Prosecution Insights
Last updated: October 01, 2026
Application No. 18/976,142

PREVENTING UNAUTHORIZED ACCESS TO DEVICE LOCATION

Non-Final OA §101§103§112
Filed
Dec 10, 2024
Priority
Dec 10, 2023 — provisional 63/608,285
Examiner
FARAMARZI, GITA
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
Apple Inc.
OA Round
1 (Non-Final)
51%
Grant Probability
Moderate
1-2
OA Rounds
1y 9m
Est. Remaining
70%
With Interview

Examiner Intelligence

Grants 51% of resolved cases
51%
Career Allowance Rate
41 granted / 80 resolved
-6.7% vs TC avg
Strong +19% interview lift
Without
With
+18.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
22 currently pending
Career history
122
Total Applications
across all art units

Statute-Specific Performance

§101
8.3%
-31.7% vs TC avg
§103
57.4%
+17.4% vs TC avg
§102
4.9%
-35.1% vs TC avg
§112
28.4%
-11.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 80 resolved cases

Office Action

§101 §103 §112
CTNF 18/976,142 CTNF 89584 DETAILED ACTION Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. 12-151 AIA 26-51 12-51 Status of Claims The following is a Non-Final Office Action in response to applicant’s filing on December 10, 2024. Claims 1-20 are pending, of which claims 1, 14 and 18 are in independent form. Specification 06-16 AIA Applicant is reminded of the proper language and format for an abstract of the disclosure. The abstract should be in narrative form and generally limited to a single paragraph on a separate sheet within the range of 50 to 150 words in length. The abstract should describe the disclosure sufficiently to assist readers in deciding whether there is a need for consulting the full patent text for details. The language should be clear and concise and should not repeat information given in the title. It should avoid using phrases which can be implied, such as, “The disclosure concerns,” “The disclosure defined by this invention,” “The disclosure describes,” etc. In addition, the form and legal phraseology often used in patent claims, such as “means” and “said,” should be avoided. 06-13 AIA The abstract of the disclosure is objected to because it should avoid using phrases which can be implied (i.e., a service running on a server devices can receive… the set of user devices can include… service can receive… service can determine). Further, “ a service running on a server devices ” is grammatically incorrect . Correction is required. See MPEP § 608.01(b). Claim Rejections - 35 USC § 101 07-04-01 AIA 07-04 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Analysis Step 1 (Statutory Categories) — 2019 PEG pq. 53 Claims 1-20 are directed to the statutory categories of invention. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 1 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: “ determining … whether the first user device is untrusted; and in accordance with a determination that the first user device is untrusted,”. This step constitutes analyzing information, which can be performed mentally. The claim further recites “in accordance with a determination … whether the first user device is untrusted”. This is a decision-making rule governing access to information based on a trusted vs. untrusted, which is directed to access control policies. Therefore, claim 1’s step of “ determining … whether the first user device is untrusted ” is an abstract idea regardless of the technical domain in which it is applied. Accordingly, claim 1 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 1 does not integrate the abstract idea into a practical application. Although the claim recites the additional limitations “ receiving , by the service, a first signal indicative that a critical operation associated with the profile is being requested; … receiving , by the service from a first user device of the set of one or more user devices, a request for respective user device tracking information for other devices of the set of one or more user devices; receiving, by a service running on one or more server devices … the set of one or more user devices including trusted devices and untrusted devices” and “ determining , by the service, to not transmit respective user device tracking information for other devices to the first user device” and “ a service running on one or more server devices ”, “ user devices ”, “ receiving signal and transmitting data ”, these elements merely represent generic computer components performing generic computer functions. The claim recites additional elements of receiving and transmitting data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. The claim does not improve the functioning of a computer. Instead, the claim merely uses generic computing components to implement the abstract idea of evaluating and authorizing a request . Therefore, claim 1 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 1 does not include an inventive concept. The additional elements ( receiving data, determining a status based on data, transmitting data, and using generic servers and devices ) are routine and conventional . The claim merely applies generic computing techniques to perform the abstract idea. The claim therefore amounts to: applying an abstract idea using generic computer components which does not constitute significantly more. Accordingly, under Step 2B of the PEG, the claim 1 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 2 depends from claim 1 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: “ determining whether … originates from a web browser… determining… the first user device is untrusted…”. Considered as a whole, the claim is directed to the abstract idea of evaluating information and making a decision on the evaluation . This is a concept that can be performed by a human. Therefore, claim 2’s steps of “ determining … whether the request originates from a web browser , and determining … the first user device is untrusted… ” are an abstract idea regardless of the technical domain in which they are applied. Accordingly, claim 2 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 2 does not integrate the abstract idea into a practical application. The additional limitations “ a service, and web browser on the first user device ” merely refine how relationships are identified between entities The claim recites additional elements of tracking data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. Therefore, claim 2 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 2 does not include an inventive concept. The additional steps of identifying a request from a web browser and using a service to make determination are routine and conventional . The claim merely applies generic computing techniques to perform the abstract idea. Accordingly, under Step 2B of the PEG, the claim 2 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 3 depends from claim 2 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: “ determining whether the first user device is untrusted is based at least in part on an indication that the first user device did not receive biometric authentication … determining whether the first user device is untrusted includes: transmitting, by the service to the first user device, the biometric confirmation request, the first user device configured to request biometric authentication in response to the biometric confirmation request;”. Considered as a whole, the claim is directed to the abstract idea of collecting information (biometric), evaluating that information, and making a determination . This is a concept that can be performed by a human and constitutes a mental process . Further, the claim recites “the indication that the first user device did not receive biometric authentication in response to the biometric confirmation request”. Such a rule-based decision making is a method of organizing human activity . Accordingly, claim 3 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 3 does not integrate the abstract idea into a practical application. Although the claim recites a “and receiving , … the indication that the first user device did not receive biometric authentication in response to the biometric confirmation request” and “ service, first user device, transmitting … biometric confirmation request, and receiving … indication ” are additional element of receiving data by a computer is an insignificant extra solution activity. This element is recited at a high level of generality and are used only as tool to perform the abstract idea. The claim does not improve the biometric authentication technology. The additional limitation biometric confirmation request, and receiving … indication… ) is merely data gathering activity and it does not impose any meaningful technical constraint on the abstract idea. Therefore, claim 3 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 3 does not include an inventive concept. The additional element “transmitting, by the service to the first user device…. receiving , … the indication that the first user device did not receive biometric authentication in response to the biometric confirmation request” is routine and conventional . The claim merely applies combination of requesting, receiving result and apply rule…, which is generic computing techniques to perform the abstract idea. The claim therefore amounts to: applying an abstract idea using generic computer components which does not constitute significantly more. Accordingly, under Step 2B of the PEG, the claim 3 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 4 depends from claim 2 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: “ determining whether the first user device is untrusted is based at least in part on the indication”. Considered as a whole, the claim is directed to the abstract idea of collecting biometric information, evaluating the information, and making a determination based on that evaluation . Such steps can be performed mentally. Accordingly, claim 4 recites a mental process , which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 4 does not integrate the abstract idea into a practical application. Although the claim recites a “ user devices, request for tracking information, and biometric confirmation ” is a generic data retrieval function. The claim recites additional elements of tracking data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. The claim does not improve the functioning of a computer. Therefore, claim 4 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 4 does not include an inventive concept. The additional element “ user devices, request for tracking information, and biometric confirmation ” regarding identifying the information are routine and conventional functions . The claim merely applies generic computing techniques to perform the abstract idea. The claim therefore amounts to: applying an abstract idea using generic computer components which does not constitute significantly more. Accordingly, under Step 2B of the PEG, the claim 4 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 5 depends from claim 1 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes and mathematical concept: “ determining … whether the first user device is trusted; and in accordance with determining …”. Considered as a whole, the claim is directed to the abstract idea of evaluating information, making decision and taking action . Such steps can be performed mentally and can be performed by a human. Accordingly, claim 5 recites a mental process , which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 5 does not integrate the abstract idea into a practical application. Although the claim recites a “ user devices, transmitting… tracking information ” is a generic data retrieval function. The claim recites additional elements of transmitting data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. The claim does not improve the functioning of a computer. Therefore, claim 5 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 5 does not include an inventive concept. Making a determination and transmitting the information is a conventional technique. The claim therefore amounts to: applying an abstract idea using generic computer components which does not constitute significantly more. Accordingly, under Step 2B of the PEG, the claim 5 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 6 depends from claim 5 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: “ determining whether the first user device is trusted is based at least in part on an indication that the first user device received biometric authentication in response to a biometric confirmation request from the service, and wherein determining whether the first user device is trusted includes”. Considered as a whole, the claim is directed to the abstract idea of evaluating the information and making a determination based on the evaluation . The claim further recited “in response to a biometric confirmation request from the service, and wherein determining whether the first user device is trusted and transmitting the result”. Such steps fall within certain methods of organizing human activity access control and can be performed mentally and can be performed by a human. Accordingly, claim 6 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 6 does not integrate the abstract idea into a practical application. The additional limitations “; receiving , by the service from the first user device, the indication that the first user device received biometric authentication in response to the biometric confirmation request ” and further, the additional elements ” first user device, transmitting …biometric confirmation request, and receiving… indication ” and “The claim recites additional elements of receiving and transmitting data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea.” are generic computing component performing conventional functions. The claim does not improve biometric authentication technology. Therefore, claim 6 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 6 does not include an inventive concept. The additional steps of request, authentication, receiving confirmation and applying rules are routine and conventional . The claim merely applies generic computing techniques to perform the abstract idea. Accordingly, under Step 2B of the PEG, the claim 6 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 7 depends from claim 5 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: “ determining whether the first user device is trusted is based at least in part on the biometric confirmation”. Considered as a whole, the claim is directed to the abstract idea of collecting information, evaluating the information and making a determination based on the evaluation . The claim further recited “in response to a biometric confirmation request from the service, and wherein determining whether the first user device is trusted”. Such steps fall within certain methods of organizing human activity access control and can be performed mentally and can be performed by a human. Accordingly, claim 7 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 7 does not integrate the abstract idea into a practical application. The additional limitations “ first user device, request for … tracking information, and biometric confirmation ” and “received biometric authentication” are generic computing component performing conventional functions. The claim recites additional elements of tracking data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. The claim does not improve biometric authentication technology. Therefore, claim 7 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 7 does not include an inventive concept. The additional steps of request, authentication, evaluating and applying rules are routine and conventional . The claim merely applies generic computing techniques to perform the abstract idea. Accordingly, under Step 2B of the PEG, the claim 7 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 8 depends from claim 1 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: “ determining , by the service, whether the second request originates from a web browser; and in accordance with determining the second request originates from the web browser”. Considered as a whole, the claim is directed to the abstract idea of collecting information, evaluating the information and providing a response based on the evaluation . The claim further recited “in accordance with determining the second request originates from the web browser, transmitting, … an indication that the respective user device tracking information for other devices is unknown or unavailable”. Such steps fall within certain methods of organizing human activity access control and can be performed mentally and can be performed by a human. Accordingly, claim 8 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 8 does not integrate the abstract idea into a practical application. The additional limitations “ receive… request, evaluate source and transmit… an indication ” are generic computing component performing conventional functions. The claim does not improve biometric authentication technology. The claim recites additional elements of receiving and transmitting data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. Therefore, claim 8 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 8 does not include an inventive concept. The additional steps of “ receive… request, evaluate source and transmit… an indication” are routine and conventional . The claim merely applies generic computing techniques to perform the abstract idea. Accordingly, under Step 2B of the PEG, the claim 8 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 9 depends from claim 1 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: “ wherein the critical operation includes altering a security feature associated with the profile”. Considered as a whole, the claim is directed to the abstract idea of security policy enforcement . Such step falls within certain methods of organizing human activity access control and can be performed mentally and can be performed by a human. Accordingly, claim 9 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 9 does not integrate the abstract idea into a practical application. The additional limitations “ profile, security feature ” are generic computing component performing conventional functions. The claim recites additional elements organizing by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. The claim does not improve computer functionality. Therefore, claim 9 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 9 does not include an inventive concept. The additional steps of identifying condition and alert security feature are routine and conventional . The claim merely applies generic computing techniques to perform the abstract idea. Accordingly, under Step 2B of the PEG, the claim 9 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 10 depends from claim 1 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: “ wherein the critical operation includes accessing financial information associated with the profile”. Considered as a whole, the claim is directed to the abstract idea of identifying financial information associated with a profile . Such step falls within certain methods of organizing human activity financial data management and can be performed mentally and can be performed by a human. Accordingly, claim 10 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 10 does not integrate the abstract idea into a practical application. The additional limitations “ profile and financial information ” are generic computing component performing conventional functions. The claim recites additional elements of organizing data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. The claim does not improve financial data processing technology. Therefore, claim 10 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 10 does not include an inventive concept. The additional steps of financial information and profile are routine and conventional . The claim merely applies generic computing techniques to perform the abstract idea. Accordingly, under Step 2B of the PEG, the claim 10 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 11 depends from claim 1 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: “ wherein the critical operation includes marking a second user device as a lost device”. Considered as a whole, the claim is directed to the abstract idea of identifying a device status and assigning a classification (lost device) . Such steps fall within certain methods of organizing human activity access control and can be performed mentally and can be performed by a human. Accordingly, claim 11 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 11 does not integrate the abstract idea into a practical application. The additional limitations “ user devices and profile ” are generic computing component performing conventional functions. The claim recites additional elements of organizing data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. The claim does not improve mobile device security system. Therefore, claim 11 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 11 does not include an inventive concept. The additional steps of identify condition and assign status are routine and conventional . The claim merely applies generic computing techniques to perform the abstract idea. Accordingly, under Step 2B of the PEG, the claim 11 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 12 depends from claim 1 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: Considered as a whole, the claim is directed to the abstract idea of collecting information, evaluating the information and taking an action based on the evaluation . Such steps fall within certain methods of organizing human activity access control and can be performed mentally and can be performed by a human. Accordingly, claim 12 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 12 does not integrate the abstract idea into a practical application. The additional limitations “ receiving, by the service, a second signal indicative that the critical operation is completed; receiving , … a request for respective user device tracking information … transmitting, … the set of one or more user devices based at least in part on the second signal.”…. “ user devices, signals, and tracking information ” are generic computing component performing conventional functions. The claim recites additional elements of organizing data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. The claim does not improve computer functionality. Therefore, claim 12 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 12 does not include an inventive concept. The additional steps of receiving signals, receive request and transmit information based on signal are routine and conventional . The claim merely applies generic computing techniques to perform the abstract idea. Accordingly, under Step 2B of the PEG, the claim 12 is not patent eligible. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 13 depends from claim 1 and recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: Considered as a whole, the claim is directed to the abstract idea of making information available for access by a web browser . Such step falls within certain methods of organizing human activity access control and can be performed mentally and can be performed by a human. Accordingly, claim 13 recites a mental process, which is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 13 does not integrate the abstract idea into a practical application. The additional limitations “ web browser and user device tracking information ” and “ wherein the respective user device tracking information for the set of one or more devices is accessible by a web browser” are generic computing component performing conventional functions. The claim recites additional elements of organizing data by a computer as an insignificant extra solution activity. These elements are recited at a high level of generality and are used only as tool to perform the abstract idea. The claim does not improve biometric authentication technology. Therefore, claim 13 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 13 does not include an inventive concept. The additional steps of make the information accessible via a web browser , are routine and conventional . The claim merely applies generic computing techniques to perform the abstract idea. Accordingly, under Step 2B of the PEG, the claim 13 is not patent eligible. Claim 14 includes all the limitations of claim 1. Therefore, claim 14 recites the same abstract idea of claim 1. Claim 14 recites the additional limitations “a storage medium configured to store computer-executable instructions; and one or more processors coupled to the storage medium and configured to execute computer-executable instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality , therefore, does not amount to significantly more than the abstract idea. Claim 15 depends from claim 14 includes all the limitations of claim 2. Therefore, claim 15 recites the same abstract idea of claim 2. Claim 15 recites the additional limitations “a storage medium configured to store computer-executable instructions; and one or more processors coupled to the storage medium and configured to execute computer-executable instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality , therefore, does not amount to significantly more than the abstract idea. Claim 16 depends from claim 15 includes all the limitations of claim 3. Therefore, claim 16 recites the same abstract idea of claim 3. Claim 16 recites the additional limitations “a storage medium configured to store computer-executable instructions; and one or more processors coupled to the storage medium and configured to execute computer-executable instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality , therefore, does not amount to significantly more than the abstract idea. Claim 17 depends from claim 15 includes all the limitations of claim 4. Therefore, claim 17 recites the same abstract idea of claim 4. Claim 17 recites the additional limitations “a storage medium configured to store computer-executable instructions; and one or more processors coupled to the storage medium and configured to execute computer-executable instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality , therefore, does not amount to significantly more than the abstract idea. Claim 18 includes all the limitations of claim 1 and 14. Therefore, claim 18 recites the same abstract idea of claim 1 and 14. Claim 18 recites the additional limitations “A non-transitory computer-readable storage medium having stored thereon program instructions that, when executed by one or more processors of a computer system”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality , therefore, does not amount to significantly more than the abstract idea. Claim 19 depends from claim18 includes all the limitations of claim 5. Therefore, claim 19 recites the same abstract idea of claim 5. Claim 19 recites the additional limitations “a storage medium configured to store computer-executable instructions; and one or more processors coupled to the storage medium and configured to execute computer-executable instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality , therefore, does not amount to significantly more than the abstract idea. Claim 20 depends from claim 19 includes all the limitations of claim 6. Therefore, claim 20 recites the same abstract idea of claim 6. Claim 20 recites the additional limitations “a storage medium configured to store computer-executable instructions; and one or more processors coupled to the storage medium and configured to execute computer-executable instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality , therefore, does not amount to significantly more than the abstract idea. Claim Rejections - 35 USC § 112 07-30-02 AIA The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. 07-34-01 Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1 is rejected as being indefinite. Claim 1 recites “ trusted devices and untrusted devices”. The terms “ trusted and untrusted ” are not defined by any specified criteria or threshold in the claim. The claim does not specify what condition render a device “ trusted ” or “ untrusted ”. Therefore, the terms are relative and subjective. Claim 1 is rejected as being indefinite. Claim 1 recites “ critical operation ”. Although dependent claims provide examples (altering a security feature, accessing financial information, and marking a device as lost), the claim does not define what makes an operation critical. Accordingly, the term “ critical operation ” renders the metes and bounds of the claims unclear. Claim 1 is rejected as being indefinite. Claim 1 recites “user device tracking information ”. The term “ tracking information ” is ambiguous because the claim does not specify what type of information is included such as location, usage data, or other attributes. Accordingly, the term “ tracking information ” renders the metes and bounds of the claims unclear. Accordingly, independent claims 14 and 18, and the dependent claims are similarly rejected. Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim s 1-2, 5, 7, 8-15, and 18-19 are rejected under 35 U.S.C. 103 as being unpatentable over Siddiqui (US 2018/0167376 A1), hereinafter Siddiqui in view of Zaki et al. (US 2022/0329581 A1), hereinafter Zaki . Regarding claim 1, Siddiqui discloses a computer-implemented method, comprising: receiving, by a service running on one or more server devices from a set of one or more user devices associated with a profile (Siddiqui, Para. 0016, the location authentication service may maintain a profile associated with the user. The profile may include an indication of services the user may access and for which location authentication may be performed to facilitate the access) , respective user device tracking information for each device of the set of one or more user devices (Siddiqui, Para. 0018, at least one criterion may be that the location of the authentication device is within a geographic boundary surrounding the location of the service access device or vice-versa) , the set of one or more user devices including trusted devices and untrusted devices; receiving, by the service, a first signal indicative that a critical operation associated with the profile is being requested (Siddiqui, Para. 0062, Fig. 4, Step 426, If a negative determination is made the location authentication service sends 614 a notification indicating that the location is not authenticated. The notification may be a non-acknowledgement as described with reference to numeral 424 in FIG. 4. If a positive determination is made the location authentication service sends 616 a notification indicating that the location is of the user is authenticated. The notification may be an acknowledgement as described with reference to numeral 426) ; receiving, by the service from a first user device of the set of one or more user devices (Siddiqui, Para. 0051) , a request for respective user device tracking information for other devices of the set of one or more user devices (Siddiqui, Para. 0051, the user logs on to the user's account with the third-party service 506 using the first device 502 and requests 514 the third-party service 506 to use the location authentication service 508 for user location authentication. Further, the request may indicate that the second device 504 be used as an authentication device. Upon receipt of the user's request to use the location authentication service 508 for authenticating user location, the third-party service 506 identifies 516 a location of the first device 502. Determining the location of the first device may, for example, be facilitated by an HTML5 browser of the first device 502. The HTML5 browser may supply the location information of the first device 502 to the third-party service 506. The location of the first device 502 will be compared to the location of the second device 504 in order verify that the second device 504 is associated with the user) ; determining, by the service, to not transmit respective user device tracking information for other devices to the first user device (Siddiqui, Para. 0063, to guard against a security compromise, the location authentication service may not share the location of the authentication device with the third-party service or other user devices. Further). Siddiqui does not explicitly teach determining, by the service, whether the first user device is untrusted; and in accordance with a determination that the first user device is untrusted, However, Zaki teaches determining, by the service, whether the first user device is untrusted (Zaki, Para. 0074, memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to: receive an indication of a short-range wireless connection between a first device and a second device, the first device being a trusted device authenticated for viewing account information for a user account, and the second device being an untrusted device not initially authenticated to view the account information) ; and in accordance with a determination that the first user device is untrusted (Zaki, Para. 0074) , Siddiqui and Zaki, are both considered to be analogous to the claim invention because they are in the same field of detecting unauthorized user device based on the device location among user’s multiple devices. Therefore, it would have been to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Siddiqui to incorporate the teachings of Zaki, to include determining, by the service, whether the first user device is untrusted (Zaki, Para. 0074, memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to: receive an indication of a short-range wireless connection between a first device and a second device, the first device being a trusted device authenticated for viewing account information for a user account, and the second device being an untrusted device not initially authenticated to view the account information) ; and in accordance with a determination that the first user device is untrusted (Zaki, Para. 0074). Doing so would aid to allow the primary device to initiate an authentication request, allows the backend to confirm the request and transfer an authorization token, and allows the secondary device to register using the token. Additionally, the security of the digital accounts is improved by limiting the access to a digital account based on the relationship between the primary and secondary device(Zaki, Para. 0022). Regarding claim 2, the combination of Siddiqui in view of Zaki teaches the computer-implemented method of claim 1, wherein determining whether the first user device is untrusted includes: determining, by the service, whether the request originates from a web browser on the first user device (Siddiqui, Para. 0050, adding the second device 504 may be requested by accessing an account of the user with the location authentication service 508 via a web browser) and (Siddiqui, Para. 0038, the third-party service 406 may be accessible via the web browser (for example, a web browser using an HTML 5 protocol) and the user of the first device 402 may be prompted to provide the location of the first device 402 to the third-party service 406) ; and in accordance with determining the request originates from the web browser, determining, by the service, the first user device is untrusted (Siddiqui, Para. 0050, if a negative determination is made the location authentication service sends 614 a notification indicating that the location is not authenticated. The notification may be a non-acknowledgement as described with reference to numeral 424). Therefore, it would have been to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Siddiqui to incorporate the teachings of Zaki, to include determining, by the service, whether the request originates from a web browser on the first user device (Siddiqui, Para. 0050) and (Siddiqui, Para. 0038) ; and in accordance with determining the request originates from the web browser, determining, by the service, the first user device is untrusted (Siddiqui, Para. 0050). Doing so would aid to allow the primary device to initiate an authentication request, allows the backend to confirm the request and transfer an authorization token, and allows the secondary device to register using the token. Additionally, the security of the digital accounts is improved by limiting the access to a digital account based on the relationship between the primary and secondary device(Zaki, Para. 0022). Regarding claim 5, the combination of Siddiqui in view of Zaki teaches the computer-implemented method of claim 1, further comprising: determining, by the service, whether the first user device is trusted; and in accordance with determining the first user device is trusted (Zaki, Para. 0074, receive an indication of a short-range wireless connection between a first device and a second device, the first device being a trusted device authenticated for viewing account information for a user account) , transmitting, by the service to the first user device, respective user device tracking information for other devices of the set of one or more user devices (prior to performing location-based authentication, a random string (Siddiqui, Para. 0022, for example, as encoded in a Quick Response (QR) code) may be shared between the first device 102 and the second device 104, whereby a camera-enabled second device 104 may capture a snapshot of the QR shown on a screen of the first device 102. Information encoded in the QR code may be relayed to the location authentication service 106 by the second device 104 (and/or other entities) to complete registration). Regarding claim 7, the combination of Siddiqui in view of Zaki teaches the computer-implemented method of claim 5, wherein the request for respective user device tracking information for other devices of the set of one or more user devices includes a biometric confirmation that the first user device requested and received biometric authentication in association with the request for respective user device tracking information for other devices (Siddiqui, Fig. 4, Para. 0063, the location authentication service may employ facial recognition for authenticating a user. The location authentication service may retain an image file associated with the user as part of the user's profile, such as a portrait of the user. To authenticate the user, the location authentication service may require that a device of the user send an image of the user to the location authentication service. The location authentication service may compare the image of the user retained by the location authentication service to the image provided by the user's device. The retained image may be different from the received image and when the images are compared a variance between the two images may be determined. One or more criteria may be set to determine whether the user may be authenticated based at least in part on the received image. Facial and image recognition may be used in addition to or in place of location authentication for authenticating the user) , and wherein determining whether the first user device is trusted is based at least in part on the biometric confirmation (Siddiqui, Fig. 4, Para. 0063, one or more criteria may be set to determine whether the user may be authenticated based at least in part on the received image). Regarding claim 8, the combination of Siddiqui in view of Zaki teaches the computer-implemented method of claim 1, further comprising: receiving, by the service, a second request for respective user device tracking information for the set of one or more user devices (Siddiqui, Para. 0015, the service may identify the location of the device used to request access to the service (or the service access device). The location of the device may be determined using a geo-location functionality of a web-browser, such as a hypertext markup language 5 (HTML5) enabled browser) ; determining, by the service, whether the second request originates from a web browser; and in accordance with determining the second request originates from the web browser, transmitting, by the service to the first user device, an indication that the respective user device tracking information for other devices is unknown or unavailable based at least in part on the first signal (Siddiqui, Para. 0015, the service may identify the location of the device used to request access to the service (or the service access device). The location of the device may be determined using a geo-location functionality of a web-browser, such as a hypertext markup language 5 (HTML5) enabled browser. The service may request the location of the device from the browser and receive the location from the browser. The service may then send a message, such as an application programming interface (API) function call, to the location authentication service requesting the location authentication service to authenticate the user). Regarding claim 9, the combination of Siddiqui in view of Zaki teaches the computer-implemented method of claim 1, wherein the critical operation includes altering a security feature associated with the profile (Siddiqui, Fig. 4, Step 424, the notification may be a non-acknowledgement as described with reference to numeral 424 in FIG. 4. If a positive determination is made the location authentication service sends 616 a notification indicating that the location is of the user is authenticated. The notification may be an acknowledgement as described with reference to numeral 426 in FIG. 4). Regarding claim 10, the combination of Siddiqui in view of Zaki teaches the computer-implemented method of claim 1, wherein the critical operation includes accessing financial information associated with the profile (Siddiqui, Para. 0063, the location authentication service may retain an image file associated with the user as part of the user's profile, such as a portrait of the user) and (Siddiqui, Para. 0014, a user may have a plurality of device, whereby one device of the plurality of devices may be a service access device using which the user may access a service, such as an e-mail account, an electronic banking account or a social networking account, among others). Regarding claim 11, the combination of Siddiqui in view of Zaki teaches the computer-implemented method of claim 1, wherein the critical operation includes marking a second user device as a lost device (Siddiqui, Para. 0022, the location authentication service then compares 610 the location of the first device and the location of the second device and determines 612 whether the user can be authenticated, for example, as described with reference to numeral 422 in FIG. 4. If a negative determination is made the location authentication service sends 614 a notification indicating that the location is not authenticated. The notification may be a non-acknowledgement as described with reference to numeral 424 in FIG. 4). Regarding claim 12, the combination of Siddiqui in view of Zaki teaches the computer-implemented method of claim 1, further comprising: receiving, by the service, a second signal indicative that the critical operation is completed (Siddiqui, Para. 0019, if, on the other hand, the user is not authenticated, the location authentication service may send a message (for example, a non-acknowledgement) to the service indicating that the location of the user has not been authenticated) ; receiving, by the service from the first user device, a request for respective user device tracking information for other devices of the set of one or more user devices (Siddiqui, Para. 0019, verifying the device as being a device of the user may include receiving from the device a request to designate the device for usage in location identification as described herein... The security code may be a security token, such as a temporary security token. Further, verifying the device may include comparing the location of the device with a location received from the service and determining whether a correspondence exists between the locations. The location received from the service may be a location of the service access device) ; and transmitting, by the service to the first user device, respective user device tracking information for other devices of the set of one or more user devices based at least in part on the second signal (Siddiqui, Para. 0056, the confirmation package is then transferred 522 from the first device 502 to the second device 504. Transferring the confirmation package may be performed by physically connecting the two devices and causing the confirmation package to be received by the second device 504 using any appropriate communication protocol, for example, a High-Definition Multimedia Interface (HDMI) communication protocol). Regarding claim 13, the combination of Siddiqui in view of Zaki teaches the computer-implemented method of claim 1, wherein the respective user device tracking information for the set of one or more devices is accessible by a web browser (Siddiqui, Para. 0015, the location of the device may be determined using a geo-location functionality of a web-browser, such as a hypertext markup language 5 (HTML5) enabled browser). Regarding claim 14, the claim is interpreted and rejected for the same rational set forth in claim 1. Regarding claim 15, the claim is interpreted and rejected for the same rational set forth in claim 2. Regarding claim 18, the claim is interpreted and rejected for the same rational set forth in claims 1 and 14. Regarding claim 19, the claim is interpreted and rejected for the same rational set forth in claim 5 . 07-21-aia AIA Claim s 3-4, 6, 16-17 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Siddiqui (US 2018/0167376 A1), hereinafter Siddiqui in view of Zaki et al. (US 2022/0329581 A1), hereinafter Zaki and further in view of Royyuru (US 2017/0085563 A1), hereinafter Royyuru . Regarding claim 3, the combination of Siddiqui in view of Zaki does not explicitly teach the computer-implemented method of claim 2, wherein determining whether the first user device is untrusted is based at least in part on an indication that the first user device did not receive biometric authentication in response to a biometric confirmation request from the service, and wherein determining whether the first user device is untrusted includes: transmitting, by the service to the first user device, the biometric confirmation request, the first user device configured to request biometric authentication in response to the biometric confirmation request; and receiving, by the service from the first user device, the indication that the first user device did not receive biometric authentication in response to the biometric confirmation request. However, Royyuru teaches wherein determining whether the first user device is untrusted is based at least in part on an indication that the first user device did not receive biometric authentication in response to a biometric confirmation request from the service (Royyuru, Para. 0037, this input may be authenticated locally using the mobile device and the biometric authentication application. Here, the authentication was unsuccessful due to a mismatch between the received biometric input and a stored biometric input) , and wherein determining whether the first user device is untrusted includes: transmitting, by the service to the first user device, the biometric confirmation request, the first user device configured to request biometric authentication in response to the biometric confirmation request (Royyuru, Para. 0037, a biometric authentication application 314 may be launched on the mobile device. The biometric authentication application may prompt the user to provide a biometric input, such as a fingerprint. This input may be authenticated locally using the mobile device and the biometric authentication application) ; and receiving, by the service from the first user device, the indication that the first user device did not receive biometric authentication in response to the biometric confirmation request (Royyuru, Para. 0037, the authentication was unsuccessful due to a mismatch between the received biometric input and a stored biometric input. A failure message 316 is returned to the user). Siddiqui, Zaki, and Royyuru are all considered to be analogous to the claim invention because they are in the same field of detecting unauthorized user device based on the device location among user’s multiple devices. Therefore, it would have been to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Siddiqui to incorporate the teachings of Zaki, to include wherein determining whether the first user device is untrusted is based at least in part on an indication that the first user device did not receive biometric authentication in response to a biometric confirmation request from the service (Royyuru, Para. 0037) , and wherein determining whether the first user device is untrusted includes: transmitting, by the service to the first user device, the biometric confirmation request, the first user device configured to request biometric authentication in response to the biometric confirmation request (Royyuru, Para. 0037) ; and receiving, by the service from the first user device, the indication that the first user device did not receive biometric authentication in response to the biometric confirmation request (Royyuru, Para. 0037). Doing so would aid to reduce and/or eliminate the need to continually enter information into a browser using a mobile device keyboard and/or navigating data fields using a touchscreen or other input interface, such as a keyboard or mouse. It will be appreciated that the terms mobile device, user device, and computing device are used interchangeably herein. Such devices may include, without limitation, mobile phones, tablet computers, laptop computers, desktop computers, and/or other computing devices that are configurable, either on their own or with connectable equipment, to perform biometric authentication (Royyuru, Para. 0019). Regarding claim 4, the combination of Siddiqui in view of Zaki teaches the computer-implemented method of claim 2, and wherein determining whether the first user device is untrusted is based at least in part on the indication (Zaki, Para. 0040, A notification can be transmitted (e.g., from the authentication system 108) to the first device 102 via push notification, email, short-message-service (SMS), or the like seeking the additional authenticating information. Alternatively or in addition, the first device 102 can be unauthenticated (or untrusted) in response to authenticating a new, second device 104). Siddiqui in view of Zaki do not explicitly teach wherein the request for respective user device tracking information for other devices includes an indication that biometric confirmation was not received by the first user device in association with the request for respective user device tracking information for other devices, However, Royyuru teaches wherein the request for respective user device tracking information for other devices includes an indication that biometric confirmation was not received by the first user device in association with the request for respective user device tracking information for other devices (Royyuru, Para. 0037, the authentication was unsuccessful due to a mismatch between the received biometric input and a stored biometric input. A failure message 316 is returned to the user) , Siddiqui, Zaki, and Royyuru are all considered to be analogous to the claim invention because they are in the same field of detecting unauthorized user device based on the device location among user’s multiple devices. Therefore, it would have been to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Siddiqui to incorporate the teachings of Zaki, to include wherein the request for respective user device tracking information for other devices includes an indication that biometric confirmation was not received by the first user device in association with the request for respective user device tracking information for other devices (Royyuru, Para. 0037). Doing so would aid to reduce and/or eliminate the need to continually enter information into a browser using a mobile device keyboard and/or navigating data fields using a touchscreen or other input interface, such as a keyboard or mouse. It will be appreciated that the terms mobile device, user device, and computing device are used interchangeably herein. Such devices may include, without limitation, mobile phones, tablet computers, laptop computers, desktop computers, and/or other computing devices that are configurable, either on their own or with connectable equipment, to perform biometric authentication (Royyuru, Para. 0019). Regarding claim 6, the combination of Siddiqui in view of Zaki does not explicitly teach the computer-implemented method of claim 5, wherein determining whether the first user device is trusted is based at least in part on an indication that the first user device received biometric authentication in response to a biometric confirmation request from the service, and wherein determining whether the first user device is trusted includes: transmitting, by the service to the first user device, the biometric confirmation request, the first user device configured to request biometric authentication in response to the biometric confirmation request; and receiving, by the service from the first user device, the indication that the first user device received biometric authentication in response to the biometric confirmation request. However, Royyuru teaches the computer-implemented method of claim 5, wherein determining whether the first user device is trusted is based at least in part on an indication that the first user device received biometric authentication in response to a biometric confirmation request from the service (Royyuru, Fig. 5, Para. 0046, the mobile authentication application may then cause the biometric mobile application to launch to perform a local authentication of the user's biometric input. Upon the biometric mobile application successfully authenticating the user, the mobile authentication application may cause the user credentials to be provided to the website) , and wherein determining whether the first user device is trusted includes: transmitting, by the service to the first user device, the biometric confirmation request, the first user device configured to request biometric authentication in response to the biometric confirmation request (Royyuru, Fig. 5, Para. 0047, the mobile device may receive, via the touchscreen display or other input interface, such as a keyboard or mouse, an input associated with a biometric access icon displayed on the website. The biometric access icon may be associated with a secure webpage) ; and receiving, by the service from the first user device, the indication that the first user device received biometric authentication in response to the biometric confirmation request (Royyuru, Fig. 5, Para. 0048, an authentication confirmation is then communicated to an entity associated with the secure webpage). Siddiqui, Zaki, and Royyuru are all considered to be analogous to the claim invention because they are in the same field of detecting unauthorized user device based on the device location among user’s multiple devices. Therefore, it would have been to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Siddiqui to incorporate the teachings of Zaki, to include the computer-implemented method of claim 5, wherein determining whether the first user device is trusted is based at least in part on an indication that the first user device received biometric authentication in response to a biometric confirmation request from the service (Royyuru, Fig. 5, Para. 0046) , and wherein determining whether the first user device is trusted includes: transmitting, by the service to the first user device, the biometric confirmation request, the first user device configured to request biometric authentication in response to the biometric confirmation request (Royyuru, Fig. 5, Para. 0047) ; and receiving, by the service from the first user device, the indication that the first user device received biometric authentication in response to the biometric confirmation request (Royyuru, Fig. 5, Para. 0048). Doing so would aid to reduce and/or eliminate the need to continually enter information into a browser using a mobile device keyboard and/or navigating data fields using a touchscreen or other input interface, such as a keyboard or mouse. It will be appreciated that the terms mobile device, user device, and computing device are used interchangeably herein. Such devices may include, without limitation, mobile phones, tablet computers, laptop computers, desktop computers, and/or other computing devices that are configurable, either on their own or with connectable equipment, to perform biometric authentication (Royyuru, Para. 0019). Regarding claim 16, the claim is interpreted and rejected for the same rational set forth in claim 3. Regarding claim 17, the claim is interpreted and rejected for the same rational set forth in claim 4. Regarding claim 20, the claim is interpreted and rejected for the same rational set forth in claim 6 . Conclusion 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892 . Any inquiry concerning this communication or earlier communications from the examiner should be directed to GITA FARAMARZI whose telephone number is (571)272-0248. The examiner can normally be reached Monday- Friday 9:00 am- 6:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado can be reached at (571)272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GITA FARAMARZI/Examiner, Art Unit 2496 /JORGE L ORTIZ CRIADO/Supervisory Patent Examiner, Art Unit 2496 Application/Control Number: 18/976,142 Page 2 Art Unit: 2496 Application/Control Number: 18/976,142 Page 3 Art Unit: 2496 Application/Control Number: 18/976,142 Page 4 Art Unit: 2496
Read full office action

Prosecution Timeline

Dec 10, 2024
Application Filed
May 27, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12627633
SYSTEM AND METHOD FOR APPLICATION TRAFFIC AND RUNTIME BEHAVIOR LEARNING AND ENFORCEMENT
5y 9m to grant Granted May 12, 2026
Patent 12339997
ENTITY FOCUSED NATURAL LANGUAGE GENERATION
2y 1m to grant Granted Jun 24, 2025
Patent 12316648
Data value classifier
5y 10m to grant Granted May 27, 2025
Patent 12301564
VIRTUAL SESSION ACCESS MANAGEMENT
4y 3m to grant Granted May 13, 2025
Patent 12256022
BLOCKCHAIN TRANSACTION COMPRISING RUNNABLE CODE FOR HASH-BASED VERIFICATION
3y 3m to grant Granted Mar 18, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
51%
Grant Probability
70%
With Interview (+18.9%)
3y 7m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 80 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month