computing environment may allocate computing hardware for execution of the function specified by a received event. The computing hardware may then proceed with executing the function as specified by the event.” (Para 0015 Claim 3: Chen in combination with the references relied upon in Claim 1 teach those respective limitations. Chen does not explicitly teach the following limitations in full. However, Guo further teaches: wherein the resource comprises at least one of: a vehicle control system; a vehicle cabin control system; a computing resource of the vehicle; an application executing on the vehicle; an application programming interface (API) associated with the vehicle; an electronic control unit (ECU) within the vehicle; or firmware of the vehicle. (Guo) – “The specification relates to a location data correction service for connected vehicles. The correction service is serverless and provided by one or more connected vehicles.” (Para 0001) “The ego vehicle 123 includes one or more of the following elements: a processor 125; a rich sensor set 126; a standard-compliant GPS unit 150; a vehicle control system 153; a communication unit 145; an onboard unit 139; a memory 127; and a correction system 199. These elements may be communicatively coupled to one another via a bus 121. In some embodiments, the communication unit 145 includes a C-V2X radio.” (Para 0144) “In some embodiments, the onboard unit 139 is the computer system 200 depicted in FIG. 2. In some embodiments, the onboard unit 139 is an electronic control unit (ECU).” (Para 0147) Therefore, it would be obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to have modified the system of Chen with the correction service of Guo. One of ordinary skill in the art would have been motivated to make these modifications, with a reasonable expectation of success, “so that the legacy vehicle receives a benefit by correcting the legacy location data to minimize the variance” (Guo Abstract). Claim 4: Chen in combination with the references relied upon in Claim 1 teach those respective limitations. Chen further teaches: wherein the requesting entity comprises at least one of: a second vehicle; a user computing device; a cloud service; a non-user computing device; a trusted application; a non-trusted application; or a fleet management system. (Chen) – “As another example, if the identifier of the event source is a certificate 162, 166, 306 issued by a trusted authority, the proxy controller may verify the certificate 162, 166, 306 using another certificate 312 that is expected for messages 142, 144, 200, 304, 324 associated with execution of the function 104, 106.” (Para 0037) “For example, the serverless computing environments may rely on event sources, such as Amazon® S3, Google Cloud® Pub/Sub, and MQ Telemetry Transport (MQTT) event sources, to provide authentic and/or secure events for execution by the serverless computing environment.” (Para 0015) Examiner Note: Event Source corresponds with trusted application. Claim 5: Chen in combination with the references relied upon in Claim 1 teach those respective limitations. Chen does not explicitly teach the following limitations. Davidovich, in the same field of endeavor of connected vehicles, teaches: wherein the safety level comprises an automotive safety integrity level (ASIL) classification. (Davidovich) – “Automotive Safety Integrity Levels (ASIL) refers to a classification of inherent safety risk in an automotive system or elements of such a system. ASIL classifications (levels) are used within ISO 26262 to express the level of risk reduction required to prevent a specific hazard.” (Para 0002) “The one or more safety mechanisms may be of a first safety level (for example ASIL-B compliant) that is higher than a second safety level (for example ASIL QM) of the Linux OS.” (Para 0121) “A memory domain interference safety mechanism is provided that will prevent the interference in the memory domain. The memory domain interference safety mechanism may manage accesses to the memory domain and enforce access rules that will prevent a software element from performing an unauthorized access to (or just an unauthorized modifying of) data or code belonging to another process (e.g. other executing software).” (Para 0140) Therefore, it would be obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to have modified the system of Chen with the method of implementing safety mechanisms of Davidovich. One of ordinary skill in the art would have been motivated to make these modifications, with a reasonable expectation of success, because “There is a need to provide a system that is safe enough despite the usage of Linux OS.” (Davidovich Para 0007). Claim 6: Chen in combination with the references relied upon in Claim 5 teach those respective limitations. Chen further teaches: wherein [the ASIL classification] permits an interaction with the serverless function. (Chen) – “The identifier of the event source may then be validated (block 410). For example, the proxy controller 122, 124, 302, 322 may validate the identifier of the event source included within the message 142, 144, 200, 304, 324 received from the controller 128, 130. The proxy controller 122, 124, 302, 322 may validate the identifier of the event source using different techniques that depend on the type of the identifier of the event source. For example, if the identifier of the event source is cryptographically generated (e.g., a hash 326 included in the message 142, 144, 200, 304, 324 or encrypting of the message 142, 144, 200, 304, 324), the proxy controller 122, 124, 302, 322 may verify the identifier using a public key 136, 138, 332 associated with the controller 128, 130 (e.g., by processing the hash 326 with the public key 136, 138, 332 or decrypting the message 142, 144, 200, 304, 324 with the public key 136, 138, 332). As another example, if the identifier of the event source is a certificate 162, 166, 306 issued by a trusted authority, the proxy controller may verify the certificate 162, 166, 306 using another certificate 312 that is expected for messages 142, 144, 200, 304, 324 associated with execution of the function 104, 106. Additional details regarding validation of certificates 162, 166, 306 are discussed below in connection with the method 500 and FIG. 5.” (Para 0037) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. Chen does not explicitly teach: the ASIL classification Davidovich, in the same field of endeavor of connected vehicles, teaches: the ASIL classification (Davidovich) – “Automotive Safety Integrity Levels (ASIL) refers to a classification of inherent safety risk in an automotive system or elements of such a system. ASIL classifications (levels) are used within ISO 26262 to express the level of risk reduction required to prevent a specific hazard.” (Para 0002) “The one or more safety mechanisms may be of a first safety level (for example ASIL-B compliant) that is higher than a second safety level (for example ASIL QM) of the Linux OS.” (Para 0121) “A memory domain interference safety mechanism is provided that will prevent the interference in the memory domain. The memory domain interference safety mechanism may manage accesses to the memory domain and enforce access rules that will prevent a software element from performing an unauthorized access to (or just an unauthorized modifying of) data or code belonging to another process (e.g. other executing software).” (Para 0140) Therefore, it would be obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to have modified the system of Chen with the method of implementing safety mechanisms of Davidovich. One of ordinary skill in the art would have been motivated to make these modifications, with a reasonable expectation of success, because “There is a need to provide a system that is safe enough despite the usage of Linux OS.” (Davidovich Para 0007). Claim 7: Chen in combination with the references relied upon in Claim 1 teach those respective limitations. Chen further teaches: wherein exposing the serverless function corresponding to the resource [of the vehicle] comprises transmitting an indication of the serverless function to the requesting entity. (Chen) – “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. Chen does not explicitly teach: of the vehicle Guo, in the same field of endeavor of connected vehicles, teaches: of the vehicle (Guo) – “The specification relates to a location data correction service for connected vehicles. The correction service is serverless and provided by one or more connected vehicles.” (Para 0001) Therefore, it would be obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to have modified the system of Chen with the correction service of Guo. One of ordinary skill in the art would have been motivated to make these modifications, with a reasonable expectation of success, “so that the legacy vehicle receives a benefit by correcting the legacy location data to minimize the variance” (Guo Abstract). Claim 8: Chen in combination with the references relied upon in Claim 1 teach those respective limitations. Chen further teaches: further comprising: receiving, from the requesting entity, a request that indicates an action with respect to the resource based on the serverless function; and (Chen) – “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) executing the action based on the request. (Chen) – “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Claim 9: Chen in combination with the references relied upon in Claim 8 teach those respective limitations. Chen further teaches: wherein executing the action based on the request comprises at least one of: receiving data from the requesting entity; transmitting data to the requesting entity; controlling the vehicle; controlling a cabin system of the vehicle; or updating a vehicle system of the vehicle. (Chen) – “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Claim 10: Chen in combination with the references relied upon in Claim 8 teach those respective limitations. Chen further teaches: wherein the serverless function defines allowed parameters within the request. (Chen) – “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Claim 11: Chen in combination with the references relied upon in Claim 8 teach those respective limitations. Chen further teaches: further comprising: activating, based on the request, the resource; and (Chen) – “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) deactivating the resource subsequent to executing the action. (Chen) – “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) Examiner Note: Since the function is executed according to the event, it is implied that the function ends once the event is complete. Claim 12: Chen in combination with the references relied upon in Claim 1 teach those respective limitations. Chen further teaches: wherein the serverless function comprises a first serverless function when the safety level of the resource comprises a first safety level, wherein the serverless function comprises a second serverless function when the safety level of the resource comprises a second safety level, and wherein the first serverless function is different from the second serverless function. (Chen) – “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Claim 13: Chen in combination with the references relied upon in Claim 1 teach those respective limitations. Chen further teaches: wherein the serverless function comprises a first serverless function when the requesting entity comprises a first requesting entity, wherein the serverless function comprises a second serverless function when the requesting entity comprises a second requesting entity, and wherein the first serverless function is different from the second serverless function. (Chen) – “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Claim 14: Chen in combination with the references relied upon in Claim 1 teach those respective limitations. Chen further teaches: further comprising: obtaining, prior to receiving the message and from a cloud service, the set of safety rules and the plurality of serverless functions. (Chen) – “As another example, if the identifier of the event source is a certificate 162, 166, 306 issued by a trusted authority, the proxy controller may verify the certificate 162, 166, 306 using another certificate 312 that is expected for messages 142, 144, 200, 304, 324 associated with execution of the function 104, 106.” (Para 0037) “For example, the serverless computing environments may rely on event sources, such as Amazon® S3, Google Cloud® Pub/Sub, and MQ Telemetry Transport (MQTT) event sources, to provide authentic and/or secure events for execution by the serverless computing environment.” (Para 0015) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Claim 15: Canceled Claim 16: Chen explicitly teaches: A system, comprising: a memory; and a processing device, operatively coupled to the memory, to: receive, from a requesting entity, a message comprising an indication of a resource [of a vehicle] and an indication of the requesting entity; (Chen) – “In another embodiment, a system is provided including a processor and a memory. The memory may store instructions which, when executed by the processor, cause the processor to detect that a function of a serverless computing environment is created within a first container of the serverless computing environment and determine that a label corresponding to the function indicates that verification is required for events intended for execution by the function.” (Para 0003) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The message may then be received at the function (block 408).” (Para 0038) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. determine, based on the message and a set of safety rules for a set of resources [of the vehicle], a safety level of the resource, [wherein the set of safety rules is associated with a standard]; and (Chen) – “The identifier of the event source may then be validated (block 410). For example, the proxy controller 122, 124, 302, 322 may validate the identifier of the event source included within the message 142, 144, 200, 304, 324 received from the controller 128, 130. The proxy controller 122, 124, 302, 322 may validate the identifier of the event source using different techniques that depend on the type of the identifier of the event source. For example, if the identifier of the event source is cryptographically generated (e.g., a hash 326 included in the message 142, 144, 200, 304, 324 or encrypting of the message 142, 144, 200, 304, 324), the proxy controller 122, 124, 302, 322 may verify the identifier using a public key 136, 138, 332 associated with the controller 128, 130 (e.g., by processing the hash 326 with the public key 136, 138, 332 or decrypting the message 142, 144, 200, 304, 324 with the public key 136, 138, 332). As another example, if the identifier of the event source is a certificate 162, 166, 306 issued by a trusted authority, the proxy controller may verify the certificate 162, 166, 306 using another certificate 312 that is expected for messages 142, 144, 200, 304, 324 associated with execution of the function 104, 106. Additional details regarding validation of certificates 162, 166, 306 are discussed below in connection with the method 500 and FIG. 5.” (Para 0037) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. Per BRI, validation corresponds with safety level. expose, to the requesting entity, a serverless function corresponding to the resource [of the vehicle] from amongst a plurality of serverless functions based on the safety level (Chen) – “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. wherein the serverless function defines a level of access to the resource based on a hazard potential of the resource or trustworthy status of the requesting entity (Chen) – “The unique identifier of the controller 128, 130 may be selected such that only messages 142, 144 generated by the controller 128, 130 could include the unique identifier. In certain implementations, the unique identifier may be a unique cryptographic identifier of the controller 128, 130… In additional or alternative implementations, the controller 128, 130 may include a certificate within the message 142, 144 that corresponds to the controller 128, 130. For example, the authority database 158 includes functions 160, 164 associated with certificates 162, 166. The certificates 162, 166 may be issued (e.g., created by a trusted authority) for each function executed by the serverless computing environment, including the functions 104, 106. For example, the certificates 162, 166 may be issued by a trusted third-party certificate-issuing service and/or by the function 104, 106 itself and stored on the authority database 158.” (Para 0029) “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The identifier of the event source may then be validated (block 410). For example, the proxy controller 122, 124, 302, 322 may validate the identifier of the event source included within the message 142, 144, 200, 304, 324 received from the controller 128, 130. The proxy controller 122, 124, 302, 322 may validate the identifier of the event source using different techniques that depend on the type of the identifier of the event source. For example, if the identifier of the event source is cryptographically generated (e.g., a hash 326 included in the message 142, 144, 200, 304, 324 or encrypting of the message 142, 144, 200, 304, 324), the proxy controller 122, 124, 302, 322 may verify the identifier using a public key 136, 138, 332 associated with the controller 128, 130 (e.g., by processing the hash 326 with the public key 136, 138, 332 or decrypting the message 142, 144, 200, 304, 324 with the public key 136, 138, 332). As another example, if the identifier of the event source is a certificate 162, 166, 306 issued by a trusted authority, the proxy controller may verify the certificate 162, 166, 306 using another certificate 312 that is expected for messages 142, 144, 200, 304, 324 associated with execution of the function 104, 106. Additional details regarding validation of certificates 162, 166, 306 are discussed below in connection with the method 500 and FIG. 5.” (Para 0037) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Chen does not explicitly teach: of a vehicle … of the vehicle … wherein the set of safety rules is associated with a standard … of the vehicle Guo, in the same field of endeavor of connected vehicles, teaches: of a vehicle … of the vehicle … of the vehicle (Guo) – “The specification relates to a location data correction service for connected vehicles. The correction service is serverless and provided by one or more connected vehicles.” (Para 0001) Therefore, it would be obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to have modified the system of Chen with the correction service of Guo. One of ordinary skill in the art would have been motivated to make these modifications, with a reasonable expectation of success, “so that the legacy vehicle receives a benefit by correcting the legacy location data to minimize the variance” (Guo Abstract). Guo does not explicitly teach: wherein the set of safety rules is associated with a standard Davidovich, in the same field of endeavor of connected vehicles, teaches: wherein the set of safety rules is associated with a standard (Davidovich) – “Automotive Safety Integrity Levels (ASIL) refers to a classification of inherent safety risk in an automotive system or elements of such a system. ASIL classifications (levels) are used within ISO 26262 to express the level of risk reduction required to prevent a specific hazard.” (Para 0002) “The one or more safety mechanisms may be of a first safety level (for example ASIL-B compliant) that is higher than a second safety level (for example ASIL QM) of the Linux OS.” (Para 0121) “A memory domain interference safety mechanism is provided that will prevent the interference in the memory domain. The memory domain interference safety mechanism may manage accesses to the memory domain and enforce access rules that will prevent a software element from performing an unauthorized access to (or just an unauthorized modifying of) data or code belonging to another process (e.g. other executing software).” (Para 0140) Therefore, it would be obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to have modified the system of Chen with the method of implementing safety mechanisms of Davidovich. One of ordinary skill in the art would have been motivated to make these modifications, with a reasonable expectation of success, because “There is a need to provide a system that is safe enough despite the usage of Linux OS.” (Davidovich Para 0007). Claim 17: Rejected based on the same rationale as Claim 2 Claim 18: Rejected based on the same rationale as Claim 8 Claim 19: Chen explicitly teaches: A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processing device, cause the processing device to: receive, from a requesting entity, a message comprising an indication of a resource [of a vehicle] and an indication of the requesting entity; (Chen) – “In another embodiment, a system is provided including a processor and a memory. The memory may store instructions which, when executed by the processor, cause the processor to detect that a function of a serverless computing environment is created within a first container of the serverless computing environment and determine that a label corresponding to the function indicates that verification is required for events intended for execution by the function.” (Para 0003) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The message may then be received at the function (block 408).” (Para 0038) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. determine, based on the message and a set of safety rules for a set of resources [of the vehicle], a safety level of the resource, [wherein the set of safety rules is associated with a standard]; and (Chen) – “The identifier of the event source may then be validated (block 410). For example, the proxy controller 122, 124, 302, 322 may validate the identifier of the event source included within the message 142, 144, 200, 304, 324 received from the controller 128, 130. The proxy controller 122, 124, 302, 322 may validate the identifier of the event source using different techniques that depend on the type of the identifier of the event source. For example, if the identifier of the event source is cryptographically generated (e.g., a hash 326 included in the message 142, 144, 200, 304, 324 or encrypting of the message 142, 144, 200, 304, 324), the proxy controller 122, 124, 302, 322 may verify the identifier using a public key 136, 138, 332 associated with the controller 128, 130 (e.g., by processing the hash 326 with the public key 136, 138, 332 or decrypting the message 142, 144, 200, 304, 324 with the public key 136, 138, 332). As another example, if the identifier of the event source is a certificate 162, 166, 306 issued by a trusted authority, the proxy controller may verify the certificate 162, 166, 306 using another certificate 312 that is expected for messages 142, 144, 200, 304, 324 associated with execution of the function 104, 106. Additional details regarding validation of certificates 162, 166, 306 are discussed below in connection with the method 500 and FIG. 5.” (Para 0037) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. Per BRI, validation corresponds with safety level. expose, to the requesting entity, a serverless function corresponding to the resource [of the vehicle] from amongst a plurality of serverless functions based on the safety level, (Chen) – “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Examiner Note: Bracketed text note explicitly taught by primary reference, but is taught by non-primary reference later in the rejection. wherein the serverless function defines a level of access to the resource based on a hazard potential of the resource or trustworthy status of the requesting entity (Chen) – “The unique identifier of the controller 128, 130 may be selected such that only messages 142, 144 generated by the controller 128, 130 could include the unique identifier. In certain implementations, the unique identifier may be a unique cryptographic identifier of the controller 128, 130… In additional or alternative implementations, the controller 128, 130 may include a certificate within the message 142, 144 that corresponds to the controller 128, 130. For example, the authority database 158 includes functions 160, 164 associated with certificates 162, 166. The certificates 162, 166 may be issued (e.g., created by a trusted authority) for each function executed by the serverless computing environment, including the functions 104, 106. For example, the certificates 162, 166 may be issued by a trusted third-party certificate-issuing service and/or by the function 104, 106 itself and stored on the authority database 158.” (Para 0029) “A message may then be created that includes the event (block 404). For example, the controller 128, 130 that received the event may create a message 142, 144, 200, 304, 324 in response to receiving the events 154, 156, 204, 308, 328.” (Para 0034) “The message may be signed with an identifier of the event source (block 406). For example, the controller 128, 130 may sign the message 142, 144, 200, 304, 324 with an identifier of the event source 146, 148 from which the event 154, 156, 204, 308, 328 was received.” (Para 0035) “The identifier of the event source may then be validated (block 410). For example, the proxy controller 122, 124, 302, 322 may validate the identifier of the event source included within the message 142, 144, 200, 304, 324 received from the controller 128, 130. The proxy controller 122, 124, 302, 322 may validate the identifier of the event source using different techniques that depend on the type of the identifier of the event source. For example, if the identifier of the event source is cryptographically generated (e.g., a hash 326 included in the message 142, 144, 200, 304, 324 or encrypting of the message 142, 144, 200, 304, 324), the proxy controller 122, 124, 302, 322 may verify the identifier using a public key 136, 138, 332 associated with the controller 128, 130 (e.g., by processing the hash 326 with the public key 136, 138, 332 or decrypting the message 142, 144, 200, 304, 324 with the public key 136, 138, 332). As another example, if the identifier of the event source is a certificate 162, 166, 306 issued by a trusted authority, the proxy controller may verify the certificate 162, 166, 306 using another certificate 312 that is expected for messages 142, 144, 200, 304, 324 associated with execution of the function 104, 106. Additional details regarding validation of certificates 162, 166, 306 are discussed below in connection with the method 500 and FIG. 5.” (Para 0037) “The event may then be executed using the function (block 412). For example, if the identifier of the event source is successfully validated at block 410, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. For example, after validating the identifier of the event source 146, 148, the proxy controller 122, 124, 302, 322 may forward all or part of the message 142, 144, 200, 304, 324 to the function 104, 106 (e.g., to the container 103, 105). After receiving the message 142, 144, 200, 304, 324, the function 104, 106 may execute according to the event 154, 156, 204, 308, 328. As explained above, the event 154, 156, 204, 308, 328 may include information, configurations, and/or data for use in executing the function 104, 106. Accordingly, the function 104, 106, when executing, may incorporate the information provided within the event 154, 156, 204, 308, 328.” (Para 0038) “The method 400 may begin with receiving an event from an event source for execution by a function of a serverless computing environment (block 402). For example, the serverless computing environment 102 may receive an event 154, 156, 204, 308, 328 from an event source 146, 148 for execution by a function 104, 106 of the serverless computing environment 102… In certain implementations, the event 154, 156, 204, 308, 328 may specify the function 104, 106 for execution. In additional or alternative implementations, the event source 146, 148 may correspond to a particular function 104, 106 of the serverless computing environment 102 and the function 104, 106 for execution may be determined based on the event source 146, 148 from which the event 154, 156, 204, 308, 328 is received. In still further implementations, the serverless computing environment (e.g., the controller 128, 130) may identify a type of the event 154, 156, 204, 308, 328.” (Para 0033) Chen does not explicitly teach: of a vehicle … of the vehicle … wherein the set of safety rules is associated with a standard … of the vehicle Guo, in the same field of endeavor of connected vehicles, teaches: of a vehicle … of the vehicle … of the vehicle (Guo) – “The specification relates to a location data correction service for connected vehicles. The correction service is serverless and provided by one or more connected vehicles.” (Para 0001) Therefore, it would be obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to have modified the system of Chen with the correction service of Guo. One of ordinary skill in the art would have been motivated to make these modifications, with a reasonable expectation of success, “so that the legacy vehicle receives a benefit by correcting the legacy location data to minimize the variance” (Guo Abstract). Guo does not explicitly teach: wherein the set of safety rules is associated with a standard Davidovich, in the same field of endeavor of connected vehicles, teaches: wherein the set of safety rules is associated with a standard (Davidovich) – “Automotive Safety Integrity Levels (ASIL) refers to a classification of inherent safety risk in an automotive system or elements of such a system. ASIL classifications (levels) are used within ISO 26262 to express the level of risk reduction required to prevent a specific hazard.” (Para 0002) “The one or more safety mechanisms may be of a first safety level (for example ASIL-B compliant) that is higher than a second safety level (for example ASIL QM) of the Linux OS.” (Para 0121) “A memory domain interference safety mechanism is provided that will prevent the interference in the memory domain. The memory domain interference safety mechanism may manage accesses to the memory domain and enforce access rules that will prevent a software element from performing an unauthorized access to (or just an unauthorized modifying of) data or code belonging to another process (e.g. other executing software).” (Para 0140) Therefore, it would be obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to have modified the system of Chen with the method of implementing safety mechanisms of Davidovich. One of ordinary skill in the art would have been motivated to make these modifications, with a reasonable expectation of success, because “There is a need to provide a system that is safe enough despite the usage of Linux OS.” (Davidovich Para 0007). Claim 20: Rejected based on the same rationale as Claim 2 Claim 21: Rejected based on the same rationale as Claim 5 Response to Arguments Applicant's arguments with respect to the 35 U.S.C. 103 rejections mailed 06/04/2026 have been fully considered but are not convincing. Rejection rationale has been updated to reflect amendment. Specifically, Applicant argues: “Without acquiescing to the Office action's position, the Applicant notes that in the cited paragraphs, Chen merely teaches "[t]he message may be signed with an identifier of the event source" and "the identifier may be a unique identifier associated with the event source." Chen, paragraph [0035]. Chen does not appear to teach anything related to defining a level of access. Moreover, Chen fails to teach or suggest that the identifier (the alleged "serverless function") defining a level of access based on a hazard potential of the resource or trustworthy status of the event source (the alleged "requesting entity"). As a result, the Applicant asserts that Chen fails to teach the above-referenced feature of claim 1. Guo and Davidovich both remain silent regarding defining a level of access to a resource based on a hazard potential of the resource or trustworthy status of a requesting entity. Therefore, Guo and Davidovich fail to overcome the deficiencies of Chen in supplying the above-referenced feature of claim 1. In view of the above, the combination of Chen, Guo, and Davidovich fails to disclose, teach, or suggest at least "wherein the serverless function defines a level of access to the resource based on a hazard potential of the resource or trustworthy status of the requesting entity" and claim 1 is allowable.” However, this is unconvincing. The assertion that “Chen does not appear to teach anything related to defining a level of access” appears to rest upon an overly narrow interpretation. Per BRI, merely granting or denying access would correspond with a level of access. Therefore, the validation process of Chen corresponds with this. Moreover, Chen teaches validating identifiers based on trust certificates (See Chen 0029 and 0037) which corresponds with a trustworthy status of the requesting entity. As such, all outstanding claims remain rejected in view of the prior art. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Behm (US20210099339) teaches a trust manager in a serverless computing service. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DAVID RUBEN PEDERSEN whose telephone number is (571)272-9696. The examiner can normally be reached M-Th: 07:00 -16:00 Eastern. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ramon Mercado can be reached at (571) 270-5744. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DAVID RUBEN PEDERSEN/Examiner, Art Unit 3658
Read full office action

Prosecution Timeline

Show 1 earlier event
Jan 15, 2026
Non-Final Rejection mailed — §103
Mar 24, 2026
Examiner Interview Summary
Mar 24, 2026
Applicant Interview (Telephonic)
Mar 26, 2026
Response Filed
Jun 04, 2026
Final Rejection mailed — §103
Jul 24, 2026
Request for Continued Examination
Jul 29, 2026
Response after Non-Final Action
Aug 07, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12704381
TRIP PLANNING WITH ENERGY CONSTRAINT
3y 0m to grant Granted Aug 11, 2026
Patent 12682691
EXPEDITED UPDATE OF CACHED DATA FOR DEVICES IN STANDBY
2y 8m to grant Granted Jul 14, 2026
Patent 12682762
NAVIGATION PLANNING SYSTEM AND NAVIGATION PLANNING METHOD
1y 10m to grant Granted Jul 14, 2026
Patent 12668273
Hierarchical Planning Through Goal-Conditioned Offline Reinforcement Learning
2y 4m to grant Granted Jun 30, 2026
Patent 12663291
VEHICLE TRAVEL CONTROL ASSISTANCE SYSTEM HAVING MAP UPDATE FUNCTION, MAP UPDATE SERVER APPARATUS, AND ASSISTANCE SERVER APPARATUS
3y 2m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
57%
Grant Probability
99%
With Interview (+51.1%)
3y 0m (~10m remaining)
Median Time to Grant
High
PTA Risk
Based on 116 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month