Prosecution Insights
Last updated: August 15, 2026
Application No. 19/220,269

DIGITAL IDENTITY LOCK

Non-Final OA §101§103
Filed
May 28, 2025
Priority
Jun 21, 2019 — provisional 62/864,891 +7 more
Examiner
ANDERSON, SCOTT C
Art Unit
3694
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Early Warning Services LLC
OA Round
1 (Non-Final)
58%
Grant Probability
Moderate
1-2
OA Rounds
1y 6m
Est. Remaining
90%
With Interview

Examiner Intelligence

Grants 58% of resolved cases
58%
Career Allowance Rate
611 granted / 1044 resolved
+6.5% vs TC avg
Strong +31% interview lift
Without
With
+31.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
44 currently pending
Career history
1083
Total Applications
across all art units

Statute-Specific Performance

§101
36.8%
-3.2% vs TC avg
§103
28.8%
-11.2% vs TC avg
§102
14.1%
-25.9% vs TC avg
§112
18.6%
-21.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1044 resolved cases

Office Action

§101 §103
DETAILED ACTION This Office action is in reply to application no. 19/220,269, filed 28 May 2025 with a preliminary amendment filed 4 September 2025. Claim 1 has been cancelled. Claims 2-21 are pending and are considered below. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Objections Claim 18 is objected to because of the following informalities: “inputing” and “identitfy” are not words. The Examiner assumes they are unintentional misspellings of “inputting” and “identify”. Appropriate correction is required. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 2-21 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claims lie within statutory categories of invention, as each is directed to a system (machine), method (process) or non-transitory computer readable medium (manufacture). The claim(s) recite(s) a data gathering step (accessing transaction data), analyzing user activity in no particular manner, determining in no particular manner that the activity is suspicious, and notifying someone else of the suspicious activity. First, detecting suspicious activity is a fundamental business practice and a commercial activity, each of which is among the “certain methods of organizing human activity” deemed abstract. Second, these are mental steps which, in the absence of computers, could be performed mentally and/or with paper records. A loss prevention officer at a store can observe a shopper’s activity and can consult paper records about her past transactions or activities, can mentally determine a level of suspicion, and can tell someone else e.g. verbally of this suspicion. None of this presents any practical difficulty and none requires any technology beyond paper records. This judicial exception is not integrated into a practical application because aside from the bare inclusion of a generic computer, discussed below, nothing is done beyond what was set forth above, which does not go beyond generally linking the abstract idea to the technological environment of generic, networked computers. See MPEP § 2106.05(h). As the claims only manipulate data pertaining to user activities, suspicions and the like, they do not improve the “functioning of a computer” or of “any other technology or technical field”. See MPEP § 2106.05(a). They do not apply the abstract idea “with, or by use of a particular machine”, MPEP § 2106.05(b), as the below-cited Guidance is clear that a generic computer is not the particular machine envisioned. They do not effect a “transformation or reduction of a particular article to a different state or thing”, MPEP § 2106.05(c). First, such data, being intangible, are not a particular article at all. Second, the claimed manipulation is neither transformative nor reductive; as the courts have pointed out, in the end, data are still data. They do not apply the abstract idea “in some other meaningful way beyond generally linking [it] to a particular technological environment”, MPEP § 2106.05(e), as the lack of technical and algorithmic detail in the claims is so as not to go beyond such a general linkage. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional claim limitations, considered individually and as an ordered combination, are insufficient to elevate an otherwise-ineligible claim. Claim 2, which has the most, includes a processor and memory storing instructions. These elements are recited at a high degree of generality and the specification does not meaningfully limit them, such that a generic computer will suffice. It only performs generic computer functions of nondescriptly manipulating data and sharing data with persons and/or other devices. Generic computers performing generic computer functions, without an inventive concept, do not amount to significantly more than the abstract idea. The type of information being manipulated does not impose meaningful limitations or render the idea less abstract. The claim elements when considered in ordered combination – a generic computer performing a chronological sequence of abstract steps – do nothing more than when they are analyzed individually. The other independent claims are simply different embodiments but are likewise directed to a generic computer performing, essentially, the same process. The dependent claims further do not amount to significantly more than the abstract idea: claims 3, 4 and 13 purport to limit objects or entities outside the scope of the claimed invention. Claims 5, 6, 15 and 19 are simply further descriptive of the type of information being manipulated. Claim 7 simply recites storing information; claim 8 consists entirely of nonfunctional printed matter, of no patentable significance. Claim 10 simply recites additional data gathering; claims 11 and 12 simply specify a recipient of information. Claims 14, 17, 18 and 20 simply recite further, abstract manipulation of data, and claim 21 simply recites additional input and output. The claims are not patent eligible. For further guidance please see MPEP § 2106.03 – 2106.07(c) (formerly referred to as the “2019 Revised Patent Subject Matter Eligibility Guidance”, 84 Fed. Reg. 50, 55 (7 January 2019)). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 2-6, 8, 9 and 13-21 are rejected under 35 U.S.C. 103 as being unpatentable over Novick et al. (U.S. Publication No. 2019/0220863, filed 8 January 2019) in view of Hey et al. (U.S. Publication No. 2017/0357968). In-line citations are to Novick. With regard to Claim 2: Novick teaches: An identity network, comprising: a network interface that is in communication with a plurality of identity providers; [0056; access to the Internet reads on this; 0097; transceivers are used] one or more processors; and a memory having instructions stored thereon that, when executed by the one or more processors, cause the one or more processors [0097; a processor and memory units storing applications] to: access transaction data from each of the plurality of identity providers; [0042; data from a “third-party security provider” is used; 0438; a “service provider” may provide information] analyze device activity of a user device; determine that the device activity is suspicious; [0008; “detecting the identity of a user of an electronic device or system; for determining whether or not an electronic device or system is being used by a fraudulent user” by “detecting that a user of an electronic device or electronic system is currently performing, or has recently or previously performed, online interactions that indicate that a fraudulent activity or money laundering activity is attempted or is being performed”] and generate and send an alert… the alert comprising an indication that the device activity of the user device is suspicious. [0070; such an alert is sent to a “bank representative and/or a regulatory agency and/or a law enforcement agency”] Novick does not explicitly teach that an alert is sent to one or more identity providers of the plurality of identity providers, but it is known in the art. Hey teaches a method for reviewing authentication services [title] in which under certain circumstances a “warning” may be transmitted “to the service provider”. [Claim 2] A determination is made that a transaction was fraudulent. [0023] Hey and Novick are analogous art as each is directed to electronic means for managing information related to suspicious activity. It would have been obvious to one of ordinary skill in the art just prior to the filing of the claimed invention to combine the teaching of Hey with that of Novick as it is simply a substitution of one known part for another with predictable results, simply sending information to a service provider as in Hey rather than, or in addition to, the destinations of Novick; the substitution produces no new and unexpected result. In this and the subsequent claims, that an alert comprises “an indication that the device activity of the user device is suspicious” consists entirely of nonfunctional printed matter which bears no functional relation to the substrate and so is considered but given no patentable weight. With regard to Claim 3: The identity network of claim 2, wherein: each identity provider of the plurality of identity providers has access only to its own transaction data. This claim is not patentably distinct from claim 2, as it purports to limit the identity providers with no clear nexus to the claimed identity network. For example, this limitation would be satisfied by simply letting each identity provider access its own, unclaimed device and keeping the others out; there is no requirement that any identity provider have access to any of the data within the claimed system. With regard to Claim 4: The identity network of claim 2, wherein: the user device has a device ID associated with each identity provider of the plurality of identity providers with which the user device has interacted. This claim is not patentably distinct from claim 2 as it purports to limit only unclaimed user devices and imparts neither structure nor functionality to the claimed system. With regard to Claim 5: The identity network of claim 4, wherein: the device ID associated with each identity provider is unique to each of the plurality of identity providers. This claim is not patentably distinct from claim 4. First, it consists entirely of nonfunctional, descriptive language, disclosing at most a coincidence among data but which imparts neither structure nor functionality to the claimed system. Further, it purports to limit only data associated with unclaimed user devices. With regard to Claim 6: The identity network of claim 4, wherein: the user device has network device ID associated with the identity network. This claim is not patentably distinct from claim 4. First, it consists entirely of nonfunctional, descriptive language, disclosing at most a coincidence among data but which imparts neither structure nor functionality to the claimed system. Further, it purports to limit only data associated with unclaimed user devices. With regard to Claim 8: The identity network of claim 4, wherein: the alert sent to a particular identity provider of the one or more identity providers comprises the device ID of the user device that is associated with the particular identity provider. This claim is not patentably distinct from claim 4 as it consists entirely of nonfunctional printed matter, disclosing the content of information which is merely transmitted or displayed and then not further processed, which bears no functional relation to the claimed substrate and which is therefore considered but given no patentable weight. With regard to Claim 9: Novick teaches: A method of detecting suspicious activity, comprising: accessing, by an identity network, transaction data from each of a plurality of identity providers that are in communication with the identity network; [0056; the Internet is used; 0042; data from a “third-party security provider” is used; 0438; a “service provider” may provide information] analyzing, by the identity network, device activity of a user device; determining, by the identity network, that the device activity is suspicious; [0008; “detecting the identity of a user of an electronic device or system; for determining whether or not an electronic device or system is being used by a fraudulent user” by “detecting that a user of an electronic device or electronic system is currently performing, or has recently or previously performed, online interactions that indicate that a fraudulent activity or money laundering activity is attempted or is being performed”] and generating and sending, via a network interface of the identity network, an alert… the alert comprising an indication that the device activity of the user device is suspicious. [0070; such an alert is sent to a “bank representative and/or a regulatory agency and/or a law enforcement agency”] Novick does not explicitly teach that an alert is sent to one or more identity providers of the plurality of identity providers, but it is known in the art. Hey teaches a method for reviewing authentication services [title] in which under certain circumstances a “warning” may be transmitted “to the service provider”. [Claim 2] A determination is made that a transaction was fraudulent. [0023] Hey and Novick are analogous art as each is directed to electronic means for managing information related to suspicious activity. It would have been obvious to one of ordinary skill in the art just prior to the filing of the claimed invention to combine the teaching of Hey with that of Novick as it is simply a substitution of one known part for another with predictable results, simply sending information to a service provider as in Hey rather than, or in addition to, the destinations of Novick; the substitution produces no new and unexpected result. With regard to Claim 13: The method of detecting suspicious activity of claim 9, wherein: each of the plurality of identity providers operates as one or both of an identity provider and a relying party. This claim is not patentably distinct from claim 9, as it purports to limit the external, unclaimed identity providers, but imparts neither structure nor functionality to the claimed method or any computer performing it. With regard to Claim 14: The method of detecting suspicious activity of claim 9, wherein: determining that the device activity is suspicious comprises applying one or both of a model of normal activity and a model of suspicious activity to the device activity. [0114; a model is used to compare user interaction with interactions of a known user] With regard to Claim 15: The method of detecting suspicious activity of claim 14, wherein: the one or both of the model of normal activity and the model of suspicious activity are based at least in part on demographic data. [0023; it may be based on “age range”] With regard to Claim 16: Novick teaches: A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors of an identity network, [0056; the Internet is used; 0042; data from a “third-party security provider” is used; 0438; a “service provider” may provide information] cause the identity network to: access transaction data from each of a plurality of identity providers that are in communication with the identity network; [0042; data from a “third-party security provider” is used; 0438; a “service provider” may provide information] analyze device activity of a user device; determine that the device activity is suspicious; [0008; “detecting the identity of a user of an electronic device or system; for determining whether or not an electronic device or system is being used by a fraudulent user” by “detecting that a user of an electronic device or electronic system is currently performing, or has recently or previously performed, online interactions that indicate that a fraudulent activity or money laundering activity is attempted or is being performed”] and generate and send an alert… the alert comprising an indication that the device activity of the user device is suspicious. [0070; such an alert is sent to a “bank representative and/or a regulatory agency and/or a law enforcement agency”] Novick does not explicitly teach that an alert is sent to one or more identity providers of the plurality of identity providers, but it is known in the art. Hey teaches a method for reviewing authentication services [title] in which under certain circumstances a “warning” may be transmitted “to the service provider”. [Claim 2] A determination is made that a transaction was fraudulent. [0023] Hey and Novick are analogous art as each is directed to electronic means for managing information related to suspicious activity. It would have been obvious to one of ordinary skill in the art just prior to the filing of the claimed invention to combine the teaching of Hey with that of Novick as it is simply a substitution of one known part for another with predictable results, simply sending information to a service provider as in Hey rather than, or in addition to, the destinations of Novick; the substitution produces no new and unexpected result. With regard to Claim 17: The non-transitory computer-readable medium of claim 16, wherein: determining that the device activity is suspicious comprises modeling the device activity and comparing the modeled device activity to one or more models that indicate whether the device activity is suspicious. [0114; a model is used to compare user interaction with interactions of a known user] With regard to Claim 18: The non-transitory computer-readable medium of claim 16, wherein: accessing the transaction data comprises checking previous and current usage activity saved and associated with the user device; and determining that the device activity is suspicious comprises inputing the previous and current usage activity into one or more models that identitfy suspicious activity. [0560; present interactions are compared with previous interactions for this purpose] With regard to Claim 19: The non-transitory computer-readable medium of claim 17, wherein: the one or more models comprise a machine learning model. [0135; a specific type of machine learning is used] This claim is not patentably distinct from claim 17, as referring to a model as a “machine learning model”, without more, is considered mere labeling and given no patentable weight. The reference is provided for the purpose of compact prosecution. With regard to Claim 20: The non-transitory computer-readable medium of claim 16, wherein the instructions further cause the identity network to: receive a request from a relying party to validate or authenticate a digital identity of a user of the user device using one of the plurality of identity providers; [0373; such a request is made] and generate a confidence score that the user device is legitimate for the request. [0037; a specific formula for generating such a score is provided] With regard to Claim 21: The non-transitory computer-readable medium of claim 16, wherein the instructions further cause the identity network to: receive a request from a relying party to validate or authenticate a digital identity of a user of the user device using one of the plurality of identity providers; [0373 as cited above in regard to claim 20] and alert the relying party that the device activity of the user device is suspicious. [see above in regard to claim 2; the combination with Hey reads on this; the content of the alert is nonfunctional printed matter as explained above] Claim(s) 7 and 10-12 are rejected under 35 U.S.C. 103 as being unpatentable over Novick et al. in view of Hey et al. further in view of Poon et al. (U.S. Publication No. 2014/0156531) Claims 7 and 10 are similar so are analyzed together. With regard to Claim 7: The identity network of claim 6, wherein: the instructions further cause the one or more processors to store each device identifier associated with a user device. With regard to Claim 10: The method of detecting suspicious activity of claim 9, wherein: accessing the transaction data from each of the plurality of identity providers comprises receiving the device activity of the user device from a first identity provider of the plurality of identity providers, the device activity comprising a device ID associated with the user device and the first identity provider; and the method further comprises accessing a database to identify a network device ID of the user device based on the device ID associated with the user device and the first identity provider. Novick and Hey teach the network of claim 6 and method of claim 9, but do not explicitly teach storing device identifiers, but it is known in the art. Poon teaches a mobile transaction authentication system [title] which “stores” a “MAC [address]” of a “mobile device” on a computer of a “payment server”. [0217] Alternatively, and “IP address” may be stored. [0181] The information is used to determine whether a “transaction” involving the mobile device “is fraudulent”. [abstract] Poon and Novick are analogous art as each is directed to electronic means for determining fraudulent or suspicious activity involving mobile computing devices. It would have been obvious to one of ordinary skill in the art just prior to the filing of the claimed invention to combine the teaching of Poon with that of Novick and Hey as it is simply a substitution of one known part for another with predictable results, simply storing and/or using Poon’s data in place of, or in addition to, that of Novick; the substitution produces no new and unexpected result. With regard to Claim 11: The method of detecting suspicious activity of claim 10, wherein: the alert is sent to the first identity provider. [id.; at most, this is a substitution of known parts with predictable results, simply sending data to one destination rather than another, with no new and unexpected result inherent or disclosed] With regard to Claim 12: The method of detecting suspicious activity of claim 11, wherein: the alert is further sent to other identity providers of the plurality of identity providers that have interacted with the user device or that may interact with the user device in the future. [id.] This claim is not patentably distinct from claim 11. That the “alert is further sent to other identity providers of the plurality of identity providers” consists entirely of a mere duplication of parts, of no patentable significance as no new and unexpected result is inherent or disclosed. See MPEP § 2144.04(VI)(B). That the providers “have interacted with the user device or that may interact with the user device in the future” refers to steps taken entirely outside the scope of the claimed method and so is considered but given no patentable weight. Further, it is unclear how the system performing the method would be able to know whether the future might include an interaction between an external provider and an external user device. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SCOTT C ANDERSON whose telephone number is (571)270-7442. The examiner can normally be reached M-F 9:00 to 5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bennett Sigmond can be reached at (303) 297-4411. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SCOTT C ANDERSON/Primary Examiner, Art Unit 3694
Read full office action

Prosecution Timeline

May 28, 2025
Application Filed
Jul 17, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705597
POST-PURCHASE CREDIT OFFER AND TENDER SWITCH
1y 7m to grant Granted Aug 11, 2026
Patent 12700020
SYSTEM AND METHOD FOR FUNDING A VIRTUAL LOCATION
4y 1m to grant Granted Aug 04, 2026
Patent 12694456
AUTOMATIC GENERATION OF OPTIMIZED AGGREGATION METRICS FOR USAGE BASED INSURANCE
2y 5m to grant Granted Jul 28, 2026
Patent 12687931
Enhanced Systems and Methods for Multi-Platform Advertising Using Holographic Displays, Biometric Integration, Quantum Technologies, and Device Synchronization
1y 4m to grant Granted Jul 21, 2026
Patent 12682364
DETECTING UNAUTHORIZED ONLINE APPLICATIONS USING MACHINE LEARNING
1y 12m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
58%
Grant Probability
90%
With Interview (+31.4%)
2y 9m (~1y 6m remaining)
Median Time to Grant
Low
PTA Risk
Based on 1044 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month