Prosecution Insights
Last updated: August 17, 2026
Application No. 18/949,872

MULTI-FACTOR AUTHENTICATION ASSISTED AUTO-REGISTRATION

Non-Final OA §103
Filed
Nov 15, 2024
Examiner
NGUY, CHI D
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
LENOVO GLOBAL TECHNOLOGY (UNITED STATES) INC.
OA Round
1 (Non-Final)
75%
Grant Probability
Favorable
1-2
OA Rounds
1y 8m
Est. Remaining
91%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
382 granted / 508 resolved
+17.2% vs TC avg
Strong +16% interview lift
Without
With
+15.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
19 currently pending
Career history
534
Total Applications
across all art units

Statute-Specific Performance

§101
9.2%
-30.8% vs TC avg
§103
52.6%
+12.6% vs TC avg
§102
17.6%
-22.4% vs TC avg
§112
11.7%
-28.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 508 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The Application number 18/9494,872 filed on 11/15/2024 has been considered. Claims 1-20 are pending. Information Disclosure Statement The information disclosure statement (IDS) submitted on 11/15/2024 is being considered by the examiner. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Ha et al. (US 11,956,234 hereinafter Ha) in view of Grover et al. (US 2025/0337727 hereinafter Grover). Regarding claim 1, Ha discloses a method comprising: receiving, at the on-premises computing system and from a user device, a second authentication payload (FIG. 1-4, col. 7, lines 7-57; i.e. receiving at the second device from the first device an authentication code); presenting, by the on-premises computing system and to the cloud service portal, at least a portion of the first authentication payload (FIG. 1-4, col. 7, lines 7-57; i.e. sending by the second device the authentication code to the cloud server) and at least a portion of the second authentication payload; and establishing a secured connection between the cloud service portal and the on-premises computing system for accessing services via the cloud service portal in response to a successful validation of the first authentication payload and the second authentication payload (FIG. 1-4, col. 7, lines 7-57; i.e. registering or establish a secured connection between the second device and the cloud server based on the first authentication payload and the second authentication payload). Ha does not explicitly disclose receiving, at an on-premises computing system and from a cloud service portal a software package for installation at the on-premises computing system, wherein the software package comprises a first authentication payload and presenting at least a portion of the second authentication payload. However, Grover discloses receiving, at an on-premises computing system and from a cloud service portal a software package for installation at the on-premises computing system, wherein the software package comprises a first authentication payload (FIG. 4, ¶ [0036]-[0037], [0057]-[0059]). Therefore, it would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to combine Ha and Grover in order to provide enhanced security of the sensitive information (Grover, ¶ [0002]-[0005]). Regarding claim 2, Ha in view of Grover discloses the method of claim 1, wherein the first authentication payload comprises a pre-registration payload, wherein the pre-registration payload is derived at the cloud service portal based on a set of user credentials and a successful authentication of the user device (Ha, col. 13, lines 16-35; Grover, ¶ [0005]). Regarding claim 3, Ha in view of Grover discloses the method of claim 2, wherein the on-premises computing device automatically registers with the cloud service portal in response to receiving the pre-registration payload (Ha, col. 10, lines 17-28; Grover, ¶ [0057]-[0059], [0100]). Regarding claim 4, Ha in view of Grover discloses the method of claim 1, wherein the first authentication payload originates at the cloud service portal, and wherein the first authentication payload is routed through the user device to be received at the on-premises computing system (Ha, col. 7, lines 7-57; Grover, ¶ [0057]-[0059]). Regarding claim 5, Ha in view of Grover discloses the method of claim 1, wherein the first authentication payload comprises a certificate, wherein the certificate associates the software package with the user device (Grover, ¶ [0087]). Regarding claim 6, Ha in view of Grover discloses the method of claim 1, wherein the second authentication payload comprises a multi-factor authentication (“MFA”) payload that is generated, during an installation of the software package on the on-premises computing system, at the user device based on an authentication token, a successful MFA authentication, and the first authentication payload, wherein the authentication token is received from one of the cloud service portal and an MFA server associated with the cloud service portal (Ha, col. 7, lines 7-57; Grover, ¶ [0057]-[0059]). Regarding claim 7, Ha in view of Grover discloses the method of claim 6, wherein a request is sent, during the installation of the software package, to one of the cloud service portal and the MFA server associated with the cloud service portal, to create an MFA challenge that sends the authentication token to the user device (Ha, col. 7, lines 7-57; Grover, ¶ [0057]-[0059]). Regarding claim 8, Ha in view of Grover discloses the method of claim 1, further comprising: receiving one or more additional authentication payloads from the user device based on a context associated with the user device, wherein the one or more additional authentication payloads are derived at the user device based on one or more additional authentication tokens received from another user device, wherein the another user device is trusted by the on-premises computing system; and presenting the one or more additional authentication payloads along with the first authentication payload and the second authentication payload to the cloud service portal to access the services via the cloud service portal (Ha, col. 6, lines 43-62; Grover, ¶ [0052], [0057]-[0059]). Regarding claim 9, Ha in view of Grover discloses the method of claim 1, wherein presenting the first authentication payload and the second authentication payload to the cloud service portal comprises binding the first authentication payload with the second authentication payload (Ha, col. 7, lines 7-57; Grover, ¶ [0057]-[0059]). Regarding claim 10, Ha in view of Grover discloses the method of claim 1, wherein the software package is customized based on a user of the user device and/or an organization (Grover, ¶ [0037]). Regarding claim 11, Ha in view of Grover discloses the method of claim 6, wherein the authentication token comprises a one-time password (“OTP”) (Grover, FIG. 1, ¶ [0004]). Regarding claim 12, Ha discloses an apparatus comprising: a processor (FIG. 1-2); and non-transitory computer readable storage media storing code, the code being executable by the processor to perform operations comprising (FIG. 1-2): receiving, at the on-premises computing system and from a user device, a second authentication payload (FIG. 1-4, col. 7, lines 7-57; i.e. receiving at the second device from the first device an authentication code); presenting, by the on-premises computing system and to the cloud service portal, at least a portion of the first authentication payload (FIG. 1-4, col. 7, lines 7-57; i.e. sending by the second device the authentication code to the cloud server) and at least a portion of the second authentication payload; establishing a secured connection between the cloud service portal and the on-premises computing system for accessing services via the cloud service portal in response to a successful validation of the first authentication payload and the second authentication payload (FIG. 1-4, col. 7, lines 7-57; i.e. registering or establish a secured connection between the second device and the cloud server based on the first authentication payload and the second authentication payload). Ha does not explicitly disclose receiving, at an on-premises computing system and from a cloud service portal a software package for installation at the on-premises computing system, wherein the software package comprises a first authentication payload and presenting at least a portion of the second authentication payload. However, Grover discloses receiving, at an on-premises computing system and from a cloud service portal a software package for installation at the on-premises computing system, wherein the software package comprises a first authentication payload (FIG. 4, ¶ [0036]-[0037], [0057]-[0059]). Therefore, it would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to combine Ha and Grover in order to provide enhanced security of the sensitive information (Grover, ¶ [0002]-[0005]). Regarding claim 13, see claim 2 above for the same reasons of rejections. Regarding claim 14, see claim 3 above for the same reasons of rejections. Regarding claim 15, see claim 4 above for the same reasons of rejections. Regarding claim 16, see claim 5 above for the same reasons of rejections. Regarding claim 17, see claim 6 above for the same reasons of rejections. Regarding claim 18, see claim 7 above for the same reasons of rejections. Regarding claim 19, see claim 8 above for the same reasons of rejections. Regarding claim 20, Ha discloses a system comprising: a cloud service portal (FIG. 1-2); and an on-premises computing system in communication with the cloud service portal, the on-premises computing system comprising a processor and non-transitory computer readable storage media, wherein the on-premises computing system is configured to (FIG. 1-2): receive, at the on-premises computing system and from a user device, a second authentication payload (FIG. 1-4, col. 7, lines 7-57; i.e. receiving at the second device from the first device an authentication code), present, by the on-premises computing system and to the cloud service portal, at least a portion of the first authentication payload (FIG. 1-4, col. 7, lines 7-57; i.e. sending by the second device the authentication code to the cloud server) and at least a portion of the second authentication payload, and establish a secured connection between the cloud service portal and the on-premises computing system for accessing services via the cloud service portal in response to a successful validation of the first authentication payload and the second authentication payload (FIG. 1-4, col. 7, lines 7-57; i.e. registering or establish a secured connection between the second device and the cloud server based on the first authentication payload and the second authentication payload). Ha does not explicitly disclose receiving, at an on-premises computing system and from a cloud service portal a software package for installation at the on-premises computing system, wherein the software package comprises a first authentication payload and presenting at least a portion of the second authentication payload. However, Grover discloses receiving, at an on-premises computing system and from a cloud service portal a software package for installation at the on-premises computing system, wherein the software package comprises a first authentication payload (FIG. 4, ¶ [0036]-[0037], [0057]-[0059]). Therefore, it would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to combine Ha and Grover in order to provide enhanced security of the sensitive information (Grover, ¶ [0002]-[0005]). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHI D NGUY whose telephone number is (571)270-7311. The examiner can normally be reached Monday-Friday 9-5 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571)270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /C.D.N/Examiner, Art Unit 2435 /AMIR MEHRMANESH/Supervisory Patent Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Nov 15, 2024
Application Filed
Jun 08, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12683983
METHOD AND SYSTEM FOR DETECTING RESTRICTED CONTENT ASSOCIATED WITH RETRIEVED CONTENT
3y 4m to grant Granted Jul 14, 2026
Patent 12664297
Attribute-Based Permissions Groups
2y 11m to grant Granted Jun 23, 2026
Patent 12657284
CODE COVERAGE BASED RISK MITIGATION FOR CONTAINERS
3y 6m to grant Granted Jun 16, 2026
Patent 12657265
PHYSICAL UNCLONABLE FUNCTION READOUT APPARATUS
3y 1m to grant Granted Jun 16, 2026
Patent 12659727
VEHICLE, DEVICE, COMPUTER PROGRAM AND METHOD FOR LOADING DATA
2y 7m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
75%
Grant Probability
91%
With Interview (+15.9%)
3y 5m (~1y 8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 508 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month