DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 are examined.
Claims 1-20 are rejected.
Information Disclosure Statement
The argument regarding the IDS has been persuasive; the objection has been withdrawn.
Specification
The new title has been accepted.
Response to Amendment
Applicant’s arguments filed 05/04/2026 have been fully considered.
As per the rejections pertaining to 35 U.S.C. 112(b), necessary amendments have been made to overcome the rejections; the associated rejections have been withdrawn.
As per the rejections pertaining to 35 U.S.C. 102 and 35 U.S.C. 103, the rejections have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Wang (CN 113051112 A).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 8-9 are rejected under 35 U.S.C. 103 as being unpatentable over Barr (“AWS CloudTrail Update – SSE-KMS Encryption & Log File Integrity Verification,” 2015) from henceforth referred to as Barr in view of Wang (CN 113051112 A).
Per claim 8, Barr teaches
A management server comprising (page 2):
A memory configured to store computer-executable instructions (page 2);
At least one processor configured to access the memory and execute the instruction (page 2); and
A communication device configured to perform communication with an electronic device, wherein the at least one processor is configured to (page 2):
Verify integrity of an encrypted OTA log based on an electronic signature combined with the encrypted OTA log based on receiving the encrypted OTA log from the electronic device (page 3, digital signature is used as part of the validation and verification process);
Verify an access authority of a user who has entered a request for decryption of the encrypted OTA log based on receiving the request for decryption; and (page 2, decrypt permission is applied to the principal – IAM users, roles, groups, etc)
Store the encrypted OTA log based on the integrity of the encrypted OTA log having been verified (page 2, validation and verification is done on encrypted log files before they are stored in the S3 bucket)
Wherein the encrypted OTA log is generated by applying an OTA log to an encryption model (page 1, first paragraph, supporting encryption of logs using SSE-KMS and log file integrity validation)
Barr fails to teach, but Wang teaches, the following:
…based on failure of over-the-air (OTA) programming at an end point in time when the OTA programming performed in a target controller ends, and (Wang, top of page 5, "therefore, when a certain ECU occurs the accidental fault; it can directly obtain the ECU fault operation log cached during the fault period and the vehicle CAN message data cached in the same time period by the gateway...[...] the gateway through the ECU fault operation log and the vehicle CAN message data are uploaded to the remote server, which is convenient for the subsequent fault ECU accurately locating fault generation reason." The log is transmitted upon the failure of the OTA and the log is encrypted, and thus the encryption Is based upon the failure of the OTA)
Wherein the OTA log comprises logs accumulated from a start point in time when the OTA programming is performed in the target controller until the end point in time (Wang, top of page 11, “The invention can monitor the running state of all the ECU in the vehicle for a long time”)
It is obvious to a person of ordinary skill in the art prior to the effective filing date of the claimed invention to combine the two prior art because by doing so the invention can improve the stability of the ECU whilst keeping the data flow controllable (Wang, top of page 11)
Per claim 9, Barr in view of Wang teaches
The management server of claim 8, wherein the at least one processor is configured to obtain an OTA log by performing decryption of the encrypted OTA log based on the access authority of the user based on the access authority of the user having been verified (Barr, page 2, the decrypt permission is set to the principal and only those who have access will be able to obtain the OTA log)
Claim(s) 10 is rejected under 35 U.S.C. 103 as being unpatentable over Barr in view of Wang in further view of Yoo (US 20240362104 A1) from henceforth referred to as Yoo.
Per claim 10, Barr in view of Wang teaches
The management server of claim 9, wherein the at least one processor is configured to:
….provide [data] to the user in response to the request for decryption…. (Barr, page 2, information in the S3 bucket is released only if the user has appropriate level of security)
Barr in view of Wang fails to teach
Obtain status information of a target controller corresponding to the OTA log and a communication record between the target controller and the main controller which are included in the OTA log; and
Provide a cause of failure of OTA in the target controller…. Based on the status information of the target controller and the communication record.
However Yoo teaches
Obtain status information of a target controller corresponding to the OTA log and a communication record between the target controller and the main controller which are included in the OTA log; and ([0050] uses Redfish API to collect information such as operating system information, firmware information, etc)
Provide a cause of failure of OTA in the target controller…. Based on the status information of the target controller and the communication record. ([0049] the management server analyzes logs and patterns when an issue of the fault occurs in any device of the management target server…. [0067] the data of the analysis can be shown to the user terminal via Flask Response User Web page)
It is obvious to a person of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Barr to incorporate the teachings of Yoo because Yoo demonstrates how a structured and unstructured log data can be used for failure analysis, which is important since this optimization can allow the servers to be managed smoothly and respond smoothly to events (Yoo, [0004]).
Claims 1-7, 11-20 are rejected under 35 U.S.C. 103 as being unpatentable over Sangameswaran et al (US 11782691 B2) from henceforth referred to as Sangameswaran in view of Barr (“AWS CloudTrail Update – SSE-KMS Encryption & Log File Integrity Verification,” 2015) from henceforth referred to as Barr in further view of Wang (CN 113051112 A).
Per claim 1, Sangameswaran teaches:
An electronic device comprising ([2] vehicle electronic control units):
a memory configured to store computer-executable instructions ([9] memory);
at least one processor configured to access the memory and execute the instruction ([10] processor); and
a communication device configured to perform communication with a management server ([25] obtaining over-the-air (OTA) updates that allow a customer to update vehicle software without visiting a dealer),
wherein the at least one processor is configured to:
allocate a first target area to a memory of a target controller at a start point in time when over-the-air (OTA) programming is performed in the target controller by a main controller ([30] initial manifest and the update state log is stored on the target device);
store an OTA log containing a communication record between the target controller and the main controller in the first target area ([30] initial manifest and the update state log is stored on the target device);
Sangameswaran fails to teach
apply the OTA log to an encryption model
However, Barr teaches
apply the OTA log to an encryption model (page 1, first paragraph, supporting encryption of logs using SSE-KMS and log file integrity validation)
It is obvious to a person of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Sangameswaran to incorporate the teachings of Barr because the AWS CloudTrail documentation demonstrates that encryption and integrity verification of log data are well-known practices in remote system logging.
Sangameswaran in view of Barr fails to teach
…transmit an … OTA log to the management server based on failure of the OTA at an end point in time when the OTA performed in the target controller ends
wherein the OTA log comprises logs accumulated from the start point in time until the end point in time
However, Wang teaches
…transmit an … OTA log to the management server based on failure of the OTA at an end point in time when the OTA performed in the target controller ends (top of page 5, "therefore, when a certain ECU occurs the accidental fault; it can directly obtain the ECU fault operation log cached during the fault period and the vehicle CAN message data cached in the same time period by the gateway...[...] the gateway through the ECU fault operation log and the vehicle CAN message data are uploaded to the remote server, which is convenient for the subsequent fault ECU accurately locating fault generation reason")
wherein the OTA log comprises logs accumulated from the start point in time until the end point in time (top of page 11, “The invention can monitor the running state of all the ECU in the vehicle for a long time”).
It is obvious to a person of ordinary skill in the art prior to the effective filing date of the claimed invention to combine the two prior art because by doing so the invention can improve the stability of the ECU whilst keeping the data flow controllable (Wang, top of page 11)
Sangameswaran in view of Barr in further view of Wang teaches the following claims:
Per claim 2,
The electronic device of claim 1, wherein the at least one processor is configured to:
allocate a second target area different from the first target area to a memory of the main controller at the start point in time when the OTA is performed; (Sangameswaran, [35] GIVIS system can be set to receive the post-update log. A person of ordinary skill in the art prior to the earliest priority date of the claimed invention would understand that, in order to receive and process the log, memory must be allocated to store the log data. Therefore, it would have been obvious to allocate memory for the log)
determine at least one of the first target area, or the second target area, or any combination thereof as an area for storing the OTA log, before performing communication between the target controller and the main controller; and (Sangameswaran [30] update state log is stored on the target device)
store the OTA log in the determined area (Sangameswaran [30] update state log is stored on the target device)
Per claim 3,
The electronic device of claim 1, wherein the at least one processor is configured to:
obtain status information including at least one of power information of a vehicle including the target controller, OTA task information, or control information of the target controller, or any combination thereof; and (Sangameswaran, [30] the process will receive a state log identifying the success or failure of various update installations)
store the status information and the OTA log in the first target area (Sangameswaran, FIG. 2B, the post update state log is sent. It would have been obvious to a person of ordinary skill in the art prior to the effective filing date of the claimed invention that the data is stored in the first target area prior to the transmission because data transmission requires the data to be held in memory or storage at the source location before being transmitted)
Per claim 4,
The electronic device of claim 1, wherein the at least one processor is configured to:
determine whether the OTA is successful, based on at least one of a log of download phase, a log of background transfer phase, a log of update phase, or a log of OTA end phase, or any combination thereof, which is included in the OTA log at the end point in time when the OTA ends; and (Sangameswaran, [35] post-update log that includes the success or failure of updates is sent)
delete the OTA log stored in the first target area based on the OTA being successful at the end point in time when the OTA ends (Sangameswaran, [36] teaches that “it is also possible, for the process to log or record the transmission of certain software version updates to a vehicle.” By stating that this is possible, the prior art implies that long-term retention on the target device is not the typical case, but rather an optional or situational practice. Therefore, a person of ordinary skill in the art prior to the effective priority date of the claimed invention would have understood that such logs are generally not kept long term on the target device).
Per claim 5,
The electronic device of claim 1, wherein the encrypted OTA log comprises a first encrypted OTA log obtained by applying at least one OTA log to a public key encryption algorithm (Barr, page 1, first paragraph, supporting encryption of logs using SSE-KMS and log file integrity validation) based on the OTA failing (Wang, top of page 5, "therefore, when a certain ECU occurs the accidental fault; it can directly obtain the ECU fault operation log cached during the fault period and the vehicle CAN message data cached in the same time period by the gateway...[...] the gateway through the ECU fault operation log and the vehicle CAN message data are uploaded to the remote server, which is convenient for the subsequent fault ECU accurately locating fault generation reason." The log is transmitted upon the failure of the OTA and the log is encrypted, and thus the encryption Is based upon the failure of the OTA)
Per claim 6,
The electronic device of claim 5, wherein the encrypted OTA log further comprises a second encrypted OTA log obtained by applying at least one OTA log to a hash algorithm and encryption algorithm (Barr, page 1, first paragraph, supporting encryption of logs using SSE-KMS and log file integrity validation) based on the OTA failing (Wang, top of page 5, "therefore, when a certain ECU occurs the accidental fault; it can directly obtain the ECU fault operation log cached during the fault period and the vehicle CAN message data cached in the same time period by the gateway...[...] the gateway through the ECU fault operation log and the vehicle CAN message data are uploaded to the remote server, which is convenient for the subsequent fault ECU accurately locating fault generation reason." The log is transmitted upon the failure of the OTA and the log is encrypted, and thus the encryption Is based upon the failure of the OTA)
Per claim 7,
The electronic device of claim 6, wherein the at least one processor is configured to combine an electronic signature capable of verifying integrity with at least one of the first encrypted OTA log, or the second encrypted OTA log, or any combination thereof (Barr, page 1, first paragraph, supporting encryption of logs using SSE-KMS and log file integrity validation)
Per claim 11, Sangameswaran teaches:
allocating a first target area to a memory of a target controller at a start point in time when performing over-the-air (OTA) programming in the target controller by a main controller; ([30] initial manifest and the update state log is stored on the target device);
storing an OTA log containing a communication record between the target controller and the main controller in the first target area; and ([30] initial manifest and the update state log is stored on the target device);
Sangameswaran fails to teach
applying the OTA log to an encryption model
However, Barr teaches
applying the OTA log to an encryption model (page 1, first paragraph, supporting encryption of logs using SSE-KMS and log file integrity validation)
It is obvious to a person of ordinary skill in the art prior to the effective priority date of the claimed invention to modify Sangameswaran to incorporate the teachings of Barr because the AWS CloudTrail documentation demonstrates that encryption and integrity verification of log data are well-known practices in remote system logging.
Sangameswaran in view of Barr fails to teach
… transmitting an …OTA log to the management server based on failure of the OTA at an end point in time when the OTA performed in the target controller ends
wherein the OTA log comprises logs accumulated from the start point in time until the end point in time
However, Wang teaches
… transmitting an …OTA log to the management server based on failure of the OTA at an end point in time when the OTA performed in the target controller ends (top of page 5, "therefore, when a certain ECU occurs the accidental fault; it can directly obtain the ECU fault operation log cached during the fault period and the vehicle CAN message data cached in the same time period by the gateway...[...] the gateway through the ECU fault operation log and the vehicle CAN message data are uploaded to the remote server, which is convenient for the subsequent fault ECU accurately locating fault generation reason")
wherein the OTA log comprises logs accumulated from the start point in time until the end point in time (top of page 11, “The invention can monitor the running state of all the ECU in the vehicle for a long time”).
It is obvious to a person of ordinary skill in the art prior to the effective filing date of the claimed invention to combine the two prior art because by doing so the invention can improve the stability of the ECU whilst keeping the data flow controllable (Wang, top of page 11)
As for claims 12-17, these claims recite similar limitations found in claims 2-7 and thus are rejected on the same grounds as claims 2-7.
Per claim 18,
The control method of claim 11, further comprising:
verifying integrity of the encrypted OTA log based on an electronic signature combined with the encrypted OTA log based on receiving the encrypted OTA log from an electronic device (Barr, page 3, digital signature is used as part of the validation and verification process);
verifying an access authority of a user who has entered a request for decryption of the encrypted OTA log based on receiving the request for decryption; and (Barr, page 2, decrypt permission is applied to the principal – IAM users, roles, groups, etc)
storing the encrypted OTA log based on the integrity of the encrypted OTA log having been verified. (Barr, page 2, validation and verification is done on encrypted log files before they are stored in the S3 bucket).
Per claim 19,
The control method of claim 18, wherein, when the access authority of the user having been verified, an OTA log is obtained by performing decryption of the encrypted OTA log based on the access authority of the user. (Barr, page 2, the decrypt permission is set to the principal and only those who have access will be able to obtain the OTA log)
As for claims 20, the claim recites similar limitations found in claim 10 and thus is rejected on the same grounds as claims 10.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KAYO LISA RUSIN whose telephone number is (703)756-1679. The examiner can normally be reached Monday-Friday 8:30 - 5:00 EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ashish Thomas can be reached at 571-272-0631. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/K.L.R./Examiner, Art Unit 2114
/ASHISH THOMAS/Supervisory Patent Examiner, Art Unit 2114