DETAILED ACTION
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant’s submission filed on 12 February 2026 has been entered.
Response to Arguments
Applicant’s arguments (“REMARKS”) filed 12 February 2026 have been fully considered, and they are persuasive as to the previous grounds of rejection.
Claims 1-3, 11, and 16 were amended. Claims 6 and 21-22 were canceled. Claims 4 and 14 were previously canceled. Claims 23-25 are new. Claims 1, 11, and 16 are independent. Claims 1-3, 5, 7-13, 15-20, and 23-25 are currently pending.
Re: Claim Rejections Under 35 U.S.C. §103
Applicant’s amendments and arguments, indicated on pp.11-13 of the REMARKS, in response to the rejection of the claims under 35 U.S.C. §103 with respect to Edwards et al., US 2022/0182380 A1 (hereinafter, “Edwards ‘380”) Kshirsagar et al., US 9,824,199 B2 (hereinafter, “Kshirsagar ‘199”), and US 2010/0082660 (hereinafter, “Muilenburg ‘660”) have been fully considered, and they are persuasive as to the previous grounds of rejection. Specifically, with respect to the independent claims, Applicant argues that:
The references do not disclose the limitation “applying respective weights to different types of behavioral biometrics of the behavioral data, wherein the respective weights influence how the different types of behavioral biometrics contribute to the comparison”, as amended.
The references do not disclose the limitation “adjusting at least one of the respective weights based on evaluation feedback indicative of how prior behavioral biometrics contributed to prior identity determinations associated with the user profile”, as amended.
Note Regarding 35 U.S.C. § 112(a)
A new rejection of independent claims 1, 11, and 16, and of the corresponding dependent claims, under Claim Rejections – 35 USC §112(a) is set forth below. This rejection is directed to the written description support for the limitations added by the amendments, and in particular for the recitation of evaluation feedback indicative of how prior behavioral biometrics contributed to prior identity determinations associated with the user profile.
In Response to Argument A
Applicant argues that Edwards ‘380, Kshirsagar ‘199, and Muilenburg ‘660 fail to disclose “applying respective weights to different types of behavioral biometrics of the behavioral data, wherein the respective weights influence how the different types of behavioral biometrics contribute to the comparison,” as amended in the independent claims.
This argument is persuasive as to the previous grounds of rejection.
With respect to the independent claims, Applicant's arguments and amendments have necessitated new ground(s) of rejection presented in this Office Action. A new ground of rejection has been asserted over Chari et al., US 2016/0006730 A1 (hereinafter, “Chari ‘730”).
Chari ‘730 discloses a system for continuous user authentication in which a server monitors user actions on a user computer, including keyboard events, mouse events, and other sensor input events, and executes a plurality of distinct behavioral biometric modalities, generating a separate individual score for each modality (Chari ‘730, ¶¶34, 43, 51, 54). Chari ‘730 further discloses that the individual scores of the several modalities are combined using weights at an ensemble scoring stage, such that the weight assigned to a given modality governs the extent of its contribution to the resulting identity determination (Chari ‘730, ¶¶40, 69, 93, 117). Chari ‘730 additionally discloses allocating greater weight to behavioral features that better determine user identity (Chari ‘730, ¶89).
See Claim Rejections – 35 USC §103 below for further details.
In Response to Argument B
Applicant argues that Edwards ‘380, Kshirsagar ‘199, and Muilenburg ‘660 fail to disclose “adjusting at least one of the respective weights based on evaluation feedback indicative of how prior behavioral biometrics contributed to prior identity determinations associated with the user profile,” as amended in the independent claims.
This argument is persuasive as to the previous grounds of rejection.
With respect to the independent claims, Applicant's arguments and amendments have necessitated new ground(s) of rejection presented in this Office Action. A new ground of rejection has been asserted over Adir et al., US 2020/0125706 A1 (hereinafter, “Adir ‘706”).
Adir ‘706 discloses assigning a weight to each of a plurality of parameters measured during an authentication process, where the weight is indicative of the significance of that parameter to the verification of the user’s identity. Parameters of greater significance, reliability, and consistency are assigned larger weights in order to increase their contribution, while parameters of lesser significance, reliability, and consistency are assigned smaller weights in order to reduce their contribution (Adir ‘706, ¶¶21, 45, 93, 98). Adir ‘706 further discloses that these weights are updated, adjusted, and adapted according to the analysis of data captured during subsequent authentication processes, and that the weights may be defined according to successful and failed verifications of the user, including by identifying which parameter was highly indicative of the cause of failure and adjusting the weight of that parameter (Adir ‘706, ¶¶24, 48, 94). Adir ‘706 additionally discloses training a model using datasets with labels indicating the success or failure of the corresponding authentication process, such that the weights are adjusted according to the values associated with failed/ successful authentication processes. The model learns the respective weights of successful and of failed authentication processes (Adir ‘706, ¶¶108, 111).
See Claim Rejections – 35 USC §103 below for further details.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-3, 5, 7-13, 15-20, and 23-25 are rejected under 35 U.S.C. 112(a) as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for pre-AIA the inventor(s), at the time the application was filed, had possession of the claimed invention.
As per claims 1, 11, and 16:
Independent claims 1, 11, and 16 were amended to recite the limitations “applying respective weights to different types of behavioral biometrics of the behavioral data, wherein the respective weights influence how the different types of behavioral biometrics contribute to the comparison” and “adjusting at least one of the respective weights based on evaluation feedback indicative of how prior behavioral biometrics contributed to prior identity determinations associated with the user profile”. The Specification does not provide written description support for these limitations for the reasons set forth below.
First, with respect to “weights” applied to “different types of behavioral biometrics”, the only disclosure in the Specification directed to the weighting of behavioral data states that ‘each type of event data can be given a different weight’, that ‘some types of data may have more variance than other types of data’, and that “[s]ame user score model 210 can adjust weights for each type of data to improve scoring” (Specification, ¶56). The weights disclosed at paragraph ¶56 are accordingly applied to types of event data.
The Specification, however, distinguishes event data (also referred as biometric data or behavioral data in the Specification) from the “behavioral biometrics” recited in the claims. For example, the Specification at ¶51 identifies the event data as x-y coordinates of a cursor, mouse movements, mouse clicks, mouse wheel scrolls, mousepad inputs, keyboard events, key inputs, keystrokes, keypress downs, and keypress releases. Specification, at ¶52, then states that same user score model 210 ‘can derive behavioral biometrics or pseudo behavioral biometrics from the event data’. Specification at ¶¶52-55 discloses examples of the derived behavioral biometrics, namely a manner or habit of switching from one field to another field, a velocity and precision of mouse movements, an amount of time spent filling out fields and other input habits, and a typing speed and/or method of typing. Therefore, behavioral biometrics are described as quantities derived from the event data and are not the event data itself.
The Examiner further notes that the remaining weighting disclosure in the Specification, at ¶45, is directed to ‘each type of device data’ within device fingerprint model 206, and to the weighting of sets of device fingerprints. This disclosure is directed to device data rather than to behavioral biometrics, and to a different model than same user score model 210.
Accordingly, while the Specification discloses applying respective weights to different types of event data, it does not disclose applying respective weights to different types of behavioral biometrics, nor does it disclose that the applied weights influence how the different types of behavioral biometrics contribute to the comparison, as recited in claims 1, 11, and 16.
Next, with respect to the limitation “evaluation feedback indicative of how prior behavioral biometrics contributed to prior identity determinations”, the claims require “feedback” that is itself indicative of the “contribution” of particular behavioral biometrics to prior identity determinations. The Specification does not appear to disclose this.
The Specification, at ¶56, discloses that ‘same user score model 210 may determine over time (e.g., by receiving feedback data that identifies whether the end user was actually the claimed person) that patterns of mouse movements are less consistent in providing accurate predictions that the end user is the claimed person’. The feedback data disclosed in the Specification therefore identifies only the correctness of a prior determination (i.e., whether the end user was in fact the claimed person). It is the model, and not the feedback data, that determines over time that a particular type of data is less consistent in providing accurate predictions.
The Specification does not disclose receiving feedback that conveys how any particular behavioral biometric contributed to any prior identity determination, nor does it disclose associating the prior identity determination to any type of behavioral biometric. Accordingly, the Specification accordingly does not provide adequate support for adjusting a weight “based on evaluation feedback indicative of how prior behavioral biometrics contributed to prior identity determinations”, as recited in claims 1, 11, and 16.
As per claims 2-3, 5, 7-10, 12-13, 15, 17-20, and 23-25:
Dependent claims 2-3, 5, 7-10, 12-13, 15, 17-20, and 23-25 depend on claims 1, 11, and 16, and therefore incorporate the same limitations. For the reasons stated above, the Specification does not provide written description support for these limitations.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-3, 5, 7-13, 15-20, and 23-25 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
As per claims 1, 11, and 16:
Claims 1, 11, and 16 recites: “… obtained from one or more sensors of the user device when the user is performing an interaction …”. The term “the user device” makes the claims indefinite as it lacks proper antecedent basis.
As per claims 2-3, 5, 7-10, 12-13, 15, 17-20, and 23-25:
Claims 1, 11, and 16 are rejected under 35 U.S.C. 112(b), as stated above, as being indefinite for failing to particularly point out and distinctly claim the subject matter. Thus, claims 2-3, 5, 7-10, 12-13, 15, 17-20, and 23-25 are rejected under 35 U.S.C. 112(b) by virtue of their dependency from claims 1, 11, and 16.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-2, 8-9, 11-12, 16-17, and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over by Edwards et al., US 2022/0182380 A1 (hereinafter, “Edwards ‘380”), in view of Kshirsagar et al., US 9,824,199 B2 (hereinafter, “Kshirsagar ‘199”), and further in view of Chari et al., US 2016/0006730 A1 (hereinafter, “Chari ‘730”), and further in view of Adir et al., US 2020/0125706 A1 (hereinafter, “Adir ‘706”).
As per claim 1: Edwards ‘380 discloses:
A computer-implemented method comprising: receiving, by a subject evaluation service, behavioral data of a user from a (receiving, by the authenticating device 108, behavioral biometric data from a user 101, also referred to as customer 101, via a user device 102, 104 [Edwards ‘380, ¶¶19, 28, 43, 69; Fig.1, Fig.4 (step 430)]),
wherein the behavioral data includes behavioral biometrics of the user obtained from one or more sensors of the user device (the behavioral biometric data includes behavioral data and biometric data obtained from sensors and input devices of the user device 102, 104 [Edwards ‘380, ¶¶18-19, 45, 54; Figs.1-2])
when the user is performing an interaction with the (the behavioral data may be received while the user 101 is performing an interaction with a service, portal, website, or application on the user device 102, 104, where the interaction may be a log-in attempt into the service, portal, website, or application on the user device 102, 104 [Edwards ‘380, ¶¶20, 43, 69, 83; Fig.4 (step 430)]);
comparing, by the subject evaluation service, the behavioral data with a biometric fingerprint associated with a user profile (comparing, by the authenticating device 108, the received behavioral biometric data with a stored biometric behavioral data profile associated with a user model [Edwards ‘380, ¶¶19, 42, 46, 69, 84; Fig.4 (step 440)]),
and generating, by the subject evaluation service, based on the comparison between the behavioral data and the biometric fingerprint, a score (generating, by the authenticating device 108, a degree of similarity, also referred to as level of similarity or similarity score, based on the comparison between the received behavioral biometric data with a stored biometric behavioral data profile associated with a user model [Edwards ‘380, ¶¶19, 46, 70, 84; Fig.4 (step 450)])
indicative of a likelihood that an identity of the user is associated with the user profile (based on the degree of similarity, authenticate the user 101 and determine the likelihood that an identity of the user 101 is associated with the user model [Edwards ‘380, ¶¶19-20, 46-47, 64, 70, 84; Fig.4 (steps 450 and 480)]).
Edwards ‘380, as stated above, does not explicitly disclosed the limitation “… receiving, by a subject evaluation service, behavioral data of a user from a partner service … when the user is performing an interaction with the partner service via a partner service webpage or application executing on the user device … wherein the comparison between the behavioral data with the biometric fingerprint comprises: applying respective weights to different types of behavioral biometrics of the behavioral data, wherein the respective weights influence how the different types of behavioral biometrics contribute to the comparison; and adjusting at least one of the respective weights based on evaluation feedback indicative of how prior behavioral biometrics contributed to prior identity determinations associated with the user profile …”.
Kshirsagar ‘199, however, discloses:
… receiving, by a subject evaluation service, behavioral data of a user from a partner service … when the user is performing an interaction with the partner service via a partner service webpage or application executing on the user device (receiving, by an application server (which comprises a profile collection service 108 and a profile based authentication service 126), interaction data 118 of a user 120 from a service when the user 120 is performing an interaction with the service via a service webpage executing on a user device 122 [Kshirsagar ‘199, Col.4 line 38-Col.5 line 22, Col.8 lines 34-50, Col.11 lines 8-20; Fig.1]); Kshirsagar ‘199 provides examples of “partner services”, such as cellular providers (which include user information sources 414) and enterprise data assets 602, where interaction data is received from said “partner services” rather than directly from the user [Kshirsagar ‘199, Col.13 lines 48-63, Col.14 lines 24-41, Col.15 line 24-Col.16 line 7; Figs.4-6])
…
…
Edwards ‘380 and Kshirsagar ‘199 are analogous art because they are from the same field of endeavor, namely that of performing authentication using biometric behavioral data. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Edwards ‘380 and Kshirsagar ‘199 before them, to modify the method in Edwards ‘380 to include the teachings of Kshirsagar ‘199, namely to modify the behavioral biometric data collection process of Edwards ‘380 such that behavioral data is received not only directly from a plurality of user devices, but also from a plurality of services, as disclosed in Kshirsagar ‘199, where the interaction data is sent from the services to the authenticating device for the generation of biometric/behavioral data profiles. A motivation for doing so would be to improve the accuracy of biometric authentication by generating a comprehensive identity fingerprint from a plurality of service interactions (see Kshirsagar ‘199, Col.4 line 61-Col.5 line 51).
As stated above, Edwards ‘380 in view of Kshirsagar ‘199 does not explicitly disclose the limitation “… wherein the comparison between the behavioral data with the biometric fingerprint comprises: applying respective weights to different types of behavioral biometrics of the behavioral data, wherein the respective weights influence how the different types of behavioral biometrics contribute to the comparison; and adjusting at least one of the respective weights based on evaluation feedback indicative of how prior behavioral biometrics contributed to prior identity determinations associated with the user profile …”.
Chari ‘730, however, discloses:
… wherein the comparison between the behavioral data with the biometric fingerprint comprises: applying respective weights to different types of behavioral biometrics of the behavioral data, wherein the respective weights influence how the different types of behavioral biometrics contribute to the comparison (a server 20 continuously obtains monitored data related to user actions on a computer 10 of a user, where the monitored input events include keyboard events 307, mouse events 309, and other input events 310, and where input sensor data has included keyboard, mouse, video, audio and mobile devices [Chari ‘730, ¶¶25, 33, 51, 54]; the multi-modal event feature extraction block 220 includes four biometric modalities for user verification, namely a windowing system event sequences modality, a network footprint modality, an application-specific user actions modality, and a forensic linguistic analysis modality, where an individual score is generated for each of the biometric modalities [Chari ‘730, ¶¶34, 43, 92]; the individual scores of the respective biometric modalities are combined at the ensemble scoring block 250 using weights, where individual scores may be combined using an aggregation function such as sum, max, and/or weighting individual components, and where weights are assigned to different features such that the scores for these features are combined using a weighted sum approach [Chari ‘730, ¶¶40, 93, 117]; the weighted sum may be proportional to the accuracy of the models based on the features selected, and where a modality yields little entropy the system may rely more on [Chari ‘730, ¶¶69, 89]);
…
Edwards ‘380 (modified by Kshirsagar ‘199) and Chari ‘730 are analogous art because they are from the same field of endeavor, namely that of performing authentication using biometric behavioral data. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Edwards ‘380 (modified by Kshirsagar ‘199) and Chari ‘730 before them, to modify the method in Edwards ‘380 (modified by Kshirsagar ‘199) to include the teachings of Chari ‘730, namely to modify the comparison process of Edwards ‘380 such that the plurality of types of behavioral biometrics are assigned respective weights that govern the extent to which each type contributes to the comparison, as disclosed in Chari ‘730. A motivation for doing so would be to improve the accuracy of the identity verification by weighting each type of behavioral biometric in proportion to the accuracy of the model from which its score is derived, and by relying more heavily upon those behavioral features that better discriminate the identity of the user (see Chari ‘730, ¶¶69, 89).
As stated above, Edwards ‘380 in view of Kshirsagar ‘199, and further in view of Chari ‘730 does not explicitly disclose the limitation “… and adjusting at least one of the respective weights based on evaluation feedback indicative of how prior behavioral biometrics contributed to prior identity determinations associated with the user profile …”.
Adir ‘706, however, discloses:
… and adjusting at least one of the respective weights based on evaluation feedback indicative of how prior behavioral biometrics contributed to prior identity determinations associated with the user profile (one or more of the authentication process parameters are assigned a respective weight indicative of a significance of the respective authentication process parameter to the verification of the user, where parameters having higher significance, reliability, and consistency are assigned larger weights to increase their contribution, and where parameters having lesser significance, reliability, and consistency are assigned smaller weights to reduce their contribution [Adir ‘706, ¶¶21, 45, 93, 98]; one or more weights associated with respective authentication process parameters are automatically adjusted, updated, and adapted according to the analysis of the data captured during one or more subsequent authentication processes following the first authentication process, where the weights may be defined according to successful and/or failed verification of the biometric signature of the user 206; during the analysis of one or more failed verifications, the authenticator 222 may identify that the value of one or more of the authentication process parameters is highly indicative of a root cause for the verification failure and may assign a larger weight to the parameter [Adir ‘706, ¶¶24, 48, 94]; the machine learning model is trained with training datasets with a label indicating success or failure of the authentication process, where the machine learning model adjusts the weights assigned to the authentication process parameters according to values associated with failed/ successful authentication processes, and where the machine learning model is trained to detect the authentication process parameters and their weight characteristic to authentication processes [Adir ‘706, ¶¶108, 111]).
Edwards ‘380 (modified by Kshirsagar ‘199 and Chari ‘730) and Adir ‘706 are analogous art because they are from the same field of endeavor, namely that of performing authentication of a user based on a comparison of measured data against a stored model of the user. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Edwards ‘380 (modified by Kshirsagar ‘199 and Chari ‘730) and Adir ‘706 before them, to modify the method in Edwards ‘380 (modified by Kshirsagar ‘199 and Chari ‘730) to include the teachings of Adir ‘706, namely to implement the respective weights of Chari ‘730 such that at least one of the weights is subsequently adjusted according to successful and failed verifications of the user, where the parameter identified as indicative of the outcome of a prior verification has its weight adjusted accordingly, as disclosed in Adir ‘706. A motivation for doing so would be to constantly enhance the model during multiple authentication processes so as to significantly improve its accuracy, consistency, and correspondence with the user, and to tune the system to each user in order to further increase the robustness, accuracy, and immunity of the authentication process (see Adir ‘706, ¶¶21, 24, 48).
As per claim 2: Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706 discloses all limitations of claim 1, as stated above, from which claim 2 is dependent upon. Furthermore, Edwards ‘380 discloses:
further comprising: requiring the user to perform additional security measures when the score is below a threshold score (initiating a secondary authentication method when the degree of similarity is below a predetermined threshold [Edwards ‘380, ¶¶48, 70, 84; Fig.4 (step 460)]);
or granting access to the user without requiring the user to perform additional security measures when the score is above a threshold score (when the degree of similarity is above a predetermined threshold, granting access to the user 101 without performing secondary authentication methods [Edwards ‘380, ¶¶46, 70, 84; Fig.4 (steps 450 and 480)]).
As per claim 8: Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706 discloses all limitations of claim 1, as stated above, from which claim 8 is dependent upon. Furthermore, Edwards ‘380 discloses:
further comprising: receiving device data from the user device while the user is performing the interaction with the service executing on the user device (receiving scenario data, also-referred to as scenario-specific data, from the user device 102, 104 while the user 101 is performing an interaction with a service, portal, website, or application on the user device 102, 104, where the interaction may be a log-in attempt into the service, portal, website, or application on the user device 102, 104, and where the scenario data may be specific to the user device 102, 104 [Edwards ‘380, ¶¶43, 58, 60-61, 83]),
wherein the device data includes identifying information about the user device (the scenario data may include a device identifier [Edwards ‘380, ¶¶22, 43, 58, 60, 63]);
comparing the device data with device fingerprints to identify the device fingerprint associated with the user device (comparing the received scenario data and stored scenario data associated with the user device user device 102, 104 [Edwards ‘380, ¶¶58, 63, 84], where associated stored scenario data is identified, and where the associated stored scenario data corresponds to the user device [Edwards ‘380, ¶¶60-65]).
As per claim 9: Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706 discloses all limitations of claims 1 and 8, as stated above, from which claim 9 is dependent upon. Furthermore, Edwards ‘380 discloses:
further comprising: determining, based on the comparison between the device data and the device fingerprints, that the user device is a device that has not been historically used by the user (based on the comparison between the received scenario data and stored scenario data associated with the user device user device 102, 104, determine whether the user device is historically used by the user 101 [Edwards ‘380, ¶¶60-65]);
requiring the user to perform additional security measures based on a determination that the user device is not the device historically used by the user (initiating a secondary authentication method when the degree of similarity between the received scenario data and stored scenario data is below a predetermined threshold (i.e., the device user device 102, 104 is not the device historically used by the user 101) [Edwards ‘380, ¶¶60, 63, 65, 84).
As per claims 11-12:
Claims 11-12 define a system that recites substantially similar subject matter as the method of claims 1-2, respectively. Specifically, claims 11-12 are directed to a system comprising a non-transitory memory storing computer-readable instructions and a processor to execute the instructions to perform the computer-implemented method of claims 1-2, respectively, where claim 12 recites the first alternative recited in claim 2. Thus, the rejection of claims 1-2 is equally applicable to claims 11-12, respectively.
As per claims 16-17 and 19-20:
Claims 16-17 and 19-20 define a non-transitory computer-readable medium that recites substantially similar subject matter as the method of claims 1, 2, and 8-9, respectively. Specifically, claims 16-17 and 19-20 are directed to a non-transitory computer-readable medium comprising instructions which may be executed by a processor to perform the computer-implemented method of claims 1, 2, and 8-9, respectively, where claim 17 recites the second alternative recited in claim 2. Thus, the rejection of claims 1, 2, and 8-9 is equally applicable to claims 16-17 and 19-20, respectively.
Claims 3 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706, and further in view of Upson et al., US 8,533,815 B1 (hereinafter, “Upson ‘815”).
As per claim 3: Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706 discloses all limitations of claims 1-2, as stated above, from which claim 3 is dependent upon. Furthermore, Edwards ‘380 discloses:
further comprising: wherein, in response to the method requiring the user to perform the additional security measures: (initiating a secondary authentication method when the degree of similarity is below a predetermined threshold [Edwards ‘380, ¶¶48, 70, 84; Fig.4 (step 460)])
receiving a successful authentication response to the (based on the degree of similarity, authenticate the user 101 and determine the likelihood that an identity of the user 101 is associated with the user model [Edwards ‘380, ¶¶19-20, 46-47, 64, 70, 84; Fig.4 (steps 450 and 480)]); and
updating the biometric fingerprint with the behavioral data to generate an updated biometric fingerprint (updating the stored biometric behavioral data profile associated with a user model with the received biometric behavioral data [Edwards ‘380, ¶¶46-47]).
As stated above, while Edwards ‘380 discloses updating the user model in response to a successful authentication, Edwards ‘380 does not disclose updating the user model in response to a successful authentication of the secondary authentication method. Specifically, Edwards ‘380 does not explicitly disclose the limitation “… receiving a successful authentication response to the additional security measures … based on the successful authentication response to the additional security measures … updating the biometric fingerprint with the behavioral data …”.
Upson ‘815, however, discloses:
… receiving a successful authentication response to the additional security measures (in response to denying access to a resource based on a biometric template, performing an additional authentication method based on a passkey, where the passkey may be successfully received from a user [Upson ‘815, Col.4 lines 7-67; Figs.1-2])
… based on the successful authentication response to the additional security measures … updating the biometric fingerprint with the behavioral data … (based on successful authentication of the user based on the passkey, updating the biometric template with the newly received biometric data [Upson ‘815, Col.5 lines 1-22; Figs.1-2])
Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Upson ‘815 are analogous art because they are from the same field of endeavor, namely that of performing authentication using biometric behavioral data. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Upson ‘815 before them, to modify the method in Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) to include the teachings of Upson ‘815, namely to modify the user model update process of Edwards ‘380 such that the user models are updated with newly received data after a successful secondary authentication process, as disclosed in Upson ‘815. A motivation for doing so would be to reduce instances where users are falsely rejected by constantly updating the biometric template with new data (see Upson ‘815, Col.3 lines 34-50, Col.5 lines 1-22).
As per claim 13: Claim 13 defines a system that recites substantially similar subject matter as the method of claim 3. Specifically, claim 13 is directed to a system comprising a non-transitory memory storing computer-readable instructions and a processor to execute the instructions to perform the computer-implemented method of claim 3. Thus, the rejection of claim 3 is equally applicable to claims 13.
Claims 5 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706, and further in view of Machani, US 9,935,947 B1 (hereinafter, “Machani ‘947”).
As per claim 5: Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706 discloses all limitations of claim 1, as stated above, from which claim 5 is dependent upon. Furthermore, Edwards ‘380 discloses:
wherein the user device is a (determine an initial user model for a user/user device that is logging in to a service [Edwards ‘380, ¶¶59, 83]),
the method further comprising: determining that the identity of the user is associated with the user profile (determining that the identity of the user is associated with the user model based on login attempts [Edwards ‘380, ¶¶59-63]);
and updating a device fingerprint with device data of the user device (updating the stored scenario data associated with the received scenario data [Edwards ‘380, ¶¶53, 64]),
wherein the device data includes identifying information about the user device (the scenario data may include a device identifier [Edwards ‘380, ¶¶22, 43, 58, 60, 63]).
As stated above, Edwards ‘380 does not explicitly disclose the limitation “… wherein the user device is a new device that the user has not used to interact with the service before …”.
Machani ‘947, however, discloses:
… wherein the user device is a new device that the user has not used to interact with the service before (a new device has not been used to interact with the biometric system before; updating the registry of user devices associated with the user by adding the information identifying the new device to the registry of user devices associated with the user [Machani ‘947, Col.17 lines 49-55, Col.18 lines 37-62]) …
Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Machani ‘947 are analogous art because they are from the same field of endeavor, namely that of performing authentication using biometric behavioral data. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Machani ‘947 before them, to modify the method in Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) to include the teachings of Machani ‘947, namely to implement the generation of a new user model, as disclosed in Edwards ‘380, to be associated with incorporating a new device into the user model that uses a service, as disclosed in Machani ‘947. A motivation for doing so would be to increase the utility of the system by incorporating additional devices that are associated with the user, where the additional devices are incorporated into the system after a secure verification process (see Machani ‘947, Col.17 lines 49-55, Col.18 lines 37-62).
As per claim 15: Claim 15 defines a system that recites substantially similar subject matter as the method of claim 5. Specifically, claim 15 is directed to a system comprising a non-transitory memory storing computer-readable instructions and a processor to execute the instructions to perform the computer-implemented method of claim 5. Thus, the rejection of claim 5 is equally applicable to claims 15.
Claims 7 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706, and further in view of Hall et al., US 2022/0366027 A1 (hereinafter, “Hall ‘027”).
As per claim 7: Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706 discloses all limitations of claim 1, as stated above, from which claim 7 is dependent upon. Furthermore, Edwards ‘380 discloses:
wherein the interaction is associated with a first user (the interaction is associated with a first user device [Edwards ‘380, ¶¶43-44; Fig.1]),
the method further comprising: receiving additional behavioral data from the user, wherein the additional behavioral data includes additional behavioral biometrics of the user obtained from the one or more sensors of the user device when the user is performing an additional interaction associated with a second user (receiving additional behavioral biometric data from the user 101 from interactions with a service via sensors from a second user device 104 [Edwards ‘380, ¶¶43-44; Fig.1]); and
determining, based on the additional biometric data and the biometric fingerprint, that the user is associated with both the first user (determining based on the additional behavioral biometric data and the user model, that the user 101 is associated with both the first user device and the second user device [Edwards ‘380, ¶¶49, 60-62).
As stated above, Edwards ‘380 does not explicitly disclose the limitation “… the interaction is associated with a first user account … an additional interaction associated with a second user account … determining … that the user is associated with both the first user account and the second user account…”.
Hall ‘027, however, discloses:
… the interaction is associated with a first user account … an additional interaction associated with a second user account … determining … that the user is associated with both the first user account and the second user account (a user of computing device 106, or of multiple computing devices 106, creates different user accounts on the biometric information monitoring platform 110, resulting in user data for the same user being associated with two different user identifiers, where the user analysis module 624 analyzes the user data, including the biometric measurements 604, to determine when user data associated with multiple user identifiers is associated with the same user, and where the data combining module 626 combines the user data associated with the multiple user identifiers so that the user data is associated with the same user identifier [Hall ‘027, ¶¶108-110, 121]) …
Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Hall ‘027 are analogous art because they are from the same field of endeavor, namely that of performing authentication using biometric behavioral data. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Hall ‘027 before them, to modify the method in Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) to include the teachings of Hall ‘027, namely to implement the user determination process of Edwards ‘380 to not only determine that two different devices may be associated with the same user, based on biometric data, but also determine that two different accounts may be associated with the same user, as disclosed in Hall ‘027. A motivation for doing so would be to increase accuracy of collected data across different accounts as well as reduce the number of redundant accounts (see Hall ‘027, ¶¶108, 121).
As per claim 18: Claim 18 defines a non-transitory computer-readable medium that recites substantially similar subject matter as the method of claim 7. Specifically, claims 18 is directed to a non-transitory computer-readable medium comprising instructions which may be executed by a processor to perform the computer-implemented method of claim 7. Thus, the rejection of claim 7 is equally applicable to claim 18.
Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706, and further in view of Popa, US 2023/0140665 A1 (hereinafter, “Popa ‘665”), and further in view of Chow, US 11,090,566 B1 (hereinafter, “Chow ‘566”).
As per claim 10: Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706 discloses all limitations of claim 1, as stated above, from which claim 10 is dependent upon. Furthermore, Edwards ‘380 discloses:
further comprising: (implementing an authentication device 108 configured to receive behavioral biometric data and behavioral biometric data of user models, and output a similarity score indicative of the likelihood that the identity of the user is associated with the user model [Edwards ‘380, ¶¶43, 46-49]),
(the authentication device is configured such that the similarity score is increased when the received behavioral biometric data of a user is associated with the stored behavioral biometric data of a user model, and the similarity score is decreased when the received behavioral biometric data of a user is not associated with the stored behavioral biometric data of a user model [Edwards ‘380, ¶¶19, 46-48, 53, 84]).
As stated above, Edwards ‘380 does not explicitly disclose the limitation “… training a machine learning model configured to receive the behavioral data and the biometric fingerprint … the training comprising: providing training behavioral data inputs to the machine learning model; providing training biometric fingerprints inputs to the machine learning model; and incrementing an output score … decrementing the output score …”.
Popa ‘665, however, discloses:
training a machine learning model configured to receive the behavioral data and the biometric fingerprint … the training comprising: providing training behavioral data inputs to the machine learning model; providing training biometric fingerprints inputs to the machine learning model (a machine learning (ML) algorithm(s) used for authentication that is trained on behavioral biometrics patterns (BBP), such as typing patterns from a large array of anonymized or artificially generated users (AAGU) with the ability to process any new BBP and return an array of matching results against each of the anonymized users that the model was trained on. The output matrices or result is then matched against previously recorded similar data and returns a matching/authentication score or binary result [Popa ‘665, ¶¶29, 47-49]); and
Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Popa ‘665 are analogous art because they are from the same field of endeavor, namely that of performing authentication using biometric behavioral data. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Popa ‘665 before them, to modify the method in Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) to include the teachings of Popa ‘665, namely to implement the authentication device of Edwards ‘380 as a trained machine learning model, as disclosed in Popa ‘665, where the machine learning model is trained by providing training behavioral biometric data and training user models. A motivation for doing so would be to increase the accuracy and security of biometric/behavioral based authentication processes by incorporating a ML model which can be trained and tweaked for more accuracy (see Popa ‘665, ¶¶3-7).
As stated above, Edwards ‘380 in view of Popa ‘665 does not explicitly disclose the limitation “… training a machine learning model … incrementing an output score … decrementing the output score …”.
Chow ‘566, however, discloses:
… training a machine learning model … incrementing an output score … decrementing the output score (the behavior analysis engine 400 may match certain attributes in training the behavior learning model 408b, where the behavioral value point may be incremented or decremented by a multiple of the adjustment value point [Chow ‘566, Col.27 lines 34-53, Col.33 line 51-Col.34 line 7]) …
Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, Adir ‘706, and Popa ‘665) and Chow ‘566 are analogous art because they are from the same field of endeavor, namely that of analyzing and utilizing user behavior data. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, Adir ‘706, and Popa ‘665) and Chow ‘566 before them, to modify the method in Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, Adir ‘706, and Popa ‘665) to include the teachings of Chow ‘566, namely to implement the authentication device of Edwards ‘380 as a trained machine learning model, as disclosed in Popa ‘665, where outputs are incremented or decremented based on corresponding comparison operations, as disclosed in Chow ‘566. A motivation for doing so would be to better analyze and define user behaviors by using incremental tweaks to the value points during training (see Chow ‘566, Col.33 line 51-Col.34 line 7).
Claims 23-25 are rejected under 35 U.S.C. 103 as being unpatentable over Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706, and further in view of Muilenburg et al., US 2010/0082660 (hereinafter, “Muilenburg ‘660”).
As per claim 23: Edwards ‘380, in view of Kshirsagar ‘199, and further in view of Chari ‘730, and further in view of Adir ‘706 discloses all limitations of claim 1, as stated above, from which claim 23 is dependent upon. Furthermore, Edwards ‘380 discloses:
wherein the biometric fingerprint is based on an aggregation of behavioral biometrics of the user reported by at least two (generating a biometric/behavioral data profile comprising one or more user models, where the biometric/behavioral data profile is generated, by the authenticating device 108, based on user interaction data received from a plurality of user devices [Edwards ‘380, ¶¶42-43, 49, 53-54, 60-61]).
Edwards ‘380, as stated above, does not explicitly disclose the limitation “… an aggregation of behavioral biometrics of the user reported by at least two partner services from event data recorded while the user previously interacted with the at least two partner services, wherein each of the at least two partner services execute a script configured to report the behavioral biometrics …”.
Kshirsagar ‘199, however, discloses:
… an aggregation of behavioral biometrics of the user reported by at least two partner services from event data recorded while the user previously interacted with the at least two partner services (aggregating user interaction data to generate a historical profile and an identity fingerprint for the user, where the generated identity fingerprint is used for subsequent authentication operations, and where the interaction data is transmitted from a plurality of different services. For example, www.awebstore.com (i.e., a first partner service) transmits user interaction data 106 to an application server (which comprises a profile collection service 108 and a profile based authentication service 126). Next, www.mysocialnet.com (i.e., a second partner service) transmits user interaction data 112 to the application server (i.e., the subject evaluation service), where the application server aggregates the interaction data to generate and store an identity fingerprint for the user [Kshirsagar ‘199, Col.2 line 32-Col.4 line 25, Col.8 lines 34-50; Fig.1]), the behavioral biometrics of the user to the subject evaluation service …
Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Kshirsagar ‘199 are analogous art for the reasons stated in claim 1. For the reasons stated in claim 1, prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Kshirsagar ‘199 before them, to modify the method in Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) to include the teachings of Kshirsagar ‘199.
As stated above, Edwards ‘380 in view of Kshirsagar ‘199 does not explicitly disclose the limitation “… wherein each of the at least two partner services execute a script configured to report the behavioral biometrics of the user to the subject evaluation service …”.
Muilenburg ‘660, however, discloses:
… wherein each of the at least two partner services execute a script configured to report the behavioral biometrics of the user to the subject evaluation service (a method for aggregating user profile information in a network of affiliated websites [Muilenburg ‘660, ¶¶Abstract, 48; Fig.2A], where interaction data 215 is received by the website manager 210 from a plurality of websites, and where user profiles 222 are generated based on the aggregated interaction data, and where the websites are configured to execute instructions, including scripting technologies such as Javascript, to transmit interaction data to the website manager [Muilenburg ‘660, ¶¶48, 63, 66, 72-73, 76, 91, 105, 161, 290; Fig.2A, Fig.3A]) …
Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Muilenburg ‘660 are analogous art because they are from the same field of endeavor, namely that of performing authentication using biometric behavioral data. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) and Muilenburg ‘660 before them, to modify the method in Edwards ‘380 (modified by Kshirsagar ‘199, Chari ‘730, and Adir ‘706) to include the teachings of Muilenburg ‘660, namely to modify the behavioral biometric data collection process of Edwards ‘380 such that interaction data is not only aggregated via a plurality of devices, but also via a plurality of services, as disclosed in Kshirsagar ‘199, where each of the services is configured to transmit interaction data to the authenticating device in response to the execution of specific instructions, as disclosed in Muilenburg ‘660. A motivation for doing so would be to increase the effectiveness of marketing by modifying websites such that they are dynamically configured for a particular user based on user activity received from a plurality of other websites (see Muilenburg ‘660, ¶¶27-29).
As per claims 24-25: Claims 24-25 define a system and a non-transitory computer-readable medium, respectively, that recite substantially similar subject matter as the method of claim 23. Specifically, claim 24 is directed to a system comprising a non-transitory memory storing computer-readable instructions and a processor to execute the instructions to perform the computer-implemented method of claim 23, and claim 25 is directed to a non-transitory computer-readable medium comprising instructions which may be executed by a processor to perform the computer-implemented method of claim 23. Thus, the rejection of claim 23 is equally applicable to claims 24-25, respectively.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
Lynch, US 20100281059 A1: The user profile comprises identity data such as static information about a user and behavior data comprising dynamic information about the user, monitor the activities of the user through an interface to collect behavior indicators, and to update the behavior data using the collected behavior indicators
Bordow, US 11290448 B1: generation a central identity databank for a user's digital life. The identity databank may include identity elements with payload values and metadata values corresponding immutable attributes of the user, allows service provider devices to more reliably validate transactions with user devices via an identity system.
Deutschmann et al., US 11860985 B2: While the user uses the device, behaviometric data is recorded which includes measures of how the user uses the device. Additional data, however, can only be accessed with a biometric and/or second authentication after collecting at least some behaviometric data.
Zaki et al., US 20210390165 A1: demonstrating, to the user, historical account data based on the login status, wherein the historical account data comprises at least historical biometric data associated with one or more historical logins; receiving, via the one or more processors, the user instruction based on the historical account data.
Chan et al., US 20210044578 A1: A system for utilizing behavioral features to authenticate a user entering login credentials. Receive a request to access a user account and compare behavioral features included in the request to behavioral features included in a user behavior profile associated with the user account.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALAN L KONG whose telephone number is (571)272-2646. The examiner can normally be reached Monday-Friday 9:00am-5:30pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JUNG (JAY) KIM can be reached on (571)272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ALAN L KONG/Examiner, Art Unit 2494
/KAVEH ABRISHAMKAR/Primary Examiner, Art Unit 2494