Prosecution Insights
Last updated: October 02, 2026
Application No. 18/916,853

GENERATIVE ARTIFICIAL INTELLIGENCE (AI) DRIVEN CONVERSATIONAL AUTHENTICATION

Non-Final OA §102§103
Filed
Oct 16, 2024
Examiner
ALATA, AYOUB
Art Unit
2494
Tech Center
2400 — Computer Networks
Assignee
Kyndryl Inc.
OA Round
2 (Non-Final)
82%
Grant Probability
Favorable
2-3
OA Rounds
8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
403 granted / 494 resolved
+23.6% vs TC avg
Strong +26% interview lift
Without
With
+25.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
8 currently pending
Career history
501
Total Applications
across all art units

Statute-Specific Performance

§101
10.1%
-29.9% vs TC avg
§103
43.1%
+3.1% vs TC avg
§102
22.4%
-17.6% vs TC avg
§112
15.9%
-24.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 494 resolved cases

Office Action

§102 §103
DETAILED ACTION Response to Amendment 1. This written action is responding to the amendment dated on 05/06/2026. 2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 3. The objection to claims 2-4, 9-11, and 16-18 is withdrawn. 4. Claims 1-5, 8-11, and 15-18 are amended. 5. Claims 1-20 are submitted for examination. 6. Claims 1-20 are rejected. 7. The Examiner would like to point out that this action is made final (See MPEP 706.07a). 8. Applicant’s Argument: On pages 8-9 of the Remarks/Arguments, Applicant argues that the combination of Avadhanam and Ur fail to teach: "wherein the generating the authentication security question includes obtaining user information known to the user, wherein the user information comprises at least one of user location information, user historical patterns, user account changes, user sentiment based information, user imaginary scenarios, or user created content." Response to Argument: Examiner respectfully disagrees with Applicant’s arguments because Avadhanam substantially teaches an authentication module may authenticate a user by dynamically generating a set of challenge questions based on past behavior information of the user (col. 24, lin. 24-29), wherein the past behavior information may include the user's purchase history, search history, interaction with a virtual assistant, social media interaction, usage history of the cloud devices, for example, usage statistics and usage patterns for the cloud-based devices of the user, questions asked to the virtual assistants, usage of the online accounts, past orders, gift registry (col. 3, lin. 16-30), and wherein the identity management server may present the set of challenge questions to the first device or the first user using the IP address of the first device from the first identity information based on the request (col. 14, lin. 53-57). Thus, Avadhanam teaches the above limitation. 9. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-3, 6-10, 13-17 and 20 are rejected under 35 U.S.C. 102(a)(1) as being unpatentable over Avadhanam et al. US 11,552,953 (hereinafter Avadhanam). Regarding claim 1 Avadhanam teaches a computed-implemented method comprising: receiving a request from a user to access a protected resource (col. 24, lin. 5-7) and fig. 13; generating an authentication security question based on knowledge about the user, wherein receiving the request causes the authentication security question to be generated, wherein generating the authentication security question includes obtaining user information known to the user, wherein the user information comprises at least one of user location information, user historical patterns, user account changes, user sentiment based information, user imaginary scenarios, or user created content; presenting the authentication security question to the user (Avadhanam teaches an authentication module may authenticate a user by dynamically generating a set of challenge questions based on past behavior information of the user (col. 24, lin. 24-29), wherein the past behavior information may include the user's purchase history, search history, interaction with a virtual assistant, social media interaction, usage history of the cloud devices, for example, usage statistics and usage patterns for the cloud-based devices of the user, questions asked to the virtual assistants, usage of the online accounts, past orders, gift registry (col. 3, lin. 16-30), and wherein the identity management server may present the set of challenge questions to the first device or the first user using the IP address of the first device from the first identity information based on the request (col. 14, lin. 53-57)); and in response to a user answer for the authentication security question being correct, granting the user access to the protected resource (Avadhanam teaches based on the response from the device, the first user may be authenticated and allowed to access a domain (col. 24, lin. 31-36) and fig. 13). Regarding claim 2 Avadhanam teaches the computer-implemented method of claim 1, wherein: receiving the request includes the user attempting to access an online system; and the authentication security question is generated in real-time (Avadhanam teaches a user with a device may request access to a network device (col. 24, lin. 5-7) and fig. 13, wherein an authentication module may authenticate the user by dynamically in other words in real-time generating a set of challenge questions based on past behavior information of the user (col. 24, lin. 24-29) and (col. 32, 8-10). Regarding claim 3 Avadhanam teaches the computer-implemented method of claim 1, wherein the user information includes personal activities of the user and real-time data about the user (Avadhanam teaches the set of challenge questions may include questions about a recent purchase made by the first user using Amazon Prime account (col. 10, lin. 26-28), wherein the processes and architectures can be performed either in real-time (col. 32, 8-10)). Regarding claim 6 Avadhanam teaches the computer-implemented method of claim 1, further comprising causing an AI model to evaluate the user answer for at least one of a meaning or a context using the knowledge about the user and the authentication security question presented to the user (Avadhanam teaches the set of challenge questions and the expected response may be determined using a machine learning model based on the past behavior information associated with the user (col. 22, lin. 42-45)). Regarding claim 7 Avadhanam teaches the computer-implemented method of claim 1, further comprising executing an initial authentication prior to generating the authentication security question, wherein passing the initial authentication function determines that the knowledge about the user is to be utilized to generate the authentication security question (Avadhanam teaches certain systems may include infrastructure to support authentication of the devices or the user of the devices using various factors such as tokens, fingerprinting, challenge questions, passwords, and personal identification numbers (PINs) to allow or deny access to other devices (col. 2, lin. 44-48)). In response to Claim 8: Rejected for the same reason as claim 1 In response to Claim 9: Rejected for the same reason as claim 2 In response to Claim 10: Rejected for the same reason as claim 3 In response to Claim 13: Rejected for the same reason as claim 6 In response to Claim 14: Rejected for the same reason as claim 7 In response to Claim 15: Rejected for the same reason as claim 1 In response to Claim 16: Rejected for the same reason as claim 2 In response to Claim 17: Rejected for the same reason as claim 3 In response to Claim 20: Rejected for the same reason as claim 7 10. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 4, 11 and 18 are rejected under 35 U.S.C. 103 as unpatentable over Avadhanam as mentioned above, and further in view of Studer et al,. US 2025/0321813 (hereinafter Studer). Regarding claim 4 Avadhanam teaches the computer-implemented method of claim 1, wherein generating the authentication security question based on the knowledge about the user comprises causing an artificial intelligence (AI) model to generate the authentication security question based on the knowledge about the user (Avadhanam teaches the set of challenge questions and the expected response may be determined using a machine learning model based on the past behavior information associated with the user (col. 22, lin. 42-45)). Avadhanam does not teach using a retrieval-augmented generation process. Studer substantially teaches using one or more retrieval-augmented generation algorithms [0062] and fig. 4. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Avadhanam such that the invention further includes using a retrieval-augmented generation process. One would have been motivated to do so to enhance data accuracy of generative data models [0062]. In response to Claim 11: Rejected for the same reason as claim 4 In response to Claim 18: Rejected for the same reason as claim 4 11. Claims 5, 12 and 19 are rejected under 35 U.S.C. 103 as unpatentable over Avadhanam as mentioned above, and further in view of Cordes et al,. US 9,384,450 (hereinafter Cordes). Regarding claim 5 Avadhanam teaches the computer-implemented method of claim 1, further comprising validating the user answer by determine at least one of a meaning or a context of the user answer; wherein the user answer and the knowledge retrieved about the user are input into an AI model (Avadhanam teaches based on the response from the device, the first user may be authenticated and allowed to access a domain (col. 24, lin. 31-36). The set of challenge questions and the expected response may be determined using a machine learning model based on the past behavior information associated with the user (col. 22, lin. 42-45). Avadhanam does not teach using semantic analysis to output a determination of whether the meaning or the context of the user answer is correct along with a confidence score for the determination. Cordes substantially teaches scoring classifiers may primarily use semantic analysis and machine learning to achieve matching by meaning between ground truth and candidate answers (col. 6, lin. 42-44). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Avadhanam such that the invention further includes using semantic analysis to output a determination of whether the meaning or the context of the user answer is correct along with a confidence score for the determination. One would have been motivated to do so to improve accuracy and data quality, for example by interpreting the meaning of the text rather than matching keywords, which leads to better understanding a user preference. In response to Claim 12: Rejected for the same reason as claim 5 In response to Claim 19: Rejected for the same reason as claim 5 Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Ayoub Alata whose telephone number is (313) 446-6541. The examiner can normally be reached on M-F: 8:00am-4:30pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Jay Kim can be reached at (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. /AYOUB ALATA/ Primary Examiner, Art Unit 2494
Read full office action

Prosecution Timeline

Oct 16, 2024
Application Filed
Feb 17, 2026
Non-Final Rejection mailed — §102, §103
Apr 23, 2026
Interview Requested
Apr 29, 2026
Applicant Interview (Telephonic)
May 06, 2026
Response Filed
Jun 17, 2026
Final Rejection mailed — §102, §103
Jul 22, 2026
Interview Requested
Jul 27, 2026
Response after Non-Final Action

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748865
SECURE PROCESSING SYSTEMS AND METHODS
1y 8m to grant Granted Sep 29, 2026
Patent 12726353
CONTROL SYSTEM AND VEHICLE
1y 8m to grant Granted Sep 01, 2026
Patent 12718167
DATA PROCESSING SYSTEMS FOR IDENTIFYING, ASSESSING, AND REMEDIATING DATA PROCESSING RISKS USING DATA MODELING TECHNIQUES
1y 11m to grant Granted Aug 25, 2026
Patent 12688277
TECHNIQUES FOR INSPECTING RUNNING VIRTUALIZATIONS FOR CYBERSECURITY RISKS
2y 2m to grant Granted Jul 21, 2026
Patent 12682082
Oracle for Authenticating Software Layers Using Software Security Version Numbers and Security Context
2y 9m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

2-3
Expected OA Rounds
82%
Grant Probability
99%
With Interview (+25.6%)
2y 7m (~8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 494 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month