Prosecution Insights
Last updated: October 04, 2026
Application No. 16/950,404

NON-STORED MULTIPLE FACTOR VERIFICATION

Final Rejection §101§103
Filed
Nov 17, 2020
Examiner
POPHAM, JEFFREY D
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
Portal26 Inc.
OA Round
5 (Final)
38%
Grant Probability
At Risk
6-7
OA Rounds
0m
Est. Remaining
62%
With Interview

Examiner Intelligence

Grants only 38% of cases
38%
Career Allowance Rate
179 granted / 474 resolved
-20.2% vs TC avg
Strong +24% interview lift
Without
With
+24.0%
Interview Lift
resolved cases with interview
Typical timeline
4y 7m
Avg Prosecution
25 currently pending
Career history
508
Total Applications
across all art units

Statute-Specific Performance

§101
14.7%
-25.3% vs TC avg
§103
47.6%
+7.6% vs TC avg
§102
14.4%
-25.6% vs TC avg
§112
21.1%
-18.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 474 resolved cases

Office Action

§101 §103
Remarks Claims 1, 2, 6-10, 13-17, and 19-26 are pending. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Interpretation The claims include subject matter that is not required thereby. For example, claim 1 includes a limitation “receiving, by a validator of the authentication system, the characters of the currently provided first identity factor from the user system and the one or more rotated cube matrices from the matrix generator to generate characters for an unverified second identity factor, wherein to generate the characters for the unverified second identity factor comprises” and then describes this generating of characters in a few steps. However, “to generate characters” is intended use that never needs to be performed. Thus, “to generate characters” and on, through all indented steps, has no bearing on the scope of the claims. It is suggested that the claims include these steps as positive steps instead of intended use indented under a receiving limitation. As of now, only the receiving is required, and none of the generating characters is required by the claims. All independent claims have the same issue. Additional claims have similar issues. Response to Arguments Applicant's arguments filed 11/25/2024 have been fully considered but they are not persuasive. With respect to Applicant’s allegations regarding the 101 rejection, Applicant fails to show where the claims include these additional elements and improvements. In fact, Applicant does not appear to argue that any limitation from any claim provides anything being argued. Thus, the arguments are moot since they are not directed to the claims at hand. Moreover, the claims have been heavily amended and Applicant appears to only argue the previous 101 rejection, which is irrelevant now due to Applicant removing the majority of the independent claims and adding even more than was removed. With respect to Applicant’s allegations regarding Sonkar in the middle of page 15, including “Sonkar’s method is not related to a user authentication process”, Applicant is entirely incorrect. For example, paragraph 1 of Sonkar, under the heading “FIELD”, states “Methods and systems disclosed herein relate generally to computer security and authentication”. If this is not clear enough, Sonkar discloses user authentication credentials, such as a username and password in paragraph 51, for example. Even in Applicant’s arguments, Applicant explicitly discusses Sonkar’s disclosure of user’s credentials entered via a changing keypad. Sonkar is certainly related to user authentication. With respect to Applicant’s allegations spanning pages 15-16 of the response, it is noted that, similar to the last office action, Sonkar is cited for the majority of the claims, including authenticating using matrices, but does not explicitly disclose rotated cube matrices. This is taught by Chan. Thus, Applicant’s allegation that “Sonkar does not disclose, teach, or suggest, at least: generating, …, one or more rotated cube matrices…” is a piecemeal argument. In response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). In fact, all of Applicant’s 103 arguments appear to be piecemeal arguments. On pages 16-17, Applicant provides a list of limitations that Applicant believes are not taught by Sonkar, but fails to identify any reasons, other than a piecemeal argument regarding rotated cube matrices. In response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Applicant's arguments fail to comply with 37 CFR 1.111(b) because they amount to a general allegation that the claims define a patentable invention without specifically pointing out how the language of the claims patentably distinguishes them from the references. Applicant then provides a list of limitations that Applicant believes are not taught by Chan on page 17, with no argument whatsoever. In response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Applicant's arguments fail to comply with 37 CFR 1.111(b) because they amount to a general allegation that the claims define a patentable invention without specifically pointing out how the language of the claims patentably distinguishes them from the references. Sonkar as modified by Chan discloses the argued limitations as follows: Regarding Claim 1, Sonkar discloses a method comprising: Receiving, in a matrix generator of an authentication system, characters of a currently provided first identity factor from a user system (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-79, 84-92, 101-108, and associated figures; receiving any identity factor, such as account identifier, username, password, PIN, portion(s) of the above or many additional factors, etc., as examples); Generating, by the matrix generator, one or more matrices using the characters of the currently provided first identity factor as an input parameter, wherein each of the generated one or more matrices contains matrices of values associated with the characters of the currently provided first identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; generating layouts, positions, or the like, as well as using a one way function, such as a trapdoor function, as examples); Receiving, by a validator of the authentication system, the characters of the currently provided first identity factor from the user system and the one or more matrices from the matrix generator to generate characters for an unverified second identity factor, wherein to generate the characters for the unverified second identity factor comprises (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; receiving the above to be used in generating a position based on the keypad generated from the previous input, etc., for example): Deriving corresponding coordinate location values for the matrices of values associated with the characters of the currently provided first identity factor, the coordinate location values are associated with the characters of the currently provided first identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; generating a position based on the keypad generated from the previous input, etc., for example); Subtracting a first set of predefined difference values from the derived coordinate location values to generate coordinate location values of a non-stored user key, wherein the coordinate location values of the non-stored user key are different from the coordinate location values associated with the characters of the currently provided first identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; values in the matrix are changed by a predefined difference value, for example); Adding a second set of predefined difference values to the coordinate location values of the non-stored user key to generate coordinate location values for characters of the unverified second identity factor, wherein the first and second set of predefined values are previously generated during a registration phase (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; values in the matrix are changed again by a predefined difference value, for example); For each one of the coordinate location values for the characters of the unverified second identity factor, locating in the one or more matrices a corresponding value to identify matrices of values associated with characters of the unverified second identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; finding the correct matrix location, for example); and Converting the identified matrices of values associated with the characters of the unverified second identity factor to the characters of the unverified second identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures); Receiving, by the validator, characters of a currently provided second identity factor from the user system (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; receiving second input either via keypad or via position, for example); and Comparing, with the validator, the characters of the unverified second identity factor from the characters of the currently provided second identity factor to determine whether the unverified second identity factor matches the currently provided second identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-65, 73-80, 84-97, 101-108, 112-116, and associated figures; authenticate the above, for example); But does not appear to explicitly disclose that the one or more matrices comprise one or more rotated cube matrices. Chan, however, discloses that the one or more matrices comprise one or more rotated cube matrices (Exemplary Citations: for example, Abstract, Paragraphs 35-42, 44, 46, 49-54, and associated figures; authentication using cube corresponding to matrix(es) and rotations as well as selections there from, for example); and Wherein each of the generated one or more rotated cube matrices contains matrices of values associated with the characters of the currently provided first identity factor (Exemplary Citations: for example, Abstract, Paragraphs 35-42, 44, 46, 49-54, and associated figures; authentication using cube corresponding to matrix(es) and rotations as well as selections there from, for example). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the authentication via 3D object techniques of Chan into the authentication system of Sonkar in order to allow the system to use additional means for input, to provide for authentication via both rotations as well as selections, to provide additional authentication parameters, and/or to increase security in the system. Therefore, Sonkar as modified by Chan discloses the entirety of claim 1. Claim Objections Claims 24 and 26 are objected to because of the following informalities: Claim 24 is dependent on itself. For purposes of prior art rejection, claim 24 has been construed as being dependent from claim 23. Claim 26 is dependent on a non-existing claim. For purposes of prior art rejection, claim 26 has been construed as being dependent from claim 25. Appropriate correction is required. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1, 2, 6-10, 13-17, and 19-26 rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Regarding claim 1, with respect to step 1, this part of the eligibility analysis evaluates whether the claim falls within any statutory category. MPEP 2106.03. The claim recites a method comprising: receiving, in a matrix generator of an authentication system, characters of a currently provided first identity factor from a user system, generating, by the matrix generator, one or more rotated cube matrices using the characters of the currently provided first identity factor as an input parameter, wherein each of the generated one or more rotated cube matrices contains matrices of values associated with the characters of the currently provided first identity factor, receiving, by a validator of the authentication system, the characters of the currently provided first identity factor from the user system and the one or more rotated cube matrices from the matrix generator to generate characters for an unverified second identity factor, wherein to generate the characters for the unverified second identity factor comprises: deriving corresponding coordinate location values for the matrices of values associated with the characters of the currently provided first identity factor, the coordinate location values are associated with the characters of the currently provided first identity factor, subtracting a first set of predefined difference values from the derived coordinate location values to generate coordinate location values of a non-stored user key, wherein the coordinate location values of the non-stored user key are different from the coordinate location values associated with the characters of the currently provided first identity factor, adding a second set of predefined difference values to the coordinate location values of the non-stored user key to generate coordinate location values for characters of the unverified second identity factor, wherein the first and second set of predefined values are previously generated during a registration phase, for each one of the coordinate location values for the characters of the unverified second identity factor, locating in the one or more rotated cube matrices a corresponding value to identify matrices of values associated with characters of the unverified second identity factor, and converting the identified matrices of values associated with the characters of the unverified second identity factor to the characters of the unverified second identity factor, receiving, by the validator, characters of a currently provided second identity factor from the user system, and comparing, with the validator, the characters of the unverified second identity factor from the characters of the currently provided second identity factor to determine whether the unverified second identity factor matches the currently provided second identity factor. . Therefore, this claim appears to be a method, which is a statutory category of invention. Please see MPEP 2106.3.I: A process defines "actions", i.e., an invention that is claimed as an act or step, or a series of acts or steps. As explained by the Supreme Court, a "process" is "a mode of treatment of certain materials to produce a given result. It is an act, or a series of acts, performed upon the subject-matter to be transformed and reduced to a different state or thing." Gottschalk v. Benson, 409 U.S. 63, 70, 175 USPQ 673, 676 (1972) (italics added) (quoting Cochrane v. Deener, 94 U.S. 780, 788, 24 L. Ed. 139, 141 (1876)). See also Nuijten, 500 F.3d at 1355, 84 USPQ2d at 1501 ("The Supreme Court and this court have consistently interpreted the statutory term ‘process’ to require action"); NTP, Inc. v. Research in Motion, Ltd., 418 F.3d 1282, 1316, 75 USPQ2d 1763, 1791 (Fed. Cir. 2005) ("[A] process is a series of acts.") (quoting Minton v. Natl. Ass’n. of Securities Dealers, 336 F.3d 1373, 1378, 67 USPQ2d 1614, 1681 (Fed. Cir. 2003)). As defined in 35 U.S.C. 100(b), the term "process" is synonymous with "method." The other three categories (machines, manufactures and compositions of matter) define the types of physical or tangible "things" or "products" that Congress deemed appropriate to patent. Digitech Image Techs. v. Electronics for Imaging, 758 F.3d 1344, 1348, 111 USPQ2d 1717, 1719 (Fed. Cir. 2014) ("For all categories except process claims, the eligible subject matter must exist in some physical or tangible form."). Thus, when determining whether a claimed invention falls within one of these three categories, examiners should verify that the invention is to at least one of the following categories and is claimed in a physical or tangible form. • A machine is a "concrete thing, consisting of parts, or of certain devices and combination of devices." Digitech, 758 F.3d at 1348-49, 111 USPQ2d at 1719 (quoting Burr v. Duryee, 68 U.S. 531, 570, 17 L. Ed. 650, 657 (1863)). This category "includes every mechanical device or combination of mechanical powers and devices to perform some function and produce a certain effect or result." Nuijten, 500 F.3d at 1355, 84 USPQ2d at 1501 (quoting Corning v. Burden, 56 U.S. 252, 267, 14 L. Ed. 683, 690 (1854)). • A manufacture is "a tangible article that is given a new form, quality, property, or combination through man-made or artificial means." Digitech, 758 F.3d at 1349, 111 USPQ2d at 1719-20 (citing Diamond v. Chakrabarty, 447 U.S. 303, 308, 206 USPQ 193, 197 (1980)). As the courts have explained, manufactures are articles that result from the process of manufacturing, i.e., they were produced "from raw or prepared materials by giving to these materials new forms, qualities, properties, or combinations, whether by hand-labor or by machinery." Samsung Electronics Co. v. Apple Inc., 137 S. Ct. 429, 120 USPQ2d 1749, 1752-3 (2016) (quoting Diamond v. Chakrabarty, 447 U. S. 303, 308, 206 USPQ 193, 196-97 (1980)); Nuijten, 500 F.3d at 1356-57, 84 USPQ2d at 1502. Manufactures also include "the parts of a machine considered separately from the machine itself." Samsung Electronics, 137 S. Ct. at 435, 120 USPQ2d at 1753 (quoting 1 W. Robinson, The Law of Patents for Useful Inventions §183, p. 270 (1890)). • A composition of matter is a "combination of two or more substances and includes all composite articles." Digitech, 758 F.3d at 1348-49, 111 USPQ2d at 1719 (citation omitted). This category includes all compositions of two or more substances and all composite articles, "'whether they be the results of chemical union or of mechanical mixture, or whether they be gases, fluids, powders or solids.'" Chakrabarty, 447 U.S. at 308, 206 USPQ at 197 (quoting Shell Dev. Co. v. Watson, 149 F. Supp. 279, 280 (D.D.C. 1957); id. at 310 holding genetically modified microorganism to be a manufacture or composition of matter). With respect to step 2A, prong one, this part of the eligibility analysis evaluates whether the claim recites a judicial exception. As explained in MPEP 2106.04(II) and the October 2019 Update, a claim ‘recites’ a judicial exception when the judicial exception is ‘set forth’ or ‘described’ in the claim. There are no nature-based product limitations in the claim, and thus the markedly different characteristics analysis is not performed. However, the claim still must be reviewed to determine if it recites any other type of judicial exception. Claim 1 recites the following limitations that are directed to abstract ideas: A method comprising: Receiving, in a matrix generator of an authentication system, characters of a currently provided first identity factor from a user system (mental process and/or certain methods of organizing human activity and/or mathematical equation; mental process, a human being hearing a "first identity factor" spoken by a user, or reading it from paper, as examples); Generating, by the matrix generator, one or more rotated cube matrices using the characters of the currently provided first identity factor as an input parameter, wherein each of the generated one or more rotated cube matrices contains matrices of values associated with the characters of the currently provided first identity factor (mental process and/or certain methods of organizing human activity and/or mathematical equation; mental process, a human being mentally (or with pen and paper) generating a matrix of values based on received "first identity factor"); Receiving, by a validator of the authentication system, the characters of the currently provided first identity factor from the user system and the one or more rotated cube matrices from the matrix generator to generate characters for an unverified second identity factor, wherein to generate the characters for the unverified second identity factor comprises (mental process and/or certain methods of organizing human activity and/or mathematical equation; receiving the above, such as by hearing, reading from paper, or the like, as examples): Deriving corresponding coordinate location values for the matrices of values associated with the characters of the currently provided first identity factor, the coordinate location values are associated with the characters of the currently provided first identity factor (mental process and/or certain methods of organizing human activity and/or mathematical equation; math and/or a human performing some function (e.g., find the letter “b” on a piece of paper and see that it is associated with the number “10”), for example); Subtracting a first set of predefined difference values from the derived coordinate location values to generate coordinate location values of a non-stored user key, wherein the coordinate location values of the non-stored user key are different from the coordinate location values associated with the characters of the currently provided first identity factor (mental process and/or certain methods of organizing human activity and/or mathematical equation; math, easily performed by a human. Subtraction is taught in grade school, for example); Adding a second set of predefined difference values to the coordinate location values of the non-stored user key to generate coordinate location values for characters of the unverified second identity factor, wherein the first and second set of predefined values are previously generated during a registration phase (mental process and/or certain methods of organizing human activity and/or mathematical equation; math, easily performed by a human. Addition is taught in grade school, for example); For each one of the coordinate location values for the characters of the unverified second identity factor, locating in the one or more rotated cube matrices a corresponding value to identify matrices of values associated with characters of the unverified second identity factor (mental process and/or certain methods of organizing human activity and/or mathematical equation; lookup on a piece of paper, for example); and Converting the identified matrices of values associated with the characters of the unverified second identity factor to the characters of the unverified second identity factor (mental process and/or certain methods of organizing human activity and/or mathematical equation; reading, remembering, recalling, writing down, etc. of the values in the above lookup, for example); Receiving, by the validator, characters of a currently provided second identity factor from the user system (mental process and/or certain methods of organizing human activity and/or mathematical equation; receiving characters in any fashion, such as by hearing, reading, etc., as examples); and Comparing, with the validator, the characters of the unverified second identity factor from the characters of the currently provided second identity factor to determine whether the unverified second identity factor matches the currently provided second identity factor (mental process and/or certain methods of organizing human activity and/or mathematical equation; comparing in the mind, on paper, or via math, for example). As noted, these can be performed by a human either completely mentally or by using certain methods of organizing human activity, such as a human writing and reading via documentation or filing systems. As explained in the MPEP and the October 2019 Update, situations like this where a series of steps recite judicial exceptions, examiners should combine all recited judicial exceptions and treat the claim as containing a single abstract idea for purposes of further eligibility. See MPEP 2106.04 and 2106.05(ii). Thus, for purposes of further discussion, this rejection may consider all limitations as a single abstract idea. With respect to step 2A, prong two, this part of the eligibility analysis evaluates whether the claim as a whole integrates the recited judicial exception into a practical application of the exception. This evaluation is performed by (a) identifying whether there are any additional elements recited in the claim beyond the judicial exception, and (b) evaluating those additional elements individually and in combination to determine whether the claim as a whole integrates the exception into a practical application. 2019 PEG Section III(A)(2), 84 Fed. Reg. at 54-55. The independent claims recites no additional elements. However, if there were any additional elements, this/these additional element(s) is/are recited so generically (no details are provided other than generic functionality that can be performed by a human and/or in a mathematical equation) that it represents no more than mere instructions to apply the judicial exception on a computer system. This limitation can also be viewed as nothing more than an attempt to generally link the use of the judicial exception to the technological environment of a computer. It should be noted that because the courts have made clear that mere physicality or tangibility of an additional element or elements is not a relevant consideration in the eligibility analysis, the nature of these components being physical or tangible does not affect this analysis. See MPEP 2106.05(I) for more information on this point, including explanations from judicial decisions including Alice Corp. Pty. Ltd. V. CLS Bank Int’l, 573 U.S. 208, 224-26 (2014). Even when viewed in combination, any additional elements in this claim do no more than automate the abstract ideas that the human can perform, using computer components as a tool. There is no improvement to any computers or other technology achieved by the claim by automating the abstract ideas, and thus this claim cannot improve computer functionality or other technology. See, e.g., Trading Technologies Int’l v. IBG, Inc., 921 F.3d 1084, 1093 (Fed. Cir. 2019) (using a computer to provide a trader with more information to facilitate market trades improved the business process of market trading, but not the computer) and the cases discussed in MPEP 2106.05(a)(I), particularly FairWarning IP, LLC v. Iatric Sys., 839 F.3d 1089, 1095 (Fed. Cir. 2016) (accelerating a process of analyzing audit log data is not an improvement when the increased speed comes solely from the capabilities of a general-purpose computer) and Credit Acceptance Corp. v. Westlake Services, 859 F.3d 1044, 1055 (Fed. Cir. 2017)(using a generic computer to automate a process of applying to finance a purchase is not an improvement to the computer’s functionality). Accordingly, the claim as a whole does not integrate the recited judicial exception into a practical application and the claim is directed to the judicial exception. With respect to step 2B, this part of the eligibility analysis evaluates whether the claim as a whole amounts to significantly more than the recited exception, i.e., whether any additional element, or combination of additional elements, adds an inventive concept to the claim. MPEP 2106.05. As explained with respect to Step 2A Prong Two, the additional element(s) described above is/are at best the equivalent of merely adding the words “apply it” to the judicial exception. Mere instructions to apply an exception cannot provide an inventive concept. Any other additional elements identified above are extra-solution activity, which for purposes of Step 2A Prong Two was considered insignificant. Under the 2019 PEG, however, a conclusion that an additional element is insignificant extra-solution activity in Step 2A should be re-evaluated in Step 2B. 2019 PEG Section III(B), 84 Fed. Reg. at 56. At Step 2B, the evaluation of the insignificant extra-solution activity consideration takes into account whether or not the extra-solution activity is well-known. See MPEP 2106.05(g). Here, any insignificant extra solution activity is within the examples provided in USPTO guidance, such as MPEP 2106.05(g), for example. Thus, any subject matter that may be considered extra-solution activity therefore remain insignificant extra-solution activity even upon reconsideration, and do not amount to significantly more. Even when considered in combination, these additional elements represent mere instructions to apply an exception and insignificant extra-solution activity, which cannot provide an inventive concept. Similar to claim 1, claims 8 and 15 and all dependent claims are also rejected, even though there are some inherent (e.g., claims 6-7's "transmitting [results]") or explicit (claim 8's "user system", "client system", "authentication system", etc.) recitation of additional elements. None of them appear to be more than using computers as a tool to implement the abstract idea, and thus are simply instructions to apply an exception MPEP 2106.05(f), (2). The only post-solution activity recited appears to be claims 6-7 (and their equivalent) which is insignificant post solution activity, because it is simply presenting or transmitting results of the judicial exception (MPEP 2106.05(g)). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 2, 6-10, 13-17, and 19-26 are rejected under 35 U.S.C. 103 as being unpatentable over Sonkar (U.S. Patent Application Publication 2018/0285549) in view of Chan (U.S. Patent Application Publication 2016/0019382). Regarding Claim 1, Sonkar discloses a method comprising: Receiving, in a matrix generator of an authentication system, characters of a currently provided first identity factor from a user system (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-79, 84-92, 101-108, and associated figures; receiving any identity factor, such as account identifier, username, password, PIN, portion(s) of the above or many additional factors, etc., as examples); Generating, by the matrix generator, one or more matrices using the characters of the currently provided first identity factor as an input parameter, wherein each of the generated one or more matrices contains matrices of values associated with the characters of the currently provided first identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; generating layouts, positions, or the like, as well as using a one way function, such as a trapdoor function, as examples); Receiving, by a validator of the authentication system, the characters of the currently provided first identity factor from the user system and the one or more matrices from the matrix generator to generate characters for an unverified second identity factor, wherein to generate the characters for the unverified second identity factor comprises (It is noted that “to generate characters…” through all indented limitations as intended use and is not required by the claim. Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; receiving the above to be used in generating a position based on the keypad generated from the previous input, etc., for example): Deriving corresponding coordinate location values for the matrices of values associated with the characters of the currently provided first identity factor, the coordinate location values are associated with the characters of the currently provided first identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; generating a position based on the keypad generated from the previous input, etc., for example); Subtracting a first set of predefined difference values from the derived coordinate location values to generate coordinate location values of a non-stored user key, wherein the coordinate location values of the non-stored user key are different from the coordinate location values associated with the characters of the currently provided first identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; values in the matrix are changed by a predefined difference value, for example. It is noted that adding and subtracting may occur in any variety of steps. For example, adding 1 and subtracting 2 results in a single subtraction of 1. Thus, any single addition or subtraction also meets both the subtracting and adding limitations and both are intended use and are not required by the claim as well); Adding a second set of predefined difference values to the coordinate location values of the non-stored user key to generate coordinate location values for characters of the unverified second identity factor, wherein the first and second set of predefined values are previously generated during a registration phase (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; values in the matrix are changed again by a predefined difference value, for example); For each one of the coordinate location values for the characters of the unverified second identity factor, locating in the one or more matrices a corresponding value to identify matrices of values associated with characters of the unverified second identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; finding the correct matrix location, for example); and Converting the identified matrices of values associated with the characters of the unverified second identity factor to the characters of the unverified second identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures); Receiving, by the validator, characters of a currently provided second identity factor from the user system (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; receiving second input either via keypad or via position, for example); and Comparing, with the validator, the characters of the unverified second identity factor from the characters of the currently provided second identity factor to determine whether the unverified second identity factor matches the currently provided second identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-65, 73-80, 84-97, 101-108, 112-116, and associated figures; authenticate the above, for example); But does not appear to explicitly disclose that the one or more matrices comprise one or more rotated cube matrices. Chan, however, discloses that the one or more matrices comprise one or more rotated cube matrices (Exemplary Citations: for example, Abstract, Paragraphs 35-42, 44, 46, 49-54, and associated figures; authentication using cube corresponding to matrix(es) and rotations as well as selections there from, for example); and Wherein each of the generated one or more rotated cube matrices contains matrices of values associated with the characters of the currently provided first identity factor (Exemplary Citations: for example, Abstract, Paragraphs 35-42, 44, 46, 49-54, and associated figures; authentication using cube corresponding to matrix(es) and rotations as well as selections there from, for example). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the authentication via 3D object techniques of Chan into the authentication system of Sonkar in order to allow the system to use additional means for input, to provide for authentication via both rotations as well as selections, to provide additional authentication parameters, and/or to increase security in the system. Regarding Claim 8, Claim 8 is a system claim that corresponds to method claim 1 and is rejected or the same reasons. In addition, claim 8 includes a client system of an entity comprising one or more computing devices, the client system being communicatively coupled to the user system via a computer network, found in Sonkar (Exemplary Citations: for example, Figure 1 and associated written description, as well as all below citations; this may be the computing device, VR application server, or the like, as examples), for example. The user system and authentication system are already part of claim 1, however, Sonkar also discloses a user system comprising one or more computing devices operable to receive identity factors from a user (Exemplary Citations: for example, Figure 1 and associated written description, as well as all below citations; this may be the VR device, for example); and An authentication system comprising one or more processors and storage devices being communicatively coupled to the user system and the client system via the computer network, wherein the authentication system is (Exemplary Citations: for example, Figure 1 and associated written description, as well as all below citations; this may be the VR application server, transaction processing computer, authorizing computer, etc., as examples). Regarding Claim 15, Claim 15 is a method claim that corresponds to method claim 1 and is rejected for the same reasons. In addition, claim 15 includes a step of providing an authentication system comprising one or more processors and storage devices being communicatively coupled to a user system and a client system via a computer network, found in Sonkar (Exemplary Citations: for example, Figure 1 and associated written description, as well as all below citations; this may be the VR application server, transaction processing computer, authorizing computer, etc., as examples), for example. Regarding Claim 2, Sonkar as modified by Chan discloses the method of claim 1, in addition, Sonkar discloses that generating, by the matrix generator, one or more matrices using the characters of the currently provided first identity factor as an input parameter comprises producing a result (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; result of the above, for example); and Chan discloses that generating, by the matrix generator, one or more rotated cube matrices using the characters of the currently provided first identity factor as an input parameter comprises producing a series of rotations for the one or more rotated cube matrices, wherein the matrices of values represents faces of the one or more rotated cube matrices (Exemplary Citations: for example, Abstract, Paragraphs 35-42, 44, 46, 49-54, and associated figures; authentication using cube corresponding to matrix(es) and rotations as well as selections there from, for example). Regarding Claim 6, Sonkar as modified by Chan discloses the method of claim 1, in addition, Sonkar discloses in response to determining that the unverified second identity factor matches the currently provided second identity factor, transmitting a valid authentication response to the user system (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-65, 73-80, 84-97, 101-108, 112-116, and associated figures; authentication response, for example ). Regarding Claim 13, Claim 13 is a system claim that corresponds to method claim 6 and is rejected for the same reasons. Regarding Claim 16, Claim 16 is a method claim that corresponds to method claim 6 and is rejected for the same reasons. Regarding Claim 7, Sonkar as modified by Chan discloses the method of claim 1, in addition, Sonkar discloses in response to determining that the unverified second identity factor does not match the currently provided second identity factor, transmitting an invalid authentication response to the user system (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-65, 73-80, 84-97, 101-108, 112-116, and associated figures; decline result, for example). Regarding Claim 14, Claim 14 is a system claim that corresponds to method claim 7 and is rejected for the same reasons. Regarding Claim 17, Claim 17 is a method claim that corresponds to method claim 7 and is rejected for the same reasons. Regarding Claim 9, Sonkar as modified by Chan discloses the system of claim 8, in addition, Sonkar discloses that the characters of the currently provided first identity factor comprises a password or biometric data of the user (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-79, 84-92, 101-108, and associated figures). Regarding Claim 10, Sonkar as modified by Chan discloses the system of claim 8, in addition, Sonkar discloses that the client system becomes accessible to the user system after the authentication system determines that the unverified second identity factor matches the currently provided second identity factor (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-65, 73-80, 84-97, 101-108, 112-116, and associated figures; transaction proceeds, for example). Regarding Claim 19, Sonkar as modified by Chan discloses the method of claim 15, in addition, Sonkar discloses that receiving the characters of the currently provided first identity factor comprises collecting biometric data from the user system (Exemplary Citations: for example, Abstract, Paragraphs 20, 21, 51, 52, 58-60, 65, 73-79, 84-92, 101-108, 121, and associated figures; eyes, eye movements, motion detection, etc., as examples). Regarding Claim 20, Sonkar as modified by Chan discloses the method of claim 15, in addition, Sonkar discloses that receiving the characters of the currently provided first identity factor comprises receiving a password from the user system (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-79, 84-92, 101-108, and associated figures). Regarding Claim 21, Sonkar as modified by Chan discloses the method of claim 1, in addition, Sonkar discloses that prior to receiving, in the matrix generator of the authentication system, the characters of the currently provided first identity factor, generating an unverified user key at least based on a username provided by the user system, the non-stored user key compared to the unverified user key (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-79, 84-92, 101-108, and associated figures; receiving any identity factor, such as account identifier, username, as examples). Regarding Claim 23, Claim 23 is a system claim that corresponds to method claim 21 and is rejected for the same reasons. Regarding Claim 25, Claim 25 is a method claim that corresponds to method claim 21 and is rejected for the same reasons. Regarding Claim 22, Sonkar as modified by Chan discloses the method of claim 21, in addition, Sonkar discloses that the username is provided during the registration phase (Exemplary Citations: for example, Abstract, Paragraphs 21, 51, 52, 58-60, 65, 73-80, 84-97, 101-108, 112-116, and associated figures; username or account identifier provided during registration, for example). Regarding Claim 24, Claim 24 is a system claim that corresponds to method claim 22 and is rejected for the same reasons. Regarding Claim 26, Claim 26 is a method claim that corresponds to method claim 22 and is rejected for the same reasons. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Jeffrey D Popham whose telephone number is (571)272-7215. The examiner can normally be reached Monday through Friday 9:00-5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Jeffrey D. Popham/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Show 10 earlier events
Sep 17, 2024
Examiner Interview Summary
Nov 25, 2024
Response after Non-Final Action
Nov 25, 2024
Response Filed
Apr 02, 2025
Response Filed
Apr 02, 2025
Response after Non-Final Action
Jul 10, 2025
Response after Non-Final Action
Jul 10, 2025
Response Filed
Aug 07, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730884
SYSTEMS AND METHODS FOR INTELLIGENT CONFIGURATION AND DEPLOYMENT OF ALERT SUPPRESSION PARAMETERS IN A CYBERSECURITY THREAT DETECTION AND MITIGATION PLATFORM
3y 5m to grant Granted Sep 08, 2026
Patent 12671985
ACCESS AND MOBILITY MANAGEMENT FUNCTION RELOCATION DUE TO SECURITY GATEWAY OVERLOAD/FAILURE
3y 10m to grant Granted Jun 30, 2026
Patent 12481750
A METHOD OF PROCESSING TRANSACTIONS FROM AN UNTRUSTED SOURCE
5y 2m to grant Granted Nov 25, 2025
Patent 12425407
Identity And Access Management Using A Decentralized Gateway Computing System
2y 10m to grant Granted Sep 23, 2025
Patent 12380240
PROTECTING SENSITIVE DATA IN DOCUMENTS
4y 10m to grant Granted Aug 05, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

6-7
Expected OA Rounds
38%
Grant Probability
62%
With Interview (+24.0%)
4y 7m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 474 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month