Prosecution Insights
Last updated: August 17, 2026
Application No. 18/918,822

IDENTIFICATION OF USERS OF SYSTEMS

Non-Final OA §102§103
Filed
Oct 17, 2024
Examiner
DOAN, TRANG T
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Kyndryl Inc.
OA Round
2 (Non-Final)
83%
Grant Probability
Favorable
2-3
OA Rounds
1y 6m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
522 granted / 630 resolved
+24.9% vs TC avg
Strong +17% interview lift
Without
With
+16.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
22 currently pending
Career history
657
Total Applications
across all art units

Statute-Specific Performance

§101
15.3%
-24.7% vs TC avg
§103
35.5%
-4.5% vs TC avg
§102
19.8%
-20.2% vs TC avg
§112
19.7%
-20.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 630 resolved cases

Office Action

§102 §103
DETAILED ACTION In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This Office Action is in response to the communication filed on 4/30/2026. Claims 1-20 are pending for consideration. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Specification The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification. Response to Arguments Applicant's arguments regarding the 101 rejection filed on 4/30/2026 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. Applicant’s arguments with respect to claim(s) 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-3, 5-9, 13-14, 16-17 and 19-20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by YAHYA et al. (EP 4546178) (hereinafter YAHYA). Regarding claim 1, YAHYA discloses a method, comprising: obtain, by a computing device, location information of a user attempting to gain access to a system (YAHYA: paragraphs 0034, 0038 and 0044, “the user activity monitor 110 collects recent user location based information from the Location Module 42, including past and current locations, and recent user-activity in the social media platform 170. User activity comprises those actions by the user when interacting and interfacing with the Client”…“By way of the Semantic Module 180 coupled to the AI Engine 141 and vector database 130, genAPI 140 can read logs, extract location information, and generate images based on recent user locations”); generate, by the computing device, a plurality of images from the location information, the plurality of images including at least one image representative of the location of the user (YAHYA: paragraphs 0035 and 0045-0052, “the user activity monitor 110 identifies user-knowledge events includes determining a recency of user activity in view of the user logs, and said step of generating random image questions retrieves user-knowledge events from recent user activities and location data of the client 101 occurring only while the user is simultaneously logged into a communication platform” … “Accompanying the images 423 are associated text questions, also produced by genAPI 140, based on their activity with social media apps 170, and/or also user location based activity, for example, where the user is, or has been active, for example, using Global Positioning System (GPS) data, such as on a smart watch that tracks running activity, or vehicle activity on a GPS maps application”); present, by the computing device, the plurality of images to the user (YAHYA: paragraphs 0052-0054, “generates user-knowledge events with user location data from the recent user-activity in vector format as described above, and generates random image questions concerning the user-knowledge events and location based information”…“The User Authentication Module 120 presents the random image questions to the user. It presents the random image questions to, and receive answers from, the user as part of the authentication step… The questions are designed to pull recent user activity content from the social media platform 170 and Location Module 420 to form the random image questions. In some embodiments, the random questions additionally present as challenge a "Completely Automated Public Turing test to tell Computers and Humans Apart" (CAPTCHA) with content relevant to recent user-activity according to location based information”); validate, by the computing device, the user by determining that the user has selected the at least one image representative of the location information of the user (YAHYA: paragraphs 0054-0055, “the User Authentication Module 120 presents the answered questions and corresponding user selected image answers to the Response Image Verification API component of the genAPI 140. The set of random image questions presented to the user that they decide to answer, and respond with answers, are called answered image questions.”); and allow, by the computer device, the user to access the system based on the user being validated (YAHYA: paragraphs 0033 and 0057-0061, “It now compares the expected answer to the answered image questions received from the user, and authenticates the user if the compare is within a probabilistic threshold”…“The Response Image Verification component of the genAPI 140, by way of the App Service 127, database 130 and optional AI Engine 141, performs a comprehensive analysis of the user's response (i.e., corresponding image answers to asked question), taking into account factors such as semantic similarity, contextual relevance, location information, and behavioral patterns to determine the authenticity of the user's response. By leveraging advanced algorithms, it verifies the authenticity of the user's response to the answered image questions, in view of the answer, recent user activity, user location data, and user knowledge events, and determines whether the authentication should be granted or denied.”… “Authentication is the process of validating the identity of a registered user or process before enabling access to protected networks and systems”). Regarding claim 14, claim 14 discloses a product claim that is substantially equivalent to the method of claim 1. Therefore, the arguments set forth above with respect to claim 1 are equally applicable to claim 14 and rejected for the same reasons. Regarding claim 20, claim 20 discloses a system claim that is substantially equivalent to the method of claim 1. Therefore, the arguments set forth above with respect to claim 1 are equally applicable to claim 20 and rejected for the same reasons. Regarding claim 2, YAHYA discloses wherein the system comprises a web-based system (YAHYA: paragraphs 0062-0063, “a system 200 for secure user-activity image based authentication according to location utilizing dynamic and generative image question generation within an Identity and Access Management (IAM) ecosystem. The system 200 comprises the Client 101, the AI Engine 141, a Service Provider 131 and an Identity Provider (IdP) 121 communicatively coupled over the Internet and/or a telecommunications network”… “the Client 101 is a computational device such as a computer or mobile device, with location based capabilities, such as GPS, communicatively connected to these components. It includes an operating system (OS) or browser for executing an Application (App) 102 as one example of a program that requires user-based image authentication. It may be a native app executing on the OS or a web app through a browser.”). Regarding claim 3, YAHYA discloses wherein the generating the plurality of images includes generating images that are not representative of the location of the user (YAHYA: paragraphs 0052 and 0054, “the genAPI 140 is coupled to a Semantic Module 180 that serves as an efficient middleware to enable rapid delivery of enterprise-grade user-activity image based authentication solutions. By way of the Semantic Module 180 coupled to the AI Engine 141 and vector database 130, genAPI 140 can read logs, extract location information, and generate images based on recent user locations. It can also generate an application logo that the user used before. This variation enhances the richness of the user experience by incorporating visual elements tied to user's activities.”… “corresponding images 173 for the social media platforms”). Regarding claim 5, YAHYA discloses wherein the plurality of images are generated by a text-to-image generative AI engine (YAHYA : paragraph 0039, “in some embodiments, the Semantic Module 180 is a lightweight, open-source development kit that builds AI agents that integrate Language Models (LLMs) like OpenAl, Azure OpenAl, with C#, Python, or Java codebases. For this purpose, the Semantic Module 180 is coupled to the AI Engine 141 for generating the images and associated text based questions related to the images based on user activity and knowledge. The Artificial Intelligence (Al) Engine 141 provides both generated text to image (T2I) conversion and generated image to text (I2T) conversion. The Semantic Module 180 is also coupled to a vectorized data base 130, which includes capabilities for Vectorization 131, Blob Storage 132, and a Shared Signals Framework 133, as described further ahead. The Semantic Module 180 coordinates and orchestrates interactions between the AI Engine 141 and the vectorized database 130 to provide the back-end support for the Image Generation API 140.”). Regarding claim 6, YAHYA discloses wherein the obtaining the location information comprises obtaining one of an IP location of a device used by the user and GPS coordinates of the user (YAHYA: paragraphs 0062-0063, “a system 200 for secure user-activity image based authentication according to location utilizing dynamic and generative image question generation within an Identity and Access Management (IAM) ecosystem. The system 200 comprises the Client 101, the AI Engine 141, a Service Provider 131 and an Identity Provider (IdP) 121 communicatively coupled over the Internet and/or a telecommunications network”… “the Client 101 is a computational device such as a computer or mobile device, with location based capabilities, such as GPS, communicatively connected to these components. It includes an operating system (OS) or browser for executing an Application (App) 102 as one example of a program that requires user-based image authentication. It may be a native app executing on the OS or a web app through a browser.”). Regarding claims 7 and 17, YAHYA discloses wherein the location information represents a location familiar to the user obtained by querying a history of a device used by the user (YAHYA: paragraphs 0034, 0038 and 0044, “the user activity monitor 110 collects recent user location based information from the Location Module 42, including past and current locations, and recent user-activity in the social media platform 170. User activity comprises those actions by the user when interacting and interfacing with the Client”…“By way of the Semantic Module 180 coupled to the AI Engine 141 and vector database 130, genAPI 140 can read logs, extract location information, and generate images based on recent user locations”). Regarding claims 8 and 19, YAHYA discloses wherein the plurality of images is obtained from a street view of the location information (YAHYA : paragraph 0055, “Briefly, the genAPI 141 (reinforced by AI engine 140 where necessary) reads all these user activities and location data and automatically generate a unique token challenge as a question. User activities may be based on other factors such as GPS location and the challenge would be as follows: "Did you go out yesterday morning to buy a coffee on Yonge Street?" Yes/No. Or the combination of 2: "Did you go out yesterday morning to buy a coffee on Yonge Street and open Instagram?" Yes/No. If for some reason the user does not remember a specific activity, they can move on to the next challenge/question. The user decides which of the random questions to answer.”). Regarding claim 9, YAHYA discloses wherein the plurality of images comprises using random addresses, one of which is the location information (YAHYA : paragraphs 0047 and 0049, “These system, device and security events, although independent from user-activity, can be used to embellish user-knowledge events and mental recollection in generating the random questions. The device events may be referenced in conjunction with user-activity when the AI Engine 141 generates user-knowledge events from recent user-activity and recent or past user location information.”… “the User Authentication Module 120 presents a request to the Random Image for Question API component of the genAPI 140 for one or more random image questions related to recent user activity and according to past and/or present user location.”). Regarding claim 13, YAHYA discloses wherein the computing device includes software provided as a service in a cloud environment (YAHYA : paragraphs 0058-0063, “in one arrangement, the Response Verification component of the genAPI 140 can be deployed on the Microsoft Azure .sup.® cloud platform, leveraging its robust infrastructure and services. Azure.sup.® App Service provides a serverless architecture that ensures scalability, high availability, and efficient resource utilization. It may also leverage Azure.sup.® Blob Storage to securely store the Vector Database 130, enabling efficient storage and retrieval of user activity data. Azure.sup.® Functions, a serverless compute service, are utilized to implement the APIs for generating random questions and verifying user responses. Azure Functions provide an event-driven, scalable approach to handle API requests and execute the necessary computations”). Regarding claim 16, YAHYA discloses wherein the location information is a location of the user (YAHYA: paragraphs 0033 and 0057-0061, “It now compares the expected answer to the answered image questions received from the user, and authenticates the user if the compare is within a probabilistic threshold”…“The Response Image Verification component of the genAPI 140, by way of the App Service 127, database 130 and optional AI Engine 141, performs a comprehensive analysis of the user's response (i.e., corresponding image answers to asked question), taking into account factors such as semantic similarity, contextual relevance, location information, and behavioral patterns to determine the authenticity of the user's response. By leveraging advanced algorithms, it verifies the authenticity of the user's response to the answered image questions, in view of the answer, recent user activity, user location data, and user knowledge events, and determines whether the authentication should be granted or denied.”… “Authentication is the process of validating the identity of a registered user or process before enabling access to protected networks and systems”). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 4 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over YAHYA in view of Fu et al. (US 20250278952) (hereinafter Fu). Regarding claims 4 and 15, YAHYA does not explicitly disclose the following limitation which is disclosed Brown, wherein the plurality of images are generated by an image-to-image generative AI engine (Fu: paragraphs 0010 and 0046, 0062-0063 and 0073, “The NN and/or generative AI shown in diagram 300b may correspond to a Pix2Pix model or other type of GAN or image-to-image generative AI for image data generation”). YAHYA and Fu are analogous art because they are from the same field of endeavor, image verification. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of YAHYA and Fu before him or her, to modify the system of YAHYA to include a plurality of images are generated by an image-to-image generative AI engine of Fu. The suggestion/motivation for doing so would have been to allow for verification of content in an image (Fu: see Abstract). Claim(s) 10-12 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over YAHYA in view of Shannon et al. (US 20260050898) (hereinafter Shannon). Regarding claim 10, YAHYA does not explicitly disclose the following limitation which is disclosed Shannon, further comprising validating a device of the user as being a trusted device (Shannon: paragraph 0106, “Perform Mutual Authentication-The Mobile Banking Application and the Enterprise Application perform mutual authentication using digital certificates or pre-shared keys. This step verifies that both devices are trusted and authorized to communicate securely.”). YAHYA and Shannon are analogous art because they are from the same field of endeavor, access authorization. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of YAHYA and Shannon before him or her, to modify the system of YAHYA to include validating a device of the user as being a trusted device of Shannon. The suggestion/motivation for doing so would have been to ensure that data exchanged during a session is protected against eavesdropping and tampering (Shannon: paragraph 0082). Regarding claim 11, YAHYA as modified discloses wherein the validating of the device comprises a hardware validation or a digital validation (Shannon: paragraph 0106, “The Mobile Banking Application and the Enterprise Application perform mutual authentication using digital certificates or pre-shared keys. This step verifies that both devices are trusted and authorized to communicate securely.”). The same motivation to modify YAHYA in view of Shannon, as applied in claim 10 above, applies here. Regarding claims 12 and 18, YAHYA as modified discloses wherein the validating of the device includes a primary validation and a secondary validation should the primary validation fail (Shannon: paragraphs 0126 and 0137, “The system can integrate with MDM solutions like VMware Workspace ONE or Microsoft Intune to enforce biometric authentication for accessing corporate resources. MDM solutions can require users to set up biometric authentication on their devices as part of the security policy, ensuring that only compliant devices can participate in the session.” and “Biometric Verification Failure and Recovery: If the initial biometric verification fails (Sequences 204 or 206), the system can implement a recovery process. The application can prompt the user to re-capture their biometric data. If the second attempt also fails, the system could offer alternative authentication methods”) . The same motivation to modify YAHYA in view of Shannon, as applied in claim 10 above, applies here. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to TRANG T DOAN whose telephone number is (571)272-0740. The examiner can normally be reached Monday-Friday 7-4 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D Feild can be reached on (571)272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TRANG T DOAN/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Oct 17, 2024
Application Filed
Feb 03, 2026
Non-Final Rejection mailed — §102, §103
Apr 30, 2026
Response Filed
Jul 15, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705389
MITIGATING PRIVATE DATA LEAKAGE IN A FEDERATED LEARNING SYSTEM
3y 8m to grant Granted Aug 11, 2026
Patent 12706738
SYSTEMS AND METHODS FOR DECENTRALIZED DATA DISTRIBUTION
1y 8m to grant Granted Aug 11, 2026
Patent 12699811
Computer-implemented method for the secure preparation of a property transfer document
4y 3m to grant Granted Aug 04, 2026
Patent 12683773
CONTROL DEVICE, QUANTUM CRYPTOGRAPHIC COMMUNICATION SYSTEM, CONTROL METHOD, AND COMPUTER PROGRAM PRODUCT
2y 10m to grant Granted Jul 14, 2026
Patent 12671996
UPGRADING CONTROL PLANE NETWORK FUNCTIONS WITH PROACTIVE ANOMALY DETECTION CAPABILITIES
2y 8m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

2-3
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+16.9%)
3y 4m (~1y 6m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 630 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month