Prosecution Insights
Last updated: August 17, 2026
Application No. 19/007,951

PERSONAL JOURNEY BASED SECURE AUTHENTICATION

Non-Final OA §101§103
Filed
Jan 02, 2025
Examiner
AHSAN, SYED M
Art Unit
2491
Tech Center
2400 — Computer Networks
Assignee
International Business Machines Corporation
OA Round
1 (Non-Final)
74%
Grant Probability
Favorable
1-2
OA Rounds
1y 9m
Est. Remaining
93%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
217 granted / 293 resolved
+16.1% vs TC avg
Strong +19% interview lift
Without
With
+18.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
27 currently pending
Career history
326
Total Applications
across all art units

Statute-Specific Performance

§101
12.4%
-27.6% vs TC avg
§103
52.6%
+12.6% vs TC avg
§102
14.0%
-26.0% vs TC avg
§112
18.1%
-21.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 293 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 03/26/2025 was filed after the mailing date of the Non-Provisional Patent Application on 01/02/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. DETAILED ACTION This Office Action is in response to a Non-Provisional Patent Application received on 01/02/2025. In the application, claims 1-20 have been received for consideration and have been examined. Specification Applicant’s submitted specification has been reviewed and found to be in compliance. Drawings Applicant’s submitted drawings have been reviewed and found to be in compliance. Claim Rejections - 35 USC § 101 (Abstract Idea) 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more analyzed according to MPEP 2106. Step 1: The independent claims 1, 7, and 15 do fall into one of the four statutory categories of “a computer-implemented method”, “a computer program product” and “a system” claims. Nevertheless, the claims still considered as abstract idea (i.e., Mental process - concepts performed in the human mind (including an observation, evaluation, judgment, opinion) for the following prongs and reasons. Step 2A: Prong 1: The limitations of the independent claims 1, 7, and 15 recite the abstract idea of: initiating a first data collection process to collect event data corresponding to a user interacting within a space (Mental process: a human administrator can perform data collection process to collect event data corresponding to a user); extracting one or more events from the event data collected (Mental process: the human administrator can extract information from the collected event data); generating a personal journey based on the one or more events extracted from the event data collected, wherein the personal journey comprises a first sequence of events (Mental process: the human administrator can generate a plan based on the extracted events from the collected data, wherein the generated plan comprises information from the events); initiating, upon detection of a first trigger condition, a second data collection process to collect additional event data corresponding to the user interacting within the space (Mental process: the human administrator detects a trigger condition, the human administrator initiates further data collection process to collect additional event data in regards to the user interaction); generating a predicted sequence of events based on a portion of the additional event data and the first sequence of events (Mental process: the human administrator can generate a prediction based on the collection of data from the user interaction events); generating an actual sequence of events based on the additional event data (Mental process: the human administrator can generate an actual sequence of events based on the additional event data); generating, by [[computationally]] comparing the actual sequence of events to the predicted sequence of events, a similarity metric between the actual sequence of events and the predicted sequence of events (Mental process: the human administrator can generate a score by comparing the actual sequence of events and the predicted sequence of events); and initiating a first responsive action upon determination that the similarity metric does not meet a predefined similarity metric threshold (Mental process: the human administrator can initiate a responsive action upon determination that the generated score fails to meet a predefined threshold). Step 2A: Prong 2: The judicial exception (i.e., computationally comparing the events) is not integrated into a practical application. In particular, the claims do not recite any additional element to perform beyond routine steps. To show that the involvement of a computer assists in improving the technology, the claims must recite the details regarding how a computer aids the method, the extent to which the computer aids the method, or the significance of a computer to the performance of the method. Merely adding generic computer components to perform the method is not sufficient. Thus, the claim must include more than mere instructions to perform the method on a generic component or machinery to qualify as an improvement to an existing technology (MPEP 2106.5(a) II). In this particular case, the additional elements of the claim are: “A computer-implemented method” (claim 1), “A computer program product comprising one or more computer readable storage media” (claim 7) and “A computer system” (claim 15). According to the established Alice v. CLS Bank framework by courts, the claim limitations have been analyzed as follows: The method can be broken down into steps that a human could theoretically do with a pen, a piece of paper, and their own brain: Collecting data on what a user is doing. Predicting what they will do next based on past habits. Comparing what actually happened to the prediction. Taking an action if the prediction is wrong. Because these steps are essentially just mental processes, analyzing data, and evaluating outcomes, they are viewed as abstract ideas standing alone. If a claim is abstract, it can still be patented if it adds an "inventive concept"—such as a specific, unconventional way to improve computer technology. This method uses broad terms like "first data collection process" and "predefined similarity metric threshold". These are generic terms. They simply instruct a computer to perform abstract tasks faster, rather than actually solving a specific technological problem. Courts have repeatedly ruled that merely applying a mental or business process to a generic computer does not make it eligible for a patent. The additional elements are recited at a high-level of generality (i.e., as generic terms performing generic computer functions (see instant spec. [0008], & [0045-0046]) such that it amounts no more than mere instructions to apply the exception using generic computer components. Accordingly, the additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, the claims are directed to an abstract idea. Step 2B: The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the claims do not reflect improvement in the technology. Further, mere automated instructions to apply an exception using a generic computer component cannot provide an inventive concept. Thus, the claims are not patent eligible. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements identified above amount to no more than mere instructions to apply the exception using general purpose computer. To support this factual conclusion, the examiner takes Official Notice that one of the ordinary skill in the art, before the effective filing date of the claimed invention, would have found processors and/or software well-known and routine in technology that involves computers (instant spec. [0008], & [0045-0046] discloses that the functions of the disclosed claims can be implemented using generic computer(s)) such that it amounts no more than mere instructions to apply the exception using generic computer components. Accordingly, the additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Thus, the examiner asserts that the above noted elements, when considered individually or in combination, do not constitute as “significantly more” than the abstract idea. The dependent claims 2-6, 8-14, and 16-20 of respective independent claims 1, 7, and 15 have been analyzed and fall into one of the statutory categories and therefore passes step 1 analysis. However, under step 2, 2A & 2B analysis, the dependent claims recite mental processes which can be implemented by one or more human users using pen and paper. Thus, dependent claims also recite abstract idea and considered ineligible. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 7-9, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Cheng et al., (US20180357321A1) in view of Gomez et al., (US20220224683A1). Regarding claim 1, Cheng discloses: A computer-implemented method comprising: initiating a first data collection process to collect event data corresponding to a user interacting within a space ([0002], [0021], [0035], & [0050] discloses collecting user behavior data during browsing sessions, including clicks, dwell time, back clicks, search requests, exit rate, and device type from users interacting with a networked system); extracting one or more events from the event data collected ([0035], [0041-0042], & [0051] discloses filtering user behavior, identifying user events, and sequentializing events based on timestamps); generating a personal journey (i.e., ordered event sequence) based on the one or more events extracted from the event data collected, wherein the personal journey comprises a first sequence of events ([0002], [0021], [0035], & [0051] discloses representing each browsing session as a sequence of states/events and sequentializing user behavior into an ordered event sequence); initiating, upon detection of a first trigger condition, a second data collection process to collect additional event data corresponding to the user interacting within the space ([0022] & [0037] discloses receiving user events during a second browsing session after training the behavioral model and collecting current user behavior during a subsequent browsing session); generating a predicted sequence of events based on a portion of the additional event data and the first sequence of events ([0019–0022], [0036], [0038], [0053], & [0055] discloses training an LSTM model using historical behavioral sequences and generating predicted future behavior using current user events together with historical behavior. This is the strongest reference for this limitation); generating an actual sequence of events based on the additional event data ([0022], [0041-0042], [0050-0051] discloses collecting, filtering, and sequentializing current user behavior to form the actual behavioral sequence). Cheng fails to disclose: generating, by computationally comparing the actual sequence of events to the predicted sequence of events, a similarity metric between the actual sequence of events and the predicted sequence of events; determining that the similarity metric does not meet a predefined similarity metric threshold; and initiating a first responsive action upon determination that the similarity metric does not meet a predefined similarity metric threshold. However, Gomez discloses: generating, by computationally comparing (i.e., comparing using machine learning model) the actual sequence of events to the predicted sequence of events ([0011-0012] discloses machine learning model disclosed herein also is capable of authenticating the new user by comparing a new behavior with many user's behaviors stored in a database (e.g., few-shot inference). Models use a Siamese neural network to perform the above analysis by comparing the first and second behaviors. The data for the first and second behaviors is the input to the neural network. The output from the neural network is used to determine whether the person attempting to log into the computer system is authentic. In one embodiment, the output is simply either that the user is authenticated, or that the user is not authenticated. In doing so, whether two behaviors belong to the same user is assessed), a similarity metric between the actual sequence of events and the predicted sequence of events ([0052-0057] discloses generating similarity values using feature vectors and distance metrics (e.g., cosine similarity, Euclidean distance, Manhattan distance) for authentication); determining that the similarity metric does not meet a predefined similarity metric threshold ([0033], and [0055-0056] discloses comparing the similarity/confidence score against an authentication threshold to determine whether the user should be authenticated); and initiating a first responsive action upon determination that the similarity metric does not meet a predefined similarity metric threshold ([0056-0057] discloses initiating an authentication decision (e.g., authenticate or deny authentication) based on the similarity evaluation). It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to modify the sequentialized behavior prediction system with the behavioral authentication techniques of Gomez to improve the reliability and security of user-specific decision making. Regarding claim 7, it is a computer readable storage media claim and recites similar subject matter as claim 1 and therefore rejected under similar ground of rejection. Regarding claim 15, it is a computer system claim and recites similar subject matter as claim 1 and therefore rejected under similar ground of rejection. Regarding claim 8, the combination of Cheng and Gomez discloses: The computer program product of claim 7, wherein the stored program instructions are stored in a computer readable storage device in a data processing system, and wherein the stored program instructions are transferred over a network from a remote data processing system (Cheng: [0070-0071]). Regarding claim 9, it is a computer readable storage media claim and recites similar subject matter as claim 8 and therefore rejected under similar ground of rejection. Claim(s) 1-6, 10-14, and 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over Cheng et al., (US20180357321A1) in view of Gomez et al., (US20220224683A1) and further in view of Gandhi et al., (US20240039903A1). Regarding claim 2, the combination of Cheng and Gomez fails to disclose: The computer-implemented method of claim 1, wherein the first responsive action includes initiating a request for additional authentication information. However, Gomez discloses: wherein the first responsive action includes initiating a request for additional authentication information ([0045] The user device 104 may provide credentials to the authentication server 122 and/or perform other operations for registering the user device 104 with authentication server 122. In some further instances, the user device 104, the remote system 118, and/or the application service 120 may trigger the authentication server 122 to initiate MFA based at least in part on the user 106 attempting to access and/or requesting permission to perform an action requiring authentication). It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to modify Cheng in view of Gomez and include Multi-Factor Authentication (MFA) techniques of Gandhi. The motivation to include MFA techniques is to reduce the attack surface and protects a computing environment by requiring a higher level of identity assurance from users trying to access the computing environment resources. Regarding claim 10, it is a computer readable storage media claim and recites similar subject matter as claim 2 and therefore rejected under similar ground of rejection. Regarding claim 16, it is a computer system claim and recites similar subject matter as claim 2 and therefore rejected under similar ground of rejection. Regarding claim 3, the combination of Cheng and Gomez fails to disclose: The computer-implemented method of claim 1, wherein the first responsive action includes denying access to a secure access point. However, Gandhi discloses: wherein the first responsive action includes denying access to a secure access point ([0046] In some further instances, the authentication server may, in isolation or in combination with the user device 105, access point 110, remote system 118, and/or the application service 120 determine a confidence value indicating a likelihood that a user is within the predefined threshold proximity to the user device 104. For example, the predefined threshold proximity may be a maximum distance of 1.5 meters to the user device 104 and/or the access point 110. As such, where the user 106 performs the gesture 108 at a distance greater than 1.5 meters from the user device 104 and/or the access point 110, the authentication server 122 may not grant the user 106 access and/or permission to act; [0053] In some further instances, the access point and/or AAP 204 may direct the user 106 to perform the authenticating gesture 206 within a specific distance (e.g., 0.5 m, 1.0 m, etc.) of the access point 110 and/or the user device 104. For example, the specific distance may be included data collected associated with the authenticating gesture 206 and exceeding the specific distance may cause a failed MFA. In some instances, the access point 110 and/or AAP 204 may direct the user 106 to perform the authenticating gesture 206 at multiple distances from the access point 110 and/or the user device 104. As such, the access point 110 and/or AAP 204 may increase the accuracy of identifying the threshold proximity of the authenticating gesture 206 by collecting CSI data associated with the user 106 performing the authenticating gesture 206 at multiple distances). It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to modify Cheng in view of Gomez and include Multi-Factor Authentication (MFA) techniques of Gandhi. The motivation to include MFA techniques is to reduce the attack surface and protects a computing environment by requiring a higher level of identity assurance from users trying to access the computing environment resources. Regarding claim 11, it is a computer readable storage media claim and recites similar subject matter as claim 3 and therefore rejected under similar ground of rejection. Regarding claim 17, it is a computer system claim and recites similar subject matter as claim 3 and therefore rejected under similar ground of rejection. Regarding claim 4, the combination of Cheng and Gomez fails to disclose: The computer-implemented method of claim 1, wherein the first trigger condition comprises moving a predefined distance away from a secure access point. However, Gandhi discloses: wherein the first trigger condition comprises moving a predefined distance away from a secure access point ([0046] In some further instances, the authentication server may, in isolation or in combination with the user device 105, access point 110, remote system 118, and/or the application service 120 determine a confidence value indicating a likelihood that a user is within the predefined threshold proximity to the user device 104. For example, the predefined threshold proximity may be a maximum distance of 1.5 meters to the user device 104 and/or the access point 110. As such, where the user 106 performs the gesture 108 at a distance greater than 1.5 meters from the user device 104 and/or the access point 110, the authentication server 122 may not grant the user 106 access and/or permission to act; [0053] In some further instances, the access point and/or AAP 204 may direct the user 106 to perform the authenticating gesture 206 within a specific distance (e.g., 0.5 m, 1.0 m, etc.) of the access point 110 and/or the user device 104. For example, the specific distance may be included data collected associated with the authenticating gesture 206 and exceeding the specific distance may cause a failed MFA. In some instances, the access point 110 and/or AAP 204 may direct the user 106 to perform the authenticating gesture 206 at multiple distances from the access point 110 and/or the user device 104. As such, the access point 110 and/or AAP 204 may increase the accuracy of identifying the threshold proximity of the authenticating gesture 206 by collecting CSI data associated with the user 106 performing the authenticating gesture 206 at multiple distances). It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to modify Cheng in view of Gomez and include Multi-Factor Authentication (MFA) techniques of Gandhi. The motivation to include MFA techniques is to reduce the attack surface and protects a computing environment by requiring a higher level of identity assurance from users trying to access the computing environment resources. Regarding claim 12, it is a computer readable storage media claim and recites similar subject matter as claim 4 and therefore rejected under similar ground of rejection. Regarding claim 18, it is a computer system claim and recites similar subject matter as claim 4 and therefore rejected under similar ground of rejection. Regarding claim 5, the combination of Cheng and Gomez fails to disclose: The computer-implemented method of claim 1, wherein the first data collection process comprises collecting body movement data corresponding to the user. However, Gandhi discloses: wherein the first data collection process comprises collecting body movement data corresponding to the user ([0032] In some examples, the user 106 may attempt to receive access to the user device 104 and/or to websites, applications, and the like within the user device 104. As such, the user device may trigger MFA that requires the gesture 108. For example, the gesture 108 may be required to be performed in order to obtain access and/or obtain permission to perform an action. As such, the user device 104 or other user devices 104 in the environment 102 may collect data associated with an attempted gesture by the user 106. The gesture 108 may include things such as hand waves, handshakes, hand shapes, body movements, head movements, and/or the like). It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to modify Cheng in view of Gomez and include Multi-Factor Authentication (MFA) techniques of Gandhi. The motivation to include MFA techniques is to reduce the attack surface and protects a computing environment by requiring a higher level of identity assurance from users trying to access the computing environment resources. Regarding claim 13, it is a computer readable storage media claim and recites similar subject matter as claim 5 and therefore rejected under similar ground of rejection. Regarding claim 19, it is a computer system claim and recites similar subject matter as claim 5 and therefore rejected under similar ground of rejection. Regarding claim 6, the combination of Cheng and Gomez fails to disclose: The computer-implemented method of claim 1, wherein the first data collection process comprises collecting movement speed data corresponding to the user ([0018] Gestures may be broadly defined to include hand waves, other bodily movement, clapping, other bodily generated sounds, facial recognition, and the like. Additionally, gestures may be defined as passive or active. Passive gestures may be those gestures described above involving the user. Active gestures may include the user performing a gesture with some device. For example, an active gesture may include the user waving their personal mobile device in accordance with the predefined authenticating gesture; [0032] In some examples, the user 106 may attempt to receive access to the user device 104 and/or to websites, applications, and the like within the user device 104. As such, the user device may trigger MFA that requires the gesture 108. For example, the gesture 108 may be required to be performed in order to obtain access and/or obtain permission to perform an action. As such, the user device 104 or other user devices 104 in the environment 102 may collect data associated with an attempted gesture by the user 106. The gesture 108 may include things such as hand waves, handshakes, hand shapes, body movements, head movements, and/or the like). It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to modify Cheng in view of Gomez and include Multi-Factor Authentication (MFA) techniques of Gandhi. The motivation to include MFA techniques is to reduce the attack surface and protects a computing environment by requiring a higher level of identity assurance from users trying to access the computing environment resources. Regarding claim 14, it is a computer readable storage media claim and recites similar subject matter as claim 6 and therefore rejected under similar ground of rejection. Regarding claim 20, it is a computer system claim and recites similar subject matter as claim 6 and therefore rejected under similar ground of rejection. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SYED M AHSAN whose telephone number is (571)272-5018. The examiner can normally be reached 8:30 AM - 6:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at 571-272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SYED M AHSAN/Primary Examiner, Art Unit 2491
Read full office action

Prosecution Timeline

Jan 02, 2025
Application Filed
Jul 15, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706943
AUTOMATED THREAT RESPONSE IN EXTENDED DETECTION AND RESPONSE (XDR) SYSTEMS
2y 11m to grant Granted Aug 11, 2026
Patent 12706944
Cybersecurity System Having a Chatbot
2y 8m to grant Granted Aug 11, 2026
Patent 12706959
SYSTEM AND METHOD FOR SELF-CLUSTERING EDGE COMPUTING PROTECTION
1y 12m to grant Granted Aug 11, 2026
Patent 12700990
METHOD FOR SECURING AN EXECUTION OF A CRYPTOGRAPHIC PROCESS
3y 4m to grant Granted Aug 04, 2026
Patent 12701126
VISUAL DEEP LEARNING FOR INLINE PHISHING DETECTION
2y 3m to grant Granted Aug 04, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
74%
Grant Probability
93%
With Interview (+18.9%)
3y 4m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 293 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month