Prosecution Insights
Last updated: August 17, 2026
Application No. 19/088,444

VEHICLE AND VERIFICATION SYSTEM

Non-Final OA §102§103§112
Filed
Mar 24, 2025
Priority
Mar 28, 2024 — JP 2024-054802
Examiner
WORKU, SARON MATTHEWOS
Art Unit
Tech Center
Assignee
Toyota Motor Corporation
OA Round
1 (Non-Final)
65%
Grant Probability
Favorable
1-2
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 65% — above average
65%
Career Allowance Rate
13 granted / 20 resolved
+5.0% vs TC avg
Strong +60% interview lift
Without
With
+60.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
21 currently pending
Career history
51
Total Applications
across all art units

Statute-Specific Performance

§101
2.5%
-37.5% vs TC avg
§103
52.0%
+12.0% vs TC avg
§102
33.7%
-6.3% vs TC avg
§112
8.4%
-31.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 20 resolved cases

Office Action

§102 §103 §112
Detailed Action This office action is in response to applicant’s submission filed on March 24, 2025. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on March 24, 2025 has been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, an initialed and dated copy of Applicant’s IDS form 1449 is attached to the instant Office action. Drawings The drawings filed on March 24, 2025 have been accepted. The drawings were searched for informalities. Specification The specification filed on March 24, 2025 has been accepted. The specification was searched for informalities. Claim Rejections - 35 USC § 112 Claim 1-14 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. The term “designed to be limitedly accessible” in claims 1 and 10 is a relative term which renders the claim indefinite. The term “designed to be limitedly accessible” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. The limitation of the plurality of tokens of the target data are all of the tokens of the target data has been rendered indefinite by the use of the term “designed to be limitedly accessible” making it indefinite. The dependent claims included in the statement of rejection but not specifically addressed in the body of the rejection have inherited the deficiencies of their parent claim and have not resolved the deficiencies. Therefore, they are rejected based on the same rationale as applied to their parent claims above. Claim Rejections - 35 USC § 102 The present application is being examined under the pre-AIA first to invent provisions. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-6 and 10-11 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by US 2019/0007217 A1 to Takemori et al. (hereinafter, “Takemori”). Regarding claim 1, Takemori discloses: A vehicle comprising: a first control device including in-vehicle software (“The second ECU 1020 includes a mam arithmetic unit 1021 and an SHE (Secure Hardware Extension) 1022. The main arithmetic unit 1021 executes computer programs to achieve the function of the second ECU 1020” [0056] [Examiner notes that and the "computer program" * 1 is associated with the present application (in-vehicle software), and the "second ECU1010" is associated with the present application (first control device)]); and a second control device designed to be limitedly accessible by a specific administrator, wherein the first control device and the second control device can communicate with each other (“The second ECU 1020 receives an ECU code from the first ECU 1010 and then applies the ECU code by itself. (Step S105) The second ECU 1020 sends an applied-status measurement, representing the status of the second ECU 1020 applying the ECU code received from the first ECU 1010 by itself, to the first ECU 1010” [0088-0090] [Examiner notes that this shows they can communicate with each other]; “Example 1-d, the HSM 1012 having the certification-authority secret key Key_ca_s, which is installed in the automobile 1001, serves as a private certification authority. Thus, it is possible for the automobile 1001 to generate the automobile secret key Key_ve_s and the automobile public key certificate Cert_ve. For example, the certification-authority secret key Key_ca_s and the certification-authority public key certificate Cert_ca, which are installed in the automobile 1001, may be changed depending on the manufacture, type, and year of the automobile” [0132] [Examiner notes that the hSM is specifically described as being in the first ECU 1010 and the ECU is the control device performing the security operations. The certification-authority secret key key_ca_s originates from the certification authority. The CA is the trusted entity controlling the cryptographic credentials. The CA key is installed in the ECU’s HSM and the ECU relies on administrator-controlled cryptographic information. Since the second control device relies on administrator-controlled credentials for its security operations, access to those administrative security functions is limited to the certification authority]) the second control device is configured to: store a verification key for verifying validity of instruction information transmitted from outside of the second control device, the verification key being provided from the specific administrator in advance (“The control module 1201 sends the server public key certificate Cert_sv, which is successfully verified in validity by the IC chip 1202, to the first ECU 1010 via the diagnosis port 1060 of the automobile 1001. The first ECU 1010 receives the server public key certificate Cert_sv from the control module 1201 and then sends it to the HSM 1012. The key storage media 1013 of the HSM 1012 receives and stores the server public key certificate Cert_sv from the control module 1201” [0176] [Examiner notes that (the present application (verification)) and corresponds to the present application (transmitted from the outside of the second control device) because it is transmitted from the "control module 1201" (the present application (external)) to the "first ECU1010" (the present application (second control device))]; “The certification-authority public key certificate Cert_ca is safely stored on the HSM 1012 when manufactured” [0134] [Examiner notes that this text shows that the CA manages and provides the cryptographic verification credentials by transmitting or provisioning the certification-authority public key certificate to the vehicle, where it is stored in the HSM during manufacturing or initialization. Since the key is installed and stored before verification, the key is provided from the specific admin in advance]); and perform instruction verification to verify the validity of the instruction information using the verification key, and the first control device does not include the verification key (“The HSM 1012 verifies the electronic signature attached to the ECU code by use of the server public key certificate Cert_sv” [0084] [Examiner notes that "the HSM1012 verifies the electronic signature of the ECU code with the electronic signature by using the server public key certificate Cert _ sv", and "the ECU code with the electronic signature" corresponds to the present application (instruction information), and "verifies the electronic signature by using the server public key certificate Cert _ sv" corresponds to the present application (verification of validity). Examiner also notes that the second control device is storing the verification key, not the first control device]). Claim 10 recites substantially the same limitation as claim 1, in the form of a system for implementing the corresponding vehicle, therefore it is rejected under the same rationale. Regarding claim 2, Takemori discloses: receive the instruction information and a digital signature generated based on a secret key corresponding to the verification key (“secret key used for generating the first public key certificate” [0008]; “(2) In an onboard computer system according to one aspect of the present invention, i.e. the aforementioned onboard computer system of (1), the first secure element stores a third secret key and thereby generates a third electronic signature for application result information representing an applied result of the first data by use of the third secret key, wherein the onboard computer system transmits the application result information attached with the third electronic signature to the data delivering apparatus” [0009]); execute signature verification to verify validity of the digital signature using the verification key; and determine that the instruction information is valid when determining that the digital signature is valid (“The HSM 1012 verifies the electronic signature attached to the ECU code by use of the server public key certificate Cert_sv” [0084] [Examiner notes that "the HSM1012 verifies the electronic signature of the ECU code with the electronic signature by using the server public key certificate Cert _ sv", and "the ECU code with the electronic signature" corresponds to the present application (instruction information), and "verifies the electronic signature by using the server public key certificate Cert _ sv" corresponds to the present application (verification of validity)]. Regarding claim 3, Takemori discloses: wherein the instruction information includes data instructing to update the in-vehicle software to be distributed to the vehicle (“The present embodiment will be described with respect to an example that data of updated programs will be applied to ECUs (electronic control units) mounted on the automobile 1001” [0040]). Regarding claim 4, Takemori discloses: wherein the instruction information includes in-vehicle instruction information indicating an instruction transmitted from the in-vehicle software to hardware of the vehicle (“The first ECU 1010 includes a main arithmetic unit 1011 and an HSM (Hardware Security Module) 1012. The main arithmetic unit 1011 executes computer programs to achieve the function of the first ECU 1010. The HSM 1012 has an encryption processing function” [0053]). Regarding claim 5, Takemori discloses: wherein the instruction information includes cooperation instruction information indicating an instruction transmitted to the in-vehicle software from cooperative software cooperating with the in-vehicle software (“The first ECU 1010 receives the ECU code attached with an electronic signature from the communication module 1051 and then sends it to the HSM 1012” [0084] [Examiner notes that the communication module is the cooperative software]). Regarding claims 6 and 11, Takemori discloses: wherein the in-vehicle software included in the first control device is designed to be rewritable by one or more users (“computer programs may be normally updated by workers” [0004]), and the specific administrator includes a vehicle provider that provides the vehicle to the one or more users (“According to the procedure of delivering ECU codes of Example 1-c, the SIM 1052 having the certification-authority secret key Key_ca_s, which is installed in the automobile 1001, servers as a private certification authority. Thus, it is possible for the automobile 1001 to generate the automobile secret key Key_ve_s and the automobile public key certificate Cert_ve. In this connection, for example, the certification-authority secret key Key_ca_s and the certification-authority public key certificate Cert_ca, which are installed in the automobile 1001, can be changed depending on the manufacture, type, and year of the automobile” [0121]). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 7-9 and 12-14 are rejected under 35 U.S.C. 103 as being unpatentable over US 2019/0007217 A1 to Takemori et al. (hereinafter, “Takemori”) in view of JP 2005/244313 A to Ando. Regarding claims 7 and 12, Takemori discloses the system of claims 6/11. Takemori does not disclose: store user information for identifying each of the one or more users, the instruction information includes first user information transmitted to the second control device when a first user of the one or more users accesses the first control device, and the second control device is further configured to: execute user verification that is the instruction verification for the first user information based on the user information; and determine that the first user is an authorized user with valid access permission when determining that the first user information is valid. However, Ando discloses: store user information for identifying each of the one or more users, the instruction information includes first user information transmitted to the second control device when a first user of the one or more users accesses the first control device, and the second control device is further configured to: execute user verification that is the instruction verification for the first user information based on the user information; an determine that the first user is an authorized user with valid access permission when determining that the first user information is valid (“According to the first aspect of the present invention, the program distribution device creates an electronic signature by performing a cryptographic operation with a single encryption key on the program to which the access right identifier is added, and creates the program, the access right identifier, the electronic The signature and another encryption key paired with one encryption key are distributed to the in-vehicle gateway device. On the other hand, when the program distribution device distributes a program, an access right identifier, an electronic signature, and other encryption keys, the in-vehicle gateway device performs cryptographic operations using the other encryption keys on the program to which the access right identifier is added. An electronic signature is created, and an electronic signature created by performing cryptographic operations with one cryptographic key by the program distribution device is compared with an electronic signature created by performing cryptographic operations with another cryptographic key by itself. If the validity of the electronic signature is determined and it is detected that the electronic signature is valid, the access right to the vehicle ECU is set based on the access right identifier, and the access to the vehicle ECU for which the access right is set is permitted. In addition, access to the vehicle ECU for which the access right is not set is prohibited” [page 4]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Takemori with the added structure of Ando in order for the system to be able to efficiently verify users affiliated with the instruction sent. Regarding claims 8 and 13, a combination of Takemori-Ando discloses the system of claims 7/12. Takemori does not disclose: wherein the instruction information further includes cooperation instruction information indicating an instruction transmitted to the in-vehicle software from cooperative software cooperating with the in-vehicle software, and the second control device is further configured to: store information of cooperation permission for each of the one or more users, the cooperation permission indicating a permissible range of cooperation between the cooperative software and the in-vehicle software; and set the cooperation permission corresponding to the authorized user after the user verification. However, Ando discloses: wherein the instruction information further includes cooperation instruction information indicating an instruction transmitted to the in-vehicle software from cooperative software cooperating with the in-vehicle software, and the second control device is further configured to: store information of cooperation permission for each of the one or more users, the cooperation permission indicating a permissible range of cooperation between the cooperative software and the in-vehicle software; and set the cooperation permission corresponding to the authorized user after the user verification (“According to the first aspect of the present invention, the program distribution device creates an electronic signature by performing a cryptographic operation with a single encryption key on the program to which the access right identifier is added, and creates the program, the access right identifier, the electronic The signature and another encryption key paired with one encryption key are distributed to the in-vehicle gateway device. On the other hand, when the program distribution device distributes a program, an access right identifier, an electronic signature, and other encryption keys, the in-vehicle gateway device performs cryptographic operations using the other encryption keys on the program to which the access right identifier is added. An electronic signature is created, and an electronic signature created by performing cryptographic operations with one cryptographic key by the program distribution device is compared with an electronic signature created by performing cryptographic operations with another cryptographic key by itself. If the validity of the electronic signature is determined and it is detected that the electronic signature is valid, the access right to the vehicle ECU is set based on the access right identifier, and the access to the vehicle ECU for which the access right is set is permitted. In addition, access to the vehicle ECU for which the access right is not set is prohibited” [page 4] [Examiner notes that this text teaches assigning access rights after successful verification of an electronic signature. Specifically, once the distributed program is authenticated, the in-vehicle gateway sets access rights based on an access right identifier and permits access only to authorized ECUs while prohibiting unauthorized access. These access rights correspond to the claimed cooperation permissions because both define the permissible scope of interaction with the vehicle software]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Takemori with the added structure of Ando in order for the system to be able to efficiently verify users affiliated with the instruction sent. Regarding claims 9 and 14, a combination of Takemori-Ando discloses the system of claims 8/13. Takemori discloses: wherein in a case where the first control device is being accessed by the authorized user and the in-vehicle software receives the cooperation instruction information, the second control device is further configured to determine that the cooperation instruction information is valid when the cooperation instruction information is determined to be valid in the instruction verification (“The HSM 1012 verifies the electronic signature attached to the ECU code by use of the server public key certificate Cert_sv” [0084]) and Takemori does not disclose: a content of the cooperation instruction information is included in the permissible range indicated by the cooperation permission corresponding to the authorized user However, Ando discloses: a content of the cooperation instruction information is included in the permissible range indicated by the cooperation permission corresponding to the authorized user (“According to the first aspect of the present invention, the program distribution device creates an electronic signature by performing a cryptographic operation with a single encryption key on the program to which the access right identifier is added, and creates the program, the access right identifier, the electronic The signature and another encryption key paired with one encryption key are distributed to the in-vehicle gateway device. On the other hand, when the program distribution device distributes a program, an access right identifier, an electronic signature, and other encryption keys, the in-vehicle gateway device performs cryptographic operations using the other encryption keys on the program to which the access right identifier is added. An electronic signature is created, and an electronic signature created by performing cryptographic operations with one cryptographic key by the program distribution device is compared with an electronic signature created by performing cryptographic operations with another cryptographic key by itself. If the validity of the electronic signature is determined and it is detected that the electronic signature is valid, the access right to the vehicle ECU is set based on the access right identifier, and the access to the vehicle ECU for which the access right is set is permitted. In addition, access to the vehicle ECU for which the access right is not set is prohibited” [page 4]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Takemori with the added structure of Ando in order for the system to be able to efficiently verify users affiliated with the instruction sent. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure: Turley et al. (US 2022/0219709 A1) teaches techniques for a vehicle control system, including: a vehicle control section and a control server, wherein: the vehicle control section generates a common key for special mode control by random number generation, outputs the generated common key to the control server, and stores the generated common key in secure storage including a function that protects integrity and confidentiality of data; the control server stores the common key, applies the common key to a control signal to generate a message authentication code, and outputs the message authentication code and the control signal; the vehicle control section applies the common key to the control signal to generate a message authentication code and, when the message authentication code matches the message authentication code, implements control according to the control signal in the special mode; and when control in the special mode ends, the control server erases the stored common key. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SARON MATTHEWOS WORKU whose telephone number is (703)756-1761. The examiner can normally be reached Monday - Friday, 9:30 am - 6:30pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached on 571-270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SARON MATTHEWOS WORKU/Examiner, Art Unit 2408 /LINGLAN EDWARDS/Supervisory Patent Examiner, Art Unit 2408
Read full office action

Prosecution Timeline

Mar 24, 2025
Application Filed
Jul 28, 2026
Non-Final Rejection mailed — §102, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12701012
METHOD AND APPARATUS FOR PROVING ORIGINALITY OF CREATIVE DESIGN ON BASIS OF WEARABLE DEVICE
12m to grant Granted Aug 04, 2026
Patent 12665883
END USER PRIVACY MANAGEMENT OF ACCESSED DEVICE DATA
3y 11m to grant Granted Jun 23, 2026
Patent 12657346
Compressed Data Integrity Veritification Using Data Integrity Field
2y 9m to grant Granted Jun 16, 2026
Patent 12657300
METHOD FOR DETECTING MEMORY SAFETY BUG AND ELECTRONIC DEVICE SUPPORTING THE SAME
1y 8m to grant Granted Jun 16, 2026
Patent 12547939
SYSTEM AND A METHOD FOR PERFORMING A PRIVACY-PRESERVING DISTRIBUTION SIMILARITY TESTS BETWEEN A PLURALITY OF DATASETS
3y 0m to grant Granted Feb 10, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
65%
Grant Probability
99%
With Interview (+60.0%)
2y 8m (~1y 3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 20 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month