Prosecution Insights
Last updated: October 04, 2026
Application No. 18/504,298

Electronic Device for Performing User Authentication by Using User Biometric Information and Operation Method Thereof

Non-Final OA §103
Filed
Nov 08, 2023
Priority
Nov 01, 2019 — RE 10-2019-0138728 +2 more
Examiner
CELANI, NICHOLAS P
Art Unit
2449
Tech Center
2400 — Computer Networks
Assignee
Ghost Pass Inc.
OA Round
5 (Non-Final)
46%
Grant Probability
Moderate
5-6
OA Rounds
3m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 46% of resolved cases
46%
Career Allowance Rate
214 granted / 467 resolved
-12.2% vs TC avg
Strong +42% interview lift
Without
With
+42.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
36 currently pending
Career history
506
Total Applications
across all art units

Statute-Specific Performance

§101
15.7%
-24.3% vs TC avg
§103
51.5%
+11.5% vs TC avg
§102
3.1%
-36.9% vs TC avg
§112
25.2%
-14.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 467 resolved cases

Office Action

§103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims The following claim(s) is/are pending in this office action: 1-20 The following claim(s) is/are amended: 1, 12, 17 The following claim(s) is/are cancelled: - The following claim(s) is/are new: - Claim(s) 1-20 is/are rejected. Response to Arguments Applicant’s arguments filed in the amendment filed 6/22/2026, have been fully considered but are moot in view of new grounds of rejection. The reasons set forth below. Applicant’s Invention as Claimed Claim Rejections - 35 USC § 103 A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Lee (US Pub. 2022/0058256) in view of Baltatu (US Pub. 2008/0019573) and further in view of Connell (US Pub. 2017/0324736). With respect to Claim 1, Lee teaches a user authentication device comprising: a wireless communication circuit; (Claim 1; a wireless communication circuit) one or more processors electrically coupled to the wireless communication circuit; (Claim 1; one or more processors electrically coupled to the wireless communication circuit) and a memory electrically connected to the one or more processors, (Claim 1; and a memory electrically connected to the one or more processors) wherein the memory includes one sub-biometric information from among a plurality of sub-biometric information on a user and information on a user authentication request device, (Sub-biometric information will be taught later. Claim 1; wherein the memory includes first biometric information on a user and information on a user authentication request device) and determine whether the first data and the first biometric information match, (Claim 1; the one or more processors confirms whether first data received from the user authentication request device by using the wireless communication circuit matches with the first biometric information,) the wireless communication circuit transmits authentication result data about whether the first data matches with the first biometric information to the user authentication request device, and (Claim 1; and the wireless communication circuit transmits authentication result data for whether the first data matches with the first biometric information to the user authentication request device) wherein the first data is transmitted to the server from the user authentication request device, (Examiner notes that this feature is not limiting on the claims because the claims are for a user authentication device and the limitation refers to actions taken by two other devices not the subject of the claimed article. Regardless, Lee teaches, see paras. 100-103; server receives sensed data from the user authentication request device.) and identification information of user for each of devices that store sub-biometric information corresponding to the first data is transmitted to the user authentication request device from the server. (Examiner notes that this feature is not limiting on the claims because the claims are for a user authentication device and the limitation refers to actions taken by two other devices not the subject of the claimed article. Regardless, see Lee, paras. 104-106; Server retrieves the id of the user authentication device using the sensed data. Server transmits the identification information to the user authentication request device. See also Baltatu, Abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards.) But Lee does not explicitly teach sub-biometric information. Baltatu, however, does teach wherein the memory includes one sub-biometric information from among a plurality of sub-biometric information on a user (Examiner asserts that the sub-biometric information is obvious over the biometric information because it is just split biometric information. Making separable is obvious, see MPEP 2144.04, and it would have been obvious to one of ordinary skill prior to the effective filing date to separate and separately store the biometric information in order to improve security. Regardless, Examiner will cite Baltatu to teach. Baltatu, abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards.) and the plurality of sub-biometric information includes at least a portion of first biometric information on the user, (Abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards.) the one or more processors are configured to generate the first biometric information on the user through mutual information exchange with another user authentication device or a server which stores sub-biometric information excluding the one sub-biometric information, in response to receiving first data from the user authentication request device using the wireless communication circuit, (paras. 62-69; when user seeks a verification, a first device transfers its portion of the user’s biometric template to another device. That device puts the portions together to reforge the template and uses the template to perform the authentication. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template.) the first biometric information is divided into a plurality of sub-biometric information prior to receiving the first data and wherein the plurality of sub-biometric information is distributed (Abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template.) based on a number of user authentication devices of a user authentication system including the user authentication device (paras. 84, 91; biometric information can be split into an arbitrary number of devices. para. 55; host computer stores a portion. Para. 56; storage can be in a cell phone memory or in any personal processing device. Paras. 7-9, 84; system improves security by splitting the template to multiple devices. Therefore, it would have been obvious to one of ordinary skill prior to the effective filing date to base the division on the number of available devices in order to improve security by requiring the tampering of additional devices to defeat security.) each sub-biometric information of the plurality of sub-biometric information is stored in a memory of a respective user authentication device of the user authentication devices or a memory the server, and (Abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template.) the user authentication system includes the user authentication device of the user and the another user authentication device of another user (Ownership by another user will be taught later. paras. 67-71; authentication by comparing sample with template. paras. 84, 91; biometric information can be split into an arbitrary number of devices. paras. 9, 84; portions of the template must be recomposed to create the original template for authentication. Para. 56; storage can be in a cell phone memory or in any personal processing device. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template. To the extent that this suggests storage on at least one personal device of the individual who provided the first biometric information, it would have been obvious to one of ordinary skill prior to the effective filing date to store within the user’s personal device to prevent the recreation of the template without the user’s consent.) and the first data is transmitted to external devices that store at least one sub-biometric information specified based on the identification information of the user. (First see Lee, Claim 9; transmission based on ID information. Fig. 3, para. 82; system sends sensed data to the device that stores the biometric information so device can get the biometric information and perform authentication. Then see Baltatu, paras. 84, 91; biometric information can be split into an arbitrary number of devices. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template. Para. 62-67; during verification, devices send both the live template and their portion of a reference template to a device and the device recomposes the reference template and compares the reference template to the live template. Therefore, it would have been obvious to one of ordinary skill prior to the effective filing date to transmit the first data to the devices that store the sub-biometric information so that they know which particular template of their stored templates to all for recomposing the template.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the user authentication device of Lee and the sub-biometric information in order to enhance user security and privacy. (Baltatu, paras. 12, 79) But modified Lee does not explicitly teach and the another user authentication device of another user. Connell, however, does teach and the another user authentication device of another user, at least one sub-biometric information among the plurality of sub-biometric information is stored in the another user authentication device of the another user, (First see Lee, para. 13; user information includes user id, which suggests multiple users use the system. Examiner notes Baltatu previously taught sub-biometric storage in multiple devices. But see also Connell Figs. 4-5, paras. 48-52; Users can use authentication coordinator to register their smart devices such as smartphones to the system. A user’s biometric template can be stored in full or part in a plurality of devices. para. 54; template storage devices include any devices included on a network with storage and processing capabilities. para. 57; a template storage device can contain multiple templates corresponding to multiple users. To the extent that para. 57 does not teach storage in another user authentication device of another user, see para. 48; networked devices can be any devices connected through a cloud computing network. Fig. 1, paras. 32, 26-30; cloud computing environment can be one or more networks such as private, public or hybrid clouds, or a combination thereof. Private clouds may be owned by an organization or a third party. Public clouds are owned by an organization selling cloud services. Hybrid clouds may be a combination of two or more private or public clouds. Therefore, the system contemplates a network of devices with a plurality of owners, any of which can be networked devices which store biometric templates.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the user authentication device of modified Lee and the storage in another user authentication device of another user in order to safeguard biometric data by making it difficult to match a biometric template on an external device with its source. (Connell, para. 48) With respect to Claim 2, modified Lee teaches the user authentication device of claim 1, and Lee also teaches wherein the first data may be set to be deleted in response to being transmitted from the user authentication request device to the user authentication device. (para. 45; In addition, the first data may be set to be deleted in response to being transmitted from the user authentication request device to the user authentication device.) With respect to Claim 3, modified Lee teaches the user authentication device of claim 1, and Lee also teaches wherein the first biometric information includes at least one of fingerprint information, DNA information, body skeleton information, hand shape information, retina information, iris information, face information, vein information, electrocardiogram information, handwriting information, gait information, signature information, blood vessel information, sweat gland structure information, voice information, and biomolecular information. (Claim 2; wherein the first biometric information includes at least one of fingerprint information, DNA information, body skeleton information, hand shape information, retina information, iris information, face information, vein information, electrocardiogram information, handwriting information, gait information, signature information, blood vessel information, sweat gland structure information, voice information, and biomolecular information.) With respect to Claim 4, modified Lee teaches the user authentication device of claim 1, and Baltatu also teaches wherein the one or more processors are further configured to: collect sub-biometric information excluding the one sub-biometric information from among the plurality of sub-biometric information, in response to receiving the first data from the user authentication request device using the wireless communication circuit, and generate the first biometric information by combining the one sub-biometric information stored in the memory and the collected sub-biometric information. (paras. 62-69; when user seeks a verification, a first device transfers its portion of the user’s biometric template to another device. That device puts the portions together to reforge the template and uses the template to perform the authentication.) The same motivation to combine as Claim 1 applies here. With respect to Claim 5, modified Lee teaches the user authentication device of claim 1, and Baltatu also teaches wherein the one or more processors are further configured to: collect some sub-biometric information excluding the one sub-biometric information from among the plurality of sub-biometric information, in response to receiving the first data from the user authentication request device using the wireless communication circuit, and generate the first biometric information by combining the one sub-biometric information stored in the memory and the collected some sub-biometric information. (paras. 62-69; when user seeks a verification, a first device transfers its portion of the user’s biometric template to another device. That device puts the portions together to reforge the template and uses the template to perform the authentication. Para. 90; template can be split into more than two portions.) The same motivation to combine as Claim 1 applies here. With respect to Claim 6, modified Lee teaches the user authentication device of claim 1, and Lee also teaches further comprising: an input/output device, wherein the input/output device receives a first ultrasonic signal, and the one or more processors output a second ultrasonic signal by using the input/output device in response to the first ultrasonic signal being received. (Claim 3; an input/output device, wherein the input/output device receives a first ultrasonic signal, and the one or more processors outputs a second ultrasonic signal by using the input/output device in response to the first ultrasonic signal being received.) With respect to Claim 7, modified Lee teaches the user authentication device of claim 6, and Lee also teaches wherein the first ultrasonic signal is included in the information of the user authentication request device and the second ultrasonic signal includes identification information of the user authentication device. (Claim 4; wherein the first ultrasonic signal is included in the information of the user authentication request device and the second ultrasonic signal includes identification information of the user authentication device.) With respect to Claim 8, modified Lee teaches the user authentication device of claim 1, and Lee also teaches wherein the user authentication device includes a camera module or a sensor module, the one or more processors acquire the first biometric information based on data obtained by sensing a body of the user by using the camera module or the sensor module, and the memory stores the first biometric information in a security area. (Claim 5; wherein the user authentication device includes a camera module or a sensor module, the one or more processors acquires the first biometric information based on data obtained by sensing a body of the user by using the camera module or the sensor module, and the memory stores the first biometric information in a security area.) With respect to Claim 9, modified Lee teaches the user authentication device of claim 1, and Lee also teaches further comprising: an input/output device, wherein the one or more processors install an application related to the user authentication request device by a selection of the user, the one or more processors store the information on the user authentication request device by using the application in the memory, the one or more processors use the input/output device to acquire data about one or more pieces of information requested from the user authentication request device by using the application, and the wireless communication circuit transmits the acquired one or more pieces of information to the user authentication request device. (Claim 6; an input/output device, wherein the one or more processors installs an application related to the user authentication request device by a selection of the user, the one or more processors stores the information on the user authentication request device by using the application in the memory, the one or more processors uses the input/output device to acquire data about one or more pieces of information requested from the user authentication request device by using the application, and the wireless communication circuit transmits the acquired one or more pieces of information to the user authentication request device.) With respect to Claim 10, modified Lee teaches the user authentication device of claim 9, and Lee also teaches wherein the information on the user authentication request device includes at least one of a type of a service related to the user authentication request device, specific contents of the service related to the user authentication request device, a position of the user authentication request device, a type of the user authentication request device, and sensor information included in the user authentication request device. (Claim 7; wherein the information on the user authentication request device includes at least one of a type of a service related to the user authentication request device, specific contents of the service related to the user authentication request device, a position of the user authentication request device, a type of the user authentication request device, and sensor information included in the user authentication request device.) With respect to Claim 11, modified Lee teaches the user authentication device of claim 9, and Lee also teaches wherein the information on the user includes at least one of an ID, a password, a name, a gender, a mobile phone number, an addresses, an email address, an identification number related to a service provided by the user authentication request device, a type of the service to be used, and specific contents of the service. (Claim 8; wherein the information on the user includes at least one of an ID, a password, a name, a gender, a mobile phone number, an addresses, an email address, an identification number related to a service provided by the user authentication request device, a type of the service to be used, and specific contents of the service.) With respect to Claim 12, Lee teaches a user authentication request device comprising: an input/output device; (Claim 9; request device comprising an I/O device) a sensor module; (Claim 9; sensor module) a camera module; Claim 9; camera module) a wireless communication circuit; (Claim 9; wireless communication circuit) and one or more processors electrically connected to the input/output device, the sensor module, the camera module, and the wireless communication circuit, (Claim 9; processor) wherein the one or more processors acquire raw data obtained by sensing a body of a user by using the sensor module or the camera module, (Claim 9; processor acquires raw data by sensing a body) transmits the raw data to a server, and obtain, from the server, identification of a user for each of devices that store sub-biometric information corresponding to the raw data (paras. 100-103; server receives sensed data from the user authentication request device. paras. 104-106; Server retrieves the id of the user authentication device using the sensed data. Server transmits the identification information to the user authentication request device. See also Baltatu, Abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards.) and the one or more processors execute a function determined based on authentication data received from the user authentication device of a first user by using the wireless communication circuit (Claim 9; function based on authentication) and the authentication data is generated by matching the raw data and the first biometric information stored in the user authentication device of the first user, (Claim 1; the one or more processors confirms whether first data received from the user authentication request device by using the wireless communication circuit matches with the first biometric information. Para. 37; execute user authentication by comparing biometric information stored in the user authentication device) But Lee does not explicitly teach sub-biometric information. Baltatu, however, does teach the wireless communication circuit transmits the raw data to external devices that store at least one sub-biometric information specified based on the identification information on a user for each of devices that store sub-biometric information, (First see Lee, Claim 9; transmission based on ID information. Fig. 3, para. 82; system sends sensed data to the device that stores the biometric information so device can get the biometric information and perform authentication. Then see Baltatu, paras. 84, 91; biometric information can be split into an arbitrary number of devices. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template. Para. 62-67; during verification, devices send both the live template and their portion of a reference template to a device and the device recomposes the reference template and compares the reference template to the live template. Therefore, it would have been obvious to one of ordinary skill prior to the effective filing date to transmit the first data to the devices that store the sub-biometric information so that they know which particular template of their stored templates to all for recomposing the template.) the first biometric information is divided into a plurality of sub-biometric information before transmitting the raw data (Examiner asserts that the sub-biometric information is obvious over the biometric information because it is just split biometric information. Making separable is obvious, see MPEP 2144.04, and it would have been obvious to one of ordinary skill prior to the effective filing date to separate and separately store the biometric information in order to improve security. Regardless, Examiner will cite Baltatu to teach. Baltatu, abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template.) and distributed based on a number of user authentication devices of a user authentication system including the user authentication device, (paras. 84, 91; biometric information can be split into an arbitrary number of devices. para. 55; host computer stores a portion. Para. 56; storage can be in a cell phone memory or in any personal processing device. Paras. 7-9, 84; system improves security by splitting the template to multiple devices. Therefore, it would have been obvious to one of ordinary skill prior to the effective filing date to base the division on the number of available devices in order to improve security by requiring the tampering of additional devices to defeat security.) each of the plurality of sub-biometric information is stored in memory of user authentication device of the user authentication system or the server, and (Abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards. paras. 62-69; when user seeks a verification, a first device transfers its portion of the user’s biometric template to another device. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template.) the user authentication system includes the user authentication device of the user and another user authentication device of another user (Ownership by another user will be taught later. paras. 67-71; authentication by comparing sample with template. paras. 84, 91; biometric information can be split into an arbitrary number of devices. paras. 9, 84; portions of the template must be recomposed to create the original template for authentication. Para. 56; storage can be in a cell phone memory or in any personal processing device. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template. To the extent that this suggests storage on at least one personal device of the individual who provided the first biometric information, it would have been obvious to one of ordinary skill prior to the effective filing date to store within the user’s personal device to prevent the recreation of the template without the user’s consent.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the user authentication request device of Lee and the sub-biometric information in order to enhance user security and privacy. (Baltatu, paras. 12, 79) But modified Lee does not explicitly teach and another user authentication device of another user. Connell, however, does teach and another user authentication device of another user, at least one sub-biometric information among the plurality of sub-biometric information is stored in the another user authentication device of the another user, (First see Lee, para. 13; user information includes user id, which suggests multiple users use the system. Examiner notes Baltatu previously taught sub-biometric storage in multiple devices. But see also Connell Figs. 4-5, paras. 48-52; Users can use authentication coordinator to register their smart devices such as smartphones to the system. A user’s biometric template can be stored in full or part in a plurality of devices. para. 54; template storage devices include any devices included on a network with storage and processing capabilities. para. 57; a template storage device can contain multiple templates corresponding to multiple users. To the extent that para. 57 does not teach storage in another user authentication device of another user, see para. 48; networked devices can be any devices connected through a cloud computing network. Fig. 1, paras. 32, 26-30; cloud computing environment can be one or more networks such as private, public or hybrid clouds, or a combination thereof. Private clouds may be owned by an organization or a third party. Public clouds are owned by an organization selling cloud services. Hybrid clouds may be a combination of two or more private or public clouds. Therefore, the system contemplates a network of devices with a plurality of owners, any of which can be networked devices which store biometric templates.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the user authentication request device of modified Lee and the storage in another user authentication device of another user in order to safeguard biometric data by making it difficult to match a biometric template on an external device with its source. (Connell, para. 48) With respect to Claim 13, modified Lee teaches the user authentication request device of claim 12, and Lee also teaches further comprising: a memory electrically connected to the one or more processors, wherein the memory includes information on the user received from the user authentication device of the first user. (Claim 10) With respect to Claim 14, modified Lee teaches the user authentication request device of claim 13, and Lee also teaches wherein the memory does not store the raw data. (Claim 11) With respect to Claim 15, modified Lee teaches the user authentication request device of claim 12, and Lee also teaches wherein the input/output device outputs a first ultrasonic signal and receives a second ultrasonic signal in response to an output of the first ultrasonic signal, and the one or more processors acquire an identification number of the user authentication device of the first user based on the second ultrasonic signal. (Claim 12) With respect to Claim 16, modified Lee teaches the user authentication request device of claim 12, and Lee also teaches wherein the input/output device includes a touch screen, the one or more processors display information request for the user authentication device of the first user by using the touch screen and acquires a selection of the user in response to the displayed information, and the one or more processors acquire an identification number for the user authentication device of the first user based on the acquired user selection data. (Claim 13) With respect to Claim 17, Lee teaches a server comprising: a wireless communication circuit; (Claim 14; server with wireless communication circuit) one or more processors electrically connected to the wireless communication circuit; (Claim 14; processor) and a memory electrically connected to the one or more processors, (Claim 14; processor) wherein the wireless communication circuit receives double-encrypted first data from a first electronic device, (Claim 14; double encrypted data) the one or more processors store first result data to which a first decryption method that is predetermined for the first data is applied in the memory, (Claim 14; first decryption) the first result data includes identification information on the first electronic device, (Claim 14; identification information) the wireless communication circuit receives second data from a second electronic device, (Claim 14; receipt of second data) the one or more processors retrieve second result data to which a second encryption method that is predetermined for the second data is applied in the memory, (Claim 14; retrieval of second data) and the wireless communication circuit transmits identification information of a user for each of devices that store sub-biometric information corresponding to raw data according to the retrieving result to the second electronic device. (Claim 14; transfer of ID information. paras. 100-103; server receives sensed data from the user authentication request device. paras. 104-106; Server retrieves the id of the user authentication device using the sensed data. Server transmits the identification information to the user authentication request device. See also Baltatu, Abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards.) But Lee does not explicitly teach sub-biometric information. Baltatu, however, does teach the memory stores one sub-biometric information of biometric information of user of the first electronic device; (Examiner asserts that the sub-biometric information is obvious over the biometric information because it is just split biometric information. Making separable is obvious, see MPEP 2144.04, and it would have been obvious to one of ordinary skill prior to the effective filing date to separate and separately store the biometric information in order to improve security. Regardless, Examiner will cite Baltatu to teach. Baltatu, abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template.) the one sub-biometric information is divided from the biometric information based on a number of user authentication devices of a user authentication system including the user authentication device, (paras. 84, 91; biometric information can be split into an arbitrary number of devices. para. 55; host computer stores a portion. Para. 56; storage can be in a cell phone memory or in any personal processing device. Paras. 7-9, 84; system improves security by splitting the template to multiple devices. Therefore, it would have been obvious to one of ordinary skill prior to the effective filing date to base the division on the number of available devices in order to improve security by requiring the tampering of additional devices to defeat security.) sub-biometric information divided from the biometric information excluding the one sub-biometric information is stored in memory of user authentication device of the user authentication system, (Abstract, paras. 14-18, 52-59; during enrollment system splits the biometric information of a user into multiple parts and stores them in different memories such as client devices, databases, or memory cards. paras. 62-69; when user seeks a verification, a first device transfers its portion of the user’s biometric template to another device. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template.) the user authentication system includes the first electronic device and a user authentication device of another user (Ownership by another user will be taught later. paras. 67-71; authentication by comparing sample with template. paras. 84, 91; biometric information can be split into an arbitrary number of devices. paras. 9, 84; portions of the template must be recomposed to create the original template for authentication. Para. 56; storage can be in a cell phone memory or in any personal processing device. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template. To the extent that this suggests storage on at least one personal device of the individual who provided the first biometric information, it would have been obvious to one of ordinary skill prior to the effective filing date to store within the user’s personal device to prevent the recreation of the template without the user’s consent.) and the second data is transmitted to all electronic devices that store at least one sub-biometric information specified based on the identification information. (First see Lee, Claim 9; transmission based on ID information. Fig. 3, para. 82; system sends sensed data to the device that stores the biometric information so device can get the biometric information and perform authentication. Then see Baltatu, paras. 84, 91; biometric information can be split into an arbitrary number of devices. Paras. 87, 90; client-server scenario in which client and server both store a portion of the template. Para. 62-67; during verification, devices send both the live template and their portion of a reference template to a device and the device recomposes the reference template and compares the reference template to the live template. Therefore, it would have been obvious to one of ordinary skill prior to the effective filing date to transmit the first data to the devices that store the sub-biometric information so that they know which particular template of their stored templates to all for recomposing the template.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the server of Lee and the sub-biometric information in order to enhance user security and privacy. (Baltatu, paras. 12, 79) But modified Lee does not explicitly teach and a user authentication device of another user. Connell, however, does teach and a user authentication device of another user, and at least one sub-biometric information among the plurality of sub-biometric information is stored in the user authentication device of the another user. (First see Lee, para. 13; user information includes user id, which suggests multiple users use the system. Examiner notes Baltatu previously taught sub-biometric storage in multiple devices. But see also Connell Figs. 4-5, paras. 48-52; Users can use authentication coordinator to register their smart devices such as smartphones to the system. A user’s biometric template can be stored in full or part in a plurality of devices. para. 54; template storage devices include any devices included on a network with storage and processing capabilities. para. 57; a template storage device can contain multiple templates corresponding to multiple users. To the extent that para. 57 does not teach storage in another user authentication device of another user, see para. 48; networked devices can be any devices connected through a cloud computing network. Fig. 1, paras. 32, 26-30; cloud computing environment can be one or more networks such as private, public or hybrid clouds, or a combination thereof. Private clouds may be owned by an organization or a third party. Public clouds are owned by an organization selling cloud services. Hybrid clouds may be a combination of two or more private or public clouds. Therefore, the system contemplates a network of devices with a plurality of owners, any of which can be networked devices which store biometric templates.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the server of modified Lee and the storage in a user authentication device of another user in order to safeguard biometric data by making it difficult to match a biometric template on an external device with its source. (Connell, para. 48) With respect to Claim 18, modified Lee teaches the server of claim 17, and Lee also teaches wherein the first result data includes encrypted user biometric information of the first electronic device, and does not include key data for decrypting the encrypted user biometric information of the first electronic device. (Claim 15) With respect to Claim 19, modified Lee teaches the server of claim 17, and Lee also teaches wherein the one or more processors transmit user authentication completion data to the second electronic device in response to the second result data being retrieved in the memory to the second electronic device. (Claim 16) With respect to Claim 20, modified Lee teaches the server of claim 17, and Lee also teaches wherein the one or more processors transmit the second data to the first electronic device in response to the second result data being retrieved in the memory. (Claim 17) Alternate Grounds Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Lee (US Pub. 2022/0058256) in view of Baltatu (US Pub. 2008/0019573). With respect to Claim 1, Lee and Baltatu teach as above but under this ground of rejection are also sufficient to render obvious without Connell. Lee also teaches the user authentication system includes the user authentication device of the user and the another user authentication device of another user, (para. 13; user information includes user id, which suggests multiple users use the system.) and Baltatu also teaches at least one sub-biometric information among the plurality of sub-biometric information is stored in the another user authentication device of the another user. (First see Lee, Fig. 2, paras. 65-66; user authentication device stores biometric information. Then see Baltatu, paras. 67-71; authentication by comparing sample with template. paras. 84, 91; biometric information can be split into an arbitrary number of devices. paras. 9, 84; portions of the template must be recomposed to create the original template for authentication. Para. 56; storage can be in a cell phone memory or in any personal processing device. Ownership of the device is not a structural limitation, and a recitation with respect to the manner in which a claimed apparatus is intended to be employed does not differentiate the claimed apparatus from a prior art apparatus if the prior art apparatus teaches all the structural limitations of the claim, see MPEP 2114. Lee/Baltatu render obvious storage of sub-biometric information in a plurality of user authentication devices, and the limitation that one of the devices must be owned by another does not distinguish a structure claim.) The same citation would apply, mutatis mutandis, to all other claims. Remarks Applicant makes minor amendments to Claim 1 and relevantly adds the limitation “the user authentication system includes the user authentication device of the user and the another user authentication device of another user, at least one sub-biometric information among the plurality of sub-biometric information is stored in the another user authentication device of the another user” or equivalent language to all claims. Applicant argues the new feature is not taught by Lee/Baltatu. Applicant argues at Remarks, pg. 11, that Baltatu standing on its own teaches storage in a smart card and an operator device. This argument ignores that Lee, unsurprisingly, teaches user authentication devices precisely like those claimed. Therefore the “storage subject” argument lacks merit when considered in light of all the teachings rather than improperly piecemealing the rejection. Applicant makes a similar argument at Remarks, pg. 12, with respect to the “scope of systems in Baltatu.” The same response applies – Applicant ignores that Lee teaches storage on a user authentication device and Baltatu teaches a divided biometric template technique and that the combination would teach the amended language. Applicant argues at Remarks, pgs. 11-12 that the amended claims require storage of at least one part of the sub-biometric information in a device of another user. Applicant calls this “cooperation topology.” Examiner notes that “cooperation topology” is not a specification term and appears to be coined in response to the fact that the cited Baltatu employs data storage on two devices both owned by the same person. Lee/Baltatu renders the claimed scope obvious. The distinction is a distinction in legal ownership, which is not a structural difference in devices. Applicant does not argue that Lee/Baltatu does not teach storage in multiple (Baltatu) user authentication devices (Lee) of a user obvious, and the only distinction between that situation and the claimed situation is that the claim requires legal ownership of one of the devices to be owned by another user. But a claim to a device (whether it be the user authentication device, the user authentication request device, or the server) is distinguished by structure, and the legal ownership of a device is not a structural distinction. See MPEP 2114. Regardless, Examiner used the time allotted for this action to attempt to teach the feature as if it were entitled to patentable weight. Examiner makes Lee/Baltatu an alternate ground and additionally relies upon Connell in the main ground of rejection, which more explicitly teaches a system in which multiple users register multiple devices and storage of full or partial templates may be had in any device. Applicant argues at Remarks, pgs. 12-13 that the claims are nonobvious because of a principle of operation. Specifically, Applicant argues that Baltatu teaches away from the claims because it requires “a multi-party cooperative authentication.” Applicant argues an unclaimed feature. As above, the legal ownership of devices is not a patentable distinction. Regardless, the claims do not require “multi-party cooperation” or “motivation to involve another user in the authentication of the first user” or “a different end user who is separately authenticated.” The only things the claims require is storage on a user authentication device, and Lee teaches that user authentication devices can store templates. The claims do not require a second user to authenticate or to cooperate or be involved in the authentication of the first user. Nor are “the claimed device and the other user’s device” “functionally interdependent,” at least no more so than any other storage location. Applicant prefaces the argument with a statement that “the amended features are not a mere design choice,” apparently anticipating Examiner would conclude as such. Examiner does not prefer to use “design choice” as it has murky legal ramifications, but what Examiner will find is that the location of storage would have been known by one of ordinary skill to be fungible and therefore the location of storage is a simple substitution (see MPEP 2143(I)(B)). Specifically, a person of ordinary skill after reading Lee would have recognized that storage of biometric information in third-party devices is permissible. After all, Lee’s (and therefore Applicant’s) server stores the user’s biometric information in order to look up the user authentication device. See Instant Claim 17; “the memory stores one sub-biometric information of the user of the first electronic device” and Lee, para. 100. Further, Baltatu teaches that a split template is secure so long as a malicious person (Baltatu contemplates a hacker) does not have access to all of the parts, see Baltatu, para. 79. Therefore, even if one were to assume malintent on the part of some other user the template-as-a-whole would still be secure because the user only had access to one part of it. Consequently, Examiner disagrees that it is a principle of operation that templates cannot be stored on third-party devices, or that “cooperation” is against the principle of operation of the references. Applicant fails to explain how storage of sub-template on a differently-owned end-user device that is used in order to achieve authentication is a different principle of operation than storage of an entire template on a differently-owned server device in order to look up the authenticating device in order to achieve authentication as in Lee. Regardless, the above argument is based only on Lee/Baltatu. Examiner notes that in Connell the reference explicitly considers storage of templates on any device and suggests that is, in fact, more secure than storage on one’s own devices because if the template is compromised “it can be difficult to match a biometric template on an external device with its source.” (Connell, para. 48) Consequently, Connell posits each template storage device storing multiple biometric templates corresponding to multiple users. (para. 57) Whatever principle of operation arguments that could be made against Lee/Baltatu because Baltatu only teaches single-ownership of devices fail against Connell’s teachings. The amended claims remain obvious. All claims are rejected. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to NICHOLAS P CELANI whose telephone number is (571)272-1205. The examiner can normally be reached on M-F 9-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Vivek Srivastava can be reached on 571-272-7304. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NICHOLAS P CELANI/Examiner, Art Unit 2449
Read full office action

Prosecution Timeline

Show 4 earlier events
Oct 08, 2025
Request for Continued Examination
Oct 17, 2025
Response after Non-Final Action
Nov 21, 2025
Non-Final Rejection mailed — §103
Feb 19, 2026
Response Filed
Apr 06, 2026
Final Rejection mailed — §103
Jun 22, 2026
Request for Continued Examination
Jun 28, 2026
Response after Non-Final Action
Jul 14, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750673
AUTHENTICATION HARDENING WITH PROOF OF PROXIMITY OVER LOCAL CONNECTION
3y 2m to grant Granted Sep 29, 2026
Patent 12748864
DATA ENCRYPTION AND DECRYPTION USING DYNAMIC SCREENS AND LOGIC BLOCKS
1y 12m to grant Granted Sep 29, 2026
Patent 12732513
MACHINE LEARNING FOR DETECTING MALICIOUS ACTIVITY USING ACCESS ACTIVITY AND JOB TITLE
2y 10m to grant Granted Sep 08, 2026
Patent 12732484
AUTOMATED FUZZY HASH BASED SIGNATURE COLLECTING SYSTEM FOR MALWARE DETECTION
2y 0m to grant Granted Sep 08, 2026
Patent 12706878
ZERO-TRUST ARCHITECTURE FOR SECURE AGGREGATION IN FEDERATED LEARNING
3y 9m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
46%
Grant Probability
88%
With Interview (+42.3%)
3y 2m (~3m remaining)
Median Time to Grant
High
PTA Risk
Based on 467 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month