Prosecution Insights
Last updated: October 02, 2026
Application No. 18/618,383

SECURE AI AUTHENTICATION AND INTERACTION

Non-Final OA §101§103§112
Filed
Mar 27, 2024
Examiner
NOEL, LYDIA LOUIS-FILS
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Microsoft Technology Licensing, LLC
OA Round
3 (Non-Final)
68%
Grant Probability
Favorable
3-4
OA Rounds
6m
Est. Remaining
93%
With Interview

Examiner Intelligence

Grants 68% — above average
68%
Career Allowance Rate
69 granted / 101 resolved
+10.3% vs TC avg
Strong +25% interview lift
Without
With
+24.7%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
18 currently pending
Career history
137
Total Applications
across all art units

Statute-Specific Performance

§101
5.7%
-34.3% vs TC avg
§103
62.2%
+22.2% vs TC avg
§102
9.1%
-30.9% vs TC avg
§112
19.1%
-20.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 101 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office Action is in response to Continuation filed on 06/30/2026. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 06/30/2026 has been entered. Response to argument In light of applicant Amendments, the previous rejection of claims 1–13 under 35 U.S.C. 112(b), based on clarity regarding the relationship between the previously recited “credential” and “information” terminology, is withdrawn. Applicant's arguments regarding the 101 rejection are not persuasive. Although amended claim 14 recites receiving inputs from biometric and non-biometric sensors, these limitations merely identify sources of data used in generating the authentication model. Claim 14 only requires generating a trained user authentication model and does not require using the trained model to authenticate a user, grant or deny access, or otherwise cause a technological security action. Accordingly, the amendments do not integrate the judicial exception into a practical application. Applicants’ arguments filed on 06/30/2026 with respect to the 103 rejection of claims 1-20 have been considered but are moot in view of the new ground(s) of rejection, which were necessitated by amendment. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Issue #1 — Biometric sensor detecting gesture/movement pattern Independent claims 1, 6, and 14 have been amended to require a particular relationship between a biometric sensor and a user gesture credential or user movement pattern. Claim 1 requires: “a biometric sensor input device that wirelessly detects at least one non-location credential … comprising a user gesture credential or a user movement pattern.” Claim 6 similarly requires: “detecting, by a biometric sensor input device … biometric information … comprising … a user gesture credential or a user movement pattern.”, and Claim 14 requires selection of a gesture credential or movement pattern as the non-contact input and then: “receiving from a biometric sensor the at least one non-contact input.” The originally filed specification does not reasonably convey possession of these amended relationships. The specification generally in para [0025], [0057], [0080] identifies biometric sensors as including devices such as cameras, microphones, fingerprint readers, and the like, but does not identify a gesture or movement pattern as biometric information detected by such a biometric sensor. Likewise, para [0123] separately identifies the possible non-contact inputs as a biometric input, a gesture input, or a movement-pattern credential, rather than describing the gesture or movement pattern itself as biometric information obtained from a biometric sensor. Although para [0066] states that a model may be trained based on a combination of 3D-position information and movement-pattern information, that paragraph does not disclose that the movement pattern information is biometric information detected by a biometric sensor input device. Accordingly, while the specification separately discloses biometric sensors and gesture/movement-pattern information, it does not reasonably convey possession of the presently claimed combination in which the gesture or movement-pattern credential is biometric information detected or received from a biometric sensor, as required by independent claims 1, 6, and 14. The amended limitations therefore lack adequate written-description support. Issue #2 — Functional ML/authentication-model breadth Claims 1 and 6 broadly recite an “at least one machine learning (ML) model configured to perform a user authentication analysis” that receives specified credential information and provides an authentication response on which authentication of the user is based. Claim 14 broadly recites training an authentication model from gesture/movement-pattern and location inputs to “generate a trained user authentication model.”. However, the disclosures do not sufficiently describe how the specifically claimed input information is processed by the broadly recited ML/authentication model to achieve the claimed authentication functionality. In particular, the specification does not adequately describe: how the heterogeneous gesture or movement-pattern information and location information are represented as ML features; how those materially different input types are combined, correlated, temporally associated, weighted, or otherwise provided to the authentication model; what authentication-specific training examples, target values, or labels correspond to the claimed gesture/movement-pattern and location combination; what learned relationship between the gesture/movement information and location information constitutes an authorized versus unauthorized user; how the broadly recited ML model derives the claimed user authentication response from those inputs; or for claim 14, how the claimed training actually produces the broadly recited trained user authentication model having the claimed authentication functionality. For example, para [0066] merely states that model trainer 303 may train model N 320 based on 3D-position information 340 and movement patterns 342, but does not describe how those heterogeneous inputs are represented, correlated, labeled, or processed to produce an authentication decision. Similarly, para [0081]–[0083] state the desired request ML response and authentication result, but do not disclose the algorithm or procedure by which the ML model derives that authentication response from the credential combination. Although para [0097]–[0100] list numerous generic ML algorithms and general training concepts, merely identifying neural networks, logistic regression, Naive Bayes, decision trees, clustering, and other generic ML techniques does not itself disclose representative implementations of those models configured to perform the particular claimed authentication analysis using the particular claimed inputs. Thus, the disclosure substantially identifies the desired inputs and outputs of the claimed ML functionality without sufficiently identifying how the claimed function is achieved over the full scope of the broadly recited ML/authentication model. Accordingly, the specification does not reasonably convey possession of the full scope of the claimed invention. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 8 and 12 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 8, claim 8 recites, in relevant part: “varying selection of at least one of the biometric information from at least the one non-location credential, the user gesture credential, or the non-biometric information from a plurality of non-biometric information…”. It is unclear what is being selected; whether “the non-location credential” and “the user gesture credential” are sources of the biometric information or separate selectable alternatives; what “at least the one non-location credential” means; and how the listed alternatives are grammatically related. Accordingly, one of ordinary skill in the art would not be reasonably apprised of the scope of claim 8. Claim 12, claim 12 recites “wherein the determination of the user proximity information is based on at least one of a time of flight or an angle of arrival…” However, claim 12 depends from claim 11, which in turn depends from claim 6. Neither claim 6 nor claim 11 previously recites “user proximity information”. The term “user proximity information” is introduced in claim 9, and the act of “determining the user proximity information” is introduced in claim 10. Claim 12, however, does not depend from either claim 9 or claim 10. Accordingly, claim 12 lacks proper antecedent basis and is indefinite under §112(b). Claims 2-5, 7-12, and 15-20 fail to overcome the grounds of rejection issued for claims 1, 6, and 14 under 35 U.S.C. § 112 and incorporate the same limitations for which claims 1, 6, and 14 have been rejected. The same reasoning and factual bases set forth for the rejection of claims 1, 6, and 14 are equally applicable to claims 2-5, 7-12, and 15-20. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 14-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to abstract idea without significantly more. Applying the subject Matter Eligibility Test for Products and Processes to claims 14-20: Regarding claims 14-20: Eligibility Step 1: The four categories of Statutory Subject Matter Independents claim 14 recites a method which falls under one of the four Statutory categories. Eligibility Step 2A: Is the claim directed to a law of nature, a natural phenomenon (product of nature), or an abstract idea? Prong One: However, the claim recites an abstract idea that is subjected to a judicial exception because the steps recited in the method and system claim can be considered a mental process defined as an abstract idea because the steps recited in the claims would be considered a “concept performed in the human mind”. Each limitation recited in the claim 14 (enabling selection… of at least one non-contact input… and at least one user location input for an authentication model for the user; receiving… the at least one non-contact input; receiving … the at least one user location input; and training the authentication model… based on the received at least one non-contact input and the received at least one user location input to generate a trained user authentication model) is considered a mental process abstract idea, nothing in the claim preclude it from practically being performed in the human mind . Because each limitation in said step can be performed in the mind, and therefore the claims would be considered a mental process abstract idea. Prong Two: The claim recites additional element: a computing system, an authentication model, a biometric sensor, non-biometric sensor, and a Machin learning (ML) user authentication engine in claim 20. These elements are recited at a high level of generality, i.e., as a generic components performing a generic computer function of (detecting data, transmitting requests, and receiving response). The claims do not recite any technological improvement to computer functionality or ML model architecture. Instead, they merely apply authentication in the context of conventional hardware. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to the abstract idea. Eligibility Step 2B: Does the claim recite additional elements that amount to significantly more than the judicial exception? As discussed with respect to Step 2A Prong Two, the additional element in the claim amounts to no more than mere instructions to apply the exception using a generic computer component. The same analysis applies here in 2B, i.e., mere instructions to apply an exception using a generic computer component cannot integrate a judicial exception into a practical application at Step 2A or provide an inventive concept in Step 2B. For this reason, the claim is not eligible subject matter under 35 U.S.C. 101. Claim 15 recites: The method of claim 15, “interacting with the trained user authentication model to authenticate the user; and providing access to a secure account by the user based on the authenticating”. The limitation is regarding a process direct to a mental process and mathematical concept (Subject Matter Edibility Test, Steps 1 and 2A Prong 1 – see more detailed analysis for claim 1 above that also applies to this claim), which is further analyzed under Step 2A, Prong 2 and step 2B. Because the limitation(s) do(es) not add any significant element, the claim(s) do(es) not integrate the judicial exception into a practical application (Step 2A Prong 2). Likewise, for the same rational, the claim(s) also therefore do(es) not recite additional elements that amount to significantly more than the judicial exception. Thus, the claim is not eligible under 35 U.S.C. 101. Claim 16 recites: The method of claim 16, “wherein the at least one non-contact input comprises at least one of a biometric input, a gesture input, or a movement pattern input”. The limitation is regarding a process direct to a mental process and mathematical concept (Subject Matter Edibility Test, Steps 1 and 2A Prong 1 – see more detailed analysis for claim 1 above that also applies to this claim), which is further analyzed under Step 2A, Prong 2 and step 2B. Because the limitation(s) do(es) not add any significant element, the claim(s) do(es) not integrate the judicial exception into a practical application (Step 2A Prong 2). Likewise, for the same rational, the claim(s) also therefore do(es) not recite additional elements that amount to significantly more than the judicial exception. Thus, the claim is not eligible under 35 U.S.C. 101. Claim 17 recites: The method of claim 17, “signing the trained user authentication model with a model authentication key to generate a trained secure user authentication model”. The limitation is regarding a process direct to a mental process and mathematical concept (Subject Matter Edibility Test, Steps 1 and 2A Prong 1 – see more detailed analysis for claim 1 above that also applies to this claim), which is further analyzed under Step 2A, Prong 2 and step 2B. Because the limitation(s) do(es) not add any significant element, the claim(s) do(es) not integrate the judicial exception into a practical application (Step 2A Prong 2). Likewise, for the same rational, the claim(s) also therefore do(es) not recite additional elements that amount to significantly more than the judicial exception. Thus, the claim is not eligible under 35 U.S.C. 101. Claim 18 recites: The method of claim 18, “wherein the at least one non-contact input comprises at least one of a public key, a private key, a cloud key, or an SSH key”. The limitation is regarding a process direct to a mental process and mathematical concept (Subject Matter Edibility Test, Steps 1 and 2A Prong 1 – see more detailed analysis for claim 1 above that also applies to this claim), which is further analyzed under Step 2A, Prong 2 and step 2B. Because the limitation(s) do(es) not add any significant element, the claim(s) do(es) not integrate the judicial exception into a practical application (Step 2A Prong 2). Likewise, for the same rational, the claim(s) also therefore do(es) not recite additional elements that amount to significantly more than the judicial exception. Thus, the claim is not eligible under 35 U.S.C. 101. Claim 19 recites: The method of claim 19, “wherein the at least one user location input is generated by an ultra-wideband (UWB) enabled device”. The limitation is regarding a process direct to a mental process and mathematical concept (Subject Matter Edibility Test, Steps 1 and 2A Prong 1 – see more detailed analysis for claim 1 above that also applies to this claim), which is further analyzed under Step 2A, Prong 2 and step 2B. Because the limitation(s) do(es) not add any significant element, the claim(s) do(es) not integrate the judicial exception into a practical application (Step 2A Prong 2). Likewise, for the same rational, the claim(s) also therefore do(es) not recite additional elements that amount to significantly more than the judicial exception. Thus, the claim is not eligible under 35 U.S.C. 101. Claim 20 recites: The method of claim 20, “selecting the trained user authentication model from a plurality of trained user authentication models for deployment in a machine-learning (ML) user authorization engine”. The limitation is regarding a process direct to a mental process and mathematical concept (Subject Matter Edibility Test, Steps 1 and 2A Prong 1 – see more detailed analysis for claim 1 above that also applies to this claim), which is further analyzed under Step 2A, Prong 2 and step 2B. Because the limitation(s) do(es) not add any significant element, the claim(s) do(es) not integrate the judicial exception into a practical application (Step 2A Prong 2). Likewise, for the same rational, the claim(s) also therefore do(es) not recite additional elements that amount to significantly more than the judicial exception. Thus, the claim is not eligible under 35 U.S.C. 101. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-4, 6, 9-10, 13-16 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Gordon et al. (U.S. Pub 2022/0366026 A1; Hereinafter “Gordon”) in view of DiAcetis et al. (U.S. Pub. No. 2022/0035895 A1; Hereinafter “DiAcetis”). As per claims 1 and 6, Gordon teaches a system, comprising (Gordon: fig. 1-2, para[33-36], “System challenges for MFA”): a biometric sensor input device that wirelessly detects at least one non-location credential of a user (Gordon: para [48-49], “Google Authenticator App. Then at login, prompt the user to enter a code generated by the mobile app, and validate it with the above library, before allowing them to proceed. Together these steps represent first (password) and second (device) factors, which combine to create multi-factor authentication C5 150.”, para [55], [67-68], “The multi-factor authentication may consist of the shared secret plus two-factor authentication implementation described but may also be a hardware/software biometric.”); a processor, and a memory device that stores program code structured to cause the processor to: generate a request to at least one machine learning (ML) model configured to perform a user authentication analysis (Gordon teaches a system comprising a processor and memory storing program code for implementing a machine-learning-based authenticator. Gordon’s learning based authenticator observes phenomena associated with authorized and unauthorized usage, is trained using positively and negatively labeled observations, and predicts an authentication result. Gordon further teaches a multi-factor authenticator using a shared secret, a known device, or a biometric attribute. See Gordon, Fig. 1; para [28-29], [31-43], [50], [0053], [67-69], and [81]); wherein the request includes the at least one non-location credential (Gordon teaches the learning based authenticator 160 receives observed phenomena and generates a determination of whether the observed behavior appears authorized or unauthorized. See Gordon, Fig. 1; para [28-029], [31-43], [50], [53], [67-69], and [81]); receive at least one user authentication response from the at least one ML model (Gordon teaches whenever C6 160 observes phenomena that results in a negative authentication result, it pings C5 150 to execute a manual (meaning user-in-the-loop) MFA challenge. The results, or outcome, of that MFA challenge are then communicated to the labeler 180, which then annotates the observations where they are recorded in the data lake, usually with 0 or ‘False’ for failed, 1 or ‘True’ for success, “The labeler 180 may label further types of labels beyond authorized and unauthorized, such as attacker, guest, new user, credential change, or locality information, device ID, MFA meta information, level of attack sophistication, etc. see Gordon para see fig. 2, para [33-43], [72-76],); and authenticate the user based on the at least one user authentication response from the at least one ML model (Gordon teaches an output of the learning based authenticator determines whether the user is allowed to log in or execute a requested task. See Gordon, Fig. 2, steps 220–260; para [33-43]. Gordon also teaches biometric authentication and detection of an authorized user device based on proximity. Gordon explains that a second authentication factor may include turning on a camera for facial recognition or detecting the authorized user’s device for proximity, and that the ML-based authenticator may incorporate biometric inputs, including behavioral or facial-image inputs. See Gordon, para [67-69]). Although, Gordon teaches detecting the authorized user's device for proximity as a second factor, Gordon does not clearly teach a positioning receiver that wirelessly detects at least one user location credential; a request including the at least user location credential; and the at least one non-location credential comprising a user gesture credential, or a user movement pattern credential. However, in the related art, DiAcetis teaches a positioning receiver that wirelessly detects at least one user location credential (DiAcetis teaches receipt and processing of positioning information from wireless positioning systems and sensors, see DiAcetis fig 1A-B para[29] ); a request including the at least user location credential (DiAcetis teaches using the position and gesture/movement information together as respective authentication factors and providing authenticated access to a secured resource after confirmation of the factors. DiAcetis expressly claims positioning data indicating that the computing device is within a predetermined geographic area as a first authentication factor and a gesture or predetermined movement pattern detected by another computing device as a second authentication factor, see DiAcetis fig 1A-B para[36-37] [80-86]); and the at least one non-location credential comprising a user gesture credential, or a user movement pattern credential (DiAcetis teaches a sensor input device that detects a gesture credential or movement pattern of the user, see DiAcetis fig 1A-B para[36-37] [47] [80-86])). Therefore, It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Gordon’s machine learning based authentication system, as taught by DiAcetis, to obtain wireless positioning information and a user gesture or movement pattern as additional authentication inputs, because it would provide independent contextual and user presence factors that improve authentication reliability and resistance to remote credential misuse or spoofing (DiAcetis; para [49]). As per claim 2, Gordon in view of DiAcetis teaches the independent claim 1. Gordon teaches wherein the at least one non-location credential comprises a user biometric credential (Gordon: para[28], “multi-factor authenticator 150—this is a piece of software and/or hardware that uses two of the following authentication methods to confirm user identity: a shared secret, a known device, or a biometric attribute.”). As per claim 3, Gordon in view of DiAcetis teaches the independent claim 1. Gordon teaches wherein the at least one non-location credential further comprises at least one of a public key, a private key, a cloud key, or a secure shell SSH key (Gordon: para[28], “multi-factor authenticator 150—this is a piece of software and/or hardware that uses two of the following authentication methods to confirm user identity: a shared secret, a known device, or a biometric attribute.”). As per claims 4 and 9, Gordon in view of DiAcetis teaches the independent claim 1. DiAcetis teaches wherein the at least one location credential indicates at least one of proximity, geolocation, three-dimensional (3D) position, or presence detection of the user or a user associated device (DiAcetis teaches that the location credential may indicate: the user’s current location; whether the user is within a predetermined geographic area; proximity to another device or location; movement through an environment; and presence within the secured area. See DiAcetis, Figs. 1A–1B; claims 21, para [27–28], [34–35]). Therefore, It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Gordon’s machine learning based authentication system, as taught by DiAcetis, to obtain wireless positioning information and a user gesture or movement pattern as additional authentication inputs, because it would provide independent contextual and user presence factors that improve authentication reliability and resistance to remote credential misuse or spoofing (DiAcetis; para [49]). As per claim 10, Gordon in view of DiAcetis teaches the dependent claim 9. DiAcetis teaches determining the user proximity information based on a secure challenge to authenticate the biometric information (DiAcetis teaches determining that a computing device is within a predetermined secured area as a first factor and issuing a secure challenge requiring an additional operation at another device, including entering a fingerprint, performing a gesture, or performing a predetermined movement pattern. See DiAcetis, claims 21–26 and 28–33.). Therefore, It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Gordon’s machine learning based authentication system, as taught by DiAcetis, to obtain wireless positioning information and a user gesture or movement pattern as additional authentication inputs, because it would provide independent contextual and user presence factors that improve authentication reliability and resistance to remote credential misuse or spoofing (DiAcetis; para [49]). As per claim 13, Gordon in view of DiAcetis teaches the dependent claim 9. DiAcetis teaches wherein the determination whether to authenticate the user is based, at least in part, on an indication by the user proximity information that the user is located within a geo-fence position threshold (DiAcetis teaches determining whether authenticated access should be granted based at least in part on positioning information indicating that the user-associated computing device is within a predetermined geographic area. DiAcetis further teaches terminating access when the device exits the predetermined area. See DiAcetis, claims 21, 27–28, and 34–35.”). Therefore, It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Gordon’s machine learning based authentication system, as taught by DiAcetis, to obtain wireless positioning information and a user gesture or movement pattern as additional authentication inputs, because it would provide independent contextual and user presence factors that improve authentication reliability and resistance to remote credential misuse or spoofing (DiAcetis; para [49]). As per claim 14, Gordon teaches a method in a computing system, comprising: enabling selection, via the computing system, of at least one non-contact input for an authentication model for the user (Gordon: para [28], “multi-factor authenticator 150—this is a piece of software and/or hardware that uses two of the following authentication methods to confirm user identity: a shared secret, a known device, or a biometric attribute”); receiving from a biometric sensor the at least one non-contact input (Gordon teaches a Google Authenticator App. Then at login, prompt the user to enter a code generated by the mobile app, and validate it with the above library, before allowing them to proceed. Together these steps represent first (password) and second (device) factors, which combine to create multi-factor authentication C5 150, “The multi-factor authentication may consist of the shared secret plus two-factor authentication implementation described but may also be a hardware/software biometric.” See Gordon para [48-49], [55], [67-68],); and training the authentication model, via the computing system based on the received at least one non-contact input and the received at least one user location input to generate a trained user authentication model (Gordon teaches a learning component determines if the observed and modeled phenomena appears authorized or unauthorized; Step 3 230—System challenges for MFA”, para[53], “The MLBA may be in the app backend, in the app front-end, or separate system with its own agent on devices C1 110, C2 120 and/or others, or part of the OS or another agent of the devices or cloud infrastructure.” See Gordon para [29], [33-43],). Gordon does not clearly teach enabling at least one user location input; receiving from a non-biometric sensor the at least user location input; and the at least one non-location input comprising a user gesture credential, or a user movement pattern credential. However, in the related art, DiAcetis teaches enabling at least one user location input (DiAcetis teaches receipt and processing of positioning information from wireless positioning systems and sensors, see DiAcetis fig 1A-B para[29] ); receiving from a non-biometric sensor the at least user location input (selecting and using position as a first authentication factor; selecting a gesture or predetermined movement pattern as another authentication factor; obtaining gesture or movement information through another computing device, camera, image-processing mechanism, motion detector, or sensor; obtaining position through GPS, Wi-Fi, Bluetooth proximity, routers, access points, or device sensors; and storing positioning information for machine-learning purposes., see DiAcetis fig 1A-B para[36-37] [80-86], claims 21, 25-26); and the at least one non-location input comprising a user gesture credential, or a user movement pattern credential (DiAcetis teaches a sensor input device that detects a gesture credential or movement pattern of the user, see DiAcetis fig 1A-B para[36-37] [47] [80-86])). Therefore, It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Gordon’s machine learning based authentication system, as taught by DiAcetis, to obtain wireless positioning information and a user gesture or movement pattern as additional authentication inputs, because it would provide independent contextual and user presence factors that improve authentication reliability and resistance to remote credential misuse or spoofing (DiAcetis; para [49]). As per claim 15, Gordon in view of DiAcetis teaches the independent claim 14. Gordon teaches interacting with the trained user authentication model to authenticate the user; and providing access to a secure account by the user based on the authenticating (Gordon teaches a user attempts to log in, or execute a task on device Cl using app…Learning component determines if the observed and modeled phenomena appears authorized or unauthorized; Step 3 230—System challenges for MFA; Step 4 240—If MFA fails a negative label is created for phenomena; Step 5 250—if MFA succeeds the labeler 180 labels the data that prompted S3 230 to provide a negative result with a positive label in the data lake C7; and Step 6 260—user allowed to log in or execute task. If S2 220 is successful, the user may progress to S6 260. If S3 230 fails, the behavior receives a negative label.”. see Gordon para[31-43], step 1-6, fig. 2,). As per claim 16, Gordon in view of DiAcetis teaches the independent claim 14. Gordon teaches wherein the at least one non-contact input further comprises a biometric input (Gordon: para[28], “multi-factor authenticator 150—this is a piece of software and/or hardware that uses two of the following authentication methods to confirm user identity: a shared secret, a known device, or a biometric attribute.”); and the at least one user location input indicates at least one of proximity, geolocation, three-dimensional (3D) position, or presence detection (Gordon: para [68], “The second factor may be frictionless, such as turning on a camera for facial recognition (third factor) or detecting the authorized user's device for proximity as a second factor.”). As per claim 18, Gordon in view of DiAcetis teaches the independent claim 14. Gordon teaches wherein the at least one non-location credential comprises at least one of a public key, a private key, a cloud key, or a secure shell SSH key (Gordon: para[28], “multi-factor authenticator 150—this is a piece of software and/or hardware that uses two of the following authentication methods to confirm user identity: a shared secret, a known device, or a biometric attribute.”). Claims 5 and 7 are rejected under 35 U.S.C. 103 as being unpatentable over Gordon et al. (U.S. Pub 2022/0366026 A1; Hereinafter “Gordon”) in view of DiAcetis et al. (U.S. Pub. No. 2022/0035895 A1; Hereinafter “DiAcetis”) and Fu et al. (U.S. Pub 20210398132 A1; Hereinafter “Fu”). As per claims 5 and 7, Gordon in view of DiAcetis teaches the independent claim 1. Fu teaches wherein the authenticator is further configured to: vary selection of the at least one ML model, from a plurality of trained ML models, for the request based on at least one of the location credential or the non-location credential (Fu: para[36], [51-63], “In step S104, rule processing computer 140 can determine a machine learning model from a plurality of machine learning models by applying rules to the external data… In a log-in example, the prediction request may comprise an indicator that it is an authorization request, a user identifier, a device identifier, a password (or a derivative of the password), a location, and a time stamp. As an example, user device 110 may send an authorization request to data enrichment computer 120 for a transaction that a user is making while on vacation.”). Therefore, It would have been obvious to further modify Gordon’s authentication system, as enhanced by DiAcetis, to select an applicable trained model from a plurality based on the received authentication information, as taught by Fu, because selecting a model suited to the available credential type, device context, or location would improve the relevance and accuracy of the resulting authentication analysis (Fu: para [21]). Claims 8, 11-12 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Gordon et al. (U.S. Pub 2022/0366026 A1; Hereinafter “Gordon”) in view of DiAcetis et al. (U.S. Pub. No. 2022/0035895 A1; Hereinafter “DiAcetis”) and Pirch et al. (U.S. Pub 20200314651 A1; Hereinafter “Pirch”). As per claim 8, Gordon in view of DiAcetis teaches the independent claim 6. Pirch teaches varying selection of at least one of the biometric information from at least one non-location credential, the user gesture credential, or the non-biometric information from a plurality of non-biometric information based on at least one parameter (Pirch: para[116-117], “The trained machine learning model is trained with data sets collected from a plurality of users. The data sets may include movement data for the plurality of users within a range of the asset. The data sets may include movement data from the plurality of users. The information received from the wireless key device may include movement data of the user collected from an accelerometer of the wireless key device.”). Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to have update Gordon MFA authentication with user location such as UWB/BLE proximity of Pirch, it will improve authentication robustness and resist remote spoofing with because it will add more layer of protection from potential fraud and misuse (Pirch: para [55]). As per claim 11, Gordon in view of DiAcetis teaches the independent claim 6. Pirch teaches wherein the user associated device comprises an ultra-wideband (UWB) enabled device (Pirch: para[21], [46], “In FIG. 2D, key device A 230 and key device C 240 continue to move and the location information of their respective movement is provided to the reader 210 through the UWB communication.”). Therefore, It would have been obvious to further modify the Gordon-DiAcetis authentication system to obtain the location information through UWB ranging, as taught by Pirch, because UWB provides accurate proximity and direction information suitable for confirming the physical presence and position of the user-associated device during authentication (Pirch: para [55]). As per claim 12, Gordon in view of DiAcetis and Pirch teaches the dependent claim 11. Pirch teaches wherein the determination of the user proximity information is based on at least one of a time of flight or an angle of arrival for a communication from the user associated device (Pirch: para[51], “Identifying the location of the person 335 and performing continuous localization of the person 335 (through their key device), may provide a direction the person 335 is moving. Using the determined direction, the readers may identify an angle of arrival 340. The angle of arrival 340 may be used to determine which doorway of multiple doorways that the person 335 is intending to enter.”). Therefore, It would have been obvious to further modify the Gordon-DiAcetis authentication system to obtain the location information through UWB ranging, as taught by Pirch, because UWB provides accurate proximity and direction information suitable for confirming the physical presence and position of the user-associated device during authentication (Pirch: para [55]). As per claim 19, Gordon in view of DiAcetis teaches the independent claim 14. Pirch teaches wherein the at least one user location input is generated by an ultra-wideband (UWB) enabled device (Pirch: para[21], [46], “In FIG. 2D, key device A 230 and key device C 240 continue to move and the location information of their respective movement is provided to the reader 210 through the UWB communication.”). Therefore, It would have been obvious to further modify the Gordon-DiAcetis authentication system to obtain the location information through UWB ranging, as taught by Pirch, because UWB provides accurate proximity and direction information suitable for confirming the physical presence and position of the user-associated device during authentication (Pirch: para [55]). Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Gordon et al. (U.S. Pub 2022/0366026 A1; Hereinafter “Gordon”) in view of DiAcetis et al. (U.S. Pub. No. 2022/0035895 A1; Hereinafter “DiAcetis”) and Cao et al. (C.N. 115442050 A; Hereinafter “Cao”). As per claim 17, Gordon in view of DiAcetis teaches the independent claim 14. Gordon in view of DiAcetis does not teach signing the trained user authentication model with a model authentication key to generate a trained secure user authentication model. However, in the related art, Cao teaches signing the trained user authentication model with a model authentication key to generate a trained secure user authentication model (Cao: fig. 1, step 1-3, “in order to achieve the purpose of the above invention, the present invention adopts the following technical solution: by adding the evaluation server in the federal learning architecture, the training participant sends the model data for evaluating and verifying, eliminating virus data of malicious participants. and combining the SM9 encryption and signature algorithm to ensure the security of the user privacy in the whole federal learning communication process. the training participant encrypts the trained model M, and signing the model, the central server confirms the identity rationality of the training participant through the signature verification algorithm, then sends the model information to the evaluation server to decrypt, the evaluation server evaluates the data after decrypting the model data, returning back to the central server after reaching the standard model data aggregation”. Therefore, It would have been obvious to further modify the Gordon-DiAcetis trained authentication model, as taught by Cao, to digitally sign the trained model using a model-authentication key because signing would permit verification that the deployed model originated from an authorized source and had not been altered, thereby protecting the integrity of the authentication process (Cao: page 3). Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Gordon et al. (U.S. Pub 2022/0366026 A1; Hereinafter “Gordon”) in view of DiAcetis et al. (U.S. Pub. No. 2022/0035895 A1; Hereinafter “DiAcetis”) and Wang et al. (U.S. Pub 20230048386 A1; Hereinafter “Wang”). As per claim 20, Gordon in view of DiAcetis teaches the independent claim 14. Gordon in view of DiAcetis does not teach selecting the trained user authentication model from a plurality of trained user authentication models for deployment in a machine-learning (ML) user authorization engine. However, in the related art, Wang teaches selecting the trained user authentication model from a plurality of trained user authentication models for deployment in a machine-learning (ML) user authorization engine (Wang: para[65-68], “determining, in response to a selection operation by the user for the at least two trained models, a model selected by the user as the target model.”. Therefore, It would have been obvious to further modify Gordon’s authentication-model system, as enhanced by DiAcetis, to select a trained model from a plurality for deployment, as taught by Wang, because selecting a model appropriate for the credential types or authentication environment would improve processing efficiency and ensure that the model suited to the current authentication context is deployed (Wang: para[192]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20130127591 A1- A method for authenticating a user using multifactor biometric authentication with data from the mobile device; obtaining data from one or more fixed sensor devices at a location in the physical vicinity of the secure facility; cross-validating data from the mobile device with data from the one or more fixed sensor devices; and granting access to the secure facility if the authentication of the user and the cross-validation are successful. Any inquiry concerning this communication or earlier communications from the examiner should be directed to LYDIA L NOEL whose telephone number is (571)272-1628. The examiner can normally be reached Odd Weeks-Monday: 8:00 AM 4:00 PM, Tuesday & Wednesday: 9:00 AM 3:00 PM. Even Weeks-Monday: 8:00 AM 4:00 PM, Tuesday through Thursday: 9:00 AM 1:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571)-270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /L.L.N./ Examiner, Art Unit 2437 /ALEXANDER LAGOR/ Supervisory Patent Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Mar 27, 2024
Application Filed
Sep 22, 2025
Non-Final Rejection mailed — §101, §103, §112
Feb 04, 2026
Non-Final Rejection mailed — §101, §103, §112
Feb 18, 2026
Response Filed
Apr 01, 2026
Final Rejection mailed — §101, §103, §112
Jun 30, 2026
Request for Continued Examination
Jul 03, 2026
Response after Non-Final Action
Aug 25, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12720307
Authentication of Subscriber Entities to Enterprise Networks
2y 10m to grant Granted Aug 25, 2026
Patent 12647254
DATA FILE ENCRYPTION AND TRANSMISSION/RECEPTION SYSTEM AND DATA FILE ENCRYPTION AND TRANSMISSION/RECEPTION METHOD
3y 0m to grant Granted Jun 02, 2026
Patent 12632589
PRIVACY PRESERVING LOGGING
4y 1m to grant Granted May 19, 2026
Patent 12610231
Wireless Fine Time Measurement Authentication
4y 8m to grant Granted Apr 21, 2026
Patent 12587846
DEVICE, METHOD AND COMPUTER READABLE MEDIUM FOR RESISTING DOWNGRADE ATTACKS
2y 5m to grant Granted Mar 24, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
68%
Grant Probability
93%
With Interview (+24.7%)
3y 0m (~6m remaining)
Median Time to Grant
High
PTA Risk
Based on 101 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month