Prosecution Insights
Last updated: August 18, 2026
Application No. 18/756,855

ENHANCED BIOMETRIC MULTIFACTOR AUTHENTICATION FOR TRANSACTIONS

Final Rejection §101§103
Filed
Jun 27, 2024
Examiner
MADAMBA, CLIFFORD B
Art Unit
3692
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
NCR Corporation
OA Round
2 (Final)
44%
Grant Probability
Moderate
3-4
OA Rounds
1y 2m
Est. Remaining
59%
With Interview

Examiner Intelligence

Grants 44% of resolved cases
44%
Career Allowance Rate
291 granted / 658 resolved
-7.8% vs TC avg
Moderate +15% lift
Without
With
+14.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
24 currently pending
Career history
689
Total Applications
across all art units

Statute-Specific Performance

§101
42.8%
+2.8% vs TC avg
§103
37.1%
-2.9% vs TC avg
§102
4.4%
-35.6% vs TC avg
§112
14.7%
-25.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 658 resolved cases

Office Action

§101 §103
DETAILED ACTION Status of Claims The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This action is in reply to the remarks/arguments for Application 18/756,855 filed on 12 May 2026. Claim 1 has been amended. Claims 13-20 are presently withdrawn. Claims 1-20 are currently pending with claims 1-12 have been actively examined. Response to Arguments A. Claim Rejections – 35 U.S.C. § 101: Claims 1-20 stand rejected under U.S.C. § 101 as being directed to non-statutory subject matter. 1. Applicant argues that the claim is directed to a practical application. Examiner respectfully disagrees. The judicial exception is not integrated into a practical application because, when analyzed under prong two of step 2A, the additional elements of the claim such as a “user-operated device”, “terminal”, “cloud server”, represent the use of a computer as a tool to perform an abstract idea and/or does no more than generally apply the abstract idea to a particular field of use. Therefore, the additional elements do not integrate the abstract idea into a practical application as they do no more than represent a computer performing functions that correspond to (i.e. automate) implement the acts of using rules and/or instructions to facilitate a transaction in an automatic manner comprising the steps of merely collecting (“receiving a registration request”), computing (“generating a facial signature” … and … “hash value”), transmitting (“receiving … images”), comparing (“verifying … facial signature matches”), and relaying (“sending a message”) data/information associated with a commercial and/or financial transaction. Applicant’s argument is therefore unpersuasive. 2. Applicant argues that the claimed invention constitutes a technical improvement to computer-implemented biometric authentication systems. Examiner respectfully disagrees. There is no actual improvement made to the operations or physical structure of the additional elements claimed. There are no actual improvements to another technology or technical field, no improvements to the functioning of the computer itself, and there are no meaningful limitations beyond generally applying the use of the abstract idea to a particular technological environment evident in the claims. Applicant’s argument is therefore unpersuasive. 3. Applicant argues that the analysis under Step 2B is inapplicable as the claim integrates any exception into a practical application. Examiner respectfully disagrees. When analyzed under step 2B, the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception itself. Viewed as a whole, the combination of elements recited in the claims merely describe the concept of using rules and/or instructions to facilitate a transaction in an automatic manner comprising the steps of merely collecting (“receiving a registration request”), computing (“generating a facial signature” … and … “hash value”), transmitting (“receiving … images”), comparing (“verifying … facial signature matches”), and relaying (“sending a message”) data/information associated with a commercial and/or financial transaction using computer computer-related technology and/or devices that merely perform as designed to function. Therefore, the use of these additional elements does no more than employ a computer as a tool to automate and/or implement the abstract idea, which cannot provide significantly more than the abstract idea itself (MPEP 2106.05(I)(A)(f) & (h)). Hence, claim 1 is not patent eligible. Applicant’s argument is therefore unpersuasive. The rejection is therefore maintained. B. Claim Rejections – 35 U.S.C. § 103: Claims 1-20 stand rejected under 35 U.S.C. 103 as being unpatentable over Beigi, US 2015/0347734 A1 (“Beigi”), in view of Nagalla, US 10,346,675 B1 (“Nagalla”). The Office herein gives consideration to the remarks and/or amendments made to the pending set of amended claims, but are considered moot in light of the new grounds of rejection provided below, for the current listing of amended claims. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. In the instant case, representative method claim 1 is directed towards facilitating biometric multi-factor authentication associated with a commercial and/or financial activity. Claim 1 recites the abstract idea of using rules and/or instructions to facilitate a transaction in an automatic manner comprising the steps of merely collecting (“receiving a registration request”), computing (“generating a facial signature” … and … “hash value”), comparing (“verifying … facial signature matches”), and relaying (“sending a message”) data/information associated with a commercial and/or financial transaction, which is grouped under the certain methods of organizing human activity – fundamental economic principles, practices or concepts; sales activity; following set of instructions; commercial interactions (business relations); managing personal behavior of relationships or interactions between people (including social activities, teachings, following rules or instructions) as well as mathematical concepts – mathematical relationships, inasmuch as the claimed method as a whole is directed towards facilitating utilizing a mathematical model to perform calculations (e.g., hash value) utilizing an algorithm, but for the recitation of computer-related components. Other than the mere nominal recitation of a computer-related device – nothing in the claim element precludes the steps from the organizing human interactions and mathematical concepts groupings grouping, in prong one of step 2A. Accordingly, for these reasons, the claim recites an abstract idea. Claim 1 recites: “receiving, from a user-operated device of a user, a registration request, wherein the registration request including images depicting a face of the user and at least two actions being performed by the user; generating a facial signature for the face depicted in the images and at least one hash value based on the at least two actions depicted in the images; storing, in a non-transitory computer-readable storage medium of a cloud server, the facial signature and the at least one hash value in a record indexed on the facial signature; receiving, from a terminal, second images of the user for a transaction; generating a candidate facial signature and at least one candidate hash value from the second images which depict the face and at least two candidate actions performed by the user; searching the record stored in the non-transitory computer-readable storage medium using the candidate facial signature to locate a registered user record, and providing an authentication failed message when no registered user record is located; verifying the candidate facial signature matches the facial signature and the at least one candidate hash value matches the at least one hash value; and sending a message to the terminal based on the verifying, wherein the message including an authentication successful message or an authentication failed message.” Based on the underlined elements above, abstract ideas and/or concepts are identified. Accordingly, the claim recites an abstract idea. This judicial exception is not integrated into a practical application because, when analyzed under prong two of step 2A, the additional elements of the claim such as a “user-operated device”, “terminal”, “cloud server”, represent the use of a computer as a tool to perform an abstract idea and/or does no more than generally apply the abstract idea to a particular field of use. Therefore, the additional elements do not integrate the abstract idea into a practical application as they do no more than represent a computer performing functions that correspond to (i.e. automate) implement the acts of using rules and/or instructions to facilitate a transaction in an automatic manner comprising the steps of merely collecting (“receiving a registration request”), computing (“generating a facial signature” … and … “hash value”), transmitting (“receiving … images”), comparing (“verifying … facial signature matches”), and relaying (“sending a message”) data/information associated with a commercial and/or financial transaction. When analyzed under step 2B, the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception itself. Viewed as a whole, the combination of elements recited in the claims merely describe the concept of using rules and/or instructions to facilitate a transaction in an automatic manner comprising the steps of merely collecting (“receiving a registration request”), computing (“generating a facial signature” … and … “hash value”), transmitting (“receiving … images”), comparing (“verifying … facial signature matches”), and relaying (“sending a message”) data/information associated with a commercial and/or financial transaction using computer computer-related technology and/or devices that merely perform as designed to function. Therefore, the use of these additional elements does no more than employ a computer as a tool to automate and/or implement the abstract idea, which cannot provide significantly more than the abstract idea itself (MPEP 2106.05(I)(A)(f) & (h)). Hence, claim 1 is not patent eligible. Independent claim 12 recites substantially the same limitations and/or subject matter as claim 1 above and is ineligible for the same reasons. The subject matter of claim 12 corresponds to the subject matter of claim 1 in terms of a method (e.g., process). Therefore the reasoning provided for claim 1 applies to claim 12 accordingly. Independent claim 18 recites substantially the same limitations and/or subject matter as claim 1 above and is ineligible for the same reasons. The subject matter of claim 18 corresponds to the subject matter of claim 1 in terms of a system (e.g., machine). Therefore the reasoning provided for claim 1 applies to claim 18 accordingly. Dependent claims 2-11, 13-17 and 19-20 add further details and contain limitations that narrow the scope of the invention. However, these details do not result in significantly more than the abstract idea itself. As explained in the December 16, 2014 Interim Eligibility Guidance from the USPTO (in reference to the BuySAFE, Inc. v. Google, Inc. decision), further narrowing the details of an abstract idea does not change the § 101 analysis since a more narrow abstract idea does not make it any less abstract. Viewed individually and in combination, these additional elements do not provide meaningful limitations to transform the abstract idea such that the claims amount to significantly more than the abstraction itself. Accordingly, the present pending claims are not patent eligible and are rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter. Claim Rejections – 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office Action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Beigi, US 2015/0347734 A1 (“Beigi”), in view Maizels et al., US 2024/0070251 A1(“Maizels”), in view of Nagalla, US 10,346,675 B1 (“Nagalla”). Re Claim 1: (Currently Amended) Beigi discloses a method, comprising: A method, comprising: receiving, from a user-operated device of a user, a registration request, wherein the registration request including images depicting a face of the user and at least two actions being performed by the user; (2.1 The Enrollment and/or Registration Stage; ¶[0154]: “When the phone is registered ( or at some later time), the owner of the device does a biometric enrollment and the model/models is/are built and stored on the device. These models are generally representations of the features of the specific biometric of interest.”; ¶[0019]: “For the second factor (knowledge of a fact), as an example, a challenge in the form of a traditional passcode may be requested, in which case it is usually typed in, or depending on the available input devices, preselected or predefined facial expressions (for cameras), natural language understanding or a repeated phrase, through a speech recognizer for a microphone input, a handwritten signature such as described by [4] used with a touchpad or a pen may be used along with other methods …”: ¶[0020]: “For the third factor (something one is), biometric techniques are used. Many different biometric methods may be used, such as those listed in Section 1.3. Some such techniques are Speaker Recognition, Image-Based or Audio Based Ear Recognition, Face Recognition, Fingerprint Recognition, Palm Recognition, Hand-Geometry Recognition, Iris Recognition, Retinal Scan, Thermographic Image Recognition, Vein Recognition, Signature Verification …”) generating a facial signature for the face depicted in the images and at least one hash value based on the at least two actions depicted in the images; (¶[0025]: “FIG.1 describes the process of registering the essential authentication data such as the digest (hash) of the subscriber ID, biometric models, and the binary code of the software being run with certificate authorities. This is the process that takes place once, either when the user has first activated the device or once for each new security level and access credential which is added.”; ¶[0183]: “FIG. 11 shows the validation process for the reference data. At the time of each transaction where authentication is necessary, this process of validation takes place. The data is retrieved from the persistent memory of the device and is decrypted to get the signed hash values of the different reference data. Then the original reference data is retrieved by the authentication application from the persistent memory of the device and is hashed in the same manner as it was done in the hashing step of the registration defined in Section 2.4. These two sets of hash values are then compared as prescribed by FIG. 11 to see if they match.”) With regard to the limitation(s) comprising: storing, in a non-transitory computer-readable storage medium of a cloud server, the facial signature and the at least one hash value in a record indexed on the facial signature; Maizels however, makes these teachings in a related endeavor ([0156] “… system may include a cloud server”; [0297] “In some embodiments, cloud server 122 may also be configured to verify the identity of the individual based on the received signals. In some embodiments, an authentication service provider ( or an identity verification service provider) may use a system, such as server 122, for providing identity verification of the individual based on the individual's facial micromovements”; [0779] “… data structure may reside in a database accessible by the server in the cloud”; [0317] “…an encrypted version of the signature may be stored in the secure data structure. A "hash" of the received reference signal may be stored as the correlation in some embodiments. As would be recognized a person of ordinary skill in the art, a hash is a unique digital signature generated from an input signal ( e.g., the received reference signals reference signals) using, for example, commercially available algorithms. A hashed/encrypted signature of the individual may be stored as the correlation …”; [0371] “In some embodiments, a "hash" of an individual's facial skin micromovements may be stored as the reference facial skin micromovements of that individual.”; [0392] “in some embodiments, the third signals 1908 may be compared with the previously received second signals 1906 and/or first signals 1902 to determine if the third signals 1908 are associated with the same individual as the first and second signals … system may store the received third facial skin micromovements signals (or an encrypted hash or signature of these signals”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Maizels with the invention of Beigi as described above for the motivation of enhancing authentication certainty through the matching of neuromuscular activity. With regard to the limitation(s) comprising: receiving, from a terminal, second images of the user for a transaction; Nagalla however, makes these teachings in a related endeavor (Abstract: “The method prompts the user via a facial gesture cue to make a facial gesture, captures a second facial image of the user, and compares the second image with stored facial gesture credentials. The user is authorized to perform a transaction in the event the first facial image matches a facial recognition credential for an authorized account, and the second facial image matches a facial gesture credential associated with the authorized account.”; FIG. 2: “210 Capture by imaging sensor of user terminal, second imaging data including second facial image of user following the display of facial gesture cue”; C2 L44-47: “The method prompts the user via a facial gesture cue to make a facial gesture, captures a second facial image of the user, and compares the second image with stored facial gesture credentials.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Nagalla with the invention of Beigi as described above for the motivation of facilitating authentication of individuals engaging in transactions in a secure manner. Beigi further discloses: generating a candidate facial signature and at least one candidate hash value from the second images which depict the face and at least two candidate actions performed by the user; (¶[0025]: “FIG.1 describes the process of registering the essential authentication data such as the digest (hash) of the subscriber ID, biometric models, and the binary code of the software being run with certificate authorities. This is the process that takes place once, either when the user has first activated the device or once for each new security level and access credential which is added.”; ¶[0183]: “FIG. 11 shows the validation process for the reference data. At the time of each transaction where authentication is necessary, this process of validation takes place. The data is retrieved from the persistent memory of the device and is decrypted to get the signed hash values of the different reference data. Then the original reference data is retrieved by the authentication application from the persistent memory of the device and is hashed in the same manner as it was done in the hashing step of the registration defined in Section 2.4. These two sets of hash values are then compared as prescribed by FIG. 11 to see if they match.”) With regard to the limitation(s) comprising: searching the record stored in the non-transitory computer-readable storage medium using the candidate facial signature to locate a registered user record, and providing an authentication failed message when no registered user record is located; Maizels however, makes these teachings in a related endeavor ([0355] “cloud server 122 may also notify the institution and/or another person/entity the results of the comparison …”; [0251] “Authorizing a transaction refers to the process of granting approval or permission for an activity to occur. In some cases, authorizing a transaction may involve verifying the legitimacy of a transaction request and confirming the identity of an individual by finding a match … When a match is not found, information may be provided to indicate that the transaction is not authorized. The information may be provided via a speech detection system or via a mobile communications device”; [0303] “when an individual engages in a transaction (e.g., attempts to access a customer's account) with the institution 1400, the institution 1400 may request 1506 the authentication service provider ( or system 1500) to authenticate the individual (e.g., verify the identity of the individual, confirm that the individual is the customer associated with the account, etc.). System 1500 may receive real-time facial micromovement signals 1508 of the individual when the individual is engaged in the transaction, and the system 1500 may compare 1512 the received real-time signals 1508 with the stored reference signals 1502 or correlations 1504 to determine whether the individual is a customer”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Maizels with the invention of Beigi as described above for the motivation of enhancing authentication certainty through the matching of neuromuscular activity. Beigi further discloses: verifying the candidate facial signature matches the facial signature and the at least one candidate hash value matches the at least one hash value; (¶[0183]: “These two sets of hash values are then compare as prescribed by FIG. 11 to see if they match. If they match …”) sending a message to the terminal based on the verifying, wherein the message including an authentication successful message or an authentication failed message. (¶[0071]: “FIG. 33 shows a scenario in which the user has forgotten to enter the required PIN. An error message is displayed to alert the user to make sure a valid PIN is entered.”; ¶[0167]: “The PDA owner receives notification for the transaction plus the challenge information.”; ¶[0238]: “Each time there is a successful authentication, a counter (Figure component 87) is incremented by the authentication software. Once the minimum number of matches (Figure component 88) has been achieved, before getting to the maximum number of tests which are defined by the administration, access is granted to the group of people who have authenticated.”) Re Claim 2: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. With regard to the limitation comprising: utilizing the message as a front-end security layer for a third-party payment service, wherein the third-party payment service performs automatic payment transaction based on a verified facial signature of the user. Nagalla however, makes these teachings in a related endeavor (C8 L20-24: “An authorized transaction can include one or more banking transaction including withdrawing cash, depositing money, making a payment, effecting a money transfer, and providing account information for the authorized user's account.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Nagalla with the invention of Beigi as described above for the motivation of facilitating authentication of individuals engaging in transactions in a secure manner. Re Claim 3: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. Beigi further discloses: identifying a sequence with which the user performs the at least two actions from the images and enforcing the sequence during the verifying. (¶[0019]: “For the second factor (knowledge of a fact), as an example, a challenge in the form of a traditional passcode may be requested, in which case it is usually typed in, or depending on the available input devices, preselected or predefined facial expressions (for cameras), natural language understanding or a repeated phrase, through a speech recognizer for a microphone input, a handwritten signature such as described by [4] used with a touchpad or a pen may be used along with other methods …”: ¶[0020]: “For the third factor (something one is), biometric techniques are used. Many different biometric methods may be used, such as those listed in Section 1.3. Some such techniques are Speaker Recognition, Image-Based or Audio Based Ear Recognition, Face Recognition, Fingerprint Recognition, Palm Recognition, Hand-Geometry Recognition, Iris Recognition, Retinal Scan, Thermographic Image Recognition, Vein Recognition, Signature Verification …”) Re Claim 4: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. With regard to the limitation comprising: receiving a modification request from the user-operated device comprising additional images depicting the user performing the at least two actions in a different sequence or performing different actions; and processing the generating of the facial signature and the at least one hash value to update one or more of the facial signature and the at least one hash value. Nagalla however, makes these teachings in a related endeavor (C11 L3-11: “In another example, API's may be used by authorized users of the financial institution to update previously established facial recognition credential records 142, facial gesture credential records 144, and secondary biometric credential records 146. Authorized users may set up user credential records that serve as user-supplied information for authenticating access to a user's account; and users may update user credential records much as customers of financial institutions may update passwords.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Nagalla with the invention of Beigi as described above for the motivation of facilitating authentication of individuals engaging in transactions in a secure manner. Re Claim 5: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. Beigi further discloses: receiving a deletion request from the user-operated device; and deleting the facial signature and the at least one hash value to deregister the user from multiple factor biometric authentication services provided by the method. (¶[0077]: “In addition, every database record has a Deactivate binary input. When it is set to "No", then the record is active, hence it is usable in authentication and other references. If it is set to "Yes", then the record is deactivated and it is treated as a deleted record.”) Re Claim 6: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. Beigi further discloses: wherein receiving the registration request further includes identifying the at least two actions depicted in the images as facial expressions, user hand gestures, or a combination thereof. (¶[0019]: “For the second factor (knowledge of a fact), as an example, a challenge in the form of a traditional passcode may be requested, in which case it is usually typed in, or depending on the available input devices, preselected or predefined facial expressions (for cameras), natural language understanding or a repeated phrase, through a speech recognizer for a microphone input, a handwritten signature such as described by [4] used with a touchpad or a pen may be used along with other methods …”: ¶[0020]: “For the third factor (something one is), biometric techniques are used. Many different biometric methods may be used, such as those listed in Section 1.3. Some such techniques are Speaker Recognition, Image-Based or Audio Based Ear Recognition, Face Recognition, Fingerprint Recognition, Palm Recognition, Hand-Geometry Recognition, Iris Recognition, Retinal Scan, Thermographic Image Recognition, Vein Recognition, Signature Verification …”) Re Claim 7: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. Beigi further discloses: wherein verifying further includes enforcing a time frame within which the at least one candidate hash value has to be matched to the at least one hash value and if not matched providing the authentication failed message to the sending. (¶[0104]: “preselected facial gestures have been chosen by the user which need to be enacted at the test or verification time, in order for the person to be authenticated.”) Re Claim 8: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. Beigi further discloses: wherein verifying further includes enforcing a sequence associated with the at least two candidate actions depicted in the second images and when the sequence is not detected providing the authentication failed message to the sending. (¶[0078]: “MatchesRequested designates the minimum number of successful authentication matches done in sequence to allow access. That is 88 in the Figures. Once the value of the number of successful matches, 87 reaches this value, access is granted.”) Re Claim 9: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. Beigi further discloses: wherein verifying further includes providing an authentication failed message to the sending when candidate facial signature does not match the facial signature. (¶[0071]: “FIG. 33 shows a scenario in which the user has forgotten to enter the required PIN. An error message is displayed to alert the user to make sure a valid PIN is entered.”; ¶[0167]: “The PDA owner receives notification for the transaction plus the challenge information.” Re Claim 10: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. Beigi further discloses: wherein verifying further includes providing real-time feedback messages to the terminal as each of the candidate facial signature and the at least one hash value are successfully or unsuccessfully matched. (¶[0067]: “FIG. 29 shows a tablet device with an interface for inputting a PIN, accepting a speaker recognition audio input, a face recognition video capture, and the means for displaying a random string to be used for liveness testing through speech recognition. It also shows feedback on whether access has been granted or denied and the number of people who have matched the authentication procedure for this specific access control session and the total number of such authentications that need to be successfully performed.”) Re Claim 11: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. Beigi further discloses: wherein verifying further includes verifying that a particular candidate hash value for a particular second action of the user depicted in the second images matches a particular hash value and sending a second message to the terminal, wherein the second message including a loyalty authentication successful message or a loyalty authentication failed message. (¶[0071]: “FIG. 33 shows a scenario in which the user has forgotten to enter the required PIN. An error message is displayed to alert the user to make sure a valid PIN is entered.”; ¶[0167]: “The PDA owner receives notification for the transaction plus the challenge information.” Re Claim 12: (Original) Beigi in view of Maizels in view of Nagalla discloses the method of claim 1. Beigi further discloses: wherein verifying further includes verifying that at least two additional candidate hash values for remaining second actions of the user depicted in the second images matches at least one remaining hash value and providing the authentication successful message or the authentication failed message to the sending. (¶[0071]: “FIG. 33 shows a scenario in which the user has forgotten to enter the required PIN. An error message is displayed to alert the user to make sure a valid PIN is entered.”; ¶[0167]: “The PDA owner receives notification for the transaction plus the challenge information.” Re Claims 13 – 20 : (Withdrawn) Conclusion The prior art(s) made of record and not relied upon is/are considered pertinent to applicant's disclosure. Meikle, SR. (US 2024/0281811 A1) discloses a system and method for biometric payment. The system and methods disclosed provide a platform system, including software, and a backend system to conduct financial transactions, particularly biometric payments. The biometric payment platform system distinctly leverages biometric technology, such as facial recognition, to automatically verify the user's identity, access a digital asset, namely a digital wallet, that is specific to the user, and proceed with the payment (or other financial transaction). The platform also enables users, and vendors/business, to perform other financial transactions related to their digital asset, including transferring funds, withdrawing funds, and depositing funds. The platform provides convenient and secure financial transactions, without the user having to remember passwords, carry physical cards ( e.g., debit card, credit card, etc.) or wallets, or even carry their own smartphone. Hecker et al. (US 2019/0166119 A1) discloses security gesture authentication. Hecker discloses wherein real-time facial recognition is augmented with an additional second biometric-based security gesture authentication. Facial biometric authentication is performed on a user for access to a resource. When facial authentication is successful, an image or a video of the user is captured performing a security gesture. Pixel values from the image or video are compared against expected pixel values for the security gesture and when the comparison is within a threshold, the user is provided access to the resource. Claims 1-20 are rejected. THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Clifford Madamba whose telephone number is 571-270-1239. The examiner can normally be reached on Mon-Thu 7:30-5:00 EST Alternate Fridays. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ryan Donlon, can be reached at 571-272-3602. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CLIFFORD B MADAMBA/Primary Examiner, Art Unit 3692
Read full office action

Prosecution Timeline

Jun 27, 2024
Application Filed
Dec 27, 2025
Non-Final Rejection (signed) — §101, §103
Feb 12, 2026
Non-Final Rejection mailed — §101, §103
May 12, 2026
Response Filed
Jul 14, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12700033
GASLESS DECENTRALIZED TOKEN SWAPS
2y 5m to grant Granted Aug 04, 2026
Patent 12688495
Vehicle and Control Method of Vehicle
2y 3m to grant Granted Jul 21, 2026
Patent 12664581
BIDDING SYSTEM AND METHOD BASED ON BLOCKCHAIN TECHNOLOGY
3y 0m to grant Granted Jun 23, 2026
Patent 12629956
CARD AND METHOD OF PRODUCING THE CARD
2y 0m to grant Granted May 19, 2026
Patent 12626248
METHOD FOR SIGNING APPLICATION, AND SERVICE PLATFORM
1y 10m to grant Granted May 12, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
44%
Grant Probability
59%
With Interview (+14.9%)
3y 4m (~1y 2m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 658 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month