Prosecution Insights
Last updated: July 31, 2026
Application No. 18/902,675

DYNAMICALLY TRUSTED ENDPOINTS

Final Rejection §102
Filed
Sep 30, 2024
Priority
Oct 02, 2023 — provisional 63/587,412
Examiner
DESROSIERS, EVANS
Art Unit
2491
Tech Center
2400 — Computer Networks
Assignee
Vercrio Inc.
OA Round
2 (Final)
83%
Grant Probability
Favorable
3-4
OA Rounds
1y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
861 granted / 1039 resolved
+24.9% vs TC avg
Strong +23% interview lift
Without
With
+22.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
20 currently pending
Career history
1065
Total Applications
across all art units

Statute-Specific Performance

§101
2.3%
-37.7% vs TC avg
§103
78.6%
+38.6% vs TC avg
§102
9.3%
-30.7% vs TC avg
§112
1.8%
-38.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1039 resolved cases

Office Action

§102
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claims 1-23 remain for examination. Applicant's arguments filed on 03/17/2026 have been fully considered but they are not persuasive. The rejections are maintained and incorporated by reference the last Office action on 12/19/2025. Accordingly, this action has been made final. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-23 is/are rejected under 35 U.S.C. 102(1)(2) as being anticipated by Griffin U.S. Patent Application Publication No. 20200082108 A1 (hereinafter "Griffin"). As to claim 1, Griffin teaches a method for preventing an Adversary in the Middle (AiTM) attack on deployed Multi-Factor Authentication (MFA) system, the method comprising (Griffin Pa. [0016]) [This information can then be used in a multifactor risk based authentication system to streamline client access while still providing security]: collecting Internet Protocol (IP) addresses for electronic devices associated with a plurality of users and store the IP addresses in a database (Griffin Pa. [0004]) [The data store is configured to store a plurality of stored IP addresses from which users have made requests to access the stored data]; receiving a request for authentication for a user from a first electronic device; acquiring the IP addresses associated with first electronic device (Griffin Pa. [0007]) [determining an authentication level for a user based on an IP address of the request to access data]; determining whether the IP address associated with the first electronic device matches an IP address associated with an electronic device associated with the user from the database (Griffin Pa. [0054]) [The authentication level module 112 may compare the IP address with stored IP addresses in the data store module 108. The authentication level module 112 may determine that the IP address matches (e.g., exact match or determined match) one of the stored IP addresses]; and proceeding with an authentication process for the user in response to a match between the IP address associated with the first electronic device and the IP address associated with the electronic device associated with the user from the database (Griffin Pa. [0058]) [The authentication level module 112 may determine that the IP address associated with the requesting device 130 matches a stored IP address in data store module 108. The authentication level module 112 may determine that the requesting device 130 can authenticate at the second authentication level and increment the value associated with the IP address] As to claim 2, Griffin teaches further comprising rejecting the request for authentication (Griffin Pa. [0016]) [can determine when a given IP address should not be used for authentication] in response to a mismatch between the IP address associated with the first electronic device and the IP address associated with the electronic device associated with the user from the database (Griffin Claim 17) [determining that the IP address does not match the stored IP address by lacking a match of at least a portion of the IP address with a portion of the stored IP address] [0015] [are technologies that help measure authentication risk from different perspectives. Many “bad” IP locations can be tracked and blocked by automated systems via black lists] As to claim 3, Griffin teaches further comprising: generating an allow list based on the IP addresses associated with the plurality of users (Griffin Pa. [0013]) [a list of IP addresses can be stored and updated. The list can be updated to include a new IP address when a user from a plurality of users attempts to access data that is accessible via an IP network]; determining whether the IP address associated with first electronic device is on the allow list; and proceeding with authentication for the user in response to a determination that the IP address associated with the first electronic device is on the allow list (Griffin Pa. [0042]) [the authentication level module and authentication systems of the network device can have access to a full spectrum of account-based traffic across all originating IP addresses. The combination of this information can then be used to measure relative authentication risk upon connection. In other words, an IP address list may look like the following] As to claim 4, Griffin teaches wherein determining whether the IP address associated with the first electronic device matches the IP address associated with an electronic device associated with the user from the database is performed in response to a determination that the IP address associated with the first electronic device is not on the allow list (Griffin Pa. [0054]) [The authentication level module 112 may determine that the IP address matches (e.g., exact match or determined match) one of the stored IP addresses. The authentication level module may compare other aspects of the identifying information, such as the browser settings with stored browser settings associated with the stored IP address that matched the IP address.] As to claim 5, Griffin teaches wherein the allow list is configurable by system administration (Griffin Pa. [0006]) [The credential authentication system includes a data store configured to store a plurality of user authentication credentials and a credential verification module] As to claim 6, Griffin teaches further comprising: determining whether a certificate is present in the request for authentication; proceeding with the authentication process for the user in response to a determination that the certificate is present in the request for authentication; and authenticating the user and uploading a certificate to the first electronic device in response to a determination that the certificate is not present in the request for authentication (Griffin Pa. [0027]) [the credential verification module 119 may authenticate a request from the requesting device 130 based on the IP address and submission of a user credential (i.e., username/password combination, digital certificate, etc.). I] As to claim 7, Griffin teaches wherein authenticating the user comprises sending a request for authorization of the first electronic device to the electronic device associated with the user from the database (Griffin Pa. [0007]) [determining an authentication level for a user based on an IP address of the request to access data] As to claim 8, Griffin teaches further comprising rejecting the request for authentication in response to a rejection of the request for authorization from the user via electronic device associated with the user (Griffin Claim 17) [determining that the IP address does not match the stored IP address by lacking a match of at least a portion of the IP address with a portion of the stored IP address] [0015] [are technologies that help measure authentication risk from different perspectives. Many “bad” IP locations can be tracked and blocked by automated systems via black lists] As to claim 9, Griffin teaches wherein authenticating the user comprises the determining whether the IP address associated with the first electronic device matches the IP address associated with the electronic device associated with the user from the database (Griffin Pa. [0054]) [The authentication level module 112 may determine that the IP address matches (e.g., exact match or determined match) one of the stored IP addresses. The authentication level module may compare other aspects of the identifying information, such as the browser settings with stored browser settings associated with the stored IP address that matched the IP address.] As to claim 10, claim 10 recites the claimed that contain respectively similar limitations as claims 1-9; therefore, it is rejected under the same rationale. As to claim 11, Griffin teaches further comprising sending an instruction to the user via the electronic device associated with the user to reinitiate the request for authentication for the user on the first electronic device after the certificate is sent to the first electronic device (Griffin Pa. [0027]) [The data storage 117 may be configured to store multiple user credentials (e.g., username/password combinations, user certificates, digital signatures, etc.). The credential verification module 119 may perform authentication according to the authentication level determined by the authentication determination subsystem 114.] As to claim 12, Griffin teaches further comprising rejecting the request for authentication in response to a rejection of the request to add the certificate to the first electronic device (Griffin Pa. [0027]) [The data storage 117 may be configured to store multiple user credentials (e.g., username/password combinations, user certificates, digital signatures, etc.). The credential verification module 119 may perform authentication according to the authentication level determined by the authentication determination subsystem 114.] As to claim 13, claim 13 recites the claimed that contain respectively similar limitations as claim 1; therefore, it is rejected under the same rationale. As to claim 14, claim 14 recites the claimed that contain respectively similar limitations as claims 1-9; therefore, it is rejected under the same rationale. As to claim 15, claim 15 recites the claimed that contain respectively similar limitations as claim 10; therefore, it is rejected under the same rationale As to claim 16, claim 16 recites the claimed that contain respectively similar limitations as claim 11; therefore, it is rejected under the same rationale As to claim 17, claim 17 recites the claimed that contain respectively similar limitations as claims 1-10; therefore, it is rejected under the same rationale. As to claim 18, claim 18 recites the claimed that contain respectively similar limitations as claims 1-5; therefore, it is rejected under the same rationale. As to claim 19, claim 19 recites the claimed that contain respectively similar limitations as claim 3; therefore, it is rejected under the same rationale. As to claim 20, claim 20 recites the claimed that contain respectively similar limitations as claim 4; therefore, it is rejected under the same rationale. As to claim 21, claim 21 recites the claimed that contain respectively similar limitations as claim 10; therefore, it is rejected under the same rationale. As to claim 22, claim 22 recites the claimed that contain respectively similar limitations as claim 1; therefore, it is rejected under the same rationale. As to claim 23, claim 23 recites the claimed that contain respectively similar limitations as claims 1-10; therefore, it is rejected under the same rationale. Response to Arguments Arguments It is argued that In order to anticipate a claim under 35 U.S.C. § 102, every element of the claim must be disclosed in a single reference.1 The exclusion of a claimed element, no matter how insubstantial or obvious, from a prior art reference is enough to negate anticipation under 35 U.S.C. § 102.2 Thus, for a proper showing that Griffin anticipates these claims, "every element and limitation of the claimed invention must be found" in Griffin. Furthermore, the claim elements found in a single reference must be "arranged as in the claim."3 See also MPEP § 2131 ("The elements must be arranged as required by the claim."). For reasons discussed below, Griffin fails to disclose one or more elements of claim 1, and therefore Applicant's claim 1 is patentable over Griffin. As an initial matter, Griffin fails to disclose or suggest "A method of preventing an Adversary in the Middle (AiTM) attack on deployed Multi-Factor Authentication (MFA) system," as recited in the preamble of claim 1. Applicant notes that the preamble is limiting, as it gives "life, meaning, and vitality" to the claim by defining the scope, e.g., acting as a constraint to provide specific context for the method, as opposed to simply stating an intended use. See, MPEP §2111.02. The Examiner alleges that Griffin discloses this feature of Applicant's claim 1. Specifically, the Examiner cites paragraph [0016] of Griffin as stating "This information can then be used in a multifactor risk based authentication system to streamline client access while still providing security." Applicant respectfully disagrees. Griffin's disclosure at paragraph [0016] that "information can [] be used in a multifactor risk based authentication system to streamline client access" is not the same as "preventing an Adversary in the Middle (AiTM) attack ..." as recited. There is no explicit or implicit disclosure of preventing an Adversary in the Middle (AiTM) attack in paragraph [0016] or elsewhere in Griffin. For example, the disclosure of Griffin is directed to an entirely different problem and solution than "preventing an Adversary in the Middle (AiTM) attack on deployed Multi-Factor Authentication (MFA) system." Griffin describes using an originating IP address and an IP address counter that tracks requests by a user to access data from that or a different IP address "to determin[e] an authentication level ... to be used to authenticate the user that is making the request to access the data." See, paragraph [0004], [0010], [0011], and FIG. 2. Griffin is directed to determining an appropriate authentication level for a user. It does not explicitly or tracks requests by a user to access data from that or a different IP address "to determin[e] an authentication level ... to be used to authenticate the user that is making the request to access the data." See, paragraph [0004], [0010], [0011], and FIG. 2. For example, paragraph [0057] of Griffin states "the authentication level module 112 may select a first authentication level based on the value associated with the IP address," whereas paragraph [0058] states "In another example, the authentication level module 112 may select a second authentication level based on matching the IP address with a recorded IP address from a previous authentication of the user." Thus, Griffin is determining which authentication level is to be used based on the IP address, and discloses that selecting the "second authentication level" when the IP address matches with a recorded IP address from a previous authentication of the user. In contrast, the claim recites "proceeding with an authentication process for the user in response to a match between the IP address associated with the first electronic device and the IP address associated with the electronic device associated with the user from the database." "Proceeding with an authentication process ... in response [to an IP address match]" is not the same as Griffin's selection of a "second authentication level based on matching the IP address" in paragraph [0058]. To place the claim element of "proceeding with an authentication process for the user in response to a match ..." in proper context, claim 1 requires a sequence that includes 1) collect and store IP addresses associated with a plurality of users, 2) receive a request for authentication from a first electronic device, 3) acquire the IP address of that first electronic device, 4) determine whether that IP address "matches an IP address associated with an electronic device associated with the user," and 5) in response to a match, "proceeding with an authentication process for the user." In the context of this claim, the element of "proceeding with an authentication process for the user in response to [an IP address] match ..." operates as a pre- multifactor authentication (MFA) gate that is used to prevent an Adversary in the Middle (AiTM) attack. In other words, the system proceeds with the authentication process for the user if the initiating device's IP address matches an IP address associated with the user. Griffin has no such disclosure. The selection of an authentication level based on matching the IP address, e.g., in paragraph [0058] is not a gate that controls whether "an authentication process" proceeds, as required by Applicant's claims. Instead, Griffin always proceeds with some form of authentication. Griffin, for example, discloses using either aSer. No.: 18/90 "standard authentication" level (FIG. 2, blocks 206/214; [0011]) or a "step up authentication" level (Fig. 2, blocks 210/218). The elements disclosed in Griffin are not "arranged as in the claim"4 and accordingly, Griffin fails to anticipate claim 1. Accordingly, because Griffin fails to disclose the above-identified elements, and Griffin fails to disclose the claim elements, as arranged in the claim, Applicant's claim 1 is patentable over Griffin. Independent claims 13, 14, and 23 were "rejected under the same rationale" as claim 1. Accordingly, Applicant submits that Applicant's independent claims 13, 14, and 23 are patentable over Griffin for at least the same reasons. Dependent claims 2-12 and 15-22 depend, directly or indirectly, from claims 1 and 14, respectively, and are therefore patentable over Griffin for at least the same reasons as the claims from which they depend. 4 Brown v. 3M, 265 F.3d 1349, 1351 (Fed. Cir 2001). Examiner’s response In response to applicant's argument, Examiner respectfully submits that claimed limitation is to be given their broadest reasonable interpretation during prosecution, and the scope of a claim cannot be narrowed by reading disclosed limitations into the claim. See In re Morris, 127 F.3d 1048, 1054, 44 USPQ2D 1023, 1027 (Fed. Cir. 1997); In re Zletz, 893 F.2d 319, 321, 13 USPQ2D 1320, 1322 (Fed. Cir. 1989); In re Prater, 415 F.2d 1393, 1404, 162 USPQ 541,550 (CCPA 1969). In addition, the law of anticipation does not require that a reference "teach" what an appellant's disclosure teaches. Assuming that reference is properly "prior art,'" it is only necessary that the claims "read on" something disclosed in the reference, i.e., all limitations of the claim are found in the reference, or "fully met" by it. Kalman v. Kimberly-Clark Corp., 713 F.2d 760, 772, 218 USPQ 781,789 (Fed. Cir. 1983). In this case, Griffin fairly discloses the claimed limitation “A method of preventing an Adversary in the Middle (AiTM) attack on deployed Multi-Factor Authentication (MFA) system" (Griffin Pa. [0016]) [This information can then be used in a multifactor risk based authentication system to streamline client access while still providing security] Furthermore, the use of Multi-Factor Authentication relates to well-known option in the field of authentication, the skilled person would consider with no inventive skills. Also, the preamble “Multi-Factor Authentication (MFA) system”, doesn’t have any relation with the body of the claim; therefore, it does not have any weight. In addition, the claimed limitation below has been interpreted as authentication of user based on comparison of two IP addresses. Consequently, Griffin clearly discloses proceeding with an authentication process for the user in response to a match between the IP address associated with the first electronic device and the IP address associated with the electronic device associated with the user from the database (Griffin Pa. [0058]) [The authentication level module 112 may determine that the IP address associated with the requesting device 130 matches a stored IP address in data store module 108. The authentication level module 112 may determine that the requesting device 130 can authenticate at the second authentication level and increment the value associated with the IP address] Appellant’s arguments are unpersuasive because they do not properly address the merits of the rejection. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to EVANS DESROSIERS whose telephone number is (571)270-5438. The examiner can normally be reached Monday -Friday 8:00 am - 5:30 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at (571)272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /EVANS DESROSIERS/Primary Examiner, Art Unit 2491
Read full office action

Prosecution Timeline

Sep 30, 2024
Application Filed
Dec 19, 2025
Non-Final Rejection mailed — §102
Mar 17, 2026
Response Filed
May 05, 2026
Final Rejection mailed — §102
Jul 20, 2026
Request for Continued Examination
Jul 20, 2026
Applicant Interview (Telephonic)
Jul 25, 2026
Examiner Interview Summary
Jul 30, 2026
Response after Non-Final Action

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12682086
ELECTRONIC ACCESS CONTROL SYSTEM
2y 1m to grant Granted Jul 14, 2026
Patent 12683993
SYSTEM AND METHOD FOR PROVIDING FLEET CYBER-SECURITY
2y 0m to grant Granted Jul 14, 2026
Patent 12676852
SYSTEMS AND METHODS FOR FIRMWARE PASSWORD MANAGEMENT
2y 1m to grant Granted Jul 07, 2026
Patent 12676858
SYSTEMS AND METHODS FOR SECURE ONLINE CREDENTIAL AUTHENTICATION
1y 10m to grant Granted Jul 07, 2026
Patent 12665906
MANAGING SECURITY GROUPS FOR DATA INSTANCES
2y 10m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+22.9%)
3y 0m (~1y 2m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 1039 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month