DETAILED ACTION
This office action is in response to the application filed on 3/18/2025. Claim(s) 1-20 is/are pending and are examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority/Benefit
Applicant’s priority claim is hereby acknowledged of CON of 17/377,256 07/15/2021 PAT 12273378, which papers have been placed of record in the file.
Information Disclosure Statement PTO-1449
The Information Disclosure Statement(s) submitted by applicant on 5/15/2025 has/have been considered. The submission is in compliance with the provisions of 37 CFR § 1.97. Form PTO-1449 signed and attached hereto.
Examiner’s Note – Allowable Subject Matter
Claims 9 overcome the prior art and would otherwise be allowable if incorporated into the base claim along with any intervening claims. Further, the claims must overcome the rejection below.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to:
http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claim(s) 1-20 is/are rejected on the grounds of nonstatutory double patenting as being unpatentable over claims 1, 3-7, 10-17, 19-20 of U.S. Patent No. 12273378. Although the claims at issue are not identical in form, they are not patentably distinct from each other. In particular, instant claims 1, 14, and 19 are anticipated by patented claim 1. Instant claims 2, 15, and 20 are anticipated by patented claim 1. Instant claim 3 is anticipated by patented claim 2. Instant claims 5 and 17 are anticipated by patented claim 2. Instant claim 6 is anticipated by patented claim 3. Instant claims 7 and 18 are anticipated by patented claim 4. Instant claim 8 is anticipated by patented claim 5. Instant claim 9 is anticipated by patented claim 6. Instant claim 10 is anticipated by patented claim 7. Instant claim 11 is anticipated by patented claim 10. Instant claims 12-14 are anticipated by patented claims 11-13, respectively. Instant claim 15 is anticipated by patented claim 13. Instant claims 17-19 are anticipated by patented claims 14-17, respectively. Instant claim 20 is anticipated by patented claim 17.
Instant claims 4 and 16 are substantially similar to patented claim 1. The patented claims do not, but in related art, Tasaki (US 2021/0067528 A1) ¶ 82 and 85 teaches determining multiple thresholds for threats and acting on the lower threat levels. Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of the patented claims and Tasaki, to modify the autonomous vehicle attack mitigation system of Alvarez in view of Overby in view of Juliato to include the method to have multiple threshold levels for threat as taught in Tasaki. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-3, 5-6, 11-15, 17, and 19-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Alvarez (US 2021/0114606 A1) in view of Overby (US 2019/0379682 A1) in view of Juliato (US 2020/0128031 A1).
Regarding claims 1, 14, and 19, Alvarez teaches:
“A method (Alvarez, ¶ 19 and 138 teach the implementation of method steps on a processor, memory and non-transitory computer readable medium), comprising: determining, whether an illicit signal transmitted on an in- vehicle communication network of a vehicle satisfies a threshold condition (Alvarez, Figs. 3B, 10A as well as ¶ 50 and 78-79 teach monitoring in vehicle network messages in a message stream. Alvarez, Figs. 3B, 10A-10B steps 1010 and 1012 as well as ¶ 50 and 80-86 teaches first determining if a message contains a malicious command based on its being outside of typical parameters for vehicle messages. Alvarez, Figs. 10A-10B steps 1014, 1016 and 1030 as well as ¶ 87-88 teaches determining if the malicious message results in a safety critical situation by checking if the expected trajectory produced by the message falls outside the reachability set of typical path planning options); and responsive to determining that the illicit signal satisfies the threshold condition, performing a countermeasure operation (Alvarez, Figs. 10A-10B steps 1016-1028 as well as ¶ 88-91 teaches that based on determining that an unsafe condition exists and further the level of unsafety, shutting down the automatic driving, i.e., ODD operational design domain. Following this, the control of the vehicle is either handed over to the driver or a redundant and separate sub-system element 1028 performs an emergency maneuver to protect the passengers)”.
Alvarez does not, but in related art, Overby teaches:
“determining, by a processing device (Overby, ¶ 40-41, 49-50 and 163 teaches vehicle onboard IDPS which makes determinations about messages traversing the in vehicle network and then can perform mitigation of malicious messages);
that renders communication on at least part of the in-vehicle communication network affected by the illicit signal (Overby, Figs. 10 and 11, ¶ 160-165 teaches corrupting CAN messages so that they can not harm the in vehicle modules)”.
Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Overby and Alvarez, to modify the autonomous vehicle attack mitigation system of Alvarez to include the method to make local threat determinations and mitigation methods as taught in Overby. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results.
Alvarez and Overby do not, but in related art, Juliato teaches:
“renders inoperable (Juliato, Fig. 9, ¶ 30, 34, 60, and 62-63 teaches taking the compromised ECU attempting a flooding attack offline and bringing up a backup ECU)”.
Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Overby, Juliato and Alvarez, to modify the autonomous vehicle attack mitigation system of Alvarez and Overby to include the method to shut down ECUs that are attacking the autonomous vehicle network as taught in Juliato. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results.
Regarding claims 2, 15, and 20, Alvarez, Overby, and Juliato and teaches:
“The method of claim 1 (Alvarez, Overby, and Juliato teaches the limitations of the parent claims as discussed above), wherein determining whether the illicit signal transmitted on the in-vehicle communication network satisfies the threshold condition is performed at the vehicle (Overby, ¶ 40-41, 49-50 and 163 teaches vehicle onboard IDPS which makes determinations about messages traversing the in vehicle network and then can perform mitigation of malicious messages. Overby, ¶ 211 and 259 teaches confidence threshold for determining malicious behavior)”.
Regarding claim 3, Alvarez, Overby, and Juliato and teaches:
“The method of claim 1 (Alvarez, Overby, and Juliato teaches the limitations of the parent claims as discussed above), wherein the vehicle is an autonomous vehicle (Alvarez, ¶ 144 autonomous vehicle)”.
Regarding claims 5 and 17, Alvarez, Overby, and Juliato and teaches:
“The method of claim 1 (Alvarez, Overby, and Juliato teaches the limitations of the parent claims as discussed above), wherein the in-vehicle communication network comprises a redundant system comprising a first vehicle sub-system and a second vehicle sub-system configured to perform redundant vehicle operations using the in- vehicle communication network (Juliato, Fig. 9, ¶ 30, 34, 60, and 62-63 teaches taking the compromised ECU attempting a flooding attack offline and bringing up a backup ECU), wherein performing the countermeasure operation comprises: disabling at least part of the first vehicle sub-system that is affected by the illicit signal while at least part of the second vehicle sub-system is enabled to perform the redundant vehicle operations that were previously performed by the first vehicle sub- system (Juliato, Fig. 9, ¶ 30, 34, 60, and 62-63 teaches taking the compromised ECU attempting a flooding attack offline and bringing up a backup ECU)”.
Regarding claim 6, Alvarez, Overby, and Juliato and teaches:
“The method of claim 1 (Alvarez, Overby, and Juliato teaches the limitations of the parent claims as discussed above), wherein performing the countermeasure operation causes a reduction in functionality of the vehicle (Juliato, Fig. 9, ¶ 30, 34, 60, and 62-63 teaches taking the compromised ECU attempting a flooding attack offline and bringing up a backup ECU)”.
Regarding claim 11, Alvarez, Overby, and Juliato and teaches:
“The method of claim 1 (Alvarez, Overby, and Juliato teaches the limitations of the parent claims as discussed above), wherein determining whether the illicit signal transmitted on an in-vehicle communication network satisfies the threshold condition comprises: identifying one or more characteristics corresponding to the illicit signal (Alvarez, Figs. 10A-10B steps 1014, 1016 and 1030 as well as ¶ 87-88 teaches determining if the malicious message results in a safety critical situation by checking if the expected trajectory produced by the message falls outside the reachability set of typical path planning options), wherein the one or more characteristics corresponding to the illicit signal comprise at least one of a vehicle operational state (Alvarez, Figs. 10A-10B steps 1014, 1016 and 1030 as well as ¶ 87-88 teaches determining if the malicious message results in a safety critical situation by checking if the expected trajectory produced by the message falls outside the reachability set of typical path planning options. Alvarez, Figs. 10A-10B steps 1014, 1016 and 1030 as well as ¶ 87-88 teaches determining if the malicious message results in a safety critical situation by checking if the expected trajectory produced by the message falls outside the reachability set of typical path planning options); and determining whether the illicit signal satisfies the threshold condition based on the one or more characteristics corresponding to the illicit signal (Alvarez, Figs. 10A-10B steps 1014, 1016 and 1030 as well as ¶ 87-88 teaches determining if the malicious message results in a safety critical situation by checking if the expected trajectory produced by the message falls outside the reachability set of typical path planning options)”.
Regarding claim 12, Alvarez, Overby, and Juliato teaches:
“The method of claim 1 (Alvarez, Overby, and Juliato teaches the limitations of the parent claims as discussed above), further comprising: detecting the illicit signal on the in- vehicle communication network (Alvarez, ¶ 49-50, in the decentralized IDS implementation each ECU node is able to detect that a message with its message ID is fraudulent because it knows whether or not it sent it and can notify the other nodes that it is fake)”.
Regarding claim 13, Alvarez, Overby, and Juliato teaches:
“The method of claim 12 (Alvarez, Overby, and Juliato teaches the limitations of the parent claims as discussed above), wherein detecting the illicit signal on the in- vehicle communication network comprises: determining whether a performance of a vehicle action satisfies a threshold tolerance, wherein the illicit signal is detected responsive to determining that the performance of the vehicle action does not satisfy the threshold tolerance (Alvarez, Figs. 10A-10B steps 1016-1028 as well as ¶ 88-91 teaches that based on determining that an unsafe condition exists and further the level of unsafety, shutting down the automatic driving, i.e., ODD operational design domain. Following this, the control of the vehicle is either handed over to the driver or a redundant and separate sub-system element 1028 performs an emergency maneuver to protect the passengers)”.
Claim(s) 4 and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Alvarez in view of Overby in view of Juliato in view of Tasaki (US 2021/0067528 A1).
Regarding claims 4 and 16, Alvarez, Overby, and Juliato and teaches:
“The method of claim 1 (Alvarez, Overby, and Juliato teaches the limitations of the parent claims as discussed above)”.
Alvarez in view of Overby in view of Juliato does not, but in related art, Tasaki teaches:
“determining that the illicit signal does not satisfy the threshold condition (Tasaki, ¶ 82 and 85 teaches determining multiple thresholds for threats and acting on the lower threat levels); determining whether the illicit signal satisfies an alternative threshold condition corresponding to a lower level severity than the threshold condition (Tasaki, ¶ 82 and 85 teaches determining multiple thresholds for threats and acting on the lower threat levels); and responsive to determining that the illicit signal satisfies the alternative threshold condition, performing an alternate countermeasure operation (Tasaki, ¶ 82 and 85 teaches determining multiple thresholds for threats and acting on the lower threat levels)”.
Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Alvarez in view of Overby in view of Juliato and Tasaki, to modify the autonomous vehicle attack mitigation system of Alvarez in view of Overby in view of Juliato to include the method to have multiple threshold levels for threat as taught in Tasaki. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results.
Claim(s) 7-8, 10, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Alvarez in view of Overby in view of Juliato in view of Kaster (US 2017/0063996 A1).
Regarding claims 7, and 18, Alvarez in view of Overby in view of Juliato:
“The method of claim 1 (Alvarez, Overby, and Juliato teaches the limitations of the parent claims as discussed above)”.
Alvarez in view of Overby in view of Juliato does not, but in related art, Kaster teaches:
“wherein performing the countermeasure operation comprises reducing power to the at least part of the in-vehicle communication network to prevent communication on the at least part of the in-vehicle communication network affected by the illicit signal (Kaster, ¶ 19 teaches shutting off power to the ECU that is the target of the attack)”.
Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Alvarez in view of Overby in view of Juliato and Kaster, to modify the autonomous vehicle attack mitigation system of Alvarez in view of Overby in view of Juliato to include the method to shut down an attacked ECU to thwart a vehicle network cyber attack as taught in Kaster. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results.
Regarding claim 8, Alvarez, Overby, and Juliato and Kaster teaches:
“The method of claim 7 (Alvarez, Overby, Kaster, and Juliato teaches the limitations of the parent claims as discussed above), wherein reducing the power to the at least part of the in- vehicle communication network comprises reducing the power to a node of the in-vehicle communication network (Kaster, ¶ 19 teaches shutting off power to the ECU that is the target of the attack)”.
Regarding claim 10, Alvarez, Overby, and Juliato and teaches:
“The method of claim 1 (Alvarez, Overby, and Juliato teaches the limitations of the parent claims as discussed above)”.
Alvarez in view of Overby in view of Juliato does not, but in related art, Kaster teaches:
“wherein performing the countermeasure operation comprises: transmitting a plurality of signals on the at least part of the in-vehicle communication network affected by the illicit signal to flood the at least part of the in- vehicle communication network with the plurality of signals (Kaster, ¶ 7 and 21 teaches creating and sending large amounts of high priority CAN messages on a vehicle network to block an attack)”.
Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Alvarez in view of Overby in view of Juliato and Kaster, to modify the autonomous vehicle attack mitigation system of Alvarez in view of Overby in view of Juliato to include the method to flood a CAN bus with messages to thwart a vehicle network cyber attack as taught in Kaster. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results”.
Conclusion
In the case of amending the claimed invention, Applicant is respectfully requested to indicate the portion(s) of the specification which dictate(s) the structure relied on for proper interpretation and also to verify and ascertain the metes and bounds of the claimed invention.
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure: See PTO-892.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Stephen T Gundry whose telephone number is (571) 270-0507. The examiner can normally be reached Monday-Friday 9AM-5PM (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571) 270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/STEPHEN T GUNDRY/Primary Examiner, Art Unit 2435