. Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This is the initial office action has been issued in response to patent application, 19/291122, filed on filed 05 August 2025 with foreign priority date 21 august 2024. Claims 1-20, as originally filed, are currently pending and have been considered below
Information Disclosure Statement
The information disclosure statement filed 08/05/2025 complies with the provisions of 37 CFR 1.97, 1.98 and MPEP § 609 and the information referred to therein has been considered as to the merits.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-3, 6-19 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Mondello et al. (US2020/0313911 A1, publish date 10/01/2020). (on applicant’s IDS filed 08/05/2025)
Claim 1:
With respect to claim 1, Mondello et al. discloses a computer system, which is connected to a recipient system by a data link (par. 114: "a method for encrypted and decrypted communication between the internal vehicle computing device and the external entity (e.g., a server acting as a host device) is discussed") from a sender system (Fig. 4 (300) : "Vehicle"; Fig. 8(810"): "vehicle computing to a recipient system (Fig. 4(350) "host"; Fig. 8(810): "external computing device"; par. 145), to which a volume limit applies intermittently (par . 110: "The host device 350 can energize the communication component 310 when the vehicle 300 brings antenna 340 within a communication distance of antenna 380"; par. 112: "this occurs when the vehicle approaches an external communication component (e.g., a server or other computing device acting as a host device) within a particular proximity so that communication can begin and/ or become strengthened. The communication di stance is or example 2-3 meters. par. 107: "NFC tag" ), the computer system comprising processing circuitry (Fig. 4(300) "vehicle"; Fig. 6; Fig. 8(810"); par. 145: "a vehicle computing device 810" e.g., vehicle computing device 110 in Fig. 3 or computing device 141 or Fig. 1") configured to:
obtain a data set ( par . 145: "vehicle computing device ... can send data to an external computing device 810`; par. 115: "Data sent by the vehicle 100 can include car information, passenger information, goods information, and the like");
generate an asymmetric key pair comprising a private key and a public key (Fig. 6(540): "asymmetric key generator"; par. 136: "The asymmetric key generator 540 can generate a public key, KLkpublic, (referred to as an external public key) and a private key, KLkprivate, (referred to as an external private key) associated with an external communication component");
share the private key of the asymmetric key pair with the recipient system (Fig. 6(540- >550) : "KLprivate - > Encrypt >K" "; par. 138: "The external private key KLkprivate can be input into an additional encryptor 550, resulting in output K". The output K" is the external certificate, I DL1certificate, transmitted to a host device that verifies identity)");
encrypt the data set using the public key of the asymmetric key pair, for thereby
obtaining an encrypted data set which is decryptable only by means of the private key (par. 115: II the vehicular communication component 130 can encrypt data using the received external public key and send the encrypted data to the external communication component) (0117: encryption and/or decryption methods as described below. The securing of the data can ensure that unauthorized activity is prevented from interfering with the operation the vehicle 100 and the external entity);
await a time period in which the volume limit does not apply to the data link ( par . 110: "The host device 350 can energize the communication component 310 when the vehicle 300 brings antenna 340 within a communication distance of antenna 380"; par. 112: "this occurs when the vehicle approaches an external communication component (e.g., a server or other computing device acting as a host device) within a particular proximity so that communication can begin and/or become strengthened. The communication distance is for example 2-3 meters.");
and, in that time period, transfer the encrypted data set to the recipient system over the data link ( par . 112: "this occurs when the vehicle approaches an external communication component (e.g., a server or other computing device acting as a host device) within a particular proximity so that communication can begin and/or become strengthened. The communication distance is for example 2-3 meters.' "; par. 114: "a method for encrypted and decrypted communication).
Claim 2:
With respect to claim 2, Mondello et al. discloses a vehicle comprising the computer system of claim 1 (vehicle computing device, Figure 3).
Claim 3:
With respect to claim 3, Mondello et al. discloses a computer-implemented method for safe transfer of a large data set from a sender system to a recipient system which are connected by a data link (par. 114: "a method for encrypted and decrypted communication between the internal vehicle computing device and the external entity (e.g., a server acting as a host device) is discussed") from a sender system (Fig. 4 (300) : "Vehicle"; Fig. 8(810"): "vehicle computing to a recipient system (Fig. 4(350) "host"; Fig. 8(810): "external computing device"; par. 145), to which a volume limit applies intermittently (par . 110: "The host device 350 can energize the communication component 310 when the vehicle 300 brings antenna 340 within a communication distance of antenna 380"; par. 112: "this occurs when the vehicle approaches an external communication component (e.g., a server or other computing device acting as a host device) within a particular proximity so that communication can begin and/ or become strengthened. The communication di stance is or example 2-3 meters. par. 107: "NFC tag" ),
the method comprising the following steps performed by processing circuitry (Fig. 4(300) "vehicle"; Fig. 6; Fig. 8(810"); par. 145: "a vehicle computing device 810" e.g., vehicle computing device 110 in Fig. 3 or computing device 141 or Fig. 1") in the sender system:
obtain a data set ( par . 145: "vehicle computing device ... can send data to an external computing device 810`; par. 115: "Data sent by the vehicle 100 can include car information, passenger information, goods information, and the like");
generate an asymmetric key pair comprising a private key and a public key (Fig. 6(540): "asymmetric key generator"; par. 136: "The asymmetric key generator 540 can generate a public key, KLkpublic, (referred to as an external public key) and a private key, KLkprivate, (referred to as an external private key) associated with an external communication component");
sharing the private key of the asymmetric key pair with the recipient system (Fig. 6(540- >550) : "KLprivate - > Encrypt >K" "; par. 138: "The external private key KLkprivate can be input into an additional encryptor 550, resulting in output K". The output K" is the external certificate, I DL1certificate, transmitted to a host device that verifies identity)");
encrypting the data set using the public key of the asymmetric key pair, for thereby obtaining an encrypted data set which is decryptable only by means of the private key
(par. 115: II the vehicular communication component 130 can encrypt data using the received external public key and send the encrypted data to the external communication component) (0117: encryption and/or decryption methods as described below. The securing of the data can ensure that unauthorized activity is prevented from interfering with the operation the vehicle 100 and the external entity);
awaiting a time period in which the volume limit does not apply to the data link ( par . 110: "The host device 350 can energize the communication component 310 when the vehicle 300 brings antenna 340 within a communication distance of antenna 380"; par. 112: "this occurs when the vehicle approaches an external communication component (e.g., a server or other computing device acting as a host device) within a particular proximity so that communication can begin and/or become strengthened. The communication distance is for example 2-3 meters."); and,
in that time period, transferring the encrypted data set to the recipient system over the
data link ( par . 112: "this occurs when the vehicle approaches an external communication component (e.g., a server or other computing device acting as a host device) within a particular proximity so that communication can begin and/or become strengthened. The communication distance is for example 2-3 meters.' "; par. 114: "a method for encrypted and decrypted communication).
Claim 6:
With respect to claim 6, Mondello et al. discloses wherein sharing the private key with the recipient system includes further sharing a fingerprint enabling the recipient system to verify that the private key and the data set are related (par 0144-0145, a signature can be generated and sent with the data, using a signature, can avoid repudiation by the first device and ensure that the second device can perform the requested task without subsequent difficulty).
Claim 7:
With respect to claim 7, Mondello et al. discloses wherein encrypting the data set includes storing the encrypted data set in a nonvolatile memory in the sender system
(par 107 a short-range communication device (e.g., an NFC tag)., par 107 a non-volatile storage component 330 stores information about the vehicle 300 (such as vehicle ID, driver/passenger information, carried goods information,, etc.)
Claims 8, 16:
With respect to claims 8, 16, Mondello et al. discloses the data link includes a high-reliability sub-link (par 0088: cellular telephone, par 0229 a cellular communications network), which has a volume limit, and a high-volume sub-link, which is available only intermittently ( par . 110: "The host device 350 can energize the communication component 310 when the vehicle 300 brings antenna 340 within a communication distance of antenna 380"; par. 112: "this occurs when the vehicle approaches an external communication component (e.g., a server or other computing device acting as a host device) within a particular proximity so that communication can begin and/or become strengthened. The communication distance is for example 2-3 meters."); the private key is shared with the recipient system over the high-reliability sub-link (Fig. 6(540- >550) : "KLprivate - > Encrypt >K" "; par. 138: "The external private key KLkprivate can be input into an additional encryptor 550, resulting in output K". The output K" is the external certificate, I DL1certificate, transmitted to a host device that verifies identity)"); and
the encrypted data set is transferred to the recipient system over the high-volume sub link ( par . 112: "this occurs when the vehicle approaches an external communication component (e.g., a server or other computing device acting as a host device) within a particular proximity so that communication can begin and/or become strengthened. The communication distance is for example 2-3 meters.' "; par. 114: "a method for encrypted and decrypted communication).
Claims 9, 17:
With respect to claims 9, 17, Mondello et al. discloses wherein the high-reliability sub-link includes a satellite communication channel (par 0101: wireless transponders, NFC, Bluetooth, RFID, touchless sensors, magnetic bars, and the like).
Claims 10, 18:
With respect to claims 10, 18, Mondello et al. discloses wherein the high-volume sub-link includes a cellular communication channel (par 0088: cellular telephone, par 0229 a cellular communications network).
Claims 11, 19:
With respect to claims 11, 19, Mondello et al. discloses wherein the high-volume sub-link includes a noncellular short-distance communication channel, such as an IEEE 802.11 channel (par 0107: a short-range communication device (e.g., an NFC tag).
Claim 12:
With respect to claim 12, Mondello et al. discloses wherein the volume limit specifies a maximum data rate of the data link, preferably a nonzero maximum data rate of the data link (NFC tag operates at the globally unlicensed 13,56 MHZ frequency).
Claim 13:
With respect to claim 13, Mondello et al. discloses wherein the volume limit specifies a maximum data volume which is transferable over the data link in a time period of a predefined duration, preferably a nonzero maximum data volume which is transferable over the data link in the time period (NFC tag operates at the globally unlicensed 13,56 MHZ frequency).
Claim 14:
With respect to claim 14, Mondello et al. discloses wherein the private key of the asymmetric key pair is shared with the recipient system prior to said time period in which the volume limit does not apply to the data link (Figure 6).
Claim 15:
With respect to claim 15, Mondello et al. discloses a non-transitory computer-readable storage medium comprising instructions which, when executed by the processing circuitry, cause the processing circuitry to perform the method of claim 3 (par 0201: a non-transitory computer storage medium stores instructions which, when executed on a computing device).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 4, 20 are rejected under 35 U.S.C. 103 as being unpatentable over
Mondello et al. (US2020/0313911 A1, publish date 10/01/2020) in view of Muthaiah (US2012/0155636). (on applicants IDs filed 08/05/2025)
Claims 4, 20:
With respect to claims 4, 20, Mondello et al. discloses further comprising deleting the private key from the sender system as soon as practicable after sharing the private key with the recipient system (par 0434: an unauthorized person powered-up the device and attempted to read the stored keys. If tampering has occurred, the device is discarded and the indication of tampering communicated to the sender (e.g., transfer company) to avoid further technical security problems).
Muthaiah teaches further comprising deleting the private key from the sender system as soon as practicable after sharing the private key with the recipient system (par 0033: the key held in possession by the host vehicle is only maintained for as long as the V2V communications is enabled by the host vehicle. Once it is determined that V2V communications are not required by the host vehicle, the current cryptographic key held by the processing unit or storage device is deleted).
Mondello et al. and Muthaiah are analogous art because they are from the same field of endeavor of secure keys of vehicles.
It would have been obvious to one skilled in the art before the effective filing date of the claimed invention to use Muthaiah in Mondello et al. for purposes of an enhanced security system when using a decryption key for security purposes to enable secure vehicle operations and to keep the key safe; however, that has proven to be a difficult task as a key stored in some memory of the vehicle is always at risk of being stolen by an attacker attempting to gain access to the vehicle. If the attacker can gain access to both the key and the algorithm, then the attacker can access secure operations of the vehicle.
Claims 5, 20 are rejected under 35 U.S.C. 103 as being unpatentable over
Mondello et al. (US2020/0313911 A1, publish date 10/01/2020) in view of Shaffer et al. (US2023/0283463 A1, publish date 09/07/2023). (on applicants IDs filed 08/05/2025)
Claims 5, 20:
With respect to claims 5, 20, Mondello et al. discloses further comprising deleting the data set as soon as practicable after encrypting the data set (par 0142: data received from the device being verified can be accepted, decrypted, and/or processed. In response to the certificate not being verified, data received from the device being verified can be discarded, removed, and/or ignored).
Shaffer et al. teaches further comprising deleting the data set as soon as practicable after encrypting the data set (Par 0087: the source device need not continue to store the raw data, and may delete (or generally not store) any source data once it is encrypted into the source-encrypted source data for even further security against hacking (e.g., locally decrypting it if needed again in the future using its own decryption key, whether for access or editing).
Mondello et al. and Shaffer et al. are analogous art because they are from the same field of endeavor of secure data of vehicles.
It would have been obvious to one skilled in the art before the effective filing date of the claimed invention to use Shaffer et al. in Mondello et al. for purposes of control over who has access data.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure, see PTO Form 892.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Helai Salehi whose telephone number is 571-270-7468. The examiner can normally be reached on Monday - Friday from 9 am to 5 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Jeff Pwu, can be reached on 571-272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HELAI SALEHI/ Examiner, Art Unit 2433
/JEFFREY C PWU/ Supervisory Patent Examiner, Art Unit 2433