Prosecution Insights
Last updated: October 02, 2026
Application No. 18/983,156

DEVICES, SYSTEMS, AND METHODS FOR AUTHENTICATING SERVICE PROVIDER COMMUNICATIONS

Non-Final OA §103§112
Filed
Dec 16, 2024
Examiner
KENNEDY, LESA M
Art Unit
2458
Tech Center
2400 — Computer Networks
Assignee
The Pnc Financial Services Group Inc.
OA Round
1 (Non-Final)
77%
Grant Probability
Favorable
1-2
OA Rounds
1y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 77% — above average
77%
Career Allowance Rate
160 granted / 208 resolved
+18.9% vs TC avg
Strong +24% interview lift
Without
With
+24.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
13 currently pending
Career history
226
Total Applications
across all art units

Statute-Specific Performance

§101
9.9%
-30.1% vs TC avg
§103
52.9%
+12.9% vs TC avg
§102
10.6%
-29.4% vs TC avg
§112
19.4%
-20.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 208 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims This office action is a response to an application filed on 12/16/2024, wherein claims 1-22 are presented for examination. Information Disclosure Statement The information disclosure statement (IDS) submitted on 12/16/2024 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Objections Claims are objected to because of the following informalities: Claim 2 recites “the unverified communication channel”. However, claim 1 recites “a first communication channel” and “an unverified originator” but does not recite “an unverified communication channel”. It appears that “the unverified communication channel” is intended to refer to the “first communication channel”. Claim 7 recites “the mobile computing device” but should read “the mobile communication device”. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 15-19 and 22 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention. Claim 15 recites “the service provider” which lacks antecedent basis. Claim 15 is therefore rendered indefinite. For examination purposes, claim 15 will be interpreted as depending from claim 14 which recites “a service provider device”. Claim 16 recites “the service provider” and “the special circumstance” which lack antecedent basis. Claim 16 is therefore rendered indefinite. For examination purposes, claim 16 will be interpreted as depending from claim 15 which recites “a special circumstance”. Claim 17 recites “the pre-defined risk mitigation action” which lacks antecedent basis. Claim 17 is therefore rendered indefinite. For examination purposes, claim 17 will be interpreted as depending from claim 16 which recites “a pre-defined risk mitigation action”. Claim 18 recites “the pre-defined risk mitigation action” and “the determined location” which lack antecedent basis. Claim 18 is therefore rendered indefinite. For examination purposes, claim 18 will be interpreted as depending from claim 17 which recites “… determining … a location …”. Claim 19 recites “the pre-defined risk mitigation action” which lacks antecedent basis. Claim 19 is therefore rendered indefinite. For examination purposes, claim 19 will be interpreted as depending from claim 16 which recites “a pre-defined risk mitigation action”. Claim 22 recites “The system of claim 19”, however claim 19 is directed to a method. Claim 22 is therefore rendered indefinite. For examination purposes, claim 22 with be interpreted as reciting “The system of claim 21”. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-4, 10-14 and 20-22 are rejected under 35 U.S.C. 103 as being unpatentable over Anzaldua (US 11,316,849) in view of Kwok et al. (US 2023/0362298), hereinafter Kwok. Regarding claim 1, Anzaldua discloses a method comprising: receiving, via a mobile communication device, a communication from an unverified originator via a first communication channel (Anzaldua, col 2, ln 7-20, 53-64: a customer’s device (mobile communication device) receives a call (communication/ first communication channel) from a CSR (unverified originator)); in response to receiving the communication, establishing, via the mobile communication device, a second, secure communication channel between the mobile communication device and a service provider server, wherein the second, secure communication channel is provided via an application stored in a memory of the mobile communication device and executed by a processor of the mobile communication device (Anzaldua, col 2, ln 65 – col 3, ln 9: customer logs into his/her account through an application (second secure communication channel) operating on the customer’s mobile device (mobile communication device) to communicate with an authentication server (service provider server)); receiving, via the mobile communication device, a first user input from a user of the mobile communication device, wherein the first user input comprises authentication information in response to the communication (Anzaldua, col 2, ln 21-41; col 4, ln 24-38: after the customer/second person logs into his/her account the second person inputs a one-time passcode (authentication information)); generating, via the mobile communication device, a unique authentication request comprising the authentication information (Anzaldua, col 4, ln 24-38: customer device generates a message (request) comprising the passcode); transmitting, via the mobile communication device, the unique authentication request to the service provider server via the second, secure communication channel (Anzaldua, col 4, ln 24-38: customer device sends the message (request) to the authentication server (service provider server)); receiving and outputting to the user of the mobile communication device, via the mobile communication device, an authentication response from the originator of the communication via the first communication channel (Anzaldua, col 4, ln 39-55: CSR’s computer receives the passcode; the CSR (originator) verbally mentions the passcode (authentication response) to the customer (user of the mobile communication device) over the call (first communication channel)); and determining whether the originator of the communication is a service provider associated with the user of the mobile communication device based on the authentication response (Anzaldua, col 4 ln 56 – col 5, ln 12: customer verifies whether the CSR (originator) is associated with his/her account (service provider) based on the passcode (authentication response)). Anzaldua does not explicitly disclose determining, via the mobile communication device. However, Kwok discloses determining, via the mobile communication device, whether the originator of the communication is a service provider associated with the user of the mobile communication device based on the authentication response (Kwok, [0051]: application installed on user device (mobile communication device) determines whether first authentication information and a received second authentication information (authentication response) match; [0050], [0085]: the returned second authentication information (authentication response) verifies the source of a telephone call (i.e., that originator is service provider)). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua and Kwok before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls in which the customer determines when passcodes match in order to authenticate a caller as taught by Anzaldua, to include enabling the customer’s mobile application to perform the passcode match determination as taught by Kwok. The motivation for doing so would have been to reduce the reliance on the customer’s manual judgement, thereby improving the security and reliability of determining whether the caller is authentic. Regarding claim 2, Anzaldua does not explicitly disclose wherein: determining whether the unverified originator of the communication is a service provider associated with the user of the mobile communication device based on the authentication response comprises determining, via the mobile communication device, that the unverified originator of the communication is the service provider; and the method further comprises, in response to determining that the unverified originator of the communication is the service provider, maintaining, via the mobile communication device, the communication by preserving the unverified communication channel. However, Kwok discloses wherein: determining whether the unverified originator of the communication is a service provider associated with the user of the mobile communication device based on the authentication response comprises determining, via the mobile communication device, that the unverified originator of the communication is the service provider (Kwok, [0051]: application installed on user device (mobile communication device) determines whether first authentication information and a received second authentication information (authentication response) match; [0050], [0085]: the returned second authentication information (authentication response) verifies the source of a telephone call (i.e., that the originator is service provider)); and the method further comprises, in response to determining that the unverified originator of the communication is the service provider, maintaining, via the mobile communication device, the communication by preserving the unverified communication channel (Kwok, [0052]: when there is a match (i.e., originator is the service provider), the user device connects the telephone call or provides an indication to the server device or representative’s device (i.e., communication is maintained); when there is a mismatch, the application ends the call). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua and Kwok before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls in which the customer determines when passcodes match in order to authenticate a caller as taught by Anzaldua, to include enabling the customer’s mobile application to perform the passcode match determination, and additionally maintain or end the call based on that determination as taught by Kwok. The motivation for doing so would have been to reduce the reliance on the customer’s manual judgement and prevent the original call continuing when the authentication fails, thereby improving security. Regarding claim 3, Anzaldua does not explicitly disclose wherein: determining whether the unverified originator of the communication is a service provider associated with the user of the mobile communication device based on the authentication response comprises determining, via the mobile communication device, that the originator of the communication is not the service provider; and the method further comprises, in response to determining that the unverified originator of the communication is not the service provider, performing, via the mobile communication device, a risk mitigation action. However, Kwok discloses wherein: determining whether the unverified originator of the communication is a service provider associated with the user of the mobile communication device based on the authentication response comprises determining, via the mobile communication device, that the originator of the communication is not the service provider (Kwok, [0051]: application installed on user device (mobile communication device) determines whether first authentication information and a received second authentication information (authentication response) match; [0050], [0085]: the returned second authentication information (authentication response) verifies the source of a telephone call (i.e., whether the originator is service provider); [0052]: determining that the first and second authentication information do not match); and the method further comprises, in response to determining that the unverified originator of the communication is not the service provider, performing, via the mobile communication device, a risk mitigation action (Kwok, [0052]: ending the call). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua and Kwok before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls in which the customer determines when passcodes match in order to authenticate a caller as taught by Anzaldua, to include enabling the customer’s mobile application to perform the passcode match determination, and additionally maintain or end the call based on that determination as taught by Kwok. The motivation for doing so would have been to reduce the reliance on the customer’s manual judgement and prevent the original call continuing when the authentication fails, thereby improving security. Regarding claim 4, Anzaldua does not explicitly disclose wherein the risk mitigation action comprises terminating, via the mobile communication device, the communication by terminating the first communication channel. However, Kwok discloses wherein the risk mitigation action comprises terminating, via the mobile communication device, the communication by terminating the first communication channel (Kwok, [0052]: ending the call). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua and Kwok before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls in which the customer determines when passcodes match in order to authenticate a caller as taught by Anzaldua, to include enabling the customer’s mobile application to perform the passcode match determination, and additionally maintain or end the call based on that determination as taught by Kwok. The motivation for doing so would have been to reduce the reliance on the customer’s manual judgement and prevent the original call continuing when the authentication fails, thereby improving security. Regarding claim 10, Anzaldua discloses wherein outputting the authentication response comprises playing the authentication response via a speaker of the mobile communication device (Anzaldua, col 6, ln 56 – col 5, ln 2: customer device (mobile communication device) audibly presents the passcode (authentication response) sent by the CSR’s computer). Regarding claim 11, Anzaldua discloses wherein outputting the authentication response comprises presenting the authentication response via a display of the mobile communication device (Anzaldua, col 6, ln 56 – col 5, ln 2: customer device (mobile communication device) displays the passcode (authentication response) sent by the CSR’s computer). Regarding claim 12, Anzaldua discloses wherein the authentication response comprises responsive authentication information, and wherein determining whether the originator of the communication is actually the service provider comprises determining whether the responsive authentication information in the authentication response corresponds to the authentication information in the unique authentication request (Anzaldua, col 4, ln 39 – col 5, ln 2: customer receives the passcode (authentication response/responsive authentication information) from the CSR and compares the password he/she entered (authentication information) with the passcode from the CSR (responsive authentication information) to determine if there is a match (i.e., originator is the service provider)). Anzaldua does not explicitly disclose via the mobile communication device. However, Kwok discloses wherein the authentication response comprises responsive authentication information, and wherein determining whether the originator of the communication is actually the service provider comprises determining, via the mobile communication device, whether the responsive authentication information in the authentication response corresponds to the authentication information in the unique authentication request (Kwok, [0051]: application installed on user device (mobile communication device) determines whether first authentication information and a received second authentication information (authentication response) match; [0050], [0085]: the returned second authentication information (authentication response) verifies the source of a telephone call (i.e., that originator is service provider)). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua and Kwok before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls in which the customer determines when passcodes match in order to authenticate a caller as taught by Anzaldua, to include enabling the customer’s mobile application to perform the passcode match determination as taught by Kwok. The motivation for doing so would have been to reduce the reliance on the customer’s manual judgement, thereby improving the security and reliability of determining whether the caller is authentic. Regarding claim 13, Anzaldua does not explicitly disclose wherein determining whether the originator of the communication is actually the service provider comprises autonomously determining, via the mobile communication device, whether the originator of the communication is actually the service provider. However, Kwok discloses wherein determining whether the originator of the communication is actually the service provider comprises autonomously determining, via the mobile communication device, whether the originator of the communication is actually the service provider (Kwok, [0051]: application installed on user device (mobile communication device) determines whether first authentication information and a received second authentication information (authentication response) match; [0050], [0085]: the returned second authentication information (authentication response) verifies the source of a telephone call (i.e., that originator is service provider)). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua and Kwok before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls in which the customer determines when passcodes match in order to authenticate a caller as taught by Anzaldua, to include enabling the customer’s mobile application to perform the passcode match determination as taught by Kwok. The motivation for doing so would have been to reduce the reliance on the customer’s manual judgement, thereby improving the security and reliability of determining whether the caller is authentic. Regarding claim 14, Anzaldua discloses a method comprising: initiating, via a service provider device, a communication with a mobile communication device via a first communication channel (Anzaldua, col 3, ln 35 – 67: CSR computer (service provider device) initiates a call (communication/first communication channel) with a customer device (mobile communication device)); receiving, via a service provider server, a unique authentication request provided by the mobile communication from the mobile communication device via a secure, second channel, wherein the unique authentication request comprises authentication information provided via a user input received by an application stored in a memory of the mobile communication device and executed by a processor of the mobile communication device (Anzaldua, col 2, ln 65 – col 3, ln 8: customer logs into his/her account through an application (second secure communication channel) operating on the customer’s mobile device (mobile communication device) to communicate with an authentication server (service provider server); col 4, ln 24-38: after the customer logs into his/her account, the customer inputs a passcode (authentication information); the customer device generates and sends a message (request) comprising the passcode (authentication information) and an account identifier to the authentication server (service provider server)); in response to the communication having been initiated by the service provider device, referencing, via the service provider device, the unique authentication request stored on the service provider server (Anzaldua, col 9, ln 37-42: CSR computer obtains a passcode from the authentication server that references the stored passcode and account identifier (i.e., the request); col 4, ln 39-55: after the customer mentions to the CST that he/she has entered the passcode in the customer device, the CSR requests and obtains the passcode from the authentication server); transmitting, via the service provider device, an authentication response to the mobile communication device comprising responsive authentication information based on the authentication information (Anzaldua, col 4, ln 39-55: CSR’s computer (service provider device) sends the passcode (authentication response/responsive authentication information) to the customer’s device); receiving, via the service provider device, a confirmation that the authentication information in unique authentication request corresponds to the responsive authentication information in the authentication response (Anzaldua, col 4, ln 56 – col 5, ln2: customer device sends a match condition message (confirmation) to the authentication server; col 5, ln 24-37: authentication server authenticates the CSR (service provider device) to access the account associated with the customer (i.e., CSR (service provider device) receives confirmation)). Anzaldua does not explicitly disclose maintaining, via the service provider device, the communication via the first communication channel based on the confirmation. However, Kwok discloses maintaining, via the service provider device, the communication via the first communication channel based on the confirmation (Kwok, [0083]: after the server device receives confirmation, the agent services the customer and the call ends only at the conclusion of the telephone call). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua and Kwok before him or her before the effective filing date of the claimed invention, to modify a method in which authentication operations occur while the CSR is on a call with the customer to determine whether the CSR is granted or denied access to the customer’s account as taught by Anzaldua, to include completing the connection to the agent/CSR based on confirmation, and then allowing the agent/CSR to service the customer as taught by Kwok. The motivation for doing so would have been to improve security by ensuring that the CSR and customer communication is maintained only after authentication is confirmed, thereby preventing sensitive customer service activity from continuing when authentication fails. Regarding claim 20, Anzaldua discloses further comprising: detecting, via the service provider server, unusual behavior associated with the mobile communication device, wherein the communication is initiated based on the detection of unusual behavior associated with the mobile communication device (Anzaldua, col 1, ln 19-40: CSR calls the customer to notify the customer of suspected credit card fraud). Regarding claim 21, Anzaldua discloses a system comprising: a service provider server (Anzaldua, Fig. 2: authentication server); and a mobile communication device comprising a processor and a memory configured to store an application that, when executed by the processor, causes the mobile communication device to (Anzaldua, Fig. 2: customer device; Fig. 4): receive a communication from an unverified originator via a first communication channel (Anzaldua, col 2, ln 7-20, 53-64: a customer’s device (mobile communication device) receives a call (communication/ first communication channel) from a CSR (unverified originator)); in response to receiving the communication, establish a second, secure communication channel with the service provider server (Anzaldua, col 2, ln 65 – col 3, ln 9: customer logs into his/her account through an application (second secure communication channel) operating on the customer’s mobile device (mobile communication device) to communicate with an authentication server (service provider server)); receive a first user input from a user of the mobile communication device, wherein the first user input comprises authentication information in response to the communication (Anzaldua, col 2, ln 21-41; col 4, ln 24-38: after the customer/second person logs into his/her account the second person inputs a one-time passcode (authentication information)); generate a unique authentication request comprising the authentication information (Anzaldua, col 4, ln 24-38: customer device generates a message (request) comprising the passcode); transmit the unique authentication request to the service provider server via the second, secure communication channel (Anzaldua, col 4, ln 24-38: customer device sends the message (request) to the authentication server (service provider server)); receive an authentication response from the originator of the communication via the first communication channel (Anzaldua, col 4, ln 39-55: CSR’s computer receives the passcode; the CSR (originator) verbally mentions the passcode (authentication response) to the customer over the call (first communication channel)). Anzaldua does not explicitly disclose determine whether the originator of the communication is a service provider associated with the user of the mobile communication device based on the authentication response. However, Kwok discloses determine whether the originator of the communication is a service provider associated with the user of the mobile communication device based on the authentication response (Kwok, [0051]: application installed on user device (mobile communication device) determines whether first authentication information and a received second authentication information (authentication response) match; [0050], [0085]: the returned second authentication information (authentication response) verifies the source of a telephone call (i.e., that the originator is a service provider)). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua and Kwok before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls in which the customer determines when passcodes match in order to authenticate a caller as taught by Anzaldua, to include enabling the customer’s mobile application to perform the passcode match determination as taught by Kwok. The motivation for doing so would have been to reduce the reliance on the customer’s manual judgement, thereby improving the security and reliability of determining whether the caller is authentic. Regarding claim 22, Anzaldua does not explicitly disclose wherein, when executed by the processor, the application further causes the mobile communication device to: determine that the unverified originator of the communication is not the service provider; and perform a risk mitigation action based on the determination that the unverified originator of the communication is not the service provider. However, Kwok discloses wherein, when executed by the processor, the application further causes the mobile communication device to: determine that the unverified originator of the communication is not the service provider (Kwok, [0051]-[0052]: the application stores a copy of the first authentication information and determines when the first authentication information and the returned second authentication do not match); and perform a risk mitigation action based on the determination that the unverified originator of the communication is not the service provider (Kwok, [0052]: the application ends the call). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua and Kwok before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls in which the customer determines when passcodes match in order to authenticate a caller as taught by Anzaldua, to include enabling the customer’s mobile application to perform the passcode match determination, and additionally maintain or end the call based on that determination as taught by Kwok. The motivation for doing so would have been to reduce the reliance on the customer’s manual judgement and prevent the original call continuing when the authentication fails, thereby improving security. Claims 5-8 are rejected under 35 U.S.C. 103 as being unpatentable over Anzaldua in view of Kwok, further in view of Silva (US 2012/0015634). Regarding claim 5, Anzaldua and Kwok do not explicitly disclose wherein the risk mitigation action comprises recording, via the mobile communication device, the communication in the memory of the mobile communication device. However, Silva discloses wherein the risk mitigation action comprises recording, via the mobile communication device, the communication in the memory of the mobile communication device (Silva, [0009], [0019]: call-recording application on wireless phone records communications). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua, Kwok and Silva before him or her before the effective filing date of the claimed invention, to modify a system in which a mobile device detects failed authentication of a service provider call as taught by Anzaldua and Kwok, to include a mobile device recording functionality for capturing call information as taught by Silva. The motivation for doing so would have been to allow the mobile device to preserve a record of unauthenticated calls for later review or reporting. Regarding claim 6, Anzaldua and Kwok do not explicitly disclose wherein the risk mitigation action comprises recording, via the mobile communication device, information associated with the communication in a memory of the mobile communication device, wherein the information associated with the communication comprises at least one of a name of originator, a date, a time, a location, a phone number, and an IP address, or combinations thereof. However, Silva discloses wherein the risk mitigation action comprises recording, via the mobile communication device, information associated with the communication in a memory of the mobile communication device (Silva, [0009], [0019]), wherein the information associated with the communication comprises at least one of a name of originator, a date, a time, a location, a phone number, and an IP address, or combinations thereof (Silva, [0020]: date, time caller number, GPS location). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua, Kwok and Silva before him or her before the effective filing date of the claimed invention, to modify a system in which a mobile device detects failed authentication of a service provider call as taught by Anzaldua and Kwok, to include utilizing the mobile device for capturing call information as taught by Silva. The motivation for doing so would have been to allow the mobile device to preserve a record of unauthenticated communications for later review or reporting. Regarding claim 7, Anzaldua and Kwok do not explicitly disclose wherein the risk mitigation action further comprises reporting, via the mobile communication device, by causing the mobile computing device to transmit the information associated with the communication to a third party system via a communication circuit of the mobile computing device. However, Silva discloses wherein the risk mitigation action further comprises reporting, via the mobile communication device, by causing the mobile computing device to transmit the information associated with the communication to a third party system via a communication circuit of the mobile computing device (Silva, [0010]: audio forwarded to a third party database). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua, Kwok and Silva before him or her before the effective filing date of the claimed invention, to modify a system in which a mobile device detects failed authentication of a service provider call as taught by Anzaldua and Kwok, to include utilizing the mobile device for capturing call information and transferring the audio/data files to a third party database as taught by Silva. The motivation for doing so would have been to allow the mobile device to report information associated with unauthenticated communications for later investigation. Regarding claim 8, Anzaldua and Kwok do not explicitly disclose wherein the third party system is associated with at least one of the service provider, a police unit, a government agency, an information technology management firm, and a telecommunications provider, or combinations thereof. However, Silva discloses wherein the third party system is associated with at least one of the service provider, a police unit, a government agency, an information technology management firm, and a telecommunications provider, or combinations thereof (Silva, [0008]: undercover law enforcement personnel (i.e., police unit or government agency)). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua, Kwok and Silva before him or her before the effective filing date of the claimed invention, to modify a system in which a mobile device detects failed authentication of a service provider call as taught by Anzaldua and Kwok, to include utilizing the mobile device for capturing call information and transferring the audio/data files to a third party database as taught by Silva. The motivation for doing so would have been to allow the mobile device to report information associated with unauthenticated communications for later investigation. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Anzaldua in view of Kwok and Silva, further in view of Edwards et al. (US 2014/0128047), hereinafter Edwards. Regarding claim 9, Anzaldua, Kwok and Silva do not explicitly disclose wherein the risk mitigation action further comprises preventing, via the mobile communication device, the unverified originator from initiating another communication by storing the information associated with the communication on a black list stored in the memory of the mobile communication device, wherein the mobile communication device is configured to autonomously reject communications comprising information on the black list. However, Edwards discloses wherein the risk mitigation action further comprises preventing, via the mobile communication device, the unverified originator from initiating another communication by storing the information associated with the communication on a black list stored in the memory of the mobile communication device, wherein the mobile communication device is configured to autonomously reject communications comprising information on the black list (Edwards, [0084]: a device’s database is updated; [0150]-[0151]: the mobile device includes a local blocking database; if a communication is from a number in a blacklisted category, the blocking application can block the communication). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua, Kwok, Silva and Edwards before him or her before the effective filing date of the claimed invention, to modify a system in which a mobile device detects failed authentication of a service provider call as taught by Anzaldua, Kwok and Silva, to include utilizing a mobile device black list and call blocking functionality as taught by Edwards. The motivation for doing so would have been to reduce future exposure to the same suspected fraudulent caller. Claims 15-19 are rejected under 35 U.S.C. 103 as being unpatentable over Anzaldua in view of Kwok, further in view of Lindsay (US 2018/0247483). Regarding claim 15, Anzaldua discloses authentication information from the mobile communication device via the secure, second channel (Anzaldua, col 2, ln 65 – col 3, ln 9: customer logs into his/her account through an application (second secure communication channel) operating on the customer’s mobile device (mobile communication device) to communicate with an authentication server (service provider server); col 2, ln 21-41; col 4, ln 24-38: after the customer/second person logs into his/her account the second person inputs a one-time passcode (authentication information)). Anzaldua does not explicitly disclose further comprising: prior to the communication having been initiated by the service provider device, receiving and storing, via the service provider server, pre-defined authentication information from the mobile communication device via the secure, second channel, wherein the pre-defined authentication information communicates to a user of the service provider device that a user of the mobile communication device is in a special circumstance; determining, via the service provider device, that the authentication information in the unique authentication request corresponds to the pre-defined authentication information stored on the service provider server; and determining, via the service provider device, that the user of the mobile communication device is in the special circumstance based on the correspondence between the authentication information in the unique authentication request and the pre-defined authentication information stored on the service provider server. However, Kwok discloses further comprising: prior to the communication having been initiated by the service provider device, receiving and storing, via the service provider server, pre-defined authentication information from the mobile communication device (Kwok, Fig. 3, steps 304-310). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua and Kwok before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls in which the customer determines when passcodes match in order to authenticate a caller as taught by Anzaldua, to include pre-call storage and device/application side verification as taught by Kwok. The motivation for doing so would have been to automate and strengthen the passcode comparison process and reduce the reliance on the customer’s manual judgement, thereby improving the security and reliability of determining whether the caller is authentic. Furthermore, the combination of Anzaldua and Kwok does not explicitly disclose wherein the pre-defined authentication information communicates to a user of the service provider device that a user of the mobile communication device is in a special circumstance; determining, via the service provider device, that the authentication information in the unique authentication request corresponds to the pre-defined authentication information stored on the service provider server; and determining, via the service provider device, that the user of the mobile communication device is in the special circumstance based on the correspondence between the authentication information in the unique authentication request and the pre-defined authentication information stored on the service provider server. However, Lindsay discloses receiving and storing, via the service provider server, pre-defined authentication information from the mobile communication device via the second channel, wherein the pre-defined authentication information communicates to a user of the service provider device that a user of the mobile communication device is in a special circumstance (Lindsay, [0037]: the establishment of secondary passwords and rules (pre-defined authentication information) are preconfigured; [0017]: the secondary password is used when under duress or in emergencies (special circumstance)); determining, via the service provider device, that the authentication information in the unique authentication request corresponds to the pre-defined authentication information stored on the service provider server (Lindsay, [0335]: for example, after the user enters the user ID, the system (service provider device) determines that the login information (authentication information in the request) is for an insecure setting (i.e., corresponds to the pre-defined authentication information)); and determining, via the service provider device, that the user of the mobile communication device is in the special circumstance based on the correspondence between the authentication information in the unique authentication request and the pre-defined authentication information stored on the service provider server (Lindsay, [0335]: determining the user is in an insecure setting (special circumstance)). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua, Kwok and Lindsay before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls as taught by Anzaldua and Kwok, to include utilizing user preconfigured secondary passwords, hidden actions or covert cues as taught by Lindsay in order to indicate duress or an insecure setting. The motivation for doing so would have been to inform the service provider when the customer is in a special circumstance, thereby improving fraud prevention and customer protection during service provider calls. Regarding claim 16, Anzaldua and Kwok do not explicitly disclose further comprising: performing, via the service provider device, a pre-defined risk mitigation action based on the determination that the special circumstance applies to the communication. However, Lindsay discloses further comprising: performing, via the service provider device, a pre-defined risk mitigation action based on the determination that the special circumstance applies to the communication (Lindsay, [0246]: system (service provider device) determines when hidden/covert actions correspond to preconfigured rules indicating an emergency/duress (special circumstance), and performs preconfigured actions specified by the user such as notification of authorities, deactivation of account, etc. (pre-defined risk mitigation actions)). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua, Kwok and Lindsay before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls as taught by Anzaldua and Kwok, to include utilizing user preconfigured secondary passwords, hidden actions or covert cues as taught by Lindsay in order to indicate duress or an insecure setting. The motivation for doing so would have been to inform the service provider when the customer is in a special circumstance, thereby improving fraud prevention and customer protection during service provider calls. Regarding claim 17, Anzaldua and Kwok do not explicitly disclose wherein: performing the pre-defined risk mitigation action comprises determining, via the service provider device, a location of the mobile communication device based on geolocation data associated with the unique authentication request and/or the communication. However, Lindsay discloses wherein: performing the pre-defined risk mitigation action comprises determining, via the service provider device, a location of the mobile communication device based on geolocation data associated with the unique authentication request and/or the communication (Lindsay, [0193]: Central/security system (service provider device) determines risk based on user status/location information. If there is elevated risk, the system retrieves the rules for elevated risk (pre-defined risk mitigation action)). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua, Kwok and Lindsay before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls as taught by Anzaldua and Kwok, to include utilizing user preconfigured secondary passwords, hidden actions or covert cues in order to indicate duress or an insecure setting, along with location sensitive security rules as taught by Lindsay. The motivation for doing so would have been to ensure that when a special circumstance/risk condition is detected, the service provider can determine the customer’s mobile device location and apply the appropriate predefined protective action, thereby improving customer protection. Regarding claim 18, Anzaldua and Kwok do not explicitly disclose wherein: the pre-defined risk mitigation action comprises deploying a police officer or medical assistance to the determined location of the mobile communication device. However, Lindsay discloses wherein: the pre-defined risk mitigation action comprises deploying a police officer or medical assistance to the determined location of the mobile communication device (Lindsay, [0020]: customized rules (pre-defined risk mitigation actions) are established to configure the system’s (service provider device) response to primary and secondary passwords; [0344]: e.g., an emergency alert is initiated resulting in action by local authorities). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua, Kwok and Lindsay before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls as taught by Anzaldua and Kwok, to include utilizing user preconfigured security rules to trigger emergency alerts and action by local authority as taught by Lindsay. The motivation for doing so would have been to allow the service provider system to respond to a customer’s covert duress signal, thereby improving customer safety. Regarding claim 19, Anzaldua and Kwok do not explicitly disclose wherein the pre-defined risk mitigation action comprises locking an account of the user of the mobile communication device hosted by the service provider or denying a transaction request initiated by the mobile communication device. However, Lindsay discloses wherein the pre-defined risk mitigation action comprises locking an account of the user of the mobile communication device hosted by the service provider or denying a transaction request initiated by the mobile communication device (Lindsay, [0020]: customized rules are established to configure the system’s (service provider) response to a primary or secondary passwords; [0343]: e.g., an account is temporarily inactivated (locked) until the user contacts a bank official to confirm that the account has not been compromised). It would have been obvious to one of ordinary skill in the art, having the teachings of Anzaldua, Kwok and Lindsay before him or her before the effective filing date of the claimed invention, to modify a method for authenticating service provider telephone calls as taught by Anzaldua and Kwok, to include utilizing account locking rules as taught by Lindsay. The motivation for doing so would have been to allow the service provider system to mitigate risk by temporarily locking the customer account when the authentication process indicates compromise. Related Art The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure: Gadwale (US 2021/0084034) discloses a service provider/call center authentication system using a first voice communication channel and a second trusted/secure application channel between the service provider application service and the client device (Gadwale, [0015], [0032], [0036]-[0038]). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to LESA M KENNEDY whose telephone number is (571)431-0704. The examiner can normally be reached Monday-Wednesday 9:30 am - 5:30 pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Umar Cheema can be reached on (571) 270-3037. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. The examiner also requests, in response to this Office Action, support be shown for language added to any original claims on amendment and any new claims. That is, indicate support for newly added claim language by specifically pointing to page(s) and line no(s) in the specification and/or drawing figure(s). This will assist the examiner in prosecuting the application. /LESA M KENNEDY/Primary Examiner, Art Unit 2458
Read full office action

Prosecution Timeline

Dec 16, 2024
Application Filed
Jul 08, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748830
HAND-BASED BIOMETRIC AUTHENTICATION
2y 5m to grant Granted Sep 29, 2026
Patent 12744679
MANAGING UNIQUE SECRETS IN DISTRIBUTED SYSTEMS
4y 0m to grant Granted Sep 22, 2026
Patent 12743513
System and Method for Ransomware Scan Using Incremental Data Blocks
2y 6m to grant Granted Sep 22, 2026
Patent 12706963
REDUCING IMS NETWORK CONGESTION WHEN A NODE IN THE IMS NETWORK BECOMES UNAVAILABLE
2y 2m to grant Granted Aug 11, 2026
Patent 12676900
IMS ROUTING BASED ON SUBSCRIBER TYPE
2y 2m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
77%
Grant Probability
99%
With Interview (+24.4%)
3y 0m (~1y 2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 208 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month