Prosecution Insights
Last updated: October 01, 2026
Application No. 19/209,452

SYSTEMS AND METHODS FOR OVER-TIME EVENT MONITORING WITH ENHANCED RULES CONFLICT CHECKING WITH DATA VALIDATION

Final Rejection §103
Filed
May 15, 2025
Priority
Oct 23, 2020 — continuation of 12/326,851
Examiner
TOUGHIRY, ARYAN D
Art Unit
2165
Tech Center
2100 — Computer Architecture & Software
Assignee
State Farm Mutual Automobile Insurance Company
OA Round
2 (Final)
69%
Grant Probability
Favorable
3-4
OA Rounds
1y 10m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 69% — above average
69%
Career Allowance Rate
137 granted / 199 resolved
+13.8% vs TC avg
Strong +20% interview lift
Without
With
+19.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
20 currently pending
Career history
217
Total Applications
across all art units

Statute-Specific Performance

§101
0.6%
-39.4% vs TC avg
§103
71.2%
+31.2% vs TC avg
§102
16.5%
-23.5% vs TC avg
§112
6.9%
-33.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 199 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments filed 8/16/2026 have been fully considered Double Patenting: These issues have been not been resolved and the rejection has not been withdrawn in light of the amendments and arguments. 35 USC § 102 & 35 USC § 103: Regarding Applicant’s Argument (pages 11-13): Examiner’s response:- Applicant’s arguments with respect to the rejection(s) of under 35 USC § 102/103 have been fully considered, upon further consideration a new ground(s) of rejection is made in view of US 20210192073 A1; GOODSITT; Jeremy Edward et al. (hereinafter Goodsitt). Double Patenting Claims 1-20 are non-provisionally rejected on the ground of obviousness-type nonstatutory double patenting as being unpatentable over claims 1-32 of US Patent No 12326851. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the copending application disclose the function and structure of the claims of the instant application to those having ordinary skill in the art. 6/22/2026 – 19209452 – claim 1 12/05/2024 – 12326851 – claim 1 A computer system for performing over-time event monitoring, the computer system including at least one processor in communication with at least one memory device, wherein the at least one processor is programmed to: scan a plurality of data messages transmitted over a computer network for one or more indicators of a first event, the one or more indicators including at least one of a message type, a destination system, a source system, or one or more payload fields of the plurality of data messages; based upon identifying the one or more indicators of the first event, further scan the plurality of data messages for a subset of data messages from the plurality of data messages associated with the first event to determine whether the first event is complete; identify a first data message, a second data message, and a third data message from the plurality of data messages as including an identifier being associated with the first event, the first data message, the second data message, and the third data message being associated with first time data, second time data, and third time data respectively; determine that the second time data and the first time data indicate that the second data message was transmitted within a first predefined period of time from when the first data message was transmitted; determine that the third time data and the second time data indicate that the third data message was transmitted within a second predefined period of time from when the second data message was transmitted; and based upon the first predefined period of time and the second predefined period of time being satisfied, mark the first event as being complete in the at least one memory device. A computer system for performing over-time event monitoring, the computer system including at least one processor in communication with at least one memory device, wherein the at least one processor is programmed to: scan a plurality of data messages previously transmitted over a computer network for one or more indicators of a first event, the one or more indicators including at least one of a message type, a destination system, a source system, or one or more payload fields of the plurality of data messages; detect a first data message in the plurality of data messages, wherein the first data message is associated with the first event comprising a series of data messages including the first data message associated with first time data indicating when the first data message was transmitted, a second data message associated with second time data indicating when the second data message was transmitted, and a third data message associated with third time data indicating when the third data message was transmitted, wherein the first data message indicates a start of the first event and the series of data messages, wherein the second data message indicates an end of the first event and the series of data messages, wherein the third data message is to be transmitted between the transmission of the first data message and the second data message, wherein the second data message is to be transmitted over the computer network within a predetermined period of time after the transmission of the first data message, wherein the first data message, the second data message, and the third data message include an identifier to indicate that they are associated with the first event, and wherein the first data message, the second data message, and the third data message are different; scan the plurality of data messages for the second data message and the third data message transmitted over the computer network subsequent to the first data message associated with the first event, wherein the second data message and the third date data message include an identifier to indicate that they are associated with the first event; determine whether the first time data and the second time data are in compliance with the predetermined period of time; when the first time data and the second time data are in compliance with the predetermined period of time, mark the first event as being complete in the at least one memory device; and when the first time data or the second time data are not in compliance with the predetermined period of time, transmit an error message to a user computer device. Corresponding product claim 9 is rejected similarly as claim 1 above. Corresponding method claim 17 is rejected similarly as claim 1 above. 5/15/2025 – 19209452 – claim 2 12/05/2024 – 12326851 – claim 1 The computer system of Claim 1, wherein the at least one processor is further programmed to:determine that the first data message, the second data message, and the third data message were all transmitted within a threshold period of time associated with a deadline; and markthe first event as being complete further based upon the deadline being satisfied. A computer system for performing over-time event monitoring, the computer system including at least one processor in communication with at least one memory device, wherein the at least one processor is programmed to: scan a plurality of data messages previously transmitted over a computer network for one or more indicators of a first event, the one or more indicators including at least one of a message type, a destination system, a source system, or one or more payload fields of the plurality of data messages; detect a first data message in the plurality of data messages, wherein the first data message is associated with the first event comprising a series of data messages including the first data message associated with first time data indicating when the first data message was transmitted, a second data message associated with second time data indicating when the second data message was transmitted, and a third data message associated with third time data indicating when the third data message was transmitted, wherein the first data message indicates a start of the first event and the series of data messages, wherein the second data message indicates an end of the first event and the series of data messages, wherein the third data message is to be transmitted between the transmission of the first data message and the second data message, wherein the second data message is to be transmitted over the computer network within a predetermined period of time after the transmission of the first data message, wherein the first data message, the second data message, and the third data message include an identifier to indicate that they are associated with the first event, and wherein the first data message, the second data message, and the third data message are different; scan the plurality of data messages for the second data message and the third data message transmitted over the computer network subsequent to the first data message associated with the first event, wherein the second data message and the third date data message include an identifier to indicate that they are associated with the first event; determine whether the first time data and the second time data are in compliance with the predetermined period of time; when the first time data and the second time data are in compliance with the predetermined period of time, mark the first event as being complete in the at least one memory device; and when the first time data or the second time data are not in compliance with the predetermined period of time, transmit an error message to a user computer device. Corresponding product claim 10 is rejected similarly as claim 2 above. Corresponding method claim 18 is rejected similarly as claim 2 above. 5/15/2025 – 19209452 – claim 3 12/05/2024 – 12326851 – claim 11 The computer system of Claim 1, wherein the at least one processor is further programmed to: identify the first data message and the second data message before identifying the third data message; determine that a deadline period of time associated with the first event is within a threshold amount of time from a current time and that the third data message has not yet been transmitted; and transmit an alert to a user computing device, the alert associated with the deadline period of time, the user computing device associated with the first event. The computer system in accordance with Claim 10, wherein if the current duration of the first event is within a predetermined amount of time from the maximum duration of the first event, transmit a reminder notification to complete the first event to the user computer device Corresponding product claim 11 is rejected similarly as claim 3 above. 5/15/2025 – 19209452 – claim 4 12/05/2024 – 12326851 – claim 31 The computer system of Claim 3, wherein the at least oneprocessor is further programmed to identify the third data message after transmitting the alert. The method in accordance with Claim 17 further comprising: detecting a fourth data message in the plurality of data messages, wherein the fourth data message is associated with a second event that includes the fourth data message and a fifth data message; and scanning the plurality of data messages for the fifth data message associated with the second event. Corresponding product claim 12 is rejected similarly as claim 4 above. Corresponding method claim 19 is rejected similarly as claim 4 above. 5/15/2025 – 19209452 – claim 5 12/05/2024 – 12326851 – claim 6 The computer system of Claim 1, wherein the first data message is associated with a start of the first event and the third data message is associated with an end of the first event. The computer system in accordance with Claim 1, wherein the first event includes a maximum duration corresponding to the predetermined period of time, wherein a current duration of the first event is based upon a time when the first data message was transmitted and a current time, and wherein the first event has expired when the current duration exceeds the maximum duration. Corresponding product claim 13 is rejected similarly as claim 5 above. 5/15/2025 – 19209452 – claim 6 12/05/2024 – 12326851 – claim 5 The computer system of Claim 5, wherein the at least one processor is further programmed to: identify the first data message before identifying the second data message and the third data message; The computer system in accordance with The computer system in accordance with wherein if the one or more additional data messages are detected by the scan, the at least one processor is further programmed to indicate that the first event is complete. Corresponding product claim 14 is rejected similarly as claim 6 above. 5/15/2025 – 19209452 – claim 7 12/05/2024 – 12326851 – claim 11 The computer system of Claim 1, wherein the at least one processor is further programmed to: identify the first data message before identifying the second data message and the third data message; determine that at least one of the second data message or the third data message have not been transmitted and a threshold amount of time remaining before a deadline associated with the first event has passed; and transmit a reminder notification to a user computing device associated with the first event, the reminder notification associated with the at least one of the second data message or the third data message The computer system in accordance with Claim 10, wherein if the current duration of the first event is within a predetermined amount of time from the maximum duration of the first event, transmit a reminder notification to complete the first event to the user computer device Corresponding product claim 15 is rejected similarly as claim 7 above. Corresponding method claim 20 is rejected similarly as claim 7 above. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1,2,5,6,9,10,13, and 14 are rejected under 35 U.S.C. 103 as being unpatentable over US 20210144026 A1; STEIN; Yehiel et al. (hereinafter Stein) in view of US 20110173354 A1; Hall; Kenwood H. et al. (hereinafter Hall) and US 20210192073 A1; GOODSITT; Jeremy Edward et al. (hereinafter Goodsit) Regarding claim 1, Stein teaches A computer system for performing over-time event monitoring, the computer system including at least one processor in communication with at least one memory device, wherein the at least one processor is programmed to: scan a plurality of data messages transmitted over a computer network for one or more indicators of a first event (Stein [0014] Code instructions to receive a plurality of messages intercepted by one or more devices adapted to monitor messages[0015] Code instructions to apply a plurality of trained machine learning models to evaluate a compliance of each of the plurality of intercepted messages with one or more of a plurality of baseline models according to one or more of a plurality of features identified for each intercepted message. The baseline models defining a plurality of learned message patterns is created by training the plurality of machine learning models with a plurality of training datasets comprising a plurality of training messages reflecting valid operation of the vehicle. [0016] Code instructions to identify one or more incompliant intercepted messages which are incompliant with one or more of the baseline model, the incompliant intercepted message(s) is transmitted as result of one or more abnormal events. [0017] Code instructions to generate an alert indicative of the one or more abnormal events [0048] identifying one or more abnormal events (operational anomalies) during operation of a vehicle, specifically a ground vehicle, for example, a car, a truck, a motorcycle, a train and/or the like. Identifying the abnormal events is done by intercepting a plurality of messages[0094] In order to be able to correlate the intercepted messages with time and/or space attributes, the monitoring device(s) 320 may assign metadata to one or more of the intercepted messages which may be naturally be intercepted at different communication channels 302 at different times. The metadata assigned to the intercepted message(s) may include, for example, a time tag indicating a time of interception of the respective message, a source communication channel 302 where the respective message is intercepted and/or the like. The metadata assigned to the intercepted messages may be used to correlate messages intercepted at various times and/or locations (communication channels 302) to create one or more time continuum and/or space continuum meta-events. [85-94] elaborate on the matter [FIG.2] shows overall visual) the one or more indicators including at least one of a message type, a destination system, a source system, or one or more payload fields of the plurality of data messages; (Stein [0022] the plurality of features comprising one or more members of a group consisting of: a message type, a message identifier, a message rate, a message timing, a sequence of messages in the subset, a message size, a message content, a correlation between one or more of the messages and one or more previously intercepted messages. Applying the machine learning algorithms to a wide variety of message features may significantly improve the ability of the machine learning algorithms to detect and learn message patterns and hence to detect the incompliant messages and abnormal event(s).[0030] In an optional implementation form of the first and/or second aspects, one or more subsets of the plurality of messages are arranged in one or more unified time ordered datasets created according to one or more message arrangement rules defining consolidation of the one or more subsets according to one or more message attributes, the message attributes [1014] transmit the intercepted messages to the analysis server 230 via the network 240 may compress the message ID, the payload and/or the metadata of one or more of the intercepted messages [0115]... based on one or more message attributes, for example, an originating device such as the device 310, a destination device 310, a message type, a message identifier, a message size, a message (payload) content, a message timing, a type of communication channel 302, an identifier of the communication channel 302, an identifier of the segment and/or the like.[149] further elaborates on the matter ) identify a first data message, a second data message, and a third data message from the plurality of data messages as including an identifier associated with the first event, (Stein [0022] In a further implementation form of the first and/or second aspects, the plurality of features comprising one or more members of a group consisting of: a message type, a message identifier, a message rate, a message timing, a sequence of messages in the subset, a message size, a message content, a correlation between one or more of the messages and one or more previously intercepted messages. [0114] The message arrangement rules may also dictate grouping together multiple messages to create unified time ordered datasets based on both time and space attributes. For example, a certain message arrangement rule may dictate grouping together multiple messages intercepted at a certain communication channel 302 within a certain time period, for example, 3 seconds and/or the like. Based on the arrangement rules, a respective unified time ordered dataset may therefore include one or more messages having one or more instances two each intercepted at a different location (channel/segment) at a different time assigned and having a respective time tag[0094] In order to be able to correlate the intercepted messages with time and/or space attributes, the monitoring device(s) 320 may assign metadata to one or more of the intercepted messages which may be naturally be intercepted at different communication channels 302 at different times. The metadata assigned to the intercepted message(s) may include, for example, a time tag indicating a time of interception of the respective message, a source communication channel 302 where the respective message is intercepted and/or the like. The metadata assigned to the intercepted messages may be used to correlate messages intercepted at various times and/or locations [112-116] elaborates on the matter) the first data message, the second data message, and the third data message being associated with first time data, second time data, and third time data respectively; (Stein [0031] a compliance of the one or more unified time ordered datasets with one or more of the baseline models according to one or more of: a correlation between the one or more unified time ordered datasets and one or more other unified time ordered datasets and one or more of the plurality of features identified for at least some of the messages of the one or more unified time ordered datasets. Providing the additional context information to the machine learning algorithms may further improve the ability of the machine learning algorithms to detect the incompliant intercepted message(s). [0094] the intercepted messages with time and/or space attributes, the monitoring device(s) 320 may assign metadata to one or more of the intercepted messages which may be naturally be intercepted at different communication channels 302 at different times. The metadata assigned to the intercepted message(s) may include, for example, a time tag indicating a time of interception of the respective message, a source communication channel 302 where the respective message is intercepted and/or the like. The metadata assigned to the intercepted messages may be used to correlate messages intercepted at various times and/or locations (communication channels 302) to create one or more time continuum and/or space continuum meta-events. [0099] The mechanisms applied to reduce the message data include, for example: [0100] Transmitting a relative timestamp for one or more of the intercepted messages. An absolute (real) timestamp may be periodically assigned to an intercepted message every predefined period [114-123] elaborate on the matter [FIG.2] shows visual) determine that the second time data and the first time data indicate that the second data message was transmitted within a first predefined period of time from when the first data message was transmitted; determine that the third time data and the second time data indicate that the third data message was transmitted within a second predefined period of time from when the second data message was transmitted; (Stein [0023] valid operation of the vehicle where each of the message transmission patterns is well defined (expressed) by predefined message features' values and/or patterns for the messages and/or of the unified time ordered datasets. [0053] grouping together multiple messages intercepted at a certain communication channel segment during a certain time period [0100] Transmitting a relative timestamp for one or more of the intercepted messages. An absolute (real) timestamp may be periodically assigned to an intercepted message every predefined period (e.g. every minute) and each following message may be assigned with a relative offset counter. This may significantly reduce the data volume of the time stamps [129] The parametric supervised algorithms may define a clear baseline of the valid, legitimate and/or allowed message transmission patterns expressed by the predefined values and/or features of the messages and/or of the unified time ordered datasets which in turn reflect valid operation and/or behavior of the vehicle 202. The non-parametric semi-supervised algorithms may expand the baseline model to include predefined message transmission patterns which are defined (expressed) by the learned values and/or features of the messages and/or of the unified time ordered datasets. [149] payload values of the speed messages and the throttle messages intercepted in real time in the operational environment of the vehicle 202 within a predefined time interval (e.g. 100 ms) are inconsistent with each other, the message analyzer 220 may be unable to classify this message sequence (transmission pattern) in the baseline model and may therefore determine the message sequence is incompliant with the baseline model. The message analyzer 220 may therefore determine that such incompliant message sequence (pattern) resulted from one or more abnormal events taking place in the operational environment of the vehicle 202.[116-125] elaborate on the matter) Stein lacks explicitly and orderly teaching and based upon the first predefined period of time and the second predefined period of time being satisfied, mark the first event as being complete in the at least one memory device. However Hall teaches based upon the first predefined period of time and the second predefined period of time being satisfied, mark the first event as being complete in the at least one memory device. (Hall [0035] At step 102, the state machine 42 processes each of the connection timers 130 in the timer array 128. Referring to FIG. 6, each timer 130 includes registers for storing at least an accumulated value 132, a preset value 134 and status 136. The accumulated value 132 identifies the current execution time for the timer 130 and is preferably an integral number that is either decremented from the preset value 134 to zero or incremented from zero to the preset value 134. The preset value 134 is determined by the length of time the timer is to run divided by the periodic rate at which the timer is decremented or incremented. The status register 136 includes one or more status flags indicating, for example, that the timer is done, the timer is waiting to be loaded into the event buffer, or the timer has reached a minimum set point.[0040] Referring again to FIG. 5, as the timer data is retrieved from the timer array 128, the status for each timer 130 is checked at step 110. Checking the status of each timer 130 includes comparing the accumulated value 132 to determine whether the timer has expired. If the timer 130 has expired, the state machine 42 sets the done flag in the status register 136 and resets the accumulated value 132 so that the timer can begin counting again at the next cycle. If the timer 130 has not expired, then the state machine 42 will update the accumulated value according to step 112.In step 142, the appropriate resolution timer done flag is checked. The state machine 42 determines whether the done flag of the proper resolution timer is set in step 144 to determine if the accumulated value 132 needs to be updated. The accumulated value 132 is updated, if required, at step 146. It is contemplated that any suitable set of resolution timers may be implemented. Preferably, the resolution timers exist to permit a range of RPI values for the timers 130 to be set from about 10 .mu.s to at least 10 seconds [0042-44] elaborate on the matter [FIG.5] shows corresponding visual) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to take all prior methods and make the addition of Hall in order create an efficient way to process and label data within a specific period of time (Hall [0004] In order to ensure predictable control of the process, the communication between the controller and the inputs and outputs must be highly reliable and performed at well-defined periods. The controller must also verify that the input and output (I/O) devices connected to the controller continue operating properly.[0041] Referring to FIG. 7, each accumulated value 132 is updated according to the resolution selected for that timer 130. In order to reduce the required memory allocation for each timer 130, a series of resolution timers may be executing such that the accumulated value is only updated on scans when the designated resolution timer is done. For example, resolution timers may be assigned a preset value of ten or one hundred. The resolution timer is continuously executed such that the resolution timer done flag is set every tenth or one hundredth cycle. Each timer 130 can be configured to be updated each scan or, optionally, only when the appropriate resolution timer done flag is set) the combination lack explicitly and orderly teaching based upon identifying the one or more indicators of the first event, further scan the plurality of data messages for a subset of data messages from the plurality of data messages associated with the first event to determine whether the first event is complete; However Goodsitt teaches based upon identifying the one or more indicators of the first event, further scan the plurality of data messages for a subset of data messages from the plurality of data messages associated with the first event to determine whether the first event is complete; (Goodsitt [0005] an identity information of the recipient, and where the at least one decryption mechanism is configured to decrypt, based on a scanning operation at the device of the recipient, two or more distinct scannable encryption mechanisms associated with two or more portions of a sender message, and where each of the two or more scannable encryption mechanisms are located on a surface of a portion of a physical mailing associated with a postal service, and where the surface of the portion of the physical mailing has both the two or more scannable encryption mechanisms and an unencrypted message portion, receive a first confirmation message once the decryption of one of the two or more portions of the sender message is complete, and receive a second confirmation message once the decryption of another one of the two or more portions of the sender message is complete. [0038] At block 240, one or more embodiments of the logic flow 200 may include at least one component as described in the present disclosure sending a second confirmation message to the at least one device associated with the sender once a decryption of another one of the two or more portions of the sender message is complete. In various embodiments, the confirmation can be sent from the mobile device to the server at any time after the second message portion has been decrypted. In various embodiments, an affirmative act on the mobile device can be required of the user to confirm that he or she has reviewed the second message segment. In various embodiments, review of the second message segment can be required before other message segments are decryptable, e.g. when dealing with a (second) sensitive term of a terms of service, that terms may have to be reviewed and confirmed reviewed first before proceeding to additional terms, even if the decryption mechanism or mechanisms otherwise permit decryption of subsequent message segments. [FIG.1] shows visual for based upon identifying the one or more indicators of the first event, further scan the plurality of data messages for a subset of data messages from the plurality of data messages associated with the first event to determine whether the first event is complete) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to take all prior methods and make the addition of Goodsitt's validation methods in order to efficiently create a more secure system (Goodsitt [0001] The present embodiments relate to increasing the security associated with deliverable items, packages, and/or products, and more particularly to enhancing the security associated with deliverable mail.[0003] Accordingly, there is a need to improve the security associated with the delivery of items, products, and/or packages.[0005] Another aspect of the present disclosure includes an apparatus configured to encode, decode and/or facilitate physical delivery of a message. The apparatus includes: a processor circuit, and a memory storing instructions which when executed by the processor circuit, cause the processor circuit to: transmit to a device of a recipient at least one decryption mechanism, where the at least one decryption mechanism is based at least in part on an identity information of the recipient, and where the at least one decryption mechanism is configured to decrypt, based on a scanning operation at the device of the recipient, two or more distinct scannable encryption mechanisms associated with two or more portions of a sender message, and where each of the two or more scannable encryption mechanisms are located on a surface of a portion of a physical mailing associated with a postal service, and where the surface of the portion of the physical mailing has both the two or more scannable encryption mechanisms and an unencrypted message portion, receive a first confirmation message once the decryption of one of the two or more portions of the sender message is complete, and receive a second confirmation message once the decryption of another one of the two or more portions of the sender message is complete.) Therefore Corresponding product claim 9 is rejected similarly as claim 1 above. Additional Limitations: computer readable medium capable of reading and executing instructions (Stein [FIG.2] shows corresponding visual with computer readable medium capable of reading and executing instructions[0064] As will be appreciated by one skilled in the art, aspects of the present invention may be embodied as a system, method or computer program product. Accordingly, aspects of the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a “circuit,” “module” or “system.” Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer readable medium(s) having computer readable program code embodied thereon.) Corresponding method claim 17 is rejected similarly as claim 1 above. Regarding claim 2, Stein, Hall and Goodsitt teach The computer system of Claim 1, wherein the at least one processor is further programmed to: determine that the first data message, the second data message, and the third data message were all transmitted within a threshold period of time associated with a deadline; and mark the first event as being complete further based upon the deadline being satisfied. (Hall [0035] At step 102, the state machine 42 processes each of the connection timers 130 in the timer array 128. Referring to FIG. 6, each timer 130 includes registers for storing at least an accumulated value 132, a preset value 134 and status 136. The accumulated value 132 identifies the current execution time for the timer 130 and is preferably an integral number that is either decremented from the preset value 134 to zero or incremented from zero to the preset value 134. The preset value 134 is determined by the length of time the timer is to run divided by the periodic rate at which the timer is decremented or incremented. The status register 136 includes one or more status flags indicating, for example, that the timer is done, the timer is waiting to be loaded into the event buffer, or the timer has reached a minimum set point.[0040] Referring again to FIG. 5, as the timer data is retrieved from the timer array 128, the status for each timer 130 is checked at step 110. Checking the status of each timer 130 includes comparing the accumulated value 132 to determine whether the timer has expired. If the timer 130 has expired, the state machine 42 sets the done flag in the status register 136 and resets the accumulated value 132 so that the timer can begin counting again at the next cycle. If the timer 130 has not expired, then the state machine 42 will update the accumulated value according to step 112.In step 142, the appropriate resolution timer done flag is checked. The state machine 42 determines whether the done flag of the proper resolution timer is set in step 144 to determine if the accumulated value 132 needs to be updated. The accumulated value 132 is updated, if required, at step 146. It is contemplated that any suitable set of resolution timers may be implemented. Preferably, the resolution timers exist to permit a range of RPI values for the timers 130 to be set from about 10 .mu.s to at least 10 seconds [0042-44] elaborate on the matter [FIG.5] shows corresponding visual) Corresponding product claim 10 is rejected similarly as claim 2 above. Corresponding method claim 18 is rejected similarly as claim 2 above. Regarding claim 5, Stein, Hall and Goodsitt teach The computer system of Claim 1, wherein the first data message is associated with a start of the first event and the third data message is associated with an end of the first event. (Stein [0072] events during operation of a vehicle, specifically a ground vehicle by applying trained machine learning models to trained to identify one or more messages exchanged over communication channels of the vehicle...messages transmission patterns reflecting valid, legitimate and/or normal operation of the vehicle including, for example, operation states of the vehicle and/or transitions between the states.[0130] According to some embodiments of the present invention, the message analyzer 220 may apply the machine learning models in a phased (sequenced) processing pipeline to create the baseline model. The message analyzer 220 may break down the intercepted messages to multiple processing stages thus creating a pipelined representation of the baseline model defining valid message transmission patterns reflecting valid operation and behavior of the vehicle 202. [0140] FIG. 8, which is a schematic illustration of an exemplary state machine describing state transition between messages clusters identified by applying machine learning models to messages intercepted in a vehicular environment, according to some embodiments of the present invention. A state machine 800 which may be a segment of the baseline model presents an exemplary state transition probability distribution for transitions between clusters of messages identified by a set of machine learning models, for example, the first set of machine learning models. The state machine 800 may be created by the message analyzer 220 applying the temporal scaling to clusters such as the clusters 510_6, 510_7, 510_8 and 510_9. As seen from the state machine 800 transitions are identified during the training phase between some of the clusters 510, for example, a transition from the cluster 510_6 to the cluster 510_8, a transition from the cluster 510_6 to the cluster 510_9, a transition from the cluster 510_8 to the cluster 510_6 [126-132] elaborate on the matter [FIG. 2 in conjunction with FIG.3] shows corresponding visual) Corresponding product claim 13 is rejected similarly as claim 5 above. Regarding claim 6, Stein, Hall and Goodsitt teach The computer system of Claim 5, wherein the at least one processor is further programmed to: identify the first data message before identifying the second data message and the third data message (Stein [FIG. 2 in conjunction with FIG.3] shows identify the first data message before identifying the second data message and the third data message; and based upon identifying the first data message, further scan the plurality of data messages for the second data message and the third data message [0086] Reference is now made to FIG. 3, which is a schematic illustration of an exemplary system for intercepting communication messages exchanged over communication channels of a vehicle, according to some embodiments of the present invention. An exemplary system 300 may be deployed in a vehicle such as the vehicle 202 for intercepting messages exchanged between a plurality of devices 310 deployed in the vehicle 202 for collecting data [0094] correlate the intercepted messages with time and/or space attributes, the monitoring device(s) 320 may assign metadata to one or more of the intercepted messages which may be naturally be intercepted at different communication channels 302 at different times. The metadata assigned to the intercepted message(s) may include, for example, a time tag indicating a time of interception of the respective message, a source communication channel 302 where the respective message is intercepted and/or the like. The metadata assigned to the intercepted messages may be used to correlate messages intercepted at various times and/or locations (communication channels 302) to create one or more time continuum and/or space continuum meta-events. The meta-event(s) may be arranged as one or more unified time ordered datasets reflecting typical patterns and behavior of communication traffic (message transmission) over the communications channel(s) 302 of the vehicle 202. [112-115] elaborate on the matter) Corresponding product claim 14 is rejected similarly as claim 6 above. Claims 3,4,7,8,11,12,15,16 and 20 are rejected under 35 U.S.C. 103 as being Stein in view Hall, and Goodsitt and US 20210192065 A1; Cuka; David Aloysius et al. (hereinafter Cuka). Regarding claim 3, Stein, Hall and Goodsitt teach The computer system of Claim 1, wherein the at least one processor is further programmed to: identify the first data message and the second data message before identifying the third data message; (Stein [0043] FIG. 5 is a schematic illustration of exemplary message clusters created by applying machine learning models to messages intercepted[0044] FIG. 6 is a graph chart of an exemplary 2 dimensional space distribution of messages clusters created by applying machine learning models to messages intercepted in a vehicular environment [0051] time ordered messages dataset are arranged according to a timing of transmission (and interception) of each of the messages thus consolidating groups of the plurality of messages in a time continuum. For example, a certain message arrangement rule may dictate grouping together multiple messages intercepted within a certain time period [0058] Some existing methods may apply rule based methods and/or systems to detect the abnormal event(s) by comparing transmission of the intercepted messages to predefined rules and identifying incompliance with the rules. Such rule based implementations may require identifying in advance most if not all possible valid, legitimate and/or normal operation modes or states of the vehicle. Such rule based methods may further attempt to predict potential abnormal events and define the respective message transmission rules. [0082] In case the process 100 is executed by the remote analysis server 230, the processor(s) 214 may execute a message collector module 222 for collecting intercepted messages exchanged over one or more communication channels of the vehicle 202. The message collector 222 may further transmit the intercepted messages[93-99] elaborate on the matter [FIG.2 in conjunction with FIG.3] shows corresponding visual) the combination lack explicitly and orderly teaching determine that a deadline period of time associated with the first event is within a threshold amount of time from a current time and that the third data message has not yet been transmitted;and transmit an alert to a user computing device, the alert associated with the deadline period of time, the user computing device associated with the first event. However Cuka teaches determine that a deadline period of time associated with the first event is within a threshold amount of time from a current time and that the third data message has not yet been transmitted; and transmit an alert to a user computing device, the alert associated with the deadline period of time, the user computing device associated with the first event. (Cuka [0016] the at least one processing device is further configured to: determine that at least the portion of the one or more applications are not eligible for being accessed using the one or more hardware devices based on at least the one or more user profiles and the one or more open source code rules; and transmit a notification to the one or more user profiles currently having access to at least the portion of the one or more applications, wherein the notification comprises a tracking ticket and a target time limit, wherein the tracking ticket is configured to track one or more actions performed on at least the portion of the one or more applications by the one or more user profiles, wherein the target time limit comprises a predetermined time limit within which the one or more user profiles are required to remove at least the portion of the one or more applications from the one or more hardware devices. [0070] the system may be configured to transmit a notification to the one or more user profiles currently having access to at least the portion of the one or more applications, wherein the notification comprises a tracking ticket and a target time limit. In one aspect, the tracking ticket is configured to track one or more actions performed on at least the portion of the one or more applications by the one or more user profiles, and the target time limit may include a predetermined time limit within which the one or more user profiles are required to remove at least the portion of the one or more applications from the one or more hardware devices [FIG.1] shows overall visual of the system which can perform corresponding limitations) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to take all prior methods and make the addition of the Cuka in order to create a efficient methods distribute notifications and data in a system (Cuka [0035] In this regard, the system may dynamically utilize the volatile memory over the non-volatile memory by storing multiple pieces of information in the volatile memory, thereby reducing the load on the system and increasing the processing speed [0054] IT governance can be defined as a set of processes to effectively manage all IT resources, functions, and processes which support the overall IT strategy of the entity. An enforceable program of IT governance is key to gaining more value from open source and protecting the overall interests of the entity. With the level of customizability, freedom, and flexibility provided by free open source software (FOSS), entities are increasingly adopting FOSS to be integrated with proprietary and third party source code to create a robust technology environment. Understanding and targeting open source issues within the technology environment of the entity is the first of many steps in developing and implementing a FOSS governance system.[0055] large entities with expansive technology platform require a more efficient and seamless FOSS governance system that not only determines whether a FOSS is approved/disapproved, but also has the ability to initiate the execution of an action based on the decision-making process. The present invention not only provides a scalable option of scanning for FOSS across the entire technology platform of the entity, but also provides an automated solution for enforcing FOSS governance on devices across the technology platform.) Corresponding product claim 11 is rejected similarly as claim 3 above. Regarding claim 4, Stein, Hall, Goodsitt and Cuka teach The computer system of Claim 3, wherein the at least one processor is further programmed to identify the third data message after transmitting the alert. (Stein [0043] FIG. 5 is a schematic illustration of exemplary message clusters created by applying machine learning models to messages intercepted[0044] FIG. 6 is a graph chart of an exemplary 2 dimensional space distribution of messages clusters created by applying machine learning models to messages intercepted in a vehicular environment [0051] time ordered messages dataset are arranged according to a timing of transmission (and interception) of each of the messages thus consolidating groups of the plurality of messages in a time continuum. For example, a certain message arrangement rule may dictate grouping together multiple messages intercepted within a certain time period [0058] Some existing methods may apply rule based methods and/or systems to detect the abnormal event(s) by comparing transmission of the intercepted messages to predefined rules and identifying incompliance with the rules. Such rule based implementations may require identifying in advance most if not all possible valid, legitimate and/or normal operation modes or states of the vehicle. Such rule based methods may further attempt to predict potential abnormal events and define the respective message transmission rules. [0082] In case the process 100 is executed by the remote analysis server 230, the processor(s) 214 may execute a message collector module 222 for collecting intercepted messages exchanged over one or more communication channels of the vehicle 202. The message collector 222 may further transmit the intercepted messages[93-99] elaborate on the matter [FIG.2 in conjunction with FIG.3] shows corresponding visual) Corresponding product claim 12 is rejected similarly as claim 4 above Corresponding method claim 19 is rejected similarly as claim 4 above Regarding claim 7, Stein, Goodsitt and Hall teach The computer system of Claim 1, wherein the at least one processor is further programmed to: identify the first data message before identifying the second data message and the third data message; (Stein [FIG. 2 in conjunction with FIG.3] shows identify the first data message before identifying the second data message and the third data message; and based upon identifying the first data message, further scan the plurality of data messages for the second data message and the third data message [0086] Reference is now made to FIG. 3, which is a schematic illustration of an exemplary system for intercepting communication messages exchanged over communication channels of a vehicle, according to some embodiments of the present invention. An exemplary system 300 may be deployed in a vehicle such as the vehicle 202 for intercepting messages exchanged between a plurality of devices 310 deployed in the vehicle 202 for collecting data [0094] correlate the intercepted messages with time and/or space attributes, the monitoring device(s) 320 may assign metadata to one or more of the intercepted messages which may be naturally be intercepted at different communication channels 302 at different times. The metadata assigned to the intercepted message(s) may include, for example, a time tag indicating a time of interception of the respective message, a source communication channel 302 where the respective message is intercepted and/or the like. The metadata assigned to the intercepted messages may be used to correlate messages intercepted at various times and/or locations (communication channels 302) to create one or more time continuum and/or space continuum meta-events. The meta-event(s) may be arranged as one or more unified time ordered datasets reflecting typical patterns and behavior of communication traffic (message transmission) over the communications channel(s) 302 of the vehicle 202. [112-115] elaborate on the matter) the combination lack explicitly and orderly teaching determine that at least one of the second data message or the third data message have not been transmitted and a threshold amount of time remaining before a deadline associated with the first event has passed; and transmit a reminder notification to a user computing device associated with the first event, the reminder notification associated with the at least one of the second data message or the third data message. However Cuka teaches determine that at least one of the second data message or the third data message have not been transmitted and a threshold amount of time remaining before a deadline associated with the first event has passed; and transmit a reminder notification to a user computing device associated with the first event, the reminder notification associated with the at least one of the second data message or the third data message. (Cuka [0016] the at least one processing device is further configured to: determine that at least the portion of the one or more applications are not eligible for being accessed using the one or more hardware devices based on at least the one or more user profiles and the one or more open source code rules; and transmit a notification to the one or more user profiles currently having access to at least the portion of the one or more applications, wherein the notification comprises a tracking ticket and a target time limit, wherein the tracking ticket is configured to track one or more actions performed on at least the portion of the one or more applications by the one or more user profiles, wherein the target time limit comprises a predetermined time limit within which the one or more user profiles are required to remove at least the portion of the one or more applications from the one or more hardware devices. [0070] the system may be configured to transmit a notification to the one or more user profiles currently having access to at least the portion of the one or more applications, wherein the notification comprises a tracking ticket and a target time limit. In one aspect, the tracking ticket is configured to track one or more actions performed on at least the portion of the one or more applications by the one or more user profiles, and the target time limit may include a predetermined time limit within which the one or more user profiles are required to remove at least the portion of the one or more applications from the one or more hardware devices [FIG.1] shows overall visual of the system which can perform corresponding limitations) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to take all prior methods and make the addition of the Cuka in order to create an efficient method to distribute notifications and data in a system (Cuka [0035] In this regard, the system may dynamically utilize the volatile memory over the non-volatile memory by storing multiple pieces of information in the volatile memory, thereby reducing the load on the system and increasing the processing speed [0054] IT governance can be defined as a set of processes to effectively manage all IT resources, functions, and processes which support the overall IT strategy of the entity. An enforceable program of IT governance is key to gaining more value from open source and protecting the overall interests of the entity. With the level of customizability, freedom, and flexibility provided by free open source software (FOSS), entities are increasingly adopting FOSS to be integrated with proprietary and third party source code to create a robust technology environment. Understanding and targeting open source issues within the technology environment of the entity is the first of many steps in developing and implementing a FOSS governance system.[0055] large entities with expansive technology platform require a more efficient and seamless FOSS governance system that not only determines whether a FOSS is approved/disapproved, but also has the ability to initiate the execution of an action based on the decision-making process. The present invention not only provides a scalable option of scanning for FOSS across the entire technology platform of the entity, but also provides an automated solution for enforcing FOSS governance on devices across the technology platform.) Corresponding product claim 15 is rejected similarly as claim 7 above. Corresponding method claim 20 is rejected similarly as claim 7 above. Regarding claim 8, Stein, Hall, Goodsitt and Cuka teach The computer system of Claim 7, wherein the reminder notification includes instructions to transmit the at least one of the second data message or the third data message. (Stein [0043] FIG. 5 is a schematic illustration of exemplary message clusters created by applying machine learning models to messages intercepted[0044] FIG. 6 is a graph chart of an exemplary 2 dimensional space distribution of messages clusters created by applying machine learning models to messages intercepted in a vehicular environment [0051] time ordered messages dataset are arranged according to a timing of transmission (and interception) of each of the messages thus consolidating groups of the plurality of messages in a time continuum. For example, a certain message arrangement rule may dictate grouping together multiple messages intercepted within a certain time period [0058] Some existing methods may apply rule based methods and/or systems to detect the abnormal event(s) by comparing transmission of the intercepted messages to predefined rules and identifying incompliance with the rules. Such rule based implementations may require identifying in advance most if not all possible valid, legitimate and/or normal operation modes or states of the vehicle. Such rule based methods may further attempt to predict potential abnormal events and define the respective message transmission rules. [0082] In case the process 100 is executed by the remote analysis server 230, the processor(s) 214 may execute a message collector module 222 for collecting intercepted messages exchanged over one or more communication channels of the vehicle 202. The message collector 222 may further transmit the intercepted messages[93-99] elaborate on the matter [FIG.2 in conjunction with FIG.3] shows corresponding visual) Corresponding product claim 16 is rejected similarly as claim 8 above. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ARYAN D TOUGHIRY whose telephone number is (571)272-5212. The examiner can normally be reached Monday - Friday, 9 am - 5 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Aleksandr Kerzhner can be reached at (571) 270-1760. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ARYAN D TOUGHIRY/Examiner, Art Unit 2165 /ALEKSANDR KERZHNER/Supervisory Patent Examiner, Art Unit 2165
Read full office action

Prosecution Timeline

May 15, 2025
Application Filed
Mar 27, 2026
Non-Final Rejection mailed — §103
Jun 17, 2026
Applicant Interview (Telephonic)
Jun 17, 2026
Examiner Interview Summary
Jun 22, 2026
Response Filed
Sep 11, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737380
COMPONENT CHARACTERISTICS SIMILARITY COMPARISON
3y 1m to grant Granted Sep 15, 2026
Patent 12693991
SYSTEM AND METHOD FOR SYSTEM REPLICATION AND MIGRATION FOR IN-MEMORY DATABASE SYSTEMS
3y 2m to grant Granted Jul 28, 2026
Patent 12694031
SYSTEMS AND METHODS FOR ENHANCED RULES CONFLICT CHECKING WITH DATA VALIDATION
1y 6m to grant Granted Jul 28, 2026
Patent 12664176
CUSTOMIZED DATA ANALYSIS AND VISUALIZATION USING STRUCTURED DATA TABLES AND NODAL NETWORKS
3y 10m to grant Granted Jun 23, 2026
Patent 12664189
Method for Analyzing Technology and Device Thereof
2y 3m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
69%
Grant Probability
88%
With Interview (+19.6%)
3y 3m (~1y 10m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 199 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month