Prosecution Insights
Last updated: October 01, 2026
Application No. 19/410,777

SYSTEMS AND METHODS FOR PROVIDING A DYNAMIC DEVICE TRUST DASHBOARD

Non-Final OA §101§103§112
Filed
Dec 05, 2025
Priority
Dec 19, 2023 — divisional of 18/545,484
Examiner
KIM, STEVEN S
Art Unit
3698
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Wells Fargo Bank, N.A.
OA Round
1 (Non-Final)
39%
Grant Probability
At Risk
1-2
OA Rounds
4y 5m
Est. Remaining
79%
With Interview

Examiner Intelligence

Grants only 39% of cases
39%
Career Allowance Rate
181 granted / 468 resolved
-13.3% vs TC avg
Strong +40% interview lift
Without
With
+40.0%
Interview Lift
resolved cases with interview
Typical timeline
5y 3m
Avg Prosecution
21 currently pending
Career history
497
Total Applications
across all art units

Statute-Specific Performance

§101
24.5%
-15.5% vs TC avg
§103
31.7%
-8.3% vs TC avg
§102
7.3%
-32.7% vs TC avg
§112
32.2%
-7.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 468 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is a non-final office action. Claims 1-20 are pending. Information Disclosure Statement The information disclosure statement (IDS) submitted on 12/05/2025 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Divisional This application is a divisional application of U.S. application no. 18/545,484 filed on 12/19/2023 (Parent Application). Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Per claim 1, the claim recites in part in response to determining that the authorization rule set is satisfied, determining, by the operations circuitry, that the user device is authorized to perform the device action request; and performing, by the operations circuitry and based on the request information, an action flow that corresponds to the action request type. The scope of the claim is unclear as it is unclear whether the performing the action flow step is contingent on the conditional statement of “in response to determining that the authorization rule set is satisfied …” or that the step always occurs regardless of the conditional situation of in response to the authorization rule set is satisfied. The other independent claims, claims 9 and 17, are significantly similar to claim 1. As such, claims 9 and 17 are also rejected. The dependent claims are rejected as they depend on claim(s) above without curing the deficiency. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to abstract idea without significantly more. MPEP 2106 provides step(s) in determining eligibility under 35 U.S.C. § 101. Specifically, it must be determined whether the claim is directed to one of the four statutory categories of invention, i.e., process, machine, manufacture, or composition of matter. If the claim does fall within one of the statutory categories, it must then be determined whether the claim is directed to a judicial exception (i.e., law of nature, natural phenomenon, and abstract idea), and if so, it must additionally be determined whether the claim is a patent-eligible application of the exception. If an abstract idea is present in the claim, any additional elements in the claim must integrate the judicial exception into a practical application. If not, the inquiry continues to see whether any element or combination of elements in the claim must be sufficient to ensure that the claim amounts to significantly more than the abstract idea itself. Examples of abstract ideas include mathematical concepts, mental processes, and certain methods of organizing human activities. Under Step 1, claims 1-8 are directed to a method (i.e., process), claims 9-16 are directed to an apparatus, while claims 17-20 are directed to a computer program product (i.e., at least one non-transitory computer-readable storage medium). Thus, the claimed inventions are directed towards one of the four statutory categories under 35 USC § 101. Nevertheless, the claims also fall within the judicial exception of an abstract idea without significantly more. Step 2A, 1st prong: Claim 1 recites: A method for handling a device action request, the method comprising: a) receiving, by communications hardware, the device action request from a user device, wherein the device action request comprises an action request type and request information; b) determining, by operations circuitry, an authorization rule set for the user device from a device profile of a device trust dashboard; c) determining, by the operations circuitry, a device trust score for the user device based on the device profile of the device trust dashboard; d) determining, by the operations circuitry and based on the device trust score, whether the authorization rule set is satisfied; e) in response to determining that the authorization rule set is satisfied, determining, by the operations circuitry, that the user device is authorized to perform the device action request; and f) performing, by the operations circuitry and based on the request information, an action flow that corresponds to the action request type. (Emphasis added on the additional element(s)) Under the broadest reasonable interpretation, the claim recites a process that a) receives request (i.e., request type and request information) from a user, e) determining that the user is authorized to perform the request in response to determining that an authorization rule is satisfied, and f) performing based on the request information an action flow (i.e., authorization) that corresponds to the action request type. The claim further recites three determining steps in determining whether the authorization rule set is satisfied, i.e., b) determining an authorization rule set for the user from a profile of a source, c) determining a trust score for the user based on the profile of the source, and d) determining based on the trust score whether the authorization rule set is satisfied. As such, the claim recites a certain method of organizing human activity, i.e., managing personal behavior or relationships or interaction between people. The examiner also finds that step(s) b)-e) fall within the category of mental process as the determining step(s) can be performed with human mind with pen and paper. The other independent claims, i.e., claims 9 and 17, are significantly similar to claim 1. Hence, claims 9 and 17 also recite abstract idea. Under the Step 2A (prong 2), this judicial exception is not integrated into a practical application. Specifically, the additional elements in the claim(s), i.e., device, communication hardware, operations circuitry, device trust dashboard, apparatus comprising the communication hardware and the operation circuitry, and a computer program product comprising at least one non-transitory computer readable storage medium storing software instructions, amount to no more than mere instructions to implement the abstract idea and/or merely uses a computer as a tool to perform an abstract idea, and or generally linking the use of the judicial exception to a particular technological environment or field of use (i.e., device(s)) – see MPEP 2106.05(f) and 2106.05(h). There is no indication that the claim improves upon the recited communication hardware and/or the operations circuitry individually or in combination. Under Step 2B, examiners should evaluate additional elements individually and in combination to determine whether they provide an inventive concept (i.e. whether the additional elements amount to significantly more than the exception itself). Here, the claim(s) do not include additional elements that are sufficient to amount to significantly more than the judicial exception. Specifically, the claim(s) as a whole, taken individually and in combination, do not provide an inventive concept. As explained above with respect to the integration of the abstract idea into a practical application, the additional elements used to perform the claimed judicial exception amount to no more than mere instructions to implement the abstract idea and/or merely uses a computer as a tool to perform an abstract idea generally linking the use of the judicial exception to a particular technological environment or field of use. Mere instructions to implement the abstract idea on a computer, or merely using the computer as a tool to perform an abstract idea to apply the exception using a generic computer component cannot provide an inventive concept. Looking at the limitations as a combination adds nothing that is not already present when looking at the elements taken individually. There is no indication that the combination of the elements improves the functioning of the recited computer component(s), i.e., communication hardware and operations circuitry individually or in combination. Dependent claims 2-8, 10-16 and 18-20 further expand on the abstract idea without further additional element(s) other than the ones that are identified above. For these reasons, the claims are rejected under 101. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claim(s) 1-6, 9-14, and 17-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 2010/0107225 A1 (“Spencer”) in view of US 2012/0233665 A1 (“Ranganathan”). Per claims 1, 9, and 17, Spencer teaches a method for handling a device action request, the method comprising: receiving, by communications hardware (communications device/interface 212, Figure 2B), the device action request from a user device (i.e., remote device), wherein the device action request comprises an action request type and request information ([0011], network access module adapted for communicating with the remote device and for receiving therefrom a wireless transmission comprising identifying data …; [0032]-[0034], the system 10 may be used to identify different remote devices 102 via network access module and authenticate and authorize access to network and/or Web-based services accessible via the service access module … provide full access to each remote device or provide restricted access to selected services based on user information, remote device owner or type information, service provider information, related purchase information, service promotions, and/or a combination of the above and other such information); determining, by operations circuitry (processor(s)), an authorization rule set for the user device from a device profile of a device trust dashboard (i.e., knowledge base) ([0033], the system 10 may be used to identify different remote devices 102 via network access module and authenticate and authorize access to network and/or Web-based services accessible via the service access module; [0035], compared to a remote device profile stored in a knowledge base operatively coupled to the service access module; [0036], service profile for the remote devices; [0037]; [0068]); determining, by the operations circuitry, whether the authorization rule set is satisfied ([0038], authorization constraints can be associated with a service profile and used to directly or indirectly limit or disable specified applications, or to limit or disable network access functionality … authorization whitelists can also be used to define access to services or to provide minimum service level guarantees; [0068], the user information can be associated with a user profile for identification, authentication and authorization. Specific remote device information may also be extracted for the purpose of identifying and/or authenticating the remote device being used to access the network; [0081], advanced device profile for authentication purpose); in response to determining that the authorization rule set is satisfied, determining, by the operations circuitry, that the user device is authorized to perform the device action request([0038], authorization constraints can be associated with a service profile and used to directly or indirectly limit or disable specified applications, or to limit or disable network access functionality … authorization whitelists can also be used to define access to services or to provide minimum service level guarantees; [0068]; [0081]); and performing, by the operations circuitry and based on the request information, an action flow that corresponds to the action request type ([0038]-[0039], define access to services … provides one or more remote devices access to one or more services .. access to digital home services, such as access to digital TV or other forms of home content to access applications … to access images, music, videos, files, and the like; [0068], [0128], different aspects of a service profile can be applied based on information about the remote device; [0143]-[0146]). Spencer further teaches an apparatus comprising communication hardware, and operations circuitry as well as computer program product comprising at least one non-transitory computer readable (see Figure 2B). Spencer does not teach, but Ranganathan teaches determining, by the operations circuitry, a device trust score for the user device based on the device profile of the device trust dashboard and the determining whether the authorization rule set is satisfied is based on the device trust score ([0046], device reputation or trust score is calculated using history data; [0066], device score and the IP score may be stored and associated with the device such as through the device UUID; [0067], the fraud score may be used by the service provider, along with other information, to authorize, deny, or request additional information in response to a transaction request). It would have been obvious to one of ordinary skill in the art before the effective filing of instant claim to include the technique of use of a device trust score as taught by Ranganathan to Spencer for the purpose of better determine the authenticity or trustworthiness of a transaction request made through a user device ([0006]). In further reference to claim 1, the claim is directed to a method, i.e., process. As such, the claimed limitation of in response to determining that the authorization rule set is satisfied, determining, by the operations circuitry, that the user device is authorized to perform the device action request; and performing, by the operations circuitry and based on the request information, an action flow that corresponds to the action request type does not further limit the scope of the claim as the claim is an conditional, i.e., only occurs when the authorization rule set is satisfied. As per claims 2, 10, and 18, Spencer/Ranganathan does not particular teach in response to determining that the user device failed to be authorized to perform the device action request, providing, by the communications hardware, an action denial response to the user device, wherein the action denial response is indicative of a reason for an authorization failure of the user device. The examiner takes Official notice that in response to determining that the user device failed to be authorized to perform the device action request (i.e., authorization/authentication failure), providing by a communication hardware an action denial response to the user device wherein the action denial response is indicative of a reason for an authorization failure of the user device. As Spencer/Ranganathan discloses determining that the user device either successfully or unsuccessfully authorized to perform the device action as described above, it would have been obvious to one of ordinary skill in the art prior to the effective filing of the claimed invention to include the well-known technique of providing by the communications hardware an action denial response (i.e., reason for an authorization failure of the user device) to the user device so that the user may be informed and act accordingly. As per claims 3, 11, and 19, Spencer/Ranganathan further teaches determining, by the operations circuitry, a device identifier for the user device from the device action request; and identifying, by the operations circuitry, the device profile for the user device using the device identifier (Spencer: Figure 7, device lookup and device profile; [0106], device identifying information; [0111])(Ranganathan: [0030], UUID, [0065]). As per claims 4, 12, and 20, Spencer/Ranganathan further teaches verifying, by the operations circuitry, a provided user credential (Ranganathan: [0085], user names and passwords); determining, by the operations circuitry, whether an authorization rule in the authorization rule set requires a type of user credential to perform the action request type (Ranganathan: [0007], provide additional authentication; [0067], request additional information); in response to determining that the authorization rule requires the type of user credential, determining, by the operations circuitry, whether the provided user credential corresponds to the type of user credential (Ranganathan: [0007], provide additional authentication; [0067], request additional information); and in response to determining that the provided user credential corresponds to the type of user credential, selecting, by the operations circuitry, the device trust score from the device profile (Ranganathan: [0007], provide additional authentication; [0067], request additional information). As per claims 5 and 14, Spencer/Ranganathan further teaches in response to determining that the provided user credential fails to correspond to the type of user credential, selecting, by the operations circuitry, a capped device trust score associated with the authorization rule as the device trust score (Ranganathan: [0065], default device score). Claim(s) 6 and 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Spencer/Ranganathan as applied to claims 1 and 9 above, and further in view of US 2022/0114587 A1 (“Kurani”). As per claims 6 and 14, Spencer/Ranganathan does not particularly teach identifying, by the operations circuitry, an institutional requirement for the action request type; and determining, by the operations circuitry and based on the device trust score, whether the institutional requirement is satisfied, wherein the user device is authorized to perform the device action request in response to determining that the authorization rule set is satisfied and that the institutional requirement is satisfied. Kurani, however, teaches identifying, by the operations circuitry, an institutional requirement for the action request type; and determining, by the operations circuitry and based on the device trust score, whether the institutional requirement is satisfied, wherein the user device is authorized to perform the device action request in response to determining that the authorization rule set is satisfied and that the institutional requirement is satisfied ([0035], defining transaction amount limits, transaction frequency limits, overall device spending limits, approval requirements). It would have been obvious to one of ordinary skill in the art before the effective filing of instant claim to combine the teachings of adding additional controls as disclosed by Kurani to Spencer/Ranganathan to control that the payment parameters do not violate the spending controls (Abstract). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20150242855 A1 discloses notification of authorization or rejection and reasons for declining of authorization; US 20120233665 A1 discloses assigning of a dynamic trust score that may be updated as needed, wherein the trust score of a device and the updates are based on various activities and information associated with the device. The trust score is based on parameters of the device, i.e., device type, registered device location, device phone number, device ID, etc., and activities the device engages in such of amount of transactions, dollar amount of transactions, amount of denied transactions, amount of denied requests, amount of approved requests, location of requests, etc. The disclosure also discloses a device profile that includes the dynamic trust score. Since the trust score is dynamic, a system receiving a transaction from the device can have more accurate information about the device and allow accurate assessment of the risk associated with the request. US 10826889 B2 discloses a device that determines a registered device associated with the customer is a trusted device, a location trust value for the applicant device based on a geolocation proximity between the applicant device and the trusted device, and an environment trust value for the applicant device based on a proximity in a network topology between the applicant device and the trusted device. The device further determines a trust score for the applicant device based on the location trust value and the environment trust value, and sends a signed certificate to the applicant device over the network when the trust score for the applicant device exceeds a threshold. The patent also discloses a dashboard that shows device profile including trust score. PNG media_image1.png 454 833 media_image1.png Greyscale US 20100274597 A1 discloses a methods and systems for establishing an identity confidence database, particularly activities that either increase or decrease confidence score in a customer and granting of additional privileges or removing of privileges based on the dynamic confidence score. The prior art of record does not, however, teach the combination of claimed subject matter as claimed in claims 7 and 15. Any inquiry concerning this communication or earlier communications from the examiner should be directed to STEVEN S KIM whose telephone number is (571)270-5287. The examiner can normally be reached Monday -Friday: 7:00 - 3:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Patrick McAtee can be reached on 571-272-7575. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /STEVEN S KIM/Primary Examiner, Art Unit 3698
Read full office action

Prosecution Timeline

Dec 05, 2025
Application Filed
Jul 14, 2026
Non-Final Rejection mailed — §101, §103, §112
Sep 25, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737756
SECURE PROVISION OF UNDETERMINED DATA FROM AN UNDETERMINED SOURCE INTO THE LOCKING SCRIPT OF A BLOCKCHAIN TRANSACTION
3y 0m to grant Granted Sep 15, 2026
Patent 12731144
SYSTEMS AND METHODS FOR USE IN BIOMETRIC-ENABLED NETWORK INTERACTIONS
3y 2m to grant Granted Sep 08, 2026
Patent 12711512
SPECULATIVE TRANSACTION OPERATIONS FOR RECOGNIZED DEVICES
1y 7m to grant Granted Aug 18, 2026
Patent 12664528
SYSTEM AND METHOD FOR IMPLEMENTING AN INTERBANK INFORMATION NETWORK
2y 2m to grant Granted Jun 23, 2026
Patent 12656945
AUTO-SEGMENTATION OF NON-FUNGIBLE TOKENS USING MACHINE LEARNING
1y 8m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
39%
Grant Probability
79%
With Interview (+40.0%)
5y 3m (~4y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 468 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month