CTNF 19/006,156 CTNF 88811 Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. DETAILED ACTION This Office Action is in response to the application 19/006,156 filed on 01/16/2025. Claims 1-12 have been examined and are pending in this application. Information Disclosure Statement The information disclosure statement (IDS), submitted on 12/30/2024, is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Objections 07-29-01 AIA Claim 4 is objected to because of the following informalities: Regarding claim 4 , the acronym 'HMI' is used without spelling out in full at their first occurrences in the claim . Appropriate correction is required. Claim Rejections - 35 USC § 112 07-30-02 AIA The following is a quotation of 35 U.S.C. 112(b): (B) CONCLUSION. —The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. 07-34-01 Claim 1-12 are rejected under 35 U.S.C. 112(b) , as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention. Regarding claims 1, 9, 11 and 12, claims 1, 9, 11 and 12 recite “a plurality of function blocks :” which is a subjective term. A claim that requires the exercise of subjective judgment without restrictions may render the claim indefinite. In re Musgrave, 431 F.2d 882, 893 (CCPA 1970). Claim scope cannot depend solely on the unrestrained, subjective opinion of a particular individual purported to be practicing the invention. Datamize LLC v. Plumtree Software, Inc., 417 F.3d 1342, 1350, 75 USPQ2d 1801, 1807 (Fed. Cir. 2005). The meaning of the term “function blocks” is not provided in the specification; therefore, the claim is rejected under 35 USC 112 second paragraphs ( see MPEP 2173.05(b)). Regarding claim 12 , claim 12 recites “A non-transitory computer readable storage medium storing a program for causing a computer mounted in a vehicle to implement ……” which is unclear. It is not clear how the stored program causing a computer to implement the steps determine and implement update. For the examination purpose Examiner understand that programs or codes are loaded in a non-transitory computer readable storage medium” or “a computer readable storage device” and executed by a processor that could implement the steps such as determine and implement update. 35 USC § 112, Sixth Paragraph – Claim Interpretations The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f): (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f), because the claim limitation(s) uses a generic placeholder (e.g., “ a coordination control unit”, "an access control unit," "a necessity determination unit," “a state determination unit,” "an update execution unit that receives,” "a permission confirmation unit," "an operation permission unit," “a state determination unit,” "an occupant determination unit," "a first confirmation unit," “a second confirmation unit,” "a battery state monitoring unit," "a limited update unit," and "a function”) that is coupled with functional language (e.g., configured to ) without reciting sufficient structure to perform the recited function (e.g., to implement, receive, determine etc.) and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: “ a coordination control unit configured to implement coordination between the plurality of function blocks; wherein the coordination control unit includes: an access control unit configured to, …,” in claim 1 . “unit configured to determine presence or absence of an occupant in the vehicle, and the permission confirmation unit includes: a first confirmation unit configured to confirm the permission from the………” in claim 4. “a battery state monitoring unit configured to monitor a state of a battery mounted in the vehicle; and a limited update unit configured to partially implement the update ……” in claim 5 “a necessity determination unit configured to determine whether to be in an update necessity state where there is a need to implement an update to the access authorization policy; a state determination unit configured to determine whether a state of the vehicle is in a safe state where the update to the access authorization policy can be…...” in claim 9. “a function to determine whether to be in an update necessity state where there is a need to implement ……….configured to execute a predetermined process; a function to determine whether a state of the………” in claim 12. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f), applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f). Regarding claims 2-8 and 10 ; claims 2-8 and 10 are dependent on claim 1 and 9, and therefore inherit 35 USC § 112, Sixth Paragraph – Claim Interpretations issues of the independent claim. Claim Rejections - 35 USC § 103 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim s 1-12 are rejected under 35 U.S.C. 103 as being unpatentable over Kato (US 2008/0219274) and in view of Kaijo (JP 2018/160888) . Regarding claim 1, Kato discloses an in-vehicle system comprising: a plurality of function blocks, each mounted on one of a plurality of electronic control units connected to an in-vehicle network, or on an external device remotely connected to the in-vehicle network, each configured to execute a predetermined process (Kato abstract; An on-vehicle gateway device connected to an information system network and a control system network of a vehicle executes monitoring the status of an information system via an information system access circuit taking charge of message transmission and reception to and from the information system network, and an information system management step to manage information acquired by the information system monitoring. See also par. 0014); and a coordination control unit configured to implement coordination between the plurality of function blocks (Kato par. 0063; A policy management unit 109 managing policies for access control, an information system monitoring unit 105 monitoring the status of the information system by using the information system access unit 102, an information system configuration management unit 106 storing and managing information acquired by the information system monitoring unit 105, a control system monitoring unit 107 monitoring the status of the control system by using the control system access unit 102. See also par. 0074); wherein the coordination control unit includes: an access control unit configured to, upon receiving an access request from a use source block, which is one of the plurality of function blocks, to a use destination block, which is another of the plurality of function blocks, determine whether the use source block has access right to the use destination block using an access authorization policy that defines access rights between the function blocks, and to transmit the access request to the use destination block when it is determined that the access right is present (Kato par. 0079 and 0090; First, the control system monitoring unit 107 requests the control system access unit 104 for an access to the control system (step 601), and the control system access unit 104 performs diagnostic communication, such as DiagOnCAN, regarding the designated part (step 602). A response message by diagnostic communication is returned to the control system monitoring unit 107 (step 603), and management information in the control system configuration management unit 108 is updated in accordance with the response message (step 604). If, for instance, a response message to an inquiry from the control system monitoring unit 107 to the ECU or a message periodically transmitted from the ECU includes information on battery voltage. A message from the information system LAN 112 is accepted by the information system access unit 102 (step 801). After that, the access control unit 103 acquires the policy from the policy management unit 109 (step 802)); a necessity determination unit configured to determine whether to be in an update necessity state where there is a need to implement an update to the access authorization policy (Kato abstract, par. 0024 and 0099; A control system management step to manage information acquired by the control system monitoring, managing policies for access control by the access control circuit controlling data flows between the information system access circuit and the control system access circuit, and determining whether or not to update the policies managed by policy management and to update the policies. After that, the policy update unit 110 updates the contents of the policy management unit 109 with the latest policies (step 907) and, comparing the recommended applicable system and the control system configuration management unit 108, if there is a difference, sends a message urging necessary system updating (if the ECU 117 is to be updated, reprogramming) to the car navigation terminal 113 to have it displayed (step 908)). Kato teaches, a control system management step to manage information acquired by the control system monitoring, managing policies for access control by the access control circuit (Kato abstract). However, Kato does not explicitly disclose a state determination unit configured to determine whether a state of the vehicle equipped with the in-vehicle network is in a safe state where the update to the access authorization policy is safely implemented; and an update execution unit configured to implement the update to the access authorization policy when the necessity determination unit determines to be in the update necessity state and the state determination unit determines that the vehicle is in the safe state. However, in an analogous art, Kaijo teaches a state determination unit configured to determine whether a state of the vehicle equipped with the in-vehicle network is in a safe state where the update to the access authorization policy is safely implemented (Kaijo par. 0097; When the vehicle state is "running" or "stopped", a determination rule not performing the updating process is shown. On the other hand, when the vehicle state is "parked", a determination rule for performing the update processing is shown. See also par. 0146); and an update execution unit configured to implement the update to the access authorization policy when the necessity determination unit determines to be in the update necessity state and the state determination unit determines that the vehicle is in the safe state (Kaijo par. 0097; Then, when the vehicle state changes to "parking", it is determined that the update processing unit 1120 satisfies the condition for executing the update processing, and the update processing is executed. See also par. 0103). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Kaijo with the method and system of Kato, wherein an update execution unit configured to implement the update to the access authorization policy when the necessity determination unit determines to be in the update necessity state and the state determination unit determines that the vehicle is in the safe state to provide users with a means for an update processing method, an on-vehicle network system, and an electronic control unit that can efficiently and reliably update a key used in an on-vehicle network system (Kaijo abstract). Regarding claim 2 , Kato and Kaijo disclose the in-vehicle system according to claim 1, Kato further discloses wherein the update execution unit further includes: a permission confirmation unit configured to confirm whether there is permission from a vehicle user to implement the update to the access authorization policy; and an operation permission unit configured to permit the operation of the update execution unit when the permission confirmation unit confirms the permission from the vehicle user (Kato abstract, par. 0024 and 0099; A control system management step to manage information acquired by the control system monitoring, managing policies for access control by the access control circuit controlling data flows between the information system access circuit and the control system access circuit, and determining whether or not to update the policies managed by policy management and to update the policies. After that, the policy update unit 110 updates the contents of the policy management unit 109 with the latest policies (step 907) and, comparing the recommended applicable system and the control system configuration management unit 108, if there is a difference, sends a message urging necessary system updating (if the ECU 117 is to be updated, reprogramming) to the car navigation terminal 113 to have it displayed (step 908)). Regarding claim 3 , Kato and Kaijo disclose the in-vehicle system according to claim 2, Kato further discloses wherein the permission confirmation unit is configured to confirm whether there is permission from the vehicle user when the necessity determination unit determines to be in the update necessity state and the state determination unit determines to be the safe state (Kato par. 0091; Next, the determination of whether or not to permit access checked at step 803 or 804 is confirmed (step 805). If the result is to permit access, it is determined whether or not conversion is needed by comparing the "CAN ID" prescribed by the access conversion rules of FIG. 7C with the CAN ID of the transmission message and "Part name", "Hardware identifier" and "Software identifier" prescribed in the "Check list" prescribed by the access conversion rules of FIG. 7C with the corresponding contents of the information system configuration management unit 106 or the control system configuration management unit 108 (step 806).) Regarding claim 4 , Kato and Kaijo disclose the in-vehicle system according to claim 2, Kaijo further disclose wherein the update execution unit further includes an occupant determination unit configured to determine presence or absence of an occupant in the vehicle, and the permission confirmation unit includes: a first confirmation unit configured to confirm the permission from the vehicle user via an HMI device provided in the vehicle when the occupant determination unit determines that there is an occupant; and a second confirmation unit configured to confirm the permission from the vehicle user via a pre-registered user terminal when the occupant determination unit determines that there is no occupant (Kaijo par. 0091; Further, the frame processing unit 1115 performs processing according to the data of the received frame. It is assumed that the ECU 111 has a function of sounding an alarm sound such as having a speaker or the like for sounding an alarm sound to an occupant of a vehicle). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Kaijo with the method and system of Kato, wherein an update execution unit configured to implement the update to the access authorization policy when the necessity determination unit determines to be in the update necessity state and the state determination unit determines that the vehicle is in the safe state to provide users with a means for an update processing method, an on-vehicle network system, and an electronic control unit that can efficiently and reliably update a key used in an on-vehicle network system (Kaijo abstract). Regarding claim 5 , Kato and Kaijo disclose the in-vehicle system according to claim 1, Kato further discloses wherein the update execution unit further includes: a battery state monitoring unit configured to monitor a state of a battery mounted in the vehicle; and a limited update unit configured to partially implement the update to the access authorization policy when the battery state is a low voltage state where an operation of the update execution unit may become unstable (Kato par. 0017 and 0079; In another preferable configuration, the control system monitoring unit has means to acquire a battery voltage from a message flowing over the control system network. A response message to an inquiry from the control system monitoring unit 107 to the ECU or a message periodically transmitted from the ECU includes information on battery voltage, this information is extracted from the message, and the status 404 of the record regarding the part name 401 "battery" in FIG. 4 is updated by entering a value, such as "voltage 10 V). Regarding claim 6 , Kato and Kaijo disclose the in-vehicle system according to claim 1, Kaijo further discloses wherein the safe state is a state where the vehicle is in parking or stopped (Kaijo par. 0097; Then, when the vehicle state changes to "parking", it is determined that the update processing unit 1120 satisfies the condition for executing the update processing, and the update processing is executed. See also par. 0103). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Kaijo with the method and system of Kato, wherein an update execution unit configured to implement the update to the access authorization policy when the necessity determination unit determines to be in the update necessity state and the state determination unit determines that the vehicle is in the safe state to provide users with a means for an update processing method, an on-vehicle network system, and an electronic control unit that can efficiently and reliably update a key used in an on-vehicle network system (Kaijo abstract). Regarding claim 7 , Kato and Kaijo disclose the in-vehicle system according to claim 1, Kato further discloses wherein the necessity determination unit determines to be in the update necessity state when there is update information for the access authorization policy (Kato abstract, par. 0024 and 0099; A control system management step to manage information acquired by the control system monitoring, managing policies for access control by the access control circuit controlling data flows between the information system access circuit and the control system access circuit, and determining whether or not to update the policies managed by policy management and to update the policies. After that, the policy update unit 110 updates the contents of the policy management unit 109 with the latest policies (step 907) and, comparing the recommended applicable system and the control system configuration management unit 108, if there is a difference, sends a message urging necessary system updating (if the ECU 117 is to be updated, reprogramming) to the car navigation terminal 113 to have it displayed (step 908)). Regarding claim 8 , Kato and Kaijo disclose the in-vehicle system according to claim 1, Kato further discloses wherein the necessity determination unit determines to be in the update necessity state when an abnormality of the vehicle is detected (Kato par. 0085; The configuration described above makes possible appropriate access control by adapting to version updating and status variations of the vehicle expected to change dynamically. For instance, such measures can be taken as "no access to the ECU is attempted if the battery voltage is not above a prescribed level" or "any request from the car navigation device is intercepted if any abnormality in the car navigation device is detected"). Regarding claim 9 , Kato discloses an electronic control device mounted on a vehicle, comprising: an access control unit configured to, upon receiving an access request from a use source block, which is one of a plurality of function blocks each configured to execute a predetermined process, to a use destination block, which is another of the plurality of function blocks, determine whether the use source block has access right to the use destination block using an access authorization policy that defines access rights between the function blocks, and to transmit the access request to the use destination block when it is determined that the access right is present (Kato par. 0079 and 0090; First, the control system monitoring unit 107 requests the control system access unit 104 for an access to the control system (step 601), and the control system access unit 104 performs diagnostic communication, such as DiagOnCAN, regarding the designated part (step 602). A response message by diagnostic communication is returned to the control system monitoring unit 107 (step 603), and management information in the control system configuration management unit 108 is updated in accordance with the response message (step 604). If, for instance, a response message to an inquiry from the control system monitoring unit 107 to the ECU or a message periodically transmitted from the ECU includes information on battery voltage. A message from the information system LAN 112 is accepted by the information system access unit 102 (step 801). After that, the access control unit 103 acquires the policy from the policy management unit 109 (step 802)); a necessity determination unit configured to determine whether to be in an update necessity state where there is a need to implement an update to the access authorization policy (Kato abstract, par. 0024 and 0099; A control system management step to manage information acquired by the control system monitoring, managing policies for access control by the access control circuit controlling data flows between the information system access circuit and the control system access circuit, and determining whether or not to update the policies managed by policy management and to update the policies. After that, the policy update unit 110 updates the contents of the policy management unit 109 with the latest policies (step 907) and, comparing the recommended applicable system and the control system configuration management unit 108, if there is a difference, sends a message urging necessary system updating (if the ECU 117 is to be updated, reprogramming) to the car navigation terminal 113 to have it displayed (step 908)). Kato teaches, a control system management step to manage information acquired by the control system monitoring, managing policies for access control by the access control circuit (Kato abstract). However, Kato does not explicitly disclose a state determination unit configured to determine whether a state of the vehicle is in a safe state where the update to the access authorization policy can be safely implemented; and an update execution unit configured to implement the update to the access authorization policy when the necessity determination unit determines to be in the update necessity state and the state determination unit determines to be in the safe state. However, in an analogous art, Kaijo teaches a state determination unit configured to determine whether a state of the vehicle is in a safe state where the update to the access authorization policy can be safely implemented (Kaijo par. 0097; when the vehicle state is "running" or "stopped", a determination rule not performing the updating process is shown. On the other hand, when the vehicle state is "parked", a determination rule for performing the update processing is shown. See also par. 0146); and an update execution unit configured to implement the update to the access authorization policy when the necessity determination unit determines to be in the update necessity state and the state determination unit determines to be in the safe state (Kaijo par. 0097; Then, when the vehicle state changes to "parking", it is determined that the update processing unit 1120 satisfies the condition for executing the update processing, and the update processing is executed. See also par. 0103). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Kaijo with the method and system of Kato, wherein an update execution unit configured to implement the update to the access authorization policy when the necessity determination unit determines to be in the update necessity state and the state determination unit determines that the vehicle is in the safe state to provide users with a means for an update processing method, an on-vehicle network system, and an electronic control unit that can efficiently and reliably update a key used in an on-vehicle network system (Kaijo abstract). Regarding claim 10 , Kato and Kaijo disclose the electronic control device according to claim 9, wherein the necessity determination unit is configured to determine to be in the update necessity state when there is a first situation where update information for the access authorization policy exists, and when there is a second situation where an abnormality of the vehicle is detected (Kato par. 0085; The configuration described above makes possible appropriate access control by adapting to version updating and status variations of the vehicle expected to change dynamically. For instance, such measures can be taken as "no access to the ECU is attempted if the battery voltage is not above a prescribed level" or "any request from the car navigation device is intercepted if any abnormality in the car navigation device is detected"); and the update execution unit is configured to, in the first situation, update a normal-time access authorization policy using the update information acquired from an external device remotely connected to an in-vehicle network to which the electronic control device is connected, and in the second situation, switch to and use an abnormal-time access authorization policy prepared separately from the normal- time access authorization policy (Kato par. 0119; he validity duration 10703 indicates how long the will be held by the on-vehicle gateway device 10100. For instance, a length of time matching the data updating time designated by software on the information system terminal 10122 which the control request 10702 causes to generate is designated. Thus, it is usual for information on the traveling route which is updated at one-second intervals to remain effective for one second until the information is updated next time). Regarding claims 11-12; claims 11-12 are directed to a method and non-transitory computer readable storage medium associated with the control device claimed in claim 9. Claims 11-12 are similar in scope to claim 9 respectively, and is therefore rejected under similar rationale respectively. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SANCHIT K SARKER whose telephone number is (571)270-7907. The examiner can normally be reached M-F 8:30 AM-5:30 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, FARID HOMAYOUNMEHR can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SANCHIT K SARKER/Primary Examiner, Art Unit 2495 Application/Control Number: 19/006,156 Page 2 Art Unit: 2495 Application/Control Number: 19/006,156 Page 3 Art Unit: 2495 Application/Control Number: 19/006,156 Page 4 Art Unit: 2495 Application/Control Number: 19/006,156 Page 5 Art Unit: 2495 Application/Control Number: 19/006,156 Page 6 Art Unit: 2495 Application/Control Number: 19/006,156 Page 7 Art Unit: 2495 Application/Control Number: 19/006,156 Page 8 Art Unit: 2495 Application/Control Number: 19/006,156 Page 9 Art Unit: 2495 Application/Control Number: 19/006,156 Page 10 Art Unit: 2495 Application/Control Number: 19/006,156 Page 11 Art Unit: 2495 Application/Control Number: 19/006,156 Page 12 Art Unit: 2495 Application/Control Number: 19/006,156 Page 13 Art Unit: 2495 Application/Control Number: 19/006,156 Page 14 Art Unit: 2495 Application/Control Number: 19/006,156 Page 15 Art Unit: 2495 Application/Control Number: 19/006,156 Page 16 Art Unit: 2495 Application/Control Number: 19/006,156 Page 17 Art Unit: 2495 Application/Control Number: 19/006,156 Page 18 Art Unit: 2495 Application/Control Number: 19/006,156 Page 19 Art Unit: 2495 Application/Control Number: 19/006,156 Page 20 Art Unit: 2495