DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims Status
Claims 1 and 9 filed 07/27/2026 have been amended.Claims 1-6, 8-14 and 16 are pending and have been rejected.Claims 7 and 15 have been canceled.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 07/27/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Arguments
Applicant's arguments filed 07/27/2026 have been fully considered but they are not persuasive. Applicant asserts that Roese nor Kim teach or suggest each and every element of amended independent claims 1 and 9. Furthermore, Roese does not teach or suggest at least wherein the first network zone and the second network zone each comprise separate virtual local area networks of the vehicle. However, the Examiner respectfully disagrees as the reference of Roese et al. (U.S. Publication 2009/0187968) was used to show dynamic policy allocation for network service provisioning in paragraphs 0012, 0023, 0026 & 0044. Kim et al. (U.S. Publication 2016/0255154) reference was used to show a security device for a network access to functional elements included in a vehicle and a method of designing the security device. Furthermore, Kim was used to disclose the limitation of “at least wherein the first network zone and the second network zone each comprise separate virtual local area networks of the vehicle”. As it is Applicant's right to claim as broadly as possible their invention, it is also the Examiner's right to interpret the claim language as broadly as possible. It is the Examiner's position that the detailed functionality that allows for Applicant's invention to overcome the prior art used in the rejection, fails to differentiate in detail how these features are unique. It is clear that Applicant must be able to submit claim language to distinguish over the prior arts used in the above rejection sections that discloses distinctive features of Applicant's claimed invention. It is suggested that Applicant compare the original specification and claim language with the cited prior art used in the rejection section above or the remark section below to draw an amended claim set to further the prosecution.
Failure for Applicant to narrow the definition/scope of the claims and supply arguments commensurate in scope with the claims implies the Applicant's intent to broaden claimed invention.
Based on the rationale explained above, the Examiner disagrees with the prior arts being silent to the claimed embodiment.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-16 are rejected under 35 U.S.C. 103 as being unpatentable over Roese et al. (U.S. Publication 2009/0187968), hereinafter ‘Roese’ in view of Kim et al. (U.S. Publication 2016/0255154), hereinafter ‘Kim’.
As to claims 1 & 9, Roese discloses a method and an apparatus, comprising: interpreting a policy comprising a network usage permission description (Roese, see [0012] & [0023], dynamic policy system can enable a network administrator to establish comprehensive control of network services usage); configuring a first network interface circuit in response to the network usage permission description (Roese, see [0026], the system is able to enforce established and generated policies, on an initial and continual basis, based on usage permission rules established by a network administrator. It can restrict usage of the network system and its services based on the attached function's characteristics, the particular connection point through which network infrastructure connection is established, and network system events related or unrelated to the attached function. See [0044], the policy system is configured to maintain and update the information associated with the attached functions and the network infrastructure of the network system in a centralized database, including the saved policies history); and Roese is silent to regulating communications, using the first network interface circuit, between end points of a first network zone of a vehicle and end points of a second network zone of the vehicle, wherein the first network zone and the second network zone each comprise separate virtual local area networks of the vehicle. However, Kim discloses regulating communications, using the first network interface circuit, between end points of a first network zone of a vehicle and end points of a second network zone of the vehicle (Kim, [0034], a vehicular security network device includes a first conduit, which is a sole network path connecting a first security zone to an external network. The first security zone can be construed as being a logical and/or physical zone including a plurality of functional elements of a vehicle. See [0040], a gate keeper is disposed on the conduit to control an access to the security zone by an external source. See [0043], the gate keeper configured to maintain security of the subzone by the security element of a higher level than the gate keeper), wherein the first network zone and the second network zone each comprise separate virtual local area networks of the vehicle (Kim, see [0100], the user uses application of the smartphone to communicate signal to the vehicle through a 3G/4G network or through the Internet, wherein the signal can access some of the functional elements through an internal network of the vehicle). Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Roese in view of Kim in order to further modify the method provides dynamic network policy management from the teachings of Roese with the method of preventing a security attack/threat on a vehicle network from the teachings of Kim.
One of ordinary skill in the art would have been motivated because it would allow to analyze a risk to security of a vehicle and provide a security countermeasure against the analyzed risk. (Kim – 0006). As to claims 2 & 10, Roese in view of Kim discloses everything disclosed in claims 1 & 10. Roese further discloses wherein the network usage permission description further comprises an external data access description (Roese, see [0045], network services usage is permitted an attached function via a connection point deemed not to be inherently secure (e.g., an edge Switch port associated with an external internet connection), the policing system can prompt the attached function to initiate an improved connection, such as a VPN, or can notify the attached function that supplemental restrictions apply while in the insecure area); and the method further comprises: configuring a gatekeeper interface circuit in response to the external data access description (Roese, see [0026], enforce established and generated policies based on usage permission rules established by a network administrator. It can restrict usage of the network system and its services based on the attached function's characteristics, the particular connection point through which network infrastructure connection is established, and network system events related or unrelated to the attached function. All policy sets can be directed to all network entry devices. The policy sets can be apportioned among the network entry devices and attached functions forced to particular connection points based on established sets of policies. It is contemplated that multiple policies will be applied to the connection points ); and regulating communications, using the gatekeeper interface circuit, with an external device in response to the external data access description (Roese, see [0045], network services usage is permitted an attached function via a connection point deemed not to be inherently secure (e.g., an edge switch port associated with an external internet connection), the policing system can prompt the attached function to initiate an improved connection, such as a VPN, or can notify the attached function that supplemental restrictions apply while in the insecure area).
As to claim 3 & 11, Roese in view of Kim discloses everything disclosed in claims 2 & 10. Roese further discloses wherein the external data access description comprises permissions associated with the external device (Roese, see [0045], network services usage is permitted an attached function via a connection point deemed not to be inherently secure (e.g., an edge switch port associated with an external internet connection), the policing system can prompt the attached function to initiate an improved connection, such as a VPN, or can notify the attached function that supplemental restrictions apply while in the insecure area).
As to claims 4 & 12, Roese in view of Kim disclosed everything disclosed in claims 2 & 10. Kim discloses wherein: the external data access description comprises permissions associated with a flow of the vehicle (Kim, [0040-0041], a gate keeper is disposed on the conduit to control an access to the security zone by an external source. A security zone includes functional elements (vehicles) connected to the outside of the security zone through a conduit. A gate keeper is disposed on the conduit to control an access to the security zone by an external source.); and Roese further discloses regulating communications comprises regulating communications based on a flow association of a communicating one of the end points of the first network zone or second network zone (Roese, see [0023], the dynamic policy function includes the sub-functions of monitoring the network for triggers, decision making of whether to modify an assigned set of policies and enforcement of the assigned set of policies. The dynamic policy function module of any particular device of the infrastructure can include any one or more of the three identified sub-functions. See [0045], network services usage is permitted an attached function via a connection point deemed not to be inherently secure (e.g., an edge switch port associated with an external internet connection), the policing system can prompt the attached function to initiate an improved connection, such as a VPN, or can notify the attached function that supplemental restrictions apply while in the insecure area).
As to claims 5 & 13, Roese in view of Kim disclosed everything disclosed in claims 2 & 10. Roese further discloses wherein: the external data access description comprises permissions associated with an application (Roese, see [0042], the set of policies evaluation and possible policy change or modification can occur per session, per port, per flow, per user, per attached function, per application sought, etc.), wherein regulating communications comprises: regulating communications based on an application association of a communicating device, the communicating device comprising one of: the external device, an end point of the first network zone, or an end point of the second network zone (Roese, see [0023], the dynamic policy function includes the sub-functions of monitoring the network for triggers, decision making of whether to modify an assigned set of policies and enforcement of the assigned set of policies. The dynamic policy function module of any particular device of the infrastructure can include any one or more of the three identified sub-functions. See [0045], network services usage is permitted an attached function via a connection point deemed not to be inherently secure (e.g., an edge switch port associated with an external internet connection), the policing system can prompt the attached function to initiate an improved connection, such as a VPN, or can notify the attached function that supplemental restrictions apply while in the insecure area).
As to claims 6 & 14, Roese in view of Kim disclosed everything disclosed in claims 2 & 10. Kim further discloses wherein: the external data access description comprises permissions associated with a network zone of the vehicle, and regulating communications comprises: regulating communications based on at least one of a source zone or a destination zone of a regulated communication, and the external data access description (Kim, [0034], a vehicular security network device includes a first conduit, which is a sole network path connecting a first security zone to an external network. The first security zone can be construed as being a logical and/or physical zone including a plurality of functional elements of a vehicle. See [0040], a gate keeper is disposed on the conduit to control an access to the security zone by an external source. See [0043], the gate keeper configured to maintain security of the subzone by the security element of a higher level than the gate keeper).
As to claims 8 & 16, Roese in view of Kim disclosed everything disclosed in claims 1 & 9. Roese discloses wherein the network usage permission description further comprises: a network utilization description corresponding to at least one of the first network zone or the second network zone (Roese, see [0045], an attached function is permitted network services usage via a connection point deemed not to be inherently secure (e.g., an edge Switch port associated with an external internet connection), the policing system can prompt the attached function to initiate an improved connection, such as a VPN, or can notify the attached function that supplemental restrictions apply while in the insecure area.); and wherein regulating communications comprises regulating communications based on the network utilization description, and an associated communicating device associated with a regulated communication (Roese, see [0023], the dynamic policy function includes the sub-functions of monitoring the network for triggers, decision making of whether to modify an assigned set of policies and enforcement of the assigned set of policies. The dynamic policy function module of any particular device of the infrastructure can include any one or more of the three identified sub-functions. The policy sets can be apportioned among the network entry devices and attached functions forced to particular connection points based on established sets of policies. See [0045], network services usage is permitted an attached function via a connection point deemed not to be inherently secure (e.g., an edge switch port associated with an external internet connection), the policing system can prompt the attached function to initiate an improved connection, such as a VPN, or can notify the attached function that supplemental restrictions apply while in the insecure area)). Kim further discloses and a communicating device description comprising at least one of an end point of one of the first network zone or the second network zone, a flow, a vehicle function, or an application (Kim, see [0040], a security zone include functional elements having a same required security level, and is connected to the outside of the security zone through a conduit. A gate keeper is disposed on the conduit to control an access to the security zone by an external source. See [0100], smartphone application of user (vehicle owner) can provide communication in order to access a functional element for controlling the vehicle);
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TANIA M PENA-SANTANA whose telephone number is (571)270-0627. The examiner can normally be reached Monday - Friday 8am to 4pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas R Taylor can be reached at 5712723889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/TANIA M PENA-SANTANA/Examiner, Art Unit 2443
/NICHOLAS R TAYLOR/Supervisory Patent Examiner, Art Unit 2443