Prosecution Insights
Last updated: August 16, 2026
Application No. 17/591,444

LINKING OF COMMUNICATIONS DEVICE SUBSCRIBER IDENTIFIERS FOR FRAUD DETECTION

Non-Final OA §102§103
Filed
Feb 02, 2022
Examiner
DHAKAD, RUPALI
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Prove Identity Inc.
OA Round
5 (Non-Final)
37%
Grant Probability
At Risk
5-6
OA Rounds
0m
Est. Remaining
67%
With Interview

Examiner Intelligence

Grants only 37% of cases
37%
Career Allowance Rate
13 granted / 35 resolved
-20.9% vs TC avg
Strong +30% interview lift
Without
With
+30.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
23 currently pending
Career history
75
Total Applications
across all art units

Statute-Specific Performance

§101
15.1%
-24.9% vs TC avg
§103
58.2%
+18.2% vs TC avg
§102
7.8%
-32.2% vs TC avg
§112
18.0%
-22.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 35 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claims 1, 3-11, 20-22, 24-29 are pending. Claims 1, 3, 4, 11, 20, 21, 22, 28, 29 are amended. Claims 2, 12-19, 23 and 30-35 are cancelled. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 04/03/2026 has been entered. Response to Arguments Applicant’s arguments with respect to claim(s) 1, 3-4, 11, 20, 22, 29 rejected under 35 U.S.C. 102 (a)(1) have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Regarding independent claim 1: Applicant’s Argument on page 8-12: “The cited portions of Larkin do not teach, suggest, or disclose (i) obtaining one or more subscriber identifiers previously or subsequently assigned to a communications device or (ii) determining whether at least one of the one or more subscriber identifiers previously or subsequently assigned to the communications device is suspected of participating in a fraudulent transaction, as recited in claim 1….” In response, applicant’s argument with respect to limitation of “(i) obtaining one or more IMSI numbers that were previously or subsequently assigned to a mobile phone and (ii) determining whether at least one IMSI number previously or subsequently assigned to the communications device is suspected of participating in a fraudulent transaction” is moot in view of a new ground of rejection. Applicant’s argument with respect to amended limitation of claim 1 is moot in view of a new ground of rejection. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 3-4, 11, 20, 22, 29 are rejected under 35 U.S.C. 103 as being unpatentable over Larkin (U. S. PGPub.No. 2015/0038120 A1) (hereinafter “Larkin”), and further in view of Descombes et al. (U. S. PGPub. No. 2007/0275718 A1) (hereinafter “Descombes”) Regarding claim 1, Larkin teaches: A method to detect and/or prevent fraud that involves a communications device (Larkin: Abstract, “A method and a system are provided within a wireless network, for preventing fraudulent use of a Mobile Subscriber Integrated Services Digital Network Number (MSISDN) of a mobile phone terminal user”), comprising: transmitting, from a client computing resource to an authenticator, a subscriber identifier suspected of participating in a first fraudulent transaction (Larkin: [0075] obtaining the IMSI currently associated with the MSISDN in the wireless network in reply to the MAP request; [0076] comparing the obtained IMSI with the stored IMSI for the extracted MSISDN. [0081] In an embodiment of the invention, the method may comprise the further step of generating an alarm if the obtained IMSI does not match the stored IMSI for the extracted MSISDN. In a variant of this embodiment, the method may comprise the further step of automatically querying the provider if the obtained IMSI does not match the stored IMSI for the extracted MSISDN); responsive to determining that at least one of the one of the one or more subscriber identifiers previously or subsequently assigned to the communications device is suspected of participating in the second fraudulent transaction (Larkin: [0127] The invention thus provides a method of detecting whether the International Mobile Subscriber Identity (IMSI) number attached to a Mobile Subscriber Integrated Services Digital Network Number (MSISDN) has changed for a subscriber or not. [0128] The SIM Takeover Protection system can determine if the IMSI of a Mobile number (MSISDN) has changed for a mobile subscriber and therefore whether the Mobile number (MSISDN) has been potentially compromised. [0207] 5. If there is NO entry in the table for the query above, then perform a second query (=second fraudulent transaction) to see if there is an entry for the MSISDN and the Org_ID (using the alternate key) exists. [0208] 6. If the second query on the MSISDN and Org-ID returns any data (meaning there is an entry for the MSISDN, but with a different IMSI), the system will do the following…),alerting the client computing resource (Larkin: [0146], The Alarm will indicate to the user (e.g. a service provider like a bank or credit card company) that the user should be contacted to verify the IMSI change. [0214] 7. If there is a change to the IMSI for an MSISDN, then write all the info to the IMSI Alarm Table and update the Alarm time stamp details. The system would also set the "MSISDN Potentially Compromised" column to TRUE). Larkin does not explicitly disclose: and obtaining, from the authenticator, one or more subscriber identifiers previously or subsequently assigned to the communications device by a communication services carrier; determining whether at least one of the one or more subscriber identifiers previously or subsequently assigned to the communications device is suspected of participating in a second fraudulent transaction; determining that the first subscriber identifier was assigned to the communications device;; further responsive to determining that at least one of the one or more subscriber identifiers previously or subsequently assigned to the communications device is suspected of participating in the second fraudulent transaction, designating the first subscriber identifier as being fraudulent; wherein the first subscriber identifier was assigned to the communications device at a first time; wherein the one or more subscriber identifiers previously or subsequently assigned to the communications device include a second subscriber identifier that was assigned to the communications device at a second time, the second time occurring before the first time; and wherein the one or more subscriber identifiers previously or subsequently assigned to the communications device include a third subscriber identifier that was assigned to the communications device at a third time, the third time occurring after the first time. However, in an analogous art, Descombes teaches: and obtaining, from the authenticator, one or more subscriber identifiers previously or subsequently assigned to the communications device by a communication services carrier (Descombes: [0046], the connection history database 206 may include additional details associated with each IMEI/IMSI pair. For example, the connection history database 206 may be arranged to permanently store the earliest recorded connection attempt for each IMEI/IMSI pair… the network operator can supply details of this first known pairing to the database 206 in any suitable manner) determining whether at least one of the one or more subscriber identifiers previously or subsequently assigned to the communications device is suspected of participating in a second fraudulent transaction (Descombes: [0054] For example, if it is determined that a connecting IMSI/IMEI pair is connecting from Paris, but that the previous connection (=previous connected subscriber identifier) attempt was from New York, it can be assumed that one of the IMSI/IMEI pairs includes a cloned identifier if the time difference between the two connection attempts is less than that required to travel from Paris to New York) determining that the first subscriber identifier was assigned to the communications device (Descombes: [0032] To determine whether the connecting IMEI has been cloned the connection history database 206 is searched (step 310) to determine whether the connecting IMEI has previously attempted to connect to the network with an IMSI other than the connecting IMSI. If the connecting IMEI has only ever been connected to the network with the connecting IMSI this indicates that it is unlikely that the connecting IMEI has been cloned (step 320)); further responsive to determining that at least one of the one or more subscriber identifiers previously or subsequently assigned to the communications device is suspected of participating in the second fraudulent transaction (Descombes: [0051], , it is determined that a cloned IMSI 1 is detected paired with IMEI 2, it can be fairly assumed that the pairing IMSI 1 with IMEI 2 is fraudulent, since the earliest recorded connection attempt stored in the connection history database shows that IMSI 1 was first paired with IMEI 1) designating the first subscriber identifier as being fraudulent (Descombes: [0055], The fraud management system may take any appropriate action such as signalling an alarm (=designating=flagging), disconnecting or causing the cloned IMEI or cloned IMSI to be refused connection to the network or disconnected from the network as appropriate, and the like) wherein the first subscriber identifier was assigned to the communications device at a first time (Descombes: [0027], determining whether an IMEI or an IMSI has been cloned. At step 304 the connecting IMEI/IMSI pair, IMEI 1 and IMSI 1, along with the current timestamp, T.sub.6, are stored in the connection history database 206 (see Table 1) (Examiner’s Note: [Table 1], provides pairing of IMEI with IMSI connected with each other previously. Table 1 extract of the connection history database 206)); wherein the one or more subscriber identifiers previously or subsequently assigned to the communications device include a second subscriber identifier that was assigned to the communications device at a second time, the second time occurring before the first time (Descombes: [0051], it is determined that a cloned IMSI 1 is detected paired with IMEI 2, it can be fairly assumed that the pairing IMSI 1 with IMEI 2 is fraudulent, since the earliest recorded connection attempt stored in the connection history database shows that IMSI 1 was first paired with IMEI 1. (Examiner’s Note: [Table 1], provides pairing of IMEI with IMSI connected with each other previously. Table 1 extract of the connection history database 206); and wherein the one or more subscriber identifiers previously or subsequently assigned to the communications device include a third subscriber identifier that was assigned to the communications device at a third time, the third time occurring after the first time (Descombes: [0050], when in the above example it is determined that a cloned IMEI 1 is detected paired with IMSI 4 using the connection history database 206 it can be determined that the first entry for the IMEI 1 was with IMSI 1 at T.sub.0. Thus, it can be reasonable assumed that the pairing IMEI 1 with IMSI 4 is fraudulent and that it is this pairing that uses the cloned IMEI 1. (Examiner’s Note: [Table 1], provides pairing of IMEI with IMSI connected with each other previously. Table 1 extract of the connection history database 206)). It would be obvious to a person having ordinary skill in the art, before the effective filing date of the invention, to modify Larson’s method of verify the IMSI change. [0214] 7. If there is a change to the IMSI for an MSISDN and alarming user that MSISDN Potentially Compromised by applying Descombes’s method of determining if IMEI/IMSI is cloned and determined if IMSI-IMEI pair containing cloned identifier, in order to detect fraudulent use of the communication device (Descombes: [0011]). Regarding claim 3, the Larkinin view of Descombes teaches: The method of claim 1 (see rejection of claim 1 above), wherein the subscriber identifiers previously or subsequently assigned to the communications device comprise an International Mobile Equipment Identifier (IMEI) or an Integrated Circuit Card Identification (ICC ID) Number (Larkin: [0265], [0265] The IMEI/ICCID/MEID can identify the make and model of a phone, which can be used to identify the truthfulness of a new customer, where the customer is asked to enter the make and model of their phone. [0274] Fraudster Uses Many SIM Cards with the same mobile phone terminal, since such terminals are expensive, whereas SIM Cards are not. Fraudsters tend to change numbers frequently in order to deceive. The service can usefully detect patterns of repeated use of a same IMEI/ICCID/MEID with multiple IMSIs, and isolate communication accordingly) Regarding claim 4, the Larkin in view of Descombes teaches: The method of claim 1 (see rejection of claim 1 above), wherein the one or more subscriber identifiers previously or subsequently assigned to the communication device comprise at least one telephone number of a chain of telephone numbers that has been modified via a change to a Mobile Station International Subscriber Directory Number (MSISDN) of the communications device (Larkin: [0274] Fraudster Uses Many SIM Cards with the same mobile phone terminal, since such terminals are expensive, whereas SIM Cards are not. Fraudsters tend to change numbers frequently in order to deceive. The service can usefully detect patterns of repeated use of a same IMEI/ICCID/MEID with multiple IMSIs, and isolate communication accordingly. [0216], A Statistics Server will record and log all statistics in the database or relevant files on the files system. The Statistics Server will record statistics about, but is not limited to, the number of IMSI lookups performed, successful IMSI lookups, failed IMSI lookups, number of IMSI changes (=a chain of telephone numbers that has been modified), etc.) Regarding claim 11, the Larkin in view of Descombes teaches: The method of claim 1, (see rejection of claim 1 above), receiving, via a user interface to a web browser, the first subscriber identifier suspected of participating in the first fraudulent transaction (Larkin: [0044] That number is a unique identifier for the phone itself. The attackers are using code injection to show users a prompt from their online banking site asking them to enter their IMEI numbers (=examiner is interpreting that this processing is happening via user interface to the web browser) in order to access their accounts. Once the attackers have the IMEI number, they then call the victim's carrier and report the phone lost or stolen and ask for a new SIM card. With that in hand, the attackers then receive the one-time passwords meant for the victim for her bank account and the victim is then relieved of her money. Regarding claim 20, Larkin teaches: a non-transitory computer-readable media having instructions encoded thereon which, responsive to execution of the encoded instructions by a computer processor, of a communications device, coupled to at least one memory device, direct the computer processor to (Larkin: [0175] A typical hardware architecture of the mobile telephone handset 301 of the example is shown in FIG. 4 in further detail, by way of non-limitative example. The handset 301 firstly includes a data processing unit 401, for instance a general-purpose microprocessor (`CPU`), acting as the main controller of the handset 301 and which is coupled with memory means 402, comprising non-volatile random-access memory (`NVRAM`), either permanently embedded within the terminal or in the form of a removable data storage medium such as an SD or mini-SD card, or both). This claim contains identical limitations found within that of claim 1 above albeit directed to a different statutory category (non-transitory medium). For this reason, the same grounds of rejection are applied to claim 20. Regarding claim 22, the Larkin in view of Descombes teaches: a processor coupled to at least one memory device to (Larkin: [0175] A typical hardware architecture of the mobile telephone handset 301 of the example is shown in FIG. 4 in further detail, by way of non-limitative example. The handset 301 firstly includes a data processing unit 401, for instance a general-purpose microprocessor (`CPU`), acting as the main controller of the handset 301 and which is coupled with memory means 402, comprising non-volatile random-access memory (`NVRAM`), either permanently embedded within the terminal or in the form of a removable data storage medium such as an SD or mini-SD card, or both): This claim contains identical limitations found within that of claim 1 above albeit directed to a different statutory category (apparatus medium). For this reason, the same grounds of rejection are applied to claim 22. Regarding claim 29, this claim contains identical limitations found within that of claim 11 above albeit directed to a different statutory category (apparatus medium). For this reason, the same grounds of rejection are applied to claim 29. Claims 5 and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Larkin (U. S. PGPub. No. 2015/0038120 A1) (hereinafter “Larkin”) in view of Descombes et al. (US. PGPub. No. 2007/0275718 A1) (hereinafter “Descombes”); and further in view of MANEPALLI et al (U. S. PGPub. No. 2020/0245142 A1) (hereinafter “Manepalli”) Regarding claim 5, the Larkin in view of Descombes teaches: The method of claim 1 (see rejection of claim 1 above), Larkin in view of Descombes does not explicitly teach: obtaining from the authenticator a measure of velocity or a measure of frequency of changes to the one or more subscriber identifiers previously or subsequently assigned to the communications device by the communication services carrier However, in an analogous art, Manepalli teaches: obtaining from the authenticator a measure of velocity or a measure of frequency of changes to the one or more subscriber identifiers being previously or subsequently assigned to the communications device by the communication services carrier (Manepalli :[0037],Application server 130 then determines a risk indicator for the specified mobile number 201 based on device history information 305 received from device history server 150. In some embodiments, examples of such risk factors include a recent change from one mobile device ID 202 to another mobile device ID 202 that is associated with the mobile number 201; a recent change from one SIM card ID 204 to another SIM card ID 204 that is associated with the mobile number 201; a high frequency of changes (=a measure of frequency of changes ) in mobile device ID 202 and/or SIM card ID 204 associated with the mobile number 201, and the like). A person having ordinary skill in the art, before the effective filing date of the invention, would have found it obvious to modify Larkin in view of Descombes by applying the well-known technique as disclosed by Manepalli ‘s method of obtaining frequency of changes in mobile device ID/SIM card ID. The motivation is to detect fraudulent users within a telecommunication network (Manepalli: [0004]). Regarding claim 24, this claim contains identical limitations found within that of claim 5 above albeit directed to a different statutory category (apparatus medium). For this reason, the same grounds of rejection are applied to claim 24. Claim(s) 6-7, 9-10, 25-26, 28 are rejected under 35 U.S.C. 103 as being unpatentable over Larkin (U. S. PGPub. No. 2015/0038120 A1) (hereinafter “Larkin”) in view of Descombes et al. (US. PGPub. No. 2007/0275718 A1) (hereinafter “Descombes”), MANEPALLI et al (U. S. PGPub. No. 2020/0245142 A1) (hereinafter “Manepalli”); and further in view of KOGANTI et al (U. S. PGPub. No. 2017/0329966 A1) (hereinafter “Koganti”) Regarding claim 6, the Larkin in view of Descombes, Manepalli teaches: The method of claim 5 (see rejection of claim 5 above), The above cited combination of Larkin in view of Descombes, Manepalli does not explicitly teaches: obtaining a trust score; and a reliability metric that qualifies the trust score from the authenticator based, at least in part, on the authenticator and either the measure of velocity or the measure of frequency of changes to the MSISDN of the communications device authenticator. However, in an analogous art, Koganti teaches: obtaining a trust score (Koganti: [0051], The security threat information of the scoring service 345 may include the trust score. [0052], The device trust score may indicate a trust associated with the electronic device 11 itself. Violations and/or changes of the design and/or intended use of the electronic device 11 may affect the trust score in a manner indicative of a reduction in the trustworthiness of the device with regard to security….The relative amount of change to the device trust score may depend on the detected threat. For example, a detected virus may result in a larger change in the device trust score than detected adware as the device may be more vulnerable to data theft and be less secure in the presence of the virus than in the presence of the adware) and a reliability metric that qualifies the trust score from the authenticator based, at least in part, on the authenticator and either the measure of velocity or the measure of frequency of changes to the MSISDN of the communications device authenticator (Koganti: [0043], In a further example, the network connection service 325 may indicate a level of trust (=reliability matric) for the network connected to the electronic device 11 via the network connection service 325. [0052], Violations and/or changes of the design and/or intended use of the electronic device 11 may affect the trust score in a manner indicative of a reduction in the trustworthiness of the device with regard to security.) A person having ordinary skill in the art, before the effective filing date of the invention, would have found it obvious to modify Larkin in view of Descombes, Manepalli by applying the well-known technique as disclosed by Koganti’s method of computing trust score of electronic device, in order to determining the trustworthiness of the electronic device based on the trust score of the electronic device. Regarding claim 7, the Larkin in view of Descombes, Manepalli and Koganti teaches: The method of claim 6 (see rejection of claim 6 above), wherein the obtained trust score corresponds to a quantity computed utilizing deterministic behaviors with respect to the communications device (Koganti: [0052], Violations and/or changes of the design and/or intended use of the electronic device 11(=deterministic behavior) may affect the trust score in a manner indicative of a reduction in the trustworthiness of the device with regard to security. The relative amount of change to the device trust score may depend on the detected threat. For example, a detected virus may result in a larger change in the device trust score than detected adware as the device may be more vulnerable to data theft and be less secure in the presence of the virus than in the presence of the adware). A person having ordinary skill in the art, before the effective filing date of the invention, would have found it obvious to modify Larkin in view of Descombes, Manepalli by applying the well-known technique as disclosed by Koganti’s method of computing trust score of electronic device, in order to determining the trustworthiness of the electronic device based on the trust score of the electronic device. Regarding claim 9, Larkin in view of Descombes, Manepalli and Koganti teaches: The method of claim 6 (see rejection of claim 6 above), wherein the reliability metric corresponds to the measure of velocity or the measure of frequency with which the one or more subscriber identifiers were previously or subsequently assigned to the communications device by the communication services carrier (Koganti: [0043], In a further example, the network connection service 325 may indicate a level of trust (=reliability matric) for the network connected to the electronic device 11 via the network connection service 325. [0052], Violations and/or changes of the design and/or intended use of the electronic device 11 may affect the trust score in a manner indicative of a reduction in the trustworthiness of the device with regard to security. ) A person having ordinary skill in the art, before the effective filing date of the invention, would have found it obvious to modify Larkin in view of Descombes, Manepalli by applying the well-known technique as disclosed by Koganti’s method of computing trust score of electronic device, in order to determining the trustworthiness of the electronic device based on the trust score of the electronic device. Regarding claim 10, Larkin in view of Descombes, Manepalli and Koganti teaches: The method of claim 9 (see rejection of claim 9 above), designating for monitoring one or more of a currently-assigned subscriber identifier (Descombes: [0055], The fraud management system may take any appropriate action such as signalling an alarm (=designating=flagging), disconnecting or causing the cloned IMEI or cloned IMSI to be refused connection to the network or disconnected from the network as appropriate, and the like) and the one or more subscriber identifiers previously or subsequently assigned to the communications device, based at least in part on the reliability metric being less than a threshold (Koganti: [0043], In a further example, the network connection service 325 may indicate a level of trust (=reliability matric) for the network connected to the electronic device 11 via the network connection service 325. [0052], Violations and/or changes of the design and/or intended use of the electronic device 11 may affect the trust score in a manner indicative of a reduction in the trustworthiness of the device with regard to security. [0066] The scoring service 345 may compare the trust scores to one or more trust score thresholds and/or to one or more security policies. The trust score thresholds may correspond to the trust score (i.e., a device trust score threshold for the device trust score. [0073], Perfect device health may correspond to a trust score with no changes due to detected threats. Thus, in reference to the scoring example of Table 1, the perfect device health may correspond to a trust score of 100. One or more security policies may designate a first trust score range corresponding to good health and a second trust score range corresponding to bad health. For example, a trust score above a particular threshold may correspond to good health and a trust score below the particular threshold may correspond to bad health). A person having ordinary skill in the art, before the effective filing date of the invention, would have found it obvious to modify Larkin in view of Descombes, Manepalli by applying the well-known technique as disclosed by Koganti’s method of computing trust score of electronic device, in order to determining the trustworthiness of the electronic device based on the trust score of the electronic device. Regarding claim 25, this claim contains identical limitations found within that of claim 6 above albeit directed to a different statutory category (apparatus medium). For this reason, the same grounds of rejection are applied to claim 25. Regarding claim 26, this claim contains identical limitations found within that of claim 7 above albeit directed to a different statutory category (apparatus medium). For this reason, the same grounds of rejection are applied to claim 26. Regarding claim 28, this claim contains identical limitations found within that of claim 10 above albeit directed to a different statutory category (apparatus medium). For this reason, the same grounds of rejection are applied to claim 28. Claim 21 is rejected under 35 U.S.C. 103 as being unpatentable over Larkin (U. S. PGPub. No. 2015/0038120 A1) (hereinafter “Larkin”) in view of Descombes et al. (US. PGPub. No. 2007/0275718 A1) (hereinafter “Descombes”); and further in view of Asveren (U. S. Pat No. 9, 736, 130 B1) (hereinafter (“Asveren”). Regarding claim 21, the Larkin in view of Descombes teaches: The method of claim 20 (see rejection of claim 20 above), The above cited combination of Larkin in view of Descombes does not disclose: initiate a web browser-based session with the client computing resource prior to directing the computer processor to transmit the first subscriber identifier to the authenticator. However, Asveren teaches: initiate a web browser-based session with the client computing resource prior to directing the computer processor to transmit the first subscriber identifier to the authenticator (Asveren: [Col 11, lines 9-18, provides for, in step 324, the communications device communicates with a session border controller exchanging call control signaling to establish a call. Step 324 includes step 326 in which the communications device sends a signal, e.g., to the SBC, to initiate a call, said signal including said call authorization token. In some embodiments, the signal to initiate a call is an invite message, e.g., a SIP INVITE message, including information identifying the party to which the call is directed and the issued call authorization token). A person having ordinary skill in the art, before the effective filing date of the invention, would have found it obvious to modify Larkin in view of Descombes by applying the well-known technique as disclosed by Asveren of establishing/initiate a call between calling party and called party in order to communicate between two parties. The motivation is to protect the call center infrastructure in the legacy SIP domain from excessive call rates (Asveren: [Col 1, lines 40-41). Claim 8 and 27 are rejected under 35 U.S.C. 103 as being unpatentable over Larkin (U. S. PGPub. No. 2015/0038120 A1) (hereinafter “Larkin”) in view of Descombes et al. (US. PGPub. No. 2007/0275718 A1) (hereinafter “Descombes”), MANEPALLI et al (U. S. PGPub. No. 2020/0245142 A1) (hereinafter “Manepalli”) and KOGANTI et al (U. S. PGPub. No. 2017/0329966 A1) (hereinafter “Koganti”); and in further view of Snell et al (U. S. PGPub. No. 2022/0012743 A1) (hereinafter “Snell”) Regarding claim 8, the Larkin in view of Descombes, Manepalli and Koganti teaches: The method of claim 7 (see rejection of claim 7 above), The Larkin in view of Descombes, Manepalli and Koganti does not expliclty disclose: wherein the deterministic behaviors with respect to the communications device includes one or more of communications device tenure, removal and/or replacement of a subscriber identity module (SIM) of the communications device, use of a one- time code to reset an account password of the communications device, and recent porting of a telephone number corresponding to the communications device. However, in an analogous art, Snell teaches: wherein the deterministic behaviors with respect to the communications device (Snell: [0017] FIG. 5A is a diagram representing example behavior factors, which may be utilized by a customer service representative to authenticate the identity of a transacting party) includes one or more of communications device tenure, removal and/or replacement of a subscriber identity module (SIM) of the communications device (Snell: [0074], removal/replacement of a SIM (e.g., SIM-swap in FIG. 5A) may be indicative of transacting party 230 attempting to fraudulently register a telephone number belonging to a different subscriber of a mobile communications device services provider. Field 520 of FIG. 5A additionally includes an indication of phone tenure, which may provide an indication of a duration during which transacting party 230 has owned/operated communications device 102. As shown in FIG. 5A communications device 102 has not undergone a removal/replacement of a SIM for at least one year. Further, transacting party 230 has owned and/or operated (e.g., tenure) communications device 102 for at least one year), use of a one-time code to reset an account password of the communications device, and recent porting of a telephone number corresponding to the communications device (Snell: [0037], Such risk events may include, but are not limited to, recent porting of a subscriber account identifier (e.g., a telephone number)(=recent porting telephone number) associated with a communications device, recent replacement of a communications device, a recent request of a one-time-password (=one-time code) associated with a communications device, removal/replacement of a SIM of a communications device, as well as any number of additional risk events associated with the device) A person having ordinary skill in the art, before the effective filing date of the invention, would have found it obvious to modify Larkin in view of Descombes, Manepalli and Koganti by applying the well-known technique as disclosed by Snell of providing behavior factors associated with a communication device in order to authenticate the identity of a transacting party. The motivation is to reduce the instances of fraud and deception, various fraud-protection processes (Snell: [0003]). Regarding claim 27, this claim contains identical limitations found within that of claim 8 above albeit directed to a different statutory category (apparatus medium). For this reason, the same grounds of rejection are applied to claim 27. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Refer to PTO-892, Notice of References Cited for a listing of analogous art. Boursier et al. (U. S. PGPub. No. 2007/0142086 A1): A mobile telephone handset includes: a storage support which is secured against fraudulent access and which stores the IMEI of the handset. A connector for a secure electronic module is associated with an operator. A handset operating system controls authentication of the IMEI storage support by a secure electronic module which is connected to the aforementioned connector in order to establish a secure communication channel between the storage support and the module and transmission of the IMEI over the secure channel to the secure electronic module. The arrangement can be used to prevent the dynamic modification of the IMEI during the transmission thereof. Koral et al. (U. S. 2023/0092778 A1): The disclosed technology is directed towards detecting suspected malicious activity involving mobile devices and subscriber identity module (SIM) cards, including discerning benign SIM swap events from likely malicious SIM swap events. In one example, call detail records, radio access network events and billing events are collected and analyzed to detect subscriber identity module swap events between mobile devices. Based on the collected data and related data sources SIM swap events are classified as benign or suspected malicious classifications. Malicious classifications can result in information representative of the suspected as malicious classification being output, e.g., as a type of fraudulent activity. A confidence level can be associated with classification output data, including for types of fraudulent activities and types of benign activities. Any inquiry concerning this communication or earlier communications from the examiner should be directed to RUPALI DHAKAD whose telephone number is (571)270-3743. The examiner can normally be reached M-F 8:30-5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at 5712705143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /R.D./Examiner, Art Unit 2437 /ALI S ABYANEH/Primary Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Show 6 earlier events
Jul 25, 2025
Response Filed
Nov 05, 2025
Final Rejection mailed — §102, §103
Dec 23, 2025
Examiner Interview Summary
Dec 23, 2025
Applicant Interview (Telephonic)
Feb 05, 2026
Response after Non-Final Action
Apr 03, 2026
Request for Continued Examination
Apr 09, 2026
Response after Non-Final Action
Aug 05, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12592937
Method For Protection From Cyber Attacks To A Vehicle, And Corresponding Device
3y 10m to grant Granted Mar 31, 2026
Patent 12587544
METHOD AND SYSTEM TO REMEDIATE A SECURITY ISSUE
4y 5m to grant Granted Mar 24, 2026
Patent 12513154
BLOCKCHAIN-BASED DATA DETECTION METHOD, APPARATUS, AND COMPUTER-READABLE STORAGE MEDIUM
3y 7m to grant Granted Dec 30, 2025
Patent 12495039
INTEGRATED AUTHENTICATION SYSTEM AND METHOD
3y 2m to grant Granted Dec 09, 2025
Patent 12468826
METHOD FOR OPERATING A PRINTING SYSTEM
3y 5m to grant Granted Nov 11, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
37%
Grant Probability
67%
With Interview (+30.0%)
3y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 35 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month