Prosecution Insights
Last updated: October 02, 2026
Application No. 18/990,282

ADAPTIVE SECURITY AUTHENTICATION

Final Rejection §101§103§112
Filed
Dec 20, 2024
Examiner
KHATRI, NILESH B
Art Unit
3699
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
PayPal Inc.
OA Round
2 (Final)
62%
Grant Probability
Moderate
3-4
OA Rounds
1y 4m
Est. Remaining
86%
With Interview

Examiner Intelligence

Grants 62% of resolved cases
62%
Career Allowance Rate
116 granted / 188 resolved
+9.7% vs TC avg
Strong +24% interview lift
Without
With
+24.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
16 currently pending
Career history
213
Total Applications
across all art units

Statute-Specific Performance

§101
30.7%
-9.3% vs TC avg
§103
41.2%
+1.2% vs TC avg
§102
5.4%
-34.6% vs TC avg
§112
17.4%
-22.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 188 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims This communication is responsive to the submission filed May 26, 2026. Claims 1, 5, and 8 are amended. Claims 1-20 are pending. Information Disclosure Statement The information disclosure statement(s) (IDS) submitted on March 16, 2026, is/are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement(s) has/have been considered by the examiner. Response to Remarks 35 U.S.C. § 101 Applicant contends that the claims are directed towards patent eligible subject matter. First, Applicant contends that the claims recite a practical application of the abstract ideas as the claim improves the function of a computer or another technology. Examiner respectfully disagrees. Examiners evaluate integration into a practical application by: (1) identifying whether there are any additional elements recited in the claim beyond the judicial exception(s); and (2) evaluating those additional elements individually and in combination to determine whether they integrate the exception into a practical application. See MPEP 2106.04(d)(II). Here, the claim limitations Applicant cites to as reciting a practical application of the abstract ideas are part of the abstract ideas themselves rather than additional elements that could serve to recite a practical application of the abstract ideas. 35 U.S.C. § 102 Applicant’s arguments with respect to claim(s) 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. For example, calculating a risk score and confidence scores for various authentication factors to initiate to complete a transaction are Certain Methods of Organizing Human Activities as they recite commercial interactions, i.e., a transaction process, and managing relationships between entities, i.e., selecting which customer authentication method to use. Therefore, such subject matter cannot serve as a basis to recite a practical application of the abstract ideas. While the claims do recite the additional elements of the various machine learning models, the various machine learning models, as recited, are used to perform the identified abstract ideas. Therefore, such additional elements amount to an instruction to apply the abstract ideas using computers. Applicant also cites to Ex Parte Desjardins as being analogous to the pending claims. Examiner respectfully disagrees as the claim in Desjardins recited additional elements that served as the basis for reciting a practical application. Here, the claims fail to recite such claim limitations. Therefore, Applicant’s contention that the claims recite a practical application of the abstract ideas is unpersuasive. Applicant next contends that the claims recite significantly more than the abstract ideas. Examiner respectfully disagrees. In the Step 2B analysis, Examiners carry over their identifications of the additional elements in the claim from Step 2A Prong Two and carry over their conclusions from Step 2A Prong Two. See MPEP 2106.05(II). As discussed above, the claim recites the additional elements of the various machine learning models and the conclusion from Step 2A Prong Two for these additional elements is that they are used to perform the abstract idea. Therefore, they also fail to recite significantly more than the abstract idea. Accordingly, this ground of rejection is maintained. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Per Claims 1-4: Independent claim 1 recites “predicting, with a second machine learning model using the transaction data, a second conversion score characterizing a probability of the online transaction being completed with each of a plurality of security authentication flows”. It is unclear whether the second machine learning model recited in this limitation is the same as or different from the second machine learning model previously recited in the claim. Independent claim 1 also recites “the second conversion score of each of the plurality of security authentication flows being based on the first conversion scores of a combination of one or more authentication factors of the plurality of authentication factors” and “the selected one of the plurality of security authentication flows comprising a corresponding combination of one or more authentication factors presented to a user deice for authentication”. Under the broadest reasonable interpretation, it is unclear how there can be a combination of one authentication factor. Rather, a combination implies that there are at least two or more authentication factors. Therefore, it is unclear whether the claim requires only one authentication factor or a combination of two or more authentication factors. Claims 2-4 are rejected by reason of their dependency from claim 1. Per Claims 5-7: Independent claim 5 recites “determining, using the at least one machine learning model, a conversion score for a combination of one or more authentication factors for each of the one or more potential security authentication procedures being completed based on the transaction data”, “evaluating, using the at least one machine learning model, the one or more potential security authentication procedures based on the risk score and the conversion scores for the respective combination of one or more authentication factors” and “presenting the corresponding combination of one or more authentication factors to a user device associated with the online transaction”. Under the broadest reasonable interpretation, it is unclear how there can be a combination of one authentication factor. Rather, a combination implies that there are at least two or more authentication factors. Therefore, it is unclear whether the claim requires only one authentication factor or a combination of two or more authentication factors. Claims 6-7 are rejected by reason of their dependency from claim 5. Per Claims 8-20: Independent claim 8 recites “selecting, based on the assessment, one of a plurality of security authentication flows having a combination of one or more authentication factors predicted to have a highest probability of the online transaction being completed; and requesting the combination of one or more authentication factors from a user device”. Under the broadest reasonable interpretation, it is unclear how there can be a combination of one authentication factor. Rather, a combination implies that there are at least two or more authentication factors. Therefore, it is unclear whether the claim requires only one authentication factor or a combination of two or more authentication factors. Claims 9-20 are rejected by reason of their dependency from claim 8. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to abstract ideas without significantly more. There are two criteria for subject matter eligibility. The first is that the claimed invention must be to one of the four statutory categories, i.e., a process, machine, manufacture, or composition of matter. See MPEP 2106(I). Second, the claimed invention also must qualify as patent-eligible subject matter, i.e., the claim must not be directed to a judicial exception unless the claim as a whole includes additional limitations amounting to significantly more than the exception. See MPEP 2106(I). Here, claims 1-4 are directed towards a machine, claims 5-7 are directed towards a manufacture, and claims 8-20 are directed towards a process. Therefore, the analysis proceeds to determine whether the claims recite abstract ideas. Per Claim 1: Claim 1, as a whole, is directed towards the abstract idea of determining an authentication method to use based on transaction characteristics. In particular, the claim recites detecting a pending authentication for a transaction. The system predicts, based on the transaction data, a risk of the transaction being fraudulent. The claim predicts, using the transaction data, a first conversion score representing a probability of the transaction being completed with respect to multiple authentication factors. The system also predicts, based on the transaction data, a second conversion score of the transaction being completed using each of a plurality of authentication methods. The second conversion score is based on a combination of authentication factors. The system then predicts, based on the risk and the probability, a recommendation for each of the authentication methods. The system then selects an authentication method based on the recommendations and initiates the selected authentication method. The selected authentication method corresponds to a combination of authentication factors presented to a user. Further, the models used to make the prediction are based on historical data. In other words, the claim recites both Mental Processes as well as Certain Methods of Organizing Human Activities recognized as reciting abstract ideas. More specifically, the following underlined claim elements recite abstract ideas while the non-underlined claim elements recite additional elements according to MPEP 2106.04(a). a processor; and a non-transitory computer-readable medium having stored thereon instructions that are executable by the processor to cause the system to perform operations comprising: detecting a pending security authentication requirement for an online transaction; predicting, with a first machine learning model using transaction data associated with the online transaction, a risk score characterizing a probability of the online transaction being fraudulent; predicting, with a second machine learning model using the transaction data, a first conversion score characterizing a probability of the online transaction being completed with respect to each of a plurality of authentication factors; predicting, with a second machine learning model using the transaction data, a second conversion score characterizing a probability of the online transaction being completed with each of a plurality of security authentication flows, the second conversion score of each of the plurality of security authentication flows being based on the first conversion scores of a combination of one or more authentication factors of the plurality of authentication factors; predicting, with a third machine learning model configured to adjust the second conversion scores based on the risk score, a recommendation score for each of the plurality of security authentication flows; selecting, based on the recommendation scores, one of the plurality of security authentication flows; and initiating the selected one of the plurality of security authentication flows to continue the online transaction, the selected one of the plurality of security authentication flows comprising a corresponding combination of one or more authentication factors presented to a user device for authentication, wherein each of the first machine learning model, the second machine learning model, and the third machine learning model is trained on historical transaction data to predict a respective score based on the online transaction. Because the claim recites abstract ideas, the analysis proceeds to determine whether the claim recites additional elements that recite a practical application of the abstract ideas. According to MPEP 2106.04(d), additional elements that recite an instruction to apply the abstract ideas using a computer, that recite insignificant extra-solution activities, or that generally link the use of the abstract ideas to a particular technological environment or field of use are not indicative of a practical application. Here, the claim recites the additional elements of a processor, a non-transitory computer-readable medium, online transactions, and machine learning models. However, these additional elements are tools used to implement the abstract ideas. In other words, they amount to an instruction to apply the abstract ideas using computers. Therefore, the claim as a whole fails to recite a practical application of the abstract ideas. The analysis then proceeds to determine whether the additional elements, when considered individually and in combination, recite significantly more than the abstract ideas. According to MPEP 2106.05, additional elements that recite an instruction to apply the abstract ideas using a computer, that recite insignificant extra-solution activities, that generally link the use of the abstract ideas to a particular technological environment or field of use, or that recite well-understood, routine, and conventional activities are not indicative of reciting significantly more than the abstract ideas. Claim elements previously considered to recite insignificant extra-solution activities are reevaluated at this step to determine whether they recite well-understood, routine, and conventional activities. Such findings must be supported by the evidentiary requirements set forth in the Berkheimer Memo. Here, the claim recites the additional elements of a processor, a non-transitory computer-readable medium, online transactions, and machine learning models. However, these additional elements are tools used to implement the abstract ideas. In other words, they amount to an instruction to apply the abstract ideas using computers. Therefore, the additional claim elements, when considered individually and in combination, fail to recite significantly more than the abstract ideas. Accordingly, claim 1 is rejected as being directed towards patent ineligible subject matter. Per Claim 5: Claim 5, as a whole, is directed towards the abstract idea of determining an authentication method to use based on transaction characteristics. In particular, the claim recites identifying a transaction requiring a security authentication. The claim then selects one potential security authentication procedure based on transaction data. The claim determines, based on the transaction data, a risk of the transaction being fraudulent. The system also predicts, based on the transaction data, a probability of the transaction being completed using each of a plurality of authentication methods. The claim then determines, based on the risk and the probability, a recommendation for each of the authentication methods. The system then selects an authentication method based on the recommendations and initiates the selected authentication method. In other words, the claim recites Certain Methods of Organizing Human Activities recognized as reciting abstract ideas. More specifically, the following underlined claim elements recite abstract ideas while the non-underlined claim elements recite additional elements according to MPEP 2106.04(a). identifying an online transaction requiring a security authentication; selecting one or more potential security authentication procedures based on transaction data corresponding to the online transaction; determining, using at least one machine learning model, a risk score of the online transaction being fraudulent based on the transaction data; determining, using the at least one machine learning model, a conversion score for a combination of one or more authentication factors for each of the one or more potential security authentication procedures being completed based on the transaction data; evaluating, using the at least one machine learning model, the one or more potential security authentication procedures based on the risk score and the conversion scores for the respective combination of one or more authentication factors; selecting a security authentication procedure from the one or more potential security authentication procedures based on the evaluating; and using the selected security authentication procedure for the online transaction by presenting the corresponding combination of one or more authentication factors to a user device associated with the online transaction. Here, the claim recites the additional elements of an online transaction and machine learning models. However, these additional elements are used as tools to perform the abstract idea. In other words, the additional elements amount to an instruction to perform the abstract ideas using computers. Therefore, the claim fails to recite a practical application of the abstract ideas or significantly more than the abstract ideas. Accordingly, claim 5 is rejected as being directed towards patent ineligible subject matter. Per Claim 8: Claim 8, as a whole, is directed towards the abstract idea of determining an authentication method to use based on transaction characteristics. In particular, the claim recites receiving transaction data for a transaction having a pending security authentication requirement. The claim determines, based on the transaction data, a risk of the transaction being fraudulent. The claim also calculates, based on the transaction data, a probability of the transaction being completed using each of a plurality of authentication methods. The claim then assesses, based on the risk and the completion probability, a probability for each of the authentication methods. The claim selects, based on the assessment, a security authentication flow having a combination of authentication factors predicted to have the highest probability of the transaction being completed. The claim then requests, based on the assessing, a combination of authentication factors. In other words, the claim recites Certain Methods of Organizing Human Activities recognized as reciting abstract ideas. More specifically, the following underlined claim elements recite abstract ideas while the non-underlined claim elements recite additional elements according to MPEP 2106.04(a). receiving transaction data corresponding to an online transaction having a pending security authentication requirement for one or more authentication factors to process the online transaction; determining, from the transaction data, a risk score corresponding to a probability of the online transaction being fraudulent; calculating, using the transaction data, a conversion score corresponding to a probability of the online transaction being completed with respect to the one or more authentication factors; assessing combinations of the one or more authentication factors for the security authentication requirement based on applying the risk score and the conversion score to determine probabilities of the online transaction being completed with the combinations of the one or more authentication factors; selecting, based on the assessment, one of a plurality of security authentication flows having a combination of one or more authentication factors predicted to have a highest probability of the online transaction being completed; and requesting the combination of one or more authentication factors from a user device, selected based on the assessing, to satisfy the security authentication requirement for the online transaction. Here, the claim recites the additional elements of an online transaction and a user device. However, these additional elements are used to implement the abstract ideas. In other words, they amount to an instruction to apply the abstract idea using computers. Therefore, the claim fails to recite a practical application of the abstract ideas or significantly more than the abstract ideas. Accordingly, claim 8 is rejected as being directed towards patent ineligible subject matter. Per Claims 2-4, 5-7, and 9-20: Claims 2-4, 5-7, and 9-20 have also been analyzed for subject matter eligibility. However, these claims also fail to recite patent eligible subject matter for the following reasons: Claim 2 recites the abstract idea of using an acceptable level of chargeback rates and transaction abandonments to predict the scores, which is a Certain Method of Organizing Human Activities. Claim 3 recites the abstract idea of using an authentication preference when selecting a security authentication method, which is a Certain Method of Organizing Human Activities. Claim 4 recites the abstract idea of applying heuristics to eliminate a security authentication method, which is a Certain Method of Organizing Human Activities. Claim 6 recites the abstract idea of selecting the authentication method based on location, which is a Certain Method of Organizing Human Activities. Claim 7 recites the abstract idea of identifying exemptions to location-based authentication requirements, which is a Certain Method of Organizing Human Activities. Claim 9 recites the abstract idea that determining the risk score is based on detecting fraudulent transaction probabilities, which is a Certain Method of Human Activities. Claim 10 recites the abstract idea of outputting the risk score based on chargebacks, which is a Certain Method of Organizing Human Activities. Claim 11 recites the abstract idea of determining transaction completion probabilities, which is a Certain Method of Organizing Human Activities. Claim 12 recites the abstract idea of outputting a conversion score for the authentication methods, which is a Certain Method of Organizing Human Activities. Claim 13 recites the abstract idea of outputting a conversion score for the authentication methods, which is a Certain Method of Organizing Human Activities. Claim 14 recites the abstract idea of transforming the transaction data to calculate a conversion score for each of the authentication methods, which is a Certain Method of Organizing Human Activities. Claim 15 recites the abstract idea of selecting a combination of authentication methods with a higher security than another combination of authentication methods, which is a Certain Method of Organizing Human Activities. Claim 16 recites the abstract idea of selecting a combination of authentication factors having a higher conversion score than another combination of authentication factors, which is a Certain Method of Organizing Human Activities. Claim 17 recites the abstract idea of applying a heuristic to filter out combinations of authentication factors, which is a Certain Method of Organizing Human Activities. Claim 18 recites the abstract idea of filtering out combinations of authentication factors based on location, which is a Certain Method of Organizing Human Activities. Claim 19 recites the abstract idea of filtering out combinations of authentication factors based on an acceptable level of chargeback rates or transaction abandonment, which is a Certain Method of Organizing Human Activities. Claim 20 recites using a machine learning model to calculate the risk score, the conversion store, and assessing the combination of factors. However, the additional element of the machine learning model fails to recite a practical application of the abstract ideas or significantly more than the abstract ideas because it amounts to an instruction to apply the abstract ideas using computers. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 1-3, 5-14, 16, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Patent Pub. No. 2022/0327504 to Koren et al. in view of U.S. Patent Pub. No. 2020/0162515 to Dubinsky et al. Per Claim 1: Koren discloses: A system comprising: a processor; and a non-transitory computer-readable medium having stored thereon instructions that are executable by the processor to cause the system to perform operations comprising: (see Koren at ¶ 9: The system comprises at least one processor operatively connected to a memory) detecting a pending security authentication requirement for an online transaction; (see Koren at ¶ 40: In response to a transaction trigger by a merchant system and/or online processing system, the intelligent routing system 110 is configured to analyze the circumstances for the transaction.) predicting, with a first machine learning model using transaction data associated with the online transaction, a risk score characterizing a probability of the online transaction being fraudulent; (see Koren at ¶ 43: In another example, the system 110 can include neural networks that are configured to identify fraudulent or improper transactions as outlier transactions, so that transactions not flagged as outliers can be expedited with confidence. See also ¶ 49: For example, payment information can be analyzed by machine learning models to determine if the information matches fraudulent classifications. If the analysis determines that the transaction is invalid, fraud processes can be triggered (e.g., at 208). In some examples, fraud processing can include updating machine learning models based on collected activity or indicators.) predicting, with a second machine learning model using the transaction data, a second conversion score characterizing a probability of the online transaction being completed with each of a plurality of security authentication flows; (see Koren at ¶ 70: In some embodiments, the physical device being used by a purchaser can affect the likelihood of success of a transaction. In one example, the screen size of a mobile device can limit the user's ability to correctly respond to a CAPTCHA and/or authentication requests. In another example, a device may not display the authentication check correctly, which would result in a failed valid transaction. Where the system determines that the user is not likely to complete the request successfully (e.g., based on their device), the system can re-route to avoid the enhanced security or recommend a different payment modality (e.g., PAYPAL versus credit card) to avoid the issue entirely. See also ¶ 75: In further example, the model accepts as input device data, transactions data, historical user data, statistical behavioral data and generates an output that includes a probability score of cooperation per of each type of challenge. With the probability score output the system can evaluate candidate routes and select the option that achieves the highest likelihood of success given the prediction of where the user will comply or succeeds at security challenges.) predicting, with a third machine learning model configured to adjust the second conversion scores based on the risk score, a recommendation score for each of the plurality of security authentication flows; (see Koren at ¶ 84: According to various embodiments, the authentication decision strategy can be determined by an intelligent routing system and/or processing engines instantiated by the intelligent routing system. For example, the authentication decision strategy can include analysis of a risk score produced by risk engine, user behavior analysis by a user behavior cooperation engine, among other options. For example, the authentication decision strategy can include evaluation of processing routes imposed or restricted by regulatory requirements. A regulation compliance engine can evaluate potential routes and limit options based on applicable regulations. The filtered set of options can be evaluated as part of the authentication decision strategy at 2004.) selecting, based on the recommendation scores, one of the plurality of security authentication flows; and (see Koren at ¶ 75: With the probability score output the system can evaluate candidate routes and select the option that achieves the highest likelihood of success given the prediction of where the user will comply or succeeds at security challenges.) initiating the selected one of the plurality of security authentication flows to continue the online transaction. (see Koren at ¶ 86: Where authentication is recommended at 2008 YES, an authentication request can be made at 2010. In some examples, the purchaser may be presented with an SMS code that must be entered to complete a transaction. In other embodiments, authentication can include a challenge response protocol, username and password, biometric authentication, or other authentication information.) wherein each of the first machine learning model, the second machine learning model, and the third machine learning model is trained on historical transaction data to predict a respective score based on the online transaction. (see Koren at ¶ 88: Additional processing may be executed upon a failed transaction, which includes, for example, updating training of machine learning models used in the routing determination, updating histogram analysis of transaction and execution data, among other options.) However, Koren fails to disclose but Dubinsky, an analogous art of authentication, discloses: predicting, with a second machine learning model using the transaction data, a first conversion score characterizing a probability of the online transaction being completed with respect to each of a plurality of authentication factors; (see Dubinsky at ¶ 116: System 10 may calculate and attribute a risk score to at least one authentication factor and/or authentication scheme according to the stored data. For example, system 10 may calculate a percentage of successful fraudulent attempts of a specific authentication factor (e.g., password-based authentication) from an overall number of authentication attempts using that authentication factor. The risk score may be a function of the calculated percentage (e.g. the percentage of authentication attempts by the specific authentication factor that do not include successful fraudulent attempts and verified failed unauthorized authentication) and may represent the probability that the specific authentication factor may be safely used (e.g., not succumb to a fraudulent authentication attempt).) the second conversion score of each of the plurality of security authentication flows being based on the first conversion scores of a combination of one or more authentication factors of the plurality of authentication factors; (see Dubinsky at ¶¶ 124-129: According to some embodiments, policy 411 may include at least one of: a minimal number of authentication factors; at least one required type of authentication factors (e.g., authentication by password and authentication by answering a predefined question); at least one required identity criterion (e.g., authentication by ‘knows’, ‘is’ and ‘has’ criteria); a minimal success probability score per each authentication factor; and a minimal overall success probability score for the authentication scheme.) the selected one of the plurality of security authentication flows comprising a corresponding combination of one or more authentication factors presented to a user device for authentication (see Dubinsky at ¶ 106: a first scheme may include three ‘knows’ authentication factors. For example, user 50 may be required to provide a password, a name of a pet and a name of a relative, to accumulate the score of the three authentication factors and obtain the required level of authentication.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Koren so that a combination of multiple authentication factors are used to determine the likelihood of success of the transaction. One of ordinary skill in the art would have been motivated to do so to reduce fraud. Per Claim 5: Koren discloses: A non-transitory computer-readable medium having stored thereon instructions that are executable by a processor of a computing system to cause the computing system to perform operations comprising: (see Koren at ¶ 105: The computer system 700 may include one or more processors 710 and one or more articles of manufacture that comprise non-transitory computer-readable storage media (e.g., memory 720 and one or more non-volatile storage media 730).) identifying an online transaction requiring a security authentication; (see Koren at ¶ 40: In response to a transaction trigger by a merchant system and/or online processing system, the intelligent routing system 110 is configured to analyze the circumstances for the transaction.) selecting one or more potential security authentication procedures based on transaction data corresponding to the online transaction; (see Koren at ¶ 85: The results of the authentication decision strategy can include whether or not to execute enhanced security measures (e.g., execute 3DS or not, select a security version, select other protocol optimization parameters, select information sets to be processed as part of transaction routing, etc.).) determining, using at least one machine learning model, a risk score of the online transaction being fraudulent based on the transaction data; (see Koren at ¶ 43: In another example, the system 110 can include neural networks that are configured to identify fraudulent or improper transactions as outlier transactions, so that transactions not flagged as outliers can be expedited with confidence. See also ¶ 49: For example, payment information can be analyzed by machine learning models to determine if the information matches fraudulent classifications. If the analysis determines that the transaction is invalid, fraud processes can be triggered (e.g., at 208). In some examples, fraud processing can include updating machine learning models based on collected activity or indicators.) determining, using the at least one machine learning model, a conversion score [[for a combination of one or more authentication factors]] for each of the one or more potential security authentication procedures being completed based on the transaction data; (see Koren at ¶ 70: In some embodiments, the physical device being used by a purchaser can affect the likelihood of success of a transaction. In one example, the screen size of a mobile device can limit the user's ability to correctly respond to a CAPTCHA and/or authentication requests. In another example, a device may not display the authentication check correctly, which would result in a failed valid transaction. Where the system determines that the user is not likely to complete the request successfully (e.g., based on their device), the system can re-route to avoid the enhanced security or recommend a different payment modality (e.g., PAYPAL versus credit card) to avoid the issue entirely. See also ¶ 75: In further example, the model accepts as input device data, transactions data, historical user data, statistical behavioral data and generates an output that includes a probability score of cooperation per of each type of challenge. With the probability score output the system can evaluate candidate routes and select the option that achieves the highest likelihood of success given the prediction of where the user will comply or succeeds at security challenges.) evaluating, using the at least one machine learning model, the one or more potential security authentication procedures based on the risk score and the conversion scores [[for the respective combination of one or more authentication factors]]; (see Koren at ¶ 84: According to various embodiments, the authentication decision strategy can be determined by an intelligent routing system and/or processing engines instantiated by the intelligent routing system. For example, the authentication decision strategy can include analysis of a risk score produced by risk engine, user behavior analysis by a user behavior cooperation engine, among other options. For example, the authentication decision strategy can include evaluation of processing routes imposed or restricted by regulatory requirements. A regulation compliance engine can evaluate potential routes and limit options based on applicable regulations. The filtered set of options can be evaluated as part of the authentication decision strategy at 2004.) selecting a security authentication procedure from the one or more potential security authentication procedures based on the evaluating; and (see Koren at ¶ 75: With the probability score output the system can evaluate candidate routes and select the option that achieves the highest likelihood of success given the prediction of where the user will comply or succeeds at security challenges.) using the selected security authentication procedure for the online transaction. (see Koren at ¶ 86: Where authentication is recommended at 2008 YES, an authentication request can be made at 2010. In some examples, the purchaser may be presented with an SMS code that must be entered to complete a transaction. In other embodiments, authentication can include a challenge response protocol, username and password, biometric authentication, or other authentication information.) However, Koren fails to disclose but Dubinsky discloses: a combination of one or more authentication factors (see Dubinsky at ¶ 106: a first scheme may include three ‘knows’ authentication factors. For example, user 50 may be required to provide a password, a name of a pet and a name of a relative, to accumulate the score of the three authentication factors and obtain the required level of authentication.) presenting the corresponding combination of one or more authentication factors to a user device associated with the online transaction. (see Dubinsky at ¶ 193: As shown in step S1020, the processor may send the selection list (e.g., element 310 of FIG. 2) of one or more authentication schemes to the authenticating system 40, that may, in turn prompt the user to select an authentication scheme according to their preference. The processor may store the user's selection for further analysis, to iteratively fine-tune the prediction and/or determination of an optimal authentication scheme by the processor.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Koren so that a combination of multiple authentication factors are used to determine the likelihood of success of the transaction. One of ordinary skill in the art would have been motivated to do so to reduce fraud. Per Claim 8: Koren discloses: A computer-implemented method comprising: (see Koren at Abstract: According to one aspect, systems and methods are provided that intelligently automate payment routing.) receiving transaction data corresponding to an online transaction having a pending security authentication requirement for one or more authentication factors to process the online transaction; (see Koren at ¶ 40: In response to a transaction trigger by a merchant system and/or online processing system, the intelligent routing system 110 is configured to analyze the circumstances for the transaction.) determining, from the transaction data, a risk score corresponding to a probability of the online transaction being fraudulent; (see Koren at ¶ 43: In another example, the system 110 can include neural networks that are configured to identify fraudulent or improper transactions as outlier transactions, so that transactions not flagged as outliers can be expedited with confidence. See also ¶ 49: For example, payment information can be analyzed by machine learning models to determine if the information matches fraudulent classifications. If the analysis determines that the transaction is invalid, fraud processes can be triggered (e.g., at 208). In some examples, fraud processing can include updating machine learning models based on collected activity or indicators.) calculating, using the transaction data, a conversion score corresponding to a probability of the online transaction being completed with respect to the one or more authentication factors; (see Koren at ¶ 70: In some embodiments, the physical device being used by a purchaser can affect the likelihood of success of a transaction. In one example, the screen size of a mobile device can limit the user's ability to correctly respond to a CAPTCHA and/or authentication requests. In another example, a device may not display the authentication check correctly, which would result in a failed valid transaction. Where the system determines that the user is not likely to complete the request successfully (e.g., based on their device), the system can re-route to avoid the enhanced security or recommend a different payment modality (e.g., PAYPAL versus credit card) to avoid the issue entirely. See also ¶ 75: In further example, the model accepts as input device data, transactions data, historical user data, statistical behavioral data and generates an output that includes a probability score of cooperation per of each type of challenge. With the probability score output the system can evaluate candidate routes and select the option that achieves the highest likelihood of success given the prediction of where the user will comply or succeeds at security challenges.) assessing combinations of the one or more authentication factors for the security authentication requirement based on applying the risk score and the conversion score to determine probabilities of the online transaction being completed with the combinations of the one or more authentication factors; and (see Koren at ¶ 84: According to various embodiments, the authentication decision strategy can be determined by an intelligent routing system and/or processing engines instantiated by the intelligent routing system. For example, the authentication decision strategy can include analysis of a risk score produced by risk engine, user behavior analysis by a user behavior cooperation engine, among other options. For example, the authentication decision strategy can include evaluation of processing routes imposed or restricted by regulatory requirements. A regulation compliance engine can evaluate potential routes and limit options based on applicable regulations. The filtered set of options can be evaluated as part of the authentication decision strategy at 2004.) However, Koren fails to disclose but Dubinsky discloses: selecting, based on the assessment, one of a plurality of security authentication flows having a combination of one or more authentication factors predicted to have a highest probability of the online transaction being completed; (see Dubinsky at ¶ 138: The selection of schemes is herein referred to as optimal in a sense that system 10 may select or recommend authentication schemes in a manner that optimizes (e.g., provides the highest values of at least one of: the success probability, risk score and convenience score) in relation to the respective one or more attribute weights of the dictated policy.) requesting the combination of one or more authentication factors from a user device, selected based on the assessing, to satisfy the security authentication requirement for the online transaction. (see Dubinsky at ¶ 193: As shown in step S1020, the processor may send the selection list (e.g., element 310 of FIG. 2) of one or more authentication schemes to the authenticating system 40, that may, in turn prompt the user to select an authentication scheme according to their preference. The processor may store the user's selection for further analysis, to iteratively fine-tune the prediction and/or determination of an optimal authentication scheme by the processor.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Koren so that a combination of multiple authentication factors are used to determine the likelihood of success of the transaction. One of ordinary skill in the art would have been motivated to do so to reduce fraud. Per Claim 2: The combination of Koren and Dubinsky discloses the subject matter of claim 1, from which claim 2 depends. Koren further discloses: wherein selecting the one of the plurality of security authentication flows further comprises using a third machine learning model that is configured to use a risk tolerance threshold corresponding to an acceptable level of chargeback rates and a transaction abandonment threshold corresponding to an acceptable level of abandoned transactions. (see Koren at ¶ 136: By analyzing a multitude of potential execution paths, the system is able to optimize the selected path based on overall system efficiency, and may also include options to take into account intermediary system policy (e.g., merchant policies), operational volume agreements, chargeback penalty programs when deciding how to route the transaction, among other options. See also ¶ 43: For example, a behavioral model can predict that a given user will not complete an enhanced security challenge (e.g., 3DS, etc.) and abandon a valid transaction if required. The system can route the transaction to avoid triggering the enhanced security reducing the burden for executing a given communication route, for example, by requesting the user select a different payment modality, by routing the processing according to a new transaction pathway, etc.) Per Claim 3: The combination of Koren and Dubinsky discloses the subject matter of claim 2, from which claim 3 depends. However, Koren fails to disclose but Dubinsky discloses: wherein the third machine learning model is further configured to apply an authentication preference associated with a party of the online transaction for selecting the one of the plurality of security authentication flows. (see Dubinsky at ¶ 135: Policy 411 may further include one or more attribute weights (e.g., a success probability attribute weight, a convenience attribute weight, a preference attribute weight and a risk attribute weight), associated with respective attributes (e.g., success probability, convenience score, explicit and/or implicit user preference and a risk score) of different authentication factors. In some embodiment, policy 411 may further include a preference attribute weight, to include the user's preference in the selection of authentication factors, as explained herein.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Koren so that a user’s preference is taken into consideration using the techniques disclosed in Dubinsky. One of ordinary skill in the art would have been motivated to do so to increase convenience to the user. Per Claim 6: The combination of Koren and Dubinsky discloses the subject matter of claim 5, from which claim 6 depends. Koren further discloses: wherein selecting the one or more potential security authentication procedures is further based on identifying, using the transaction data, location-based authentication requirements determined from the transaction data. (see Koren at ¶ 67: In further embodiments, the system can determine that providing additional authentication information (e.g., enhancing security) will result in a successful transaction (e.g., initially or as a re-submission). The system can also determine that going straight to authorization (skipping or not using even valid authentication information) based on a location or transaction source, a device being employed by a purchaser, etc., improves the likelihood of success.) Per Claim 7: The combination of Koren and Dubinsky discloses the subject matter of claim 6, from which claim 7 depends. Koren further discloses: wherein selecting the one or more potential security authentication procedures is further based on identifying, using the transaction data, exemptions to the location-based authentication requirements. (see Koren at ¶ 68: In the context of enhanced security protocols and/or regulated environments, there are cases that the system can ask for exemption. In some embodiments, the transaction is treated under enhanced security protocols but does not trigger additional authentication requests. When the system requests an exemption as part of the processing route, the system can determine that an exemption requests is required for the payment gateway. This can trigger the payment gateway system to ask the processor system. Each system in the processing route can trigger an exemption request to downstream systems until the acquirer or issuer system accepts the exemption request. The routing system is configured to check the constraints for each participating system in the processing route and confirm the exemption will be allowed. In some examples, the system employs statistical models and/or machine learning models to see what kind of transactions and risks those systems will allow. By modelling how an exemption request is treated by each system, for example, based on transaction amount, the system can determine how all the systems in the chain will treat the exemption request and thereby determine its effect on an optimal route.) Per Claim 9: The combination of Koren and Dubinsky discloses the subject matter of claim 8, from which claim 9 depends. Koren further discloses: wherein determining the risk score is based on a machine learning model configured to detect fraudulent transaction probabilities. (see Koren at ¶ 43: In another example, the system 110 can include neural networks that are configured to identify fraudulent or improper transactions as outlier transactions, so that transactions not flagged as outliers can be expedited with confidence. In further example, outlier identification can be used to determine that further security operations would increase the likelihood of a successful transaction.) Per Claim 10: The combination of Koren and Dubinsky discloses the subject matter of claim 9, from which claim 10 depends. Koren further discloses: wherein the machine learning model is configured to output the risk score based on chargeback fraud binary classification. (see Koren at ¶ 81: The system can include a liability shift engine 1916 configured to optimize the route of transactions in order to trigger a shift of liability to the issuer. The shift engine 1916 can also be configured to reduce the risk to enter into a fraud scheme program per acquirer/route. In some embodiments, the shift engine includes ML models trained on historical success rate of authorization after successful authentication, merchant current chargeback rates per route, fraud level per entity including fraud alerts when they exist. Upon input of transaction information the model outputs a score per possible route. The system can use the score to select an optimal routing. Various weights can be applied to each such selection or output to enable the system to reconcile the collective engine outputs or emphasize selection of weighted options.) Per Claim 11: The combination of Koren and Dubinsky discloses the subject matter of claim 8, from which claim 11 depends. Koren further discloses: wherein calculating the conversion score is based on a machine learning model configured to determine transaction completion probabilities. (see Koren at ¶ 112: The dimensions evaluated include: an assessment of the risk of the transaction (and how it may impact participants in the communication/execution pathway), the participant tailored factors controlling execution (e.g., security requirements, risk threshold, responsibility for execution (e.g., downstream shifting (as needed or as defined by participant preference), and the likelihood the various dimensions trigger failure by the processing system and/or the initiator (e.g., additional friction that may lead to abandonment of an operation), and from the end point systems which may be in a conflicting stance to the intermediary systems (e.g., reluctance to accept responsibility for execution (e.g., reluctance to authorize a “risky” transaction, or reluctance to permit approaches that avoid enhanced security, etc.)) Per Claim 12: The combination of Koren and Dubinsky discloses the subject matter of claim 11, from which claim 12 depends. Koren further discloses: wherein the machine learning model is configured to output a global conversion score for the one or more authentication factors. (see Koren at ¶ 112: According to some embodiments, the system can optimize routing to ensure completion of the transaction with the selected communication pathway. For example, the system can be configured to evaluate optional parameters and to emphasize enhanced security features while not increasing the likelihood of requiring re-execution or retransmission. According to one example, the system is configured to balance security with limiting re-execution to improve system efficiency. Various embodiments leverage enhanced security protocols (e.g., 3DS requests) without “frictionless” or exemption based approaches, when predictive modeling indicates that execution of the operation will not be affected (e.g., not likely to trigger a failure in the execution). While there are some existing approaches that leverage enhanced security protocols, these existing approaches are typically concerned with only one dimension of analysis—avoid “friction” in execution, but these approaches fail to balance the ability to improve security and authentication services, especially where modeling indicates enhanced security will not impact execution.) Per Claim 13: The combination of Koren and Dubinsky discloses the subject matter of claim 11, from which claim 13 depends. Koren further discloses: wherein the machine learning model is configured to output a local conversion score for each of a plurality of security authentication flows that use the one or more authentication factors. (see Koren at ¶ 112: According to some embodiments, the system can optimize routing to ensure completion of the transaction with the selected communication pathway. For example, the system can be configured to evaluate optional parameters and to emphasize enhanced security features while not increasing the likelihood of requiring re-execution or retransmission. According to one example, the system is configured to balance security with limiting re-execution to improve system efficiency. Various embodiments leverage enhanced security protocols (e.g., 3DS requests) without “frictionless” or exemption based approaches, when predictive modeling indicates that execution of the operation will not be affected (e.g., not likely to trigger a failure in the execution). While there are some existing approaches that leverage enhanced security protocols, these existing approaches are typically concerned with only one dimension of analysis—avoid “friction” in execution, but these approaches fail to balance the ability to improve security and authentication services, especially where modeling indicates enhanced security will not impact execution.) Per Claim 14: The combination of Koren and Dubinsky discloses the subject matter of claim 13, from which claim 14 depends. Koren further discloses: further comprising transforming the transaction data for each of the plurality of security authentication flows to calculate the local conversion score for each of the plurality of security authentication flows. (see Koren at ¶ 112: According to some embodiments, the system can optimize routing to ensure completion of the transaction with the selected communication pathway. For example, the system can be configured to evaluate optional parameters and to emphasize enhanced security features while not increasing the likelihood of requiring re-execution or retransmission. According to one example, the system is configured to balance security with limiting re-execution to improve system efficiency. Various embodiments leverage enhanced security protocols (e.g., 3DS requests) without “frictionless” or exemption based approaches, when predictive modeling indicates that execution of the operation will not be affected (e.g., not likely to trigger a failure in the execution). While there are some existing approaches that leverage enhanced security protocols, these existing approaches are typically concerned with only one dimension of analysis—avoid “friction” in execution, but these approaches fail to balance the ability to improve security and authentication services, especially where modeling indicates enhanced security will not impact execution. Further embodiments balance multiple dimensions in evaluating and identifying an optimal route. The dimensions evaluated include: an assessment of the risk of the transaction (and how it may impact participants in the communication/execution pathway), the participant tailored factors controlling execution (e.g., security requirements, risk threshold, responsibility for execution (e.g., downstream shifting (as needed or as defined by participant preference), and the likelihood the various dimensions trigger failure by the processing system and/or the initiator (e.g., additional friction that may lead to abandonment of an operation), and from the end point systems which may be in a conflicting stance to the intermediary systems (e.g., reluctance to accept responsibility for execution (e.g., reluctance to authorize a “risky” transaction, or reluctance to permit approaches that avoid enhanced security, etc.)) Per Claim 16: The combination of Koren and Dubinsky discloses the subject matter of claim 8, from which claim 16 depends. Koren further discloses: wherein selecting the combination of authentication factors is further based on selecting, when the risk score is below a risk score threshold, a combination of authentication factors having a higher conversion score than another combination of authentication factors. (see Koren at ¶ 117: The system can be configured to evaluate across multiple participant systems (e.g., merchants, intermediaries, services, etc.) in the same industry but also in different industries in order to make sure that the optimization of the communication path/system selection includes modeling within and without various industries. In some embodiments, the system can implement outlier models and/or classification models to identify operations having higher risk and/or operations having low risk and characteristics of valid transactions. In further example, the system can identify greater efficiency in triggering enhanced security in higher risk setting, rather than in lower risk settings yielding different execution path even for similar operations.) Per Claim 20: The combination of Koren and Dubinsky discloses the subject matter of claim 8, from which claim 20 depends. Koren further discloses: further comprising performing the determining the risk score, the calculating the conversion score, and the assessing the combinations of authentication factors using a machine learning model configured to select the combination of authentication factors from the transaction data. (see Koren at ¶ 43: In another example, the system 110 can include neural networks that are configured to identify fraudulent or improper transactions as outlier transactions, so that transactions not flagged as outliers can be expedited with confidence. See also ¶ 49: For example, payment information can be analyzed by machine learning models to determine if the information matches fraudulent classifications. If the analysis determines that the transaction is invalid, fraud processes can be triggered (e.g., at 208). In some examples, fraud processing can include updating machine learning models based on collected activity or indicators. See also ¶ 70: In some embodiments, the physical device being used by a purchaser can affect the likelihood of success of a transaction. In one example, the screen size of a mobile device can limit the user's ability to correctly respond to a CAPTCHA and/or authentication requests. In another example, a device may not display the authentication check correctly, which would result in a failed valid transaction. Where the system determines that the user is not likely to complete the request successfully (e.g., based on their device), the system can re-route to avoid the enhanced security or recommend a different payment modality (e.g., PAYPAL versus credit card) to avoid the issue entirely. See also ¶ 75: In further example, the model accepts as input device data, transactions data, historical user data, statistical behavioral data and generates an output that includes a probability score of cooperation per of each type of challenge. With the probability score output the system can evaluate candidate routes and select the option that achieves the highest likelihood of success given the prediction of where the user will comply or succeeds at security challenges. See also ¶ 84: According to various embodiments, the authentication decision strategy can be determined by an intelligent routing system and/or processing engines instantiated by the intelligent routing system. For example, the authentication decision strategy can include analysis of a risk score produced by risk engine, user behavior analysis by a user behavior cooperation engine, among other options. For example, the authentication decision strategy can include evaluation of processing routes imposed or restricted by regulatory requirements. A regulation compliance engine can evaluate potential routes and limit options based on applicable regulations. The filtered set of options can be evaluated as part of the authentication decision strategy at 2004.) Claim(s) 4 and 17-18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Koren and Dubinsky as applied to claims 1 and 8 above, and further in view of U.S. Patent Pub. No. 2019/0260742 to Arora et al. Per Claim 4: The combination of Koren and Dubinsky discloses the subject matter of claim 1, from which claim 4 depends. However, the combination of Koren and Dubinsky fails to disclose but Arora, an analogous art of authentication discloses: wherein selecting the one of the plurality of security authentication flows further comprises applying a set of heuristics to eliminate one or more of the plurality of security authentication flows. (see Arora at ¶ 38: As previously described, embodiments can employ the heuristic based initializer to develop an authentication model including an authentication rule set for intelligently deciding the optimal authenticator(s) from amongst those supported by an electronic device.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Koren to use heuristics to select/eliminate authentication processes using the techniques disclosed in Arora. One of ordinary skill in the art would have been motivated to do so to apply simple rules for the selection. Per Claim 17: The combination of Koren and Dubinsky discloses the subject matter of claim 8, from which claim 17 depends. However, the combination of Koren and Dubinsky fails to disclose but Arora discloses: wherein selecting the combination of authentication factors is further based on applying one or more heuristics that are independent from the risk score and the conversion score to filter out one or more combinations of the one or more authentication factors from being selected. (see Arora at ¶ 38: As previously described, embodiments can employ the heuristic based initializer to develop an authentication model including an authentication rule set for intelligently deciding the optimal authenticator(s) from amongst those supported by an electronic device.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Koren to use heuristics to select/eliminate authentication processes using the techniques disclosed in Arora. One of ordinary skill in the art would have been motivated to do so to apply simple rules for the selection. Per Claim 18: The combination of Koren, Dubinsky, and Arora discloses the subject matter of claim 17, from which claim 18 depends. However, the combination of Koren and Dubinsky fails to disclose but Arora discloses: wherein the one or more heuristics includes filtering out combinations of the one or more authentication factors based on location data associated with the online transaction. (see Arora at ¶ 49: Determining the location of the user device 104 and user 106 during the an authentication event can help determine the preferences of the user 106 in using particular authentication types based on the location of the user 106 (e.g., at home, work, etc.).) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Koren so that location is used to determine an authentication process as disclosed in Arora. One of ordinary skill in the art would have been motivated to do so to further customize the selection of the authentication process. Claim(s) 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Koren and Dubinsky as applied to claim 8 above, and further in view of U.S. Patent Pub. No. 2021/0185076 to Miller et al. Per Claim 15: The combination of Koren and Dubinsky discloses the subject matter of claim 8, from which claim 15 depends. However, the combination of Koren and Dubinsky fails to disclose but Miller, an analogous art of authentication, discloses: wherein selecting from the one or more authentication factors further comprises selecting, when the risk score exceeds a risk score threshold, a combination of authentication factors associated with a higher security than another combination of authentication factors. (see Miller at ¶ 47: Depending on the level of security threat by the guest, authentication requirements are elevated or lowered in real time as the guest interacts with the website, so that potentially risky actions (e.g., checkout, payment, user account change, etc.) by new or infrequent customers are prevented from taking place, or that normal or low risk activities (e.g., saving items in an online shopping cart) by patrons can be performed with anonymous access or using remembered credentials without asking for further authentication.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Koren so that a safer transaction prioritizes completion probability using the techniques disclosed in Miller. One of ordinary skill in the art would have been motivated to do so to more efficiently process a transaction. Claim(s) 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Koren, Dubinsky, and Arora as applied to claim 17 above, and further in view of U.S. Patent Pub. No. 2004/0230527 to Hansen et al. Per Claim 19: The combination of Koren, Dubinsky, and Arora discloses the subject matter of claim 17, from which claim 19 depends. However, the combination of Koren, Dubinsky, and Arora fails to disclose but Hansen, an analogous art of authentication, discloses: wherein the one or more heuristics includes filtering out combinations of the one or more authentication factors based on a risk tolerance threshold corresponding to an acceptable level of chargeback rates or a transaction abandonment threshold corresponding to an acceptable level of abandoned transactions. (see Hansen at ¶ 30: With reference to FIG. 1B, a block diagram of another embodiment of a money transfer system 105 is shown. This embodiment includes a FRSS 185, but not a separate authentication service 180. Authentication of the user in this embodiment is performed by evaluating the risk of chargeback.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Koren so that chargeback rates are used for determining authentication processes using the techniques disclosed in Hansen. One of ordinary skill in the art would have been motivated to reduce the risk of the transaction. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. U.S. Patent Pub. No. 2023/0245130 discloses a method for optimizing transaction authorization conversion rates using measured feedback includes retrieving payment transaction parameters and authorization results for a plurality of past payment transactions from a database, generating a transaction success model comprising authorization success factors for each of a plurality of payment transaction parameters using data science methods for statistical inference based on the retrieved payment transaction parameters and authorization results, receiving, at an acquirer processor, a payment transaction from a merchant, modifying one or more parameters of the payment transaction according to the generated transaction success model, and submitting the modified payment transaction to a financial institution for processing. U.S. Patent Pub. No. 2021/0049597 discloses predicting successful exemptions to strong authentication requirements. A first payment transaction associated with a first user is submitted for processing by a particular payment issuer along with a request for an exemption from an authentication requirement. It is determined whether the first payment transaction was successfully processed. Subsequently, it is determined whether to include the request for the exemption from the authentication requirement for a second payment transaction associated with a second user in submitting the second payment transaction for processing with the particular payment issuer based at least in part on whether the first payment transaction was successfully processed. U.S. Patent Pub. No. 2018/0130062 discloses a method of authenticating an accountholder for relaxing payment transaction authorization rules is provided. The method is implemented using an authentication computing device in communication with a memory device. The method includes receiving a transaction decline message from an issuer via a transaction message channel, transmitting an authorization rules relaxation message to an accountholder computing device via an authentication message channel separate from the transaction message channel, receiving an authorization rules relaxation response message via the authentication message channel, authenticating the authorization rules relaxation response message as originating from the accountholder, receiving an authorization request message associated with a reattempted payment transaction, inserting a rules relaxation identifier into the authorization request message, providing the authorization request message to the issuer computing device, causing modification of transaction decline systems, and receiving an approval message denoting authorization rules relaxation and acceptance of the second payment transaction by the issuer. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to NILESH B KHATRI whose telephone number is (571)270-7083. The examiner can normally be reached 8:30 AM - 5:30 PM Monday-Friday, alternating Fridays off. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha Patel can be reached at (571) 270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NILESH B KHATRI/Primary Examiner, Art Unit 3699
Read full office action

Prosecution Timeline

Dec 20, 2024
Application Filed
Feb 11, 2026
Non-Final Rejection mailed — §101, §103, §112
Mar 04, 2026
Interview Requested
Mar 11, 2026
Applicant Interview (Telephonic)
Mar 11, 2026
Examiner Interview Summary
May 26, 2026
Response Filed
Aug 13, 2026
Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743691
DIGITAL ASSET VAULT
1y 0m to grant Granted Sep 22, 2026
Patent 12737746
SYSTEMS AND METHODS OF ENCRYPTING TRANSACTION DATA
4y 0m to grant Granted Sep 15, 2026
Patent 12737805
METHODS AND SYSTEMS FOR ACCESSING ACCOUNT INFORMATION ELECTRONICALLY
2y 1m to grant Granted Sep 15, 2026
Patent 12737936
METHODS AND SYSTEMS FOR SECURE AUTHENTICATION IN A VIRTUAL OR AUGMENTED REALITY ENVIRONMENT
1y 9m to grant Granted Sep 15, 2026
Patent 12718231
CONVERSION OF CRYPTOCURRENCY TRANSACTIONS TO CENTRAL BANK DIGITAL CURRENCY FOR MERCHANT SYSTEMS
3y 6m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
62%
Grant Probability
86%
With Interview (+24.2%)
3y 2m (~1y 4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 188 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month