Prosecution Insights
Last updated: October 02, 2026
Application No. 18/938,174

IDENTITY VERIFICATION FOR CALL-BASED PROTECTED DATA TRANSMISSION OVER NETWORK

Final Rejection §103
Filed
Nov 05, 2024
Examiner
WILCOX, JAMES J
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
AT&T Mobility II LLC
OA Round
2 (Final)
70%
Grant Probability
Favorable
3-4
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 70% — above average
70%
Career Allowance Rate
437 granted / 623 resolved
+12.1% vs TC avg
Strong +61% interview lift
Without
With
+61.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
25 currently pending
Career history
659
Total Applications
across all art units

Statute-Specific Performance

§101
15.0%
-25.0% vs TC avg
§103
58.6%
+18.6% vs TC avg
§102
14.5%
-25.5% vs TC avg
§112
7.1%
-32.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 623 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This Office Action is in response to the amendment filed 05/26/2026. In the instant Amendment, claims 1, 15, 19, 20 were amended; claim 16 was cancelled; claim 21 is new; claims 1, 19 and 20 are independent claims. Claims 1-15 and 17-21 are pending in this application. THIS ACTION IS MADE FINAL. Response to Arguments Applicant’s arguments filed 05/26/2026 have been fully considered but they are not persuasive. Applicant argues that on (pages 7-12): that Kunin merely verifies an agent and controls the call, while Walheim independently protects sensitive information. The Examiner respectfully disagrees with the applicant. As an initial matter, applicant argues that Kunin’s patent publication is 20250209383. This is not the patent publication relied upon. The patent publication number relied upon was Kunin et al US 20240220592. See the Non-Final Rejection on page 2. The rejection is based on the combined teachings not on either reference individually. See In re Keller, 642 F. 2d 413, 425 (CCPA 1981). Kunin teaches in [0036]-[0039]; associating an agent’s voice signature with the agent’s login credentials, comparing the signature with a corresponding voice model, allowing a validated agent to continue the call, and taking corrective action-including terminating the call when the voice does not match (see Kunin, [0043]-[0047] and also see [0050]-[0060]). Walheim teaches in [0023]-[0028] detecting sensitive information spoken during a customer-agent call, replacing that information in the call audio, and supplying the actual information to an associated business application through the data -security application. Walheim also teaches that the employee may authenticate using voice recognition See Walheim, [0036]-[0039]. It would have been obvious to use Kunin’s voice verification result as an authorization condition for Walheim’s sensitive-data delivery. Doing so would prevent sensitive information from being supplied to a person using an authorized agent’s credentials unless that person’s voice matches the authorized agent’s voice model. This combines known authentication and sensitive-data controls to obtain the predictable result of releasing sensitive information only to a verified agent. See KSR International Co. v. Teleflex Inc., 550, US 398, 417-418 (2007). Applicant’s contention that Walheim protects information regardless of identity does not establish teaching away. Walheim does not discourage identity-based authorization; instead, it recognizes biometric authentication, including voice recognition. (See Walheim, [0037]). Applicant argues that on (pages 10-12): that the newly added out-of-band limitation is also unpersuasive. The Examiner respectfully disagrees with the applicant because Walheim teaches in [0024]-[0026] that the customer’s true sensitive information is removed from the call audio and replaced with hashed information, while the business application separately interfaces with the data-security application to store the customer’s actual information. Thus, the actual sensitive information is delivered through a data path distinct from the call-audio path. Applicant argues that on (pages 12-13): that Hahn fails to disclose or suggest claims 4 & 5. The Examiner respectfully disagrees with the applicant. Hahn in [0047]-[0056] is relied upon only for the additional-protected biometric template features. Hahn teaches transforming a voice-biometric vector into a protected vector and identifying by matching the protected test vector with a protected enrollment vector. Additionally, as to the dependent claims 2-15, 17 and 21 the Applicant argues that the claims are dependent directly or indirectly from a respective one of claims of independent claims 1, 19 and 20 and are therefore distinguished from the cited art at least by virtue OR allowable at least based on of their additionally recited patentable subject matter. The Examiner disagrees with the Applicant. The Examiner respectfully submits that dependent claims 2-15, 17 and 21 are rejected at least based on the rationale and resource presented to the argument for their respective based claims, and the reference applied to the dependent claims 2-15, 17 and 21 Therefore, in view of the above reasons, the Examiner maintains the rejection with the cited prior art references. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3 and 6-20 are rejected under 35 U.S.C. 103 as being unpatentable over Kunin et al (“Kunin,” US 20240220592) and further in view of Walheim et al (“Walheim,” US 20210377035). Regarding claim 1, Kunin discloses a method comprising: connecting, by a processing system including at least one processor via a communication network, a call between an endpoint device of a user and an agent system associated with an individual; (Kunin discloses [0025]-[0034] connecting, by a processing system including at least one processor via a communication network, a call between an endpoint device of a user and an agent system associated with an individual) obtaining, by the processing system, a voice sample of the individual via the call; (Kunin discloses [0025], [0004]-[0005] obtaining, by the processing system, a voice sample of the individual via the call, [0038]) verifying, by the processing system, an identity of the individual, wherein the verifying comprises matching the voice sample of the individual to a voice signature of the individual; (Kunin discloses [0049]-[0056] verifying, by the processing system, an identity of the individual, wherein the verifying comprises matching the voice sample of the individual to a voice signature of the individual) authorizing, by the processing system, the disclosure of the sensitive data via the endpoint device to the agent system, based upon the verifying of the identity of the individual via the matching of the voice sample of the individual to the voice signature of the individual; (Kunin discloses [0055]-[0060] authorizing, by the processing system, the disclosure of the sensitive data via the endpoint device to the agent system, based upon the verifying of the identity of the individual via the matching of the voice sample of the individual to the voice signature of the individual) Kunin fails to explicitly disclose detecting, by the processing system, a disclosure of sensitive data by the user via the endpoint device; and transmitting, by the processing system, the sensitive data to the agent system, in response to the authorizing of the disclosure of the sensitive data, wherein the transmitting of the sensitive data to the agent system is out-of-band from the call However, in an analogous art, Walheim discloses detecting, by the processing system, a disclosure of sensitive data by the user via the endpoint device; (Walheim discloses [0032]-[0039] detecting, by the processing system, a disclosure of sensitive data by the user via the endpoint device) and transmitting, by the processing system, the sensitive data to the agent system, in response to the authorizing of the disclosure of the sensitive data, (Walheim discloses [0045]-[0052] and transmitting, by the processing system, the sensitive data to the agent system, in response to the authorizing of the disclosure of the sensitive data) wherein the transmitting of the sensitive data to the agent system is out-of-band from the call, (Walheim discloses [0078], [0019] wherein the transmitting of the sensitive data to the agent system is out-of-band from the call, [0094]-[0095], [0035]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Walheim with Kunin to include detecting, by the processing system, a disclosure of sensitive data by the user via the endpoint device; and transmitting, by the processing system, the sensitive data to the agent system, in response to the authorizing of the disclosure of the sensitive data, wherein the transmitting of the sensitive data to the agent system is out-of-band from the call. One would have been motivated to intelligently hash sensitive information (Walheim, [0001]). Regarding claim 2, Kunin and Walheim disclose the method of claim 1. Kunin further discloses wherein the processing system comprises a network-based processing system deployed in the communication network, (Kunin discloses [0039], [0024], [0028] wherein the processing system comprises a network-based processing system deployed in the communication network) Regarding claim 3, Kunin and Walheim disclose the method of claim 1. Kunin further discloses wherein the processing system is a component of the endpoint device, (Kunin discloses in [0036], [0034], [0046] wherein the processing system is a component of the endpoint device) Regarding claim 6, Kunin and Walheim disclose the method of claim 1. Walheim further discloses wherein the sensitive data is transmitted in a hashed format, (Walheim discloses [0038]-[0039] wherein the sensitive data is transmitted in a hashed format) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Walheim with Kunin to include wherein the sensitive data is transmitted in a hashed format. One would have been motivated to intelligently hash sensitive information (Walheim, [0001]). Regarding claim 7, Kunin, Walheim and Hahn disclose the method of claim 6. Walheim further discloses further comprising: hashing the sensitive data to generate the sensitive data in the hashed format, (Walheim discloses [0003], [0039] further comprising: hashing the sensitive data to generate the sensitive data in the hashed format) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Walheim with Kunin to include further comprising: hashing the sensitive data to generate the sensitive data in the hashed format. One would have been motivated to intelligently hash sensitive information (Walheim, [0001]). Regarding claim 8, Kunin and Walheim disclose the method of claim 1. Kunin further discloses wherein the voice signature of the individual is obtained via a prior network-based communication between the endpoint device of the user and the agent system, (Kunin discloses [0043], [0075], [0030] wherein the voice signature of the individual is obtained via a prior network-based communication between the endpoint device of the user and the agent system) Regarding claim 9, Kunin and Walheim disclose the method of claim 1. Walheim further discloses wherein the sensitive data comprises at least one of: credit card information; (Walheim, [0020] credit card information) a social security number; (Walheim, [0020], social security number (SSN)) account information; a license number; a passport number; a username; an email address; a password; a personal identification number; (Walheim, [0020], PIN) a name; street address information; or a date of birth, Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Walheim with Kunin to include wherein the sensitive data comprises at least one of: credit card information; a social security number; account information; a license number; a passport number; a username; an email address; a password; a personal identification number; a name; street address information; or a date of birth.. One would have been motivated to intelligently hash sensitive information (Walheim, [0001]). Regarding claim 10, Kunin and Walheim disclose the method of claim 1. Walheim further discloses wherein the detecting of the disclosure of the sensitive data by the user comprises: detecting, within call data of the call, that the individual is asking for the sensitive data, (Walheim discloses [0046], [0041], [0039] wherein the detecting of the disclosure of the sensitive data by the user comprises: detecting, within call data of the call, that the individual is asking for the sensitive data, [0069]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Walheim with Kunin to include wherein the detecting of the disclosure of the sensitive data by the user comprises: detecting, within call data of the call, that the individual is asking for the sensitive data. One would have been motivated to intelligently hash sensitive information (Walheim, [0001]). Regarding claim 11, Kunin and Walheim disclose the method of claim 1. Walheim further discloses wherein the detecting of the disclosure of the sensitive data by the user comprises: detecting, within call data of the call, speech of the user indicative that the sensitive data is being disclosed, (Walheim discloses [0043], [0062], [0003] wherein the detecting of the disclosure of the sensitive data by the user comprises: detecting, within call data of the call, speech of the user indicative that the sensitive data is being disclosed) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Walheim with Kunin to include wherein the detecting of the disclosure of the sensitive data by the user comprises: detecting, within call data of the call, speech of the user indicative that the sensitive data is being disclosed. One would have been motivated to intelligently hash sensitive information (Walheim, [0001]). Regarding claim 12, Kunin and Walheim disclose the method of claim 1. Kunin further discloses further comprising: presenting a notification via the endpoint device of the verifying of the identity of the individual; and obtaining a user input granting a permission to transmit the sensitive data to the agent system, wherein the authorizing of the disclosure of the sensitive data is further based upon the obtaining of the user input granting the permission to transmit the sensitive data to the agent system, (Kunin discloses [0050], [0005], [0059], [0066] further comprising: presenting a notification via the endpoint device of the verifying of the identity of the individual; and obtaining a user input granting a permission to transmit the sensitive data to the agent system, wherein the authorizing of the disclosure of the sensitive data is further based upon the obtaining of the user input granting the permission to transmit the sensitive data to the agent system). Regarding claim 13, Kunin and Walheim disclose the method of claim 1. Kunin further discloses wherein the verifying of the identity of the individual is further based on one or more system identifiers associated with the agent system, (Kunin discloses [0062] wherein the verifying of the identity of the individual is further based on one or more system identifiers associated with the agent system) Regarding claim 14, Kunin and Walheim disclose the method of claim 13. Walheim further discloses wherein the one or more system identifiers comprise one or more of: a phone number; (Walheim, [0020], phone number) an international mobile equipment identifier; or an internet protocol address, Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Walheim with Kunin to include wherein the one or more system identifiers comprise one or more of: a phone number; an international mobile equipment identifier; or an internet protocol address. One would have been motivated to intelligently hash sensitive information (Walheim, [0001]). Regarding claim 15, Kunin and Walheim disclose the method of claim 1. Kunin further discloses wherein the transmitting of the sensitive data to the agent system is further via the call, (Kunin discloses [0032] wherein the transmitting of the sensitive data to the agent system is via the call) Regarding claim 17, Kunin and Walheim disclose the method of claim 1. Walheim further discloses wherein the matching of the voice sample of the individual to the voice signature of the individual is via a machine learning model implemented by the processing system, (Walheim discloses [0122], [0028] wherein the matching of the voice sample of the individual to the voice signature of the individual is via a machine learning model implemented by the processing system). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Walheim with Kunin to include wherein the matching of the voice sample of the individual to the voice signature of the individual is via a machine learning model implemented by the processing system. One would have been motivated to intelligently hash sensitive information (Walheim, [0001]). Regarding claim 18, Kunin and Walheim disclose the method of claim 1. Walheim further discloses wherein the authorizing of the disclosure of the sensitive data via the endpoint device to the agent system is via a machine learning model implemented by the processing system, (Walheim discloses [0021], wherein the authorizing of the disclosure of the sensitive data [0003] via the endpoint device [0074] to the agent system [0024] is via a machine learning model [0026] implemented by the processing system [0028]). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Walheim with Kunin to include wherein the authorizing of the disclosure of the sensitive data via the endpoint device to the agent system is via a machine learning model implemented by the processing system. One would have been motivated to intelligently hash sensitive information (Walheim, [0001]). Regarding claim 19, claim 19 is a directed to a non-transitory computer-readable medium. Claim 19 is similar in scope to claim 1 and is therefore rejected under the same rationale. Regarding claim 20, claim 20 is directed to an apparatus. Claim 20 is similar in scope to claim 1 and is therefore rejected under the same rationale. Claims 4-5 are rejected under 35 U.S.C. 103 as being unpatentable over Kunin et al (“Kunin,” US 20240220592) in view of Walheim et al (“Walheim,” US 20210377035) and further in view of Hahn et al (“Hahn,” US 20200335107). Regarding claim 4, Kunin and Walheim disclose the method of claim 1. Kunin and Walheim fail to explicitly disclose wherein the verifying comprises matching a hashed version of the voice sample of the individual to a hashed version of the voice signature of the individual. However, in an analogous art, Hahn discloses wherein the verifying comprises matching a hashed version of the voice sample of the individual to a hashed version of the voice signature of the individual (Hahn discloses [0026], [0078], [0047], [0093] wherein the verifying comprises matching a hashed version of the voice sample of the individual to a hashed version of the voice signature of the individual) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Hahn with Kunin and Walheim to include wherein the verifying comprises matching a hashed version of the voice sample of the individual to a hashed version of the voice signature of the individual. One would have been motivated to provide a method/system for verifying and establishing a speaker’s identity (Hahn, [0002]). Regarding claim 5, Kunin, Walheim and Hahn disclose the method of claim 4. Hahn further discloses further comprising: hashing the voice sample of the individual to generate the hashed version of the voice sample, (Hahn discloses [0093], [0078]-[0079] further comprising: hashing the voice sample of the individual to generate the hashed version of the voice sample) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Hahn with Kunin and Walheim to include further comprising: hashing the voice sample of the individual to generate the hashed version of the voice sample. One would have been motivated to provide a method/system for verifying and establishing a speaker’s identity (Hahn, [0002]). Claim 21 is rejected under 35 U.S.C. 103 as being unpatentable over Kunin et al (“Kunin,” US 20240220592) in view of Walheim et al (“Walheim,” US 20210377035) and further in view of Skliar et al (“Skliar,” US 20150100484). Regarding claim 21, Kunin and Walheim disclose the apparatus of claim 20. Kunin and Walheim fail to explicitly disclose wherein the verifying comprises matching a hashed version of the voice sample of the individual to a hashed version of the voice signature of the individual. However, in an analogous art, Skliar discloses wherein the verifying comprises matching a hashed version of the voice sample of the individual to a hashed version of the voice signature of the individual (Skliar in [0054] describes the hash value of biometric data including a voiceprint, is stored; when the data is presented again, its hash is computed and compared with the stored hash; [0056]-[0057] describe hashing biometric reference data using a one-way cryptographic function including SHA-family algorithms). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Skliar with Kunin and Walheim to include wherein the verifying comprises matching a hashed version of the voice sample of the individual to a hashed version of the voice signature of the individual. One would have been motivated to provide the ability to authenticate by comparing the hash derived from the current voice sample with a stored hash derived from the enrolled voice signature (Skliar, [0054]-[0057]). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES J WILCOX whose telephone number is (571)270-3774. The examiner can normally be reached M-F: 8 A.M. to 5 P.M.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu T. Pham can be reached at (571)270-5002.The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JAMES J WILCOX/Examiner, Art Unit 2439 /LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Nov 05, 2024
Application Filed
Feb 25, 2026
Non-Final Rejection mailed — §103
May 26, 2026
Response Filed
Aug 11, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750351
UNIQUE MACHINE-USER ID-SSH KEY FINGERPRINT
3y 4m to grant Granted Sep 29, 2026
Patent 12732357
SYSTEM AND METHOD SUPPORTING DATA RESIDENCY REQUIREMENT IN CLOUD HOSTED HARDWARE SECURITY MODULES
1y 5m to grant Granted Sep 08, 2026
Patent 12719868
METHOD, APPARATUS, AND COMPUTER-READABLE RECORDING MEDIUM FOR CONTROLLING ACCESS TO REMOTE SYSTEM IN HOME NETWORK ENVIRONMENT
3y 2m to grant Granted Aug 25, 2026
Patent 12719869
MULTI-TENANT SECRETS MANAGER
2y 7m to grant Granted Aug 25, 2026
Patent 12719871
SYSTEMS AND METHODS FOR DATA SEGREGATION AND SECURITY BASED ON ACCESS RIGHTS FOR ADDITIONAL SERVICES
2y 3m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
70%
Grant Probability
99%
With Interview (+61.2%)
3y 2m (~1y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 623 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month