Prosecution Insights
Last updated: August 17, 2026
Application No. 18/096,368

RISK LEVEL FOR MODIFYING SECURITY SAFEGUARDS

Non-Final OA §101
Filed
Jan 12, 2023
Priority
Jun 22, 2010 — continuation of 8924296 +2 more
Examiner
RANKINS, WILLIAM E
Art Unit
3694
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
American Express Travel Related Services Company, Inc.
OA Round
6 (Non-Final)
58%
Grant Probability
Moderate
6-7
OA Rounds
0m
Est. Remaining
66%
With Interview

Examiner Intelligence

Grants 58% of resolved cases
58%
Career Allowance Rate
456 granted / 790 resolved
+5.7% vs TC avg
Moderate +8% lift
Without
With
+8.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
37 currently pending
Career history
829
Total Applications
across all art units

Statute-Specific Performance

§101
35.7%
-4.3% vs TC avg
§103
27.2%
-12.8% vs TC avg
§102
7.6%
-32.4% vs TC avg
§112
26.2%
-13.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 790 resolved cases

Office Action

§101
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claim Status Claims 1-20 are pending. Response to Arguments Applicant’s arguments regarding the 101 rejection have been considered but are not persuasive. The applicant argues: Claim 1 is not directed to an abstract concept, but rather a system for controlling access to data within a networked computing environment. Claim 1 recites actions that include a "memory device," "external terminal," "database," "social networking website," and a "computer network," and also how these components interact to regulate access to stored data in a memory which is to be used for a transfer. The Office notes that claim 1 is directed to a method and not a system. Nevertheless, while claim 1 may be directed to controlling access to data it is also directed to an abstract idea because the two are not mutually exclusive. Controlling access to data is risk mitigation. Controlling access to data in a computer network is risk mitigation applied to a particular field or environment. Regarding how the components interact, the applicant has not identified any particular interactions that indicate the claims are not directed to an abstract idea. The steps are not merely evaluating information and making a decision, but include identifying specific data in memory, retrieving identification data from multiple heterogeneous network sources, and modifies a network security safeguard based on an analysis of the data, prior to execution of an action on the computer network. The process modifies a network and then executes an action on the modified network, which goes beyond a mental process or a commercial practice. The Office notes that the process modifies a security safeguard within a network and not the network itself, i.e., software or instructions are modified. Again, the modification of instructions do not necessarily require a computer but for application of the modification within a particular field or environment. Claim 1 includes a sequence of operations that cannot practically be performed in the human mind or with pen and paper. The retrieval of identification data from distributed sources such as an external terminal, database, and social networking website, and the dynamic control of access to data stored in the memory device, are steps that inherently require a computer. Thus, Applicant contends that the inquiry into the abstraction of Applicant's claims should end at this first prong as Applicant's claims do not fall into any of the enumerated groupings and therefore cannot be abstract. The applicant fails to explain why the steps of the claim cannot be performed in the human mind, absent the recited components. The claims merely recite, receiving, computing, retrieving, generating and determining and modifying data and executing a transfer based on the modified data. These actions are appended to apply them in a computer network but can generally be performed in manual environments. The applicant does not explain why these steps inherently require a computer. The process causes a change in system operation by changing the security safeguard on the network and then executing the transfer using the modification to the network. The Office notes that the process causes a change in the results obtained by the system, i.e., making it harder or easier to access data through a change in security safeguards but the system, or method, itself remains the same. The method or system does not purport to improve security measures in some particular technical fashion but merely changes security measures. Furthermore, the claimed process improves the security and operation of network-based transactions by introducing a dynamic, multi-source verification and access control mechanism. Here, a trust score is compared against a threshold derived from transaction-specific attributes. This comparison is used by the system to enforce context-sensitive access control over data to be used for the transfer. This results in a more secure and adaptive system for managing data access and network transactions. The claims do not recite any improvement in security of the system but merely a change in the security measures. The functioning of the system itself or technology or technical field is not improved by modifying security measures because modifying security measures is an abstract idea and there is no evidence that these modifications improve the functioning of the system, technology or technical field. The 112 rejection of the claims is withdrawn in view of the claim amendments. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim(s) 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim(s) recite(s): 1. A method comprising: receiving a request to perform a transfer from a requesting device associated with a user; computing a threshold trust score for accessing data stored in a memory device which is to be used for the transfer based on attributes of the transfer; retrieving identification data associated with the user of the requesting device from an external terminal, a database, and a social networking website; generating a list of identification data including the retrieved identification data; determining a user trust score associated with the user of the requesting device based on the generated list of identification data; modifying a security safeguard of a computer network based on a comparison of the user trust score to the threshold trust score; and executing the transfer via the computer network based on the modified security safeguard. The underlined elements are certain methods of organizing human activity, fundamental economic practices or principles including risk mitigation because the claims recite determining a risk level for performing a transfer and performing the transfer if the risk level is above a threshold risk level. This judicial exception is not integrated into a practical application because the claims also recite , a memory device, a requesting device, a terminal, database and website, adding the words “apply it”, or the like, to the abstract idea. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the claims do not include more than the abstract idea and the additional elements mentioned. The requesting device merely represents the vehicle by which a requester makes the transfer request, according to the specification. The identification data and trust scores are all associated with the requester and not specifically the device, so the device is merely a tool. Claims 12 and 19 are similarly rejected but include a system and a non-transitory computer-readable medium which amount to adding the words “apply it”, or the like to the judicial exception. The dependent claims merely narrow the abstract idea. As a whole and in combination the claims do not reflect integration into a practical application or significantly more. Claims 2-5, 8 and 9 narrow the idea of computing, claim 6 does not further define the identification data of claim 1, and claims 7 and 10 merely perform comparing steps, all of which narrow the abstract idea. The remaining dependent claims are similar. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to WILLIAM E RANKINS whose telephone number is (571)270-3465. The examiner can normally be reached on 9-530 M-F. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bennett Sigmond can be reached on 303-297-4411. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /WILLIAM E RANKINS/Primary Examiner, Art Unit 3694
Read full office action

Prosecution Timeline

Show 19 earlier events
Jan 06, 2026
Request for Continued Examination
Feb 12, 2026
Response after Non-Final Action
Feb 20, 2026
Non-Final Rejection mailed — §101
Apr 28, 2026
Examiner Interview Summary
Apr 28, 2026
Applicant Interview (Telephonic)
May 20, 2026
Response Filed
Jun 10, 2026
Final Rejection mailed — §101
Aug 05, 2026
Response after Non-Final Action

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699985
PROXY CARD MANAGEMENT SYSTEM
10m to grant Granted Aug 04, 2026
Patent 12639678
METHOD OF PROCESSING DIGITAL CHECKS
2y 2m to grant Granted May 26, 2026
Patent 12620020
APPLYING PROVISIONAL RESOURCE UTILIZATION THRESHOLDS
3y 6m to grant Granted May 05, 2026
Patent 12620035
DISTRIBUTED LEDGER SYSTEM FOR MANAGING LOSS HISTORIES FOR PROPERTIES
2y 0m to grant Granted May 05, 2026
Patent 12614160
DISTRIBUTION UTILITY
2y 7m to grant Granted Apr 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

6-7
Expected OA Rounds
58%
Grant Probability
66%
With Interview (+8.2%)
3y 3m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 790 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month