Prosecution Insights
Last updated: October 01, 2026
Application No. 18/368,095

GENERATING CUSTOMIZED AUTHENTICATION QUESTIONS FOR AUTOMATED VISHING DETECTION

Non-Final OA §103
Filed
Sep 14, 2023
Examiner
AL AUBAIDI, RASHA S
Art Unit
2693
Tech Center
2600 — Communications
Assignee
Bank of America Corporation
OA Round
3 (Non-Final)
78%
Grant Probability
Favorable
3-4
OA Rounds
3m
Est. Remaining
89%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
596 granted / 766 resolved
+15.8% vs TC avg
Moderate +11% lift
Without
With
+11.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
25 currently pending
Career history
793
Total Applications
across all art units

Statute-Specific Performance

§101
10.4%
-29.6% vs TC avg
§103
60.8%
+20.8% vs TC avg
§102
15.4%
-24.6% vs TC avg
§112
5.9%
-34.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 766 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 1. A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 06/22/2026 has been entered. Response to Amendment 2. This in response to an RCE amendment filed 06/22/2026. Claims 22-25 have been added. Claims 16, 18-19 and 21 have been canceled. Claims 1, 17 and 20 have been amended. Claims 1-5, 7-8, 10-17, 20 and 22-25 are now pending in this application. Note Applicant’s citation (Page 11 of the Remarks) for status of the claims (i.e., canceled claims and pending claims) are inaccurate, correction is required in subsequent action. Claim Rejections - 35 USC § 103 3. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-5, 7-15, 17, 20 and 22-25 is/are rejected under 35 U.S.C. 103 as being unpatentable over Nygate et al. (Pub.No.: 2020/0074054 A1) in view of Algard et al. (Pub.No.: 2018/0176372 A1) in view of Halferty et al. (US PAT # 8,737,581 B1) and further in view of Jung et al (Pub.No. 2007/0143625 A1). Regarding claims 1, 17 and 20, Nygate teaches a computing platform, a method and a non-transitory computer-readable media comprising: at least one processor (see [0008]); a communication interface communicatively coupled to the at least one processor (see [0008]); and memory storing computer-readable instructions that, when executed by the at least one processor (see [0009]), cause the computing platform to: train, using historical call information, an identity verification model, wherein training the identity verification model configures the identity verification model to identify, for an initiated call between a first individual and a second individual, one or more authentication questions to validate an identity of the first individual (reads on predictive model to map relationships among KBA question topics, subject characteristics, and a corresponding pass/fail rate of answers received from subjects for improving the efficacy of the KBA question. In certain example implementations, the decision tree may be used as predictive modeling approach for data mining, machine learning, and/or to determine statistics regarding the KBA question(s), see [0047-009]); input, into the identity verification model and while the first call is paused, information of one or more of: the first call, the first individual, or the second individual, wherein inputting the information causes the identity verification model to output the one or more authentication questions (Note that KBA question may be based on derived data from the retrieved information. For example, a public record source may be utilized to retrieve an address of the subject, and then geospatial data may be utilized to find business around the address to generate a KBA question, see [0044-0046] and [0021]); wherein outputting the one or more authentication questions comprises outputting a sequence of at least two authentication questions, wherein the at least two authentication questions are configured to be presented in the sequence and increase in specificity as the sequence progresses (reads on two question topics are used for the KBA question: pet name or favorite color; and for which only two characteristics about the subject are collected: gender and age. After the decision tree learning period is completed for data collected on a given population of subjects, the “pet name” and “favorite color” (topics) KBA questions may be analyzed for correlation with gender and age (subject characteristics) to determine a probability for passing. Table 6 summarizes the metrics for the pet name KBA question, and Table 7 summarizes the metrics for the favorite color KBA question, see Nygate [0032]), wherein the sequence comprises a first authentication question specific to an enterprise organization as a whole (reads on private data held by an organization and corporate-affiliation-related question topics, see [0039-0044] and [0101]), a second authentication question specific to an employee of the enterprise organization (reads on selecting a KBA question using characteristics of the particular subject and corporate-affiliation-related or personal-information-related topics, see [0029], [0032], [0036] and [0101-0102]), and authentication question specific to a prior interaction of the employee with a client (reads on the use of historical interaction data including prior communications or interactions between individuals and the enterprise, as a basis for authentication, see [0038]-[0039]); send, while the first call is paused and to a user device of the first individual, the one or more authentication questions and one or more commands directing the user device of the first individual to present the one or more authentication questions, wherein sending the one or more commands directing the user device of the first individual to present the one or more authentication questions causes the user device of the first individual to output the one or more authentication questions (reads on sending, for display on a first computing device associated with the subject, the at least one KBA identity proofing question, see [0099] and step 612 as shown in Fig. 6); receive, while the first call is paused and from the user device of the first individual, authentication information comprising responses to the one or more authentication questions (reads on receiving a response answer, step 614 as shown in Fig. 6 and [0099]); validate, while the first call is paused, the authentication information (reads on sending, for display on the first computing device associated with the subject, and responsive to a match between the response answer and the personally identifiable correct answer, a first indication of authentication in step 616 as shown in Fig. 6 and [0099]); and based on successful validation of the authentication information, cause the first call to resume (inherently taught after step 616 and once the authentication is performed). Nygate features already addressed in the rejection of claims 1, 17 and 20. Nygate does not specifically teach “detect a first call between the first individual and the second individual, wherein the first individual comprises one of: an employee of an enterprise or an impersonator of the employee of the enterprise” as recited in claims 1, 17 and 20. However, Algard teaches verification generation module 218 generates verification messages including at least some of the supplemental information received in verification request messages and, optionally, enhanced information produced by the enhancement module 216. A verification message indicates that an associated communication placed via the telephone network 105 is verified as from a legitimate calling party 110. A verification message may also include additional information about the communication, such as information describing the purpose of the communication, an image associated with the calling party 110, and/or a sponsored message from the calling party 110. For example, a verification message may include the text string “Verified call from Bank ABC,” indicating that a telephone call from a particular calling party 110 (“Bank ABC”) is legitimately from the identified calling party 110 (see [0034, 0041 and 0021]). Nygate also does not specifically teach “temporarily pause the first call” as recited in claims 1, 17 and 20. However, Halferty teaches controlling real-time participation in a teleconference call, for example, at a step 416, a pause command is received, which indicates a desire to suspend real-time participation in a teleconference call and which begins a pause process. As previously mentioned, an embodiment of our technology allows a user to pause a live teleconference call. When the pause process is instantiated, such as by selecting button 336, then recording the current conversation continues but the user by way of device 300 is no longer engaged in real-time participation. For example, at a step 416a, communications device 300 continues to record the real-time inbound audio but prevents it from being presented via the speaker 310 of communications device 300 until a resume request is received. In this way, real-time outbound audio is prevented from being communicated to the other call participants at a step 416b. The pause process includes an ability to resume the call at will. Thus, at a step 416C, application 314 enables a resume option that allows the user of device 300 to rejoin the call. This can be activated by receiving the resume request, which, when received re-enables communication of real-time inbound and real-time outbound audio (see col. 5 line 9 through col. 6, line 5 and Fig. 4). And further Nygate does not specifically teach presenting the recited question types in the claimed sequence such that the questions increase in specificity as the sequence progresses, as recited in claims 1, 17 and 20. However, Jung teaches preparing categories of authentication questions based on user-centric authentication preferences and prioritizing the categories before or during an authentication session (see [0046]-[0047]). Jung further teaches preparing authentication-question categories according to organization-dependent criteria, including industry-specific and job-related questions known to a person familiar with the particular business ([0048]). Jung also teaches generating questions for a future authentication session based on questions presented during a current or prior authentication session, selecting questions by weighting authentication-question categories, requiring multiple categories for authentication questioning, and setting the number of categories or questions according to a predetermined security requirement (see [0050]-[0054]). Thus, it would have been obvious to one of ordinary skill in the art to modify the authentication system of Nygate, as combined with Algard’s out-of-band transmission of verification information to the called user’s device and Halferty pausing of the live call during the verification process, to organize and present the authentication-question categories, including organization-dependent and job-related categories and information from a prior authentication session to permit called user to complete authentication on the user device while the call remains paused and to progressively narrow the authentication injury from broader enterprise information to more individualized employee and prior-interaction information. Such an arrangement would predictably increase authentication confidence before the call is resumed and reduce the likelihood that an unauthorized caller obtains access to protected information. The combination merely applies Jung’s known question-prioritization technique to the combined call-verification system of Nygate, Algard and Halferty for its established purpose of improving authentication security. Regarding claim 2, the combination of Nygate, Algard, Halferty and Jung teaches wherein the historical call information comprises one or more of: employee information corresponding to the first individual, enterprise information corresponding to the enterprise, customer information corresponding to the second individual, account information corresponding to the second individual (see Nygate [0039]) and details of historical calls between the second individual and the enterprise (see Nygate [0039]). Regarding claim 3, the combination of Nygate, Algard, Halferty and Jung teaches wherein the details of the historical calls between the second individual and the enterprise comprise transcripts of the historical calls (see Halferty, col. 3, lines 32-36). Regarding claim 4, the combination of Nygate, Algard, Halferty and Jung teaches wherein the one or more authentication questions further comprise one or more personalized questions for the first individual (see Nygate [0021 and 0090]). Regarding claim 5, the combination of Nygate, Algard, Halferty and Jung teaches wherein the one or more authentication questions prompt the first individual to verify one or more of: employee information corresponding to the first individual, enterprise information corresponding to the enterprise, customer information corresponding to the second individual, account information corresponding to the second individual (see Nygate [0039]) and details of historical calls between the second individual and the enterprise (see Nygate [0039]). Regarding claim 7, the combination of Nygate, Algard, Halferty and Jung teaches wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, further cause the computing platform to: send, to a user device of the second individual and prior to sending the one or more authentication questions to the user device of the first individual, the one or more authentication questions and a request to confirm the one or more authentication questions (see Nygate [0072]). Regarding claim 8, the combination of Nygate, Algard, Halferty and Jung teaches wherein the request to confirm the one or more authentication questions comprises a request to confirm one or more of: the one or more authentication questions are accurate measures for validating an identity of the first individual (reads on social security number (SSN) can be checked to determine if it is valid or not see Nygate [0095-0096]), and responses to the one or more authentication questions that may be used to validate the authentication information (reads on question/answer pairs may be stored by the host and used later to verify the person's identity, see [0037]). Regarding claim 9, the combination of Nygate, Algard, Halferty and Jung teaches wherein the first call is initiated by one of: the first individual or the second individual (see vendor and/or client in Fig. 3 and Fig. 4 with corresponding texts in Nygate). Regarding claim 10, the combination of Nygate, Algard, Halferty and Jung teaches wherein presenting the one or more authentication questions comprises: causing the one or more authentication questions to be presented, at the user device of the first individual, as an audio output (the verification presentation module 316 may also present the result of the verification using other techniques, such as by presenting an image, an audio cue (e.g., a ringtone) , see Algard [0043]). Regarding claim 11, the combination of Nygate, Algard, Halferty and Jung teaches wherein receiving the authentication information comprises receiving: a user input via a graphical user interface of the user device of the first individual, wherein the user input comprises: a selection of a user interface element corresponding to the authentication information (see Nygate [0073] and [0078]), a natural language input in a text input field (see Nygate [0073]), and a voice input corresponding to the authentication information (see Nygate [0073]). Regarding claim 12, the combination of Nygate, Algard, Halferty and Jung teaches wherein validating the authentication information comprises comparing the authentication information to known valid responses to the authentication questions (see Nygate [0095-0096]). Regarding claim 13, the combination of Nygate, Algard, Halferty and Jung teaches wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, further cause the computing platform to: based on failing to successfully validate the authentication information: identify that the first individual is an impersonator, terminate the first call, and initiate a plurality of security actions (reads on the subject 302 may be presented with other options or instructions to validate his or her identity, see Nygate [0059]). Regarding claim 14, the combination of Nygate, Algard, Halferty and Jung teaches wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, further cause the computing platform to: update, using a dynamic feedback loop and based on the one or more authentication questions (reads on refining the predictive model based on the match or a mismatch between the response answer and the personally identifiable correct answer. Certain example implementations may include refining the predictive model based on a history of matches between the response answer and the personally identifiable correct answer to produce KBA identity proofing questions that increase the probability of a match. In certain example implementations, refining the predictive model can include applying decision tree learning, see [100]), the authentication information, the information of the first individual, the information of the second individual, and the information of the first call (reads on predictive model to map relationships among KBA question topics, subject characteristics, and a corresponding pass/fail rate of answers received from subjects for improving the efficacy of the KBA question. In certain example implementations, the decision tree may be used as predictive modeling approach for data mining, machine learning, and/or to determine statistics regarding the KBA question(s), see Nygate [0047-009]), the identity verification model reads on predictive model to map relationships among KBA question topics, subject characteristics, and a corresponding pass/fail rate of answers received from subjects for improving the efficacy of the KBA question. In certain example implementations, the decision tree may be used as predictive modeling approach for data mining, machine learning, and/or to determine statistics regarding the KBA question(s), see Nygate [0047-009]. Regarding claim 15, the combination of Nygate, Algard, Halferty and Jung teaches wherein updating the identity verification model causes the identity verification model to perform one or more of: adding new authentication questions or removing the one or more authentication questions based on receiving consensus information from a plurality of individuals indicating that the one or more authentication questions resulted in one of: a false positive validation or a false negative validation (see Nygate [0037]). Regarding claim 22, the combination of Nygate, Algard, Halferty and Jung teaches wherein the one or more authentication questions comprise at least one decoy authentication question prompting for information that does not exist for the first individual (Nygate already teaches detecting and suppressing KBA questions that may be readily guessed, reducing false-positive authentication results, and generating dynamic KBA questions from public or private records (see [0037-0044]). Thus, it would have been obvious to include a decoy authentication question directed to information that does not exist for the first individual because an attempted answer to nonexistent information would expose guessing and further reduce false-positive authentication). Regarding claim 23, the combination of Nygate, Algard, Halferty and Jung teaches wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, further cause the computing platform to: filter out, from the one or more authentication questions, authentication questions corresponding to information revealed in social media information associated with the first individual (reads on Nygate teaching the detection and suppression of KBA questions having answers that may easily researched and states that when the subject has shared the information on social media site, the correct answer may be easily researched, see [0037]). Regarding claim 24, the combination of Nygate, Algard, Halferty and Jung teaches wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, further cause the computing platform to: based on an incorrect response to a given authentication question, select a security action based on a level of difficulty of the given authentication question, wherein a more intensive security action is selected when the given authentication question has a lower level of difficulty (note that Nygate teaches evaluation KBA questions using pass-rate metrics and ranking or selecting questions according to the likelihood that a genuine user will answer correctly (see [0029-0036]), and generating risk scores or warning codes and communicating authentication failure when submitted information does not match (see [0095] and [0104]). Thus, it would have been obvious to select a more intensive security action following an incorrect response to a lower-difficulty question because failure to answer an easier question provides stronger evidence of attempted fraud). Regarding claim 25, the combination of Nygate, Algard, Halferty and Jung teaches wherein validating the authentication information comprises: based on identifying that authentication information for a particular authentication question is incorrect, determining, based on a specificity level of the particular authentication question and a degree to which the authentication information is incorrect, whether to re-present the particular authentication question, present a subsequent authentication question, or initiate one or more security actions (Nygate teaches selecting questions based on subject characteristics and question topics, comparing a response with a personally identifiable correct answer, generating risk or wanning information, and refining the authentication model based on matches and mismatches (see [0029], [0035-0044], [0095], [0099-0104]). Jung further teaches weighting and prioritizing authentication-question categories, requiring multiple categories or questions, and applying security thresholds and alerts (see [0051]-[0054]). Thus, it would have been obvious to use the specificity of the question and the degree of mismatch to determine whether to re-present the question, or initiate a security action, thereby providing a graduated response proportionate to the authentication confidence. Conclusion 4. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Rasha S. AL-Aubaidi whose telephone number is (571) 272-7481. The examiner can normally be reached on Monday-Friday from 8:30 am to 5:30 pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Ahmad Matar, can be reached on (571) 272-7488. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /RASHA S AL AUBAIDI/Primary Examiner, Art Unit 2693
Read full office action

Prosecution Timeline

Sep 14, 2023
Application Filed
Aug 27, 2025
Non-Final Rejection mailed — §103
Nov 25, 2025
Response Filed
Mar 19, 2026
Final Rejection mailed — §103
May 19, 2026
Response after Non-Final Action
Jun 22, 2026
Request for Continued Examination
Jun 25, 2026
Response after Non-Final Action
Jul 15, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750629
VIRTUAL AUDIO AUGMENTATION USING COMPUTER VISION
2y 11m to grant Granted Sep 29, 2026
Patent 12744849
POLICY-ENABLED CALL HUNTING
3y 1m to grant Granted Sep 22, 2026
Patent 12744026
ON-VEHICLE SOUND CONTROL SYSTEM
2y 0m to grant Granted Sep 22, 2026
Patent 12700075
IMAGE QUALITY EVALUATION METHOD AND APPARATUS, DEVICE AND STORAGE MEDIUM
2y 2m to grant Granted Aug 04, 2026
Patent 12701190
REAL-TIME AUDIO AND VIDEO FEEDBACK DURING CONFERENCE CALLS
1y 11m to grant Granted Aug 04, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
78%
Grant Probability
89%
With Interview (+11.4%)
3y 4m (~3m remaining)
Median Time to Grant
High
PTA Risk
Based on 766 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month