Prosecution Insights
Last updated: August 17, 2026
Application No. 18/933,098

CLIENT-SIDE REQUESTS FOR NEW VIRTUAL IDENTIFIERS

Final Rejection §101§102§103
Filed
Oct 31, 2024
Examiner
KANERVO, VIRPI H
Art Unit
3691
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Capital One Services LLC
OA Round
2 (Final)
47%
Grant Probability
Moderate
3-4
OA Rounds
2y 3m
Est. Remaining
95%
With Interview

Examiner Intelligence

Grants 47% of resolved cases
47%
Career Allowance Rate
266 granted / 561 resolved
-4.6% vs TC avg
Strong +48% interview lift
Without
With
+48.0%
Interview Lift
resolved cases with interview
Typical timeline
4y 0m
Avg Prosecution
31 currently pending
Career history
606
Total Applications
across all art units

Statute-Specific Performance

§101
41.1%
+1.1% vs TC avg
§103
37.7%
-2.3% vs TC avg
§102
9.0%
-31.0% vs TC avg
§112
10.3%
-29.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 561 resolved cases

Office Action

§101 §102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of the Claims Claims 1-12, 14-19, and 21-22, are presented for examination. Applicant filed a response to a non-final Office action on 03/11/2026 amending independent claims 1, 7, and 14; canceling dependent claims 13 and 20; and adding new dependent claims 21 and 22. In light of Applicnat’s amendments, Examiner has withdrawn the previous § 101 rejection of claims 1-12 and 14-19, and the previous grounds of § 102 rejection of claims 1-12. Examiner has, however, maintained the previous objection to claim 14 and established new objections for claims 2, 4, 8, 9, and 12. Further, Examiner has established new § 101 rejection for claims 1-12, 14-19, and 21-22; new grounds of § 103 rejection for claims 1-12 and 21-22; and maintained the previous grounds of § 102 rejection of claims 14-19 in the instant Office action. Since the new § 101 rejection and the new grounds of § 103 rejection were necessitated by Applicant’s amendments, the instant rejection of claims 1-12, 14-19, and 21-22, is FINAL rejection of the claims. Examiner’s Remarks Patent Eligibility under § 101: Applicant argues in pages 11-12 of Applicant’s Remarks: Here, the Office Action identified the following claim elements as allegedly reciting the abstract idea: "determine to request the new virtual identifier based on the triggering event and the score" in claim 1; "determining to request the new virtual identifier based on the triggering event" in claim 7; and "determine a response to the request" in claim 14. See Office Action, pages 4-5. However, Applicant respectfully submits that none of these identified claim elements recite fundamental economic practices including mitigating risk, as alleged in the Office Action, nor do they recite any of the other enumerated sub-groupings set forth in MPEP 2106.04(a)(2)(II). Rather, these identified claim elements, and the other recitations of claims 1, 7, and 14, recite specific, technical operations for automated management and replacement of virtual identifiers in a computerized system, including the use of machine learning models trained on event data, secure credential handling, and cryptographically protected communications, none of which are fundamental economic practices or other enumerated methods of organizing human activity. Examiner respectfully disagrees. Applicant’s own specification recites: [0012] Risk of compromise may increase the longer and/or more often that the VCN is used. Therefore, the VCN may be periodically rotated. However, an authorized party (e.g., a merchant) that stores the VCN may suffer a breach or otherwise detect an increase in risk to the VCN before a system that issued the VCN is aware of the increased risk. Therefore, because the VCN is rotated periodically by the system that issued the VCN, security is reduced. In particular, the VCN is more likely to be stolen or otherwise compromised before replacement, which may not occur for days or even weeks. Additionally, computer resources are wasted undoing any fraudulent events (e.g., transactions) performed using the VCN. [0022] As shown by reference number 115, the ML model may output the score associated with the virtual identifier. For example, the processing device may receive the score from the ML model (e.g., from the ML host). The score may be an integer or a decimal value representing risk associated with the virtual identifier. For example, the score may be a score out of 10 or out of 100, among other examples. Additionally, or alternatively, the score may be qualitative, such as a letter grade or a risk category (e.g., “high” risk or “low” risk, among other examples). Thus, Applicant’s invention is directed to solving a problem of risk mitigation – which belongs to the group of certain methods of organizing human activity – fundamental economic practices including risk mitigation. Further, Applicant’s claims are recited in high level of abstraction lacking details and specifics as to how to carry out a technological solution for a problem of technology. Therefore, instant claims 1-12, 14-19, and 21-22, are not patent eligible under § 101. Prior Art under § 102 and § 103: Applicant argues in page 15 of Applicant’s Remarks: [T]he cited sections of HENNESSY do not disclose at least "transmit[ting], to an identifier manager associated with the virtual identifier, a request for the new virtual identifier, the request including a token with an encrypted version of the virtual identifier, a reason code associated with the triggering event, and a set of credentials associated with the processing device," as recited in claim 1, as amended. Independent claims 7 and 14, as amended, recite similar features. Therefore, independent claims 1, 7, and 14, and the claims that depend thereon, are patentable over the cited sections of the applied reference[.] Examiner respectfully disagrees. In light of Applicant’s amendments, Examiner has cited following new sections of Hennessy: [0007] In some implementations, transmitting the new virtual email address as login credentials to the requesting entity includes transmitting, through a tokenization application programming interface, data representing the new virtual email address through a tokenization API, where the data representing the new virtual email address is a token that cannot be traced to the first email address. [0016] The virtual email addresses can then be provided to a secure API that performs, for example, tokenization of the virtual email address identifier to provide a layer of protection between the virtual email address and the requesting entity. The token can then be used for identification, authorization, and/or authentication purposes. [0017] Particular embodiments of the subject matter described in this specification can be implemented to realize one or more of the following advantages. For example, using tokenization techniques to secure user data prevents user information available to the entities that participate in the process from being leaked to other entities. Additionally, by implementing other layers of protection, including encryption, the structure of the virtual email management system prevents entities from accessing any more information than is necessary for authentication or authorization. For example, the virtual email system can maintain separation between the virtual email addresses such that the main email address is not accessible to entities to whom access to a virtual email address mapped to the main email address is granted. The techniques discussed throughout this document also enable personalized content selection, internet browsing, and application usage, among other activities, to be performed while preventing any of the systems involved the content delivery or requesting entities from being able to track an individual user across different websites, data integration platforms, time periods, etc. [0018] The techniques discussed herein include transmitting data for the purposes of authentication and/or authorization using coded data or tokens in place of actual data such that the computing systems that participate in the processes discussed herein do not have access to the underlying data, but can still perform the operations of the processes using these codes. Using codes in place of actual data also protects the data even if the data is compromised, e.g., stolen or leaked to another entity, thereby improving data security. [0019] The system also automatically generates virtual email addresses for a user based on triggering events, reducing the amount of input required from a user and reducing the latency in content presentation. By automatically generating a virtual email address, the system reduces the necessary central processing unit (CPU) cycles required to perform the process, e.g., by not having to encrypt and decrypt large amounts of input from a user, reduces the latency in performing the process which is critical for implementations in which the process is used to select content for presentation on user devices, and makes the overall process more efficient. Furthermore, data can be cached locally at particular computing systems such that latency is reduced for future requests of any cached data. Reducing latency also reduces the number of errors that occur at user devices while waiting for such content to arrive. As the content often needs to be provided in milliseconds and to mobile devices connected by wireless networks, reducing the latency in selecting and providing the content based on user information is critical in preventing errors and reducing user frustration. By automatically generating a virtual email address and then using the email address for authentication and/or authorization, the system provides a seamless experience for users. [0020] The described techniques also provide a simplified process for maintaining a high level of privacy. By implementing a unified management system for various user identifiers mapped to a single, main email address of a user, the system provides a high standard for user privacy without requiring extensive changes in input required from users or authentication and/or authorization processes of requesting entities. Therefore, Hennessy teaches "transmit[ting], to an identifier manager associated with the virtual identifier, a request for the new virtual identifier, the request including a token with an encrypted version of the virtual identifier, a reason code associated with the triggering event, and a set of credentials associated with the processing device.” Claim Objections Claims 2, 4, 8, 9, 12, and 14, are objected to because of the informalities in the following recitations where Examiner has marked the suggested modifications with usual markings and bolded the appropriate parts of the claims: Claim 2: The system of claim 1, wherein the request includes [[a]] the reason code associated with the triggering event. Claim 4: The system of claim 1, wherein the indication of the new virtual identifier comprises [[a]] the token including [[an]] the encrypted version of the new virtual identifier. Claim 8: The method of claim 7, wherein the indication of the new virtual identifier comprises [[a]] the token including [[an]] the encrypted version of the new virtual identifier, and storing the indication of the new virtual identifier comprises storing the token. Claim 9: The method of claim 7, further comprising: discarding, at the processing device, [[a]] the token including [[an]] the encrypted version of the virtual identifier in response to receiving the indication of the new virtual identifier. Claim 12: The method of claim 7, wherein receiving the indication of the triggering event comprises: receiving the indication from the monitoring software executed by the processing device. Claim 14: A non-transitory computer-readable medium storing a set of instructions for processing a request for a new virtual identifier, the set of instructions comprising: . . . receive, from a processing device associated with [[the]] as virtual identifier, the request for the new virtual identifier, wherein the request includes a token with an encrypted version of the virtual identifier, a reason code associated with a triggering event, and a set of credentials associated with the processing device, wherein the triggering event includes at least one of: an expiration associated with the virtual identifier, a decline event associated with the virtual identifier, a security breach associated with the processing device, a login event associated with the processing device, a password event associated with the processing device, or a browsing event associated with the processing device; Claim Rejections - 35 USC § 101 35 U.S.C. § 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-12, 14-19, and 21-22, are rejected under 35 USC § 101 because they are directed to non-statutory subject matter. The rationale for this finding is explained below. The Supreme Court in Mayo laid out a framework for determining whether an applicant is seeking to patent a judicial exception itself or a patent-eligible application of the judicial exception. See Alice Corp., 134 S. Ct. at 2355,110 USPQ2d at 1981 (citing Mayo, 566 U.S. 66, 101 USPQ2d 1961). This framework, which is referred to as the Mayo test or the Alice/Mayo test (“the test”), is described in detail in Manual of Patent Examining Procedure (”MPEP”) (see MPEP § 2106(III) for further guidance). The step 1 of the test: It need to be determined whether the claims are directed to a patent eligible (i.e., statutory) subject matter under 35 USC § 101. Step 2A of the test: If the claims are found to be directed to a statutory subject matter, the next step is to determine whether the claims are directed to a judicial exception i.e., law of nature, natural phenomenon, and abstract idea (Prong 1). If the claims are found to be directed to an abstract idea, it needs to be determined whether the claims recite additional elements that integrate the judicial exception into a practical application (Prong 2). Step 2B of the test: If the claims are directed to a judicial exception, the next and final step is to determine whether the claims recite additional elements that amount to significantly more than the judicial exception. Step 1 of the Test: When considering subject matter eligibility under 35 USC § 101, it must be determined whether the claim is directed to one of the four statutory categories of invention, i.e., process, machine, manufacture, or composition of matter. Here, the claimed invention of claims 1-6 and 21 is a system and, thus, one of the statutory categories of invention. Further, the claimed invention of claims 7-12 and 22 is a series of steps, which is method (i.e., a process), which is also one of the statutory categories of invention. Still further, the claimed invention of claims 14-19 is a non-transitory computer-readable medium, which is also one of the statutory categories of invention. Conclusion of Step 1 Analysis: Therefore, claims 1-12, 14-19, and 21-22, are statutory under 35 USC § 101 in view of step 1 of the test. Step 2A of the Test: Prong 1: Claims 1-12, 14-19, and 21-22, however, recite an abstract idea of requesting a new virtual identifier. The creation of requesting a new virtual identifier, as recited in the independent claims 1, 7, and 14, belongs to certain methods of organizing human activity (i.e., fundamental economic practices including mitigating risk) that are found by the courts to be abstract ideas. The limitations in independent claims 1, 7, and 14, which set forth or describe the recited abstract idea, are found in the following steps: “determining to request the new virtual identifier based on the triggering event and the score” (claims 1 and 7); and “determining a response to the request” (claim 14). Prong 2: In addition to abstract steps recited above in Prong 1, independent claims 1, 7, and 14, recite additional elements: “one or more memories, and one or more processors communicatively coupled to the one or more memories” (claim 1); “monitoring software executed by a processing device” (claims 1 and 7); “a non-transitory computer-readable medium storing a set of instructions” (claim 14); “one or more instructions executed by one or more processors of a device” (claim 14); and “a processing device associated with the virtual identifier” (claim 14). These additional elements are recited at a high level of generality (e.g., as a generic processor performing a generic computer functions) such that they amount to no more than mere instructions to apply the exception using a generic computer components. Further, the following limitations recite insignificant extra solution activity (for example, data gathering): “receiving an indication of a triggering event associated with a virtual identifier, wherein the triggering event includes at least one of: an expiration associated with the virtual identifier, a decline event associated with the virtual identifier, a security breach associated with the processing device, a login event associated with the processing device, a password event associated with the processing device, or a browsing event associated with the processing device” (claims 1 and 7); “providing a data structure representing a set of events, associated with the virtual identifier and including information about transactions, login attempts, password changes, or browsing actions performed using the virtual identifier, to a machine learning model trained using events associated with virtual identifiers, including at least one of supervised or deep learning algorithms selected from at least one of: regression, decision tree, tree ensemble, random forest, boosted trees, or neural network algorithms, and configured to output a score based on the set of events” (claims 1 and 7); “transmitting, to an identifier manager associated with the virtual identifier, a request for the new virtual identifier, the request including a token with an encrypted version of the virtual identifier, a reason code associated with the triggering event, and a set of credentials associated with the processing device” (claims 1 and 7); “receiving, from the identifier manager and in response to the request, an indication of the new virtual identifier in response to the request” (claims 1 and 7); “storing the indication of the new virtual identifier, in replacement of an indication of the virtual identifier, for processing future events” (claims 1 and 7); “receiving the request for the new virtual identifier, wherein the request includes a token with an encrypted version of the virtual identifier, a reason code associated with a triggering event, and a set of credentials associated with the processing device, wherein the triggering event includes at least one of: an expiration associated with the virtual identifier, a decline event associated with the virtual identifier, a security breach associated with the processing device, a login event associated with the processing device, a password event associated with the processing device, or a browsing event associated with the processing device” (claim 14); and “transmitting the response” (claim 14). These additional limitations do not integrate the abstract idea into a practical application because they do not impose a meaningful limit on the judicial exception. The additional elements/limitations of independent claims 1, 7, and 14, here do not render improvements to the functioning of a computer or to any other technology or technical field (see MPEP § 2106.05(a)), nor do they integrate the abstract idea into a practical application under MPEP § 2106.05(b) (particular machine); MPEP § 2106.05(c) (particular transformations); or MPEP § 2106.05(e) (other meaningful limitations). Further, the combination of these additional elements/limitations is no more than mere instructions to apply the exception using a generic device. Accordingly, even in combination, these additional elements/ limitations do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Conclusion of Step 2A Analysis: Therefore, independent claims1, 7, and 14, are non-statutory under 35 USC § 101 in view of step 2A of the test. Step 2B of the Test: The additional elements of independent claims 1, 7, and 14, (see above under Step 2A - Prong 2) are described by Applicant’s Specification in following terms: [0054] Fig. 3 is a diagram of example components of a device 300 associated with client-side requests for new virtual identifiers. The device 300 may correspond to a processing device 230, an account manager 240, a user device 250, and/or an ML host 260. In some implementations, a processing device 230, an account manager 240, a user device 250, and/or an ML host 260 may include one or more devices 300 and/or one or more components of the device 300. As shown in Fig. 3, the device 300 may include a bus 310, a processor 320, a memory 330, an input component 340, an output component 350, and/or a communication component 360. [0055] The bus 310 may include one or more components that enable wired and/or wireless communication among the components of the device 300. The bus 310 may couple together two or more components of Fig. 3, such as via operative coupling, communicative coupling, electronic coupling, and/or electric coupling. For example, the bus 310 may include an electrical connection (e.g., a wire, a trace, and/or a lead) and/or a wireless bus. The processor 320 may include a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a field-programmable gate array, an application-specific integrated circuit, and/or another type of processing component. The processor 320 may be implemented in hardware, firmware, or a combination of hardware and software. In some implementations, the processor 320 may include one or more processors capable of being programmed to perform one or more operations or processes described elsewhere herein. [0056] The memory 330 may include volatile and/or nonvolatile memory. For example, the memory 330 may include random access memory (RAM), read only memory (ROM), a hard disk drive, and/or another type of memory (e.g., a flash memory, a magnetic memory, and/or an optical memory). The memory 330 may include internal memory (e.g., RAM, ROM, or a hard disk drive) and/or removable memory (e.g., removable via a universal serial bus connection). The memory 330 may be a non-transitory computer-readable medium. The memory 330 may store information, one or more instructions, and/or software (e.g., one or more software applications) related to the operation of the device 300. In some implementations, the memory 330 may include one or more memories that are coupled (e.g., communicatively coupled) to one or more processors (e.g., processor 320), such as via the bus 310. Communicative coupling between a processor 320 and a memory 330 may enable the processor 320 to read and/or process information stored in the memory 330 and/or to store information in the memory 330. This is a description of general-purpose computing system. Thus, individually, the additional elements of independent claims 1, 7, and 14, are well-understood, routine, and conventional elements that amount to no more than implementing the abstract idea with a computerized system. Further, the additional limitations of “receiving,” “providing,” “transmitting,” and “storing” information amount to no more than mere instructions to apply the exception using generic computer components. For the same reason these additional limitations are not sufficient to provide an inventive concept. The additional limitations of receiving,” “providing,” “transmitting,” and “storing” information were considered as insignificant extra-solution activity in Step 2A – Prong 2. Re-evaluating here in Step 2B, they are also determined to be well-understood, routine, and conventional activity in the field. Similarly to OIP Techs., Inc., v. Amazon.com, Inc., 788 F.3d 1359, 1363, 115 USPQ2d 1090, 1093 (Fed. Cir. 2015) (sending messages over a network), and buySAFE, Inc. v. Google, Inc., 765 F.3d 1350, 1355, 112 USPQ2d 1093, 1096 (Fed. Cir. 2014) (computer receives and sends information over a network), the additional limitations of independent claims 1, 7, and 14, “receive,” “provide,” and “transmit” information over a network in a merely generic manner. Further, similarly to Versata Dev. Group, Inc. v. SAP Am., Inc., 793 F.3d 1306, 1334, 115 USPQ2d 1681, 1701 (Fed. Cir. 2015) and OIP Techs., 788 F.3d at 1363, 115 USPQ2d at 1092-93, the additional limitations of independent claims 1 and 7 “store” information in memory. The courts have recognized receiving,” “providing,” “transmitting,” and “storing” information functions as well-understood, routine and conventional when claimed in a merely generic manner. Therefore, the additional limitations of independent claims 1, 7, and 14, are well-understood, routine, and conventional. Further, taken as combination, the additional elements/limitations add nothing more than what is present when the additional elements/limitations are considered individually. There is no indication that the combination provides any effect regarding the functioning of the computer or any improvement to another technology. Conclusion of Step 2B Analysis: Therefore, independent claims 1, 7, and 14, are non-statutory under 35 USC § 101 in view of step 2B of the test. Dependent Claims: Dependent claims 2-6 depend on independent claim 1; dependent claims 8-13 depend on independent claim 7; and dependent claims 15-20 depend on independent claim 14. The elements in dependent claims 2-6, 8-13, and 16-20, which set forth or describe the abstract idea, are: “the request includes a reason code associated with the triggering event” (claim 2: further narrowing the recited abstract idea); “the one or more processors are configured to: discard the virtual identifier based on storing the new virtual identifier” (claim 3: further narrowing the recited abstract idea); “the indication of the new virtual identifier comprises a token including an encrypted version of the new virtual identifier” (claim 4: further narrowing the recited abstract idea); “the one or more processors, to determine to request the new virtual identifier, are configured to: determine to request the new virtual identifier based on the score satisfying a replacement threshold” (claim 5: further narrowing the recited abstract idea); “the one or more processors are configured to: receive, from the identifier manager, a portion of a permanent identifier, corresponding to the virtual identifier; and output, to a user device, the portion of the permanent identifier” (claim 6: insignificant extra solution activity); “the indication of the new virtual identifier comprises a token including an encrypted version of the new virtual identifier, and storing the indication of the new virtual identifier comprises storing the token” (claim 8: further narrowing the recited abstract idea); “discarding, at the processing device, a token including an encrypted version of the virtual identifier in response to receiving the indication of the new virtual identifier” (claim 9: further narrowing the recited abstract idea); “transmitting the request for the new virtual identifier comprises: performing an application programming interface (API) call to an API function associated with virtual identifier replacement” (claim 10: further narrowing the recited abstract idea); “the request includes a set of credentials associated with the processing device” (claim 11: further narrowing the recited abstract idea); “receiving the indication of the triggering event comprises: receiving the indication from monitoring software executed by the processing device” (claim 12: insignificant extra solution activity); “the response comprises an acceptance of the request, and the one or more instructions, when executed by the one or more processors, cause the device to: generate the new virtual identifier, and the response transmitted to the processing device includes an indication of the new virtual identifier” (claim 15: further narrowing the recited abstract idea); “the one or more instructions, when executed by the one or more processors, cause the device to: transmit, to an account manager, an instruction to replace the virtual identifier with the new virtual identifier” (claim 16: insignificant extra solution activity); “the one or more instructions, when executed by the one or more processors, cause the device to: disable the virtual identifier; and activate the new virtual identifier” (claim 17: further narrowing the recited abstract idea); “the response comprises a rejection of the request, and the response transmitted to the processing device includes a reason code associated with the rejection” (claim 18: further narrowing the recited abstract idea); “the request further includes an indication that a score, associated with the virtual identifier, satisfies a replacement threshold” (claim 19: further narrowing the recited abstract idea); and “outputting, to a user device, a notification indicating that the virtual identifier has been replaced with the new virtual identifier, the notification including a portion of a permanent identifier associated with the new virtual identifier” (claim 20: further narrowing the recited abstract idea). Conclusion of Dependent Claims Analysis: Dependent claims 2-6, 8-13, and 16-20, do not correct the deficiencies of independent claims 1, 7, and 14, and they are, thus, rejected on the same basis. Conclusion of the 35 USC § 101 Analysis: Therefore, claims 1-20 are rejected as directed to an abstract idea without “significantly more” under 35 USC § 101. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. § 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under § 151, or in an application for patent published or deemed published under § 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 14-19 are rejected under 35 U.S.C. § 102(a)(2) as being anticipated by Hennessy (WO 2022/119999 A1). As to independent claim 14 Hennessy shows: one or more instructions that, when executed by one or more processors of a device (Hennessy: pages 22-23, ¶ 106), cause the device to: receive, from a processing device associated with the virtual identifier, the request for the new virtual identifier, wherein the request includes a token with an encrypted version of the virtual identifier, a reason code associated with a triggering event, and a set of credentials associated with the processing device, wherein the triggering event includes at least one of: an expiration associated with the virtual identifier, a decline event associated with the virtual identifier, a security breach associated with the processing device, a login event associated with the processing device, a password event associated with the processing device, or a browsing event associated with the processing device (Hennessy: pages 1-2, ¶ 7; pages 3-4, ¶¶ 16-18; page 16, ¶ 69; and page 21, ¶¶ 97-99); determine a response to the request (Hennessy: page 22, ¶ 102); and transmit, to the processing device, the response (Hennessy: page 22, ¶ 103). As to claim 15: Hennessy shows all the elements of claim 14. Hennessy also shows that the response comprises an acceptance of the request, and the one or more instructions, when executed by the one or more processors, cause the device to: generate the new virtual identifier, wherein the response transmitted to the processing device includes an indication of the new virtual identifier (Hennessy: page 16, ¶ 69; and page 22, ¶ 102). As to claim 16: Hennessy shows all the elements of claim 15. Hennessy also shows that the one or more instructions, when executed by the one or more processors, cause the device to: transmit, to an account manager, an instruction to replace the virtual identifier with the new virtual identifier (Hennessy: page 22, ¶ 104). As to claim 17: Hennessy shows all the elements of claim 15. Hennessy also shows that the one or more instructions, when executed by the one or more processors, cause the device to: disable the virtual identifier; and activate the new virtual identifier (Hennessy: page 22, ¶ 104). As to claim 18: Hennessy shows all the elements of claim 14. Hennessy also shows that the response comprises a rejection of the request, and wherein the response transmitted to the processing device includes a reason code associated with the rejection (Hennessy: page 16, ¶ 69). As to claim 19: Hennessy shows all the elements of claim 14. Hennessy also shows that the request further includes an indication that a score, associated with the virtual identifier, satisfies a replacement threshold (Hennessy: page 16, ¶ 69). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. § 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in § 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-12 and 21-22 are rejected under 35 U.S.C. § 103 as being unpatentable over Hennessy in view of Borysek (US 2024/0161110 A1). As to independent claims 1 and 14 Hennessy shows: one or more memories, and one or more processors, communicatively coupled to the one or more memories (Hennessy: pages 22-23, ¶ 106), configured to: receive, from monitoring software executed by a processing device, an indication of a triggering event associated with a virtual identifier, wherein the triggering event includes at least one of: an expiration associated with the virtual identifier, a decline event associated with the virtual identifier, a security breach associated with the processing device, a login event associated with the processing device, a password event associated with the processing device, or a browsing event associated with the processing device (Hennessy: page 16, ¶ 69; and page 21, ¶¶ 97-99); determine to request the new virtual identifier based on the triggering event and the score (Hennessy: page 16, ¶ 69; and page 21, ¶¶ 97-99); transmit, to an identifier manager associated with the virtual identifier, a request for the new virtual identifier, the request including a token with an encrypted version of the virtual identifier, a reason code associated with the triggering event, and a set of credentials associated with the processing device (Hennessy: pages 1-2, ¶ 7; pages 3-4, ¶¶ 16-18; and page 22, ¶ 102); receive, from the identifier manager and in response to the request, an indication of the new virtual identifier (Hennessy: page 22, ¶ 103); and store the indication of the new virtual identifier, in replacement of an indication of the virtual identifier, for processing future events (Hennessy: page 22, ¶ 104). Hennessy does not show: providing a data structure representing a set of events, associated with the virtual identifier and including information about transactions, login attempts, password changes, or browsing actions performed using the virtual identifier, to a machine learning model trained using events associated with virtual identifiers, including at least one of supervised or deep learning algorithms selected from at least one of: regression, decision tree, tree ensemble, random forest, boosted trees, or neural network algorithms, and configured to output a score based on the set of events. Borysek shows: providing a data structure representing a set of events, associated with the virtual identifier and including information about transactions, login attempts, password changes, or browsing actions performed using the virtual identifier, to a machine learning model trained using events associated with virtual identifiers, including at least one of supervised or deep learning algorithms selected from at least one of: regression, decision tree, tree ensemble, random forest, boosted trees, or neural network algorithms, and configured to output a score based on the set of events (Borysek: page 15, ¶ 136). Motivation to combine Hennessy and Borysek: It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the system and the method of Hennessy by providing a data structure representing a set of events, associated with the virtual identifier and including information about transactions, login attempts, password changes, or browsing actions performed using the virtual identifier, to a machine learning model trained using events associated with virtual identifiers, including at least one of supervised or deep learning algorithms selected from at least one of: regression, decision tree, tree ensemble, random forest, boosted trees, or neural network algorithms, and configured to output a score based on the set of events of Borysek in order to facilitate interactions with identified charges (Borysek: page 1, ¶ 2). As to claim 2: Hennessy in view of Borysek shows all the elements of claim 1. Hennessy also shows that the request includes a reason code associated with the triggering event (Hennessy: page 16, ¶ 69). As to claim 3: Hennessy in view of Borysek shows all the elements of claim 1. Hennessy also shows that the one or more processors are configured to: discard the virtual identifier based on storing the new virtual identifier (Hennessy: pages 12-13, ¶ 57). As to claim 4: Hennessy in view of Borysek shows all the elements of claim 1. Hennessy also shows that the indication of the new virtual identifier comprises a token including an encrypted version of the new virtual identifier (Hennessy: pages 3-4, ¶ 17). As to claim 5: Hennessy in view of Borysek shows all the elements of claim 1. Hennessy also shows that the one or more processors, to determine to request the new virtual identifier, are configured to: determine to request the new virtual identifier based on the score satisfying a replacement threshold (Hennessy: page 16, ¶ 69). As to claim 6: Hennessy in view of Borysek shows all the elements of claim 1. Hennessy also shows that the one or more processors are configured to: receive, from the identifier manager, a portion of a permanent identifier, corresponding to the virtual identifier, and output, to a user device, the portion of the permanent identifier (Hennessy: page 8, ¶ 38). As to claim 8: Hennessy in view of Borysek shows all the elements of claim 7. Hennessy also shows that the indication of the new virtual identifier comprises a token including an encrypted version of the new virtual identifier, and storing the indication of the new virtual identifier comprises storing the token (Hennessy: pages 3-4, ¶ 17; and page 8, ¶ 38). As to claim 9: Hennessy in view of Borysek shows all the elements of claim 7. Hennessy also shows discarding, at the processing device, a token including an encrypted version of the virtual identifier in response to receiving the indication of the new virtual identifier (Hennessy: pages 12-13, ¶ 57). As to claim 10: Hennessy in view of Borysek shows all the elements of claim 7. Hennessy also shows that transmitting the request for the new virtual identifier comprises: performing an application programming interface (API) call to an API function associated with virtual identifier replacement (Hennessy: pages 1-2, ¶ 7; and page 22, ¶ 103). As to claim 11: Hennessy in view of Borysek shows all the elements of claim 7. Hennessy also shows that the request includes a set of credentials associated with the processing device (Hennessy: page 21, ¶¶ 95-96). As to claim 12: Hennessy in view of Borysek shows all the elements of claim 7. Hennessy also shows that receiving the indication of the triggering event comprises: receiving the indication from monitoring software executed by the processing device (Hennessy: page 16, ¶ 69). As to claims 21 and 22: Hennessy in view of Borysek shows all the elements of claims 1 and 7. Hennessy also shows outputting, to a user device, a notification indicating that the virtual identifier has been replaced with the new virtual identifier, the notification including a portion of a permanent identifier associated with the new virtual identifier (Hennessy: pages 1-2, ¶¶ 7-8; and page 8, ¶ 38). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Liu (US 2025/0103371 A1) discloses: “The disclosed computing device can include host circuitry configured to provide a physical function and guest circuitry configured to provide a virtual function. The host circuitry is configured to dynamically assign request identifiers for accessing at least the host circuitry in a manner that allows the request identifiers to change on a command-to-command basis instead of a time-to-time basis that uses fixed value request identifiers in time slices.” Koren (US 2022/0327504 A1) discloses: “[0078] . . . In various embodiments, the routing path engine is a ML engine trained on transactions data with each of and/or combinations of cardholder/issuer/global historical success rates per route. Once trained, the model is configured to output for a given transaction input, a score per each possible route, and the system can use the score to select the route with the highest possible score. Further the score can be used in conjunction with the outputs of the other engines and/or the routes analyzed by the engine can be filtered based on outputs of the other engines. In one example, the model can be based on reinforcement learning methods such as multi armed bandit, among other options discussed above for the other ML models. Various other model architectures can also be used to determine a likelihood of success for a given route (e.g., information retrieval methods such as probabilistic relevance framework, Fellegi-Sunter model, Human In The Loop, supervised learning methods such as Gradient Boosting, Random Forest, Support-Vector Machines, Logistic Regression, Deep Learning, Clustering, Clustering on Graphs, Graph Machine Learning, Anomaly Detection, time series cross validation, feature engineering, labels missing at random/completely at random, among other options).” Higgins (US 10,915,900 B1) discloses: “Block 404 illustrates training a data model based at least in part on the training data, the data model determining a score indicating a likelihood that a customer will request a refund for a transaction. Training module 330 may train a data model based on a plurality of training data items such that, given a new input of customer data, merchant data, and/or transaction data associated with a transaction, the data model may output a score indicating a likelihood that a customer will request a refund for the transaction. In at least one example, training module 330 may utilize a machine learning mechanism to train the data model. In such an example, the data model may be trained using supervised learning algorithms (e.g., artificial neural networks, Bayesian statistics, support vector machines, decision trees, classifiers, k-nearest neighbor, etc.), unsupervised learning algorithms (e.g., artificial neural networks, association rule learning, hierarchical clustering, cluster analysis, etc.), semi-supervised learning algorithms, deep learning algorithms, etc.” B. C. M. Fung, K. Wang and P. S. Yu, "Top-down specialization for information and privacy preservation," 21st International Conference on Data Engineering (ICDE'05), Tokyo, Japan, 2005, pp. 205-216. Ke Wang, P. S. Yu and S. Chakraborty, "Bottom-up generalization: a data mining solution to privacy protection," Fourth IEEE International Conference on Data Mining (ICDM'04), Brighton, UK, 2004, pp. 249-256. Applicant's amendment necessitated the new grounds of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to VIRPI H. KANERVO whose telephone number is 571-272-9818. The examiner can normally be reached on Monday – Friday, 10 am – 6 pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor Abhishek Vyas can be reached on 571-270-1836. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /VIRPI H KANERVO/Primary Examiner, Art Unit 3691
Read full office action

Prosecution Timeline

Oct 31, 2024
Application Filed
Dec 11, 2025
Non-Final Rejection mailed — §101, §102, §103
Feb 03, 2026
Interview Requested
Feb 10, 2026
Examiner Interview Summary
Feb 10, 2026
Applicant Interview (Telephonic)
Mar 11, 2026
Response Filed
Jul 22, 2026
Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705621
MULTI-FACTOR AUTHENTICATION USING LOCATION DATA
3y 11m to grant Granted Aug 11, 2026
Patent 12700040
OUTLIER SYSTEM FOR GROUPING OF CHARACTERISTICS
4y 5m to grant Granted Aug 04, 2026
Patent 12694392
Variant Card
3y 1m to grant Granted Jul 28, 2026
Patent 12664584
SYSTEMS AND METHODS FOR MANAGING A LOAN APPLICATION
2y 1m to grant Granted Jun 23, 2026
Patent 12632847
System, Method, and Computer Program Product for Generating Embeddings for Objects
1y 10m to grant Granted May 19, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
47%
Grant Probability
95%
With Interview (+48.0%)
4y 0m (~2y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 561 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month