Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Priority
Acknowledgment is made of applicant's claim for foreign priority based on a German application DE 10202410827.5 filed on January 23, 2024.
Claim Objections
Claim 20 is objected to because of the following informalities: Claim is amended wherein all text depicted as a strikethrough; however the status of the claim is not stated as “(Canceled)” and thus not in compliance with 37 C.F.R. 1.121. Appropriate correction is required.
CLAIM INTERPRETATION
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are safe state trigger and signal filter.
Claims 1, 16, and 18 limitations invoke 35 U.S.C. 112(f) because they use generic placeholders, such as “safe state trigger” coupled with functional language “configured to: monitor, identify, and send, that is not modified by sufficient structure, material, or acts for performing the claimed function. The written description of the specification implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function. A review of the specification shows that the following shows the corresponding structure described in the specification for the 35 U.S.C. 112(f) limitation "safe state trigger.” Paragraph 0021 and 0049 state that: the safe state trigger 124 and the application controller 122 may be separate components of the electronic control unit 114. One having ordinary skill in the art would understand that the safe state trigger is a component similar to that of an electronic control unit.
Claims 8 – 10 limitations invoke 35 U.S.C. 112(f) because they use generic placeholders, such as “signal filter” coupled with functional language “configured to compare the input signals with a predetermined fixed signal for identifying the failure signal” that is not modified by sufficient structure, material, or acts for performing the claimed function. The written description of the specification does not implicitly or inherently discloses the corresponding structure, material, or acts and does not clearly link them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function. A review of the specification does not show or describe the corresponding structure described in the specification for the 35 U.S.C. 112(f) limitation "signal filter.” One having ordinary skill in the art would guess that the signal filter is either firmware, software, a section of a processor, a separate circuit, a microprocessor, program code, or other structure. The limitation is rejected under 35 U.S.C. 112(a) and 35 U.S.C. 112(b). MPEP §2181(II)(A) states: “If there is no disclosure of structure, material or acts for performing the recited function, the claim fails to satisfy the requirements of 35 U.S.C. 112(b).” MPEP §2181(II)(B) states: “When a claim containing a computer-implemented 35 U.S.C. 112(f) claim limitation is found to be indefinite under 35 U.S.C. 112(b) for failure to disclose sufficient corresponding structure (e.g., the computer and the algorithm) in the specification that performs the entire claimed function, it will also lack written description under 35 U.S.C. 112(a). See MPEP §2163.03.” Therefore the claim is rejected under both under 35 U.S.C. 112(a) and 35 U.S.C. 112(b) below.
Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may:
amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or
(2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 112(a)
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
Claims 8 – 10 are rejected under 35 U.S.C. §112(a), as failing to comply with the written description requirement. The claims contain subject matter which fails to disclose structure to perform "a signal filter” as claimed. Given the guidance under in the Williamson: “The standard is whether the words of the claim are understood by persons of ordinary skill in the art to have a sufficiently definite meaning as the name for structure.” Williamson v. Citrix Online, LLC, 792 F.3d 1339, 1349, 115 USPQ2d 1105, 1111 (Fed. Cir. 2015). In the examiner' s view the written description fails to impart any structural significance to the terms of "a signal filter.”
For more information, see MPEP § 2181(II)(A) The Corresponding Structure Must Be Disclosed In the Specification Itself in a Way That One Skilled In the Art Will Understand What Structure Will Perform the Recited Function.
Claim Rejections - 35 USC § 112(b)
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 8 – 10 are rejected under 35 U.S.C. 112(b), as being indefinite for failing to particularly point out and distinctly claim the subject matter which the applicant regards as the invention. The "signal filter” is indefinite under 35 U.S.C. 112 (b) because the specification fails to adequately disclose structure to perform the claimed functions. For each of the section the specification must disclose some kind of structure for performing the functions of each element. The specification provides no detail about the sections themselves. See also “Claim Interpretation” section above.
For more information, see MPEP § 2181(II). DESCRIPTION NECESSARY TO SUPPORT A CLAIM LIMITATION WHICH INVOKES 35 U.S.C. 112(f) or Pre-AIA 35 U.S.C. 112, SIXTH PARAGRAPH.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1, 2, 13, 14, 16, and 18 are rejected under 35 U.S.C. 102(a)(1) or 102(a)(2) as being anticipated by Okubo (US PG Pub. No. 20180202544), herein “Okubo.”
Regarding claim 1,
Okubo teaches an electronic control unit comprising at least: (Par. 0007: “A vehicle electronic control device including an electric actuator…”)
an electronic device; (electric actuator)
an application controller configured to controlling the electronic device; (Par. 0035: “The ATCU is composed of two CPUs including a main CPU that controls the electric actuator and a sub CPU that monitors an operating function of the main CPU.” main CPU or Sub CPU)
and a safe state trigger configured to: (failure part specifying means in conjunction with the monitoring circuit of CU (control unit))
o monitoring input signals sent from a supervising controller (sub CPU; Par. 0035: “The ATCU is composed of two CPUs including a main CPU that controls the electric actuator and a sub CPU that monitors an operating function of the main CPU.”) to the electronic control unit; (Par. 0038: “A monitoring electronic control device (hereinafter referred to as a monitoring CU) is configured separately from the ATCU, and is connected to the ATCU via a communication line. The monitoring CU monitors whether or not the main CPU and the sub CPU of the ATCU normally operate.”)
o identifying a failure signal from the input signals; (Par. 0040: “Thereafter, monitoring results are integrated in the failure part specifying means, and the failure part is specified. First, the monitoring results of the main CPU and sub CPU are collated. At this time, when both the CPUs do not detect any abnormality, it is determined that the ATCU is normal, and the system shifts to normal control and outputs the control signal. On the other hand, when the monitoring results of the main CPU and the sub CPU are different from each other, that is, when any one of the CPUs has transmitted the monitoring result that it is determined to be abnormal to the failure part specifying means, the CPU that made the same determination as a monitoring result in the monitoring CU is normalized with reference to the monitoring result of the monitoring CU. On the other hand, when the monitoring result in the monitoring CU is abnormality even though the monitoring results of both the main CPU and the sub CPU are normality among the monitoring results transmitted to the failure part specifying means, there is a possibility that the monitoring CU has failed, and thus, the main CPU and the sub CPU exclude the monitoring CU from a mutual monitoring target.” Par. 0041, 0042.)
o sending a safe state signal to the electronic device when identifying the failure signal. (Par. 0005: “…shifting to a fail-safe state with a small system configuration without greatly changing a current configuration of the electronic control device.” Par. 0033: “Thus, a description will be given in the following embodiment of the present invention regarding a monitoring system that is capable of reliably detecting microcomputer failure in an electronic control device of a vehicle automatic transmission (particularly an automatic continuously variable transmission) including an electric actuator and reliably shifting to a fail-safe state with a minimum system configuration without greatly changing a configuration of a current electronic control device.” Par. 0055: “With the above configuration, the monitoring CU can monitor the sub CPU even if the main CPU fails as well as the failure part can be suitably specified, and thus, there is no need to particularly perform the shift to fail-safe processing, and it is possible to implement normal control with the sub CPU. As a result, the reliability of the system is dramatically improved, it is possible to apply the present invention to a system with a high safety requirement with the simple configuration, and to provide the present invention with a minimum increase in cost.” Par. 0031; see also Par. 0041 that teaches switching from a main CPU to a sub CPU (failure) which causes the failure part specifying means to switch control to a sub CPU. (Shifting to a fail-safe state according to Par. 0005). See also Par. 0045 and 0066. See also Scholan cited below paragraphs 0008 and 0161. See also Scholan figure 9 that shows analysis of communications, whether there is a fault state, and causing one or more devices to transition to a safe state.)
Regarding claim 2,
The previously cited reference(s) teach the limitations of claim 1 which claim 2 depends. Okubo also teaches that the safe state trigger is configured to for bypassing (switches from main CPU) the application controller when identifying the failure signal and sending the safe state signal to the electronic device. (Par. 0013: “The control signal switching means of the vehicle control device including the electric actuator according to claim 7 or 17 switches a control signal to be used to either a control signal output from the main control unit or a control signal output from the sub control unit based on the determination result from the failure part specifying means.” Par. 0005: “Thus, an object of the present invention is to provide a monitoring system and a vehicle control device which are capable of detecting microcomputer failure in an electronic control device of a vehicle automatic transmission, which includes an electric actuator, and shifting to a fail-safe state with a small system configuration without greatly changing a current configuration of the electronic control device.” Par. 0033: “…including an electric actuator and reliably shifting to a fail-safe state with a minimum system configuration…”)
Regarding claim 13,
The previously cited reference(s) teach the limitations of claim 1 which claim 13 depends. Okubo also teaches a power adapter, wherein the safe state trigger (114) is a part of the power adapter. (Par. 0031: “In a continuously variable transmission of an electric actuator system from which the hydraulic pressure generator such as the oil pump is excluded, however, it is necessary to cut off power supply to an actuator and tum a motor into an inoperative state similarly in the hydraulic actuator system in order to prevent unintended sudden acceleration or deceleration…” Par. 0035: “driving the electric actuator, that is, an electric motor, and a control signal after subjected to environmental disturbance correction of a motor power supply voltage, temperature, and the like is output to the driver circuit in the main CPU such that the electric actuator is controlled.” Par. 0045 and 0048.)
Regarding claim 14,
The previously cited reference(s) teach the limitations of claim 1 which claim 14 depends. Okubo also teaches an electronic device (120) comprises at least one of a load switch (132) and a driver (134). (Par. 0035: “Based on these pieces of information, the main CPU determines a transmission gear ratio, that is, a control amount of the electric actuator by calculating a target drive torque. It is necessary to convert the calculated control amount into a signal for driving the electric actuator, that is, an electric motor, and a control signal after subjected to environmental disturbance correction of a motor power supply voltage, temperature, and the like is output to the driver circuit in the main CPU such that the electric actuator is controlled. Par. 0044: “…monitoring CPU cuts off the power supply of the electric actuator from the viewpoint of securing the safety when the control CPU is abnormal in the configuration of the existing electronic control device in which the monitoring CPU monitors the control CPU within the same electronic control device. According to the configuration of the present embodiment, however, it is possible to execute the normal control by performing switching to the normal control CPU using the control switching means in addition to the accurate specifying of the failure part (CPU) through the monitoring configuration…” Par. 0048.)
Regarding claim 16, it is directed to a method of steps to implement the control unit set forth in claim 1. Okubo teaches the claimed system or apparatuses in claim 1. Therefore, Okubo teaches the method of steps in claim 16.
Regarding claim 18, it is directed to a system to implement the control unit set forth in claim 1. Okubo teaches the control unit in claim 1. Therefore, Okubo teaches the system in claim 18.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 5 – 7 are rejected under 35 U.S.C. 103 as being unpatentable over Okubo in view of Hiroki et al. (JP 2020103691 A), herein “Hiroki.”
Regarding claim 5,
The previously cited reference(s) teach the limitations of claim 1 which claim 5 depends. Okubo does not teach all the elements of claims 5 - 7. Okubo may teach the elements of claim 5, Hiroki also teaches that wherein the safe state trigger is configured to trigger a safe state in case of a failure event by sending the safe state signal to the electronic device. (Page 16, last paragraph: “With such a configuration, any of the main control board 200, the main control unit 354, the sub-control board 202, and the sub-control unit 358 can receive the power of DC 5V, and the main control unit 354, the sub-control board 202, Even if an abnormality occurs in the DC 5V power supply system in any of the sub control units 358, it does not affect the operation of the main control board 200. That is, even if an abnormality occurs in the supply system of the DC 5V power supplied directly from the power supply board 350 or the supply system of the DC 5V power supplied from the power generation unit 202e, the power generation unit having a different supply system from that Normal operation can be maintained without affecting the DC5V supply system supplied from 200e.” Page 22, last paragraph: “Further, here, when the sub CPU 202a detects an abnormality in the sub control unit 358, the sub control unit 358 is set to a low level (L), and the sub control board 202 and the sub control unit 358 are separated. The sub CPU 202a can detect an abnormality in the sub control unit 358 as follows. That is, for example, when an abnormality occurs in the driver of the actuator that operates the performance accessory device 138 such that the encoder does not advance the rotation command of the actuator, the state signal is used to loop back to that effect. Is provided. The sub CPU 202a determines the abnormality of the driver from the state signal, and shuts off the output of the power of DC5V_U to which the driver is connected through the switching circuit 202h.”)
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have combined the system that includes a monitoring control unit, a failure part specifying means, a main CPU, and a sub CPU wherein a supervisory controller (monitoring CU) monitors and detects a fault condition of a main CPU or sup CPU and sends a safe state signal to the other CPU and to the electric actuator as in Okubo with control system that uses a different CPU to determine an abnormality of a sub control unit of an electronic actuator and sends a signal to shut off power of the driver of the actuator as in Hiroki in order to maintain safety of an electronic device according to national safety standards by identifying a failed portion and shutting off that portion. (Page 30, Par. 2 and Page 22, last paragraph)
Regarding claim 6,
The previously cited reference(s) teach the limitations of claim 5 which claim 6 depends. Hiroki also teach that the safe state trigger (124) is further configured for to triggering a transition mode of the electronic control unit (114) for achieving the safe state. (Hiroki teaches achieving a safe state by shutting off power to the driver of the actuator: Page 22, last paragraph: “Further, here, when the sub CPU 202a detects an abnormality in the sub control unit358, the sub control unit 358 is set to a low level (L), and the sub control board 202and the sub control unit 358 are separated. The sub CPU 202a can detect an abnormality in the sub control unit 358 as follows. That is, for example, when an abnormality occurs in the driver of the that operates the performance accessory device 138 such that the encoder does not advance the rotation command of the , the state signal is used to loop back to that effect. Is provided. The sub CPU 202a the of the driver from the , and shuts the output of the power of DC5V_U to which the driver is connected through the switching circuit 202h.”
Regarding claim 7,
The previously cited reference(s) teach the limitations of claim 5 which claim 6 depends. Hiroki also teach that the safe state comprises at least one of an OFF state and an ON state. (Page 20, Par. 4: “Specifically, the switching circuit 202h is provided in the sub control board 202. The switching circuit 202h receives the DC 5V generated by the power generation unit 202e and switches (ON/OFF) the DC 5V power output. Here, the power output from the switching circuit 202h may be DC5V_U in order to distinguish it from DC5V. Then, the sub CPU 202a (control unit) controls the switching circuit 202h to a closed state(ON) or an open state (OFF) according to the power supply status.” Par. 22, last paragraph.)
Claims 11 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Okubo in view of Yuuki et al. (JP 2009129267 A), herein “Yuuki.”
Regarding claim 11,
The previously cited reference(s) teach the limitations of claim 1 which claim 11 depends. Okubo does not teach an interface for at least a supervisory controller. Yuuki teaches that the electronic control unit comprises an interface configured to connecting the electronic control unit to at least the supervising controller wherein the safe state trigger is a part of the interface. (Abstract: “To perform periodic communication of an monitor including question information and answer information while performing periodic communication of some input/output signal at a relatively high frequency between a section and a section. <P>SOLUTION: The onboard electronic control unit having the control is configured to connect the circuit section 20A and monitoring control circuit 30A to each other through serial interface circuit 27a and37a, to perform high-speed full-duplex block communication using a communication…” Page 5, Par. 2: “…a monitoring control circuit unit having an abnormality determination unit that compares information with the correct information stored in the correct information storage memory to determine whether there is an abnormality in the main circuit control circuit unit…” Page 19, Par. 5: “The serial interface circuits 27a and 37a are connected between the main control circuit unit 20A and the supervisory control circuit unit 30A, and a plurality of bytes of downlink communication information DND and uplink communication information are transmitted by a communication permission signal ALT and a communication synchronization signal CLK.”)
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have combined the system that includes a monitoring control unit, a failure part specifying means, a main CPU, and a sub CPU wherein a supervisory controller (monitoring CU) monitors and detects a fault condition of a main CPU or sup CPU and sends a safe state signal to the other CPU and to the electric actuator as in Okubo with a vehicle control that has a monitoring control circuit where an interface is included that connects the electronic control unit(s) with the a monitoring or supervisory circuit as in Yuuki in order to improve safety of a vehicle. (Page 2, Par. 2)
Regarding claim 12,
The previously cited reference(s) teach the limitations of claim 11 which claim 12 depends. Yuuki also teaches that the interface comprises at least one transceiver for communication with the supervising controller, wherein the safe state trigger is a part of the transceiver. (Page 5, Par. 2: “A pair of serial interface circuits are connected to the microprocessor to communicate input / output…” Page 8, Par. 4: “The serial interface circuits 27a and 37a are connected between the main control circuit unit 20B and the supervisory control circuit unit 30B, and a plurality of bytes of downlink communication information DND and uplink communication information are transmitted by a communication permission signal PMT and a communication synchronization signal CLK. In addition to constituting a full-duplex block communication circuit that simultaneously transmits and receives UPD, the monitoring control circuit unit 30B includes question information updating means 604.”)
Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Okubo in view of Chinese document of Lee et al. (CN 104228539 B), herein “Lee.”
Regarding claim 17,
The previously cited reference(s) teach the limitations of claim 1 which claim 17 depends. Okubo does not teach all the elements of claim 17 wherein a device goes into safe state by using the device. However, Lee teaches going in the safe state by using the electronic device. (Abstract: “A device for controlling fault-safety of a hybrid vehicle and a method thereof. for the device of controlling fail safety of hybrid vehicle, possibly due to the failure of the high voltage component is cut under the condition that the main relay generating control electric oil pump can be driven by mixed power starter and generator or driving electric motor to provide fault safety driving, the device can comprise a method, which has determined in the running process of the hybrid vehicle hybrid power vehicle due to the failure of the high voltage component off the main relay to enter fault safe mode enter into the determined fault safe mode under the condition of detecting the HSG or driving electric motor driven by electricity, and by running under fault safe mode…” Page 6: “In another aspect of the invention, a method of controlling fail safety of hybrid vehicle, may include determining in the running process of the hybrid vehicle hybrid power vehicle due to failure of high voltage part off the main relay to enter a fault safe mode; when it is determined to enter the fault safe mode detecting generating voltage of the hybrid start/generator (HSG) or driving by the driving of the electric motor, and in fault safety drive of the generation control mode…”)
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have combined the system that includes a monitoring control unit, a failure part specifying means, a main CPU, and a sub CPU wherein a supervisory controller (monitoring CU) monitors and detects a fault condition of a main CPU or sup CPU and sends a safe state signal to the other CPU and to the electric actuator as in Okubo with a fail safety hybrid vehicle that in the running process the vehicle enters a fault safe mode as in Lee in order to control the fault safety of a hybrid vehicle and possibly cut off or stop components of the vehicle for safety purposes. (Page 4, last paragraph - Page 5, first paragraph)
Allowable Subject Matter
Claim 3 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims pending resolving any intervening issues such as any 35 U.S.C. §112(b) rejections above. Reasons for allowance will be held in abeyance pending final recitation of the claims. The prior art does not disclose the elements of claim 1 and wherein the application controller complies with a safety integrity level (SIL) lower than the SIL of a safety requirement of the electronic control unit, specifically lower than SIL4, and more specifically with an automotive safety integrity level (ASIL) lower than ASIL D.
Claim 4 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims pending resolving any intervening issues such as any 35 U.S.C. §112(b) rejections above. Reasons for allowance will be held in abeyance pending final recitation of the claims. The prior art does not disclose the elements of claim 1 and wherein the safe state trigger complies with a safety integrity level (SIL} derived from a safety requirement of the electronic control unite(114), specifically with SIL4, and more specifically with an automotive safety integrity level (ASIL} D.
Claims 8 – 10 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims pending resolving any intervening issues such as 35 U.S.C. §112(a) and 35 U.S.C. §112(b) rejections above. Reasons for allowance will be held in abeyance pending final recitation of the claims. Given the time allotted, the prior art does not disclose the elements of claim 1 and wherein the safe state trigger comprises at least one signal filter configured to compare the input signals with a predetermined fixed signal for identifying the failure signal. Claims 9 and 10 depend on claim 8 and therefore are also objected to.
Claim 15 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims pending resolving any intervening above. Reasons for allowance will be held in abeyance pending final recitation of the claims. The prior art does not disclose the elements of claims 1 and 14 and wherein the electronic device comprises a smart switch formed by the load switch and the driver, wherein the electronic device further comprises a safety switch.
Claim 19 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim 18 and any intervening claims pending resolving any intervening above. Reasons for allowance will be held in abeyance pending final recitation of the claims. The prior art does not disclose the elements of claims 18 and wherein the supervising controller complies with a safety integrity level (SIL) derived from of a safety requirement of the electronic control unit specifically with SIL4, with automotive safety integrity level (ASIL) D.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
Scholan et al. (US PG Pub. No. 20230390009) also teaches most of the elements in claim 1 wherein a control system for controlling an electronic robot system (Par. 0008). Scholan also teaches an application controller (arm controller 309) that determines if a main controller has a fault and places the robot in a safe state. Scholan also teaches a safety monitor: (Par. 0161: “If it is determined that the main controller is not sending a heartbeat signal to an input device within the predetermined constraints, the safety monitor 316 may be configured to determine that the surgical robot system 300 is in a fault state. In response to determining that there is such a fault state, the safety monitor 316 may cause the relevant input device (e.g. hand controller) to transition to a safe state. In some cases, the safety monitor 316 may be configured to cause the relevant input device to transition to a safe state by causing the safety device 314 to filter all communications between the relevant input device (e.g. hand controller) and the main controller.”)
Gonring (US PG Pub. No. 20220242538) may also be pertinent to the instant application and teaches… Gonring teaches an electronic control unit comprising at least: (control unit or controller)
an electronic device; (electric motor or battery systems/device)
an application controller configured to controlling the electronic device; (Par. 0010: “The power storage system further includes a controller coupled to each of the marine battery systems. The controller is configured to detect at least one of the marine battery systems has reached a minimum threshold state of charge, and to control an operational state of the at least one of the marine battery systems using the three-position contactor.”)
Gonring may teach a safe state trigger as a BMS.
o monitoring input signals sent from a supervising controller to the electronic control unit; (Par. 0034: “Each of the rechargeable battery systems 114A-114C is further shown to be communicably coupled to a supervisory controller 130 that is external to the battery systems 114A-114C using a controller area network (CAN). The supervisory controller 130 may include both a processor or processing component and a rule storage or memory component. In an exemplary implementation, the supervisory controller 130 is configured to monitor various systems and parameters of the marine vessel 100 and, upon detection of a fault condition (e.g., a failure of a high voltage isolation system, a break in a safety interlock loop), instruct the battery systems 114A-114C to operate in bypass or disconnected modes, depending on the characteristics of the power storage system 112 and the severity of the fault condition. Further details regarding this process are included below with reference to FIG. 7.”)
o identifying a failure signal from the input signals; (Par. 0034: “detection of a fault condition (e.g., a failure of a high voltage isolation system, a break in a safety interlock loop), instruct the battery systems 114A-114C to operate in bypass or disconnected modes, depending on the characteristics of the power storage system 112…”)
o sending a safe state signal to the electronic device when identifying the failure signal. (Par. 0044: “If the supervisory controller 130 detects an emergency stop condition at step 710, process 700 proceeds to step 712, and the supervisory controller 120 performs the emergency stop action. In an exemplary implementation, the emergency stop action includes commanding every three-position contactor 124A-126C of every battery system 114A-114C to the opened position such that the power storage system is operating in a safe mode, regardless of whether the power storage system is arranged in a series or a parallel configuration. See also Par. 0034, and 0035 – supervisory controller senses a fault and move the battery contactors in a bypass position. Par. 0036: “…the supervisory controller 130 may instruct the BMS 122B to operate the switch controller 126B and move the three-position contactor 124B to the bypass position because an enclosure temperature for the battery system 114B exceeds a maximum threshold.” Par. 0040: “…when a fault condition is detected, the supervisory controller 130 or the manual stop control 132 may command each of the three-position contactors 124A-124C to the opened position…” See also par. 0031.)
Takanori et al. (WO 2017018179 A1), herein “Takanori,” may also teach the elements of claim 2: (Page 9, claim 1: “When the unit determines that the main controller is, the unit maintains the power supply circuit in an OFF state via the signal holding circuit.” See also Page 3, Par. 2: “Further, the electronic control unit 1A includes a monitoring control unit 4 that constantly monitors whether the main control unit 2 is operating normally as fail-safe, and monitors a calculation result from the communication port 22 of the main control unit 2 by the communication port 43. When it is determined that there is an abnormality in the main control unit 2, the actuator output is turned off via the F / S circuit 11 by the output I / F stop signal 42 and the CAN transmission stop signal 44 is sent via the signal holding circuit 5. The communication can be stopped. The monitoring control unit 4 receives the activation signal 13 a at the input port 41.”)
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHAD G ERDMAN whose telephone number is (571)270-0177. The examiner can normally be reached Mon - Fri 7am - 3pm or 4pm EST..
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kenneth Lo can be reached at (571) 272-9774. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHAD G ERDMAN/Primary Examiner, Art Unit 2116