Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
The communication received on 6/03/26 has been entered.
Response to Arguments/Amendments
Applicant's arguments have been carefully considered but they were not found persuasive.
Applicant argues that, especially in light of amended claims 1, 26, 27 (the limitation previously presented in claim 12), the current claims overcame the 101 rejections, given the fact that the claims go beyond mere anomaly detection/data comparison, requiring now autonomously taking action to counter a detect cyber threat in a vehicle without any human intervention.
It appears that applicant overlooks the fact that the claims are drafted as the “intended use” claims. The claim merely requires determining an autonomous response. An independently derived decision based on the compared anomaly data clearly reads on the broadest reasonable interpretation of the claim. The claims fail short of reciting any particular actions that result in nullifying cyber-attacks against the attacked objects (e.g., vehicles).
Applicant argues that the prior art does not disclose data from a first vehicle and a second vehicle as pertaining to artificial learning/machine learning and challenges Official Notice regarding this limitation.
Applicant argues the Official Notice regarding utilizing the artificial learning/machine learning in particular, using data pertaining to more than one objects. However, applicant fails to adequately support the allegation. While choosing selectively MPEP citations (MPEP 2144.03 (B)) applicant overlooks applicant’s responsibility in regard to the Official Notice that follows (see MPEP 2144.03 (C)) applicant’s cited MPEP fragments.
(Applicant is reminded that to adequately traverse such a finding, an applicant must specifically point out the supposed errors in the examiner’s action, which would include stating why the noticed fact is not considered to be common knowledge or well-known in the art. See 37 CFR 1.111(b). See also Chevenard, 139 F.2d at 713, 60 USPQ at 241 (“[I]n the absence of any demand by appellant for the examiner to produce authority for his statement, we will not consider this contention.”)
Instead, while traversing the Official Notice, applicant argues that it does not address the specific combination of training a single machine-learning model on a normal pattern of life associated with both vehicles [and the remainer of the claim].
It appears that applicant attempted to challenge the Official Notice as pertaining to the entire claim rather than a missing concept, not addressed by the prior art. As noted in the previous Office Action, the prior art data received from the systems, and expressly discusses the AI models pertaining to “the normal pattern of life of the systems” aiming to identify suspicious activities (e.g., para 37-41). Moreover, in various paragraphs, e.g., para 6, 18, 19, 42, etc., Fellows expressly teaches the AI models being trained on systems’ normal pattern of lives. Although the prior art does not expressly discuss a model trained on data from more than one objects (vehicle), in light of the prior art teaching training models on data, applying AI to data received from various objects (such as cars, ships, etc.) and the Official Notice citing that having a model trained using data from more than one object, especially similar object being old and well known, the examiner asserted that applicant limitations would have been obvious.
Applicant argues that although Fellows teaches autonomous actions to remediate a cyber threat, the prior art does not expressly recite that these actions are in the context of vehicles.
First, again, “to remediate a cyber threat” is drafted as intended use limitations. Furthermore, while, as clearly discussed in the Office Action, Fellows discusses cyber threats, it also expressly talks about the invention pertaining to various types of vehicles (e.g., cars, ships, etc.)
As per claims 12-13, applicant argues that Berntrorp art is insufficient to address applicant’s invention (as currently amended) because it teaches a collision avoidance assessing physical trajectory threats not cyber threat.
While Fellows is directed to address threats, Fellows also expressly spells out that the invention pertains to cyber threats against autonomous vehicle system (para 90, for example), and while Fellows articulate that detecting the cyber threats are detected based on the pattern of life, clearly collisions are not the expected “pattern of life” of correctly operating vehicle (the vehicle not under the threat).
The amended claim 13, is more detailed discussed in this Office Action, below.
As per arguments directed towards claims 10-11 suggesting that Smith does not cure the previously argued limitations related to the vehicles, the examiner refers applicant to the responses above.
In arguing claims 16-22, applicant focuses on “factory network” cited in claim 20. Specifically, applicant argues that Fellows does not disclose the monitoring a factory network. Although applicant that “any particular name, e.g., ‘a factory network’ would not affect the functionality of the invention”, but rather than providing any concrete support regarding the patentability of the claims applied within a particular named objects/networks environment, applicant merely suggests that the prior art does not teach these network environments.
First, the claim does not require “monitoring” factory network. Furthermore. Furthermore, the only difference between the prior art and applicant’s invention is lack of particular labels. However, not only Fellow’s network utilizes technology but also because vehicles are objects that are manufactured in a factory and utilize technology, the prior art could satisfy the claimed “factory network”. Moreover, not only the labels would not affect the patentability of the claimed invention (as it would not affect functionality of the invention: the invention would work the same whether it would be named “network” or “factory network”) but clearly extending Fellow’s network to any particular network would have been at least an obvious variant at the time the application offering the predictable benefit of customization.
Claim(s) 1-9, 12-13, 15-23, 25-27 is/are rejected under 35 U.S.C. 102(a) as being anticipated by, or in alternative, under 35 U.S.C. 103 unpatentable over Fellows (Simon David Lincoln Fellows: USPUB 20200358810)
As per claims 1 and 26-27, Fellows teaches a method for detecting a cyber threat by a cyber threat defense system (see Abstract, Fig. 1 and 2 with the associated text, e.g., para 151-116), the method comprising: receiving data from a first vehicles (para 55); receiving data from a second vehicle; referencing one or more machine-learning models using machine-learning and artificial intelligence (AI) algorithms, the one or more machine-learning models including a first machine-learning model trained on a normal pattern of life associated with the first vehicles and the second vehicle; and comparing data received from the first vehicles and the second vehicle to the normal pattern of life associated with the first vehicles and the second vehicle to detect anomalies representing a cyber threat within the first vehicles or the second vehicle (para 41).
Note that in light of Fellows’ disclosure clearly articulating that the invention is related to more than one vehicle/car the examiner asserted that Fellows teaching expressly relates to the first and the second vehicles. However, it is noted that even if, Fellow did not contemplate such solution, Official Notice is taken that in the world of computing, the artificial learning/machine learning in particular, using data pertaining to more than one object, especially similar objects (note that Fellows expressly suggest that the invention may extend to more than one type of vehicle (e.g., cars, ships, etc.)) would have been old and well known at the time the application was filed to given the predictable benefit of obtaining more accurate results specific to a particular type of object.
The additional limitations of the independent claims as well as the limitations of claims 2-4, 7-8, 23, 25 are addressed by Fellows in para 19, 22, 28, 36, 44, 47, 55, 69, 90 and 106, for example.
As per the newly presented limitations of claim 13, given no specific limited definition/language regarding the term “correspond”, the fact that vehicles such as cars are moving, stopping, etc. any response in context of the vehicle operations would “correspond” to the listed various actions of the vehicle operations (e.g., (e.g., a driver must come to a controlled stop after the driving the vehicle, a driver disabling wipers when it stops raining, removing a key from the ignition, etc.)
As per claim 9, the software module and/or hardware device within vehicles meet the limitation of electronic control units and, as per claim 5, a skilled in the art would readily appreciate that vehicles, such as cars or ships are operated independently of one another. Similarly, in light of Fellows teaching the enterprise network dealing with vehicles such as cars, where a skilled in the art would appreciate that at least at some point they must be designed (including design of their components) and updated, the limitation of claim 22 is inherent.
As per claim 15, given no specific differentiation between the first and second model (or third model or fourth model), one could argue that the first module of claim 1 could also read on claim 15. However, it is also noted that given specific recitation of utilizing set (or subset) of instructions (module(s)) to classify information (e.g., para 113-14). (Note that not only abnormal in computing environment could, in the broadest reasonable interpretation, read on cyber threats, but also, including specific malicious data in classification would have been at least implicit given Fellows attempting to detect a cyber threat as clearly indicated in the Abstract.)
Additionally, as per claim 16-21, as clearly noted by Fellows, the set of instructions enabling the receipt of data from the Fellows network and using the ML and AI described above, meet the limitation of various other labels used in the claim language, e.g. “an enterprise module”, “operational technology module”, etc. Note that Fellows’ invention is to evaluate using normal patterns of life different vehicles (e.g., cars, ships, airplanes, etc., these devices not only having different design and parameters but they also could utilize different evaluation variables, e.g. specific protocols, e.g., para 69-71). Thus, clearly Fellows would need to have more than one (one or more) sources and models in order to accommodate this various type of devices. By the virtue of being on the same network and utilized by the same server, the specific models would meet the limitation of being associated with each other. Any particular component of these devices and/or a particular component of these devices control a particular aspect of activities and, as a result, they can reasonably meet the limitations of “controllers”. Lastly, clearly any particular name, e.g., “a factory network” would not affect the functionality of the invention and at most, would have been an obvious variant offering the predictable benefit of customization (especially since the network is a network of manufactured components of elements such as vehicle components. By the virtue of having the manufactured components on such network, the network is associated with the factory manufactured the components).
As per claim 6, given the fact that the term “similar” is not clearly defined not only one could argue that the broadest reasonable interpretation of such limitation is inherent in light of Fellows disclosure but, in fact, even more limited interpretation (see para 90) would read on the claim language.
Claim(s) 10-11 is/are rejected under 35 U.S.C. 103 unpatentable over Fellows (Simon David Lincoln Fellows: USPUB 20200358810) in view of Smith (USPUB 20190349426).
Fellows teaches the probes installed on the vehicles monitoring traffic (communicating data to vehicle module over network) as discussed above.
As per claim 10, Fellows does not teach the probes monitoring all network traffic inbound to and outbound from the vehicles. However, in the related art Smith suggests such solution (para 2148, 2167, etc.). It would have been obvious to one of ordinary skill in the art at the time the application was filed to include monitoring traffic as taught by Smith given the predictable benefit of data management.
As per claim 11, a skilled in the art would readily appreciate that any operation on data includes obtaining data types (outgoing data from the vehicle would meet the limitation of the vehicle data and, as a result, the type of this data would meet the limitation of the vehicle data type).
While Smith teaches a few entities operating on client, a watchdog agent, monitoring agent, data manager, etc., each responsible for monitoring device operation, including monitoring inbound/outbound traffic to/from device and a particular or a set of these entity could be equated to the claimed probes, wherein the set could be interpreted as an entity also transmitting and receiving data over network. As such, a skilled in the art would readily appreciate that in order to operate on the received network data, a probe entity would have to be able to perform protocol parsing from the data of at least one of i) a data link layer, ii) a physical layer.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Peter Poltorak whose telephone number is (571) 272-3840. The examiner can normally be reached Monday through Thursday from 9:00 a.m. to 5:00 p.m.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached on (571) 272-6798. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/PIOTR POLTORAK/Primary Examiner, Art Unit 2433