DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 101
Claims 1-14 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more.
Claim 8 is directed to a method for verifying integrity of vehicle control device components (i.e., a process). Therefore, claim 8 is within at least one of the four statutory categories.
Regarding Prong I of the Step 2A analysis in the 2019 PEG, the claims are to be analyzed
to determine whether they recite subject matter that falls within one of the follow groups of abstract ideas: a) mathematical concepts, b) certain methods of organizing human activity, and/or c) mental processes.
Claim 8 includes limitations that recite an abstract idea (emphasized below)
and will be used as a representative claim for the remainder of the 101 rejection. Claim 8 recites:
A method of verifying integrity of control device components interfacing a vehicle controller of an associated vehicle with a physical environment of the associated vehicle, the method comprising:
storing a dynamic vehicle model in a non-transitory memory device, the dynamic vehicle model comprising vehicle operational state data representative of normal operational states of the vehicle controller, wherein a first normal operational state maps a verified first signal obtained from a first control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state to a verified second signal obtained from a second control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state;
storing integrity verification logic data in the non-transitory memory device; and
executing the integrity verification logic by a processor device to:
receive a first observed signal from the first control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state;
use the dynamic vehicle model to map the received first observed signal to a predicted second signal expected to be obtained from the second control device component for the vehicle controller being operated in the first normal operational state;
compare the predicted second signal with a second observed signal received from the second control device component; and
verify the integrity of the first and second control device components based on a match within a predetermined range between the predicted second signal and the second observed signal, or
generate a verification refute signal based on a mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust a functional aspect of the associated vehicle
The examiner submits that the foregoing bolded limitation(s) constitute a “mental process” because under its broadest reasonable interpretation, the claim covers performance of the limitation in the human mind. But for the recitation of executing the integrity verification logic by a processor device nothing in the claim elements precludes the step from practically being performed in the mind. For example; use, compare and verify in the context of this claim encompasses a person looking at received data collected and forming a simple judgement. Additionally, the use, compare and verify steps are not too complicated to be performed with the aid of pen and paper. Accordingly, the claim recites at least one abstract idea.
Regarding Prong II of the Step 2A analysis in the 2019 PEG, the claims are to be analyzed to determine whether the claim, as a whole, integrates the abstract into a practical application. As noted in the 2019 PEG, it must be determined whether any additional elements in the claim beyond the abstract idea integrate the exception into a practical application in a manner that imposes a meaningful limit on the judicial exception. The courts have indicated that additional elements merely using a computer to implement an abstract idea, adding insignificant extra solution activity, or generally linking use of a judicial exception to a particular technological environment or field of use do not integrate a judicial exception into a “practical application”.
In the present case, the additional limitations beyond the above-noted abstract idea are as
follows (where the underlined portions are the “additional limitations”) while the bolded portions
continue to represent the “abstract idea”:
A method of verifying integrity of control device components interfacing a vehicle controller of an associated vehicle with a physical environment of the associated vehicle, the method comprising:
storing a dynamic vehicle model in a non-transitory memory device, the dynamic vehicle model comprising vehicle operational state data representative of normal operational states of the vehicle controller, wherein a first normal operational state maps a verified first signal obtained from a first control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state to a verified second signal obtained from a second control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state;
storing integrity verification logic data in the non-transitory memory device; and
executing the integrity verification logic by a processor device to:
receive a first observed signal from the first control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state;
use the dynamic vehicle model to map the received first observed signal to a predicted second signal expected to be obtained from the second control device component for the vehicle controller being operated in the first normal operational state;
compare the predicted second signal with a second observed signal received from the second control device component; and
verify the integrity of the first and second control device components based on a match within a predetermined range between the predicted second signal and the second observed signal, or
generate a verification refute signal based on a mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust a functional aspect of the associated vehicle.
For the following reason(s), the examiner submits that the above identified additional
limitations do not integrate the above-noted abstract idea into a practical application.
Regarding the additional limitations of storing, receive and generate; the examiner submits that these limitations are insignificant extra-solution activities that merely use a computer (processor) to perform the process. In particular, the receive step from external sources are recited at a high level of generality (i.e. as a general means of gathering sensor data for use in the use, verify and compare steps), and amounts to mere data gathering, which is a form of insignificant extra-solution activity. The storing step is also recited at a high level of generality, which is a form of insignificant extra-solution activity. Although the generate a verification refute signal applies practical application and is not directed to a judicial exception by using the vehicle controller to adjust a functional aspect of the associated vehicle; it is an optional limitation because executing the integrity verification logic comprises either verifying the integrity of the first and second control device components or adjusting a functional aspect of the associated vehicle based on generation of a verification refute signal which is indefinite.
Lastly, the processor merely describes how to generally “apply” the otherwise mental judgements in a generic or general purpose vehicle control environment. The method for verifying integrity of vehicle control device components is recited at a high level of generality and merely automates the use, verify and compare steps. Thus, taken alone, the additional elements do not integrate the abstract idea into a practical application.
Further, looking at the additional limitation(s) as an ordered combination or as a whole, the limitation(s) add nothing that is not already present when looking at the elements taken individually. For instance, there is no indication that the additional elements, when considered as a whole, reflect an improvement in the functioning of a computer or an improvement to another technology or technical field, apply or use the above-noted judicial exception to effect a particular vehicle navigation or control problem, implement/use the above-noted judicial exception with a particular machine or manufacture that is integral to the claim, effect a transformation or reduction of a particular article to a different state or thing, or apply or use the judicial exception in some other meaningful way beyond generally linking the use of the judicial exception to a particular technological environment, such that the claim as a whole is not more than a drafting effort designed to monopolize the exception (MPEP § 2106.05). Accordingly, the additional limitation(s) do/does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
Regarding Step 2B of the 2019 PEG, representative independent claim 8 does not include
additional elements (considered both individually and as an ordered combination) that are
sufficient to amount to significantly more than the judicial exception for the same reasons to
those discussed above with respect to determining that the claim does not integrate the abstract idea into a practical application. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a processor to perform the use, verify and compare steps amounts to nothing more than applying the exception using a generic computer component. Generally applying an exception using a generic computer component cannot provide an inventive concept. And as discussed above, the additional limitations of storing and receive; the examiner submits that these limitations are insignificant extra-solution activities.
Further, a conclusion that an additional element is insignificant extra-solution activity in
Step 2A should be re-evaluated in Step 2B to determine if they are more than what is well understood, routine, conventional activity in the field. The additional limitations of storing and receive; are well-understood, routine, and conventional activities, and the specification does not provide any indication that the processor is anything other than a conventional computer network component. MPEP 2106.05(d)(II), and the cases cited therein, including Intellectual Ventures I, LLC v. Symantec Corp., 838 F.3d 1307, 1321 (Fed. Cir. 2016), TLI Communications LLC v. AV Auto. LLC, 823 F.3d 607, 610 (Fed. Cir. 2016), and OIP Techs., Inc., v. Amazon.com, Inc., 788 F.3d 1359, 1363 (Fed. Cir. 2015), indicate that mere collection or receipt of data over a network is a well‐understood, routine, and conventional function when it is claimed in a merely generic manner. Hence, the claim is not patent eligible.
Similar analysis applied to independent claim 8.
Dependent claims 2-7 and 9-14 do not recite any further limitations that cause the claim to be patent eligible. Rather, the limitations of dependent claims are directed toward additional aspects of the judicial exception and/or well-understood, routine and conventional additional elements that do not integrate the judicial exception into a practical application. Therefore, dependent claims 2-7 and 9-14 are not patent eligible under the same rationale as provided for in the rejection of Claim 8. Therefore, claims 1-14 are ineligible under 35 USC §101.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3, 6, 8, 10 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Tsuda et al. (US 12594947 B2; hereinafter Tsuda) in view of Kundu et al. (US 20230080281 A1; hereinafter Kundu).
Regarding claim 1, Tsuda teaches an integrity verification apparatus operable in an associated vehicle to verify the integrity of control device components interfacing a vehicle controller of the associated vehicle with a physical environment of the associated vehicle (see at least, Col 1 lines 54-63, A display
control device…includes a display control unit that calculates, based on sets of sensing information acquired from plural sensors that sense objects in front of a vehicle…reliabilities of the sets of sensing information acquired from the plural sensors), the integrity verification apparatus comprising: a processor device; a non-transitory memory device operatively coupled with the processor device (see at least, Claim 1, A display control device comprising a processor coupled to a memory, the processor
executing instructions stored in the memory to perform processes); wherein a first normal operational state maps a verified first signal obtained from a first control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state to a verified second signal obtained from a second control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state (see at least, Col 9 lines 26-40, the first display control unit 66 and the second display control unit 68 calculate, based on the sets of sensing information acquired from the plural sensors (the camera 12 and the mmWave radar sensor 14) that sense objects in front of the vehicle 70, the position of the preceding vehicle in front of the vehicle…
based on the reliabilities of the sets of sensing information acquired from the plural sensors); and integrity verification logic (see at least, Col 3 lines 34-44, A display control program…causes a computer to execute a process….based on sets of sensing information acquired from plural sensors that sense objects in front of a vehicle…reliabilities of the sets of sensing information acquired from the plural sensors) stored in the non-transitory memory device (see at least, Claim 1, A display control device comprising a processor coupled to a memory, the processor executing instructions stored in the memory to perform processes), wherein the processor device is operable to execute the integrity verification logic to: receive a first observed signal from the first control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state (see at least, Col 8 lines 6-8, the first display control unit 66 calculates the position information based on the set of sensing information acquired from the camera 12); compare the predicted second signal with a second observed signal received from the second control device component; and verify the integrity of the first and second control device components based on a match within a predetermined range between the predicted second signal and the second observed signal (see at least, Col 2 lines 24-32, the display control unit, in a case in which there is a set of sensing information whose reliability is less than a predetermined value among the sets of sensing information acquired from the plural sensors, calculates the position of the detection object based on sets of sensing information acquired from a sensor group of the plural sensors excluding a sensor corresponding to the set of sensing information whose reliability is less than the predetermined value) or generate a verification refute signal based on a mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust a functional aspect of the associated vehicle.
Tsuda does not explicitly teach a dynamic vehicle model stored in the non-transitory memory device, the dynamic vehicle model comprising vehicle operational state data representative of normal operational states of the vehicle controller; use the dynamic vehicle model to map the received first observed signal to a predicted second signal expected to be obtained from the second control device component for the vehicle controller being operated in the first normal operational state. However, Kundu teaches these limitations.
Kundu teaches a dynamic vehicle model stored in the non-transitory memory device (see at least, 0040] the computer-readable media 118 may store data, data structures, machine-learning models, and other information used for performing the functions), the dynamic vehicle model comprising vehicle operational state data representative of normal operational states of the vehicle controller (see at least, [0045] For example, the vehicle control program 124 may use rule-based and or artificial-intelligence-based control algorithms to determine parameters for vehicle control); use the dynamic vehicle model to map the received first observed signal to a predicted second signal expected to be obtained from the second control device component for the vehicle controller being operated in the first normal operational state (see at least, [0166] The POZs determined for respective road segments may be sent to the safety score determining process of the predictive analytics module(s) 150. In the safety score determining process, the 3D POZ of the road segments for every candidate route may be compared with the vehicle sensor field of view (FOV) for the vehicle for which the route is being determined. For each road segment, the percentage of 3D POZ overlapped by the vehicle sensor FOV may be determined).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Tsuda to include a dynamic vehicle model stored in the non-transitory memory device, the dynamic vehicle model comprising vehicle operational state data representative of normal operational states of the vehicle controller; use the dynamic vehicle model to map the received first observed signal to a predicted second signal expected to be obtained from the second control device component for the vehicle controller being operated in the first normal operational state as taught by Kundu in order determine in advance a zone that the vehicle should monitor to ensure its safety when traversing the respective road segment (Kundu, [0028]).
Regarding claim 3, the combination of Tsuda and Kundu teaches the integrity verification apparatus according to claim 1. Tsuda further teaches wherein the processor device is operable to execute the integrity verification logic to: receive image data as the first observed signal from the first control device component comprising an imaging device (see at least, Col 4 lines 43-45, The camera 12 captures images of objects further in front of the vehicle 70 than itself and outputs the imaging results); and receive sensor data as the second observed signal from the second control device component comprising one or more of an accelerometer, a steering wheel angle position sensor, a brake pedal position sensor, a wheel speed sensor, a forward distance sensor, a rear distance sensor, and/or an engine speed or condition sensor (see at least, Col 4 lines 45-50, The mmWave radar sensor 14 measures distances to objects in front of the vehicle 70 by transmitting probing waves in the forward direction of the vehicle 70 and receiving reflected waves, and outputs the distance measurement results).
Regarding claim 6, the combination of Tsuda and Kundu teaches the integrity verification apparatus according to claim 1. Kundu further teaches wherein the processor device is operable to execute the integrity verification logic to: receive roadway image data as the first observed signal from the first control device component comprising an imaging device oriented to obtain an image of the roadway ahead of the associated vehicle (see at least, [0103] determining the safety score may include comparing the POZ with the vehicle sensor FOV for the particular vehicle to determine a percentage of overlap between the POZ for each segment and the vehicle sensor FOV; [0032] the POZ for a road segment may be determined using a camera-based driver monitoring system and data collected from monitoring a number of subjects).
Tsuda further teaches receive sensor data as the second observed signal from the second control device component comprising one or more of an accelerometer, a steering wheel angle position sensor, a brake pedal position sensor, a wheel speed sensor, a forward distance sensor, a rear distance sensor, and/or an engine speed or condition sensor (see at least, Col 4 lines 45-50, The mmWave radar sensor 14 measures distances to objects in front of the vehicle 70 by transmitting probing waves in the forward direction of the vehicle 70 and receiving reflected waves, and outputs the distance measurement results).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Tsuda to include receive roadway image data as the first observed signal from the first control device component comprising an imaging device oriented to obtain an image of the roadway ahead of the associated vehicle as taught by Kundu in order determine in advance a zone that the vehicle should monitor to ensure its safety when traversing the respective road segment (Kundu, [0028]).
Regarding claim 8, Tsuda teaches a method of verifying integrity of control device components interfacing a vehicle controller of an associated vehicle with a physical environment of the associated vehicle (see at least, Col 1 lines 54-63, A display control device…includes a display control unit that calculates, based on sets of sensing information acquired from plural sensors that sense objects in front of a vehicle…reliabilities of the sets of sensing information acquired from the plural sensors), the method comprising: wherein a first normal operational state maps a verified first signal obtained from a first control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state to a verified second signal obtained from a second control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state (see at least, Col 9 lines 26-40, the first display control unit 66 and the second display control unit 68 calculate, based on the sets of sensing information acquired from the plural sensors (the camera 12 and the mmWave radar sensor 14) that sense objects in front of the vehicle 70, the position of the preceding vehicle in front of the vehicle…based on the reliabilities of the sets of sensing information acquired from the plural sensors); storing integrity verification logic data (see at least, Col 3 lines 34-44, A display control program…causes a computer to execute a process….based on sets of sensing information acquired from plural sensors that sense objects in front of a vehicle…reliabilities of the sets of sensing information acquired from the plural sensors) in the non-transitory memory device stored in the non-transitory memory device (see at least, Claim 1, A display control device comprising a processor coupled to a memory, the processor executing instructions stored in the memory to perform processes); and executing the integrity verification logic by a processor device to: receive a first observed signal from the first control device component of the associated vehicle for the vehicle controller being operated in the first normal operational state (see at least, Col 8 lines 6-8, the first display control unit 66 calculates the position information based on the set of sensing information acquired from the camera 12); compare the predicted second signal with a second observed signal received from the second control device component; and verify the integrity of the first and second control device components based on a match within a predetermined range between the predicted second signal and the second observed signal (see at least, Col 2 lines 24-32, the display control unit, in a case in which there is a set of sensing information whose reliability is less than a predetermined value among the sets of sensing information acquired from the plural sensors, calculates the position of the detection object based on sets of sensing information acquired from a sensor group of the plural sensors excluding a sensor corresponding to the set of sensing information whose reliability is less than the predetermined value), or generate a verification refute signal based on a mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust a functional aspect of the associated vehicle.
Tsuda does not explicitly teach storing a dynamic vehicle model in a non-transitory memory device, the dynamic vehicle model comprising vehicle operational state data representative of normal operational states of the vehicle controller; use the dynamic vehicle model to map the received first observed signal to a predicted second signal expected to be obtained from the second control device component for the vehicle controller being operated in the first normal operational state. However, Kundu teaches these limitations.
Kundu teaches storing a dynamic vehicle model in a non-transitory memory device (see at least, 0040] the computer-readable media 118 may store data, data structures, machine-learning models, and other information used for performing the functions), the dynamic vehicle model comprising vehicle operational state data representative of normal operational states of the vehicle controller (see at least, [0045] For example, the vehicle control program 124 may use rule-based and or artificial-intelligence-based control algorithms to determine parameters for vehicle control); use the dynamic vehicle model to map the received first observed signal to a predicted second signal expected to be obtained from the second control device component for the vehicle controller being operated in the first normal operational state (see at least, [0166] The POZs determined for respective road segments may be sent to the safety score determining process of the predictive analytics module(s) 150. In the safety score determining process, the 3D POZ of the road segments for every candidate route may be compared with the vehicle sensor field of view (FOV) for the vehicle for which the route is being determined. For each road segment, the percentage of 3D POZ overlapped by the vehicle sensor FOV may be determined).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Tsuda to include storing a dynamic vehicle model in a non-transitory memory device, the dynamic vehicle model comprising vehicle operational state data representative of normal operational states of the vehicle controller; use the dynamic vehicle model to map the received first observed signal to a predicted second signal expected to be obtained from the second control device component for the vehicle controller being operated in the first normal operational state as taught by Kundu in order determine in advance a zone that the vehicle should monitor to ensure its safety when traversing the respective road segment (Kundu, [0028]).
Regarding claim 10, the combination of Tsuda and Kundu teaches the method according to claim 8. Tsuda further teaches comprising executing the integrity verification logic by the processor device to: receive image data as the first observed signal from the first control device component comprising an imaging device (see at least, Col 4 lines 43-45, The camera 12 captures images of objects further in front of the vehicle 70 than itself and outputs the imaging results); and receive sensor data as the second observed signal from the second control device component comprising one or more of an accelerometer, a steering wheel angle position sensor, a brake pedal position sensor, a wheel speed sensor, a forward distance sensor, a rear distance sensor, and/or an engine speed or condition sensor (see at least, Col 4 lines 45-50, The mmWave radar sensor 14 measures distances to objects in front of the vehicle 70 by transmitting probing waves in the forward direction of the vehicle 70 and receiving reflected waves, and outputs the distance measurement results).
Regarding claim 13, the combination of Tsuda and Kundu teaches the method according to claim 8. Kundu further teaches comprising executing the integrity verification logic by the processor device to: receive roadway image data as the first observed signal from the first control device component comprising an imaging device oriented to obtain an image of the roadway ahead of the associated vehicle (see at least, [0103] determining the safety score may include comparing the POZ with the vehicle sensor FOV for the particular vehicle to determine a percentage of overlap between the POZ for each segment and the vehicle sensor FOV; [0032] the POZ for a road segment may be determined using a camera-based driver monitoring system and data collected from monitoring a number of subjects).
Tsuda further teaches receive sensor data as the second observed signal from the second control device component comprising one or more of an accelerometer, a steering wheel angle position sensor, a brake pedal position sensor, a wheel speed sensor, a forward distance sensor, a rear distance sensor, and/or an engine speed or condition sensor (see at least, Col 4 lines 45-50, The mmWave radar sensor 14 measures distances to objects in front of the vehicle 70 by transmitting probing waves in the forward direction of the vehicle 70 and receiving reflected waves, and outputs the distance measurement results).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Tsuda to include receive roadway image data as the first observed signal from the first control device component comprising an imaging device oriented to obtain an image of the roadway ahead of the associated vehicle as taught by Kundu in order determine in advance a zone that the vehicle should monitor to ensure its safety when traversing the respective road segment (Kundu, [0028]).
Claims 2, 4, 7, 9, 11 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Tsuda et al. (US 12594947 B2; hereinafter Tsuda) in view of Kundu et al. (US 20230080281 A1; hereinafter Kundu) in further view of Zhu et al. (US 9555740 B1; hereinafter Zhu).
Regarding claim 2, the combination of Tsuda and Kundu teaches the integrity verification apparatus according to claim 1. The combination does not explicitly teach wherein the processor device is operable to execute the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust one or more of: a content of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a timing of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a format of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a style of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; and/or a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle. However, Zhu teaches these limitations.
Zhu teaches the processor device is operable to execute the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal (see at least, Col 12 lines 21-37, The autonomous driving computer system 144 may take various actions defined by the cross-validation algorithm 140 in response to the cross-validation operations…may display a warning to a passenger of the autonomous vehicle 102 when the autonomous driving computer system 144 determines that the sensor being
cross-validated is experiencing a problem…e.g., not accurately reporting a detected object), wherein the verification refute signal is used by the vehicle controller to adjust one or more of: a content of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a timing of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a format of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a style of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; and/or a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle (see at least, Col 12 lines 21-37, the autonomous driving computer system 144 may request that a passenger take control of the autonomous vehicle 102…may perform a combination of actions, such as displaying the warning and requesting that a passenger
take control of the autonomous vehicle 102).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the combination of Tsuda and Kundu to include execute the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle as taught by Zhu in order to maximize safety for passengers as well as objects or people in the environment.
Regarding claim 4, the combination of Tsuda and Kundu teaches the integrity verification apparatus according to claim 3. The combination does not explicitly teach wherein the processor device is operable to execute the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust one or more of: a content of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a timing of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a format of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a style of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; and/or a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle. However, Zhu teaches these limitations.
Zhu teaches the processor device is operable to execute the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal (see at least, Col 12 lines 21-37, The autonomous driving computer system 144 may take various actions defined by the cross-validation algorithm 140 in response to the cross-validation operations…may display a warning to a passenger of the autonomous vehicle 102 when the autonomous driving computer system 144 determines that the sensor being
cross-validated is experiencing a problem…e.g., not accurately reporting a detected object), wherein the verification refute signal is used by the vehicle controller to adjust one or more of: a content of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a timing of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a format of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a style of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; and/or a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle (see at least, Col 12 lines 21-37, the autonomous driving computer system 144 may request that a passenger take control of the autonomous vehicle 102…may perform a combination of actions, such as displaying the warning and requesting that a passenger
take control of the autonomous vehicle 102).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the combination of Tsuda and Kundu to include execute the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle as taught by Zhu in order to maximize safety for passengers as well as objects or people in the environment.
Regarding claim 7, the combination of Tsuda and Kundu teaches the integrity verification apparatus according to claim 1. The combination does not explicitly teach wherein the processor device is operable to execute the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to: terminate operation of one or more automatic driver assistance systems (ADASs) of the associated vehicle; execute operation of the one or more ADASs of the associated vehicle in a reduced manner; and/or initiate a correction in the one or more ADASs of the associated vehicle. However, Zhu teaches these limitations.
Zhu teaches the processor device is operable to execute the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal (see at least, Col 12 lines 21-37, The autonomous driving computer system 144 may take various actions defined by the cross-validation algorithm 140 in response to the cross-validation operations…may display a warning to a passenger of the autonomous vehicle 102 when the autonomous driving computer system 144 determines that the sensor being
cross-validated is experiencing a problem…e.g., not accurately reporting a detected object), wherein the verification refute signal is used by the vehicle controller to: terminate operation of one or more automatic driver assistance systems (ADASs) of the associated vehicle; execute operation of the one or more ADASs of the associated vehicle in a reduced manner; and/or initiate a correction in the one or more ADASs of the associated vehicle (see at least, Col 12 lines 21-37, the autonomous driving computer system 144 may request that a passenger take control of the autonomous vehicle 102…may perform a combination of actions, such as displaying the warning and requesting that a passenger
take control of the autonomous vehicle 102).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the combination of Tsuda and Kundu to include execute the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to: terminate operation of one or more automatic driver assistance systems (ADASs) of the associated vehicle as taught by Zhu in order to maximize safety for passengers as well as objects or people in the environment.
Regarding claim 9, the combination of Tsuda and Kundu teaches the method according to claim 8. The combination does not explicitly teach further comprising executing the integrity verification logic by the processor device to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust one or more of: a content of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a timing of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a format of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a style of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; and/or a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle. However, Zhu teaches these limitations.
Zhu teaches executing the integrity verification logic by the processor device to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal (see at least, Col 12 lines 21-37, The autonomous driving computer system 144 may take various actions defined by the cross-validation algorithm 140 in response to the cross-validation operations…may display a warning to a passenger of the autonomous vehicle 102 when the autonomous driving computer system 144 determines that the sensor being
cross-validated is experiencing a problem…e.g., not accurately reporting a detected object), wherein the verification refute signal is used by the vehicle controller to adjust one or more of: a content of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a timing of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a format of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a style of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; and/or a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle (see at least, Col 12 lines 21-37, the autonomous driving computer system 144 may request that a passenger take control of the autonomous vehicle 102…may perform a combination of actions, such as displaying the warning and requesting that a passenger
take control of the autonomous vehicle 102).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the combination of Tsuda and Kundu to include executing the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle as taught by Zhu in order to maximize safety for passengers as well as objects or people in the environment.
Regarding claim 11, the combination of Tsuda and Kundu teaches the method according to claim 10. The combination does not explicitly teach further comprising executing the integrity verification logic by the processor device to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the sensor data received as the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust one or more of: a content of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a timing of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a format of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a style of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; and/or a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle. However, Zhu teaches these limitations.
Zhu teaches executing the integrity verification logic by the processor device to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the sensor data received as the second observed signal (see at least, Col 12 lines 21-37, The autonomous driving computer system 144 may take various actions defined by the cross-validation algorithm 140 in response to the cross-validation operations…may display a warning to a passenger of the autonomous vehicle 102 when the autonomous driving computer system 144
determines that the sensor being cross-validated is experiencing a problem…e.g., not accurately reporting a detected object), wherein the verification refute signal is used by the vehicle controller to adjust one or more of: a content of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a timing of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a format of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; a style of a warning signal generated by the vehicle controller for warning the driver of potential danger relating to the vehicle operation; and/or a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle (see at least, Col 12 lines 21-37, the autonomous driving computer system 144 may request that a passenger take control of the autonomous vehicle 102…may perform a combination of actions, such as displaying the warning and requesting that a passenger take control of the autonomous vehicle 102).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the combination of Tsuda and Kundu to include executing the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to adjust a parameter of one or more automatic driver assistance systems (ADASs) of the associated vehicle as taught by Zhu in order to maximize safety for passengers as well as objects or people in the environment.
Regarding claim 14, the combination of Tsuda and Kundu teaches the method according to claim 8. The combination does not explicitly teach further comprising executing the integrity verification logic by the processor device to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to: terminate operation of one or more automatic driver assistance systems (ADASs) of the associated vehicle; execute operation of the one or more ADASs of the associated vehicle in a reduced manner; and/or initiate a correction in the one or more ADASs of the associated vehicle. However, Zhu teaches these limitations.
Zhu teaches executing the integrity verification logic by the processor device to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal (see at least, Col 12 lines 21-37, The autonomous driving computer system 144 may take various actions defined by the cross-validation algorithm 140 in response to the cross-validation operations…may display a warning to a passenger of the autonomous vehicle 102 when the autonomous driving computer system 144 determines that the sensor being
cross-validated is experiencing a problem…e.g., not accurately reporting a detected object), wherein the verification refute signal is used by the vehicle controller to: terminate operation of one or more automatic driver assistance systems (ADASs) of the associated vehicle; execute operation of the one or more ADASs of the associated vehicle in a reduced manner; and/or initiate a correction in the one or more ADASs of the associated vehicle (see at least, Col 12 lines 21-37, the autonomous driving computer system 144 may request that a passenger take control of the autonomous vehicle 102…may perform a combination of actions, such as displaying the warning and requesting that a passenger
take control of the autonomous vehicle 102).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the combination of Tsuda and Kundu to include executing the integrity verification logic to: generate the verification refute signal based on the mismatch within a predetermined range between the predicted second signal and the second observed signal, wherein the verification refute signal is used by the vehicle controller to: terminate operation of one or more automatic driver assistance systems (ADASs) of the associated vehicle as taught by Zhu in order to maximize safety for passengers as well as objects or people in the environment.
Claims 5 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Tsuda et al. (US 12594947 B2; hereinafter Tsuda) in view of Kundu et al. (US 20230080281 A1; hereinafter Kundu) in further view of Matsuo et al. (US 20200210735 A1; hereinafter Matsuo).
Regarding claim 5, the combination of Tsuda and Kundu teaches the integrity verification apparatus according to claim 1. The combination does not explicitly teach wherein the processor device is operable to execute the integrity verification logic to: receive driver image data as the first observed signal from the first control device component comprising an imaging device oriented to obtain an image of the driver of the associated vehicle. However, Matsuo teaches this limitation.
Matsuo teaches the processor device is operable to execute the integrity verification logic to: receive driver image data as the first observed signal from the first control device component comprising an imaging device oriented to obtain an image of the driver of the associated vehicle ([0057] The storing execution unit 216 may store, in the image storing unit 218, the occupant's face image captured by the camera 110 when the operation situation of the steering wheel 150 of the vehicle 100 acquired by the situation acquiring unit 212 matches the predetermined situation… for example, in the image storing unit 218, the face image of the driver 52, captured by the camera 110 when the rotation angle of the steering wheel 150 of the vehicle 100 falls in the predetermined range from the reference position).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the combination of Tsuda and Kundu to include the processor device is operable to execute the integrity verification logic to: receive driver image data as the first observed signal from the first control device component comprising an imaging device oriented to obtain an image of the driver of the associated vehicle as taught by Matsuo in order to judge the situation of the vehicle using the information for navigation of the vehicle (Matsuo, [0045]).
Tsuda further teaches receive sensor data as the second observed signal from the second control device component comprising one or more of an accelerometer, a steering wheel angle position sensor, a brake pedal position sensor, a wheel speed sensor, a forward distance sensor, a rear distance sensor, and/or an engine speed or condition sensor (see at least, Col 4 lines 45-50, The mmWave radar sensor 14 measures distances to objects in front of the vehicle 70 by transmitting probing waves in the forward direction of the vehicle 70 and receiving reflected waves, and outputs the distance measurement results).
Regarding claim 12, the combination of Tsuda and Kundu teaches the method according to claim 8. The combination does not explicitly teach further comprising executing the integrity verification logic by the processor device to: receive driver image data as the first observed signal from the first control device component comprising an imaging device oriented to obtain an image of the driver of the associated vehicle. However, Matsuo teaches this limitation.
Matsuo teaches executing the integrity verification logic by the processor device to: receive driver image data as the first observed signal from the first control device component comprising an imaging device oriented to obtain an image of the driver of the associated vehicle ([0057] The storing execution unit 216 may store, in the image storing unit 218, the occupant's face image captured by the camera 110 when the operation situation of the steering wheel 150 of the vehicle 100 acquired by the situation acquiring unit 212 matches the predetermined situation… for example, in the image storing unit 218, the face image of the driver 52, captured by the camera 110 when the rotation angle of the steering wheel 150 of the vehicle 100 falls in the predetermined range from the reference position).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the combination of Tsuda and Kundu to include the processor device is operable to execute the integrity verification logic to: receive driver image data as the first observed signal from the first control device component comprising an imaging device oriented to obtain an image of the driver of the associated vehicle as taught by Matsuo as taught by Matsuo in order to judge the situation of the vehicle using the information for navigation of the vehicle (Matsuo, [0045]).
Tsuda further teaches receive sensor data as the second observed signal from the second control device component comprising one or more of an accelerometer, a steering wheel angle position sensor, a brake pedal position sensor, a wheel speed sensor, a forward distance sensor, a rear distance sensor, and/or an engine speed or condition sensor (see at least, Col 4 lines 45-50, The mmWave radar sensor 14 measures distances to objects in front of the vehicle 70 by transmitting probing waves in the forward direction of the vehicle 70 and receiving reflected waves, and outputs the distance measurement results).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Satoh et al. (US 20220264081 A1 ) discloses verify the integrity of the first and second control device components based on a match within a predetermined range between the predicted second signal and the second observed signal (e.g. [0078] Various methods can be used for diagnosis by comparison between the reference value data and the sensing data in FIG. 9. For example, the reliability of each external-environment sensor may be diagnosed by comparing
differential values and integral values between the reference value data and the sensing data).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TOYA PETTIEGREW whose telephone number is (313)446-6636. The examiner can normally be reached 8:30pm - 5:00pm M-F.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jelani Smith can be reached at 571-270-3969. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/TOYA PETTIEGREW/Primary Examiner, Art Unit 3662