Prosecution Insights
Last updated: October 02, 2026
Application No. 18/334,688

COMPUTER GENERATED PASSWORD CRITERIA COMBINATIONS

Non-Final OA §103
Filed
Jun 14, 2023
Examiner
RASHID, HARUNUR
Art Unit
Tech Center
Assignee
International Business Machines Corporation
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
479 granted / 631 resolved
+15.9% vs TC avg
Strong +36% interview lift
Without
With
+36.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
18 currently pending
Career history
657
Total Applications
across all art units

Statute-Specific Performance

§101
13.3%
-26.7% vs TC avg
§103
61.1%
+21.1% vs TC avg
§102
5.3%
-34.7% vs TC avg
§112
7.4%
-32.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 631 resolved cases

Office Action

§103
DETAILED ACTION 1. Claims 1-20 are pending in this examination. Notice of Pre-AIA or AIA Status 2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 3. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claim Rejections - 35 USC § 103 4.1. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 4.2. Claims 1-2, 4-7, 9-10, 12-15, 17-18, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over US Patent Application No. 20210218768 to Keohane et al (“Keohane”) in view of US Patent Application No. 20230065220 to Rodriguez Bravo et al (“Rodriguez Bravo”). As per claim 1, Keohane discloses a computer-implemented method for generating a password criteria combination in response to a required password change, the computer-implemented method comprising ([0004], the computer processor acquires a new password for access to the targeted item, wherein the new password is based on a more complex set of password generation rules than a current password): generating, by the computer, password criteria for the new password, the password criteria being different than a previous password criteria ([0036], the new password by dynamically generating the new password and applying a longer character length and a more complex set of password generations rules than that of the current password.) receiving, at the computer, a submitted new password ([0035] In some embodiments of the present invention, password change program 200 acquires the new password from a set of pre-defined passwords, selecting a next password in the set of passwords subsequent to the current password); determining, by the computer, when the submitted new password meets each of the password criteria for the new password ([0038] In step 260, password change program 200 replaces the current password with a new password that includes a longer character string and in some embodiments of the present invention, may meet additional and more complex rules. In some embodiments the new password is from a set of sequentially more complex passwords pre-determined by the user and sequentially applied by password change program 200. In other embodiments, password change program 200 dynamically generates the new password to include a longer character string that the previous password and may meet additional and more complex rules, [0025]). Keohane does not explicitly disclose however in the same field of endeavor, Rodriguez Bravo discloses detecting, by a computer, a request for a new password for a program; allowing, by the computer, access to the program ([0023], a user, via user interface 122, invokes workflow 200 upon indicating an intent to change a default password, [0036]-[0037]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Keohane with the teaching of Rodriguez Bravo by including the feature of access, in order for Keohane’s system to prevent unauthorized access to a bank account in the same manner that a company utilizes strong passwords to stop illegal/unlawful access to proprietary data. A random password policy for a specific user associated with an entity is generated based on a global password requirement. A new password created by the specific user based on the generated random password policy is identified. That the new password complies with a set of requirements specified by the generated random password policy is confirmed. (Rodriguez Bravo, abstract). As per claim 2, the combination of Keohane and Rodriguez Bravo discloses the computer-implemented method of claim 1, wherein more than half of user accounts for the program have different password criteria (Rodriguez Bravo, [0023] FIG. 2A is a flowchart of workflow 200 depicting a method for creating unique password policies on an individual basis.). The motivation regarding the obviousness of claim 1 is also applied to claim 2. As per claim 4, the combination of Keohane and Rodriguez Bravo discloses the computer-implemented method of claim 1, wherein the at least one of the password criteria options is a limitation on any letters, numbers, asterisk, words, special characters, symbols, accent marks, punctuation marks, grammar, or phrases used in the changed password (Keohane, [0035], the number and requirements for uppercase and lowercase letters, numbers, and special characters). As per claim 5, the combination of Keohane and Rodriguez Bravo discloses the computer-implemented method of claim 1, wherein the password criteria is not identical to a previous password criteria (Keohane, [0004], the new password is based on a more complex set of password generation rules than a current password, [0038]). As per claim 6, the combination of Keohane and Rodriguez Bravo discloses the computer-implemented method of claim 1, wherein generating the password criteria further comprises: selecting one or more password requirements at random from a list of password criteria (Rodriguez Bravo, [0030] In an embodiment, muddle program 138 identifies a password (step 214). In other words, muddle program 138 identifies a new (or updated) password associated with the user (subsequent to the user creating a password based on the generated random password policy received from muddle program 138). The motivation regarding the obviousness of claim 1 is also applied to claim 6. As per claim 7, the combination of Keohane and Rodriguez Bravo discloses the computer-implemented method of claim 1, wherein determining the request for a new password is based at least in part on, determining a predetermined number of unsuccessful log ins exceeds a predetermined threshold (Keohane, [0011], unsuccessful access or login attempts exceeds an attempt threshold). Claims 9, and 17 are rejected for similar reasons as stated above, and claim 1. Claims 10, and 18 are rejected for similar reasons as stated above, and claim 2. Claim 12 rejected for similar reasons as stated above, and claim 4. Claims 13, and 19 are rejected for similar reasons as stated above, and claim 5. Claim 14 rejected for similar reasons as stated above, and claim 6. Claim 17 rejected for similar reasons as stated above, and claim 7. 4.3. Claims 3, 8, 11, 16 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Keohane and Rodriguez Bravo as applied to claim above, and in view of US Patent Application No. 20220407849 to Endler et al (“Endler ”). As per claim 3, the combination of Keohane and Rodriguez Bravo discloses the invention as described above. Keohane and Rodriguez Bravo do not explicitly disclose however, In the same field of endeavor, Endler discloses the computer-implemented method of claim 1, wherein detecting the request for a new password is based at least in part on, a predetermined amount of time passed since a previous password was created (Endler, [0126]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Keohane with the teaching of Rodriguez Bravo/ Endler by including the feature of amount of time, in order for Keohane’s system to efficiently and proactively retrieve exposed or stolen passwords, to block access to a user account associated with a compromised password, to reject use of passwords that have found to have been exposed or compromised, and to notify a user to change a password that has been found to have been exposed or compromised. Provided is a process, including: obtaining a first password to a private computer network; determining, with a credential-monitoring application within the private computer network, whether the first password satisfies one or more criteria by: comparing the first password to a set of compromised credentials within a database within the private computer network; and determining whether the first password matches one or more passwords within the database; and in response to the determination that the first password satisfies the one or more criteria from among the plurality of criteria, causing a use of the first password to access the private computer network to be rejected and causing a first user associated with the first password to be notified to change the first password (Endler, abstract). As per claim 8, the combination of Keohane, Rodriguez Bravo and Endler discloses the computer-implemented method of claim 1, wherein generating the password criteria, further comprises categorizing the criteria in one or more types of password criteria and further generating the plurality of password criteria based, at least in part, on selecting at least two criteria from two different types of password criteria (Endler, [0155], in response to the determination that the first password satisfies two or more criteria from among the plurality of criteria). The motivation regarding the obviousness of claim 1 is also applied to claim 8. Claims 11, and 20 are rejected for similar reasons as stated above, and claim 3. Claim 16 is rejected for similar reasons as stated above, and claim 8. 5.1. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure as the prior art discloses many of the claim features (See PTO-form 892). 5.2. a). US Patent Application No. 20040250141 to Casco-Arias et al., discloses a method of controlling password changes in a system having a plurality of data processing systems having separate password registries. Contents of passwords in the password registries of the data processing systems are controlled using password content policies that are centrally shared between the plurality of data processing systems. b). US Patent No. 8769607 issued to Jerdonek et al., discloses systems, methods and articles of manufacture for evaluating a password policy are disclosed. The password evaluation system receives password policy data regarding a password policy, including a password constraint. The system analyzes the password policy data to determine a usability index and a password strength index for the password policy, and also determines a usability index and password strength index for a plurality of modified password policies having password constraints different from the password policy. The system then provides a graphical representation of the usability index and the password strength for the password policy and the modified password policies, thereby allowing a password designer to optimize the tradeoffs between usability and security of a password policy. Conclusion 6. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HARUNUR RASHID whose telephone number is (571)270-7195. The examiner can normally be reached 9 AM to 5PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. HARUNUR . RASHID Primary Examiner Art Unit 2497 /HARUNUR RASHID/Primary Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Jun 14, 2023
Application Filed
Nov 20, 2023
Response after Non-Final Action
Aug 21, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730921
AUTOMATED IDENTIFICATION OF SENSITIVE DATA ACCESS BASED ON SOURCE-CODE ANALYSIS
1y 9m to grant Granted Sep 08, 2026
Patent 12711501
ASSOCIATING MULTIPLE USER ACCOUNTS WITH A CONTENT OUTPUT DEVICE
1y 8m to grant Granted Aug 18, 2026
Patent 12712745
Communication Method and Related Device
1y 6m to grant Granted Aug 18, 2026
Patent 12706945
Network Environment Control Scanning Engine
1y 8m to grant Granted Aug 11, 2026
Patent 12701003
MACHINE LEARNING FOR AUTOMATIC IDENTIFICATION OF POINTS OF INTEREST FOR SIDE CHANNEL LEAKAGE
1y 8m to grant Granted Aug 04, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+36.2%)
3y 4m (~0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 631 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month