Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Status of the Application
The following is a Final Office Action in response to communication received on 6/29/2026. Claims 1-20 are pending in this office action.
Response to Amendment
Applicant’s amendments to claims 1, 8, and 15 are acknowledged.
Response to Arguments
Based on Applicant’s amendments and Remarks (see page 8) the previous 112 second/b rejections and claim objections have been withdrawn .
On Remarks pages 9-13, Applicant argues the 101 rejection. Specifically Applicant argues that the claims do not recite a mental process and or certain methods of organizing human activities. Applicant cites Enfish and DDR Holdings for support of this argument and argues the recited databases, “automated” verifications , analyzing the “digital image”, and digital fingerprints. The Examiner has carefully considered Applicant’s arguments and claims as a whole under broadest reasonable interpretation, however the Examiner disagrees. The Examiner notes that the Examiner updated claim 15 to reflect Applicant’s amendments.
The claims recite performing various verification tests on collected information and when the verification tests are passed verifying a user. The claims are recited at such a high level of generality they recite observations, evaluations, judgements and opinions that can be performed in the human mind or with pen and paper and accordingly recite a mental process.
Further the claims 1-20 recite social activities or following rules or instructions which are in the sub-grouping of managing personal behavior or relationships or interactions between people, which is a certain methods of organizing human activities.
The argued additional elements beyond the abstract idea that the verifications are “automated” and data is stored in a database are merely recited at the apply it or generally linking it to the field of computers level as detailed in the 101 rejection below.
The Examiner maintains the Examiner’s response to the additional element of “digital fingerprinting” found on Non-Final Office Action dated 3/27/2026 on pages 3-4 (cited herein):
As to Applicant's arguments with respect to the digital fingerprint, the Examiner
respectfully disagrees. Specifically it is a mental process step or human activity to obtain or collect metadata like driver's license number, passport number, billing information, voting registrations, etc., as metadata is merely data describing other data, perform a fingerprint process of creating a unique identifier that corresponds to the collected data (an id or badge that corresponds to those other collected credentials), and perform a security verification based on a search of a data store regarding the number of attempts to access data to make a determination (for example this identifier like a badge tried to access the building 2 times in the last two hours and was denied).
This could be performed through paper logs as broadly recited in the claims. The additional elements that this metadata is instead a device fingerprint using "user interface of the external device, hardware identifiers, and network parameters" and the data store is a "database" merely results in apply it and generally linking it to the field of computers as discussed in the 101 rejection below. Applicant does not recite an improvement in fingerprinting as it relates to computer device interfaces, databases,
user devices, or digital images, rather Applicant is merely using those additional
elements the perform the abstract idea at the apply it level.
Therefore the Examiner respectfully disagrees.
The Examiner also maintains the Examiner’s response to the analyzing the digital image. Applicant has amended claim 15 to specifically recite analyzing the digital image, however again this is recited at such a high level of generality and abstraction it recites an abstract idea (both mental process and certain methods of organizing human activity) of looking at an image and making a determination. Therefore this is part of the abstract idea. The additional element that the image is “digital” merely results in apply it. Specifically there is no analysis as to how the computer performs or makes such a determination by analyzing the digital image, rather recites a result oriented solution which merely results in apply it (see MPEP 2106.05(f)).
As to Applicant’s arguments regarding improvements to the functioning of a computer and unconventional technical solution expressed in the claim, the Examiner maintains the response from the Non-Final Office Action dated 3/27/2026 on pages 4-5 (cited herein):
On Remarks pages 11-12, Applicant argues improvements to the computer,
and cites paragraphs 0015-0016 of the Applicant's specification for support of this
argument.
Examiners are required to at the specification and determine if the specification
provides an improvement that could be apparent to one of ordinary skill in the art, based
on MPEP 2106.05(a),(examples include: a discussion in the specification that identifies
a technical problem and explains the details of an unconventional technical solution
expressed in the claim, or identifies technical improvements realized by the claim over
the prior art. For example, in McRO, the court relied on the specification's explanation of
how the particular rules recited in the claim enabled the automation of specific
animation tasks that previously could only be performed subjectively by humans, when
determining that the claims were directed to improvements in computer animation
instead of an abstract idea)
or if the specification explicitly sets forth an improvement but in a conclusory
manner (i.e. a bare assertion of an improvement without the detail necessary to be
apparent to a person of ordinary skill in the art .... In contrast, the court in Affinity Labs
of Tex. v. DirecTV, LLC relied on the specification's failure to provide details regarding
the manner in which the invention accomplished the alleged improvement when holding
the claimed methods of delivering broadcast content to cellphones ineligible. 838 F.3d 1253, 1263-64, 120 USPQ2d 1201, 1207-08 (Fed. Cir. 2016), which the Examiner
should not determine the claim improves technology).
Examiner has reviewed Applicant's specification at paragraph 0015-0016 and
finds the latter. Specifically there is nothing here in these sections that explains the
details of an unconventional technical solution expressed in the claim, identifies
technical improvements realized by the claim over the prior art, or how the particular
rules recited in the claim enabled the automation of specific animation tasks that
previously could only be performed subjectively by humans.
Rather Applicant's specification merely discloses in a conclusory manner an
improvement by using a different process than the one mentioned in paragraphs 0015-
0016. Neither Applicant's claims nor invention as cited in paragraphs 0015-0016, are
related towards technical improvements in using the current process (like determining
counterfeits).
This merely recites improvements to the judicial exception of performing various
verification tests on collected information and when the verification tests are passed
authorizing a user, which has been previously found not to be an improvement in
computers or technology, see MPEP 2106.05(a) "However, it is important to keep in
mind that an improvement in the abstract idea itself (e.g. a recited fundamental
economic concept) is not an improvement in technology. For example, in Trading
Technologies Int'/ v. /BG, 921 F.3d 1084, 1093-94, 2019 USPQ2d 138290 (Fed. Cir.
2019), the court determined that the claimed user interface simply provided a trader with
more information to facilitate market trades, which improved the business process of
market trading but did not improve computers or technology."
While Applicant recites additional elements including computers, device
fingerprinting, digital images, and databases as detailed in the 101 rejection below,
Applicant does not recite an improvement in fingerprinting as it relates to computer
device interfaces, databases, user devices, or digital images, rather Applicant is merely
using those additional elements the perform the abstract idea at the apply it level or
generally linking it to the technological field of computers. Here in paragraphs 0015-
0016 (and or in applicant's claims as currently recited), there is no discussion/recitation
of an improvement to one or multiple of those additional computer elements.
Therefore the Examiner respectfully disagrees with Applicant's arguments.
Further as to Applicant’s arguments of:
“Here, the claims recite an inventive concept through their specific ordered combination of fraud prevention techniques: (1) device fingerprinting that creates unique identifiers from multiple metadata sources; (2) session tracking that monitors verification attempts within time windows; (3) multiple automated verification layers including document submission limits and contact verification; and (4) automatic authorization only when all verifications pass. This ordered combination addresses the specific technological problem of preventing sophisticated fraud attempts that might bypass individual security measures.”
These again the claims are recited at such a broad level of recitation that they recite mental process and or certain method of organizing human activities (an abstract idea) of (1) perform a fingerprint process of creating a unique identifier that corresponds to the collected data (like an id or badge that corresponds to those other collected credentials), (2) perform a security verification based on a search of a data store regarding the number of attempts to access data to make a determination (for example this identifier like a badge tried to access the building 2 times in the last two hours and was denied), (3) multiple verifications based on document submission limits and contact verification, and (4) authorizing when all verification pass. The only additional elements that the this is “device fingerprinting:” and the verifications steps are “automated” merely result in apply it or generally linking it to the field of computers as discussed above in this response to arguments section and the 101 rejection below.
On Remarks pages 14-15, Applicant argues the prior art rejection in view of Applicant’s amendments. The Examiner respectfully disagrees.
In response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986).
The cited primary reference of Sherlock et al. clearly teaches performing verifications based on one or more different features of the users’ access attempts (see paragraphs 0181-0185). Sherlock clearly teaches performing the above checks and the results being determined before using the results to decide to perform other checks but does not especially teach whether they are performed in serial or parallel or more specifically performing the disclosed processes one right after another or in serial or more specifically as recited in the claims (1) prior to an identification verification session…..initiating the identification verification session in response to the number of times being less than the first predetermined threshold and (2) during the identification verification session….in response to the first automated security verification being passed, or in response to the second automated security verification being passed.
However, Mathura et al. which is in the art of determining fraud online (see abstract) teaches (1) prior to an identification verification session…..initiating the identification verification session in response to the number of times being less than the first predetermined threshold and (2) during the identification verification session….in response to the first automated security verification being passed, or in response to the second automated security verification being passed (see paragraphs 0123-0132 and 0212).
So here as broadly recited in the claims if it is first decided that a user has not performed over a threshold number of accesses resulting in failures at a financial transaction, or the single device has not accessed the accounts from different locations within a threshold amount of time (see paragraph 0128 and 0130) the system could then perform other verification calculations (such as those in paragraphs 0123-0132) where a user could pass or fail these verification calculations, then perform further calculations, as these calculations are performed in serial or parallel as broadly recited in the claim (see paragraphs 0212).
It is further noted that the “automatically blocked” or “automatically rejected” as recited in claim 1 could be performed after the system has calculated all of the individual verification steps as broadly recited in the claims.
Before the effective filing date of the claimed invention it would have been obvious for one of ordinary skill in the art to have modified Sherlock with the aforementioned teachings from Mathura et al. with the motivation of providing a commonly known feature that checks or verifications can be performed in parallel or serial (see Mathura et al. paragraphs 0123-0132 and 0212), when Sherlock clearly teaches performing the above checks and results are used to determine performing other checks but does not especially teach whether they are performed in serial or parallel (see Sherlock paragraphs 0180-0184).
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Claims 1-7 recite a process as the claims recite a method. Claims 8-14 recite a machine as the claims recite system with a database and a processor. Claims 15-20 recite a process as the claims recite a method.
The claim(s) 1-20 recite(s) performing various verification tests on collected information and when the verification tests are passed verifying a user. The claims are recited at such a high level of generality they recite observations, evaluations, judgements and opinions that can be performed in the human mind or with pen and paper and accordingly recite a mental process.
Further the claims 1-20 recite social activities or following rules or instructions which are in the sub-grouping of managing personal behavior or relationships or interactions between people, which is a certain methods of organizing human activities.
Mental processes as well as certain methods of organizing human activities are in the groupings of enumerated abstracts ideas, and hence the claims recite an abstract idea.
This judicial exception is not integrated into a practical application because the claims merely recite limitations that are not indicative of integration into a practical application in that the claims merely recite:
(1) Adding the words “apply it” ( or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea (see MPEP 2106.05(f)) and (2) Generally linking the use of the judicial exception to a particular technological environment or field of use (see MPEP 2106.05(h)). Specifically as recited in the claims:
As per claim 1, the claims recite mental process and certain method of organizing human activity steps of requesting a verification session in response to a trigger event associated with a transaction, obtain or collect metadata like driver’s license number, passport number, billing information, voting registrations, etc., as metadata is merely data describing other data, perform a fingerprint process of creating a unique identifier that corresponds to the collected data (like an id or badge that corresponds to those other collected credentials), and perform a security verification based on a search of a data store regarding the number of attempts to access data to make a determination (for example this identifier like a badge tried to access the building 2 times in the last two hours and was denied). This could be performed through paper logs as broadly recited in the claims. Further it is mental process or certain method of organizing human activities steps to perform verifications based on collected data according to rules in different sessions (the claimed prior and the during the identification verifications sessions), including the number of times a unique identifier has initiated a verification session within a predetermined time window and automatically causing it be to rejected based on it exceeding a threshold and performing further verification in response to it being less than a predetermined threshold, receive in response to a first verification being passed, image data of a government identification from a user, performing another verification based on a number of document submissions made by an identifier within a current session, and causing a current government identification submission to be blocked in response to exceeding a threshold, receiving a contact number associated with a user and performing a verification based on the number of versification messages sent to the contact, and performing a government verification on this digital image data of the government identification in response to the verifications being passed, as broadly recited in the claims. This is part of the abstract idea.
The additional elements that the method is “computer implemented”, being performed by “one or more processors”, the verifications are “automated” and performed “automatically”, the fingerprinting and identifier is of the “device”, the data store is a “database”, the image data being “digital”, users are submitting and receiving information by a “user device”, information is received “via a network interface”, the transaction is “online”, the metadata describes “characteristics of a user interface of the user device, hardware identifiers, and network parameters”, merely results in “apply it”.
Specifically here the claim invokes computers or other machinery merely as a tool to perform an existing process. Use of a computer or other machinery in its ordinary capacity for economic or other tasks (e.g. to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea does not integrate a judicial exception into a practical application or provide significantly more. Further the additional limitations provide only a result-oriented solution and lack details as to how the computer performs the modifications which is equivalent to the words “apply it.” Here as currently recited in the claims Applicant does not recite an improvement in fingerprinting as it relates to computer device interfaces, databases, user devices, or digital images, rather Applicant is merely using those additional elements the perform the abstract idea at the apply it level.
Further the additional elements are considered nothing more than generally linking the use of the judicial exception to the technological environment or field of computers.
As per claim 2, the claims recite mental process and certain method of organizing human activities steps of receiving from storage a number of session requests initiated by the user within a current time period. This is part of the abstract idea. The additional elements that the requests are from a “user device” rather than a user and the storage is a “database” merely results in apply or generally linking it to the field of computers as discussed above.
As per claim 3, the claims recite mental process and certain method of organizing human activities steps of determining whether the number of session requests exceeds a maximum number of session requests. This is part of the abstract idea. There are no additional elements in this claim limitation beyond those previously discussed in the claims from which the claim depends.
As per claim 4, the claims recite mental process and certain method of organizing human activities steps of receiving from storage a number of submission attempts made by the user within the current session. This is part of the abstract idea. The additional elements that the requests are from a “user device” rather than a user and the storage is a “database” rather than pen and paper for example merely results in “apply it” or generally linking it to the field of computers as discussed previously above.
As per claim 5, the claims recite mental process and certain method of organizing human activities steps of determining whether the number of submission attempts exceeds a maximum number of submission attempts. This is part of the abstract idea. There are no additional elements in this claim limitation beyond those previously discussed in the claims from which the claim depends.
As per claim 6, the claims recite mental process and certain method of organizing human activity steps of receiving from storage a number of verification messages transmitted to a contact number within a current time period. This is part of the abstract idea. The additional elements that the storage is a “database” rather than pen and paper merely results in “apply it” or generally linking it to the field of computers as discussed previously above.
As per claim 7, the claims recite mental process and certain method of organizing human activity steps of determining whether the number of verification messages transmitted to the user exceeds a maximum number of submission attempts. This is part of the abstract idea. There are no additional elements in this claim limitation beyond those previously discussed in the claims from which the claim depends.
As per claim 8, the claims recite mental process and certain method of organizing human activities steps of requesting a verification session in response to a trigger event associated with a transaction, obtain or collect metadata like driver’s license number, passport number, billing information, voting registrations, etc., as metadata is merely data describing other data, perform a fingerprint process of creating a unique identifier that corresponds to the collected data (like an id or badge that corresponds to those other collected credentials), and perform a security verification based on a search of a data store regarding the number of attempts to access data to make a determination (for example this identifier like a badge tried to access the building 2 times in the last two hours and was denied). This could be performed through paper logs as broadly recited in the claims. Further it is mental process or certain method of organizing human activities steps to perform verifications based on collected data according to rules in different sessions (the claimed prior and the during the identification verifications sessions), including the number of times a unique identifier has had a session within a predetermined time window and automatically causing it be to rejected based on it exceeding a threshold and performing further verification in response to it being less than a predetermined threshold, receive in response to a first verification being passed, image data of a government identification from a user, performing another verification based on a number of government identification submissions made by an identifier within a current session, and causing a current government identification submission to be blocked in response to exceeding a threshold, analyze the government identification submission in response to the identifying being passed, and performing a government verification on this digital image data of the government identification in response to the verifications being passed, as broadly recited in the claims. This is part of the abstract idea.
The additional elements that the functions are being performed by “one or more processors”, steps are performed “automatically”, the fingerprinting and identifier is of the “device”, the data store is a “database”, the image data being “digital”, users are submitting and receiving information by a “external device”, information is received “via a network interface”, the transaction is “online”, the metadata describes “characteristics of a user interface of the user device, hardware identifiers, and network parameters”, information is received from the external device by a “transceiver”, merely results in “apply it”.
Specifically here the claim invokes computers or other machinery merely as a tool to perform an existing process. Use of a computer or other machinery in its ordinary capacity for economic or other tasks (e.g. to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea does not integrate a judicial exception into a practical application or provide significantly more. Further the additional limitations provide only a result-oriented solution and lack details as to how the computer performs the modifications which is equivalent to the words “apply it” Here as currently recited in the claims Applicant does not recite an improvement in fingerprinting as it relates to computer device interfaces, databases, external devices, digital images, or transceivers, rather Applicant is merely using those additional elements the perform the abstract idea at the apply it level.
Further the additional elements are considered nothing more than generally linking the use of the judicial exception to the technological environment or field of computers.
As per claim 9, the claims recite mental process and certain method of organizing human activities of determining the first current time period includes a predetermined number of hours up to and including a current time. This is part of the abstract idea. There are no additional elements in the claim beyond those previously discussed in the claims from which the claim depends..
As per claim 10, the claims recite mental process and certain method of organizing human activities of determining the second current time period includes a current session. This is part of the abstract idea. There are no additional elements in the claim beyond those previously discussed in the claims from which the claim depends.
As per claim 11, the claims recite mental process and certain method of organizing human activities of rejecting an operation in response to one or two verification determinations failing. This is part of the abstract idea. The additional element that this is instead being performed by one or more processors merely results in “apply it” or generally linking it to the field of computers as discussed above in claim 8.
As per claim 12, the claims recite mental process and certain method of organizing human activities steps of performing these steps during account creation. This is part of the abstract idea. There are no additional elements in the claim beyond those previously discussed in the claims from which the claim depends.
As per claim 13, the claims recite mental process and certain method of organizing human activities of transmitting a rejection notification to another entity like a user in response to the rejecting. This is part of the abstract idea. The additional elements that these steps are performed by “one or more processors” and the notification being provided to an “external device”, and a being provided by the “transceiver” merely results in apply it or generally linking to the field of computers as discussed above in claim 8.
As per claim 14, the claims recite mental process and certain method of organizing human activities of transmitting a notification that indicates further forms of identification are required to complete the operation. This is part of the abstract idea. There are no additional elements in the claim beyond those previously discussed in the claims from which the claim depends..
As per claim 15, the claims recite mental process and certain method of organizing human activities of receiving a session request from a user in response to a trigger event associated with a transaction, obtain or collect metadata like driver’s license number, passport number, billing information, voting registrations, etc., as metadata is merely data describing other data, perform a fingerprint process of creating a unique identifier that corresponds to the collected data (like an id or badge that corresponds to those other collected credentials), and perform a security check relating to the session request in response to receiving, the first security check including a search of a data store regarding the number of attempts to access data to make a determination (for example this identifier like a badge tried to access the building 2 times in the last two hours and was denied). This could be performed through paper logs as broadly recited in the claims. Further it is mental process and certain method of organizing human activities steps to perform verifications based on collected data according to rules in different sessions (the claimed prior and the during the identification verifications sessions), including the number of times a unique identifier has had a session within a predetermined time window and automatically causing it be to rejected based on it exceeding a threshold and performing further verification in response to it being less than a predetermined threshold, receive in response to a first verification being passed government identification from a user, analyzing the image data of government identification submission and performing a government verification on this digital image data of the government identification in response to the verifications being passed. This is part of the abstract idea.
The additional elements that the security checks are “automated” and steps are performed “automatically”, the fingerprinting and identifier is of the “device”, the data store is a “database”, users are submitting and receiving information by a “user device”, information is received “via a network interface”, the image data being “digital”, the transaction is “online”, the metadata describes “characteristics of a user interface of the user device, hardware identifiers, and network parameters”, merely results in “apply it”.
Specifically here the claim invokes computers or other machinery merely as a tool to perform an existing process. Use of a computer or other machinery in its ordinary capacity for economic or other tasks (e.g. to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea does not integrate a judicial exception into a practical application or provide significantly more. Further the additional limitations provide only a result-oriented solution and lack details as to how the computer performs the modifications which is equivalent to the words “apply it” Here as currently recited in the claims Applicant does not recite an improvement in fingerprinting as it relates to computer device interfaces, databases, or user devices, rather Applicant is merely using those additional elements the perform the abstract idea at the apply it level.
Further the additional elements are considered nothing more than generally linking the use of the judicial exception to the technological environment or field of computers.
As per claim 16, the claims recite mental process and certain method of organizing human activities of performing this during account creation. This is part of the abstract idea. There are no additional elements in the claim beyond those previously discussed in the claims from which the claim depends.
As per claim 17 the claims recite mental process and certain method of organizing human activities of perform a first security check that the user has not initiated more than a predetermined number of sessions within a predetermined time period. This is part of the abstract idea. The additional element that a user “device” rather than a user initiates requests merely results in apply it or generally linking it to the field of computers as discussed above in claim 15.
As per claim 18 the claims recite mental process and certain method organizing human activities steps of perform a second security check that the user has not submitted more than a predetermined number of government identification submissions within a predetermined time. This is part of the abstract idea. The additional element that a user “device” rather than a user initiates requests merely results in apply it or generally linking it to the field of computers as discussed above in claim 15.
As per claim 19 the claims recite mental process and certain method of organizing human activity steps of performing a dual mode authentication in response to passing a second security check, receive a contact identifier from the user in response to the initiating, and performing a third security check based on the contact identifier, the third security check verifying that the contact identifier has not been contacted more than a predetermined number of times within a predetermined time period. This is part of the abstract idea. The additional element that a user “device” rather than a user initiates requests merely results in apply it or generally linking it to the field of computers as discussed above in claim 15.
As per claim 20 the claims recite mental process and certain method of organizing human activities steps of receiving metadata associated with a user of the session, and in response to the first and second security checks being passed performing a risk assessment based on the received metadata the risk assessment identifying one or more high risk factors. This is part of the abstract idea. The additional element (listed in the alternative, so not required by the claim but listed here in the efforts of compact prosecution) that a user “device” rather than a user initiates requests merely results in apply it or generally linking it to the field of computers as discussed above in claim 15.
The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the claims merely recite limitations that are not indicative of an inventive concept (“significantly more”) in that the claims merely recite: (1) Adding the words “apply it” ( or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea (see MPEP 2106.05(f)) and (2) Generally linking the use of the judicial exception to a particular technological environment or field of use (see MPEP 2106.05(h)), as detailed above with respect to the practical application step.
Claim Rejections - 35 USC § 103
13. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
14. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
15. Claim(s) 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Sherlock et al. (United States Patent Application Publication Number: US 2022/0131844) further in view of Mathura et al. (United States Patent Application Publication Number: US 2016/0048937).
As per claim 1, Sherlock teaches A computer-implemented method executed by one or more processors of a verification system for reducing government identification fraud, comprising: (see abstract and paragraphs 0045 and 0407-0408, Examiner’s note: method for managing a reputation score of a user based on logins, authentications, and profile changes to determine when a problematic situation occurs (see abstract), teaches this is to reduce fraudulent activities (see paragraph 0045), and the rules are to satisfy the regulatory requirement for a regulatory where one of the regulators can be a government regulatory body (see paragraphs 0407-0408)).
receiving, via a network interface, a request from a user device to initiate an identification, verification session in response to a trigger event associated with an online transaction; (see paragraphs 0056, 0061, and 0063, Examiner’s note: access token provided to perform a transaction (see paragraph 0056) and a controller communicates with the computing sites and uses the contextual information to perform enhanced user authentication and access control to reduce fraud on computing sites (see paragraph 0061), where this may be implemented within a computing site (see paragraph 0063)).
obtaining, by the one or more processors, device-specific metadata associated with the user device, the metadata including data relating to formatting characteristics of a user interface of the user device, hardware identifiers, and network parameters; performing, by the one or more processors, a device fingerprinting process on the received metadata to generate a unique identifier associated with the user device; (see paragraph 0070-0071, Examiner’s note: creating an electronic signature associated with the device that may include browser fingerprints, IP addresses, geographic location, and processor characteristics).
performing, by the one or more processors, a first automated security verification that includes querying a session tracking database to determine a number of times a device having the unique identifier has initiated a verification session within a predetermined time window, the first automated security verification causing the request to be automatically rejected in response to the number of times exceeding a first predetermined threshold; (see paragraphs 0179-0183, Examiner’s note: here teaches receiving data from a database (see paragraph 0179), determining rate of change for different factor (see paragraph 0181) where different factors may have different expected change rates (see paragraph 0181) comparing these individual factors like IP address, shipping address, phones, emails, new devices (see paragraphs 0182-0183) to different limits and if one is above the respective limit triggering to add other considerations for access control (see paragraph 0183-0184). Here the first automated security verification it could be with respect to device ID, the second verification could be with respect to IP addresses or shipping addresses, contact number could be emails or phones for example).
receiving, digital image data of a government identification from the user device; (see paragraphs 0024-0025, 0181-0182, and Figures 13-14, Examiner’s note: IP address or IP country and shipping address (see paragraph 0181-0182), it is further noted that is from digital graph data (see paragraph 0177) and it is noted that Figures 13-14 show growth rate clusters (see paragraphs 0024-0025)).
performing, by the one or more processors, a second automated security verification that includes determining a number of document submissions made by a user device having the unique identifier within a current session, the second automated security verification causing a current government identification submission to be automatically blocked in response to the number of document submissions exceeding a second predetermined threshold; receiving a contact number associated with the user device; performing, by the one or more processors, a third automated verification based on a number of verification messages transmitted to the contact number; and automatically performing a government identification verification on the digital image data of the government identification, by the one or more processors, in response to each of the first, second, and third automated verifications being passed. (see paragraphs 0179-0183, Examiner’s note: here teaches receiving data from a database (see paragraph 0179), determining rate of change for different factor (see paragraph 0181) where different factors may have different expected change rates (see paragraph 0181) comparing these individual factors like IP address, shipping address, phones, emails, new devices (see paragraphs 0182-0183) to different limits and if one is above the respective limit triggering to add other considerations for access control (see paragraph 0183-0184). Here the first automated security verification could be with respect to device ID, the second verification could be with respect to IP addresses or shipping addresses, contact number could be emails, or phones. It is noted here the Examiner interprets the amended claim of “automatically performing” to read on the previous claim scope of allowing or not allowing a user accessing a system through specific government identifications access to the system based on the verifications being passed or failed. It is noted that the “automatically blocked” or “automatically rejected” as recited in claim 1 could be performed after the system has calculated all of the individual verification steps as broadly recited in the claims.).
Sherlock clearly teaches performing the above checks and results determined before using the results to decide to perform other checks but does not especially teach whether they are performed in serial or parallel or more specifically performing the disclosed processes one right after another or in serial or more specifically as recited in the claims (1) prior to an identification verification session…..initiating the identification verification session in response to the number of times being less than the first predetermined threshold and (2) during the identification verification session….in response to the first automated security verification being passed, or in response to the second automated security verification being passed.
However, Mathura et al. which is in the art of determining fraud online (see abstract) teaches (1) prior to an identification verification session…..initiating the identification verification session in response to the number of times being less than the first predetermined threshold and (2) during the identification verification session….in response to the first automated security verification being passed, or in response to the second automated security verification being passed (see paragraphs 0123-0132 and 0212 Examiner’s note: paragraphs 0123-0132 teaches indicators compared to thresholds, where these may be in relation to number of times access an account (see paragraph 0128, 0130), and teaches these may be performed in serial or parallel (see paragraph 0212). So here as broadly recited in the claims if it is first determined that a user has not performed over a threshold number of accesses resulting in failures at a financial transaction, or alternatively the single device has not accessed the accounts from different locations within a threshold amount of time (see paragraph 0128 and 0130) the system could then perform other verification calculations (such as those in paragraphs 0123-0132) as these are performed in serial or parallel as broadly recited in the claim (see paragraphs 0212)).
Before the effective filing date of the claimed invention it would have been obvious for one of ordinary skill in the art to have modified Sherlock with the aforementioned teachings from Mathura et al. with the motivation of providing a commonly known feature that checks or verifications can be performed in parallel or serial (see Mathura et al. paragraphs 0123-0132 and 0212), when Sherlock clearly teaches performing the above checks and results are used to determine performing other checks but does not especially teach whether they are performed in serial or parallel (see Sherlock paragraphs 0180-0184).
As per claim 2, Sherlock teaches
wherein the first security verification includes receiving, from the database, a number of session requests initiated by the user device within a current time period (see paragraph 0177, 0180, 0268, and 0276, Examiner’s note: teaches determining rate of change in a graph (see paragraphs 0177, 0180), further teaches a graph may include things like information for the last 7 days or 2 hours determining on the circumstances (see paragraphs 0268 and 0276)).
As per claim 3, Sherlock teaches
wherein the first security verification includes determining whether the number of session requests exceeds a maximum number of session requests (see paragraphs 0183-0184, Examiner’s note: comparing rate of change to preset limits).
As per claim 4, Sherlock teaches
wherein the second security verification includes receiving, from the database, a number of submission attempts made by the user device within a current session (see paragraphs 0179-0181, Examiner’s note: teaches determining rate of change where this information is determined based on information received from a database).
As per claim 5, Sherlock teaches
wherein the second security verification further includes determining whether the number of submission attempts exceeds a maximum number of submission attempts. (see paragraphs 0183-0184, Examiner’s note: comparing rate of change to preset limits).
As per claim 6, Sherlock teaches
wherein the third verification includes receiving, from the database, a number of verification messages transmitted to the contact number within a current time period. (see paragraphs 0179-0181, Examiner’s note: teaches determining rate of change where this information is determined based on information received from a database).
As per claim 7, Sherlock teaches
wherein the third verification further includes determining whether the number of verification messages transmitted to the contact number exceeds a maximum number of submission attempts. (see paragraphs 0183-0184, Examiner’s note: comparing rate of change to preset limits).
As per claim 8, Sherlock teaches A fraud reduction system, comprising: (see abstract, Examiner’s note: system for managing a reputation score of a user based on logins, authentications, and profile changes to determine when a problematic situation occurs).
A transceiver configured to send and receive communications with an external device; (see paragraphs 0056, 0061, and 0063, Examiner’s note: access token provided to perform a transaction (see paragraph 0056) and a controller communicates with the computing sites and uses the contextual information to perform enhanced user authentication and access control to reduce fraud on computing sites (see paragraph 0061), where this may be implemented within a computing site (see paragraph 0063)).
a database that stores user activity data; (see paragraphs 0179-0180, Examiner’s note: information received from databases).
and one or more processors configured to: (see paragraph 0075, Examiner’s note: site includes at least one microprocessor to execute instructions of software configured for user authentication and or access control).
receive, via a network interface, a session request from the external device in response to a trigger event associated with an online transaction; obtain device-specific metadata associated with the external device, the metadata including data relating to formatting characteristics of a user interface of the external device, hardware identifiers, and network parameters; perform a device fingerprinting process on the received metadata to generate a unique identifier associated with the user device; (see paragraph 0070-0071, Examiner’s note: creating an electronic signature associated with the device that may include browser fingerprints, IP addresses, geographic location, and processor characteristics).
first determine, based on a search of the stored user activity data using the unique identifier, whether an external device having the unique identifier has exceeded a maximum number of sessions for a first current time period, the first determine causing the request to be automatically rejected in response to the external device exceeding the maximum number of sessions; (see paragraphs 0179-0184, Examiner’s note: here teaches receiving data from a database (see paragraph 0179), determining rate of change for different factor (see paragraph 0181) where different factors may have different expected change rates (see paragraph 0181) comparing these individual factors like IP address, shipping address, phones, emails, new devices (see paragraphs 0182-0183) to different limits and if one is above the respective limit triggering to add other considerations for access control (see paragraph 0183-0184). Here in the first determine could be with respect to device ID, the second determine could be with respect to IP addresses or shipping addresses. ).
And receive, digital image data of a government identification from the external device, (see paragraphs 0024-0025, 0181-0182, and Figures 13-14, Examiner’s note: IP address or IP country and shipping address (see paragraph 0181-0182), it is further noted that is from digital graph data (see paragraph 0177) and it is noted that Figures 13-14 show growth rate clusters (see paragraphs 0024-0025)).
second determine, from the user activity data, a number of government identification submissions attempted by an external device having the unique identifier within a current session, the second determine causing a current government identification submission to be automatically blocked in response to the number of document submissions exceeding a predetermined threshold; analyze the digital image data of the government identification submission in response; and automatically performing a government identification verification in response to each of the first determine, the second determine, and the analyzing being passed. (see paragraphs 0179-0184, Examiner’s note: here teaches receiving data from a database (see paragraph 0179), determining rate of change for different factor (see paragraph 0181) where different factors may have different expected change rates (see paragraph 0181) comparing these individual factors like IP address, shipping address, phones, emails, new devices (see paragraphs 0182-0183) to different limits and if one is above the respective limit triggering to add other considerations for access control (see paragraph 0183-0184). Here in the first determine could be with respect to device ID, the second determine could be with respect to IP addresses or shipping addresses. Additionally or alternatively in response could read on things like comparing the billing address to geo location as in paragraph 0184. It is noted here the Examiner interprets the amended claim of “automatically performing” to read on the previous claim scope of allowing or not allowing a user accessing a system through specific government identifications access to the system based on the verifications being passed or failed. It is noted that the “automatically blocked” or “automatically rejected” as recited in claim 8 could be performed after the system has calculated all of the individual verification steps as broadly recited in the claims.).
Sherlock clearly teaches performing the above checks and results determined before using the results to decide to perform other checks but does not especially teach whether they are performed in serial or parallel or more specifically (1) prior to an identification verification session…..initiating the identification verification session in response to the external device being below the maximum number of sessions and (2) during the identification verification session….in response to the first determining being passed or in response to the identifying being passed
However, Mathura et al. which is in the art of determining fraud online (see abstract) teaches (1) prior to an identification verification session…..initiating the identification verification session in response to the external device being below the maximum number of sessions and (2) during the identification verification session….in response to the first determining being passed or in response to the identifying being passed (see paragraphs 0123-0132 and 0212 Examiner’s note: paragraphs 0123-0132 teaches indicators compared to thresholds, where these may be in relation to number of times access an account (see paragraph 0128, 0130), and teaches these may be performed in serial or parallel (see paragraph 0212). So here as broadly recited in the claims if it is first determined that a user has not performed over a threshold number of accesses resulting in failures at a financial transaction, or alternatively the single device has not accessed the accounts from different locations within a threshold amount of time (see paragraph 0128 and 0130) the system could then perform other verification calculations (such as those in paragraphs 0123-0132) as these are performed in serial or parallel as broadly recited in the claim (see paragraphs 0212)).
Before the effective filing date of the claimed invention it would have been obvious for one of ordinary skill in the art to have modified Sherlock with the aforementioned teachings from Mathura et al. with the motivation of providing a commonly known feature that checks or verifications can be performed in parallel or serial (see Mathura et al. paragraphs 0123-0132 and 0212), when Sherlock clearly teaches performing the above checks and that the results are used to determine whether to perform other checks but does not especially teach whether they are performed in serial or parallel (see Sherlock paragraphs 0180-0184).
As per claim 9, Sherlock teaches
wherein the first current time period includes a predetermined number of hours up to and including a current time. (see paragraph 0177, 0180, 0268, and 0276, Examiner’s note: teaches determining rate of change in a graph (see paragraphs 0177, 0180), further teaches a graph may include things like information for the last 7 days or 2 hours depending on the circumstances (see paragraphs 0268 and 0276).
As per claim 10, Sherlock teaches
wherein the second current time period includes a current session. (see paragraphs 0179-0181, Examiner’s note: teaches determining rate of change where this information is determined based on information received from a database).
As per claim 11, Sherlock teaches
wherein the one or more processors are further configured to reject an operation in response to the first or the second determining failing (see paragraphs 0183-0184, Examiner’s note: compare rate of change to a threshold for the factor to determine fraud).
As per claim 12, Sherlock teaches
wherein the operation is an account creation attempt (see paragraph 0181-0182, Examiner’s note: can relate to changes like new payment or billing address changes which is interpret as the broad recitation of account creation attempt).
As per claim 13, Sherlock teaches
wherein the one or more processors are further configured to: in response to the rejecting, cause the transceiver to transmit a rejection notification to the external device (see paragraphs 0194-0196, Examiner’s note: providing an alert to the user where the user has to confirm the change or new details).
As per claim 14, Sherlock teaches
wherein the rejection notification indicates that further forms of identification verification are required to complete the requested operation. (see paragraphs 0194-0196, Examiner’s note: providing an alert to the user where the user has to confirm the change or new details).
As per claim 15, Sherlock teaches A method, comprising: (see abstract, Examiner’s note: method for managing a reputation score of a user based on logins, authentications, and profile changes to determine when a problematic situation occurs).
receiving, via a network interface, a session request from a user device in response to a trigger event associated with an online transaction; (see paragraphs 0056, 0061, and 0063, Examiner’s note: access token provided to perform a transaction (see paragraph 0056) and a controller communicates with the computing sites and uses the contextual information to perform enhanced user authentication and access control to reduce fraud on computing sites (see paragraph 0061), where this may be implemented within a computing site (see paragraph 0063)).
obtaining metadata associated with the user device, the metadata including data relating to formatting characteristics of a user interface of the user device, hardware identifiers, and network parameters; performing a device fingerprinting process on the received metadata to generate a unique identifier associated with the user device; (see paragraph 0070-0071, Examiner’s note: creating an electronic signature associated with the device that may include browser fingerprints, IP addresses, geographic location, and processor characteristics).
performing a first automated security check relating to the session request in response to the receiving, the first security check including querying a session tracking database to determine a number of times a device having the unique identifier has initiated a verification session within a predetermined time window, the first automated security verification causing the request to be automatically rejected in response to the number of times exceeding a first predetermined threshold; and performing a second automated security check based on the user device, the second automated security check determining a number of document submissions made by a device having the unique identifier and causing the submission to be automatically blocked in response to the number of document submissions exceeding a second predetermined threshold; receiving digital image data of a government identification submission from the user device; analyzing the digital image data of the government identification submission; and automatically performing a government identification verification in response to each of the first automated security check, the second automated security check, and the analyzing being passed. (see paragraphs 0179-0184, Examiner’s note: here teaches receiving data from a database (see paragraph 0179), determining rate of change for different factor (see paragraph 0181) where different factors may have different expected change rates (see paragraph 0181) comparing these individual factors like IP address, shipping address, phones, emails, new devices (see paragraphs 0182-0183) to different limits and if one is above the respective limit triggering to add other considerations for access control (see paragraph 0183-0184). Here in the first automated security verification it could be with respect to device ID, the second verification could be with respect to IP addresses or shipping addresses. Additionally or alternatively analyzing could read on things like comparing the billing address to geo location as in paragraph 0184. It is noted here the Examiner interprets the amended claim of “automatically performing” to read on the previous claim scope of allowing or not allowing a user accessing a system through specific government identifications access to the system based on the verifications being passed or failed. It is noted that the “automatically blocked” or “automatically rejected” as recited in claim 15 could be performed after the system has calculated all of the individual verification steps as broadly recited in the claims.).
Sherlock clearly teaches performing the above checks and results determined before using the results to decide to perform other checks but does not especially teach whether they are performed in serial or parallel or more specifically (1) prior to an identification verification session…..initiating the identification verification session in response to the number of times being less than the first predetermined threshold and (2) during the identification verification session….in response to the user device passing the first security check or in response to the user device passing the second security check.
However, Mathura et al. which is in the art of determining fraud online (see abstract) teaches (1) prior to an identification verification session…..initiating the identification verification session in response to the number of times being less than the first predetermined threshold and (2) during the identification verification session….in response to the user device passing the first security check or in response to the user device passing the second security check (see paragraphs 0123-0132 and 0212 Examiner’s note: paragraphs 0123-0132 teaches indicators compared to thresholds, where these may be in relation to number of times access an account (see paragraph 0128, 0130), and teaches these may be performed in serial or parallel (see paragraph 0212). So here as broadly recited in the claims if it is first decided to determine that a user has not performed over a threshold number of accesses resulting in failures at a financial transaction, or alternatively the single device has not accessed the accounts from different locations within a threshold amount of time (see paragraph 0128 and 0130) the system could then perform other verification calculations (such as those in paragraphs 0123-0132) as these are performed in serial or parallel as broadly recited in the claim (see paragraphs 0212)).
Before the effective filing date of the claimed invention it would have been obvious for one of ordinary skill in the art to have modified Sherlock with the aforementioned teachings from Mathura et al. with the motivation of providing a commonly known feature that checks or verifications can be performed in parallel or serial (see Mathura et al. paragraphs 0123-0132 and 0212), when Sherlock clearly teaches performing the above checks and that they are performed before other checks but does not especially teach whether they are performed in serial or parallel (see Sherlock paragraphs 0180-0184).
As per claim 16, Sherlock teaches
wherein the requested operation is an account creation operation. (see paragraph 0181-0182, Examiner’s note: can relate to changes like new payment or billing address changes which is interpret as the broad recitation of account creation attempt).
As per claim 17, Sherlock teaches
wherein the first security check confirms that the user device has not initiated more than a predetermined number of sessions within a predetermined time period. (see paragraphs 0183-0184, Examiner’s note: comparing rate of change to preset limits).
As per claim 18, Sherlock teaches
wherein the second security check verifies that the user device has not submitted more than a predetermined number of government identification submissions within a predetermined time period. (see paragraphs 0183-0184, Examiner’s note: comparing rate of change to preset limits).
As per claim 19, Sherlock teaches
further comprising: initiating a dual-mode authentication procedure; and receiving a contact identifier from the user device in response to the initiating; performing a third security check based on the contact identifier, the third security check verifying that the contact identifier has not been contacted more than a predetermined number of times within a predetermined time period. (see paragraphs 0179-0183, Examiner’s note: here teaches receiving data from a database (see paragraph 0179), determining rate of change for different factor (see paragraph 0181) where different factors may have different expected change rates (see paragraph 0181) comparing these individual factors like IP address, shipping address, phones, emails, new devices (see paragraphs 0182-0183) to different limits and if one is above the respective limit triggering to add other considerations for access control (see paragraph 0183-0184). Here contact identifier number could be emails or phones).
Sherlock clearly teaches performing the above checks and results determined before using the results to decide to perform other checks but does not especially teach whether they are performed in serial or parallel or more specifically (1) performing the disclosed processes one right after another or in serial or more specifically as recited in the claims in response to the passing of the second security check
However, Mathura et al. which is in the art of determining fraud online (see abstract) teaches (1) performing the disclosed processes one right after another or serial or more specifically as recited in the claims in response to the passing of the second security check (see paragraphs 0123-0132 and 0212 Examiner’s note: paragraphs 0123-032 teaches indicators compared to thresholds, and teaches these may be performed in serial or parallel (see paragraph 0212)).
Before the effective filing date of the claimed invention it would have been obvious for one of ordinary skill in the art to have modified Sherlock with the aforementioned teachings from Mathura et al. with the motivation of providing a commonly known feature that checks or verifications can be performed in parallel or serial (see Mathura et al. paragraphs 0123-0132 and 0212), when Sherlock clearly teaches performing the above checks and that they are performed used to determine performing other checks but does not especially teach whether they are performed in serial or parallel (see Sherlock paragraphs 0180-0184).
As per claim 20, Sherlock teaches
further comprising: receiving metadata associated with at least one of the user device or the session; and in response to the first and second security checks being passed, performing a risk assessment based on the received metadata, the risk assessment identifying one or more high risk factors (see paragraph 0184, Examiner’s note: teaches additional checks that could be made in response to threshold or limits).
Conclusion
16. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
17. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
Pierson et al. (United States Patent Application Publication Number: US 2006/0048211) teaches a system to prevent fraud by identifying physical devices and tracking users logins and providing that information with multiple network service providers (see abstract)
Schultz (United States Patent Application Publication Number: US 2008/0288299) teaches a method of user identity validation during online transactions (See abstract)
Choudhuri et al. (United States Patent Application Publication Number: US 2013/0024373) teaches a multi stage filtering for fraud detection based on account data (see abstract and title)
Perram et al. (United States Patent Application Publication Number: US 2017/0098219) teaches fraudulent account detection and management (see title and abstract)
Eisen (United States Patent Application Publication Number: US 2011/0082768) teaches fingerprinting to detect fraud on the internet (See abstract and title)
Mehew et al. (United States Patent Application Publication Number: US 2012/0084203) teaches using fingerprinting which can include browser information to perform secure transactions (see abstract and title)
Etchegoyen (United States Patent Application Publication Number: US 2013/0167230) teaches using fingerprints to determine malicious devices (see abstract and paragraphs 0012 and 0025)
Nielson et al. (United States Patent Application Publication Number: US 2015/0101050) teaches using device fingerprinting to determine malware threats from devices (see abstract and paragraphs 0008, 0037-0038, and 0051)
17. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KIERSTEN SUMMERS whose telephone number is (571)272-6542. The examiner can normally be reached Monday - Friday 7am-3:30pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nathan Uber can be reached on 5712703923. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users.
To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format.
For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KIERSTEN V SUMMERS/Primary Examiner, Art Unit 3626