DETAILED ACTION
This Office Action is in response to the communication filed on 05/05/2026.
Claims 1-20 are pending.
Claims 1-20 have been amended.
Claims 1-20 are rejected.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Objections
The claim objections have been withdrawn due to Applicant’s amendments.
Claim Rejections - 35 USC § 101
The rejections under 101 have been withdrawn due to Applicant’s amendments.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
The previous 112 rejections have been withdrawn.
The term “a corresponding sensor device within each area corresponding to each second signal processing device” in claim 1, 14 and 18 not clear which renders the claim indefinite. It is not clear which object are corresponding to the other objects. For example, does:
“a... sensor device” correspond to “each area” and “to each second signal processing device” or
“a… sensor device” correspond to “each area” and “each area” corresponding to “each second signal processing device”.
Examiner believes that to each area has its own sensor and that each area has its own processing device. However, the language as written creates an antecedent basis issue because no “areas” have been introduced which leaves “each area” lacking antecedent basis.
It is not clear is applicant wants the claims to include multiple sensors in each area or multiple signals from each sensor, or both.
Claims 1, 14 and 18 have an antecedent basis issue which ties in to the above issue “a speed sensor signal” in introduced in singular form but then recited in plural form on 3rd last line of the claim as “the plurality of speed sensor signals” which creates an antecedent basis issue.
Claims 1, 14 and 18 recite “the syntax-based intrusion detection of the speed sensor signal” but the antecedent basis for this limitation reads “a syntax-based intrusion detection of the CAN message”. Additionally, the claims recite “the semantic-based intrusion detection based on correlation between the plurality of speed sensor signals received from the plurality of second signal processing devices” and “a semantic- based intrusion detection of the CAN message”.
Response to Arguments
The previous 112 rejections have been withdrawn, however new ones are made, see above.
Applicant argues (Remarks Page 16-17) that Yasmin does not teach an integrated processor, Examiner disagrees and cited Yasmin’s root IDS which teaches “Regarding the deployment of the root IDS (i.e., the first control component 601), the root IDS component will be deployed in any one of the following. The root IDS may be deployed in a dedicated hardware device that is attached to an external port of the switch or inside the switch; or, the root IDS can be implemented as root IDS software deployed on the switch; or, the root IDS may be implemented as root IDS software or hardware deployed on any vehicle domain controller device connected to the switch”
Applicant argues (Remarks Page 16-17) that Galula does not teach the specifics of comparing the data of a first sensor to the data of a second sensor, however Gala is not used to provide this teaching.
Applicant’s remaining arguments (Remarks Page 12-16) with respect to claims 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Applicant argues the dependent claims are allowable by virtue of dependent on independent claims, however examiner does not find the dependent claim allowable therefore does not find the dependent claims allowable.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 4-7, 9, 12-15 and 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Yasmin (C.N. 112997467), in view of Kitaori (U.S. 20070162252).
Regarding claims 1, 14 and 18,
Yasmin discloses: A signal processing system comprising:
a signal processing device comprising an integrated intrusion detection processor configured to, in response to receiving a Controller Area Network (CAN) message based on a first communication scheme, perform intrusion detection based on a semantic-based intrusion detection of the CAN message, and in response to receiving a Ethernet message based on a second communication scheme, perform intrusion detection on the Ethernet message; and (Yasmin [Page 15, Paragraph 4-6; Page 23, Paragraph 4-5 and page 24, paragraph 1-3; Figure 6a] teaches determining whether data traffic is an attack using a first and second monitoring component where both components generate and then combine reports which are used to determine whether traffic is an attack. This happens in response to each data packet, including a CAN message system which receives CAN and ethernet messages using system which detects based on semantics and/or syntax)
a second signal processing device comprising a first intrusion detection processor configured to, in response to receiving the CAN message based on the first communication scheme, perform intrusion detection based on a syntax-based intrusion detection of the CAN message, (Yasmin [Page 15-16; Page 22-23 Paragraph 4] teaches first and second processing devices where the first device passes the first report to the second device and in response the second device performs additional intrusion detection to generate the second report, including a CAN message system which receives CAN and ethernet messages using system which detects based on semantics and/or syntax)
wherein in response to receiving a CAN message based on the second communication scheme from an external source, the integrated intrusion detection processor in the signal processing device is configured to perform the intrusion detection based on the semantic-based intrusion detection of the CAN message after inspecting a header and payload based on the second communication scheme. (Yasmin [Pages 22-23] teaches inspecting the header and payload of the data packet to determine is a packet is normal, including a CAN message system which receives CAN and ethernet messages using system which detects based on semantics and/or syntax)
wherein the plurality of second signal processing devices are configured to receive… and perform the syntax-based intrusion detection of the… sensor signal, and (Yasmin [Page 15, Paragraph 4-6; Page 23, Paragraph 4-5 and page 24, paragraph 1-3; Figure 6a, Page 38] teaches multiple monitoring components which receive sensor data and include a CAN message system which receives CAN and ethernet messages using system which detects based on semantics and/or syntax and include data from redundant sources)
wherein the integrated intrusion detection processor in the signal processing device is configured to perform the semantic-based intrusion detection… corresponding to each second signal processing device (Yasmin [Page 15, Paragraph 4-6; Page 22-23, Paragraph 4-5 and page 24, paragraph 1-3; Figure 6a, Page 38, Fig. 8b-c] teaches multiple monitoring components which receive sensor data and include a CAN message system which receives CAN and ethernet messages using system which detects based on semantics and/or syntax and include coloration of data from redundant sources and multiple processing devices corresponding to multiple sensors (root IDS))
Yasmin does not explicitly teach: a speed sensor signal from a corresponding sensor device within each area
based on correlation correlation between the plurality of speed sensor signals received from the plurality of second signal processing devices, and in response to a difference between the plurality of speed sensor signals exceeding a reference value, determine that at least one of the plurality of speed sensor signals is abnormal. However, in the same field of endeavor Kitaori teaches: a speed sensor signal from a corresponding sensor device within each area corresponding to each second signal processing device (Kitaori [0022-0029, 0032-0036] teaches speed sensors corresponding to different sensor devices and different areas)
based on correlation between the plurality of speed sensor signals received from the plurality of second signal processing devices, and in response to a difference between the plurality of speed sensor signals exceeding a reference value, determine that at least one of the plurality of speed sensor signals is abnormal. (Kitaori [0022-0029, 0032-0036] teaches steps S300, S500/S600 and S1000 which teach S300 (data correlation), S500/S600 (threshold/speed exceeding a reference value), S700-S1000 (sensing an abnormal condition))
Yasmin and Kitaori are analogous art because they are from the same field of endeavor detection abnormalities.
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Yasmin and Kitaori before him or her, to modify the method of Yasmin to include the speed data corresponding comparisons from different sensors to identify abnormalities of Kitaori because it will allow for the abnormality detection of Yasmin to include detecting abnormalities and inconsistences in speed.
The motivation for doing so would be [“The invention provides a turning determination apparatus and a turning determination method for a vehicle, which can accurately determine whether a vehicle is turning by detecting wheel speeds of right and left wheels, even when the wheel speed of one of the right and left wheels greatly changes due to a slip or the like by detecting the speed of four different wheels.”] (Paragraph 0011-0013, 0021 by Kitaori)].
Therefore, it would have been obvious to combine Yasmin and Kitaori to obtain the invention as specified in the instant claim.
Claim 14 additionally discloses: wherein the second signal processing device is configured to receive a CAN message including an in-vehicle sensor signal based on the first communication scheme and perform intrusion detection on the CAN message, and to transmit the CAN message, for which the intrusion detection has been completed, based on the second communication scheme. (Yasmin [Page 15-16; Page 22-23 Paragraph 4] teaches first and second processing devices where the first device passes the first report to the second device and in response the second device performs additional intrusion detection to generate the second report)
Claim 18 additionally discloses: A vehicle comprising a signal processing system (Yasmin [Abstract] The invention claims an intrusion monitoring system, intrusion monitoring method and related product)
Regarding claims 4 and 17,
Yasmin discloses: The signal processing system of claim 1, wherein at least one of the second signal processing devices further comprises a second intrusion detection processor configured to, in response to receiving the Ethernet message based on the second communication scheme, perform intrusion detection on the Ethernet message. (Yasmin [Page 15-16; Page 22-23 Paragraph 4] teaches first and second processing devices where the first device passes the first report to the second device and in response the second device performs additional intrusion detection to generate the second report)
Regarding claim 5,
Yasmin in view of Kitaori discloses: The signal processing system of claim 1, wherein the at least one of the second signal processing devices is configured to receive a CAN message including an in-vehicle sensor signal based on the first communication scheme and perform intrusion detection on the CAN message, and to transmit the CAN message, for which the intrusion detection has been completed, based on the second communication scheme. (Yasmin [Page 15-16; Page 22-23 Paragraph 4] teaches first and second processing devices where the first device passes the first report to the second device and in response the second device performs additional intrusion detection to generate the second report)
Regarding claims 6 and 15,
Yasmin in view of Kitaori discloses: The signal processing system of claim 5, wherein the signal processing device is configured to transmit the CAN message based on the second communication scheme, which is received from the at least one of the second signal processing devices, to an external server. (Yasmin [Page 13, paragraph 2; Page 32 Paragraph 1-4] teaches that the processing device may be an external server)
Regarding claim 7,
Yasmin in view of Kitaori discloses: The signal processing system of claim 1, wherein the at least one of the second signal processing devices is configured to perform syntax-based intrusion detection based on a format or timing of the CAN message, and wherein the signal processing device is configured to perform semantic-based intrusion detection based on semantics of the CAN message. (Yasmin [Page 22 paragraph 2 – Page 24 paragraph 2] teaches detection of intrusion based on the format of the message)
Regarding claim 9,
Yasmin in view of Kitaori discloses: The signal processing system of claim 1, wherein the at least one of the second signal processing devices is configured to detect whether intrusion is detected in the CAN message based on a message ID, data length, and signal range of the CAN message, or a generation period of the CAN message, and wherein the signal processing device is configured to detect whether intrusion is detected in the CAN message based on a message sequence, a range of increase or decrease in signal, a signal state, or a signal correlation in the CAN message. (Yasmin [Page 23, Paragraph 2 – Page 23 Paragraph 2] teaches detecting intrusions-based frame data CAN IDS and/or frequency)
Regarding claim 12,
Yasmin in view of Kitaori discloses: The signal processing system of claim 4, wherein at least one of the second signal processing devices further comprises: a first accelerator configured to accelerate processing of the CAN message; and a second accelerator configured to accelerate processing of the Ethernet message. (Yasmin [Page 47, Paragraph 1-2] teaches the instructions may be executed by one or more processors, such as one or more digital signal processors (DSPs ), general microprocessors, application specific integrated circuits (ASICs), Field Programmable Logic Array (FPGAs) or other equivalent integrated or discrete logic circuits)
Regarding claim 13,
Yasmin in view of Kitaori discloses: The signal processing system of claim 1, wherein upon detecting intrusion in the CAN message or the Ethernet message, the integrated intrusion detection processor or the first intrusion detection processor is configured to drop the CAN message or the Ethernet message. (Yasmin [Page 40, Paragraph 5-6] teaches in response to determining data traffic is an attack, blocking the data traffic)
Claims 2-3, 8, 10-11, 16, 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Yasmin (C.N. 112997467), in view of Kitaori and further in view of Galula (U.S. 20170013005).
Regarding claims 2 and 19,
Yasmin in view of Kitaori discloses: The signal processing system of claim 1, wherein in response to receiving the CAN message based on the second communication scheme, the integrated intrusion detection processor in the signal processing device is configured to transmit the CAN message, for which the intrusion detection has been completed, (Yasmin [Page 15-16; Page 22-23 Paragraph 4] teaches first and second processing devices where the first device passes the first report to the second device and in response the second device performs additional intrusion detection to generate the second report)
Yasmin does not explicitly disclose: and a timing exception message related to the CAN message to at least one of the second signal processing devices.
However, in the same field of endeavor Galula discloses: and a timing exception message related to the CAN message to the second signal processing device. (Galula [Abstract, 0010-0011, 0059-0072, 0157-0168] teaches time based anomaly detection in an in-vehicle communication network)
Yasmin in view of Kitaori and Galula are analogous art because they are from the same field of endeavor in-vehicle intrusion detection.
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Yasmin in view of Kitaori and Galula before him or her, to modify the method of Yasmin in view of Kitaori to include the time based anomaly detection in an in-vehicle communication network of Galula because it will allow for
The motivation for doing so would be [“determine whether or not a message is anomalous based on a time difference between a reception of a CAN message from a first network and a reception of a second message from a second network”] (Paragraph 0010-0011 by Galula)].
Therefore, it would have been obvious to combine Yasmin in view of Kitaori and Galula to obtain the invention as specified in the instant claim.
Regarding claims 3, 16 and 20,
Yasmin in view of Kitaori and Galula discloses: The signal processing system of claim 2, wherein the first intrusion detection processor is configured to perform the intrusion detection based on the syntax-based intrusion detection based on a format or timing of the received CAN message, (Yasmin [Page 15, Paragraph 4-6; Page 23, Paragraph 4-5 and page 24, paragraph 1-3; Figure 6a] teaches determining whether data traffic is an attack using a first and second monitoring component where both components generate and then combine reports which are used to determine whether traffic is an attack. This happens in response to each data packet)
and, in response to receiving the timing exception message from the signal processing device, determine that the timing of the CAN message is normal while performing the intrusion detection based on the syntax-based intrusion detection. (Galula [0072-0093, 0157-0168, 0301-0302] teaches performing additional actions when the timing is normal)
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify with Galula for similar reasons as cited in claim 2.
Regarding claim 8,
Yasmin in view of Kitaori does not explicitly disclose: The signal processing system of claim 1, wherein the signal processing device is configured to perform semantic-based intrusion detection based on a correlation between a plurality of CAN messages received from a plurality of second signal processing devices.
However, in the same field of endeavor Galula teaches: The signal processing device of claim 1, wherein the signal processing device is configured to perform semantic-based intrusion detection based on a correlation between a plurality of CAN messages received from a plurality of second signal processing devices. (Galula [0037-0041, 0053-0063, 0113-0125, 0128-0134] teaches intrusion detection by comparing a plurality of messages to determine whether the messages are within the expected parameters correlating to abnormal or abnormal messages)
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify with Galula for similar reasons as cited in claim 2.
Regarding claim 10,
Yasmin in view of Kitaori and Galula discloses: The signal processing system of claim 1,
Yasmin does not explicitly disclose: wherein in response to a vehicle speed range in the CAN message exceeding an allowable value, the at least one of the second signal processing devices is configured to detect the CAN message as a message corresponding to the intrusion detection based on the syntax-based intrusion detection.
However, in the same field of endeavor Galula teaches: wherein in response to a vehicle speed range in the CAN message exceeding an allowable value, the second signal processing device is configured to detect the CAN message as a message corresponding to the intrusion detection based on the syntax-based intrusion detection. (Galula [0056-0058, 161-0165, 0230, 0258-0268) teaches determining context for intrusion detection according to vehicle speed)
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify with Galula for similar reasons as cited in claim 2.
Regarding claim 11,
Yasmin in view of Kitaori and Galula discloses: The signal processing system of claim 1,
Yasmin does not explicitly disclose: wherein in response to a range of increase or decrease in vehicle speed in the CAN message exceeding an allowable range of increase or decrease, the signal processing device is configured to detect the CAN message as a message corresponding to the intrusion detection based on the semantic-based intrusion detection.
However, in the same field of endeavor Galula teaches: wherein in response to a range of increase or decrease in vehicle speed in the CAN message exceeding an allowable range of increase or decrease, the signal processing device is configured to detect the CAN message as a message corresponding to the intrusion detection based on the semantic-based intrusion detection. (Galula [0056-0058, 161-0165, 0230, 0258-0268) teaches determining context for intrusion detection according to vehicle acceleration or deceleration)
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify with Galula for similar reasons as cited in claim 2.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's
disclosure.
Endo 2018-7-13 (US 20190028493) teaches An attack monitoring system comprises a server device; and a plurality of communication devices constituting a wireless communication network, wherein the server device includes an information acquirer that acquires, in a case where an attack is performed on a mobile unit connected to the wireless communication network, attacker information serving as information related to a transmission source of the attack; and an information sharer that causes the plurality of communication devices to share the attacker information, and each of the plurality of communication devices blocks communication transmitted from the transmission source which corresponds to the shared attacker information.
Kim 2021-2-10 (US 20230109507) teaches An intrusion detection system for detecting intrusions in an in-vehicle network includes a message queue module configured to store network messages collected from the in-vehicle network in a message queue, a memory configured to securely store a ruleset comprising a set of detection rules used in a plurality of detection techniques, a rule engine configured to apply the plurality of detection techniques to the collected network messages to detect security events and configured to determine a severity score and a reliability score for each detected security event, and an interface manager configured to transmit detection reports to a remote backend server in response to detection of the security events.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to THOMAS A CARNES whose telephone number is (571)272-4378. The examiner can normally be reached Monday-Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached at (571) 272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
THOMAS A. CARNES
Examiner
Art Unit 2436
/THOMAS A CARNES/Examiner, Art Unit 2436 /MOEEN KHAN/Primary Examiner, Art Unit 2436