Prosecution Insights
Last updated: October 02, 2026
Application No. 18/331,976

MULTI-FACTOR AUTHENTICATION HARDENING

Non-Final OA §102§103
Filed
Jun 09, 2023
Examiner
ZHAO, DON GORDON
Art Unit
Tech Center
Assignee
International Business Machines Corporation
OA Round
1 (Non-Final)
87%
Grant Probability
Favorable
1-2
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
699 granted / 801 resolved
+27.3% vs TC avg
Strong +16% interview lift
Without
With
+16.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 2m
Avg Prosecution
15 currently pending
Career history
807
Total Applications
across all art units

Statute-Specific Performance

§101
12.6%
-27.4% vs TC avg
§103
43.6%
+3.6% vs TC avg
§102
4.5%
-35.5% vs TC avg
§112
27.2%
-12.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 801 resolved cases

Office Action

§102 §103
DETAILED ACTION Claims 1-20 are presented on 06/09/2023 for examination on merits. Claims 1, 8, and 15 are independent base claims. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Examiner's Instructions for filing Response to this Office Action When the Applicant submits amendments regarding to the claims in response the Office Action, the Examiner would appreciate Applicant if a clean copy of the claims is provided to facilitate the prosecution which otherwise requires extra time for editing the marked-up claims from OCR. Please submit two sets of claims: Set #1 as in a typical filing which includes indicators for the status of claim and all marked amendments to the claims; and Set #2 as an appendix to the Arguments/Remarks for a clean version of the claims which has all the markups removed for entry by the Examiner. Claim Objections Claims 1-2, 8-9,12, and 15 are objected to because of the following informalities: Claims 1-2, 8-9,12, and 15 each recite “MFA” or “2FA” deficiently. For formality reasons, consistency of recited terms is required. It should be noted that, for example, claim 2 specifies the factor is a second-factor of a two-factor authentication (2FA) protocol while the factor is described in claim 1 as a factor of a multi-factor authentication (MFA) protocol from a user-device. Appropriate correction is required. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1-2, 6-7, 8-9, 13-15 and 19-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Chenna (US 20140351589 A1). As per claim 1, Chenna teaches a computer-implemented method comprising: receiving a request for a factor of a multi-factor authentication (MFA) protocol from a user-device (par. 0007 and 0029-0031: a client device requesting access to a computing application; par. 0015 and 0029: performing the second factor authentication process, such as OTP); generating an encrypted factor using a public key of an identity certificate issued to a user of the user-device (the Abstract: To authenticate a user, a server generates a nonce, encrypts the nonce with a public key associated with the user; par. 0018-0019: encrypts the nonce with a public key of the user; PKI. Chenna also discloses using a certificate and private key installed on a mobile device and a nonce generated on the server. See the abstract and par. 0019); sending the encrypted factor to the user-device to allow the user-device to obtain the factor by decrypting the encrypted factor using a private key that corresponds to the public key (par. 0025-0030: provide a second factor authentication challenge to users in the form of an encrypted nonce encoded in a barcode graphic. In response, a user recovers the encrypted nonce using a barcode scanner and decrypts the nonce using a private key stored on a mobile device); receiving the factor from the user-device (par. 0039: the user [receives] and recovers the nonce. At 440, the user enters the nonce in an entry field of a user interface as a one-time password value and submits it to the relying application 403); and verifying that the factor received from the user-device is a same factor used to generate the encrypted factor (par. 0039: At 445, the relying application validates the one-time password. That is, the relying application compares the nonce value sent to the client with the one received from the client to determine a result of the second factor authentication challenge. Chenna discloses that …the relying application compares the nonce value received from the requesting client (at step 220) to the nonce value generated by the relying application (at step 215). If the values match, then the relying application may conclude that the requesting client is authenticated; see par. 0033). As per claim 2, Chenna further teaches the computer-implemented method of claim 1, wherein the factor is a second-factor of a two-factor authentication (2FA) protocol (par. 0032-0033: a second factor authentication). As per claim 6, Chenna further teaches the computer-implemented method of claim 1, wherein the identity certificate is issued to the user by a provider after successful vetting of the user (par. 0028-0029: the certificate authority 127 may act as an identity authority…issuing the certificate to the user [after] the relying application 107 authenticates a user by validating a username and password; the relying application 107 maintains user certificates in a local database [while] a user is allowed to maintain the certificate and to perform a client authentication process using a certificate in a certificate store 117 on mobile device 115; see par. 0026-0027). As per claim 7, Chenna further teaches the computer-implemented method of claim 1, wherein the identity certificate is issued to the user by a certificate authority after successful vetting of the user (par. 0026-0029: the certificate authority 127 may act as an identity authority…issuing the certificate to the user [after] the relying application 107 authenticates a user by validating a username and password). Regarding claims 8 and 15, the claims are each similar to claim 1, respectively, and are therefore rejected using a similar rationale. Regarding claims 9, 13, and 14, they are respectively similar to claims 2, 6 and 7 and are therefore rejected using a similar rationale. Regarding claims 19 and 20, they are respectively similar to claims 6 and 7 and are therefore rejected using a similar rationale Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claims 3-4. 10-11, and 16-17 are rejected under 35 U.S.C. 103 as being unpatentable over Chenna, as applied to claim 1, in view of ALONSO CEBRIAN (US 20160156598 A1; hereinafter “Alonso”). As per claim 3, Chenna further teaches the computer-implemented method of claim 1, but do not explicitly disclose verifying a signature included with the factor using the public key of the identity certificate, wherein the user-device signs the factor using the private key. This aspect of the claim is identified as a further difference. In a related art, Alonso teaches: wherein verifying the factor received from the user-device further comprises: verifying a signature included with the factor using the public key of the identity certificate, wherein the user-device signs the factor using the private key (Alonso par. 0045: verifying integrity of the received digitally signed OTP with the OTP that the second server generated; the use of a public/private key for generating a digital signature by means of: generating and sending, the second server to the dedicated program, a one-time password (OTP) that the user is going to use for setting up the extra authentication factor mechanism; see par. 0074-0077 for the options of the user 100 after completing the login process). Chenna and Alonso are analogous art to the claimed invention in the same field of endeavor as the claimed invention, or reasonably pertinent to the problem faced by the inventor, which may be in a different field. Thus, it would have been obvious to one of ordinary in the art, before the effective filing date of the claimed invention, to modify Chenna’s system with Alonso’s teachings of verifying integrity of the received digitally signed OTP using a private key. For this combination, the motivation would have been to improve the level of security with a digitally signed OTP. . As per claim 4, Chenna further teaches the computer-implemented method of claim 1, but do not explicitly disclose having options for receiving the factor, which when selected, generates the request for the factor. This aspect of the claim is identified as a further difference. In a related art, Alonso teaches: wherein receiving the request for the factor further comprises: in response to verifying a user login, providing the user of the user-device with a plurality of options for receiving the factor, which when selected, generates the request for the factor (Alonso, par. 0043-0045: considering two different options. In the first one, a parental control mechanism is used so the children's (original) accounts access control is delegated to the parent control mechanism. In the second one, a single account allows multiple locks. In this latter case, the unlock action will require that multiple users unlock their locks concurrently; par. 0072 and 0077: choosing different options to establish locks with different service providers). Chenna and Alonso are analogous art to the claimed invention in the same field of endeavor as the claimed invention, or reasonably pertinent to the problem faced by the inventor, which may be in a different field. Thus, it would have been obvious to one of ordinary in the art, before the effective filing date of the claimed invention, to modify Chenna’s system with Alonso’s teachings of options for receiving a second authentication factor. For this combination, the motivation would have been to improve the level of security with user selected options for receiving the factor. Regarding claims 10-11, the claims are similar to claims 3-4, respectively, and are therefore rejected using a similar rationale. Regarding claims 16-17, the claims are similar to claims 3-4, respectively, and are therefore rejected using a similar rationale. Claims 5, 12, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Chenna, as applied to claim 1, in view of Raffay (US 20230262037 A1). As per claim 5, Chenna further teaches the computer-implemented method of claim 1, but do not explicitly disclose selecting a communication channel for sending the factor to the user-device. This aspect of the claim is identified as a further difference. In a related art, Raffay teaches: wherein receiving the request for the factor further comprises: receiving, from the user-device, a selected communication channel for sending the factor to the user-device (Raffay par. 0058-0059: instructions for accessing a security token … including a message sent via a user selected channel; The preferred communication channel may be pre-designated by the user (e.g., as received in a request to establish a user identity), or may be selected by the user when the user interacts with the authentication webpage). Chenna and Raffay are analogous art to the claimed invention in the same field of endeavor as the claimed invention, or reasonably pertinent to the problem faced by the inventor, which may be in a different field. Thus, it would have been obvious to one of ordinary in the art, before the effective filing date of the claimed invention, to modify Chenna’s system with Raffay’s teachings of a selected communication channel for sending the factor. For this combination, the motivation would have been to improve the level of security with a selectable communication channel for sending the factor. Regarding claims 12 and 18, they are each similar to claim 5 and are therefore rejected using a similar rationale. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure as the prior art additionally discloses certain parts of the claim features (See “PTO-892 Notice of Reference Cited”). Any inquiry concerning this communication or earlier communications from the examiner should be directed to DON ZHAO whose telephone number is (571)272.9953. The examiner can normally be reached on Monday to Friday, 7:30 A.M to 5:00 P.M EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl G Colin can be reached on 571.272.3862. The fax phone number for the organization where this application or proceeding is assigned is 571.273.8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866.217.9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800.786.9199 (IN USA OR CANADA) or 571.272.1000. /Don G Zhao/Primary Examiner, Art Unit 2493 09/01/2026
Read full office action

Prosecution Timeline

Jun 09, 2023
Application Filed
Nov 28, 2023
Response after Non-Final Action
Sep 04, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12745152
Methods and Apparatus for Optimizing UE Re-Authentication during Mobility across different Non-3GPP Access Points under a NSWOF
3y 0m to grant Granted Sep 22, 2026
Patent 12737461
AI-BASED FILE MALICIOUSNESS CLASSIFICATION WITH AN EXPLANATION OF REASONING
2y 6m to grant Granted Sep 15, 2026
Patent 12739097
METHOD FOR ENCRYPTING PLAIN TEXT
1y 3m to grant Granted Sep 15, 2026
Patent 12712906
SYSTEMS AND METHODS FOR DETECTING AND MITIGATING CYBER SECURITY THREATS
2y 9m to grant Granted Aug 18, 2026
Patent 12706763
Audit Chain for Hashes Using Tokenization
3y 4m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
87%
Grant Probability
99%
With Interview (+16.3%)
2y 2m (~0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 801 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month