Prosecution Insights
Last updated: August 17, 2026
Application No. 18/322,792

One-Time Password Activation Using Read Receipts

Non-Final OA §102§103
Filed
May 24, 2023
Examiner
REVAK, CHRISTOPHER A
Art Unit
Tech Center
Assignee
International Business Machines Corporation
OA Round
1 (Non-Final)
89%
Grant Probability
Favorable
1-2
OA Rounds
0m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 89% — above average
89%
Career Allowance Rate
995 granted / 1114 resolved
+29.3% vs TC avg
Moderate +9% lift
Without
With
+8.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
17 currently pending
Career history
1127
Total Applications
across all art units

Statute-Specific Performance

§101
13.0%
-27.0% vs TC avg
§103
21.3%
-18.7% vs TC avg
§102
37.5%
-2.5% vs TC avg
§112
7.0%
-33.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1114 resolved cases

Office Action

§102 §103
IDETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on May 24, 2023 in is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1, 3-5, 7-9, 11-13, 15-17, 19, and 20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Singh et al, U.S. Patent 12,223,506. As per claim 1, it is taught of a computer implemented method for managing passwords, the computer implemented method (col. 23, lines 51-63) comprising: receiving, by a number of processor units (col. 23, lines 51-54), a password request for a one-time password from a user (payment server sends a request to a server system for device behavioral analyzer service tied to information of successful verification of user input via a one-time password entered by the cardholder on the user device performing multi-factor authentication, col. 12, line 66 through col. 13, line 7); sending, by the number of processor units (col. 23, lines 51-54), the one-time password with a message request for a read receipt to the user in response to receiving the password request (server transmits a request to perform device behavioral analysis of the device used by the cardholder, col. 13, lines 38-41, that includes device activity status and behavioral characteristics as the time of receiving a one-time password and request a read receipt flag in response to receiving the one-time password along with the setting of the read receipt when the cardholder reads the one-time password, col. 13, lines 46-59); and activating, by the number of processor units (col. 23, lines 51-54), the one-time password in response to receiving the read receipt from the user (device activity status and behavioral characteristics are captured at the time of receiving a one-time password and a read receipt flag is set when the cardholder reads the one-time password (i.e., activation of the one-time password), col. 13, lines 46-59). As per claim 3, it is taught wherein sending, by the number of processor units (col. 23, lines 51-54), the one-time password with a message request for a read receipt comprises: sending, by the number of processor units (col. 23, lines 51-54), the one-time password with a message request for a read receipt to the user in a message in response to receiving the password request (server transmits a request to perform device behavioral analysis of the device used by the cardholder, col. 13, lines 38-41, that includes device activity status and behavioral characteristics as the time of receiving the one-time password and a read receipt flag in response to receiving the one-time password along with the setting of the read receipt when the cardholder reads the one-time password, col. 13, lines 46-59). As per claim 4, it is disclosed wherein the message is selected from a group comprising an email message, a text message, a chat message, and an instant messaging message (read receipt flag is set when the cardholder reads the OTP on the user device through the email and/or sms application (i.e., text message), col. 13, lines 57-59). As per claim 5, it is taught wherein the one-time password is sent in a message and the read receipt is generated automatically in response to one of opening the message, viewing a message content in the message, and user input to the message (server transmits a request to perform device behavioral analysis of the device used by the cardholder, col. 13, lines 38-41, that includes device activity status and behavioral characteristics as the time of receiving the one-time password and a read receipt flag in response to receiving the one-time password along with the setting of the read receipt with the cardholder reads the one-time password, col. 13, lines 46-59; wherein the server system triggers an API to connect to the user devices and for performing the device behavioral analysis (col. 13, lines 41-46) which is being interpreted by the Examiner as an automatic process since the device behavioral analysis is software written to carry out the process). As per claim 7, it is taught wherein the one-time password is sent to a different computing device from a computer device sending the password request for the one-time password (a first authentication token (one-time password) is received on a user device associated with the cardholder, such as a mobile device in response to complete the request for a transaction, in which a second authentication token (one-time password) is received on a second different device, such as a laptop or desktop, col. 4, lines 52-65). As per claim 8, it is disclosed wherein the one-time password is sent to a different application from an application sending the password request for the one-time password (a first authentication token (one-time password) is received on a user device associated with the cardholder, such as a mobile device in response to complete the request for a payment transaction (i.e., first application), in which a second authentication token (one-time password) is received on a second different device, such as a laptop or desktop using a multi-factor authentication system (i.e., different application from the first application), col. 4, lines 52-65). As per claim 9, it is taught of a computer system (col. 23, lines 51-63) comprising: a number of processor units, wherein the number of processor units executes program instructions (col. 23, lines 51-63) to: receive a password request for a one-time password from a user (payment server sends a request to a server system for device behavioral analyzer service tied to information of successful verification of user input via a one-time password entered by the cardholder on the user device performing multi-factor authentication, col. 12, line 66 through col. 13, line 7); send the one-time password with a message request for a read receipt to the user in response to receiving the password request (server transmits a request to perform device behavioral analysis of the device used by the cardholder, col. 13, lines 38-41, that includes device activity status and behavioral characteristics as the time of receiving a one-time password and request a read receipt flag in response to receiving the one-time password along with the setting of the read receipt when the cardholder reads the one-time password, col. 13, lines 46-59); and activate the one-time password in response to receiving the read receipt from the user (device activity status and behavioral characteristics are captured at the time of receiving a one-time password and a read receipt flag is set when the cardholder reads the one-time password (i.e., activation of the one-time password), col. 13, lines 46-59). As per claim 11, it is taught wherein in sending, by the number of processor units (col. 23, lines 51-54), the one-time password with a message request for a read receipt, the number of processor units further executes program instructions to: send the one-time password with a message request for a read receipt to the user in message in response to receiving the password request (server transmits a request to perform device behavioral analysis of the device used by the cardholder, col. 13, lines 38-41, that includes device activity status and behavioral characteristics as the time of receiving the one-time password and a read receipt flag in response to receiving the one-time password along with the setting of the read receipt when the cardholder reads the one-time password, col. 13, lines 46-59). As per claim 12, it is disclosed wherein the message is selected from a group comprising an email message, a text message, a chat message, and an instant messaging message (read receipt flag is set when the cardholder reads the OTP on the user device through the email and/or sms application (i.e., text message), col. 13, lines 57-59). As per claim 13, it is taught wherein the one-time password is sent in a message and the read receipt is generated automatically in response to one of opening the message, viewing a message content in the message, and user input to the message (server transmits a request to perform device behavioral analysis of the device used by the cardholder, col. 13, lines 38-41, that includes device activity status and behavioral characteristics as the time of receiving the one-time password and a read receipt flag in response to receiving the one-time password along with the setting of the read receipt with the cardholder reads the one-time password, col. 13, lines 46-59; wherein the server system triggers an API to connect to the user devices and for performing the device behavioral analysis (col. 13, lines 41-46) which is being interpreted by the Examiner as an automatic process since the device behavioral analysis is software written to carry out the process). As per claim 15, it is taught wherein the one-time password is sent to a different client device from a client device sending the password request for the one-time password (a first authentication token (one-time password) is received on a user device associated with the cardholder, such as a mobile device or a smartphone in response to complete the request for a transaction, in which a second authentication token (one-time password) is received on a second different device, such as a laptop or desktop, col. 4, lines 52-65). As per claim 16, it is disclosed wherein the one-time password is sent to a different application from an application sending the password request for the one-time password (a first authentication token (one-time password) is received on a user device associated with the cardholder, such as a mobile device in response to complete the request for a payment transaction (i.e., first application), in which a second authentication token (one-time password) is received on a second different device, such as a laptop or desktop using a multi-factor authentication system (i.e., different application from the first application), col. 4, lines 52-65). As per claim 17, it is taught of a computer program product for managing passwords, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computer system to cause the computer system (col. 23, lines 51-63) to: receive a password request for a one-time password from a user (payment server sends a request to a server system for device behavioral analyzer service tied to information of successful verification of user input via a one-time password entered by the cardholder on the user device performing multi-factor authentication, col. 12, line 66 through col. 13, line 7); send the one-time password with a message request for a read receipt to the user in response to receiving the password request (server transmits a request to perform device behavioral analysis of the device used by the cardholder, col. 13, lines 38-41, that includes device activity status and behavioral characteristics as the time of receiving a one-time password and request a read receipt flag in response to receiving the one-time password along with the setting of the read receipt when the cardholder reads the one-time password, col. 13, lines 46-59); and activate the one-time password in response to receiving the read receipt from the user (device activity status and behavioral characteristics are captured at the time of receiving a one-time password and a read receipt flag is set when the cardholder reads the one-time password (i.e., activation of the one-time password), col. 13, lines 46-59). As per claim 19, it is taught wherein sending, by the number of processor units (col. 23, lines 51-54), the one-time password with a message request for a read receipt, the program instructions are further executable by the computer system to cause the computer system to: send the one-time password with a message request for a read receipt to the user in message in response to receiving the password request (server transmits a request to perform device behavioral analysis of the device used by the cardholder, col. 13, lines 38-41, that includes device activity status and behavioral characteristics as the time of receiving the one-time password and a read receipt flag in response to receiving the one-time password along with the setting of the read receipt when the cardholder reads the one-time password, col. 13, lines 46-59). As per claim 20, it is disclosed wherein the message is selected from a group comprising an email message, a text message, a chat message, and an instant messaging message (read receipt flag is set when the cardholder reads the OTP on the user device through the email and/or sms application (i.e., text message), col. 13, lines 57-59). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 2, 10, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Singh et al, U.S. Patent 12,223,506 in view of Gajre et al, U.S. Patent 11,539,689. As per claims 2, 10, and 18, Singh et al discloses of it is disclosed of further comprising: receiving, by the number of processor units (col. 23, lines 51-54), a password request for a one-time password from the user (payment server sends a request to a server system for device behavioral analyzer service tied to information of successful verification of user input via a one-time password entered by the cardholder on the user device performing multi-factor authentication, col. 12, line 66 through col. 13, line 7); and sending, by the number of processor units (col. 23, lines 51-54), the one-time password with the message request for the read receipt in response to receiving requests (server transmits a request to perform device behavioral analysis of the device used by the cardholder, col. 13, lines 38-41, that includes device activity status and behavioral characteristics as the time of receiving a one-time password and request a read receipt flag in response to receiving the one-time password along with the setting of the read receipt when the cardholder reads the one-time password, col. 13, lines 46-59). Singh et al fails to disclose of receiving a subsequent password request for a new one-time password from the user. Gajre et al discloses of receiving a subsequent password request for a new one-time password from the user (a user requests a new one-time password or OTP, to restart the authentication process, col. 11, lines 24-25). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to recognize that there exists conditions whereby a new one-time password may be requested by the user due to various factors. Gajre et al discloses those factors as there existing no match for the one-time password as entered by the user, or after a predetermined number of attempted failures by the user, or even reaching an expiration time without successfully entering the one-time password, col. 11, lines 18-27. Although Singh et al fails to disclose of those conditions for requesting a new one-time password, it is obvious that a user would desire to make another attempt at authentication since they are an authorized registered user and have accidentally entered an incorrect one-time password that was previously supplied to them. The teachings of Gajre et al provide support for this condition which is known in the art. Claims 6 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Singh et al, U.S. Patent 12,223,506 in view of Feijoo et al, US 2018/0295135. As per claims 6 and 14, Singh et al discloses of the use of multi-factor authentication using one-time passwords, but fails to disclose wherein the multi-factor authentication one-time password is valid for a limited period of time in response to the one-time password being activated. Feijoo et al discloses wherein the multi-factor authentication includes a password (i.e., one-time password) is valid for a limited period of time in response to the password (i.e., one-time password) being activated (a multi-factor authentication method is employed that applies a password management requirements such as restrictions on password expiration time periods after which a new password must be defined (i.e., valid for a limited period of time in response to the one-time password being activated or initiated until an expiration time period), paragraph 0050). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to have been motivated to set time parameters to strengthen authenticity in a multi-factor authentication system to ensure that integrity of the authentication protocol is maintained. Feijoo additionally discloses of preventing re-use within a specified time period in addition to expiration time periods that are password strengthening, see paragraph 0050. Although Singh et al discloses multi-factor authentication using one-time passwords, in addition to the password being used once in Singh et al, Feijoo et al offers an additional layer of protection by application of an expiration time period on the multi-factor authentication one time password to provide enhanced authentication security. Conclusion The relevant art made of record and not relied upon is considered pertinent to applicant's disclosure. Mumick et al, US 2021/0359991 is relied upon for disclosing of provides feedback to the brand/developer about the delivery status and the read receipt of the rich one time password (ROTP) message, to allow the brand to take appropriate action, see paragraph 0050. Gordon et al, US 2018/0032997 is relied upon for disclosing of a user may choose automatic settings relating to a sent shared ticket/deal and/or invite (e.g. read receipt confirmation, time constraint(s), password confirmation, etc.) In one embodiment, the user may require a password as a condition to accepting, see paragraph 0619. Tadayon, US 2013/0166657 is relied upon for disclosing of dialog popping up to ask a receiver if she really wants to delete or forward the file or email, and/or (as another embodiment) asks for her biometrics or password to verify for authorization for deleting or moving the file or email, or forces an acknowledgement read-receipt, sent by the receiver (or by the system, automatically), to the sender, to show to the sender that the email was read or opened or forwarded by the receiver, see paragraph 0094. Green et al, US 2021/0073370 is a related teaching by the Applicant relied upon for disclosing of analyzing input security credentials to determine if they are MFA credentials to ascertain if they should be stored for automatic input or not. One known method evaluates the cadence of key stokes of the security credentials to identify a pause between the input of a fixed password and the input of an OTP. If it was determined that MFA was not being used then the client would store the password and reuse it when the session expired, see paragraph 0008. Jiang et al, U.S. Patent 10,257,202 is relied upon for disclosing a one-time password may be provided to and/or generated on a computing device associated with a user by an online platform and then entered to the online platform on an additional computing device to enable the user to access an online account via the additional computing device. After the user has been granted access to the online account, the one-time password may expire or be otherwise unusable in the event that the user attempts to log into the online account using the same one-time password at a later point in time, see column 7, lines 42-50. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER REVAK whose telephone number is (571)272-3794. The examiner can normally be reached 5:30am - 3:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHRISTOPHER A REVAK/Primary Examiner, Art Unit 2407
Read full office action

Prosecution Timeline

May 24, 2023
Application Filed
Nov 20, 2023
Response after Non-Final Action
Aug 06, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705155
CONTROL OF CONDITIONS FOR EXECUTION OF ACTIONS ON ELEMENTS INCLUDED IN COMMUNICATION SYSTEM
2y 7m to grant Granted Aug 11, 2026
Patent 12664278
SECURITY THREAT MITIGATION
2y 6m to grant Granted Jun 23, 2026
Patent 12659168
DYNAMICALLY VERIFYING AUTHENTICITY AND VALIDITY OF CREDENTIALS
2y 7m to grant Granted Jun 16, 2026
Patent 12657324
DETECTING DATA EXFILTRATION
2y 2m to grant Granted Jun 16, 2026
Patent 12651061
CYBERSECURITY TOOLS FOR MANAGING ANOMALOUS SECURITY DATA ITEMS
2y 1m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
89%
Grant Probability
98%
With Interview (+8.6%)
2y 7m (~0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 1114 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month