DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
This action is in reply to the communication(s) filed on 05 May 2026 and 08 June 2026.
Claims 1, 11 and 17 are amended.
Claim(s) 1-20 is/are currently pending and have been examined.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 08 June 2026 has been entered.
Response to Arguments
Applicant's arguments filed 11 February 2026 have been fully considered but they are not persuasive.
Rejections under 35 U.S.C. §101
Step 2A Prong One
Applicant argues that authenticating IoT-device interactions through such a computational pipeline is a computer-security activity, not an economic practical. Examiner respectfully disagrees. “Use of a computer or other machinery in its ordinary capacity for economic or other tasks (e.g., to receive, store, or transmit data) or simply adding a general-purpose computer or computer components after the fact to an abstract idea (e.g., a fundamental economic practice or mathematical equation) does not integrate a judicial exception into a practical application or provide significantly more. See Affinity Labs v. DirecTV, 838 F.3d 1253, 1262, 120 USPQ2d 1201, 1207 (Fed. Cir. 2016) (cellular telephone); TLI Communications LLC v. AV Auto, LLC, 823 F.3d 607, 613, 118 USPQ2d 1744, 1748 (Fed. Cir. 2016) (computer server and telephone unit). Similarly, "claiming the improved speed or efficiency inherent with applying the abstract idea on a computer" does not integrate a judicial exception into a practical application or provide an inventive concept. Intellectual Ventures I LLC v. Capital One Bank (USA), 792 F.3d 1363, 1367, 115 USPQ2d 1636, 1639 (Fed. Cir. 2015)” (See MPEP 2106.05(f)). The use of generic computing components in the instant application to increase the speed or efficiency of the recited judicial exception does not afford the claim eligibility.
Applicant argues that usage of an LSTM neural network cannot be performed in the human mind. Examiner agrees as evidenced by the fact that the LSTM is listed as an additional element in the 101 analysis (however Examiner notes the comparing outside of the recitation of an LSTM can be performed mentally). This ends the analysis under Step 2A Prong One. However, such recitations do not integrate the recited judicial exception into a practical application under Step 2A Prong Two. “The courts often cite to Parker v. Flook as providing a classic example of a field of use limitation. See, e.g., Bilski v. Kappos, 561 U.S. 593, 612, 95 USPQ2d 1001, 1010 (2010) ("Flook established that limiting an abstract idea to one field of use or adding token postsolution components did not make the concept patentable") (citing Parker v. Flook, 437 U.S. 584, 198 USPQ 193 (1978)). In Flook, the claim recited steps of calculating an updated value for an alarm limit (a numerical limit on a process variable such as temperature, pressure or flow rate) according to a mathematical formula "in a process comprising the catalytic chemical conversion of hydrocarbons." 437 U.S. at 586, 198 USPQ at 196. Processes for the catalytic chemical conversion of hydrocarbons were used in the petrochemical and oil-refining fields. Id. Although the applicant argued that limiting the use of the formula to the petrochemical and oil-refining fields should make the claim eligible because this limitation ensured that the claim did not preempt all uses of the formula, the Supreme Court disagreed. 437 U.S. at 588-90, 198 USPQ at 197-98. Instead, the additional element in Flook regarding the catalytic chemical conversion of hydrocarbons was not sufficient to make the claim eligible, because it was merely an incidental or token addition to the claim that did not alter or affect how the process steps of calculating the alarm limit value were performed. Further, the Supreme Court found that this limitation did not amount to an inventive concept. 437 U.S. at 588-90, 198 USPQ at 197-98. The Court reasoned that to hold otherwise would "exalt[] form over substance", because a competent claim drafter could attach a similar type of limitation to almost any mathematical formula. 437 U.S. at 590, 198 USPQ at 197.” See MPEP 2106.05(h). The recitation of an LSTM neural network does not alter or affect how the process steps of comparing IoT constellations and performing authentication using said comparisons are performed.
Applicant argues that the plurality of IoT enabled devices cannot be performed in the human mind. Examiner agrees as evidenced by the fact that the IoT devices are listed as additional elements in the 101 analysis. However, such recitations do not integrate the recited judicial exception into a practical application. “Use of a computer or other machinery in its ordinary capacity for economic or other tasks (e.g., to receive, store, or transmit data) or simply adding a general-purpose computer or computer components after the fact to an abstract idea (e.g., a fundamental economic practice or mathematical equation) does not integrate a judicial exception into a practical application or provide significantly more. See Affinity Labs v. DirecTV, 838 F.3d 1253, 1262, 120 USPQ2d 1201, 1207 (Fed. Cir. 2016) (cellular telephone); TLI Communications LLC v. AV Auto, LLC, 823 F.3d 607, 613, 118 USPQ2d 1744, 1748 (Fed. Cir. 2016) (computer server and telephone unit). Similarly, "claiming the improved speed or efficiency inherent with applying the abstract idea on a computer" does not integrate a judicial exception into a practical application or provide an inventive concept. Intellectual Ventures I LLC v. Capital One Bank (USA), 792 F.3d 1363, 1367, 115 USPQ2d 1636, 1639 (Fed. Cir. 2015)” (See MPEP 2106.05(f)). The use of generic computing components in the instant application to increase the speed or efficiency of the recited judicial exception does not afford the claim eligibility.
Applicant argues that the instant claims are eligible for reasons similar to those of Example 39 of the USPTO' s “Subject Matter Eligibility Examples: Abstract Ideas” for use in conjunction with the 2019 PEG. Examiner respectfully disagrees. In Example 39, the claims were found eligible because they did not recite any abstract idea under Step 2A Prong One. Unlike Example 39, the instant claims recite an abstract idea which is further elaborated in the provided 101 rejection. The claims are unlike those in Example 39.
Step 2A Prong Two.
Applicant argues that their claims are eligible for reasons similar to those in McRO. Examiner respectfully disagrees. This court case is directed to improvements to the functioning of a computer or to a technology or technical field. In McRO, improvements to the then done by hand animation technology whereby each person performed hand drawn animation differently into a consistent implementation by rules on a computer. Applicant’s invention would be performed the same in person as on a computer and thus is mere instructions to perform the abstract idea on a computer. The case of McRO does not apply to the applicant’s claims.
Applicant argues that the continuous scanning is not mere data gathering, but a closed-loop computational pipeline. Examiner respectfully disagrees. “Another consideration when determining whether a claim integrates the judicial exception into a practical application in Step 2A Prong Two or recites significantly more in Step 2B is whether the additional elements add more than insignificant extra-solution activity to the judicial exception. The term "extra-solution activity" can be understood as activities incidental to the primary process or product that are merely a nominal or tangential addition to the claim. Extra-solution activity includes both pre-solution and post-solution activity. An example of pre-solution activity is a step of gathering data for use in a claimed process, e.g., a step of obtaining information about credit card transactions, which is recited as part of a claimed process of analyzing and manipulating the gathered information by a series of steps in order to detect whether the transactions were fraudulent. An example of post-solution activity is an element that is not integrated into the claim as a whole, e.g., a printer that is used to output a report of fraudulent transactions, which is recited in a claim to a computer programmed to analyze and manipulate information about credit card transactions in order to detect whether the transactions were fraudulent.” See MPEP 2106.05(g). The scanning amounts to no more than merely collecting data for purposes of updating the constellation data, and as such is an activity incidental to the primary process of authentication that is merely a nominal or tangential addition to the claim. The scanning represents insignificant extra-solution activity.
Applicant argues that the claims are eligible for reasons similar to Example 41. Examiner respectfully disagrees. In Example 41, the combination of additional elements in the claim integrated the exception into the practical application of transmitting ciphertext word signal to a computer terminal over a communication channel. Applicant’s claim does not contain a combination of additional elements that improves cryptographic communications. The instant claims are not analogous to Example 41.
Applicant argues that the use of an LSTM’s abilities makes it particularly suited to the claimed constellation comparison and pattern updating functions and thus is a specific technical implementation. Examiner respectfully disagrees. “The courts often cite to Parker v. Flook as providing a classic example of a field of use limitation. See, e.g., Bilski v. Kappos, 561 U.S. 593, 612, 95 USPQ2d 1001, 1010 (2010) ("Flook established that limiting an abstract idea to one field of use or adding token postsolution components did not make the concept patentable") (citing Parker v. Flook, 437 U.S. 584, 198 USPQ 193 (1978)). In Flook, the claim recited steps of calculating an updated value for an alarm limit (a numerical limit on a process variable such as temperature, pressure or flow rate) according to a mathematical formula "in a process comprising the catalytic chemical conversion of hydrocarbons." 437 U.S. at 586, 198 USPQ at 196. Processes for the catalytic chemical conversion of hydrocarbons were used in the petrochemical and oil-refining fields. Id. Although the applicant argued that limiting the use of the formula to the petrochemical and oil-refining fields should make the claim eligible because this limitation ensured that the claim did not preempt all uses of the formula, the Supreme Court disagreed. 437 U.S. at 588-90, 198 USPQ at 197-98. Instead, the additional element in Flook regarding the catalytic chemical conversion of hydrocarbons was not sufficient to make the claim eligible, because it was merely an incidental or token addition to the claim that did not alter or affect how the process steps of calculating the alarm limit value were performed. Further, the Supreme Court found that this limitation did not amount to an inventive concept. 437 U.S. at 588-90, 198 USPQ at 197-98. The Court reasoned that to hold otherwise would "exalt[] form over substance", because a competent claim drafter could attach a similar type of limitation to almost any mathematical formula. 437 U.S. at 590, 198 USPQ at 197.” See MPEP 2106.05(h). The use of an LSTM neural network does not alter or affect how the process steps of performing authentication are performed. The recitation of an LSTM neural network does not integrate the judicial exception into a practical application.
Applicant argues that the claims do not merely improve an abstract risk-mitigation process and then repeats many of the same arguments already presented. Examiner incorporates their responses to these similar arguments herein.
Step 2B
Applicant argues that the claim limitations are not well-understood, routine, or conventional in the field and that Examiner does not provide support for the elements being well-understood, routine, or conventional. Examiner respectfully disagrees. “Although the conclusion of whether a claim is eligible at Step 2B requires that all relevant considerations be evaluated, most of these considerations were already evaluated in Step 2A Prong Two. Thus, in Step 2B, examiners should:
• Carry over their identification of the additional element(s) in the claim from Step 2A Prong Two;
• Carry over their conclusions from Step 2A Prong Two on the considerations discussed in MPEP §§ 2106.05(a) - (c), (e) (f) and (h):
• Re-evaluate any additional element or combination of elements that was considered to be insignificant extra-solution activity per MPEP § 2106.05(g), because if such re-evaluation finds that the element is unconventional or otherwise more than what is well-understood, routine, conventional activity in the field, this finding may indicate that the additional element is no longer considered to be insignificant; and
• Evaluate whether any additional element or combination of elements are other than what is well-understood, routine, conventional activity in the field, or simply append well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception, per MPEP § 2106.05(d)” (See MPEP 2106.05(II)).
In both the prior and instant Office Action, the conclusions from Step 2A Prong Two are equally applied in Step 2B which further re-evaluates additional elements which are considered to be insignificant extra-solution activity and evaluates these elements as per MPEP §2106.05(d) to be well-understood, routine, and conventional activity. Said elements which are considered to be insignificant extra-solution activity are evaluated as well-understood, routine, and conventional as per the evidentiary requirements detailed in MPEP §2106.07(a)(III) utilizing option (B) via citation to one or more of the court decisions discussed in MPEP §2106.05(d)(II). Thus, there are no further elements to evaluate under Step 2B. Most considerations relating to any additional elements were already evaluated in Step 2A Prong Two and thus do not require further re-evaluation in Step 2B.
Rejections under 35 U.S.C. §103
In response to applicant's argument that Mardikar, Kodali, and Santosh are nonanalogous art, it has been held that a prior art reference must either be in the field of the inventor’s endeavor or, if not, then be reasonably pertinent to the particular problem with which the inventor was concerned, in order to be relied upon as a basis for rejection of the claimed invention. See In re Oetiker, 977 F.2d 1443, 24 USPQ2d 1443 (Fed. Cir. 1992). In this case, all three references are reasonably pertinent to the particular problem with which the inventor was concerned, that being improving authentication processes. See at least applicant’s specification at paragraph [03]: “Currently, users make numerous transactions via electronic devices using different service providers' and merchants' platforms. The authentication processes utilized by some service providers and merchants does not provide adequate user authentication protections as they rely solely on user names and passwords for authentication. The use of usernames and passwords is no longer enough as usernames and passwords are easily compromised. In addition, the use of just user names and passwords for authentication does not ensure that the entity providing the user name and password is an authorized user.” Thus these references are analogous art as all three are clearly concerned with user authentication and profiling across many services (See the abstract and background of all three references).
Applicant’s arguments with respect to the independent claims concerning the prior arts’ teaching of an LSTM have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Applicant argues that Votaw does not disclose continuous scanning but correctly does identify that while Votaw does disclose continuous updating, that it is event-triggered and not continuous. Applicant’s arguments with respect to the independent claims with respect to the continuous scanning have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Applicant argues that the cited references do not teach generating a constellation comprising a unique digital pattern of IoT Device Interactions. Examiner respectfully disagrees. Votaw discloses user pattern analysis may include identification of one or more second apparatus activities aggregated with the first apparatus activities. See at least paragraphs [0060]-[0061] (emphasis added). Applicant admits that Kodali discloses collecting of data across multiple sources. Thus, in the combination, Votaw’s one or more second apparatus activities may come from another IoT source which then reads on a constellation comprising a unique digital pattern of IoT device interactions. The combination of references teaches the claimed invention.
Applicant argues that Santosh does not disclose Claims 10, 16 and 20. Examiner respectfully disagrees. Under the claims’ BRI and according to applicant’s specification a “trust group” is defined thusly: “In an embodiment, a trust group may include any number of persons that allow for interaction between their IoT devices and generated constellations” See specification at paragraph [71]. The same paragraph is also the only recitation of intersecting constellations which since it is not specially defined by the applicant the phrase falls to its plain meaning, which may include two constellations where at least one point matches (i.e. intersects). Santosh teaches suggesting people to add to a user’s network (which then qualifies as a trust group according to applicant’s specification since they are exchanging IoT device information in the combination) based on user matching (which falls under the aforementioned plain meaning of “intersecting constellations”). Thus Santosh discloses functional equivalency to Claims 10, 16 and 20. Furthermore, whether or not Santosh is analogous art has already been addressed above which Examiner incorporates herein.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The independent claims have been amended to recite “continuously scan, using the LSTM neural network, an environment of the plurality of IoT enabled devices to gather and collate data to update constellation patterns based on detected interactions with the plurality of IoT enabled devices.”. While the specification does disclose in paragraph [45] that the AI framework may be used in a continuous learning process, it is silent as to performing continuous scanning (emphasis added). In fact, applicant’s own specification discloses an example of this continuous learning as periodic scanning, not continuous: “The artificial intelligence framework may be used in a continuous learning process. For instance, the artificial intelligence framework may continue to scan the entire environment periodically to gather and collate data to make informed decisions regarding new constellation patterns based on transactions” (specification at paragraph [45]). While this does disclose continuous learning based on periodic updates, the specification is silent as to continuous scanning. The scanning being continuous represents new matter.
Any remaining claims not expounded upon are rejected based on their dependency to a rejected claim.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Step 1 of the 101 Analysis:
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claims recites a computing platform, method, and non-transitory machine-readable storage medium for IoT based Authentication. These are a machine, process, and article of manufacture which are within the four categories of statutory subject matter.
Step 2A Prong 1 of the 101 Analysis:
The following limitations and/or similar versions are recited in claim(s) 1, 11 and 17:
Claim 1, 11 and 17:
“generate a first constellation, the first constellation based on the received plurality of IoT enabled devices information regarding the interactions with the user of the plurality of IoT enabled devices, wherein the first constellation comprises a unique digital pattern of IoT device interactions with the user, the unique digital pattern including geolocation information and time stamp information associated with each interaction with the plurality of IoT enabled devices;”
“compare,…, the first generated constellation to at least a second constellation stored in the memory;”
“determine a trust status based on the compared first generated constellation to the at least stored second constellation;”
“…collate data to update constellation patterns based on detected interactions with the plurality of IoT enabled devices.”
These limitations, as drafted, are a process that, under its broadest reasonable interpretation, describes Fundamental Economic Principles or Practices or could reasonably describe Concepts Performed in the Human Mind but for the recitation of generic computer components. That is, other than reciting “a plurality of IoT enabled devices”, “at least one processor”, “memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:”, or “A non-transitory machine-readable storage medium storing machine-readable instructions that when executed, cause an apparatus to:” nothing in the claims’ elements precludes the steps from practically describing Fundamental Economic Principles or Practices or Concepts Performed in the Human Mind. For example, but for the recited computer language, the limitations in the context of this claim describes Mitigating Risk or could reasonably describe an Evaluation. Mitigating Risk is described when analyzing data to determine a trust stated and determining said trust status. An Evaluation is described when analyzing data to determine a trust stated and determining said trust status. If a claim limitations, under their broadest reasonable interpretation, describes Fundamental Economic Principles or Practices or Concepts Performed in the Human Mind but for the recitation of generic computer components, then it falls within the “Certain Methods of Organizing Activity” or “Mental Processes” grouping of abstract ideas respectively.
Accordingly, the independent claims recite an abstract idea.
Step 2A Prong 2 of the 101 Analysis:
This judicial exception is not integrated into a practical application. In particular, the independent claim(s) recite the following (or similar) additional elements:
Claim(s) 1, 11 and 17:
“receive from a plurality of IoT enabled devices information regarding interactions with a user of the plurality of IoT enabled devices and at least one third party IoT enabled device;”
“…using a Long Short-Term Memory (LSTM) neural network…”
“transmit the trust status to the plurality of IoT enabled devices.”
“continuously scan, using the LSTM neural network, an environment of the plurality of IoT enabled devices to gather and…”
Claim 1:
“at least one processor;”
“memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:”
Claim 17:
“A non-transitory machine-readable storage medium storing machine-readable instructions that when executed, cause an apparatus to:”
The computer components (IoT enabled devices, at least one processor, memory storing computer-readable instructions, and non-transitory machine-readable storage medium storing machine-readable instructions) are recited at a high level of generality (i.e. as generic IoT enabled devices, a generic processor, and generic storage) such that it amounts to no more than mere instructions to implement the judicial exception on a computer or by using a computer merely as a tool to perform an existing process. These element(s) in combination do not add anything that is not already present when the steps are considered separately. Simply implementing an abstract idea on a computer as a tool to perform an existing process is not indicative of integration into a practical application (See MPEP § 2106.05(f).)
The receiving, transmitting, scanning, gathering, and collating step(s) are recited at a high-level of generality (i.e., as generally receiving, generally transmitting, generally scanning, and generally gathering) such that they amounts to no more than mere data gathering which is adding insignificant extra-solution activity. These element(s) in combination do not add anything that is not already present when the steps are considered separately. Simply adding insignificant extra-solution activity is not indicative of integration into a practical application (See MPEP § 2106.05(g).)
The use of an LSTM neural network is implemented at a high level of generality (i.e. as simply using the technology) such that it amounts to no more than generally linking the use of the judicial exception to a particular technological environment or field of use. These element(s) in combination do not add anything that is not already pre-sent when the steps are considered separately. Generally linking the use of the judicial exception to a particular technological environment or field of use is not indicative of integration into a practical application (See MPEP § 2106.05(h).)
Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
The independent claims are directed to an abstract idea.
Step 2B of the 101 Analysis:
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements identified in Step 2A Prong 2 (if any) amount to no more than mere instructions to implement the judicial exception on a computer or no more than mere data gathering or data outputting which only adds insignificant extra solution activity to the judicial exception. Accordingly, the Examiner:
• Carries over their identification of the additional element(s) in the claim from Step 2A Prong Two;
• Carries over their conclusions from Step 2A Prong Two on the considerations discussed in MPEP §§ 2106.05(a) - (c), (e) (f) and (h):
• Re-evaluates any additional element or combination of elements that was considered to be insignificant extra-solution activity per MPEP § 2106.05(g), because if such re-evaluation finds that the element is unconventional or otherwise more than what is well-understood, routine, conventional activity in the field, this finding may indicate that the additional element is no longer considered to be insignificant.
These element(s) in combination do not add anything that is not already present when the steps are considered separately. Adding insignificant extra-solution activity cannot provide an inventive concept when the activities are well-understood routine and conventional. The courts have recognized the following computer functions as well-understood, routine, and conventional functions when they are claimed in a merely generic manner:
(for receiving/transmitting/scanning/gathering various data) Receiving or transmitting data over a network, (See MPEP § 2106.05(d)(II)).
The independent claims are not patent eligible.
Dependent Claim(s) 2-10, 12-16 and 18-20 recite limitations that are similar to the abstract idea noted in the independent claims because they further narrow the independent claim(s) which recite one or more judicial exceptions. Accordingly, these claim elements do not serve to confer subject matter eligibility to the claims since they recite abstract ideas.
The claims are not patent eligible.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 1-9, 11-15 and 17-19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Votaw et al. (US 2016/0055487 A1 hereinafter Votaw) in view of Mardikar et al. (US 2020/0311734 A1 hereinafter Mardikar) further in view of Kodali et al. (US 2023/0224540 A1 hereinafter Kodali) and further in view of Hallac (US 2023/0237335 A1 hereinafter Hallac).
Claim 1
A computing platform for authenticating transactions associated with a user, the computing platform comprising:
at least one processor; and (Votaw discloses a processor. See at least paragraph [0003].)
memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: (Votaw discloses memory storing code executable by the processor to perform embodiments of the invention. See at least paragraph [0003].)
receive from a plurality of IoT enabled devices information regarding interactions with a user of the plurality of IoT enabled devices and at least one third party IoT enabled device; (Votaw discloses receiving a set of apparatus activities (i.e. device information regarding interactions with an IoT). See at least paragraph [0059]. Votaw discloses user pattern analysis may include identification of one or more second apparatus activities aggregated with the first apparatus activities. See at least paragraphs [0060]-[0061]. Although Votaw does disclose multiple apparatus activities, they might not explicitly disclose receiving said data from a plurality of IoT enabled devices. Kodali teaches that Internet of Things action data (i.e. interactions) relating to a risk assessment may be collected from a plurality of Internet of Things devices including from third-party platforms. See at least paragraphs [0018], [0031], [0041] and [0064].
It would be obvious to one of ordinary skill in the art before the effective filing date to collect data from a plurality of Internet of Things devices as taught by Kodali for the behavior analysis of Votaw because Kodali additionally teaches the motivation that such data allows for complex services, such as risk assessment, involving various facets of an individual. See at least paragraph [0002].)
generate a first constellation, the first constellation based on the received plurality of IoT enabled devices information regarding the interactions with the user of the plurality of IoT enabled devices wherein the first constellation comprises a unique digital pattern of IoT device interactions with the user, the unique digital pattern including geolocation information and time stamp information associated with each interaction with the plurality of IoT enabled devices; (Votaw discloses detecting user patterns (i.e. constellations) based on user interaction with the computing device. See at least paragraph [0003]. Votaw discloses user pattern analysis may include identification of one or more second apparatus activities aggregated with the first apparatus activities. See at least paragraphs [0060]-[0061]. Votaw discloses information may include sensor information from a global positions system device. See at least paragraph [0073]. Votaw discloses patterns may include time of day (i.e. time stamp information) when a user interactions with applications. See at least paragraph [0010]. Usage of data from a plurality of IoT enabled devices is taught by the combination with Kodali as shown above which Examiner incorporates herein.)
compare, using a Long Short-Term Memory (LSTM) neural network, the first generated constellation to at least a second constellation stored in the memory; (Votaw discloses determining a level of authentication (i.e. trust status required for a transaction based on a user pattern score. See at least paragraphs [0064]-[0065]. Votaw discloses determining a threshold score based on comparing the identification set of user patterns with a baseline set of user patterns (i.e. second constellation stored in memory). See at least paragraphs [0005] and [0015]. Votaw does not disclose using an LSTM neural network.
Although Votaw does not disclose machine learning, Hallac teaches using an LSTM for fingerprinting. See at least paragraph [0053].
It would be obvious to one of ordinary skill in the art before the effective filing date to use an LSTM neural network for similarity comparisons as taught by Hallac because Hallac additionally teaches the motivation that this reduces temporal variations. See at least paragraph [0053].
Also, usage of an LSTM neural network for similarity measures as taught by Hallac in the system of Votaw is merely a combination of old elements, and in the combination each element merely would have performed the same function as it did separately, and one of ordinary skill in the art would have recognized that the results of the combination were predictable.)
determine a trust status based on the compared first generated constellation to the at least stored second constellation; and (Votaw discloses determining a level of authentication (i.e. trust status required for a transaction based on a suer pattern score. See at least paragraphs [0064]-[0065]. Votaw discloses determining a threshold score based on comparing the identification set of user patterns with a baseline set of user patterns (i.e. second constellation stored in memory). See at least paragraph [0005] and [0015].)
transmit the trust status to the plurality of IoT enabled devices; and (Although Votaw does disclose collecting data across a plurality of network devices, they might not explicitly disclose transmitting the trust status to the plurality of IoT enable devices. Mardikar teaches that a network with IoT devices including third-party device data (Mardikar discloses any functions or steps may be outsourced to or performed by one or more third parties) may share data including fraud scores (i.e. trust level). See at least paragraphs [0019], [0033]-[0034] and [0053].
It would be obvious to one of ordinary skill in the art before the effective filing date to share a fraud score among a network as taught by Mardikar by sharing the trust status of Votaw among its network of IoT devices because Mardikar additionally teaches the motivation that this allows for a dynamic trust score based on a network of data. See at least paragraphs [0001]-[0002].
Also, sharing a fraud score among a network as taught by Mardikar by sharing the trust status of Votaw among its network of IoT devices is merely a combination of old elements, and in the combination each element merely would have performed the same function as it did separately, and one of ordinary skill in the art would have recognized that the results of the combination were predictable.)
continuously scan, using the LSTM neural network, an environment of the plurality of IoT enabled devices to gather and collate data to update constellation patterns based on detected interactions with the plurality of IoT enabled devices. (Votaw discloses continuous updating of patterns associated with the user. See at least paragraph [0085]. Hallac teaches the usage of LSTM as shown above. Votaw does not disclose continuous scanning and updating. Hallac teaches receiving telematics data substantially continuously and updating weights and data substantially continuously. See at least paragraphs [0007] and [0052].
It would be obvious to one of ordinary skill in the art before the effective filing date to receive the IoT telematics data of Votaw substantially continuously and updating weights and data substantially continuously as taught by Hallac because Hallac additionally teaches the motivation that this allows the system to continuously generate/update fingerprints as additional telematics data is collected. See at least paragraph [0052].)
Claim 2
The computing platform of claim 1, wherein the computer-readable instructions, when executed by the at least one processor, cause the computing platform to receive interaction information from at least one third party IoT enabled device. (Receipt and usage of third-party data is taught by the combination with Mardikar as shown above which Examiner incorporates herein.)
Claim 3
The computing platform of claim 1, wherein the computer-readable instructions, when executed by the at least one processor, cause the computing platform to determine a risk ranking based on the comparison of the first generated constellation to the at least a second constellation stored in the memory. (Votaw discloses determining a level of authentication (i.e. trust status) required for a transaction based on a user pattern score (i.e. risk ranking). See at least paragraphs [0064]-[0065].)
Claim 4
The computing platform of claim 3, wherein the risk ranking is updated based on a defined time period comprising real-time updates. (Votaw discloses data may be based on interactions at a time of day (i.e. based on a defined time period). See at least paragraph [0082]. Votaw discloses continuously updating user patterns (i.e. in real-time). See at least paragraph [0085].)
Claim 5
The computing platform of claim 3, wherein the risk ranking is updated based on detection of a generated constellation. (Votaw discloses updating user patterns when new data is received. See at least paragraph [0085]. Votaw discloses determining user pattern score by comparing the present pattern of usage to the normal pattern of usage. See at least paragraph [0015].)
Claim 6
The computing platform of claim 1, wherein the plurality of IoT enabled devices information comprises geolocation information. (Votaw discloses information may include sensor information from a global positions system device. See at least paragraph [0073].)
Claim 7
The computing platform of claim 1, wherein the plurality of IoT enabled devices information comprises time stamp information. (Votaw discloses patterns may include time of day (i.e. time stamp information) when a user interactions with applications. See at least paragraph [0010].)
Claim 8
The computing platform of claim 1, wherein the determined trust status is further based on participation in a trust group. (Examiner notes the collection of consenting IoT devices is a trust group as per the applicant’s specification at paragraph [71] and therefore analysis based on said group’s data is analysis based on participation in a trust group. Votaw discloses detecting user patterns (i.e. constellations) based on user interaction with the computing device. See at least paragraph [0003]. Votaw discloses user pattern analysis may include identification of one or more second apparatus activities aggregated with the first apparatus activities. See at least paragraphs [0060]-[0061].)
Claim 9
The computing platform of claim 8, wherein the trust group comprises members of a work group. (While Votaw does disclose collecting data from a trust group, they might not explicitly disclose where the trust group comprises members of a work group. Mardikar teaches that registration of a digital identity in connection with a dynamic trust score may include indicating that an employer has verified that the user works for said employer (i.e. work group). See at least paragraph [0035].
It would be obvious to one of ordinary skill in the art before the effective filing date to use the work group designation as taught by Mardikar in the system of Votaw because Mardikar additionally teaches the motivation that this identity verifies that the user is who they claim to be and/or the like. See at least paragraphs [0035]-[0036].
Also, using the work group designation as taught by Mardikar in the system of Votaw is merely a combination of old elements, and in the combination each element merely would have performed the same function as it did separately, and one of ordinary skill in the art would have recognized that the results of the combination were predictable.)
Claim 11
A method comprising:
…
The remainder of Claim 11 is substantially similar to or broader than the corresponding elements in Claim 1 and is therefore rejected using similar reasoning.
Claim 12
Claim 12 is substantially similar to or broader than the corresponding elements in Claim 2 and is therefore rejected using similar reasoning.
Claim 13
The method of claim 12, further comprising generating a third constellation based on the received third party information regarding interaction with the user and the received plurality of IoT enabled devices information regarding the interactions with the user. (Receipt and usage of third-party data is taught by the combination with Mardikar as shown above which Examiner incorporates herein. Votaw discloses determining a level of authentication (i.e. trust status) required for a transaction based on a user pattern score (i.e. risk ranking). See at least paragraphs [0064]-[0065].)
Claim 14
Claim 14 is substantially similar to or broader than the corresponding elements in Claim 8 and is therefore rejected using similar reasoning.
Claim 15
Claim 15 is substantially similar to or broader than the corresponding elements in Claim 9 and is therefore rejected using similar reasoning.
Claim 17
A non-transitory machine-readable storage medium storing machine-readable instructions that when executed, cause an apparatus to: (Votaw discloses embodiment using a non-transitory computer-readable medium. See at least paragraph [0095].)
…
The remainder of Claim 17 is substantially similar to or broader than the corresponding elements in Claim 1 and is therefore rejected using similar reasoning.
Claim 18
Claim 18 is substantially similar to or broader than the corresponding elements in Claim 2 and is therefore rejected using similar reasoning.
Claim 19
Claim 19 is substantially similar to or broader than the corresponding elements in Claim 8 and is therefore rejected using similar reasoning.
Claim(s) 10, 16 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Votaw et al. (US 2016/0055487 A1 hereinafter Votaw) in view of Mardikar et al. (US 2020/0311734 A1 hereinafter Mardikar) further in view of Kodali et al. (US 2023/0224540 A1 hereinafter Kodali) further in view of Hallac (US 2023/0237335 A1 hereinafter Hallac) further in view of Santosh et al. (US 2023/0145741 A1 hereinafter Santosh).
Claim 10
The computing platform of claim 8, wherein the computer-readable instructions, when executed by the at least one processor, cause the computing platform to recommend specific trust groups based on analysis of generated intersecting constellations. (Although Votaw does disclose collecting information from a trust group, they might not explicitly disclose recommending specific trust groups based on analysis of generated intersecting constellations. Santosh teaches that a controller may suggest people (i.e. another specific trust group) to a sender who match previously identified behavior (i.e. generated intersecting constellations). See at least paragraph [0115].
It would be obvious to one of ordinary skill in the art before the effective filing date to implement suggesting matching people to a user as taught by Santosh in the system of Votaw because Santosh also teaches the motivation that these suggested people are most likely to also benefit from the senders product. See at least paragraph [0115].
Also, implementing suggest matching people to a user as taught by Santosh in the system of Votaw is merely a combination of old elements, and in the combination each element merely would have performed the same function as it did separately, and one of ordinary skill in the art would have recognized that the results of the combination were predictable.)
Claim 16
Claim 16 is substantially similar to or broader than the corresponding elements in Claim 10 and is therefore rejected using similar reasoning.
Claim 20
Claim 20 is substantially similar to or broader than the corresponding elements in Claim 10 and is therefore rejected using similar reasoning.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Gean (WO 2024/097498 A1) discloses authentication based on user interactions.
Dahit et al. (“Dynamic Trust and Risk Scoring Using Last-Known Profile Learning”) discloses a risk calculation method for IoT environments.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ADAM J HILMANTEL whose telephone number is (571)272-8984. The examiner can normally be reached M-F 8:30AM-5:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Abhishek Vyas can be reached at (571) 270-1836. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ADAM HILMANTEL/Examiner, Art Unit 3691