DETAILED CORRESPONDENCE
This Office action is in response to the application filed 4/14/2025.
Claim Status
Claims 1-11 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 4/14/2025 complies with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Drawings
The drawings are objected to under 37 CFR 1.83(a) because they fail to show the written descriptive labels for the blocks in the block diagrams of figures 2 and 4 as described in the specification. Any structural detail that is essential for a proper understanding of the disclosed invention should be shown in the drawing. MPEP § 608.02(d). Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-11 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Yousuf et al., US 2022/0080992 hereinafter “Yousuf”.
Claim 1, 9 and 11. Yousuf teaches a method for performing an Automated Driving System (ADS) feature, the ADS feature enabling a vehicle to provide at least conditional driving automation, comprising:
controlling an acceleration of the vehicle using a control system based on automotive sensor data obtained by one or more automotive sensors of the vehicle and a planned acceleration, wherein the control system comprises a first set of control components having a first Automotive Safety Integrity Level (ASIL) and a second set of control components having a second ASIL, the first ASIL being lower than the second ASIL (Taken together the following cited section reads on this element as such: [0026]-[0027], [0046], [0048], [0051], [0057], [0108] and [0167]—Each of the three main controller processors independently obtains sensor information, independently processes and independently actuates peripheral devices used to control the vehicle or other apparatus. In the example non-limiting embodiments, each of the three processors is independently powered….All relevant inputs gathered by sensors are fed into each of the three processors. Each of the three processors independently processes the sensor data, and independently provides actuation to peripheral devices….Monitoring of each processor with other processors (ASIL-B micro 1 monitors ASIL-B micro 2 and ASIL-D micro SOH and take appropriate safe action when needed….Redundant algorithm executing in 2 ASIL-B micros from sensor data processing to actuator control commands using the GPU, ASIL-B Micro cores, and safety engine (SCE) and controls algorithm executing in ASIL-D Micro….Independence of the multiple processors in terms of sensor data processing, execute applications and generate actuation commands and deliver the command(s) to actuation system(s)…. Independence of the multiple processors in terms of sensor data processing, execute applications and generate actuation commands and deliver the command(s) to actuation system(s)…. controller 100 is essentially an onboard supercomputer that operates in real time to process sensor signals and output autonomous operation commands to self-drive vehicle 50 and/or assist the human vehicle driver in driving vehicle 50. Controller 100 operates …[the] propulsion unit 56 which also receives an accelerator/throttle actuation signal 64. Controller 100 provides autonomous driving outputs in response to an array of sensor inputs….The object sensing inputs assumed (initial) to be at processors 202, 204 (ASIL-B). As is well known, Automotive Safety Integrity Level (ASIL) is a risk classification scheme defined by the ISO 26262-Functional Safety for Road Vehicles standard…The ASIL is established by performing a risk analysis of a potential hazard by looking at the Severity, Exposure and Controllability of the vehicle operating scenario. The safety goal for that hazard in turn carries the ASIL requirements. There are four ASILs identified by the standard: ASIL-A, AS1L-B, ASIL-C & ASIL-D, ASIL-D dictates the highest integrity requirements on the product and ASIL-A the lowest. Thus, ASIL-D provides a higher level of autonomous safety as compared to ASIL-B”);
detecting an acceleration deviation caused by the first set of control components based on the automotive sensor data (Taken together the following cited section reads on this element as such: [0033], [0101], [0110]-[0112]—“When one of the processors detects that another processor has failed, the detecting processor sends out a message indicating the failure which allows the overall system to adapt to the failure….avoid or mitigate unintended vehicle acceleration that may potentially lead to a hazard….the controller performs sensor data processing 140, redundant…sensor data processing 142, vehicle dynamics/vehicle path calculation 144, sensor fusion 146, and other functions that run in low priority logic loops that can be dormant and become active under certain fault conditions….”); and
when the acceleration deviation is detected, determining a safe acceleration state using the second set of control components, wherein the safe acceleration state is selected from a set of safe acceleration states based on the automotive sensor data, the set comprising at least a maximum deceleration, a reduced deceleration and a reduced acceleration (Taken together the following cited section describes this element as such: [0028], [0029], [0032], [0057]—“If one of the three processors fails for any reason, the two other processors continue to operate. Because they are performing operations that are redundant to the operations that would have been performed by the failed processor, autonomy and its associated critical functions can still be maintained when any one of the three processors fails….Controller 100 operates vehicle brakes tip via one or more braking actuators 61, operates steering mechanism 58 via a steering actuator 62, and operates propulsion unit 56 which also receives an accelerator/throttle actuation signal 64…. In other words, the processors 202, 204 together perform all of the required functions to comply with ASIL-B, and the third processor 206 augments their functionality with additional functions e.g., imminent collision or emergency braking) to provide compliance with ASIL-D, in the event of a failure of the third processor 206, the first two processors 202, 204 may be able to continue providing ASIL-B level service and may, also be able to begin providing additional active services to approach or even meet ASIL-D.”).
Claims 2 and 10. Yousuf teaches the method of claim 1 and further teaches, wherein the planned acceleration indicates an acceleration to be performed by the vehicle during a planning horizon duration, the planned acceleration being determined, for each clock cycle of a system clock, by an acceleration determination module coupled to the control system (Taken together the following cited section reads on this element as such: [0189]-[0191]—“As an example, when vehicle cameras indicate that a vehicle ahead is slowing down so that braking needs to be applied, two independent processors 202, 204 and/or processes 642, 648 independently processing the incoming sensor data may each determine that braking should be applied, but they may differ in the amount in their respective determinations of the amount of braking that should be applied. The two independent processors 202, 204 and/or processes 642, 648 each provide a braking command and the two independent commands are arbitrated by the peripheral braking controller 700 that is connected to receive both commands…. As an example, when a braking controller 700 receives a command from one processor, it may define a certain timing window (see FIG. 12) that it times (waits) to see if another processor provides a similar command before making an arbitration decision. Such a tolerance is built in in order to insure that the peripheral modules are responsive to commands issued by multiple independent processors. Such time windows in the range of 10-25 milliseconds may be acceptable to account for the only loose synchronization between the different processors 202, 204. However, the timing window should be short enough that the peripheral devices 700 can still detect a timeout. If a second message arrives after the timeout period, then the peripheral device 700 detects this with its plausibility check 702 and may ignore the second command or the first command. In some embodiments, the braking module 700 could provide feedback or notification back to controller 100 if the plausibility check indicates that one or the other of the independent control signals is the result of a fault.”).
Claim 3. Yousuf teaches the method of claim 1 and further teaches, further comprising: causing the vehicle to perform dynamic driving task (DDT) fallback ([0089]—teaches that the fallback performance and dynamic driving tasks at level 4 and 5 are system performed. Also, see fig. 2 and fig. 4).
Claim 4. Yousuf teaches the method of claim 3 and further teaches, wherein the causing the vehicle to perform DDT fallback comprises issuing a request to intervene to a fallback-ready user of the vehicle ([0089]—The driver is responsible for fallback performance and dynamic driving tasks at level 3. At levels 3 and 4, the driving mode circumstance, location capabilities are performed by the human driver in some driving. Also, see fig. 4).
Claim 5. Yousuf teaches the method of claim 1 and further teaches, further comprising: causing the vehicle to achieve a minimal risk condition ([0100]-[0105] and fig. 2 teaches various minimal risk conditions).
Claim 6. Yousuf teaches the method of claim 1 and further teaches, wherein the controlling the acceleration comprises:
determining, for each clock cycle of a system clock of the vehicle, a target acceleration based on at least the planned acceleration and the automotive sensor data ([0191]—“As an example, when a braking controller 700 receives a command from one processor, it may define a certain timing window (see FIG. 12) that it times (waits) to see if another processor provides a similar command before making an arbitration decision. Such a tolerance is built in in order to insure that the peripheral modules are responsive to commands issued by multiple independent processors. Such time windows in the range of 10-25 milliseconds may be acceptable to account for the only loose synchronization between the different processors 202, 204.”); and
translating the target acceleration into a brake torque and an engine torque ([0057]—“…controller 100 is essentially an onboard supercomputer that operates in real time to process sensor signals and output autonomous operation commands to self-drive vehicle 50 and/or assist the human vehicle driver in driving vehicle 50. Controller 100 operates vehicle brakes tip via one or more braking actuators 61, operates steering mechanism 58 via a steering actuator 62, and operates propulsion unit 56 which also receives an accelerator/throttle actuation signal 64. Controller 100 provides autonomous driving outputs in response to an array of sensor inputs including for example:”).
Claim 7. Yousuf teaches the method of claim 1 and further teaches, further comprising: receiving an override signal, the override signal causing the controlling of the acceleration to set a target acceleration of the control system to a value indicated by the override signal ([0057] describes this element as such—“Controller 100 operates vehicle brakes tip via one or more braking actuators 61, operates steering mechanism 58 via a steering actuator 62, and operates propulsion unit 56 which also receives an accelerator/throttle actuation signal 64. Controller 100 provides autonomous driving outputs in response to an array of sensor inputs”).
Claim 8. Yousuf teaches the method of claim 1 and further teaches, wherein the determining the safe acceleration state comprises determining one of the reduced deceleration and the reduced acceleration of the set of safe acceleration states based on the planned acceleration ([0057] describes this element as such—“Controller 100 operates vehicle brakes tip via one or more braking actuators 61, operates steering mechanism 58 via a steering actuator 62, and operates propulsion unit 56 which also receives an accelerator/throttle actuation signal 64. Controller 100 provides autonomous driving outputs in response to an array of sensor inputs”).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Yu, Jing, and Feng Luo. “Fallback strategy for level 4+ automated driving system.” 2019 IEEE Intelligent Transportation Systems Conference
(ITSC). IEEE, 2019. This reference teaches fallback strategies.
Kumavat et al., US 2023/0192139. This reference teaches a method for addressing failure: detecting and responding to failure and operating the vehicle.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANA D THOMAS whose telephone number is (571)272-8549. The examiner can normally be reached Monday - Friday 8 - 5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ramya Burgess can be reached at 571-272-6011. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/A.D.T/Examiner, Art Unit 3661
/RUSSELL FREJD/Primary Examiner, Art Unit 3661