Prosecution Insights
Last updated: October 02, 2026
Application No. 18/347,624

DIGITAL USER AUTHENTICATION USING PASSWORD CONTEXT SUBSTRINGS

Non-Final OA §101§102§103
Filed
Jul 06, 2023
Examiner
TRAN, TRI MINH
Art Unit
Tech Center
Assignee
International Business Machines Corporation
OA Round
1 (Non-Final)
82%
Grant Probability
Favorable
1-2
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
464 granted / 567 resolved
+21.8% vs TC avg
Strong +34% interview lift
Without
With
+34.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
13 currently pending
Career history
575
Total Applications
across all art units

Statute-Specific Performance

§101
12.9%
-27.1% vs TC avg
§103
51.9%
+11.9% vs TC avg
§102
20.7%
-19.3% vs TC avg
§112
5.3%
-34.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 567 resolved cases

Office Action

§101 §102 §103
DETAILED ACTION Claims 1-20 are pending. This is in response to the application filed on July 6, 2023. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 8-14 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter because the computer program product is interpreted as software per se. The specification discloses “A computer program product embodiment ("CPP embodiment" or “CPP”) is a term used in the present disclosure to describe any set of one, or more, storage media (also called "mediums") collectively included in a set of one, or more, storage devices that collectively include machine readable code…” (par. [0018]). However, the same passage defines the “computer readable storage media/medium” as a non-transitory medium. One cannot assume a storage media is the same as a computer readable storage media. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-5, 8-12 and 15-19 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Pub 20130254875 (hereinafter Sama) Regarding claim 1, Sama discloses a method of digital user authentication using password context substrings, the method comprising: comparing corresponding context substrings of an incorrect password input and a correct password database entry (Fig. 3 and par. [0054]-[0062] discloses a process of determine risk for a user when entering a password, steps 306-308 determine a context of entered password (Doberman vs bulldog or also a substring (bulldog vs dog)); generating a user legitimacy score based, at least in part, on the compared corresponding context substrings (Fig. 3, steps 312=322); and implementing a variable incorrect password input protocol based on the generated user legitimacy score (par. [0060] discloses a risk score when the user enters not the exact password where the risk level can be designated as "DENY" or “SUSPECT”). Regarding claim 2, Sama discloses wherein the implemented variable incorrect password input protocol includes changing a quantity of incorrect password inputs allowed before a user account lockout or a required password reset occurs (par. [0045] discloses risk score can be based to increase or to decrease the tolerance for the strike count policy (for locking the user account after a specific number of unsuccessful attempts)). Regarding claim 3, Sama discloses wherein a magnitude of the changed quantity of incorrect password inputs allowed is based on a value of the generated user legitimacy score (citation of par. [0045]). Regarding claim 4, Sama discloses wherein the changed quantity of incorrect password inputs allowed is increased when the user legitimacy score is at least equal to a predetermined threshold and is decreased when the user legitimacy score is less than the predetermined threshold (par. [0045]). Regarding claim 5, Sama discloses wherein the implemented incorrect password protocol further includes at least one of a security question, a two-factor authentication (2FA), a user notification via email or text message, and a captcha (par. [0045]). Claims 8-12 are rejected in view of claims 1-5 rejections respectively. Claims 15-19 are rejected in view of claims 1-5 rejections respectively. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 6-7, 13-14 and 20 are rejected under 35 U.S.C. 103 as being unpatentable Sama n view of Pub 20210092155 (hereinafter Wang) Regarding claim 6, Sama discloses requesting additional information from the user for authentication purposes when based on risk score (par. [0045]). However, Sama does not expressly disclose wherein the user legitimacy score is further based on at least one of a similarity score of the compared corresponding context substrings, a geolocation, an internet protocol (IP) address, and a speed of at least one incorrect password input. Wang discloses this feature (Fig. 3 and related text disclose determining security risk when a user enters a password on website that has address belong to a whitelist or blacklist. Therefore, it would have been obvious before the effective filing date of the claimed invention to modify Sama with Wang to further teach the aforementioned feature. One would have done so to include other parameters the password check for password attack. Regarding claim 7, Sama discloses wherein the context substring is a predetermined selection of plural characters and respective positions thereof (par. [0041]-[0048] discloses a predetermined set of partial characters to be checked against the real password and each character of the password can appear in different position). Claims 13-14 are rejected in view of claims 6-7 rejections respectively. Claim 20 is rejected in view of claim 6 rejection. Inquiry communication Any inquiry concerning this communication or earlier communications from the examiner should be directed to TRI M TRAN whose telephone number is (571)270-1994. The examiner can normally be reached Mon-Fri: 9am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached at (469)295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TRI M TRAN/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Jul 06, 2023
Application Filed
Nov 28, 2023
Response after Non-Final Action
Aug 11, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12724885
KEYPAD SECURITY
2y 2m to grant Granted Sep 01, 2026
Patent 12726345
SYSTEMS AND METHODS FOR DEPLOYMENT, MANAGEMENT AND USE OF DYNAMIC CIPHER KEY SYSTEMS
1y 9m to grant Granted Sep 01, 2026
Patent 12717952
SYSTEM AND METHOD OF PROCESSING A DATA ACCESS REQUEST
2y 1m to grant Granted Aug 25, 2026
Patent 12719659
Server Side Authentication
2y 1m to grant Granted Aug 25, 2026
Patent 12688290
LOW RESOURCE NEARLINE ATTACK DETECTION
2y 3m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
82%
Grant Probability
99%
With Interview (+34.4%)
2y 6m (~0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 567 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month