Prosecution Insights
Last updated: October 02, 2026
Application No. 18/678,201

LOCATION BASED AUTHENTICATION OF ACCOUNT CHANGES IN A WIRELESS NETWORK

Final Rejection §103
Filed
May 30, 2024
Examiner
MAHMUD, RANA HASSAN
Art Unit
2644
Tech Center
2600 — Communications
Assignee
T-Mobile USA Inc.
OA Round
2 (Final)
Grant Probability
Favorable
3-4
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-62.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
26 currently pending
Career history
18
Total Applications
across all art units
This examiner has no resolved cases yet (career too new); statute-level performance unavailable. The Grant Probability card shows Tech Center averages instead.

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment Amendment filed on 07/23/2026 is acknowledged. As a result, claims 1-20 are pending for examination. Response to Arguments Applicant’s arguments with respect to claims 1,11 and/or 18 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. See below detailed rejection with new reference. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 6, 8, 11 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over BAKSHI et al. (US 20210211876 A1, hereinafter Bakshi) in view of Wittenberg et al. (US 20160105801 A1, hereinafter known as Wittenberg and in further view of WADHWA et al. (US 20210065165 A1, hereinafter Wadhwa) Regarding Claim 1, Bakshi teaches a method comprising: detecting a request to perform an account modification to an account of an account holder at an authentication portal; (Bakshi[0029] When authentication server 130 receives the request to enroll user mobile device 110, authentication server 130 analyzes a header of a data packet transmitted by user mobile device 110 to determine whether the asserted network ID is actually associated with user mobile device 110. [0027] Additional examples of high-risk events include a change in a user name for a mobile account associated with the network ID, a change in an address for such a mobile account, a change in a number of identity verification queries that have been performed with respect to the network ID, etc.) recording a location associated with the request; (Bakshi[0030] Upon a determination that the asserted network ID is actually associated with user mobile device 110 and that high-risk events have not recently occurred, authentication server 130 stores the asserted network ID.) (Note: 'disclosed recording a location' stores the asserted network ID in the reference) But Bakshi does not teach identifying a location associated with the request; transmitting a first short messaging service (SMS) message to the account holder identifying the account modification and requesting a positive confirmation from the account holder to authorize the account modification from the recorded location, wherein the first SMS message does not include a one-time password (OTP) generating and sending the a second SMS message to the account holder responsive to receiving the positive confirmation to the first SMS message from the account holder. However, Wittenberg teaches identifying a location associated with the request; (Wittenberg [0031, line 10] The geographic location of a given login may be determined using a geographic IP address database that identifies general geographic areas for IP addresses. [Fig 1, 111] provides location information. [Fig 3, item 320, Fig 4 and 5 shows identifying a location]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi and by incorporating Wittenberg identifying the geographic location of the associated with the request to modify the account of the account holder. The motivation of doing so would have enabled the method of identifying the account holder correctly, recording account holder’s location and identifying the request for account modification. Benefit would be to enhance security of the transaction. But the combination of Bakshi and Wittenberg do not teach transmitting a first short messaging service (SMS) message to the account holder and requesting a positive confirmation from the account holder to authorize the account modification from the recorded location, wherein the first SMS message does not include a one-time password (OTP) generating and sending the a second SMS message to the account holder upon responsive to receiving the positive confirmation to the first SMS message from the account holder. However, in a similar endeavor, Wadhwa teaches transmitting a first short messaging service (SMS) message to the account holder and requesting a positive confirmation from the account holder to authorize the account modification from the recorded location, wherein the first SMS message does not include a one-time password (OTP) (Wadhwa [0071 and Figure 5] At step 5004, responsive to receiving the request for OTP generation, the OTP gateway server 316 initiates transmission of a data message to the user device 302b. The data message initiates an identity verification process flow for ensuring that the user 302a is in fact an individual/entity that is authorized to make payment transactions through the payment card or payment account identified at step 5002. As discussed in connection with FIG. 4, in an embodiment of the invention, the data transmission at step 5004 comprises a short-message-service (SMS). Examiner’s note: at this step, the first message only requests OTP but does not include OTP.) generating and sending the a second SMS message to the account holder upon responsive to receiving the positive confirmation to the first SMS message from the account holder. (Wadhwa [0073] As illustrated in FIG. 5, an identity verification decision is generated based on the identity verification process. At step 5008, responsive to a positive identity decision (i.e. responsive to determining that the user 302a is authorized to carry out payment transactions through the payment card or payment account identified at step 5002), an OTP corresponding to the ongoing payment transaction is transmitted for display on the user device 302b. The OTP can thereafter be used by the user 302a in the regular course for completing the ongoing payment transaction. The OTP transmitted for display at step 5008 may be an OTP that has been generated for the transaction by the OTP authentication server 314a.) (Note: Fig 4 404-408 further illustrated these steps in the method) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi and Wittenberg by further incorporating Wadhwa to transmit a first short SMS and request a positive confirmation of identity from the account holder and a second SMS containing OTP to the user device following a positive identity response from the account holder. The motivation would have further enhanced the security of the identity verification. Regarding Claim 6, the combination of Bakshi, Wittenberg and Wadhwa teach the method of claim 1 and Bakshi further teaches transmitting an SMS notification to the account holder indicating that the account modification has been prevented upon receiving a negative confirmation from the account holder. (Bakshi [0033] When authentication server 130 receives the authentication request, authentication server 130 compares the requested network ID to the network IDs of each authentication entry 132 in authentication server 130. If authentication server 130 cannot find such an authentication entry 132, then authentication server 130 transmits a message to vendor application server 140 indicating that no device associated with the requested network ID has enrolled as a trusted device.) The motivation of doing so would have further enhance the entire security process so that outside intervention does not happen. Regarding Claim 8, the combination of Bakshi, Wittenberg and Wadhwa teach the method of claim 1 and Bakshi further teaches wherein the account modification is a reset password operation or a change contact information request. (Bakshi [0061] At step 306, authentication server 130 locates an authentication entry 132 containing both the requested network ID and a cryptographic key. At step 308, authentication server 130 determines if any high-risk events involving the requested network ID have recently occurred. Such high-risk events may include, e.g., a change in the mobile device activated with the requested network ID, a change in the SIM card associated with the requested network ID, a change in a user name for a mobile account associated with the requested network ID, a change in an address for such a mobile account.) The motivation of doing so would allow the account holder to modify the account by resetting the password or changing the contact information. Regarding Claim 11, Bakshi teaches a system comprising: an authentication portal including at least one electronic processor configured to perform authentication operations (Bakshi [0075] The embodiments described herein may be practiced with other computer system configurations including hand-held devices, microprocessor systems, microprocessor-based or programmable consumer electronics, minicomputers, mainframe computers, etc.) the authentication operations comprising: receiving a request to perform an account modification to an account of an account holder; (Bakshi [0029] When authentication server 130 receives the request to enroll user mobile device 110, authentication server 130 analyzes a header of a data packet transmitted by user mobile device 110 to determine whether the asserted network ID is actually associated with user mobile device 110.) recording a location associated with the request; (Bakshi[0030] Upon a determination that the asserted network ID is actually associated with user mobile device 110 and that high-risk events have not recently occurred, authentication server 130 stores the asserted network ID. (Note: 'disclosed recording a location' is stores the asserted network ID in the reference. )) But Bakshi does not teach identifying a location associated with the request; transmitting a first short messaging service (SMS) message to the account holder identifying the account modification and requesting a positive confirmation from the account holder to authorize the account modification from the recorded location, wherein the first SMS message does not include a one-time password (OTP) generating and sending the a second SMS message to the account holder responsive to receiving the positive confirmation to the first SMS message from the account holder. However, Wittenberg teaches identifying a location associated with the request; (Wittenberg [0031, line 10] The geographic location of a given login may be determined using a geographic IP address database that identifies general geographic areas for IP addresses. [Fig 1, 111] provides location information. [Fig 3, item 320, Fig 4 and 5 shows identifying a location]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi and by incorporating Wittenberg identifying the geographic location of the associated with the request to modify the account of the account holder. The motivation of doing so would have enabled the method of identifying the account holder correctly, recording account holder’s location and identifying the request for account modification. Benefit would be to enhance security of the transaction. But the combination of Bakshi and Wittenberg do not teach transmitting first short messaging service (SMS) message to the account holder and requesting a positive confirmation from the account holder to authorize the account modification from the recorded location, wherein the first SMS message does not include a one-time password (OTP) generating and sending the a second SMS message to the account holder [[upon]] responsive to receiving the positive confirmation to the first SMS message from the account holder. However, in a similar endeavor, Wadhwa teaches transmitting first short messaging service (SMS) message to the account holder and requesting a positive confirmation from the account holder to authorize the account modification from the recorded location, wherein the first SMS message does not include a one-time password (OTP) (Wadhwa [0071] At step 5004, responsive to receiving the request for OTP generation, the OTP gateway server 316 initiates transmission of a data message to the user device 302b. The data message initiates an identity verification process flow for ensuring that the user 302a is in fact an individual/entity that is authorized to make payment transactions through the payment card or payment account identified at step 5002. As discussed in connection with FIG. 4, in an embodiment of the invention, the data transmission at step 5004 comprises a short-message-service (SMS)) generating and sending the a second SMS message to the account holder [[upon]] responsive to receiving the positive confirmation to the first SMS message from the account holder. (Wadhwa [0073] As illustrated in FIG. 5, an identity verification decision is generated based on the identity verification process. At step 5008, responsive to a positive identity decision (i.e. responsive to determining that the user 302a is authorized to carry out payment transactions through the payment card or payment account identified at step 5002), an OTP corresponding to the ongoing payment transaction is transmitted for display on the user device 302b. The OTP can thereafter be used by the user 302a in the regular course for completing the ongoing payment transaction. The OTP transmitted for display at step 5008 may be an OTP that has been generated for the transaction by the OTP authentication server 314a.) (Note: Fig 4 404-408 further illustrated these steps in the method) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi and Wittenberg by further incorporating Wadhwa to transmit a first short SMS and request a positive confirmation of identity from the account holder and a second SMS containing OTP to the user device following a positive identity response from the account holder. The motivation would have further enhanced the security of the identity verification. Regarding Claim 16, the combination of Bakshi, Wittenberg, and Wadhwa teach Claim 11 and Bakshi further teaches wherein the requested account modification is one of a reset password operation or a change contact information request. (Bakshi [0061] At step 306, authentication server 130 locates an authentication entry 132 containing both the requested network ID and a cryptographic key. At step 308, authentication server 130 determines if any high-risk events involving the requested network ID have recently occurred. Such high-risk events may include, e.g., a change in the mobile device activated with the requested network ID, a change in the SIM card associated with the requested network ID, a change in a user name for a mobile account associated with the requested network ID, a change in an address for such a mobile account.) The motivation of doing so would allow the account holder to modify the account by resetting the password or changing the contact information. Claims 2-4, 7, 12 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over BAKSHI et al. (US 20210211876 A1, hereinafter Bakshi) in the combined view of Wittenberg et al. (US 20160105801 A1, hereinafter known as Wittenberg), and WADHWA et al. (US 20210065165 A1, hereinafter Wadhwa) and in further view of NOREFORS et al. (WO 2004111809 A1, hereinafter Norefors) Regarding Claim 2, the combination of Bakshi, Wittenberg and Wadhwa teach the method of claim 1 but do not teach transmitting a message generation request to generate the OTP from the authentication portal to an identity authenticator, wherein the request to generate the OTP includes the recorded location or an originating IP address and a confirmation flag indicating that confirmation by the account holder is required before generating the OTP. However, in a similar endeavor, Norefors teaches transmitting a message generation request to generate the OTP from the authentication portal to an identity authenticator, wherein the request to generate the OTP includes the recorded location or an originating IP address and a confirmation flag indicating that confirmation by the account holder is required before generating the OTP. (Norefors [Column 3, line 47] The invention is directed to a method for providing an end user with access to an IP network over an access network comprising an access server. For the login procedure, the method comprises the steps of: - performing a first phase of a login procedure whereby a onetime-password (OTP) is provided by an authentication server and transferred to the end user over a mobile communication system, e.g. by a SMS or voice message. Refer to [Fig 3, item 6] [Column 6, line 32] the user is requested to enter the OTP by the authentication server, 9, over the web server, 10. The user then enters the OTP given by e.g. SMS or a voice message on the first means of the user station (e.g. a PC), and the OTP is via the web server provided to the authentication server, 11, 12. The authentication server then verifies the OTP to see if it is valid. If yes, a message with information to that fact is sent to the web server, 13.) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi with combined teachings of Wittenberg, and Wadhwa and by further incorporating Norefors to initiate the process of message generation to issue an OTP at the authentication portal. The motivation of doing so would have enabled the request to generate an OTP that includes the recorded location or the originating IP address and the verification of the OTP to send a confirmation message to the web server to make sure the request is sent by the account holder. Regarding Claim 3, the combination of Bakshi, Wittenberg, Wadhwa and Norefors teach all of claim 2 and Wittenberg further teaches further comprising identifying, through interaction with a location service, the location based on an internet protocol (IP) address associated with the request to perform an account modification. (Wittenberg [0031, line 10] The geographic location of a given login may be determined using a geographic IP address database that identifies general geographic areas for IP addresses. [Fig 1, 111] provides location information. [Fig 3, item 320, Fig 4 and 5 shows identifying a location]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi with the combined teachings of Wadhwa and Norefors and by further incorporating Wittenberg providing IP address to arrive at the invention. The motivation of doing so would have enabled request to perform an account modification of an account holder after identifying the location through IP address, thus enhancing the security. Regarding Claim 4, the combination of Bakshi, Wittenberg, Wadhwa and Norefors teach all of claim 3 and Wittenberg further teaches recording the IP address and the location at the identity authenticator. (Wittenberg [0031, line 5] each time a user logs into a service hosted on computer system 101, the service may capture a record of that login with information including the current time, internet protocol (IP) address, tenant or user identifier, portable unique identifier (PUID), and/or user agent string. The geographic location of a given login may be determined using a geographic IP address database that identifies general geographic areas for IP addresses.) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi with the combined teachings of Wadhwa and Norefors and by further incorporating Wittenberg with recording IP address to arrive at the invention. The motivation of do so would have enabled the method as to how to record the Login information including the IP address and the location at the identity authenticator so that authenticator can send SMS to account holder, thus further enhancing the security. Regarding Claim 7, the combination of Bakshi, Wittenberg and Wadhwa teach the method of claim 1 but do not teach upon a passing of a predetermined timeout period from the SMS message to the account holder without receiving the positive confirmation or a negative confirmation, transmitting an SMS notification to the account holder indicating that the account modification has been prevented. However, in a similar endeavor, Norfores teaches (Norefors [Column 3, line 4] Advantageously the web server redirects the login message to the access server login page when an account has been created/modified in the authentication server and a timer is set to a given time period during which user credentials are checked, and if they are not valid, an error message is returned to the user. Refer to [Fig 2, items 104, 113]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi and the combined teachings of Wittenberg and Wadhwa and by further incorporating Norefors creating a time slot beyond which account modification would be prevented. The motivation of doing so would have enabled system to prevent an account modification phase for better security. Regarding Claim 12, the combination of Bakshi, Wittenberg and Wadhwa teach the system of claim 11 and Bakshi further teaches request to perform the account modification (Bakshi [0029] When authentication server 130 receives the request to enroll user mobile device 110, authentication server 130 analyzes a header of a data packet transmitted by user mobile device 110 to determine whether the asserted network ID is actually associated with user mobile device 110. [0027] Additional examples of high-risk events include a change in a user name for a mobile account associated with the network ID, a change in an address for such a mobile account, a change in a number of identity verification queries that have been performed with respect to the network ID, etc.) The motivation of doing so would have enabled the system and apparatus to perform authentication operation for account modification of the account holder. But the combination of Bakshi, Wittenberg and Wadhwa do not teach identity authenticator including at least one electronic processor performing identity operations, the identity operations comprising: receiving a transmitted a generation request from the authentication portal for generating the OTP, the generation request containing an Internet Protocol (IP) address or the location a confirmation flag indicating that confirmation by the account holder is required before generating the OTP generating a confirmation request message, wherein the confirmation request message notifies the account holder of the requested account modification and the location and instructs the account holder to reply with a positive confirmation response to approve the requested account modification. However, in a similar endeavor, Norfores teaches identity authenticator including at least one electronic processor performing identity operations, the identity operations comprising: receiving a transmitted a generation request from the authentication portal for generating the OTP, the generation request containing an Internet Protocol (IP) address or the location (Norefors [Column 3, line 47] The invention also suggests a method for providing an end user with access to an IP network over an access network comprising an access server. For the login procedure, the method comprises the steps of: - performing a first phase of a login procedure whereby a onetime-password (OTP) is provided by an authentication server and transferred to the end user over a mobile communication system, e.g. by a SMS or voice message. Refer to [Fig 3, item 6] [Column 12, line 4] the user is requested to enter the OTP by the authentication server, 9, over the web server, 10. The user then enters the OTP given by e.g. SMS or a voice message on the first means of the user station (e.g. a PC), and the OTP is via the web server provided to the authentication server, 11, 12. The authentication server then verifies the OTP to see if it is valid. If yes, a message with information to that fact is sent to the web server, 13.) a confirmation flag indicating that confirmation by the account holder is required before generating the OTP (Norefors [Column 6, line 25] Then the web server requests the user identity, 4, and in response thereto the user enters his identity, e.g. MSISDN 5. This is forwarded to the authentication server, 6, which provides an OTP) generating a confirmation request message, wherein the confirmation request message notifies the account holder of the requested account modification and the location and instructs the account holder to reply with a positive confirmation response to approve the requested account modification. (Norefors [Column 6, line 32] the user is requested to enter the OTP by the authentication server, 9, over the web server, 10. The user then enters the OTP given by e.g. SMS or a voice message on the first means of the user station (e.g. a PC), and the OTP is via the web server provided to the authentication server, 11, 12. The authentication server then verifies the OTP to see if it is valid. If yes, a message with information to that fact is sent to the web server, 13.) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi with combined teachings of Wittenberg and Wadhwa and by further incorporating Norefors to initiate the process of message generation to issue an OTP at the authentication portal. The motivation of doing so would have enabled the request to generate an OTP that includes the recorded location or the originating IP address to pinpoint the identity of the requester. Regarding Claim 17, the combination of Bakshi, Wittenberg, Wadhwa and Norefors teach the system of claim 12 and Wittenberg further teaches wherein the authentication operations further comprise receiving [the] an Internet Protocol (IP) address and determining the location from the IP address. (Wittenberg [0031, line 5] each time a user logs into a service hosted on computer system 101, the service may capture a record of that login with information including the current time, internet protocol (IP) address, tenant or user identifier, portable unique identifier (PUID), and/or user agent string. The geographic location of a given login may be determined using a geographic IP address database that identifies general geographic areas for IP addresses. [Fig 1, 111] provides location information. [Fig 3, item 320] [Fig 4 and 5]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi with the combined teachings of Wadhwa and Norefors and by further incorporating Wittenberg to determine the location of the IP address and the process of receiving it. The motivation of doing so would have enabled to receive the IP address and the location determination of the said IP address. Claim 5 rejected under 35 U.S.C. 103 as being unpatentable over BAKSHI et al. (US 20210211876 A1, hereinafter Bakshi) in the combined view of Wittenberg et al. (US 20160105801 A1, hereinafter known as Wittenberg) and WADHWA et al. (US 20210065165 A1, hereinafter Wadhwa) and in further view of TRAYNOR et al. (US 20220078184 A1, hereinafter known as Traynor) Regarding Claim 5, the combination of Bakshi, Wittenberg and Wadhwa teach the method of claim 1 but do not teach upon receiving a matching response OTP at the authentication portal, modifying the account in accordance with the account modification and transmitting an SMS notification to the account holder indicating that the account modification has been completed. However, Traynor teaches upon receiving a matching response OTP at the authentication portal, modifying the account in accordance with the account modification and transmitting an SMS notification to the account holder indicating that the account modification has been completed. (Traynor [0035, line 9] the web server 14 sends an SMS message containing a randomly chosen one-time password (OTP) with a short validity period via cellular network 16 using an IP-to-cellular gateway. The browser for the web server 14 then prompts the user to enter the OTP once the message is received. If the input matches what the web server 14 sent within the validity period, which may be a matter of minutes or hours, registration completes and the phone number is associated with a user's account for future authentication) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi in combined teachings of Wittenberg and Wadhwa and by further incorporating Traynor to inform the account holder of the account modification completion via SMS. The motivation of doing so would have enabled method to complete the account modification after receiving OTP and going through account modification steps. Claims 9, 13-15 are rejected under 35 U.S.C. 103 as being unpatentable over BAKSHI et al. (US 20210211876 A1, hereinafter Bakshi) in the combined view of Wittenberg et al. (US 20160105801 A1, hereinafter known as Wittenberg), WADHWA et al. (US 20210065165 A1, hereinafter Wadhwa) and NOREFORS et al. (WO 2004111809 A1, hereinafter Norefors) and in further view of Tomlinson (US 20170213213 A1, hereinafter Tomlinson) Regarding Claim 9, the combination of Bakshi, Wittenberg, Wadhwa and Norefors teach all of claim 2 but fail to teach wherein the location or IP address is a parameter for a generate TempPin command. However, in a similar endeavor, Tomlinson teaches wherein the location or IP address is a parameter for a generate TempPin command. (Tomlinson [0021, line 6] the shared code and private code may each be considered to be a different personal identification number (or PIN code) associated with the client's account.) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi with the combined teachings of Wittenberg, Wadhwa and Norefors and by further incorporating Tomlinson to generate TempPin command. The motivation of doing so would have enabled the IP address to have a parameter for a generate TempPin Command for efficiency and accuracy. Regarding Claim 13, the combination of Bakshi, Wittenberg, Wadhwa and Norefors teach the system of claim 12 but fail to teach SMS delivery service including at least one electronic processor performing delivery operations including transmitting the confirmation request as the first SMS message to the account holder. However, in a similar endeavor, Tomlinson teaches SMS delivery service including at least one electronic processor performing delivery operations including transmitting the confirmation request as the first SMS message to the account holder. (Tomlinson [0043] Processes described herein may be embodied in, and fully automated via, software code modules executed by a computing system that includes one or more general purpose computers or processors. [0037, line 4 and Fig. 4:420, 425] If the shared code matches, the illustrative method proceeds to block 420, where the message generator 126 generates an authorization message (such as an SMS message) for the client, as described above, and sends the message to the client device at block 425.) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi with the combined teachings of Wittenberg, Wadhwa and Norefors and by further incorporating Tomlinson performing delivery operation transmitting confirmation request as the first SMS message to the account holder. The motivation of doing so would have enhanced authentication process thus tightened the security of the account modification. Regarding Claim 14, the combination of Bakshi, Wittenberg Wadhwa, Norefors and Tomlinson teach the system of claim 13 and Bakshi further teaches wherein the identity operations further comprise: upon receiving a negative confirmation response from the account holder, transmitting an SMS notification to the account holder via the SMS delivery service indicating that the requested account modification has been prevented and upon receiving a positive confirmation response from the account holder, permitting the account modification and transmission of the OTP. (Bakshi [0033] When authentication server 130 receives the authentication request, authentication server 130 compares the requested network ID to the network IDs of each authentication entry 132 in authentication server 130. If authentication server 130 cannot find such an authentication entry 132, then authentication server 130 transmits a message to vendor application server 140 indicating that no device associated with the requested network ID has enrolled as a trusted device.) The motivation of doing so would have enabled the account holder to know the exact situation as to when the modification request has been prevented and when to allow. Regarding Claim 15, the combination of Bakshi, Wittenberg, Wadhwa, Norefors and Tomlinson teach the system of claim 13 and Norefors further teaches wherein the identity operations further comprise: upon a passing of a predetermined timeout period from the confirmation request message being transmitted to the account holder without receiving the positive confirmation response or a negative confirmation response, transmitting an SMS notification to the account holder via the SMS delivery service indicating that the requested account modification has been prevented. (Norefors [Column 3, line 4] Advantageously the web server redirects the login message to the access server login page when an account has been created/modified in the authentication server and a timer is set to a given time period during which user credentials are checked, and if they are not valid, an error message is returned to the user. Refer to [Fig 2, items 104, 113]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi with the combined teachings of Wittenberg Tomlinson, Wadhwa and by further incorporating Norefors creating a time slot beyond which account modification would be prevented. The motivation of doing so would have enabled system to prevent an account modification phase for better security. Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over BAKSHI et al. (US 20210211876 A1, hereinafter Bakshi) in view of Wittenberg et al. (US 20160105801 A1, hereinafter known as Wittenberg), WADHWA et al. (US 20210065165 A1, hereinafter Wadhwa) and NOREFORS et al. (WO 2004111809 A1, hereinafter Norefors) and in further view of VINAYAGAM et al. (US 20260045358 A1, hereinafter known as Vinayagam) Regarding Claim 10, the combination of Bakshi, Wittenberg, Wadhwa and Norefors teach all of claim 2 and but do not teach wherein the confirmation flag is a Boolean parameter for a generate TempPin command. However, in a similar endeavor, Vinayagam teaches wherein the confirmation flag is a Boolean parameter for a generateTempPin command. (Vinayagam [0069, line 3] In one or more embodiments, the access parameters 506 can include any alphanumeric characters, a binary value, or any other value. For example, as illustrated, a “Yes” indicates access to the data while a “No” indicates that the data is not accessible by the corresponding user profile 502. In one or more embodiments, a binary “1” or “0” could be used.) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Bakshi with combined teachings of Wittenberg, Wadhwa and Norefors and by further incorporating Vinayagam to create confirmation flag as a Boolean paramenter. The motivation of doing so would have enabled the method to have the confirmation flag being a Boolean parameter for a generate TempPin command. Claims 18-19 are rejected under 35 U.S.C. 103 as being unpatentable over NOREFORS et al. (US 8108903 B2, hereinafter known as Norefors) in combined view of Wittenberg et al. (US 20160105801 A1, hereinafter known as Wittenberg), WADHWA et al. (US 20210065165 A1, hereinafter Wadhwa) and in further view of TRAYNOR et al. (US 20220078184 A1, hereinafter known as Traynor) Regarding Claim 18, Norefors teaches a method comprising: receiving a request from a user having an IP address to perform a requested account modification on an account of an account holder at an authentication portal; (Norefors [Column 3, line 31] for providing said end user station with access to an IP network. [Column 4, line 1] sending a login request to an access server from the user station. Refer to [Fig 2, item 100]) But Norefors does not teach associating the IP address with a location; However, in a similar endeavor, Wittenberg teaches associating the IP address with a location; (Wittenberg [0031, line 10] The geographic location of a given login may be determined using a geographic IP address database that identifies general geographic areas for IP addresses. [Fig 1, 111] provides location information. [Fig 3, item 320] [Fig 4 and 5]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Norefors in view of Wittenberg to identify the location of the IP address of the account holder. The motivation of doing so it to enhance the security process of the account modification. Furthermore, the combination of Norefors and Wittenberg do not teach transmitting a[[n]] first SMS confirmation request to the account holder, wherein the first SMS confirmation request indicates the requested account modification and the location and asks the account holder to provide a positive confirmation response to authorize the requested account modification or a negative confirmation response to prevent the requested account modification; responsive to receiving the positive confirmation response, generating a one-time password (OTP) and transmitting the OTP via a second SMS request to the account holder; However, in a similar endeavor, Wadhwa teaches transmitting a[[n]] first SMS confirmation request to the account holder, wherein the first SMS confirmation request indicates the requested account modification and the location and asks the account holder to provide a positive confirmation response to authorize the requested account modification or a negative confirmation response to prevent the requested account modification; (Wadhwa [0071] At step 5004, responsive to receiving the request for OTP generation, the OTP gateway server 316 initiates transmission of a data message to the user device 302b. The data message initiates an identity verification process flow for ensuring that the user 302a is in fact an individual/entity that is authorized to make payment transactions through the payment card or payment account identified at step 5002. As discussed in connection with FIG. 4, in an embodiment of the invention, the data transmission at step 5004 comprises a short-message-service (SMS)) responsive to receiving the positive confirmation response, generating a one-time password (OTP) and transmitting the OTP via a second SMS request to the account holder; (Wadhwa [0073] As illustrated in FIG. 5, an identity verification decision is generated based on the identity verification process. At step 5008, responsive to a positive identity decision (i.e. responsive to determining that the user 302a is authorized to carry out payment transactions through the payment card or payment account identified at step 5002), an OTP corresponding to the ongoing payment transaction is transmitted for display on the user device 302b. The OTP can thereafter be used by the user 302a in the regular course for completing the ongoing payment transaction. The OTP transmitted for display at step 5008 may be an OTP that has been generated for the transaction by the OTP authentication server 314a.) (Note: Fig 4 404-408 further illustrated these steps in the method) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Norefors and Wittenberg by further incorporating Wadhwa to transmit a first short SMS and request a positive confirmation of identity from the account holder and a second SMS containing OTP to the user device following a positive identity response from the account holder. The motivation would have further enhanced the security of the identity verification. The combination of Norefors, Wittenberg, and Wadhwa do not teach upon validating that [[the]] a response OTP received from a user matches the generated OTP, performing the requested account modification and notifying the account holder via SMS that the requested account modification has been completed. However, in a similar endeavor, Traynor teaches upon validating that [[the]] a response OTP received from a user matches the generated OTP, performing the requested account modification and notifying the account holder via SMS that the requested account modification has been completed. (Traynor [Column 6, line 11] The invention also suggests a method for providing an end user with access to an IP network over an access network comprising an access server. For the login procedure, the method comprises the steps of: - performing a first phase of a login procedure whereby a onetime-password (OTP) is provided by an authentication server and transferred to the end user over a mobile communication system, e.g. by a SMS or voice message. [Column 12, line 4] the user is requested to enter the OTP by the authentication server, 9, over the web server, 10. The user then enters the OTP given by e.g. SMS or a voice message on the first means of the user station (e.g. a PC), and the OTP is via the web server provided to the authentication server, 11, 12. The authentication server then verifies the OTP to see if it is valid. If yes, a message with information to that fact is sent to the web server, 13.) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Norefors in combined teachings of Wittenberg and Wadhwa and in further view of Traynor to match the SMS with the generated SMS so that the account modification process can be completed. The motivation of doing so would have enabled method as to how to receive an account modification request from an account holder from an IP address to authentication process to the completion of the account modification process. Regarding Claim 19, the combination of Norefors, Wittenberg, and Wadhwa teach claim 18 and Traynor further teaches transmitting a request to generate the OTP to an identity authenticator, wherein the request to generate the OTP includes the location or IP address and a confirmation flag indicating that confirmation from the account holder is required to authorize the requested account modification. (Traynor [Column 6, line 11] The invention also suggests a method for providing an end user with access to an IP network over an access network comprising an access server. For the login procedure, the method comprises the steps of: - performing a first phase of a login procedure whereby a onetime-password (OTP) is provided by an authentication server and transferred to the end user over a mobile communication system, e.g. by a SMS or voice message. [Column 12, line 4] the user is requested to enter the OTP by the authentication server, 9, over the web server, 10. The user then enters the OTP given by e.g. SMS or a voice message on the first means of the user station (e.g. a PC), and the OTP is via the web server provided to the authentication server, 11, 12. The authentication server then verifies the OTP to see if it is valid. If yes, a message with information to that fact is sent to the web server, 13) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Norefors in combined teachings of Wittenberg and Wadhwa and in further teaching of Traynor to transmit a message to generate an OTP. The motivation of doing so would have enabled the transmitting of a request to generate the OTP which includes the location or IP address as well as a flag to require authorization from the account holder to modify account. Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over NOREFORS et al. (US 8108903 B2, hereinafter known as Norefors) in combined view of Wittenberg et al. (US 20160105801 A1, hereinafter known as Wittenberg), WADHWA et al. (US 20210065165 A1, hereinafter Wadhwa) and TRAYNOR et al. (US 20220078184 A1, hereinafter known as Traynor) and in further view of BAKSHI et al. (US 20210211876 A1 Regarding Claim 20, the combination of Norefors, Wittenberg, Wadhwa and Traynor teach method claim 19 and Norefors further teaches upon a passing of a predetermined timeout period from the transmitting [[an]] the first SMS confirmation request to the account holder without receiving the positive confirmation response or a negative confirmation response, transmitting an SMS notification to the account holder indicating that the requested account modification has been prevented. (Norefors [Column 3, line 4] Advantageously the web server redirects the login message to the access server login page when an account has been created/modified in the authentication server and a timer is set to a given time period during which user credentials are checked, and if they are not valid, an error message is returned to the user. Refer to [Fig 2, items 104, 113]) The motivation of doing so would have enabled as to how to prevent account modification after receiving a negative confirmation or passing a predetermined timeout period is over. However, the combination of Norefors, Wittenberg, Wadhwa and Traynor do not teach upon receiving the negative confirmation response from the account holder, transmitting an SMS notification to the account holder indicating that the requested account modification has been prevented; However, in a similar endeavor, Bakshi teaches upon receiving the negative confirmation response from the account holder, transmitting an SMS notification to the account holder indicating that the requested account modification has been prevented; (Bakshi [0033] When authentication server 130 receives the authentication request, authentication server 130 compares the requested network ID to the network IDs of each authentication entry 132 in authentication server 130. If authentication server 130 cannot find such an authentication entry 132, then authentication server 130 transmits a message to vendor application server 140 indicating that no device associated with the requested network ID has enrolled as a trusted device.) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Norefors in combined teachings of Wittenberg, Wadhwa and Traynor and in further teaching of Bakshi to have the method prevent account modification after receiving negative confirmation. The motivation of doing so would have further enhance the entire security process so that outside intervention does not happen. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to RANA HASSAN MAHMUD whose telephone number is (571)272-8939. The examiner can normally be reached Mon-Friday. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kathy Wang-Hurst can be reached at 5712705371. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RANA H MAHMUD/Examiner, Art Unit 2644 /KATHY W WANG-HURST/Supervisory Patent Examiner, Art Unit 2644
Read full office action

Prosecution Timeline

May 30, 2024
Application Filed
Apr 23, 2026
Non-Final Rejection mailed — §103
Jul 23, 2026
Response Filed
Sep 17, 2026
Final Rejection mailed — §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
Grant Probability
Moderate
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month