DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, 19/357,430, was filed on 10/14/2025, and claims priority from Provisional Application 63/708,572, filed 10/17/2024.
The effective filing date is after the AIA date of March 16, 2013, and so the application is being examined under the “first inventor to file” provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Status of the Application
This Non-Final Office Action is in response to Applicant’s communication of 10/14/2025.
Claims 1-21 are pending, of which claim 1 is independent.
All pending claims have been examined on the merits.
Information Disclosure Statement
The Information Disclosure Statement (IDS) submitted on 03/23/2026 has been considered.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-21 are rejected under 35 U.S.C. §101 because the claimed invention is directed to non-statutory subject matter. The claimed invention is directed to an abstract idea, without “significantly more”.
Based on the flowchart in MPEP § 2106, Step 1 of the Alice/Mayo analysis is: “Is the claim to a process, machine, manufacture or composition of matter?”
In regards to Step 1 of the Alice/Mayo analysis, independent claim 1 is an apparatus claim.
For the sake of compact prosecution, we continue with the Alice/Mayo “abstract idea” analysis.
Step 2A, prong 1 of the Alice/Mayo analysis is: “Does the claim recite a law of nature, a natural phenomenon (product of nature), or an abstract idea?”
In regards to Step 2A, prongs 1 and 2 of the Alice/Mayo analysis, the abstract idea elements recited in independent claim 1 are shown in italic font. (The “additional elements” and “extra solution steps” are shown in italic and underlined font):
1. An anomaly detection system for protecting an e-commerce platform throughout a user's journey, the system comprising:
a unified application interface configured to:
integrate with a plurality of user touchpoints;
receive attributes associated with each user touchpoint; and
return a decision of block, allow, or challenge for a user action;
a data ingestion pipeline configured to:
capture and process real-time data from each integrated touchpoint; and
at least one of transform or store the processed data in a anomaly data lake;
a graphical database configured to:
link data associated with user interactions, user devices, user accounts, and/or user transactions across the e-commerce platform; and
update the linked data with new data from the data ingestion pipeline;
a neural network associated with the graphical database, configured to:
analyze the linked data to generate predictions of user identities and/or detect patterns indicative of anomalous behavior; and
based on at least one of the predictions or detected patterns, provide real-time risk assessments for each user action;
a plurality of machine learning models configured to:
use data from the anomaly data lake and real-time predictions from the neural network to generate risk scores for the user accounts and/or the user transactions; and
an anomaly orchestration system configured to:
apply a set of dynamic rules to the real-time risk assessments from the neural network and the risk scores from the plurality of machine learning models, to implement a anomaly prevention action including at least one of a blocking action, an allowance, a challenge, for each user action.
More specifically, claims 1-21 recite an abstract idea: “Certain Methods of Organizing Human Activity", specifically “Commercial or Legal Interactions (Including Agreements in the form of Contracts; Legal Obligations; Advertising, Marketing, or Sales Activities or Behaviors; Business Relations)”, as discussed in MPEP §2106(a)(2) Parts (I) and (II), and in the 2019 Revised Patent Subject Matter Eligibility Guidance.
The “Commercial or Legal Interactions” elements include:
“transform … the processed data in a anomaly data lake”.
“analyze the linked data to generate predictions of user identities and/or detect patterns indicative of anomalous behavior”.
“based on at least one of the predictions or detected patterns, provide real-time risk assessments for each user action”.
“use data from the anomaly data lake and real-time predictions from the neural network to generate risk scores for the user accounts and/or the user transactions”.
“apply a set of dynamic rules to the real-time risk assessments from the neural network and the risk scores from the plurality of machine learning models, to implement a anomaly prevention action including at least one of a blocking action, an allowance, a challenge, for each user action”.
Moreover, claims 1-20 recite “Mathematical Concepts", specifically “Mathematical Relationships”, “Mathematical Formulas or Equations”, and “Mathematical Calculations”, as discussed in MPEP §2106.04(a)(2) Part (IV), and in the 2019 Revised Patent Subject Matter Eligibility Guidance.
The mathematical elements include:
“analyze the linked data to generate predictions of user identities and/or detect patterns indicative of anomalous behavior”.
“based on at least one of the predictions or detected patterns, provide real-time risk assessments for each user action”.
“use data from the anomaly data lake and real-time predictions from the neural network to generate risk scores for the user accounts and/or the user transactions”.
“apply a set of dynamic rules to the real-time risk assessments from the neural network and the risk scores from the plurality of machine learning models, to implement a anomaly prevention action including at least one of a blocking action, an allowance, a challenge, for each user action”.
The “additional elements” include: “a unified application interface”, “a data ingestion pipeline”, “a graphical database”, “a neural network associated with the graphical database”, and “a plurality of machine learning models”.
The “additional extra-solution elements” include: “receive attributes associated with each user touchpoint”, “return a decision of block, allow, or challenge for a user action”, “capture and process real-time data from each integrated touchpoint”, “store the processed data in a anomaly data lake”, “link data associated with user interactions, user devices, user accounts, and/or user transactions across the e-commerce platform”, and “update the linked data with new data from the data ingestion pipeline”.
Step 2A, prong 2 of the Alice/Mayo analysis is “Does the claim recite additional elements that integrate elements that integrate the judicial exception into a practical application?”
In regards to Step 2A, prong 2 of the Alice/Mayo analysis, this abstract idea is not integrated into a practical application, because:
The claim is directed to an abstract idea with additional generic computer elements. The generically recited computer elements (“a unified application interface”, “a data ingestion pipeline”, “a graphical database”, “a neural network associated with the graphical database”, and “a plurality of machine learning models”) do not add a meaningful limitation to the abstract idea, because they amount to simply implementing the abstract idea on a computer. The claim amounts to adding the words "apply it" (or an equivalent) with the abstract idea, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea.
The claim amounts to adding the words "apply it" (or an equivalent) with the abstract idea, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea, such as in the following feature:
“a neural network associated with the graphical database, configured to: analyze the linked data to generate predictions of user identities and/or detect patterns indicative of anomalous behavior”.
“a plurality of machine learning models configured to: use data from the anomaly data lake and real-time predictions from the neural network to generate risk scores for the user accounts and/or the user transactions”.
In regards to “apply it” (applying the abstract idea on a general purpose computer), the 35 USC § 101 rejections are based on the CAFC decision in Recentive Analytics, Inc. v. Fox Corp. April 18, 2025 (https://www.cafc.uscourts.gov/opinions-orders/23-2437.OPINION.4-18-2025_2500790.pdf).
The Recentive Analytics decision states (see page 10 of the verdict): “This case presents a question of first impression: whether claims that do no more than apply established methods of machine learning to a new data environment are patent eligible. We hold that they are not.”
The Examiner holds that Applicant’s description of the neural network merely describes “apply it” uses of a generic neural network.
The extra-solution activities (“receive attributes associated with each user touchpoint”, “return a decision of block, allow, or challenge for a user action”, “capture and process real-time data from each integrated touchpoint”, “store the processed data in a anomaly data lake”, “link data associated with user interactions, user devices, user accounts, and/or user transactions across the e-commerce platform”, and “update the linked data with new data from the data ingestion pipeline”) do not add a meaningful limitation to the method, as they are insignificant extra-solution activity;
The combination of the abstract idea with the additional elements (generically recited computer elements), and/or with the extra-solution activities, does not integrate the abstract idea into a practical application.
Step 2B of the Alice/Mayo analysis is: “Does the claim recite additional elements that amount to significantly more than the judicial exception?”
In regards to Step 2B of the Alice/Mayo analysis, the claims do not include additional elements that are sufficient to amount to significantly more than the abstract idea, because:
When considering the elements "alone and in combination" (“a unified application interface”, “a data ingestion pipeline”, “a graphical database”, “a neural network associated with the graphical database”, and “a plurality of machine learning models”), they do not add significantly more (also known as an "inventive concept") to the exception, because they amount to simply implementing the abstract idea on a computer. Instead, they merely add the words "apply it" (or an equivalent) with the abstract idea, or mere instructions to implement an abstract idea on a computer, or merely use a computer as a tool to perform an abstract idea.
Instead, they merely apply established methods of machine learning to a new data environment, as held to be unpatentable in the Recentive Analytics case.
In regards to the extra solution activities (“receive attributes associated with each user touchpoint”, “return a decision of block, allow, or challenge for a user action”, “capture and process real-time data from each integrated touchpoint”, “store the processed data in a anomaly data lake”, “link data associated with user interactions, user devices, user accounts, and/or user transactions across the e-commerce platform”, and “update the linked data with new data from the data ingestion pipeline”), these are recognized as such by the court decisions listed in MPEP § 2106.05(d).
More specifically, in regards to the “storing” step, see the court cases Versata Dev. Group, Inc. v. SAP Am., Inc., 793 F.3d 1306, 1334, 115 USPQ2d 1681, 1701 (Fed. Cir. 2015) (storing and retrieving information in memory); and OIP Techs., Inc., v. Amazon.com, Inc., 788 F.3d 1359, 1363, 115 USPQ2d 1090, 1092-93 (Fed. Cir. 2015) (storing and retrieving information in memory).
More specifically, in regards to the “receiving”, “linking”, “returning”, and “updating”, steps, see the court cases OIP Techs., Inc., v. Amazon.com, Inc., 788 F.3d 1359, 1363, 115 USPQ2d 1090, 1093 (Fed. Cir. 2015) (sending messages over a network) and (presenting offers and gathering statistics), OIP Techs., 788 F.3d at 1362-63, 115 USPQ2d at 1092-93; buySAFE, Inc. v. Google, Inc., 765 F.3d 1350, 1355, 112 USPQ2d 1093, 1096 (Fed. Cir. 2014) (computer receives and sends information over a network).
Moreover, in regards to “apply it”, according to MPEP § 2106.05(f)(2):
Use of a computer or other machinery in its ordinary capacity for economic or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., a fundamental economic practice or mathematical equation) does not integrate a judicial exception into a practical application or provide significantly more. See Affinity Labs v. DirecTV, 838 F.3d 1253, 1262, 120 USPQ2d 1201, 1207 (Fed. Cir. 2016) (cellular telephone); TLI Communications LLC v. AV Auto, LLC, 823 F.3d 607, 613, 118 USPQ2d 1744, 1748 (Fed. Cir. 2016) (computer server and telephone unit). Similarly, "claiming the improved speed or efficiency inherent with applying the abstract idea on a computer" does not integrate a judicial exception into a practical application or provide an inventive concept. Intellectual Ventures I LLC v. Capital One Bank (USA), 792 F.3d 1363, 1367, 115 USPQ2d 1636, 1639 (Fed. Cir. 2015).
In contrast, a claim that purports to improve computer capabilities or to improve an existing technology may integrate a judicial exception into a practical application or provide significantly more. McRO, Inc. v. Bandai Namco Games Am. Inc., 837 F.3d 1299, 1314-15, 120 USPQ2d 1091, 1101-02 (Fed. Cir. 2016); Enfish, LLC v. Microsoft Corp., 822 F.3d 1327, 1335-36, 118 USPQ2d 1684, 1688-89 (Fed. Cir. 2016). See MPEP §§ 2106.04(d)(1) and 2106.05(a) for a discussion of improvements to the functioning of a computer or to another technology or technical field.
The Examiner holds that the independent claims “use a computer or other machinery in its ordinary capacity for economic or other tasks (e.g., to receive, store, or transmit data)” or “simply add a general purpose computer or computer components after the fact to an abstract idea”.
All dependent claims are also rejected, because they merely further define the abstract idea.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claim 1 is rejected under 35 U.S.C. §§102(a)(1) and (a)(2) as being anticipated by US-2024/0195828-A1 to Panasiuk et al. (“Panasiuk”. Eff. Filed on Dec. 12, 2022. Published on June 13, 2024).
In regards to claim 1,
1. An anomaly detection system for protecting an e-commerce platform throughout a user's journey, the system comprising:
a unified application interface configured to:
integrate with a plurality of user touchpoints;
(See Panasiuk, para. [0095]: “Inputs are provided to the system that include not only user inputs, but also a plurality risk data from a variety of network sources (e.g., hundreds or more different variables to describe a single user interaction in some cases). These inputs are used to generate risk signals that provide evidence of the trustworthiness or risk of the user or the user interaction. The risk signals can then be used to generate a risk score. Furthermore, the inputs, risk data, risk signals, and risk scores may be fed back into the model (e.g., a machine learning model) to improve the reliability of future risk assessments. Some inputs and/or signals may for example come from the dark web, which might be controversial for some users, and might be inaccessible for some users. The system can also collect touch points on a user over time, such as the pages visited, time spent on a page, etc., and use that information to help determine whether or not the user is a human, a bot, an impostor, etc.”)
receive attributes associated with each user touchpoint; and
(See Panasiuk, Abstract: “A method for detecting fraudulent activity on an online system might comprise acquiring data from online service providers about a plurality of interactions of users with the plurality of online service providers, building an identity profile of the user based on the data, receiving, from a client system, an API request, wherein the API request includes information about the user and a new user interaction apparently attempted by the user, comparing the information against the identity profile, and based on the comparing, generating an identity score for the new user interaction. If the identity score exceeds a threshold value, the method can comprise generating an alert, sending the alert to the user, receiving from the user an indication of whether the new user interaction was attempted by the user, and if the new user interaction was not attempted by the user, sending a report to the client system.”)
return a decision of block, allow, or challenge for a user action;
(See Panasiuk, para. [0015]: “Changes in a user account's identity score, or an identity score for a particular interaction that exceeds a threshold value, may trigger an alert (e.g., a customer alert or an alert to website operators) through the notification and verification system. Such knowledge-based alerts may provide a comprehensive solution for protecting users, increasing conversion rates, and guarding against advanced attacks by notifying customers of suspicious activity before damage occurs. Similarly, by using customer alerts, businesses gain immediate first-party feedback whenever a user account is compromised, allowing for swift corrective action to reduce or eliminate loss and damage. The system may also trigger requests and/or notifications to other APIs or systems.”)
(See Panasiuk, para. [0137]: “FIG. 7 is a block diagram 700 that illustrates example enrichments for the system actions described above in FIG. 6. … Any of these enrichments can be applied to an interaction for analysis on the basis of available input data such as email, IP, Device-ID, or others, to help determine whether the interaction is trusted, suspicious, or should be blocked.”)
a data ingestion pipeline configured to:
capture and process real-time data from each integrated touchpoint; and
(See Panasiuk, para. [0012]: “The identity risk index or identity score is a combination of machine learning algorithms and statistical classifiers (e.g., calculated in real time) for each user event on a system, based on a comparison (e.g., by a deep learning network, anomaly detection, or other statistical or machine learning approaches) between one or multiple interaction profiles and the behavior of that user account. In an example, an identity risk score may return a numerical value between 0.0, indicating a very high probability that the interaction is legitimate, and 1.0, indicating a very high probability that the interaction is illegitimate.”)
(See Panasiuk, para. [0018]: “The identity risk determination system can also aid with legal compliance, and compliance with industry standards such as Service Organization Control 2 (SOC 2). Rapid detection of account breaches may reduce regulatory risk and exposure, as well as reducing actual damages, reputational damages, and fines. The identity risk determination system enables organizations to understand and monitor their security exposure in real time or near-real time. By detecting early signs of breach, organizations can react quickly to prevent damage and combat fraud in real time or near real time.”)
at least one of transform or store the processed data in a anomaly data lake;
(See Panasiuk, para. [0123]: “Computer system 500 also includes a main memory 506, such as a random-access memory (RAM) or other dynamic storage device, coupled to bus 502 for storing information and instructions to be executed by processor 504. Main memory 506 may also be used for storing temporary variables or other intermediate information during execution of instructions to be executed by processor 504. Such instructions, when stored in non-transitory storage media accessible to processor 504, render computer system 500 into a special-purpose machine that is customized to perform the operations specified in the instructions.”)
a graphical database configured to:
link data associated with user interactions, user devices, user accounts, and/or user transactions across the e-commerce platform; and
update the linked data with new data from the data ingestion pipeline;
(See Panasiuk, para. [0050]: “In some embodiments, wherein the given data object is a geographic response object associated with a geographic location of the user, and wherein the condition fields comprise at least one of (1) a detected jurisdiction within which a presence of the user is detected, and/or (2) detected geographic coordinates at which the presence of the user is detected.”)
a neural network associated with the graphical database, configured to:
analyze the linked data to generate predictions of user identities and/or detect patterns indicative of anomalous behavior; and
(See Panasiuk, para. [0012]: “The identity risk index or identity score is a combination of machine learning algorithms and statistical classifiers (e.g., calculated in real time) for each user event on a system, based on a comparison (e.g., by a deep learning network, anomaly detection, or other statistical or machine learning approaches) between one or multiple interaction profiles and the behavior of that user account.”)
(See Panasiuk, para. [0138]: “Risk analysis 840 may include looking for anomalies in the activity itself (e.g., malformed responses to online forms), in the network or device from which the activity originated, whether the activity is generated by a bot or a compromised account, and threat signaling analysis (for example, whether the activity includes actions typically associated with malicious activity). Any of these analyses, or combinations thereof, can be used to determine a risk index for the requested interaction.”)
based on at least one of the predictions or detected patterns, provide real-time risk assessments for each user action;
(See Panasiuk, para. [0012]: “The identity risk index or identity score is a combination of machine learning algorithms and statistical classifiers (e.g., calculated in real time) for each user event on a system, based on a comparison (e.g., by a deep learning network, anomaly detection, or other statistical or machine learning approaches) between one or multiple interaction profiles and the behavior of that user account.”)
a plurality of machine learning models configured to:
use data from the anomaly data lake and real-time predictions from the neural network to generate risk scores for the user accounts and/or the user transactions; and
(See Panasiuk, para. [0012]: “The identity risk index or identity score is a combination of machine learning algorithms and statistical classifiers (e.g., calculated in real time) for each user event on a system, based on a comparison (e.g., by a deep learning network, anomaly detection, or other statistical or machine learning approaches) between one or multiple interaction profiles and the behavior of that user account. In an example, an identity risk score may return a numerical value between 0.0, indicating a very high probability that the interaction is legitimate, and 1.0, indicating a very high probability that the interaction is illegitimate. In another example, the identity risk score may be a string that includes a qualitative, human-readable categorization such as “TRUSTED”, “NO_RISK”, “LOW_RISK”, “MED_RISK”, “HIGH_RISK”, etc. Depending on the implementation, still other risk scores or risk indices may be returned in the API response. The risk determination system also returns extensive aggregated data about the user's activity, device, network and geography, and may also return factors explaining the particular risk or trust factors for further consumption into other systems.”)
(See Panasiuk, para. [0095]: “Inputs are provided to the system that include not only user inputs, but also a plurality risk data from a variety of network sources (e.g., hundreds or more different variables to describe a single user interaction in some cases). These inputs are used to generate risk signals that provide evidence of the trustworthiness or risk of the user or the user interaction. The risk signals can then be used to generate a risk score. Furthermore, the inputs, risk data, risk signals, and risk scores may be fed back into the model (e.g., a machine learning model) to improve the reliability of future risk assessments. Some inputs and/or signals may for example come from the dark web, which might be controversial for some users, and might be inaccessible for some users. The system can also collect touch points on a user over time, such as the pages visited, time spent on a page, etc., and use that information to help determine whether or not the user is a human, a bot, an impostor, etc.”)
an anomaly orchestration system configured to:
apply a set of dynamic rules to the real-time risk assessments from the neural network and the risk scores from the plurality of machine learning models, to implement a anomaly prevention action including at least one of a blocking action, an allowance, a challenge, for each user action.
(See Panasiuk, para. [0015]: “Changes in a user account's identity score, or an identity score for a particular interaction that exceeds a threshold value, may trigger an alert (e.g., a customer alert or an alert to website operators) through the notification and verification system. Such knowledge-based alerts may provide a comprehensive solution for protecting users, increasing conversion rates, and guarding against advanced attacks by notifying customers of suspicious activity before damage occurs. Similarly, by using customer alerts, businesses gain immediate first-party feedback whenever a user account is compromised, allowing for swift corrective action to reduce or eliminate loss and damage. The system may also trigger requests and/or notifications to other APIs or systems.”)
(See Panasiuk, para. [0137]: “FIG. 7 is a block diagram 700 that illustrates example enrichments for the system actions described above in FIG. 6. … Any of these enrichments can be applied to an interaction for analysis on the basis of available input data such as email, IP, Device-ID, or others, to help determine whether the interaction is trusted, suspicious, or should be blocked.”)
Conclusion
Applicants are invited to contact the Office to schedule an in-person interview to discuss and resolve the issues set forth in this Office Action. Although an interview is not required, the Office believes that an interview can be of use to resolve any issues related to a patent application in an efficient and prompt manner.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
Any inquiry concerning this communication or earlier communications should be directed to Examiner Ayal Sharon, whose telephone number is (571) 272-5614, and fax number is (571) 273-1794. The Examiner can normally be reached from Monday to Friday between 9 AM and 6 PM. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, SPE Christine Behncke can be reached at (571) 272-8103 or at christine.behncke@uspto.gov. The fax number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Sincerely,
/Ayal I. Sharon/
Examiner, Art Unit 3695
September 8, 2026