Prosecution Insights
Last updated: September 29, 2026
Application No. 18/923,790

SECURITY KEY FOB

Non-Final OA §101§103§112§DOUBLEPATENT
Filed
Oct 23, 2024
Examiner
LAGOR, ALEXANDER
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Mis Electronics Inc.
OA Round
1 (Non-Final)
73%
Grant Probability
Favorable
1-2
OA Rounds
1y 5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
332 granted / 454 resolved
+15.1% vs TC avg
Strong +29% interview lift
Without
With
+28.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
4 currently pending
Career history
456
Total Applications
across all art units

Statute-Specific Performance

§101
10.2%
-29.8% vs TC avg
§103
46.8%
+6.8% vs TC avg
§102
19.8%
-20.2% vs TC avg
§112
15.8%
-24.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 454 resolved cases

Office Action

§101 §103 §112 §DOUBLEPATENT
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-19 rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 11876826. Although the claims at issue are not identical, they are not patentably distinct from each other because the subject matter claim in the claim(s) of the instant application is fully disclosed and covered by the claims in the US Patent No 11876826. Instant Application US Patent No. 11876826 A security fob-ring in communication with a security system for assessing a user's security risk based on daily Biometric behavior anomalies, the system comprising: a) a processing unit; b) a memory unit; and c) a plurality of coded instructions, stored in the memory unit, that, when executed by the processing unit, cause the system to: i. collect a plurality of human biometric data from a biometric reader; ii. analyze the plurality of human biometric data using an adaptive neural network model that performs rational inference to learn the correlation between the plurality of human biometric data and daily biometric behavior anomalies to determine the user's security risk; iii. determine a risk score of the user based on the daily biometric behavior anomalies, and iv. control access of the user based on the risk score by alerting the user, disconnecting or preventing user access; wherein the security fob-ring enhance physical access control by integrating biometric data and user behavior patterns for authentication by gathering biometric information, from a distributed network. (claim 1) A system for assessing cyber competence of a user, the system comprising: a) a processing unit; b) a memory unit; and c) coded instruction, stored in the memory unit, that, when executed by the processing unit, causes to i. collect human biometrics data comprising eye movement data from a biometric reader; ii. analyze the human biometrics data using an adaptive neural network model that performs rational inference to learn the correlation between the human biometrics and mental disorder to determine a mental disorder; iii. determine a cyber competence score of the user based on mental disorder, and iv. control network access of the user based on the cyber competence score. (Claim 1) The system of claim 1, wherein controlling the network access comprises alerting the user, disconnecting the network connection of the user, and alerting a second user. (Claim 2) The system of claim 1, wherein the adaptive neural network model is trained using a two-phase machine learning engine in combination with a spiking recurrent network model. (Claim 2) The system of claim 1, wherein the adaptive neural network model is trained using a wake-sleep machine learning engine in combination with a spiking recurrent network model. (Claim 3) The system of claim 2, wherein the two-phase machine learning engine predicts the risk score for a set of predefined security hardenings. (Claim 3) The system of claim 3, wherein the wake-sleep machine learning engine is used to predict the mental disorder for a set of definitive cyber risks. (Claim 4) The system of claim 2, wherein the two-phase machine learning engine, in a first mode, predicts a set of upcoming behavior transitions during an intense and previously unseen task by utilizing a temporal context of daily biometric behavior and simulating attention shifts. (Claim 4) The system of claim 3, wherein the wake-sleep machine learning engine in a sleep mode predicts next gaze transitions during a more intense and previously unseen visual task by exploiting the temporal context of gaze fixation and simulating attention shifts (Claim 5) The system of claim 2, wherein the two-phase machine learning engine in second mode, identifies a set of correlating points between a set of simulated behavior patterns and a set of risk disorders. (Claim 5) The system of claim 3, wherein the wake-sleep machine learning engine in wake mode undercovers correlating points between simulated gaze patterns to mental disorders. (Claim 6) The system of claim 1, wherein the adaptive neural network model is based on Generic-Leaky-Integrate-and-Fire (GLIF) neural network model. (Claim 6) The system of claim 1, wherein the adaptive neural network model is developed based on Generic-Leaky-Integrate-and-Fire (GLIF) neural network model. (Claim 7) The system of claim 1, wherein the adaptive neural network model is trained using a set of recorded personal behavior data comprising several populations of equivalently structured, interconnected neurons represented as generic leaky integrate-and-fire neurons, trained with spike-timing-dependent plasticity (STDP). (Claim 7) The system of claim 1, wherein the adaptive neural network model is trained using recorded eye movement data comprising of several populations of equivalently structured, interconnected, eye movement data represented in form of generic leaky integrate-and-fire neurons, which are trained with spike-timing-dependent plasticity (STDP). (Claim 8) The system of claim 1, further comprising a correlation matrix determined by correlating the risk score through the distributed network, wherein network access is controlled based on the correlation matrix. (Claim 8) The system of claim 1, further determines a correlation matrix by correlating the cyber competence score of the user with the network activity log of a user, wherein the network access is controlled based on the correlation matrix. (Claim 9) The system of claim 8, wherein the risk score of the user is determined based on the correlation matrix using a machine learning model. (Claim 9) The system of claim 9, the cyber competence score of the user is determined based on the correlation matrix using a machine learning model. (Claim 10) A method for assessing a security risk of a user, the method comprising the steps of :a) collecting, at a computing device, human biometrics data, comprising daily activity data from a plurality of field biometric sensing devices; b) analyzing, at the computing device, the human biometrics data using an adaptive neural network model that performs rational inference to learn a correlation between a human biometric anomalies and the security risk of the user to determine a security hardening; c) determining, at the computing device or a personal data-collecting unit, a risk score of the user based on a daily behavior anomalies of the user; d) determining a correlation matrix by comparing the risk score of the user, and e) controlling a network access by the computing device to regulate security access based on the risk score. (Claim 10) A method for assessing cyber competence of a user, the method comprising: a) collecting, at a computing device, human biometrics data comprising eye movement data from a biometric reader; b) analyzing, at the computing device, the human biometric data using an adaptive neural network model that performs rational inference to learn the correlation between the human biometrics and mental disorder to determine a mental disorder; c) determining, at the computing device, a cyber competence score of the user based on mental disorder; and d) controlling, by the computing device, network access of the user based on the cyber competence score. (Claim 11) The method of claim 10, wherein controlling the network access comprises alerting the user, disconnecting the network connection of the user and notifying an administrative user. (Claim 11) The method of claim 10, wherein controlling the network access comprises alerting the user, disconnecting the network connection of the user and alerting a second user. (Claim 12) The method of claim 10, wherein the adaptive neural network model is trained using a two-phase machine learning engine in combination with a spiking recurrent network model. (Claim 12) The method of claim 10, wherein the adaptive neural network model is trained using a wake-sleep machine learning engine in combination with a spiking recurrent network model. (Claim 13) The method of claim 12, wherein the two-phase machine learning engine is used to predict the security risks of the user. (Claim 13) The method of claim 13, wherein the wake-sleep machine learning engine is used to predict the mental disorder for a set of definitive cyber risks. (Claim 14) The method of claim 12, wherein the two-phase machine learning engine, in a first mode, predicts upcoming behavior transitions during an intense and unseen visual task by exploiting a temporal context of behavior stall and simulating attention shifts. (Claim 14) The method of claim 13, wherein the wake-sleep machine learning engine in a sleep mode predicts next gaze transitions during a more intense and previously unseen visual task by exploiting the temporal context of gaze fixation and simulating attention shifts. (Claim 15) The method of claim 12, wherein the two-phase machine learning engine, in second mode, identifies a set of correlating points between simulated behavior patterns and security risks. (Claim 15) The method of claim 13, wherein the wake-sleep machine learning engine in wake mode undercovers correlating points between simulated gaze patterns to mental disorders. (Claim 16) The method of claim 10, wherein the adaptive neural network model is based on Generic-Leaky-Integrate-and-Fire (GLIF) neural network model. (Claim 16) The method of claim 10, wherein the adaptive neural network model is developed based on Generic-Leaky-Integrate-and-Fire (GLIF) neural network model. (Claim 17) The method of claim 10, wherein the adaptive neural network model is trained using a recorded behavior shift data comprising populations of equivalently structured, interconnected neurons represented as generic leaky integrate-and-fire neurons, trained with spike-timing- dependent plasticity (STDP). (Claim 17) The method of claim 10, wherein the adaptive neural network model is trained using recorded eye movement data comprising of several populations of equivalently structured, interconnected, eye movement data represented in form of generic leaky integrate-and-fire neurons, which are trained with spike-timing-dependent plasticity (STDP). (Claim 18) The method of claim 10, further comprising determining a correlation matrix by correlating the risk score with a network activity log of the user, wherein the network access is controlled based on the correlation matrix. (Claim 18) The method of claim 10, further comprises steps of determining a correlation matrix by correlating the cyber competence score of the user with the network activity log of the user, wherein the network access is controlled based on the correlation matrix. (Claim 19) The method of claim 18, wherein the risk score of the user is determined based on the correlation matrix using a machine learning model. (Claim 19) The method of claim 19, the cyber competence score of the user is determined based on the correlation matrix using a machine learning model. (Claim 20) Referring to claim 1, the claim recites in the preamble “a security fob-ring in communication with a security system for assessing a user’s risk based on daily biometric behavior anomalies.” Under MPEP § 2111.02, preamble language is given patentable weight when it breathes life and meaning into the claim or otherwise limits the claim scope. Here, the body of claim 1 recites the structural and functional limitations of the security system, including a processing unit, memory unit, coded instructions, biometric data collection, analysis by an adaptive neural network model, determination of a risk score, and control of access based on the risk score. Accordingly, the preamble phrase “security fob-ring in communication with a security system” is treated as a non-limiting recitation of the intended environment or context of use, and is not given separate patentable weight. The additional wherein clause, “wherein the security fob-ring enhance physical access control by integrating biometric data and user behavior patterns for authentication by gathering biometric information, from a distributed network,” is also not given patentable weight to the extent it merely states a result or intended use of the recited system and does not impose a separate structural or functional limitation on the claimed security system. The claim further recites the following limitation: “analyze the plurality of human biometric data using an adaptive neural network model that performs rational inference to learn the correlation between the plurality of human biometric data and daily biometric behavior anomalies to determine the user's security risk”. US Patent No. 11876826 (hereinafter “Merat”) teaches analyzing the plurality of human biometric data using an adaptive neural network model that performs rational inference to learn a correlation involving the plurality of human biometric data to determine the user’s security risk. Merat teaches analyzing human biometric data using a GLIF based adaptive neural network model trained using a wake-sleep algorithm in combination with a spiking recurrent neural network model to determine a mental disorder/disturbance level which is correlated with a mental conditional-cyber risk correlation database to determine the users associated cyber risk (¶9, ¶10, ¶28-¶31, ¶44, ¶45, claims 3-7, claim 11, claims 13-18). Merat does not teach correlating the biometric information with daily biometric behavior anomalies. U.S. PGPub. No. 2021/0112064 A1 (hereinafter “Losseva”) teaches daily biometric behavior anomalies. Losseva teaches a system for physical access control where a user’s movement through space is interpreted as a behavioral biometric (abstract, ¶1, ¶9, ¶18, ¶45, ¶54). Losseva teaches generating an adjacency matrix referred to as a “footprint” by analyzing a user’s movement patterns over time and creating a weighted directed graph representing the user’s daily behavioral baseline (abstract, ¶25, ¶78-¶80, ¶118, ¶121-¶127). Losseva teaches detecting a user’s behavioral anomalies by comparing a user’s footprint to an earlier footprint of the same user to identify deviations from the user’s daily biometric behavior baseline (abstract, ¶9, ¶14, ¶66, ¶72, ¶82, ¶146, ¶147, ¶155). It would have been obvious before the effective filing date to modify the security system taught by Merat by combining prior art elements according to known methods to yield predictable results with the teachings of Losseva (M.P.E.P. 2143(I)(A)). A person of ordinary skill in the art would have combined Merat’s known adaptive neural network correlation technique to learn correlations between human biometric data and the daily biometric behavior anomalies taught by Losseva in order to determine a user’s security risk, because doing so would yield the predictable result of identifying a user’s security risk based on biometric anomalies enhancing access control. Drawings The drawings are objected to as failing to comply with 37 CFR 1.84(p)(5) because they include the following reference character(s) not mentioned in the description: 102x and 104x in Fig. 1. Corrected drawing sheets in compliance with 37 CFR 1.121(d), or amendment to the specification to add the reference character(s) in the description in compliance with 37 CFR 1.121(b) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance The drawings are objected to under 37 CFR 1.83(a) because they fail to show as disclosed in ¶79: “Graphs 600 shows the result of a test run on a variety of mobile platforms such as cellular phones and VR glass.” as described in the specification. Any structural detail that is essential for a proper understanding of the disclosed invention should be shown in the drawing. MPEP § 608.02(d). Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. The drawings are objected to as failing to comply with 37 CFR 1.84(p)(5) because they do not include the following reference sign(s) mentioned in the description: “102n” disclosed on pg. 14, ¶¶46-47. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1-19 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claims 1 and 10 introduce a “security fob-ring,” but the specification, while describing a “smart ring” and separately describing “security fobs,” does not reasonably convey to those skilled in the art that the inventor was in possession of a combined “fob-ring” device at the time of filing. The disclosure does not expressly define “fob-ring” or otherwise describe a single device having the combined structural features of a fob and a ring. Accordingly, the originally filed specification does not provide adequate written description support for the claimed “security fob-ring.” Claims 2-9 and 11-19 depend on rejected base claims 1 and 10 and do not further limit the base claims to overcome the grounds of rejections they inherit from their base claims. Claim(s) 1-19 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. In order to determine compliance with the enablement requirement of 35 U.S.C. 112(a), the Federal Circuit developed a framework of factors in In re Wands, 858 F.2d 731, 737, 8 USPQ2d 1400, 1404 (Fed. Cir. 1988), referred to as the Wands factors to assess whether any necessary experimentation required by the specification is "reasonable" or is "undue." Consistent with Amgen Inc. et al. v. Sanofi et al., 598 U.S. 594, 2023 USPQ2d 602 (2023), the Wands factors continue to provide a framework for assessing enablement in a utility application or patent, regardless of technology area. See Guidelines for Assessing Enablement in Utility Applications and Patents in View of the Supreme Court Decision in Amgen Inc. et al. v. Sanofi et al., 89 FR 1563 (January 10, 2024). These factors include, but are not limited to: (A) The breadth of the claims; (B) The nature of the invention; (C) The state of the prior art; (D) The level of one of ordinary skill; (E) The level of predictability in the art; (F) The amount of direction provided by the inventor; (G) The existence of working examples; and (H) The quantity of experimentation needed to make or use the invention based on the content of the disclosure. Claim 1 recites: “A security fob-ring in communication with a security system for assessing a user's security risk based on daily biometric behavior anomalies, the system comprising: a) a processing unit; b) a memory unit; and c) a plurality of coded instructions, stored in the memory unit, that, when executed by the processing unit, cause the system to: i. collect a plurality of human biometric data from a biometric reader; ii. analyze the plurality of human biometric data using an adaptive neural network model that performs rational inference to learn the correlation between the plurality of human biometric data and daily biometric behavior anomalies to determine the user's security risk; iii. determine a risk score of the user based on the daily biometric behavior anomalies, and iv. control access of the user based on the risk score by alerting the user, disconnecting or preventing user access; wherein the security fob-ring enhance physical access control by integrating biometric data and user behavior patterns for authentication by gathering biometric information, from a distributed network. Claim 1 is not enabled under 35 U.S.C. 112(a) because the specification does not teach how to implement the full claimed causal chain from collecting human biometric data to deriving daily biometric behavior anomalies to determining a user’s security risk/risk score to access control. The specification recites at a high-level that the system collects human biometric data (¶14, ¶17, ¶22, ¶46, ¶67), analyzes the data using an adaptive neural network model (¶15, ¶49-54, ¶65-¶69), and assigns a risk score based on the identified human behavior anomalies (¶16, ¶49, ¶70-¶73, ¶93, FIG. 7). The specification does not provide sufficient operational detail as to how the anomalies are detected, encoded, classified, or converted into a risk score used to control access. Quantity of Experimentation: The quantity of experimentation is substantial because a person of ordinary skill in the art would still need to determine what qualifies as a “daily biometric behavior anomaly”, how to label or cluster anomaly classes, what features to extract from raw human biometric inputs, how to encode those features into the adaptive neural network model, how to build the claimed correlation matrix, and how to transform the daily biometric behavior anomaly output into a risk score that controls network access. The specification only discloses that human biometric data may be collected from a wearable device or other biometric sensing devices and processed by an adaptive neural network to determine a risk score of a user. The specification does not teach the concrete implementation steps needed to bridge the gap from encoding/processing human biometric data as inputs to the claimed adaptive neural network inference correlation anomaly determination to risk scoring steps. Amount of Direction Provided by the Inventor The specification provides broad conceptual guidance and recites high-level technical architecture without providing the concrete steps for the causal chain. The specification discloses collecting human biometric data (¶14, ¶17, ¶22, ¶46, ¶67), using an adaptive neural network model performing rational inference to learn correlations that predicts behavioral transitions (¶15, ¶20, ¶54-¶56, ¶65-¶69, ¶92, ¶93), and assigning risk scores for a user (¶16, ¶49, ¶70-¶73, FIG. 4), yet the specification does not teach the specific rules, parameters, encoding techniques, or thresholding logic a person of ordinary skill in the art would need to implement the claimed sequence in a functional security system. The specification remains generic as to how the system identifies daily human biometric behavior anomalies or how the anomalies are correlated into a risk score and used for access control. The specifications repeated use of permissive language such as “may”, “can”, and “could” reinforces that the specification is conceptual as opposed to operational (¶38, ¶40, ¶47, ¶55). Nature of the invention: The nature of the invention weighs against enablement because the invention is an adaptive neural network-based security system that depends on specific human biometric data processing steps. The specification ties the invention to adaptive neural network processing of human biometric data, correlation learning (¶15, ¶46, ¶47, ¶49-¶54), risk scoring and network access control (¶71-¶73, ¶77, ¶78, ¶93). This means the specification must teach the bridge from biometric input/encoding to adaptive neural network human biometric behavior anomaly classification to risk score generation. Without disclosure of specific information for each of these steps, a person of ordinary skill in the art is left to devise these steps without meaningful guidance. Breadth of claims: The claim limitations are broad because they cover collecting a plurality of human biometric data, analyzing the data with a generic adaptive neural network model that performs generic rational inference to determine a correlation between the data and daily biometric behavior anomalies, determining a risk score from the anomalies, and controlling access based on the risk score. The breadth of the claims is not matched with a concrete and descriptive specification. The specification allows for any human biometric data to be collected (¶13-¶15, ¶17, ¶21, ¶46), any adaptive neural network model to encode/process the biometric data for inference learning (¶50-¶54, ¶65-¶68), but does not supply a concrete mapping for the claimed adaptive neural network human biometric behavior anomaly identification to risk scoring pathway. The breadth of the claims magnifies the need for enabling detail, and the specification does not provide the full steps needed for the limitations in sequence to support the scope as claimed. Accordingly, a person of ordinary skill in the art would need to engage in undue experimentation to practice the claimed invention because the specification does not disclose how to transform human biometric inputs into daily biometric behavior anomalies, how to encode and classify the anomalies using an adaptive neural network model, how to generate a risk score from the derived anomalies, nor how to use the generated risk score to control network access. The specification describes the biometric security system at a generically functional level and repeatedly recites generalized collection of human biometric data, generic adaptive neural network correlation to derive anomalies, and user risk score generation. Accordingly, the specification does not provide the technical steps necessary to practice the claimed causal chain across the full scope. Claims 2-9 depend on the rejected claim 1 and do not overcome the deficiency raised in the rejection of the parent claim. The rejection of the dependent claims based on their dependency may be in addition to any rejections raised against the dependent claims themselves. Claim 1 and 3 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Referring to claim 1, the claim recites the limitation “wherein the security fob-ring enhance physical access control by integrating biometric data and user behavior patterns for authentication by gathering biometric information, from a distributed network”. Under broadest reasonable interpretation the security fob-ring gathering biometric information from a distributed network encompasses the security fob-ring gathering biometric information from any source on the distributed network. The specification only discloses the security fob-ring’s biometric sensors as nodes within the distributed network gathering biometric information (¶15, ¶17, ¶21, ¶22, ¶64, ¶93). Accordingly, the specification does not provide support for the broad genus as claimed. Claims 2-9 depend on the rejected claim 1 and do not overcome the deficiency raised in the rejection of the parent claim. The rejection of the dependent claims based on their dependency may be in addition to any rejections raised against the dependent claims themselves. Referring to claim 3, the claim recites “the system of claim 2, wherein the two-phase machine learning engine predicts the risk score for a set of predefined security hardenings”. As per the 112a enablement analysis of claim 1 for the limitation “wherein the system generates a risk score”, the limitation of “two-phase machine learning engine predicts the risk score” is rejected under the same merits and does not overcome the rejection. For the additional limitation of “for a set of predefined security hardenings”, the specification does not disclose a set of predefined security hardenings for risk score generation. A person of ordinary skill in the art would understand that the term “security hardening” refers to protective measures implemented by a system to minimize vulnerability. The specification discloses in 49: “System 100 may use an adaptive neural network to analyze the human biometrics data to determine human condition and disturbance level and determine the risk score of the user”. Under broadest reasonable interpretation human biometric data are inputs for the rational inference performed by the adaptive neural network model. Human biometric data is not synonymous with controls/configurations or outputs to execute when conditions happen that are applied to protect a system. Examples of security hardenings include multifactor authentication, security policies, or firewall rules. Claim 4 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. Claim 4 recites “The system of claim 2, wherein the two-phase machine learning engine, in a first mode, predicts a set of upcoming behavior transitions during an intense and previously unseen task by utilizing a temporal context of daily biometric behavior and simulating attention shifts.”. The specification recites a potential wake-sleep algorithm as a two-phase algorithm in ¶25. Further in ¶62 describing an embodiment of the first phase: “In the first phase 210, the network learns how to predict by projecting a cheap approximation of the real posterior”. Then in ¶63: “In the first phase, the model may apply learning rules that would be correct if the samples are taken from the true posterior. True posterior in this case, is the samples from the disorder model that is pre-recorded and borrowed from external sources”. The specification does not provide the inputs and outputs of the first mode, a step-by-step algorithm defining the first phase or the sequence of operations to be performed during prediction. For the limitation: “predicts a set of behavior transitions”, this claim requires a defined behavioral state representation, identifiable transitions between states and a prediction output format. The specification recites the limitation at a high-level in ¶54: “In phase 212, the model predicts upcoming behavioral transitions … The model in phase 210 uncovers the correlating points between the simulated patterns and the risk model.” The specification does not define what constitutes a behavior state, how a transition is represented, how the set of transitions is generated/extracted. For the limitation of “during an intense and previously unseen task”. This limitation requires the machine learning engine to predict transitions when the machine learning engine encounters tasks not previously observed during training. The specification merely recites the limitation in without explaining the implementation step in ¶54. The specification does not disclose how the machine learning engine determines that a task is unseen, how the machine learning engine makes predictions beyond using general training data, or what algorithm supports inference for “unseen tasks”. For the limitation “by utilizing a temporal context of daily biometric behavior”, specification discloses movements and fixations in 54 and biometric movement tracking in ¶67. There is no disclosure of how the biometric data collected is encoded into temporal context or how temporal context affects prediction decisions. For the limitation of “simulating attention shifts”, the specification recites this limitation at a high-level without any implementation steps in ¶54 and ¶69. Claim 5 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. Claim 5 recites: “The system of claim 2, wherein the two-phase machine learning engine in second mode, identifies a set of correlating points between a set of simulated behavior patterns and a set of risk disorders”. The specification discloses recites these limitations at a high-level without any concrete implementation steps in ¶54 and ¶69. The specification makes no mention for the structure of correlation (statistical, probabilistic) or how to extract correlating points. For the limitation of “between a set of simulated behavior patterns and set of risk disorders”, the specification does not disclose how simulated patterns are generated/represented nor how the set of risk disorders are represented. Claim 7 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. Claim 7 recites: “The system of claim 1, wherein the adaptive neural network model is trained using a set of recorded personal behavior data comprising several populations of equivalently structured, interconnected neurons represented as generic leaky integrate-and-fire neurons, trained with spike-timing-dependent plasticity (STDP).”. The specification recites the structure of the GLIF populations in 56-59. The specification further recites training using STDP in ¶60-¶63. However, the specification makes no mention of how “a set of recorded personal behavior data” is encoded into the GLIF adaptive neural network model nor how to partition/categorize the recorded personal behavior data into distinct populations as the structure needed for the encoding. Claim 10 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. Claim 10 recites “A method for assessing a security risk of a user, the method comprising the steps of: a) collecting, at a computing device, human biometrics data, comprising daily activity data from a plurality of field biometric sensing devices; b) analyzing, at the computing device, the human biometrics data using an adaptive neural network model that performs rational inference to learn a correlation between a human biometric anomalies and the security risk of the user to determine a security hardening; c) determining, at the computing device or a personal data-collecting unit, a risk score of the user based on a daily behavior anomalies of the user; d) determining a correlation matrix by comparing the risk score of the user, and e) controlling a network access by the computing device to regulate security access based on the risk score.”. The limitations a, b, c are rejected under the same merits as per the 112a enablement analysis of claim 1. Limitations d and e depend on the non-enabled limitation c and do not overcome the deficiency raised in the rejection. Claim 10 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. For the limitation of b) analyzing, at the computing device, the human biometrics data using an adaptive neural network model that performs rational inference to learn a correlation between a human biometric anomalies and the security risk of the user to determine a security hardening. The element “security hardening” is not disclosed in the specification as an output of the rational inference performed by an adaptive neural network. The specification mentions security actions to take for a user in response to a risk score in ¶71-¶73, ¶77-¶78. A person of ordinary skill in the art would understand that the term “security hardening” refers to protective measures implemented by a system to minimize vulnerability. Specific actions to take towards the user in response to a risk score are not modifications that improve the security architecture of the system. Claims 11-19 depend on rejected claim 10 and do not overcome the deficiency raised in the rejection of their parent claim.. The rejection of the dependent claims based on their dependency may be in addition to any rejections raised against the dependent claims themselves. Claim 14 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. Regarding claim 14, claim 14 recites: “The method of claim 12, wherein the two-phase machine learning engine, in a first mode, predicts upcoming behavior transitions during an intense and unseen visual task by exploiting a temporal context of behavior stall and simulating attention shifts.”. The additional limitations of claim 14 are rejected under the same merits as the 112a enablement analysis of claim 4. Claim 15 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. Regarding claim 15, claim 15 recites: “The method of claim 12, wherein the two-phase machine learning engine, in second mode, identifies a set of correlating points between simulated behavior patterns and security risks.“. The additional limitations of claim 15 are rejected under the same merits as the 112a enablement analysis of claim 5. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim(s) 1-19 is/are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Regarding claim 1, the term “security fob-ring” fails to particularly point out and distinctly claim the subject matter regarded as the invention. The specification describes a “smart ring” and separately describes “security fobs,” but does not clearly define whether “security fob-ring” refers to a combined fob-and-ring device, a ring in communication with a separate fob, or some other structure. In addition, the claim language creates uncertainty as to whether the applicant is claiming a fob, a system, or both, because the preamble recites a “security fob-ring in communication with a security system,” while the body of the claim recites a system with processing and memory components. Accordingly, the metes and bounds of the claimed invention are not reasonably clear to those skilled in the art.Claims 2-9 depend on the rejected claim 1 and do not overcome the deficiency raised in the rejection of the parent claim. The rejection of the dependent claims based on their dependency may be in addition to any rejections raised against the dependent claims themselves. Regarding claim 9, claim 9 recites: “The system of claim 8, wherein the risk score of the user is determined based on the correlation matrix using a machine learning model”. Claim 9 depends on the limitations of claim 8, claim 8 recites: “The system of claim 1, further comprising a correlation matrix determined by correlating the risk score through the distributed network, wherein network access is controlled based on the correlation matrix”. Under broadest reasonable interpretation claim 9 presents an unclear dependency relationship between the risk score and the correlation matrix. It is unclear whether the risk score is an input to the generation of the correlation matrix, the risk score is an output derived from the correlation matrix, or the claim is directed to an iterative or multi-stage process involving multiple risk score calculations. Regarding claim 10, claim 10 recites the limitation “determining a correlation matrix by comparing the risk score of the user” without specifying the additional element for comparison. A person of ordinary skill in the art would not be able to determine the scope of the claim with reasonable certainty. Applicant should amend the claim to explicitly recite the comparison element. Claims 11-19 depend on the rejected claim 10 and do not overcome the deficiency raised in the rejection of the parent claim. The rejection of the dependent claims based on their dependency may be in addition to any rejections raised against the dependent claims themselves. Regarding claim 17, claim 17 recites the limitation: “the adaptive neural network model is trained using a recorded behavior shift data”. For the element: “a recorded behavior shift data”, the specification does not disclose the scope of “a recorded behavior shift data” with reasonable certainty. The specification recites “nuanced shifts” in human behavior during different times of day in 7, however there is no explicit definition or structure for what a shift encompasses, nor how it is tied to being recorded nor as being a form of the broadly encompassed field of behavior data. Regarding claim 19, claim 19 recites: “The method of claim 18, wherein the risk score of the user is determined based on the correlation matrix using a machine learning model.”. Claim 19 depends on the limitations of claim 18, claim 18 recites: “The method of claim 10, further comprising determining a correlation matrix by correlating the risk score with a network activity log of the user, wherein the network access is controlled based on the correlation matrix.”. Claim 19 is rejected for the same reasons as the rejection for claim 9. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim(s) 1-19 rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Regarding claim 1 Applying the subject matter eligibility analysis for products and processes as outlined in MPEP § 2106: Step 1 – YES: “machine” The claim recites a security fob-ring in communication with a security system, the system comprising a processing unit, a memory unit, and a plurality of coded instructions stored in the memory unit, that, when executed by the processing unit cause the system to do limitations. This satisfies the statutory category requirement under 35 U.S.C § 101. Step 2A Prong I – Does the claim recite a judicial exception? YES. The claim recites a judicial exception falling within the abstract idea category of mental processes. Judicial Exception Identified: The claim recites a plurality of coded instructions, stored in the memory unit, that, when executed by the processing unit, cause the system to: “collect a plurality of human biometric data from a biometric reader”, “analyze a plurality of human biometric data … to determine the user’s security risk” and “determine a risk score of the user”, which maps to the abstract sub-category under mental processes of collecting information, analyzing it, and displaying certain results of the collection and analysis (M.P.E.P. 2106.04(a)(2)(III)(A)). Supporting Precedent: Elec. Power Grp., LLC v. Alstom S.A., 830 F.3d 1350 (Fed. Cir. 2016): The court found that claims directed to collecting data, analyzing the data, and displaying or acting on results are abstract ideas. The court emphasized that the mere fact that data is collected from a computer system does not render the underlying concept non-abstract if it involves generic data processing. FairWarning IP, LLC v. Iatric Sys., Inc., 839 F.3d 1089 (Fed. Cir. 2016): The court held that monitoring access to patient records, detecting suspicious activity, and generating alerts constitutes an abstract idea because the steps involve collecting and analyzing data to detect misuse and notify users—activities that can be performed mentally or by human observation. Symantec Corp. v. Quicken Loans Inc., 838 F.3d 1312 (Fed. Cir. 2016): Although the claims recited an electronic post office that received, screened, and distributed email, the court found that nothing in the claims foreclosed these actions from being performed by a human, mentally, or with pen and paper. The use of a computer as a tool to perform a mental process does not render the process patent-eligible. See also MPEP 2106.04(a)(2)(III)(c). Conclusion: The claim recites an abstract idea and therefore proceeds to Step 2A Prong II. Step 2A Prong II (Claim 1) - Does the claim recite additional elements that integrate the judicial exception into a practical application? NO. The claim does not demonstrate integration into a practical application. The additional elements are generic context and do not provide a technological improvement or meaningful application of the exception. The additional elements include a generic processor, generic memory, generic adaptive neural network, generic computerized security fob-ring, generic computer security system. Analysis: No Particular machine or Apparatus The additional elements as a combination comprising a processor, memory, generic neural network, generic computerized security fob-ring, and generic computer security system are recited at a high level of generality and represent generic computer or device components. The claim does not require a particular machine that meaningfully limits the abstract idea. No Transformation of an Article: The claim merely operates entirely on intangible data (collecting/analyzing/transmitting) and produces intangible results (access control). There is no transformation of a physical substrate or article. See In re Bilski, 545 F.3d 943, 960 (Fed. Cir. 2008). Mere Instructions to Apply an Exception The additional elements comprising a processor, memory, generic neural network, generic computerized security fob-ring, and generic computer security system do not amount to more than a recitation of the words "apply it" (or an equivalent) or are more than mere instructions to implement an abstract idea or other exception on a computer. The claim does not recite any specific technological mechanism for performing these steps beyond a generic combination of computer components implementation. Insignificant Extra-Solution Activity The additional elements do not add more than insignificant extra-solution activity to the judicial exception. A security fob-ring in communication with a security system for the function of transmitting/receiving/analyzing biometric data for access control falls under the insignificant extra solution activities of Mere Data Gathering and Selecting a particular data source or type of data to be manipulated (See M.P.E.P. 2106.05(g)(3)). Field of Use and Technological Environment • The additional elements do not amount to more than generally linking the use of a judicial exception to a particular technological environment or field of use. The security fob-ring in communication with the security system and the elements comprising the security system of a generic processor, generic memory, and generic neural network do not improve the operation of the security system or introduce new technical architecture within the security system (See Electric Power Group, LLC v. Alstom S.A., 830 F.3d 1350, 1354 (Fed. Cir. 2016), and M.P.E.P. 2106.05(h)). Conclusion: The claim does not integrate the exception into a practical application. The analysis proceeds to Step 2B. Step 2B - Does the claim recite additional elements that amount to “significantly more” than the exception itself? NO. The additional elements do not amount to “significantly more” than the exception. They are well-understood, routine, and conventional in the art. WURC (well-understood routine and conventional) Assessment: Generic Processor/Memory — These are generic computing components standard for any security system performing computational operations. There is no specific configuration or technical improvement for these components. See spec. disclosure of the generic processor in ¶34, ¶36, ¶94, and ¶95 and see spec. ¶35, ¶97, and ¶98 for disclosure of generic memory. Generic neural network — Neural networks are a known computational resource to a person of ordinary skill in the art, see spec. ¶15, ¶20, ¶25 for disclosure of specific types of known neural network models. Generic security fob-ring — Claim recites “a security fob-ring in communication with a security system”. The security system is comprised of a processing unit, a memory unit, and a plurality of coded instructions. Under broadest reasonable interpretation this implies the security fob-ring comprises generic computer components needed to establish communication with the security system such as a processor, memory unit, and communication device such as a USB controller/transceiver or NIC card. These are generic computing components known to a person of ordinary skill in the art. Generic security system — The claim recites that the security system comprises of the generic computing components of a processor, memory unit, and a plurality of coded instructions to execute limitations. These are generic computing components configured to perform their intended use known to a person of ordinary skill in the art. Berkheimer Standard: Under Berkheimer v. HP Inc., 881 F.3d 1360 (Fed. Cir. 2018), an applicant may overcome a WURC rejection by providing evidence (e.g., technical comparisons, performance metrics, implementation details) that the claimed elements are not routine in the art. The specification provides no such evidence. There are: No performance metrics or efficiency gains No evidence that the combination achieves a non-obvious or non-conventional result Conclusion: The additional elements are WURC and do not amount to “significantly more” than the abstract idea. The combination of a security fob-ring using generic computer components in communication with a security system comprising the generic computing elements of a processing unit, memory unit, and a plurality of coded instructions including the use of a generic neural network is a generic implementation of a security system with generic computational authentication devices. Claims 2, 6, 7, 8 are dependent claims that add limitations to Claim 1. Because Claim 1 is ineligible, all dependent claims that do not cure the § 101 deficiency are likewise ineligible. Regarding claim 2: Step 1 - YES: similar to parent claim 1, satisfying the statutory category. Step 2A Prong I – NO: claim 2 does not recite a judicial exception. FINAL CONCLUSION: Claim 2 is INELLIGIBLE under 35 U.S.C. § 101 since claim 2 depends on claim 1 and claim 1 is rejected under 35 U.S.C. § 101. Regarding claim 6: Step 1 - YES: similar to parent claim 1, satisfying the statutory category. Step 2A Prong I – NO: claim 6 does not recite a judicial exception. FINAL CONCLUSION: Claim 6 is INELLIGIBLE under 35 U.S.C. § 101 since claim 6 depends on claim 1 and claim 1 is rejected under 35 U.S.C. § 101. Regarding claim 7: Step 1 - YES: similar to parent claim 1, satisfying the statutory category. Step 2A Prong I – NO: claim 7 does not recite a judicial exception.. FINAL CONCLUSION: Claim 7 is INELLIGIBLE under 35 U.S.C. § 101 since claim 7 depends on claim 1 and claim 1 is rejected under 35 U.S.C. § 101. Regarding claim 8: Step 1 - YES: similar to parent claim 1, satisfying the statutory category. Step 2A Prong I – NO: claim 8 does not recite a judicial exception. . FINAL CONCLUSION: Claim 8 is INELLIGIBLE under 35 U.S.C. § 101 since claim 8 depends on claim 1 and claim 1 is rejected under 35 U.S.C. § 101. Claims 3, 4, 5 are dependent claims that add limitations to Claim 2. Because Claim 2 is ineligible, all dependent claims that do not cure the § 101 deficiency are likewise ineligible. Regarding claim 3: Step 1 - YES: similar to parent claim 2, satisfying the statutory category. Step 2A Prong I – YES: claim 3 recites a judicial exception. The additional limitation specifies: The system of claim 2, wherein the two-phase machine learning engine predicts the risk score for a set of predefined security hardenings. This is the abstract categories of collecting information, analyzing it, and displaying certain results of the collection and analysis under mental processes (M.P.E.P. 2106.04(a)(2)(III)(A)). Step 2A Prong II - NO: Claim 3 does not integrate the exception into a practical application. The specification of the machine learning engine predicting the risk score for a set of security hardenings is merely using a generic well-understood feature incorporated on a computer configured to perform data analysis. There is no improvement to the functioning of computer technology. The abstract idea does not require more than a general-purpose machine to implement, there is no transformation of an article, does not amount to more than insignificant extra solution activity: merely utilizing a generic machine learning model to perform data analysis are no more than mere instructions to implement the abstract idea on a generic computer. Step 2B - NO: The additional limitation of “the two-phase machine learning engine” to predict a risk score is routine data analysis and Is WURC and does not amount to significantly more. Computational data analysis incorporated using a generic machine learning engine is a well-understood feature performed on a computer and is considered conventional. FINAL CONCLUSION: Claim 3 is INELLIGIBLE under 35 U.S.C. § 101 Regarding claim 4: Step 1 - YES: similar to parent claim 2, satisfying the statutory category. Step 2A Prong I – NO: claim 4 does not recite a judicial exception. FINAL CONCLUSION: Claim 4 is INELLIGIBLE under 35 U.S.C. § 101 since claim 4 depends on claim 2 and claim 2 is rejected under 35 U.S.C. § 101. Regarding claim 5: Step 1 - YES: similar to parent claim 2, satisfying the statutory category. Step 2A Prong I – NO: claim 5 does not recite a judicial exception. FINAL CONCLUSION: Claim 5 is INELLIGIBLE under 35 U.S.C. § 101 since claim 5 depends on claim 2 and claim 2 is rejected under 35 U.S.C. § 101. Claims 9 is a dependent claim that adds limitations to Claim 8. Because Claim 8 is ineligible, all dependent claims that do not cure the § 101 deficiency are likewise ineligible. Regarding claim 9: Step 1 - YES: similar to parent claim 8, satisfying the statutory category. Step 2A Prong I – NO: claim 9 does not recite a judicial exception. FINAL CONCLUSION: Claim 9 is INELLIGIBLE under 35 U.S.C. § 101 since claim 9 depends on claim 8 and claim 8 is rejected under 35 U.S.C. § 101. Regarding claim 10 Applying the subject matter eligibility analysis for products and processes as outlined in MPEP §2106: Step 1 – YES: “process”, the claim recites: “A method for assessing a security risk of a user, the method comprising the steps…”. This satisfies the statutory category requirement under 35 U.S.C § 101(A). Step 2A Prong I – Does the claim recite a judicial exception? YES. The claim recites a judicial exception falling within the abstract idea category specifically, mental processes and mathematical concepts. Judicial Exception Identified: The claim recites: “collecting, at a computing device, human biometrics data”, “analyzing, at the computing device, the human biometrics data using an adaptive neural network model”, and “determining, at the computing device or a personal data-collecting unit, a risk score” which maps to the abstract idea of collecting information, analyzing it, and displaying certain results of the collection and analysis under mental processes (M.P.E.P. 2106.04(a)(2)(III)(a)). The claim further recites “determining a correlation matrix by comparing the risk score of the user”, correlations are categorized as the Mathematical Relationships sub-category under Mathematical Concepts (M.P.E.P. 2106.04(a)(2)(I)). Supporting Precedent: Elec. Power Grp., LLC v. Alstom S.A., 830 F.3d 1350 (Fed. Cir. 2016): The court found that claims directed to collecting data, analyzing the data, and displaying or acting on results are abstract ideas. The court emphasized that the mere fact that data is collected from a computer system does not render the underlying concept non-abstract if it involves generic data processing. FairWarning IP, LLC v. Iatric Sys., Inc., 839 F.3d 1089 (Fed. Cir. 2016): The court held that monitoring access to patient records, detecting suspicious activity, and generating alerts constitutes an abstract idea because the steps involve collecting and analyzing data to detect misuse and notify users—activities that can be performed mentally or by human observation. Symantec Corp. v. Quicken Loans Inc., 838 F.3d 1312 (Fed. Cir. 2016): Although the claims recited an electronic post office that received, screened, and distributed email, the court found that nothing in the claims foreclosed these actions from being performed by a human, mentally, or with pen and paper. The use of a computer as a tool to perform a mental process does not render the process patent-eligible. See also MPEP 2106.04(a)(2)(III)(c). Digitech Image Techs., LLC v. Elecs. for Imaging, Inc., 758 F.3d 1344, 1350, 111 USPQ2d 1717, 1721 (Fed. Cir. 2014). The court held that claims directed to a “‘process of organizing information through mathematical correlations’’ are directed to an abstract idea. Conclusion: The claim recites an abstract idea and therefore proceeds to Step 2A Prong II. Step 2A Prong II - Does the claim recite additional elements that integrate the judicial exception into a practical application? NO. The claim does not demonstrate integration into a practical application. The additional elements are generic context and do not provide a technological improvement or meaningful application of the exception. Analysis: No improvement to computer functionality/technology Generic processor Generic memory Generic neural network No Particular machine or Apparatus The additional elements as a combination comprising a processor, memory, generic neural network are recited at a high level of generality and represent generic computer or device components. The claim does not require a particular machine that meaningfully limits the abstract idea. No Transformation of an Article: The claim merely operates entirely on intangible data (collecting/analyzing/transmitting) and produces intangible results (access control). There is no transformation of a physical substrate or article. See In re Bilski, 545 F.3d 943, 960 (Fed. Cir. 2008). Mere Instructions to Apply an Exception The additional elements comprising a processor, memory, and generic neural network do not amount to more than a recitation of the words "apply it" (or an equivalent) or are more than mere instructions to implement an abstract idea or other exception on a computer. The claim does not recite any specific technological mechanism for performing these steps beyond a generic combination of computer components implementation. Insignificant Extra-Solution Activity The additional elements do not add more than insignificant extra-solution activity to the judicial exception. A computing device communicating with a network for the function of transmitting/receiving/analyzing biometric data for access control falls under the insignificant extra solution activities of Mere Data Gathering and Selecting a particular data source or type of data to be manipulated (See M.P.E.P. 2106.05(g)(3)). Field of Use and Technological Environment • The additional elements do not amount to more than generally linking the use of a judicial exception to a particular technological environment or field of use. The computing device in communication with a network does not improve the operation of the security system or introduce new technical architecture within the security system (See Electric Power Group, LLC v. Alstom S.A., 830 F.3d 1350, 1354 (Fed. Cir. 2016), and M.P.E.P. 2106.05(h)). Conclusion: The claim does not integrate the exception into a practical application. The analysis proceeds to Step 2B. Step 2B- Does the claim recite additional elements that amount to “significantly more” than the exception itself? NO. The additional elements do not amount to “significantly more” than the exception. They are well-understood, routine, and conventional in the art. WURC (well-understood routine and conventional) Assessment: Generic Processor/Memory — These are generic computing components standard for any security system performing computational operations. There is no specific configuration or technical improvement for these components. See spec. disclosure of the generic processor in ¶34, ¶36, ¶94, and ¶95 and see spec. ¶35, ¶97, and ¶98 for disclosure of generic memory. Generic neural network — Neural networks are a known computational resource to a person of ordinary skill in the art, see spec. ¶15, ¶20, ¶25 for disclosure of specific types of known neural network models. Generic Network— The claim recites “correlating the risk through a distributed network” with no disclosure of any specific type of network architecture (See ¶14, ¶15, ¶31, ¶45). Under broadest reasonable interpretation network computing components are generic computing components configured to perform their intended use known to a person of ordinary skill in the art. Berkheimer Standard: Under Berkheimer v. HP Inc., 881 F.3d 1360 (Fed. Cir. 2018), an applicant may overcome a WURC rejection by providing evidence (e.g., technical comparisons, performance metrics, implementation details) that the claimed elements are not routine in the art. The specification provides no such evidence. There are: No performance metrics or efficiency gains No evidence that the combination achieves a non-obvious or non-conventional result Conclusion: The additional elements are WURC and do not amount to “significantly more” than the abstract idea. The combination of a generic computing device using generic computer components in communication with a distributed network is a generic implementation of a security system with generic computational authentication devices. Claims 11, 12, 16, 17, 18 are dependent claims that add limitations to Claim 10. Because Claim 10 is ineligible, all dependent claims that do not cure the § 101 deficiency are likewise ineligible. Regarding claim 11: Step 1 - YES: similar to parent claim 10, satisfying the statutory category. Step 2A Prong I – YES: claim 11 recites a judicial exception. The additional limitation specifies: The method of claim 10, wherein controlling the network access comprises alerting the user, disconnecting the network connection of the user and notifying an administrative user. For the specific additional limitation of alerting/notifying, this is the specific abstract ideas of collecting information, analyzing it, and displaying certain results of the collection and analysis under mental processes (M.P.E.P. 2106.04(a)(2)(III)(A)). Step 2A Prong II - NO: Claim 11 does not integrate the exception into a practical application. The specification of the computing device is merely generic computing components. There is no improvement to any components associated with the computing device or the functionality of the computing device itself. The abstract idea does not require more than a general-purpose machine to implement, there is no transformation of an article, and the claim does not amount to more than insignificant extra solution activity. Step 2B - NO: The additional limitation of the computing device Is WURC and does not amount to significantly more. FINAL CONCLUSION: Claim 11 is INELLIGIBLE under 35 U.S.C. § 101 Regarding claim 12: Step 1 - YES: similar to parent claim 10, satisfying the statutory category. Step 2A Prong I – NO The additional limitations do not recite a judicial exception. FINAL CONCLUSION: Claim 12 is INELLIGIBLE under 35 U.S.C. § 101 since claim 12 depends on claim 10 and claim 10 is rejected under 35 U.S.C. § 101. Regarding claim 16: Step 1 - YES: similar to parent claim 10, satisfying the statutory category. Step 2A Prong I – NO: The additional limitations do not recite a judicial exception. FINAL CONCLUSION: Claim 16 is INELLIGIBLE under 35 U.S.C. § 101 since claim 16 depends on claim 10 and claim 10 is rejected under 35 U.S.C. § 101. Regarding claim 17: Step 1 - YES: similar to parent claim 10, satisfying the statutory category. Step 2A Prong I – NO: The additional limitations do not recite a judicial exception. FINAL CONCLUSION: Claim 17 is INELLIGIBLE under 35 U.S.C. § 101 since claim 17 depends on claim 10 and claim 10 is rejected under 35 U.S.C. § 101. Regarding claim 18: Step 1 - YES: similar to parent claim 10, satisfying the statutory category. Step 2A Prong I – NO: The additional limitations do not recite a judicial exception. FINAL CONCLUSION: Claim 18 is INELLIGIBLE under 35 U.S.C. § 101 since claim 18 depends on claim 10 and claim 10 is rejected under 35 U.S.C. § 101. Claims 13, 14, 15 are dependent claims that add limitations to Claim 12. Because Claim 12 is ineligible, all dependent claims that do not cure the § 101 deficiency are likewise ineligible. Regarding claim 13: Step 1 - YES: similar to parent claim 12, satisfying the statutory category. Step 2A Prong I – NO claim 13 does not recite a judicial exception. FINAL CONCLUSION: Claim 13 is INELLIGIBLE under 35 U.S.C. § 101 since claim 13 depends on claim 12 and claim 12 is rejected under 35 U.S.C. § 101. Regarding claim 14: Step 1 - YES: similar to parent claim 12, satisfying the statutory category. Step 2A Prong I – NO claim 14 does not recite a judicial exception. FINAL CONCLUSION: Claim 14 is INELLIGIBLE under 35 U.S.C. § 101 since claim 14 depends on claim 12 and claim 12 is rejected under 35 U.S.C. § 101. Regarding claim 15: Step 1 - YES: similar to parent claim 12, satisfying the statutory category. Step 2A Prong I – NO The additional limitations do not recite a judicial exception. FINAL CONCLUSION: Claim 15 is INELLIGIBLE under 35 U.S.C. § 101 since claim 15 depends on claim 12 and claim 12 is rejected under 35 U.S.C. § 101. Claim 19 is a dependent claim that adds limitations to Claim 18. Because Claim 18 is ineligible, all dependent claims that do not cure the § 101 deficiency are likewise ineligible. Regarding claim 19: Step 1 - YES: similar to parent claim 18, satisfying the statutory category. Step 2A Prong I – NO The additional limitations do not recite a judicial exception. FINAL CONCLUSION: Claim 19 is INELLIGIBLE under 35 U.S.C. § 101 since claim 19 depends on claim 18 and claim 18 is rejected under 35 U.S.C. § 101. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 1-19 rejected under 35 U.S.C. 103 as being unpatentable over U.S. PGPub. No. 2022/0094707 A1 (hereinafter “Merat”), in view of Losseva et. Al. PGPub. No. 2021/0112064 A1 (hereinafter “Losseva ”). Referring to claim 1, the claim recites: A security fob-ring in communication with a security system for assessing a user's security risk based on daily Biometric behavior anomalies (Under MPEP § 2111.02, preamble language is given patentable weight when it breathes life and meaning into the claim or otherwise limits the claim scope. Here, the body of claim 1 recites the structural and functional limitations of the security system, including a processing unit, memory unit, coded instructions, biometric data collection, analysis by an adaptive neural network model, determination of a risk score, and control of access based on the risk score. Accordingly, the preamble phrase “security fob-ring in communication with a security system” is treated as a non-limiting recitation of the intended environment or context of use, and is not given separate patentable weight. The additional wherein clause, “wherein the security fob-ring enhance physical access control by integrating biometric data and user behavior patterns for authentication by gathering biometric information, from a distributed network,” is also not given patentable weight to the extent it merely states a result or intended use of the recited system and does not impose a separate structural or functional limitation on the claimed security system.), the system comprising: a) a processing unit (Merat teaches a processor in ¶27, ¶29, ¶64, ¶87); b) a memory unit (Merat teaches a memory unit in ¶28, ¶86, ¶90, ¶91); and c) a plurality of coded instructions, stored in the memory unit, that, when executed by the processing unit, cause the system to: i. collect a plurality of human biometric data from a biometric reader (Merat teaches the system collecting human biometrics data including eye movement data from user wearable devices, biometric readers/sensing devices (abstract, ¶10, ¶40, ¶57, ¶85, claim 1, claim 11)); ii. analyze the plurality of human biometric data using an adaptive neural network model that performs rational inference to learn the correlation between the plurality of human biometric data and daily biometric behavior anomalies to determine the user's security risk (Merat teaches analyzing human biometric data using a GLIF based adaptive neural network model trained using a wake-sleep algorithm in combination with a spiking recurrent neural network model to determine a mental disorder/disturbance level which is correlated with a mental conditional-cyber risk correlation database to determine the users associated cyber risk (abstract, ¶10, ¶13, ¶28-¶31, ¶43-45, ¶56, claims 3-7, claim 11, claims 13-18). Merat does not teach correlating the plurality of human biometric data with daily biometric behavior anomalies. Losseva teaches deriving a user’s biometric behavior anomalies based on movement patterns by storing a weighted directed adjacency matrix representing the user’s behavioral baseline as a footprint (abstract, ¶25, ¶78, ¶124, ¶147, ¶148, ¶156). Losseva further teaches computing a fidelity score based on the standard deviation of the matrix’s weighted values overtime, and using the score to normalize the anomaly detection threshold (¶92-¶94, ¶98, ¶169). Losseva teaches comparing the footprint to earlier user/group footprints to detect deviations/anomalies (abstract, ¶147, ¶155).); iii. determine a risk score of the user based on the daily biometric behavior anomalies (Merat teaches determining a cyber competence score for a user that is indicative of a cyber risk (abstract, ¶10, ¶44, ¶60, ¶65, claim 1, claim 11). Losseva teaches assessing a user’s security risk based on biometric behavioral anomalies by generating a behavioral adjacency matrix (footprint) from a user’s movement patterns tracked over time, and detecting deviations by comparing the behavioral footprint against the user’s or other user’s earlier footprints. The system uses the derived anomalies for risk determination as the basis for access control decisions. (abstract, ¶1, ¶ 72, ¶147, ¶155.)), and iv. control access of the user based on the risk score by alerting the user, disconnecting or preventing user access (Merat teaches controlling network access based on the cyber competence score, wherein the system alerts the user of the “cyber vulnerability”, restricts user access based on a low cyber competence score, and disconnects a user from the network if their cyber competence score is below a threshold (¶12, ¶35, ¶67, claim 2, claim 12).);wherein the security fob-ring enhance physical access control by integrating biometric data and user behavior patterns for authentication by gathering biometric information, from a distributed network (Since the additional limitations are directed to the security fob-ring which was not given patentable weight, these additional limitations are not given patentable weight.). Accordingly, it would have been obvious before the effective filing of the invention to modify Merat by combining prior art elements according to known methods to yield predictable results with the teachings of Losseva. A person of ordinary skill in the art would have recognized to combine the biometric security system taught by Merat with the behavioral anomaly detection security system taught by Losseva. Both security systems utilize biometric behavioral data assessing user vulnerability, and use compatible computational functionality to achieve the same comprehensive and analytical security system. Incorporating Losseva’s analytical feature providing the temporal context of daily biometric behaviorial anomalies and the set of predefined security hardenings into Merat’s adaptive neural network model security system would have been a straightforward combination of using known elements, using known methods to yielding the predictable result of an enhanced security system. Referring to claim 2, the claim recites: the system of claim 1, wherein the adaptive neural network model is trained using a two-phase machine learning engine in combination with a spiking recurrent network model. Merat teaches “the adaptive neural network model is trained using a two-phase machine learning engine in combination with a spiking recurrent network model” in ¶11, ¶58, claim 3, and claim 13. Referring to claim 3, the claim recites: The system of claim 2, wherein the two-phase machine learning engine predicts the risk score for a set of predefined security hardenings Merat teaches the limitation wherein the two-phase machine learning engine predicts the risk score (abstract, ¶10, ¶42, ¶85). Merat does not teach the additional limitation for a set of predefined security hardenings. Losseva teaches the limitation of a set of predefined security hardenings. Losseva teaches a user’s fidelity score as a determination for the level of authentication required. Losseva that high fidelity scores require low authentication measures like camera surveillance, whereas low fidelity scores require additional authentication measures like entering a pin or using a keycard or a fob. Losseva further teaches a similarity score compared to a predefined threshold to detect anomalies by comparing the derived user’s current challenge template containing the users most recent movement data to an identity template containing previous biometric movement behavior data of the user/group to detect deviations. Losseva teaches that when deviations/anomalies are detected by the system, this requires the user to engage in additional measures like “step-up authentication” (¶28, ¶30, ¶95, ¶144). Referring to claim 4, the claim recites: The system of claim 2, wherein the two-phase machine learning engine, in a first mode, predicts a set of upcoming behavior transitions during an intense and previously unseen task by utilizing a temporal context of daily biometric behavior and simulating attention shifts. Merat teaches the additional limitation wherein the two-phase machine learning engine, in a first mode, predicts a set of upcoming behavior transitions during an intense and previously unseen task by utilizing a temporal context of biometric behavior and simulating attention shifts in ¶59: “The wake-sleep machine learning engine in a sleep mode predicts next gaze transitions during a more intense and previously unseen visual task by exploiting the temporal context of gaze fixation and simulating attention shifts”. Furthermore in ¶11, ¶46, claim 5, and claim 15. Merat does not teach the additional limitation for the temporal context of daily. Losseva teaches the temporal context of daily. Losseva teaches the system utilizing a comparison engine to compare the user’s current motions represented in a challenge template to the previous motions (“from for example, the day before”) referenced by an identity template to assess similarity for access in a restricted space (¶84, ¶139). Losseva further teaches that anomalies are detected by comparison of the user’s “footprints” which contain extracted data from the user’s daily work shifts, wherein the user’s daily authentication patterns are represented in the form of text string sequences (¶59-65, ¶155-¶158). Referring to claim 5, the claim recites: the system of claim 2, wherein the two-phase machine learning engine in second mode, identifies a set of correlating points between a set of simulated behavior patterns and a set of risk disorders. Merat teaches the limitations of claim 5 in ¶59: “The wake-sleep machine learning engine in wake mode undercovers correlating points between simulated gaze patterns to mental disorders”. Furthermore in ¶11 ¶59, claim 6, and claim 16. Referring to claim 6, the claim recites: The system of claim 1, wherein the adaptive neural network model is based on Generic-Leaky-Integrate-and-Fire (GLIF) neural network model Merat teaches these additional limitations in ¶10, 59, claim 7, and claim 17. Referring to claim 7, the claim recites: The system of claim 1, wherein the adaptive neural network model is trained using a set of recorded personal behavior data comprising several populations of equivalently structured, interconnected neurons represented as generic leaky integrate-and-fire neurons, trained with spike-timing-dependent plasticity (STDP). Merat teaches these additional limitations in ¶11: “the adaptive neural network model is trained using recorded eye movement data comprising of several populations of equivalently structured, interconnected, data represented in form of generic leaky integrate-and-fire neurons, which are trained with spike-timing-dependent plasticity (STDP)”. Furthermore in ¶46, ¶56, claim 8, and claim 18. Referring to claim 8, the claim recites the system of claim 1, further comprising a correlation matrix determined by correlating the risk score through the distributed network, wherein network access is controlled based on the correlation matrix. Merat teaches a system determining a correlation matrix by correlating a cyber competence score of the user with the network activity log of the user, wherein network access is controlled based on the correlation matrix (¶63, ¶85, claim 9, claim 19). Referring to claim 9, the claim recites the system of claim 8, wherein the risk score of the user is determined based on the correlation matrix using a machine learning model. Merat teaches these additional limitations (¶63, claim 10, and claim 20). Referring to claim 10, the claim recites A method for assessing a security risk of a user, the method comprising the steps of: a) collecting, at a computing device, human biometrics data, comprising daily activity data from a plurality of field biometric sensing devices; (Merat teaches collecting, at a computing device human biometrics data from a plurality of field biometric sensing devices as recited by the 103 rejection of claim 1 limitation i. Merat does not teach the limitation of the human biometrics data comprising daily activity data. Losseva teaches the limitation of the human biometrics data comprising daily activity data as recited by the 103 rejection of claim 1 limitation iii, and claim 4 for the limitation of “utilizing a temporal context of daily biometric behavior”) b) analyzing, at the computing device, the human biometrics data using an adaptive neural network model that performs rational inference to learn a correlation between a human biometric anomalies and the security risk of the user to determine a security hardening; (As recited by the 103 rejection of claim 1 limitation ii, Merat in view of Losseva teaches analyzing the plurality of human biometric data using an adaptive neural network model that performs rational inference to learn the correlation between the plurality of human biometric data and daily biometric behavior anomalies to determine the user's security risk. As recited by the 103 rejection of claim 3 for the limitation of a set of predefined security hardenings, Losseva teaches determining predefined security hardenings based on detected biometric movement anomalies and low fidelity scores.) c) determining, at the computing device or a personal data-collecting unit, a risk score of the user based on a daily behavior anomalies of the user (Merat in view of Losseva teaches this limitation as recited by the 103 rejection of claim 1 limitation iii.); d) determining a correlation matrix by comparing the risk score of the user (Under broadest reasonable interpretation consistent with the specification, the specification makes no mention of comparison for this limitation. Further there is no comparison element per the 112b rejection raised for claim 10 and “correlating” encompasses “comparing”. Therefore, Merat in view of Losseva teaches this limitation as recited by the 103 rejection of claim 8.), and e) controlling a network access by the computing device to regulate security access based on the risk score (Merat in view of Losseva teaches this limitation as recited by the 103 rejection of claim 1 limitation iv.). Referring to claim 11, the claim recites: the method of claim 10, wherein controlling the network access comprises alerting the user, disconnecting the network connection of the user and notifying an administrative user. As recited by the 103 rejection of claim 1 limitation iv, Merat teaches the limitation of controlling the network access comprises alerting the user and disconnecting the network connection of the user. For the limitation of “notifying an administrative user”, Merat teaches in ¶61: “module 312 configured to control network access of the user based on the cyber competence score”. In ¶62 Merat discloses “Module 312 may also inform other connected devices and users connected with the user and user device”. In ¶94 Merat discloses: “operator and administrative interfaces, e.g., a display, keyboard, and a cursor control device, may also be coupled to bus 1020 to support direct operator interaction with computer systems. Other operator and administrative interfaces can be provided through network connections connected through communication port 1060”. For the term “operator”, Merat discloses in ¶27: “embodiments of the present invention include various steps“ and ”steps may be performed by a combination of hardware, software, firmware, and human operators”. A person of ordinary skill in the art would understand the term “operator” can be a human and “another user” can be a human. In ¶89 Merat discloses “Communication port 1060 may be chosen depending on a network, such as a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system connects.”. A person of ordinary skill in the art would understand since module 312 informs other connected devices and users connected with the user and user device, communication must occur on the network through Communication port 1060. Since operator and administrative interfaces are used by humans and humans are users, they are synonymous with administrators. Since module 312 is connected to the network it can also operate on communication port 1060. Therefore, since the disclosure recites: “another user”, an administrator communicating on the same network is capable of receiving that information, which is synonymous with term “notifying”. Referring to claim 12, the claim recites: the method of claim 10, wherein the adaptive neural network model is trained using a two-phase machine learning engine in combination with a spiking recurrent network model. Merat in view of Losseva teaches this limitation as recited by the 103 rejection of claim 2. Referring to claim 13, the claim recites: the method of claim 12, wherein the two-phase machine learning engine is used to predict the security risks of the user. As recited by the 103 rejection of claim 1 limitation ii, Merat in view of Losseva teaches the limitation of “analyze the plurality of human biometric data using an adaptive neural network model that performs rational inference to learn the correlation between the plurality of human biometric data and daily biometric behavior anomalies to determine the user's security risk”. As recited by the 103 rejection for claim 2, Merat in view of Losseva further teaches the additional limitation of “the system of claim 1, wherein the adaptive neural network model is trained using a two-phase machine learning engine in combination with a spiking recurrent network model”. As recited by the 103 rejection of claim 5, Merat in view of Losseva further teaches the additional limitation of “the system of claim 2, wherein the two-phase machine learning engine in second mode, identifies a set of correlating points between a set of simulated behavior patterns and a set of risk disorders”. A person of ordinary skill in the art would understand these limitations taught as a combination map to the limitations of this claim. Referring to claim 14, the claim recites the method of claim 12, wherein the two-phase machine learning engine, in a first mode, predicts upcoming behavior transitions during an intense and unseen visual task by exploiting a temporal context of behavior stall and simulating attention shifts. As recited by the 103 rejection of claim 4, Merat in view of Losseva teach the limitations of “wherein the two-phase machine learning engine, in a first mode, predicts upcoming behavior transitions during an intense and unseen visual task by exploiting a temporal context and simulating attention shifts”. For the additional limitation of “by exploiting a temporal context of behavior stall”, Merat teaches in ¶47: “to maintain the correlation learning rate, the wake-sleep algorithm, can simulate the gaze transitions while unlearning the gaze stalls”. Further in ¶53 Merat teaches: “the described model learns the eye movement and gaze stall patterns and expands it in collaboration with the sleep phase of the wake-sleep algorithm”. Referring to claim 15, the claim recites: the method of claim 12, wherein the two-phase machine learning engine, in second mode, identifies a set of correlating points between simulated behavior patterns and security risks. As recited by the 103 rejection of claim 5, Merat in view of Losseva teaches the limitations of wherein the two-phase machine learning engine, in second mode, identifies a set of correlating points between simulated behavior patterns and a set of risk disorders. For the additional limitation of “security risks” instead of risk disorders, Merat teaches in 43: “system 108 may use an adaptive neural network model to determine mental disorder or disturbance level based on the received human biometrics data. Once the mental disorder or mental disturbance level is identified, system 108 may refer to a mental conditional-cyber risk correlation data 110 to determine associated cyber risk for the determined mental disorder or mental disturbance level”. A person of ordinary skill in the art would understand that the correlating points uncovered in the wake phase between the simulated gaze patterns and the mental disorder are predictive of cyber risk since the mental disorder or disturbance level is the intermediate output that maps to corresponding cyber risk classifications via the conditional-cyber risk correlation data. Regarding claim 16, the claim recites: the method of claim 10, wherein the adaptive neural network model is based on Generic-Leaky-Integrate-and-Fire (GLIF) neural network model. As recited by the 103 rejection of claim 6, Merat in view of Losseva teaches this additional limitation. Regarding claim 17, the claim recites: The method of claim 10, wherein the adaptive neural network model is trained using a recorded behavior shift data comprising populations of equivalently structured, interconnected neurons represented as generic leaky integrate-and-fire neurons, trained with spike-timing- dependent plasticity (STDP). The specification never defines “personal behavior data” and “behavior shift data” as distinct elements, as recited by claim 7, the claim element “set of recorded personal behavior data” comprises the same structure as the claim element “recorded behavior shift data” in claim 17. Since both terms describe the same set of inputs to the adaptive neural network model, the claim elements are synonymous. Therefore, since the claim elements are synonymous, Merat in view of Losseva teaches these additional limitations as recited by the 103 rejection of claim 7. Referring to claim 18, the claim recites: The method of claim 10, further comprising determining a correlation matrix by correlating the risk score with a network activity log of the user, wherein the network access is controlled based on the correlation matrix. Merat teaches this additional limitation in ¶63, ¶85, claim 9, and claim 19. Referring to claim 19, the claim recites: The method of claim 18, wherein the risk score of the user is determined based on the correlation matrix using a machine learning model. Merat in view of Losseva teaches this additional limitation as recited by the 103 rejection of claim 9. Accordingly, since claims 10-19 rely on the same reference combination of Merat in view of Losseva and the limitations are similar, it would have been obvious before the effective filing of the invention to modify Merat by combining prior art elements according to known methods to yield predictable results with the teachings of Losseva. A person of ordinary skill in the art would have found it obvious to combine the features in the security system taught by Losseva with the security system taught by Merat for the same reasons recited in the 103 rejection of claims 1-9. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to NOAH J KAISER whose telephone number is (571)272-8906. The examiner can normally be reached M-F: 10:00 a.m-6:00 p.m. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Alexander Lagor can be reached at 571-270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and hhttps://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /N.J.K./Examiner, Art Unit 2437 /ALEXANDER LAGOR/Supervisory Patent Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Oct 23, 2024
Application Filed
Jun 23, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739259
MULTI-ENGINE INTRUSION DETECTION SYSTEM
3y 3m to grant Granted Sep 15, 2026
Patent 12665753
Method for optical communications for the transmission of information and for the distribution of a cryptographic key and a system for implementing the method
3y 1m to grant Granted Jun 23, 2026
Patent 12580766
Digital Key Authentication Utilizing Device Metadata
2y 0m to grant Granted Mar 17, 2026
Patent 12549544
CONSENT-BASED AUTHORIZATION SYSTEM FOR TAXATION AND CONSUMER SERVICES
3y 5m to grant Granted Feb 10, 2026
Patent 12519823
DEVICES, SYSTEMS, AND METHODS FOR PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS
1y 10m to grant Granted Jan 06, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
73%
Grant Probability
99%
With Interview (+28.6%)
3y 4m (~1y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 454 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month