Prosecution Insights
Last updated: August 18, 2026
Application No. 18/967,189

METHOD AND SYSTEM FOR MULTI-FACTOR AUTHENTICATION

Non-Final OA §101§103
Filed
Dec 03, 2024
Examiner
BOYD, MALA DENAE
Art Unit
2497
Tech Center
2400 — Computer Networks
Assignee
AT&T Technical Services Company, Inc.
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-58.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
6 currently pending
Career history
10
Total Applications
across all art units

Statute-Specific Performance

§101
10.0%
-30.0% vs TC avg
§103
55.0%
+15.0% vs TC avg
§102
30.0%
-10.0% vs TC avg
§112
5.0%
-35.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 0 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claims 1, 14 and 18 are rejected under 101 because each claim is directed to a judicial exception without reciting significantly more. Under Step 1 claim 1 is a process, claim, claim 14 is a machine , and claim 18 is a manufacturer, but under Step 2A, Prong One, the claims recite an abstract idea, namely evaluating authentication information, determining a confidence level, selecting a second authentication query or requirement, and deciding whether to authenticate a user based on a completeness threshold, as shown for example by the limitations of “obtaining … first authentication information,” “analyzing … to determine a first authentication and to determine a confidence level,” “selecting… a type of second authentication information,” and “authenticating… based on a completeness threshold.” These limitations fall within the abstract idea groups of mental process because they recite observation, evaluation, judgement, and decision-making that can practically be performed in the human mind or with pen and paper, and also certain methods of organizing human activity because they manage access authorization and user verification. Under Step 2A, Prong Two the claims do not integrate the abstract idea into a practical application because the additional elements e.g., a processing system, processor, memory, network, authentication server, end user device, sensor, camera, database, and application are recited at a high level of generality and merely use generic computer components as tools to collect data, transmit requests, receive responses, and apply the authentication decision; there is no recited improvement to computer functionality, network operation, sensor technology or another technical field, no particular machine beyond generic computing equipment and no individually and in order combination, amount only to well understood, routine, and conventional computer implementation of the abstract authentication policy, as supported by the specification’s description of conventional processes, memories, networks, applications, databases and sensors. Dependent claims 2-13, 15-17 and 19-20 are rejected under 101 because they do not add limitations that render the abstract idea of the respective independent claims patent eligible. The claims merely further describe the abstract idea of adaptive authentication decisioning by adding details such as receiving first authentication from a different device (claims 2, 12, 19), using an image, biometric information, or user input information (claims 3, 8, 12, 19), basing the decision on a match percentage, baseline information or quantified confidence value (claims 4-6, 9), providing a temporary authentication for a time period (claims 7, 17, 20), determining a user location and requesting sensor or camera to capture authentication information (claims 10-12, 16), selecting the type of second authentication based on confidence (claim 15), or applying an AI model to the authentication information and other user information (claim 13), these are still mental process, mathematical concepts, and/or certain methods of organizing human activity, because they merely refine how the confidence evaluation, rule selection, and authentication decision are performed. The additional limitations do not integrate the abstract idea into a practical application, as they amount only to insignificant extra solution activity such as data gathering, sourcing baseline information, receiving data from another device, determining location, invoking generic sensors or cameras, or using AI at a high level of generality, without reciting a specific technology improvement to computer functionality, network operation, sensor technology or authentication architecture. The additional elements do not amount to significantly more than the abstract idea because the claimed devices, applications, sensors, cameras, location determination, and AI functionality are recited generally and as described in the specification, are well understood, routine and conventional components performing their ordinary functions. Accordingly, independent claims 1, 14 and 18; and dependent claims 2-13, 15-17 and 19-20 are patent ineligible under 101. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 2, 3, 4, 6, 9, 10, 11, 12, 13, 14, 15, 16, 18, 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kursun et al. (Pub. No. US 20190272361 A1)(hereinafter Kursun) in view of Todasco et al. (Pub. No. US 20170324752 A1)(hereinafter Todasco) and further in view of Keith, JR. (Pub. No. (US 20240022565 A1). Regarding Claim 1, Kursun teaches A method comprising: obtaining, by a processing system including a processor over a network(Kursun [0031] “FIG. 1 is a block diagram illustrating an operating environment for the entity authentication system 100(i.e. processing system), in accordance with one embodiment of the present invention. In particular, the operating environment may include an entity authentication 100(i.e. processing system), which comprises an entity authentication server 110(i.e. processor) and a database server 120, in operative communication with a plurality of authentication channels 101, 102, 103 over a network 180.” first authentication information associated with a user(Kursun [0005] “The invention may comprise receiving a first set of authentication data from a user through a first channel, wherein the authentication data comprises biometric data;”) [0032] “The entity authentication server 110(i.e. processor) may be configured to receive authentication data from one or more authentication channels 101, 102, 103 on a continuous basis. In some embodiments, the system may comprise a first authentication channel 101(e.g. first authentication) which may be a mobile device such as a smartphone. In such embodiments, the user may use the smartphone to provide authentication data (e.g., biometric voice, speech, fingerprint, or facial data, or other types of data) to the entity authentication server 110(i.e. processor). In some embodiments, said authentication data may be collected each time the user interacts with the entity authentication system 110 through the first authentication channel 101 (e.g., each time the user places a call to the entity or logs onto the entity's systems using the mobile application; pars. 31-35, 40, 45, 70-72: an entity authentication server receiving authentication data from multiple channels over a network); analyzing, by the processing system, the first authentication information to determine a first authentication and to determine a confidence level for the first authentication(Kursun [0004] “The obtained authentication data may be compared with reference data (e.g., historical data) to continuously update a confidence level associated with the user. Based on the confidence level, profile the user to detect any inconsistencies in the authentication data collected over time.”) ([0005] “The invention may comprise receiving a first set of authentication data from a user through a first channel, wherein the authentication data comprises biometric data; detecting that a confidence level associated with the user has dropped below a specified threshold; initiating a competitive authentication process; determining, based on a first mismatch vector, whether a first set of additional authentication data is required; determining system requirements for the first set of additional authentication data; determining strategy requirements for the first set of additional authentication data; and implementing the system requirements and the strategy requirements for the first set of additional authentication data.”; pars. 27, 36, 44 and 56: the system compares current authentication data with historical/reference data and calculates a confidence value/level indicating consistency); providing, by the processing system, a request for the second authentication information to an end user device associated with the user(pars. 29, 48, 50, 61 and 71: prompting the user through the system/channel to provide additional authentication data); receiving, by the processing system, the second authentication information from the end user device(Kursun [0033] “In some embodiments, the entity authentication server 110 may receive additional authentication data from a second authentication channel 102, such as a desktop or laptop computer, portable tablet, smart device, and the like.”; pars. 29, 48, 62 and 71: the system receives additional authentication data from the user through the channel/device); authenticating, by the processing system, the user according to the second authentication information [based on a completeness threshold] (pars. 47, 59, 63, 71: determining whether additional authentication data is sufficient, conclusive or whether a mismatch is eliminated/confirmed), wherein at least one of the [selecting of the type of] second authentication information or the completeness threshold is based on the confidence level(Kursun [0056] “The process continues to block 402, where the system verifies whether a confidence level threshold is reached. As described above, a confidence level may be associated with each user profile, where the confidence level represents the level of certainty with which the system has positively identified the user. Typically, the system recalculates the confidence level and adjusts it upward or downward depending on the biometric data collected from the user over time. [0058] “The process continues to block 404, where the system calculates a mismatch vector based on the authentication data (e.g., biometric data and/or non-biometric data, such as behavior data). The mismatch vector may represent the degree of deviation from historic and/or reference data (e.g., biometric, profile, or location data). Typically, a mismatch vector may be calculated for each authentication data sample obtained from the user. Accordingly, the system may be configured to resolve multiple mismatch vectors representing biometric data taken at different times from different channels.(e.g. the type of second authentication information) wherein from different channels include a second channel with biometric data e.g. voice samples as disclosed in [0071]; pars. 44 and 57: competitive authentication begins when confidence falls below threshold level … see further pars. 27, 36; pars. 29, 48, 50, 61, 63-65: when confidence level falls below a specified threshold, the system initiates a competitive authentication process and prompts the user for additional authentication data, including a different biometric data, different non-biometric data or data obtained through different channels, thereby escalating to a second or alternative authentication technique in response to the lowered confidence ) Kursun fails to explicitly teach selecting from a type from a group of different authentication queries. However, Todasco teaches selecting, by the processing system, a type of second authentication information from among a group of different authentication queries for a second authentication(Todasco [0065] “The first authentication query and the second authentication query may be different query types, wherein the query types comprise at least two of a text-based query, an image based query, a sound clip query, a video query, a number-based query, an audio query, a visual query, and an audio-visual query(e.g. a group of different authentication queries). In such embodiments, a best query type from the query types for the first user may be determined, wherein the best query type comprises one of the query types that the first user is most successful at answering. Additionally, at least one of the first authentication query, the second authentication query, and further authentication queries may be determined using the best query type(e.g. selecting). In further embodiments, the first response may comprise a request for another authentication query by the first user. Thus, a second authentication query may be determined having a second question using a different query type. A second response may be processed to determine whether the second response satisfies the second question(e.g. selecting). In such embodiments, a favored query type for the first user may be determined based on the request and the different query type, wherein at least one of the first authentication query, the second authentication query, and further authentication queries are determined using the favored query type (e.g. a type of second authentication).”; [0043] “Authentication query application 150 may further learn from the user's responses a better or more preferred query type for the user when generating an authentication query. For example, authentication query application 150 may utilize historical data of correct responses, incorrect responses, and new query requests(i.e. a request for second authentication information) to determine a query type favored by the user associated with communication device 110. ”; pars. 19, 65: query type selection from multiple different query types; par. 21: choosing a query type based on prior success/failure; par. 43: authentication query application 150 may further learn from the user’s response a better or more preferred query type of the user when generating an authentication query); Kursun and Todasco are analogues in that they are all in the same field of security architecture. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Kursun to incorporate the teachings of Todasco the selecting, by the processing system, a type of second authentication information from among a group of different authentication queries for a second authentication. Doing so, would aid in methods utilized for targeted authentication queries based on detected user actions. [0011] Todasco Kursun in view of Todasco fails to explicitly teach, completeness threshold. However, Keith, JR teaches, and authenticating, by the processing system, the user according to the second authentication information based on a completeness threshold(Keith, Jr. [0408] “FIG. 41 illustrates a flowchart of a method of implementing document signing with the human as the password(e.g. second authentication information) according to some embodiments. In the step 4100, a document is accessed for a user to sign. The document is able to be stored locally or remotely. For example, the document (e.g. second authentication information)is stored in a cloud device, and is accessed by a computing device (e.g., personal computer). The document(e.g. second authentication information) is able to be linked to/accompanied by metadata as described herein (e.g., trust score, environmental information, identification information, and more.”) [0413] “In the step 4110, the live scan (or an image of the live scan) is attached as metadata to the document(e.g. second authentication information) at the time of signing.” [0414] “In the step 4112, one or more human identity analytics are performed using a user device (e.g., mobile device). Motion analytics and many other techniques are described herein as ID trust assurance (e.g., the user's gait, biometric information, microtremors are analyzed). The identity analytics summary and quality (trust) score are attached as metadata to the document(e.g. second authentication information) at the time of signing. For example, a description of the motions (or other user aspects) detected is attached as metadata. In some embodiments, the individual breakdown of how well each motion or biometric data matched is able to be included in the metadata. Also, for example, a trust score of 95% is attached as metadata.” [0415] In some embodiments, if the trust score (or other score) is below a threshold, the user may not be able to sign the document (e.g., the device will not sign the document). For example, if a user's trust score is 70%, but the threshold is 90%, then the user is not permitted to sign the document (e.g., scanning the scan code does nothing or signals an error/warning). In some embodiments, the threshold may depend on the type of document. For example, an unimportant document (e.g., agreeing to terms of use for website) may allow a user to sign if the user's trust score is at least 80%, but an important document (e.g., mortgage paperwork, change of name), may require a user's trust score to be 95% or higher to sign.) (e.g. information based on a completeness threshold) (pars. 116-119, 123, 182-192, 200-209, 233-235, 238-240, 256-264: authenticating a user based on a thresholder score that reflects the sufficiency or completeness of the user’s identity analytics…. Continuously acquiring and analyzing multiple behavioral and biometric factors including voice, facial recognition…to generate a trusted score or confidence score for the user; pars. 117-123, 170-173, 188-192, 204, 218220, 227-229, 302-310: when the trust score is above a threshold access is granted and the user is authenticated; when the trust score is below the threshold access is limited or denied or additional challenges are triggered to raise the score… authenticating the user according to the collected authentication information based on a threshold condition that determines whether the identity evidence is sufficient to allow access), Kursun, Todasco, and Keith, JR. are analogues in that they are all in the same field of security architecture. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Kursun in view of Todasco to incorporate the teachings of Keith, JR. authenticating, by the processing system, the user according to the second authentication information based on a completeness threshold. Doing so, would aid in a user identity platform architecture which uses a multitude of biometric analytics to create an identity token unique to an individual human. [0004] Keith, JR. Regarding Claim 12, Kursun in view of Tadasco and in further view of Keith, JR. teach the method of claim 10, Kursun further teaches wherein the end user device associated with the user is a first end user device, wherein the first authentication information is received from a second end user device of the user that is different from the first end user device, and wherein the first authentication information comprises biometric information of the user (pars. 26-30, 45-53: continuous and competitive authentication method, par. 32 first end user device; pars. 33: second authentication channel /desktop/laptop/tablet/smart device; par 71: parallel first and second channels; pars 26, 32-35, 41-44: voice, face, iris, fingerprint…). Regarding Claim 13, Kursun in view of Tadasco and in further view of Keith, JR. teach The method of claim 1, outlined above. Kursun further teaches wherein the analyzing the first authentication information to determine the confidence level for the first authentication includes applying an Artificial Intelligence (AI) model to the first authentication information and to other information associated with the user(Kursun [0027]“Said confidence value may be calculated each time authentication data is collected from a user, and thus the confidence value may be constantly updated. In other embodiments, the confidence value may be lowered based on other factors of interest to the entity. For instance, the entity may lower the confidence value associated with a particular user if the user's profile has been linked with prior unauthorized activity or if the user is traveling overseas. In some embodiments, the biometric information(i.e. first authentication information) may be ascertained using an artificial intelligence engine (e.g., a neural network) where despite explicit storage of biometrics data, characteristics and learned profiles are available.”). Regarding Claim 14, claim 14 is a system claim that recites similar limitations as claim 1, therefore, is rejected based on the same rational as claim 1 outlined above. Kursun further teaches A device, comprising: a processing system including a processor; and a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations, the operations comprising(Kursun [0084] “It will also be understood that the one or more computer-executable program code portions may be stored in a transitory or non-transitory computer-readable medium (e.g., a memory, and the like) that can direct a computer and/or other programmable data processing apparatus to function in a particular manner, such that the computer-executable program code portions stored in the computer-readable medium produce an article of manufacture”)([0038] “The entity authentication server 110 typically contains a processor 221 communicably coupled to such devices as a communication interface 211 and a memory 231.”) (Kursun [0031] “FIG. 1 is a block diagram illustrating an operating environment for the entity authentication system 100(i.e. processing system): Regarding Claim 15, Kursun in view of Tadasco and in further view of Keith, JR. teach The method of claim 1 The device of claim 14, Kursun further teaches wherein the operations comprise [selecting a type of] the second authentication information from among a group of different authentication queries for the second authentication, wherein the selecting of the type of the second authentication information is based on the confidence level (pars. 27, 36, 44, 69: continuously collecting authentication data, comparing the data with historical/reference data and calculating a confidence level that is adjusted based on the consistency of the user’s authentication data; when the confidence level drops below a threshold, the system initiates a competitive authentication process and requests additional authentication data); Tadasco teaches selecting a type of different plurality of query types (see pars. 19, 21 and 42-43, 65). Keith, Jr. teaches confidence level (see pars. 116-119, 123, 182-192, 200-209, 233-235, 238-240, 256-264: authenticating a user based on a thresholder score that reflects the sufficiency or completeness of the user’s identity analytics…. Continuously acquiring and analyzing multiple behavioral and biometric factors including voice, facial recognition). The rational for combining is the same as claim 14 above. Regarding Claim 18, claim 18 a non-transitory machine-readable medium of claim 18 that recites similar limitations as claim 1, therefore, is rejected based on the same rational as claim 1, outlined above. Kursun further teaches, A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor of an end user device, facilitate performance of operations,(Kursun [0084] “It will also be understood that the one or more computer-executable program code portions may be stored in a transitory or non-transitory computer-readable medium (e.g., a memory, and the like) that can direct a computer and/or other programmable data processing apparatus to function in a particular manner, such that the computer-executable program code portions stored in the computer-readable medium produce an article of manufacture”) Regarding Claim 2, Kursun in view of Todasco and further in view of Keith, JR. teach The method of claim 1, outlined above. Kurson further teaches, wherein the end user device associated with the user is a first end user device(Kursun [0032] “a first authentication channel 101 which may be a mobile device such as a smartphone(i.e. first end user device). In such embodiments, the user may use the smartphone(i.e. first end user device) to provide authentication data (e.g., biometric voice, speech, fingerprint, or facial data, or other types of data) to the entity authentication server 110. ”), and wherein the first authentication information is received from a second end user device of the user that is different from the first end user device([0033] “the entity authentication server 110 may receive additional authentication data from a second authentication channel 102, such as a desktop or laptop computer, portable tablet, smart device, and the like. The second authentication channel 102 may also be configured to provide the various types of biometric data described herein. The entity authentication server 110 may be configured to receive authentication data with each interaction the entity authentication server 110 encounters with the second authentication channel 102 (e.g., each time the user logs onto the entity's systems through a software application or web browser).”). Regarding Claim 3, Kursun in view of Todasco and further in view of Keith, JR. teach The method of claim 2, outlined above. Kursun further teaches wherein the first authentication information includes an image of the user(Kursun [0042] “The user interface 255 may be configured to collect various types of authentication data (e.g., biometric data) from the user, including data collected from the user's voice (e.g., pitch, amplitude, etc.), speech (e.g., cadence, diction, word choice, etc.), face (e.g., facial recognition from a captured image),”), and wherein the second authentication information includes information input by the user at the first end user device([0033] “The entity authentication server 110 may be configured to receive authentication data with each interaction the entity authentication server 110 encounters with the second authentication channel 102 (e.g., each time the user logs onto the entity's systems through a software application or web browser) wherein the authentication data may be provided through a mobile application stored on the smartphone as disclosed in [0032]”). Regarding Claim 4, Kursun in view of Todasco and further in view of Keith, JR. teach The method of claim 3, outlined above. Kursun in view of Todasco does not explicitly teach completeness threshold. However, Keith, JR. further teaches wherein the completeness threshold is based on a match percentage for the information input by the user as compared to baseline information (Keith, JR. [0471] “In the step 5008, the currently acquired user information is compared with the stored user information. For motion, the comparison is performed for each of the 6 axes (e.g., a sine wave or other wave/pattern/signal for each of these axes). For location (e.g., GPS), there will be clusters of locations that the user frequents (e.g., home, work, gym). Other types of activities may result in different types of analytical structures. The comparison involves comparing the current data set (e.g., the data set of the currently acquired information) with the baseline information. For example, an acceleration value of a data point at a specific time is compared with a baseline data point in terms of acceleration and time, and the amount that they are different is determined. Each data point difference is combined to generate the collective difference. When the current data set is different from the baseline information, the trust score for the analytic is affected. For example, if the current data set matches the baseline information exactly, then the trust score is 100%. However, if there are subtle differences, the trust score may be 94% or another number (e.g., each subtle difference is added together to determine a total difference). If there are major differences, the trust score may be 25%, 50% or another relatively low number. To avoid the overhead of storing the large data set of motion sensor readings and recalculating using the complete set, the calculation is able to be performed for each sensor reading for each polling interval, and the resultant is stored in a baseline array in a local database”) [0472] In the step 5010, the stored user information (e.g., baseline) is updated based on the currently acquired user information. In some embodiments, the stored user information is updated each time new user information is acquired. For example, over time, a user's gait or other motion/feature may change, so the baseline information (stored information) is able to be updated continuously. In some embodiments, the stored information is only updated when the comparison of the current information with the stored/baseline information is above a threshold. For example, if the currently/newly acquired information results in a trust score of 25% (with the threshold of 80%), then the currently acquired information is not stored to affect the stored/baseline information.”) Kursun, Todasco, and Keith, JR. are analogues in that they are all in the same field of security architecture. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Kursun in view of Todasco to incorporate the teachings of Keith, Jr. the completeness threshold is based on a match percentage for the information input by the user as compared to baseline information. Doing so, would aid in how a token is derived on biometric factors like human behaviors, motion analytics, human physical characteristics like facial patterns, voice recognition prints, usage of device patterns, user location actions and other human behaviors which can derive a token or be used as a dynamic password identifying the unique individual with high calculated confidence. [0004] Keith, JR. Regarding Claim 6, Kursun in view of Todasco and further in view of Keith, JR. teach The method of claim 4, outlined above. Kursun in view of Todasco does not explicitly teach obtaining, by the processing system, the baseline information from stored information in a database. However, Keith, JR. further teaches obtaining, by the processing system, the baseline information from stored information in a database(Keith, JR. [0471] “To avoid the overhead of storing the large data set of motion sensor readings and recalculating using the complete set, the calculation is able to be performed for each sensor reading for each polling interval, and the resultant is stored in a baseline array in a local database.”. [0472] “In the step 5010, the stored user information (e.g., baseline) is updated based on the currently acquired user information. In some embodiments, the stored user information is updated each time new user information is acquired. For example, over time, a user's gait or other motion/feature may change, so the baseline information (stored information) is able to be updated continuously.”) (see pars. 116-119, 230-235, 290-300: service provider accessing a user history stored in a database, including prior events, online actions etc generating authentication queries based on that stored info) Kursun, Tadasco, and Keith, JR. are analogues in that they are all in the same field of security architecture. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Kursun in view of Tadasco to incorporate the teachings of Keith, Jr. the baseline information from stored information in a database . Doing so, would aid in determining whether the user information is within a similarity range is able to performed by comparing data points and/or cluster information of stored information and acquired information. [0470] Keith, JR. Regarding Claim 9, Kursun in view of Todasco and further in view of Keith, JR. teach The method of claim 1, outlined above. Kursun further teaches wherein both of the selecting of the type of second authentication information and the completeness threshold are based on the confidence level which is calculated as a quantified value(Kursun [0040]“ Accordingly, the authentication application 241 may cause the components of the entity authentication server 110 to accept authentication data from the one or more authentication channels 210, calculate confidence levels and/or mismatch vectors(e.g. quantified value) using the data within the database server 120, integrate full or partial biometric data to create a profile of a user, and so on.”). Regarding Claim 10, Kursun in view of Todasco and further in view of Keith, JR. teach The method of claim 1, outlined above. Kursun in view of Todasco does not explicitly teach determining, by the processing system, a location of the user; and providing, by the processing system, a request to a sensor according to the location to capture the first authentication information associated with the user. However, Keith, JR. teaches comprising: determining, by the processing system, a location of the user(Keith, JR. [0471] “For location (e.g., GPS(e.g. sensor)), there will be clusters of locations that the user frequents (e.g., home, work, gym).”); and providing, by the processing system, a request to a sensor according to the location to capture the first authentication information associated with the user([0541]“As described herein, sound processing, image/video processing, sensor processing (e.g., motion analysis), and/or other processing is able to be implemented. The analysis is able to be used to separate information into specific pieces of information to be compared and/or classified. For example, if a device captures information while a user is running, the information captured is able to include GPS information, time information, breath information, grunting noises, gait, arm motions, perspiration information, body temperature, heart rate, and many other separate pieces of information which are able to be classified.”). Kursun, Todasco, and Keith, JR. are analogues in that they are all in the same field of security architecture. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Kursun in view of Todasco to incorporate the teachings of Keith, Jr. determining, by the processing system, a location of the user; and providing, by the processing system, a request to a sensor according to the location to capture the first authentication information associated with the user. Doing so, would aid in how pattern matching is able to be implemented by repeatedly processing information and learning to detect patterns. [0541] Keith, JR. Regarding Claim 16, claim 16 the device of claim 14 that recites similar limitations as claim 10, therefore, is rejected based on the same rational as claim 10, outlined above. Regarding Claim 11, Kursun in view of Todasco and further in view of Keith, JR. teach The method of claim 10, outlined above. Kursun in view of Todasco does not explicitly teach wherein the sensor includes a camera at the location of the user. However, Keith, Jr. teaches wherein the sensor includes a camera at the location of the user(Keith, JR. [0477]“ Identifying the user includes acquiring user information in any manner such as acquiring image/video information using a camera, acquiring audio information using a microphone and/or acquire other information using other sensors.”). ([0487] “When a user is near or touching a bank vault, but that user is unauthorized to do so, an alert is able to be triggered. The user is able to be identified using a security camera and/or a signal sent from the user's smart phone, the identification of the identified user is able to be compared with a bank list of identifications of authorized users for the vault, and the security system is able to trigger the alarm. Additionally, the security camera or other motion/touch/proximity sensors are able to detect that the user is within a specified range of the vault.”) Kursun, Todasco, and Keith, JR. are analogues in that they are all in the same field of security architecture. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Kursun in view of Todasco to incorporate the teachings of Keith, Jr. the sensor includes a camera at the location of the user. Doing so, would aid in the implementations of the user movement and behavior tracking for security and suspicious activities method/system. [0486] Keith, JR. Regarding Claim 19, Kursun in view of Todasco and further in view of Keith, JR. teach a non-transitory machine-readable medium of claim 18, outlined above. Kursun further teaches, wherein the second authentication information is non-biometric information that is input at a communication device other than the end user device. (Kursun [0075] “If the steady state has been reached, the process may continue to block 522, where the system integrates the first set and the second set of partial authentication data (e.g., partial biometrics or other limited data) into a full profile associated with the user. The profile associated with the user may comprise the streaming (e.g., current) partial authentication data collected by the system as well as historical or reference data (including biometric and non-biometric data).”) (Keith, JR. [0521]“ The external information(i.e. non-biometric information) is able to include external factors such as diet, medication, weather, noise, stressful versus serene environments, and others. The external information is able to be acquired in any manner such as by a user manually inputting in information (e.g., typing or selecting the meal the user ate), retrieving information from a receipt (e.g., shopping receipt indicates which items a user purchased or a restaurant receipt includes the meal a user ate), extracting information from a picture (e.g., a user takes a picture of the user's meal, and the device is able to analyze the picture to parse out each item and calculate dietary information such as calories, protein, vitamins, minerals and more), and in other ways. The external information is able to be acquired by: sensors (e.g., a thermometer), searching for and acquiring information (e.g., search via a search engine to retrieve data), a microphone/camera, and/or any other manner.”) Claim(s) 5 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kursun et al. (Pub. No. US 20190272361 A1)(hereinafter Kursun) in view of Todasco et al. (Pub. No. US 20170324752 A1)(hereinafter Todasco) and further in view of Keith, JR. (Pub. No. (US 20240022565 A1) and further in view of Zizi et al. (Pub. No. (US 20220197986 A1)(hereinafter Zizi). Regarding Claim 5, Kursun in view of Todasco and further in view of Keith, JR. teach The method of claim 4, outlined above. Kursun in view of Todasco and further in view of Keith, JR. does not explicitly teach obtaining, by the processing system, the baseline information from publicly available sources. However, Zizi teaches comprising: obtaining, by the processing system, the baseline information from publicly available sources(Zizi [0248] “FIG. 33 shows an inter-operation between a prover and a verifier(e.g. Verifier function engine 3226). Prior to communication as a prover and a verifier, the verifier can do registration and receive a key (e.g., public key) associated with the prover's information directly from the prover or indirectly from the prover. During the registration process, the verifier can receive additional information (e.g., an Elliptic curve group generator in ECDSA) associated with the prover. The prover can generate or a read secure key, generate a proof message and then the prover can send proof message to the verifier. When the verifier receives the proof message from the prover, the verifier can perform verification function.”). Kursun, Todasco, Keith, JR., and Zizi are analogues in that they are all in the same field of user identification, authentication, and encryption. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Kursun in view of Todasco and further in view of Keith, JR. to incorporate the teachings of Zizi the baseline information from publicly available sources. Doing so, would aid as more portable electronic devices are used, such as laptop computers and mobile smartphones, in a highly mobile computing environment, correct authentication of people and devices becomes important to ascertain authorized use and lower risks linked to data misrouting. [0004] Zizi Claim(s) 7, 8, 17, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kursun et al. (Pub. No. US 20190272361 A1)(hereinafter Kursun) in view of Todasco et al. (Pub. No. US 20170324752 A1)(hereinafter Todasco) and further in view of Keith, JR. (Pub. No. (US 20240022565 A1) and further in view of Suzuki et al. (Pub. No. US 20150302186 A1)(hereinafter Suzuki). Regarding Claim 7, Kursun in view of Todasco and further in view of Keith, JR. teach The method of claim 4, outlined above. Kursun, Todasco, Keith, JR. does not explicitly teach wherein the first authentication results in a temporary authentication enabling use of an application by the user for a time period and the request for the second authentication information is provided to the end user device before expiration of the time period. However, Suzuki teaches wherein the first authentication results in a temporary authentication enabling use of an application by the user for a time period and the request for the second authentication information is provided to the end user device before expiration of the time period(Suzuki [Abstract] “A smartphone into which an application is installed includes a first and second authentication processing unit. The first authentication processing unit is configured to determine whether or not a current activation time of the application is past expiration time; permits authentication if the current activation time is not past the expiration time; and denies authentication if the current activation time is past the expiration time…The second authentication processing unit is configured to determine whether or not the current activation time is after previous activation time; permit authentication if the current activation time is after the previous activation time; and deny authentication if the current activation time is not after the previous activation time”). Kursun, Todasco, Keith, JR. and Suzuki are analogues in that they are all in the same field of user identification, authentication, and encryption. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Kursun in view of Todasco and further in view of Keith, JR. to incorporate the teachings of Suzuki the first authentication results in a temporary authentication enabling use of an application by the user for a time period and the request for the second authentication information is provided to the end user device before expiration of the time period. Doing so, would enable a terminal device to determine unauthorized usage of an application by a user by properly performing authentication of expiration time relating to the usage of the application, even in a state in which it is difficult to connect the terminal device to a server. [0014] Suzuki Regarding Claim 17, claim 17 the device of claim 14 that recites similar limitations as claim 7, therefore, is rejected based on the same rational as claim 7, outlined above. Regarding Claim 20, claim 20 a non-transitory machine-readable medium of claim 18 that recites similar limitations as claim 7, therefore, is rejected based on the same rational as claim 7, outlined above. Regarding Claim 8, Kursun in view of Todasco, Keith, JR. and Suzuki teach The method of claim 7. Kursun further teaches wherein the use of the application by the user is at the second end user device(Kursun [0033] “a second authentication channel 102, such as a desktop or laptop computer, portable tablet, smart device, and the like”), and wherein the first authentication information includes biometric data of the user([0005] “wherein the authentication data comprises biometric data; detecting that a confidence level associated with the user has dropped below a specified threshold;”). ([0007] “wherein the user profile associated with the user comprises historical biometric data associated with the user. The invention may further comprise, based on the first set of authentication data and the user profile associated with the user, determine whether to authenticate the user.”) Conclusion The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. Leblang et al. (Pub. No. US 20210092128 A1) teaches multi-factor authentication to access services. Valkaitis (Pub. No. US 11652810 B1) teaches secure multi-factor authentication system to authenticate a user device for accessing a service. Himabindu et al. (Pub. No. US 20200065459 A1) teaches Intelligent Dynamic Authentication System. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MALA BOYD whose telephone number is (571)272-6450. The examiner can normally be reached M-F 7:30-4:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A Shiferaw can be reached at (571)-272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Mala Boyd/Patent Examiner Art Unit 2497 /ELENI A SHIFERAW/Supervisory Patent Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Dec 03, 2024
Application Filed
Jun 24, 2026
Non-Final Rejection mailed — §101, §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month