Prosecution Insights
Last updated: October 02, 2026
Application No. 18/143,423

PHYSICAL STATE CHANGE AUTHENTICATION METHODS

Non-Final OA §102
Filed
May 04, 2023
Examiner
NOAMAN, BASSAM A
Art Unit
2497
Tech Center
2400 — Computer Networks
Assignee
T-Mobile USA Inc.
OA Round
5 (Non-Final)
79%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
223 granted / 282 resolved
+21.1% vs TC avg
Strong +46% interview lift
Without
With
+46.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
20 currently pending
Career history
295
Total Applications
across all art units

Statute-Specific Performance

§101
6.3%
-33.7% vs TC avg
§103
60.4%
+20.4% vs TC avg
§102
9.5%
-30.5% vs TC avg
§112
16.7%
-23.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 282 resolved cases

Office Action

§102
DETAILED ACTION This Non-Final Office Action is in response to Request for Continued Examination filed on 08/14/2026. Claims 1, 9 and 17 have been amended. Claims 8, 16 and 20 are/were cancelled. Claims 21-23 have been newly added. Claims 1-7, 9-15, 17-19 and 21-23 filed on 08/14/2026 remain pending in the application. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Drawings The drawings filed on 05/04/2023 are accepted. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 08/14/2026 has been entered. Response to Amendment Applicant’s amendments to the independent claims have overcome the USC 112(a) rejection previously set forth in the Final Office Action mailed on 04/15/2026. Response to Arguments The applicant’s remarks filed on 08/14/2026 have been moot considering the newly found prior art COGGILL (US 20120126940 A1). Please see detailed rejections below. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-7, 9-15, 17-19 and 21-23 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by COGGILL (US 20120126940 A1). Regarding claim 1 (Currently Amended), Vaughn teaches One or more non-transitory computer-readable media having computer-executable instructions embodied thereon that, when executed, perform a method for leveraging physical state changes of a user equipment (UE) for authentication (COGGILL Abstract “A communication or computing device having a touchscreen interface is adapted to detect a duress condition upon user access through input of a gesture-based password or authentication code.”, utilizing different sensors, e.g. touch screen sensor, force sensor as disclosed in [0070] and orientation sensor as disclosed in [0041] “The communication device may also be provided with an accelerometer 111, which may be used to detect gravity- or motion-induced forces and their direction. Detection of such forces applied to the device 100 may be processed to determine a response of the device 100, such as an orientation of a graphical user interface displayed on the display interface 110 in response to a determination of the current orientation of which the device 100.” and [0078] “…the communication device 100 may be configured to accept a password entered via the touchscreen 110 only while the device 100 is in a specific orientation”), the method comprising: receiving, via one or more sensors of the UE, sensor data corresponding to a series of unlock gestures, the series of unlock gestures comprising a plurality of physical state changes of the UE detected by two or more different classes of the one or more sensors (COGGILL [0073] “…a password may be used to secure access to the device 100.”, [0078] “Symbol passwords may be rendered more complex with multiple line segments or multiple paths, dots, and combined straight edges and curves. FIG. 8A …the communication device 100 may be configured to accept a password entered via the touchscreen 110 only while the device 100 is in a specific orientation”, e.g. touch screen sensor and orientation sensor), the physical state changes comprising one or more of: detecting a location of the UE, detecting a change to movement of the UE, detecting a change to orientation of the UE, detecting contact with the UE, detecting audible signals, or detecting light intensity (COGGILL [0078] “Symbol passwords may be rendered more complex with multiple line segments or multiple paths, dots, and combined straight edges and curves. FIG. 8A …the communication device 100 may be configured to accept a password entered via the touchscreen 110 only while the device 100 is in a specific orientation”, e.g. touch screen sensor and orientation sensor), determining that an ordered sequence of the unlock gestures matches a stored unlock sequence associated with a user of the UE (COGGILL [0078] “The symbol in FIG. 8A includes three components: a first line 810, a disconnected loop 820, and a series of four dots 830. If such a complex symbol is used as a password, the device 100 may require that the various elements 810, 820, 830 be traced on the device display 110 in a consistent order for the password to be validated…the communication device 100 may be configured to accept a password entered via the touchscreen 110 only while the device 100 is in a specific orientation…”, therefore, the ordered sequence of the unlock gestures start with the 1) specific orientation, then followed by elements 810, 820, 830 on the touch screen, which is compared to stored gestures and orientation as disclosed in [0076, 0082, 0086] “Once the password entry has been determined to be complete, the device 100 stores data representative of the symbol input and detected via the touchscreen display interface 110. The data will represent the path represented by the symbol, for example expressed in x-y coordinates with reference to the orientation of the device 100 at the time the password was entered. This x-y data may be stored in any suitable format at the device, for example concatenated as a single string.”), wherein the stored unlock sequence is one of a plurality of stored sequences associated with the user of the UE, and wherein different stored sequences of the plurality of stored unlock sequences correspond to different specific actions (COGGILL discloses stored sequences that are temporally different to distinguish normal sequence from a sequence under duress as disclosed in [0090] “…if the device 100 is also equipped with a force sensor or sensors 270, the application of force may be used to identify a duress situation. To indicate to the device 100 that the password is being entered under conditions of duress, the user may simply enter the same, predefined password, but press harder on the display interface 110 than normally for the entire duration of password entry or for a portion thereof. The device 100 may detect the applied force and interpret the password entry as a duress signal and take any predefined action in respect of the duress signal. Alternatively, duress may be indicated to the device 100 when the password is entered with less force than associated with normal password entry.”, [0097] “…timing data may be used to confirm whether a duress condition exists. As noted above, timing data, such as the time elapsed in tracing a symbol or in actuating the keys corresponding to the password, may be determined and stored. Since applying additional force to the touchscreen display interface 110 increases the normal force at the surface of the display interface 110, friction between the user's digit or contact tool and the display interface 110 may increase, causing the password entry to be slower. A marked increase in the amount of time required to compete the correct password may be used to confirm that a duress condition exists… when the password is initially set at the device 100 (as it may be with reference to the process illustrated in FIG. 10), timing data associated with the password may be stored at the device 100 as well. When password entry is subsequently detected at the communication device 100, the time required to complete the subsequent password entry is compared to the timing data. If the subsequent password entry time generally matches the stored timing data (for example, within a given tolerance), no duress condition is identified. However, if the subsequent password entry time is significantly greater or less than the stored timing data (for example, .+-.10%) while the password itself that was input otherwise matches the stored password data, a duress condition is identified. The variance between the subsequent password entry time and the stored timing data may be fixed by means of the IT policy or a setting at the communication device 100.”, where the normal sequence, e.g. Figure 9 in [0078] is similar to the sequence when a person is under duress, examiner notes that COGGILL further discloses in [0098] two different sequences, i.e. not just temporally different, and further indicates that using the temporally different sequences have more benefits as disclosed in [0098] “By defining the duress password as the same password, but simply entered on the touchscreen display 110 or keyboard 116 with greater applied force than the usual, non-duress password, the user is not required to remember any extra data (such as an extra code or series of key presses) in order to trigger a duress condition at the device 100… This is beneficial since in a real duress situation the user may panic and not recall the extra steps to be taken.”); and in response to determining that the ordered sequence matches the stored unlock sequence, unlocking at least a portion of the UE to perform [[a]] the specific action corresponding to the stored unlock sequence matched by the ordered sequence (COGGILL [0074] “…to render inaccessible any sensitive data that may be compromised by the attack.”, [0096] “…If the match is successful and no duress flag was previously set at 1425, then access to the device is permitted at 1455. If the match is successful but the duress flag had been previously set, then the device 100 may interpret this password as a duress password and enter the duress condition at 1460 and take any predefined action in respect of duress.”). Regarding claim 9, claim 9 recites similar limitations to claim 1, therefore rejected with the same rationale applied to claim 1. Regarding claim 17, claim 1 recites similar limitations to claim 1, therefore rejected with the same rationale applied to claim 1. Note that the action is recited in the alternative, which includes unlocking the device, which is disclosed COGGILL in Figure 14 1455 as discussed in claim 1 and COGGILL [0096]. Regarding claim 2 (Previously Presented), COGGILL teaches the non-transitory media of claim 1, further comprising, based on the determining that the ordered sequence matches the stored unlock sequence, selecting the specific action to perform (COGGILL [0096] “…If the match is successful and no duress flag was previously set at 1425, then access to the device is permitted at 1455. If the match is successful but the duress flag had been previously set, then the device 100 may interpret this password as a duress password and enter the duress condition at 1460 and take any predefined action in respect of duress.”). Regarding claim 10, claim 10 recites similar limitations to claim 2, therefore rejected with the same rationale applied to claim 2. Regarding claim 3 (Previously Presented), COGGILL teaches the non-transitory media of claim 1, further comprising performing the specific action opens an application on the UE (COGGILL [0076 “If the detected path matches, or substantially matches, the stored information, then the device 100 may permit access to the device's functions and data.”, [0096] “…access to the device is permitted at 1455. ”). Regarding claim 11, claim 11 recites similar limitations to claim 3, therefore rejected with the same rationale applied to claim 3. Regarding claim 4 (Previously Presented), COGGILL teaches the non-transitory media of claim 1, further comprising performing the specific action causes the UE to communicate information to another device (COGGILL [0074] “The device 100 could therefore be configured to surreptitiously and automatically initiate deletion or encryption, or take some other duress response step, such as transmitting a message requesting assistance from law enforcement”). Regarding claim 12, claim 12 recites similar limitations to claim 4, therefore rejected with the same rationale applied to claim 4. Regarding claim 5 (Previously Presented), COGGILL teaches the non-transitory media of claim 1, further comprising performing the specific action causes fake information to be displayed by the UE (COGGILL [0074] “The device 100 could therefore be configured to surreptitiously and automatically initiate deletion or encryption, or take some other duress response step, such as transmitting a message requesting assistance from law enforcement, or even executing a pre-programmed simulation to make it appear that the device 100 is broken and unable to access its data stores.”) Regarding claim 13, claim 13 recites similar limitations to claim 5, therefore rejected with the same rationale applied to claim 5. Regarding claim 6 (Previously Presented), COGGILL teaches the non-transitory media of claim 1, further comprising performing the specific action causes sensitive information to be encrypted or unavailable (COGGILL [0074] “…to render inaccessible any sensitive data that may be compromised by the attack…The device 100 could therefore be configured to surreptitiously and automatically initiate deletion or encryption, or take some other duress response step, such as transmitting a message requesting assistance from law enforcement, or even executing a pre-programmed simulation to make it appear that the device 100 is broken and unable to access its data stores.”. Regarding claim 14, claim 14 recites similar limitations to claim 6, therefore rejected with the same rationale applied to claim 6. Regarding claim 7 (Previously Presented), COGGILL teaches the non-transitory media of claim 1, further comprising performing the specific action blocks a portion of functionality of the UE (COGGILL [0074] “…to render inaccessible any sensitive data that may be compromised by the attack…unable to access its data stores”). Regarding claim 15, claim 15 recites similar limitations to claim 7, therefore rejected with the same rationale applied to claim 7. Regarding claim 18 (Original), COGGILL teaches the system of claim 17, wherein the physical state changes comprise one or more of detecting a location of the UE, detecting changes to movement of the UE, or detecting changes to an orientation of the UE (COGGILL [0041] “The communication device may also be provided with an accelerometer 111, which may be used to detect gravity- or motion-induced forces and their direction. Detection of such forces applied to the device 100 may be processed to determine a response of the device 100, such as an orientation of a graphical user interface displayed on the display interface 110 in response to a determination of the current orientation of which the device 100.” and [0078] “…the communication device 100 may be configured to accept a password entered via the touchscreen 110 only while the device 100 is in a specific orientation”). Regarding claim 19 (Original), COGGILL teaches the system of claim 17, wherein the physical state changes comprise detecting contact with the UE (COGGILL [0073] “…a password may be used to secure access to the device 100.”, [0078] “Symbol passwords may be rendered more complex with multiple line segments or multiple paths, dots, and combined straight edges and curves. FIG. 8A …the communication device 100 may be configured to accept a password entered via the touchscreen 110 only while the device 100 is in a specific orientation”, e.g. touch screen sensor and orientation sensor). Regarding claim 21 (Original), COGGILL teaches non-transitory media of claim 1, wherein the plurality of stored unlock sequences comprises a first stored unlock sequence corresponding to unlocking the UE and a second stored unlock sequence corresponding to unlocking the UE in a protected mode in which at least one application on the UE is encrypted or unavailable for the user to open (COGGILL discloses stored sequences that are temporally different to distinguish normal sequence from a sequence under duress as disclosed in [0090] “…if the device 100 is also equipped with a force sensor or sensors 270, the application of force may be used to identify a duress situation. To indicate to the device 100 that the password is being entered under conditions of duress, the user may simply enter the same, predefined password, but press harder on the display interface 110 than normally for the entire duration of password entry or for a portion thereof. The device 100 may detect the applied force and interpret the password entry as a duress signal and take any predefined action in respect of the duress signal. Alternatively, duress may be indicated to the device 100 when the password is entered with less force than associated with normal password entry.”, [0097] “…timing data may be used to confirm whether a duress condition exists. As noted above, timing data, such as the time elapsed in tracing a symbol or in actuating the keys corresponding to the password, may be determined and stored. Since applying additional force to the touchscreen display interface 110 increases the normal force at the surface of the display interface 110, friction between the user's digit or contact tool and the display interface 110 may increase, causing the password entry to be slower. A marked increase in the amount of time required to compete the correct password may be used to confirm that a duress condition exists… when the password is initially set at the device 100 (as it may be with reference to the process illustrated in FIG. 10), timing data associated with the password may be stored at the device 100 as well. When password entry is subsequently detected at the communication device 100, the time required to complete the subsequent password entry is compared to the timing data. If the subsequent password entry time generally matches the stored timing data (for example, within a given tolerance), no duress condition is identified. However, if the subsequent password entry time is significantly greater or less than the stored timing data (for example, .+-.10%) while the password itself that was input otherwise matches the stored password data, a duress condition is identified. The variance between the subsequent password entry time and the stored timing data may be fixed by means of the IT policy or a setting at the communication device 100.”, where the normal sequence, e.g. Figure 9 in [0078] is similar to the sequence when a person is under duress, examiner notes that COGGILL discloses two different sequences, i.e. not just temporally different, in [0098] and indicates that using the temporally different sequences have an advantage “[0098] By defining the duress password as the same password, but simply entered on the touchscreen display 110 or keyboard 116 with greater applied force than the usual, non-duress password, the user is not required to remember any extra data (such as an extra code or series of key presses) in order to trigger a duress condition at the device 100… This is beneficial since in a real duress situation the user may panic and not recall the extra steps to be taken.”, [0096] discloses the device access with respect to the different sequence, e.g. Figure 14 1455 for permitting access/unlock, and 1460 for duress condition where sensitive data are not available as disclosed in [0074]). Regarding claim 22, claim 22 recites similar limitations to claim 21, therefore rejected with the same rationale applied to claim 21. Regarding claim 23, claim 23 recites similar limitations to claim 21, therefore rejected with the same rationale applied to claim 21. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Vaughn (US 20170098065 A1) discloses in Abstract “Techniques for securing a computing device are provided. An example method detecting contact with a touchscreen of the computing device, monitoring the contact with the touchscreen to determine whether the contact matches a predetermined pattern of movement, and performing one or more predetermined actions responsive to the contact with the touchscreen matching the predetermined pattern.”, [0038, 0043, 0045] device 120 comprising authentication unit based on physical state change of the device by means of touch screen pressure sensor and biometric sensors. [0038] “The at least one sensor 235 can comprise one or more sensors that can be used to collect data. At least one sensor 235 can include a gyroscope that can be used to determine a three dimensional (3D) orientation of the computing device 120 or the configuration computing device 180. At least one sensor 235 can also include a magnetometer, which can serve as a compass that can determine the orientation of the device relative to the Earth's magnetic field. At least one sensor 235 can also include other types of sensors, such as a fingerprint sensor or other types of sensors that can be used to obtain biometric readings from a user of the device and which could be used as a password for locking and/or unlocking content on the device. The computing device 120 or the or the configuration computing device 180 can be configured to use biometric readings in addition to the predetermined patterns of movements discussed herein for securing the device and the contents thereof.”, [0045] “The authentication unit 362 of the computing device 120 can be configured to use biometric readings obtained by at least one sensor 235 in addition to the predetermined patterns of movements discussed herein for securing the computing device 120 and the contents thereof.”, where different sensors in addition to predetermined patterns of movements (e.g. illustrated in Figure 2) are used for unlocking the device. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BASSAM A NOAMAN whose telephone number is (571)272-2705. The examiner can normally be reached Monday-Friday 8:30 AM-5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BASSAM A NOAMAN/ Primary Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Show 7 earlier events
Jan 12, 2026
Request for Continued Examination
Jan 25, 2026
Response after Non-Final Action
Feb 02, 2026
Non-Final Rejection mailed — §102
Mar 13, 2026
Response Filed
Apr 15, 2026
Final Rejection mailed — §102
Aug 14, 2026
Request for Continued Examination
Aug 21, 2026
Response after Non-Final Action
Sep 01, 2026
Non-Final Rejection mailed — §102 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739270
INTELLIGENT WORKFLOW FOR PROTECTING SERVERS FROM OUTSIDE THREATS
4y 7m to grant Granted Sep 15, 2026
Patent 12739115
PROTOCOLS WITH NOISY RESPONSE-BASED CRYPTOGRAPHIC SUBKEYS
2y 0m to grant Granted Sep 15, 2026
Patent 12730867
METHOD AND SYSTEM FOR AUTHENTICATION
3y 11m to grant Granted Sep 08, 2026
Patent 12732343
ACCOUNT OPENING METHODS, SYSTEMS, AND APPARATUSES
2y 9m to grant Granted Sep 08, 2026
Patent 12732344
AUTHORITY MANAGEMENT METHOD
2y 9m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
79%
Grant Probability
99%
With Interview (+46.2%)
2y 9m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 282 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month