Invalidity dossier

US 9595008

Systems, methods, apparatus for evaluating status of computing device user

Current assignee: Unified Patents

Added 6/15/2026, 12:01:45 AM

At a glanceNo PTAB challenges2 lawsuits on fileasserted by Unified PatentsSoftware Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Here is a concise summary of US patent 9,595,008:

US Patent 9,595,008 Summary

  • Title: Systems, methods, apparatus for evaluating status of computing device user
  • Assignee: Nobots LLC
  • Inventor: Timothy P. Heikell
  • Filing Date: 2008-11-19
  • Issue Date: 2017-03-14

Abstract:
Methods, systems and apparatus for assessing the likely user status of a client computing device interacting with a server where the computing device is in bi-directional operative communication with the server, wherein the likely user status is one of a human operator or a computer executable program such as a “bot”. By presenting issued data from the server to the client computing device and monitoring at least some of the data generated at the client computing device in response to the issued data, a comparison can be made between the monitored data and model data relating to human interaction with or in response to the issued data. The results of the comparison can lead to a value that represents the likelihood that the monitored data results from human interaction with or in response to the issued data. Modeled data includes, but is not limited to, data indicative of human interaction with a computing environment, whether active or passive.

Plain-Language Overview of Independent Claims:

  • Independent Claim 1: This claim describes a method for determining how confident one can be that a person, not an automated program ("bot"), is operating a client computing device that is interacting with a server. The method involves:
    • A user on a client device asking a server for data.
    • The server sending data to that client device.
    • Observing data that the user generates on the client device in response to the server's data.
    • Comparing this observed user data to pre-existing "model data" which represents typical human interaction.
    • Generating a confidence score indicating the likelihood that the observed data came from a human rather than a bot.
  • Independent Claim 19: This claim describes an alternative method for assessing the confidence level that a human, rather than an automated program, operated a client computing device. This assessment happens before the server sends any specific data to the client device. The method comprises:
    • Gathering "interest data" from the client computing device before the server delivers its data.
    • Comparing this interest data to "model data" that represents how humans typically interact with a computing device before such interest data is acquired.
    • Generating a confidence score indicating the likelihood that a human, not a bot, was operating the client device at the time the interest data was gathered.

CAFC 2026 Dockets:
As of April 26, 2026, the patent US9595008B1 has been the subject of an appeal at the Court of Appeals for the Federal Circuit (case 24-1432, Nobots v. Google). Google, LLC challenged the patentability of US9595008B1, and on November 20, 2025, the Federal Circuit issued a ruling reversing the underlying patentability determination and remanding the case. This indicates that while a decision has been made, the legal proceedings related to the patent's validity are ongoing and have implications for 2026.

Generated 6/17/2026, 6:46:06 AM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 9595008. The free-form analysis below may also discuss cases beyond this list.

  • IPR2022-00940Patent Trial and Appeal Board (PTAB)Final Written Decision issued

    Defendants: Nobots LLC

  • 6:21-cv-01290Texas Western District CourtLitigation

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

US Patent 9595008 has been involved in several litigation cases. Here's a summary of the known cases:

Patent Trial and Appeal Board (PTAB) Case:

  • Case Number: IPR2022-00940 [cite: Original Patent]
  • Plaintiff(s): Unified Patents [cite: Original Patent, 4, 7]
  • Defendant(s): Nobots LLC (current assignee of US9595008) [cite: Original Patent]
  • Jurisdiction: Patent Trial and Appeal Board (PTAB)
  • Filing Date: April 29, 2022 (Effective date of IPR filing) [cite: Original Patent]
  • Outcome/Status: Final Written Decision issued. [cite: Original Patent]

District Court Cases:

  • Jurisdiction: Texas Western District Court [cite: Original Patent]
    • Case Number: 6:21-cv-01290 [cite: Original Patent]
    • Plaintiff(s): Nobots LLC (implied, as the assignee of the patent) [cite: Original Patent]
    • Defendant(s): Not specified in the provided patent information.
    • Filing Date: Not specified in the provided patent information.
    • Outcome/Status: Litigation. [cite: Original Patent]
  • Jurisdiction: Texas Western District Court [cite: Original Patent]
    • Case Number: 1:22-cv-00585 [cite: Original Patent]
    • Plaintiff(s): Nobots LLC (implied, as the assignee of the patent) [cite: Original Patent]
    • Defendant(s): Not specified in the provided patent information.
    • Filing Date: Not specified in the provided patent information.
    • Outcome/Status: Litigation. [cite: Original Patent]

Court of Appeals for the Federal Circuit (CAFC) Case:

  • Case Number: 24-1432 [cite: Original Patent]
  • Plaintiff(s): Not specified in the provided patent information.
  • Defendant(s): Not specified in the provided patent information.
  • Jurisdiction: Court of Appeals for the Federal Circuit [cite: Original Patent]
  • Filing Date: Not specified in the provided patent information.
  • Outcome/Status: Litigation. [cite: Original Patent]

Generated 6/17/2026, 6:46:22 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Unified Patents

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

One AIA trial proceeding has been filed against US patent 9,595,008: IPR2022-00940. This proceeding initially resulted in the invalidation of most challenged claims by the Patent Trial and Appeal Board (PTAB), with two claims sustained. Upon appeal, the Federal Circuit reversed the PTAB's decision on one of the sustained claims, resulting in its invalidation. Consequently, claims 1-17, 19, and 20 of US9595008B1 have been deemed unpatentable, leaving only claim 18 as sustained. This provides a strong defensive posture for a defendant, as the vast majority of the patent's claims have been canceled.

IPR2022-00940 — Google LLC v. Nobots LLC

  • Type: Inter Partes Review
  • Filed: April 2022
  • Status: Final Written Decision issued by PTAB on 2023-11-29; appealed to the Federal Circuit, with a decision issued on 2025-11-20 reversing the PTAB's finding for claim 19 and remanding the case.
  • Judge panel: Cocks, joined by Pettigrew and Parvis (at PTAB). MOORE, Chief Judge, TARANTO, Circuit Judge, and CHUN, District Judge (on appeal at Federal Circuit).
  • Petition grounds: Google LLC challenged all twenty claims (1-20) of US9595008B1. At least one ground invoked U.S. Patent Application No. 2008/0114624 (Kitts) to argue claim 19 was unpatentable for anticipation or obviousness under 35 U.S.C. §§ 102 and/or 103.
  • Institution decision: Instituted. Google successfully petitioned the PTAB to institute an IPR of all twenty claims of the '008 patent. The precise date of the institution decision is not publicly available in the search results.
  • Final Written Decision (issued 2023-11-29): The PTAB rejected Google's challenges to claims 18 and 19, holding them patentable. All other claims (1-17, 20) were held unpatentable. The PTAB initially upheld claim 19 based on its construction of "acquiring interest data." Nobots LLC argued this phrase required "active data," despite the patent defining "interest data" as "active or passive data."
  • Settlement / termination: Not applicable; a Final Written Decision was issued and subsequently appealed.
  • Appeal: Yes, Google LLC appealed the PTAB's upholding of claim 19 to the Federal Circuit (Docket Number 24-1432). The Federal Circuit issued its ruling on 2025-11-20, reversing the Board's determination that claim 19 is not unpatentable. The Federal Circuit found the Board's claim construction of "acquiring interest data" erroneous, concluding that the phrase applies even when only passive data are obtained. Since Nobots LLC did not dispute that unpatentability would follow under Google's proposed construction, the Federal Circuit reversed the Board's upholding of claim 19. The case was remanded.
  • Defensive value: This proceeding significantly narrowed the patent. Claims 1-17 and 20 were found unpatentable by the PTAB. Claim 19, initially upheld by the PTAB, was subsequently found unpatentable by the Federal Circuit. Only claim 18 remains patentable. Any infringement theory relying on claims 1-17, 19, or 20 is likely without merit or would face substantial challenges.

Strategic summary

As a result of IPR2022-00940 and its subsequent appeal to the Federal Circuit, claims 1-17, 19, and 20 of US9595008B1 are now CANCELED as unpatentable. Only claim 18 has been SUSTAINED. This represents a substantial narrowing of the patent's scope.

Regarding estoppel, under 35 U.S.C. § 315(e)(2), Google LLC (the petitioner) and its privies are estopped from asserting in a civil action or ITC investigation that claims 1-17, 19, and 20 are unpatentable on any ground that Google raised or reasonably could have raised during IPR2022-00940 based on patents or printed publications. However, this estoppel primarily impacts the petitioner. For other potential defendants, prior-art grounds not raised by Google, or grounds of invalidity not permissible in an IPR (e.g., challenges under 35 U.S.C. § 101 or § 112, or prior art that is not a patent or printed publication), may still be available.

The pattern of litigation shows that Google LLC, a major tech company, initiated the IPR against Nobots LLC, a common type of patent owner that can be associated with patent assertion entities. The fact that Google challenged all claims and largely succeeded, even pursuing an appeal to invalidate an additional claim, signals a strong belief in the invalidity of the patent. The Federal Circuit's reversal on claim construction for claim 19 demonstrates that careful claim interpretation remains critical in these proceedings.

Recommended next steps

For a defendant facing assertion of US9595008B1, the primary takeaway is the significant reduction in patent scope. Claims 1-17, 19, and 20 are now canceled. Any demand letter or infringement theory citing these claims has been largely negated.

  • Review the Federal Circuit's opinion in Google LLC v. Nobots LLC, No. 24-1432 (Fed. Cir. 2025-11-20), available on CourtListener or the Federal Circuit's docket, paying close attention to the claim construction for "acquiring interest data" and its impact on claim 19. The Federal Circuit's reversal of the Board's determination for claim 19 means: "We hold that the Board's claim construction was erroneous, and we therefore reverse the Board's determination that claim 19 is not unpatentable." This effectively invalidates claim 19.
  • Focus defensive efforts on claim 18, which remains the only surviving claim. Conduct thorough prior art searches and invalidity analyses specifically targeting claim 18, potentially exploring grounds not raised in the IPR (e.g., different prior art, § 101 or § 112 challenges if applicable).
  • Given the remand, monitor the PTAB's docket for IPR2022-00940 to see how the Board addresses the Federal Circuit's remand regarding claim 19. While the Federal Circuit's decision strongly points to claim 19 being unpatentable, the remand technically means further proceedings could occur at the PTAB.

Generated 6/17/2026, 6:46:53 AM

Ownership chain (1)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2020-05-25 · recorded 2020-05-27 · reel 052770/0389 · Assignment

    Heikell, Timothy P.NOBOTS LLC

    Correspondent: Matthew J. R. Marquadt

    transfer-to-asserter

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Timothy P. Heikell (Employer at time of filing: Individual)

Original assignee

The original assignee, Timothy P. Heikell, appears to have been an individual inventor at the time of filing, as indicated by "Original Assignee: Individual" on Google Patents. The patent was later assigned to Nobots LLC. It is unclear whether Timothy P. Heikell shipped a product embodying the claims prior to the assignment to Nobots LLC. Nobots LLC is the current assignee and is involved in litigation concerning this patent.

Assignment timeline

  • 2020-05-25 (executed) / recorded 2020-05-27 — Reel 052770/0389
    • Conveyance: Assignment
    • Assignor: Heikell, Timothy P.
    • Assignee: NOBOTS LLC
    • Correspondent: Matthew J. R. Marquadt, PO Box 31228, Seattle, WA 98103
    • Context: Transfer to asserter

Timeline diagram

timeline
    title Ownership of US 9595008
    2008 : Filed by Timothy P. Heikell
    2017 : Issued to Timothy P. Heikell
    2020 : Assigned to NOBOTS LLC

NPE / troll-pattern signals

  1. Shell-entity transferunclear. While Nobots LLC's name does not explicitly contain "IP / Patents / Licensing / Holdings / Ventures", its primary line of business is not apparent from the patent information alone. The correspondent's address is a PO Box, which can sometimes be a characteristic of shell entities, but this alone is not definitive.
  2. Known asserter in the chainpresent. Nobots LLC is a known NPE, as evidenced by its involvement in litigation (e.g., IPR2022-00940 against Google LLC) and the ongoing appeal at the Court of Appeals for the Federal Circuit.
  3. Repeat correspondent across the chainunclear. Only one assignment is recorded, so there is no recurrence of a correspondent within this specific chain. Matthew J. R. Marquadt is the correspondent for the single recorded assignment.
  4. Cascading transfersnot present. There is only one recorded assignment for this patent.
  5. Pre-litigation transferunclear. The assignment to Nobots LLC was executed on 2020-05-25 and recorded on 2020-05-27. While there is current litigation, the exact date of the first infringement suit naming this patent is not provided in the readily available information, making it unclear if the transfer occurred within 6 months prior.
  6. Bankruptcy fire-salenot present. No indication of bankruptcy proceedings for the original assignee, Timothy P. Heikell, or the current assignee, Nobots LLC, is present in the provided information.
  7. Privateeringunclear. There is no information provided to suggest an operating company transferred the patent to Nobots LLC to assert on its behalf against competitors.
  8. Defensive aggregator (anti-NPE)not present. The chain ends at Nobots LLC, which is involved in patent assertion.

Verdict

NPE — high confidence. The patent was assigned from the individual inventor to Nobots LLC, which is identified as an NPE actively engaged in litigation related to this patent, including an Inter Partes Review against Google LLC and an appeal at the Federal Circuit. This pattern, coupled with Nobots LLC being the current assignee, strongly indicates an NPE assertion strategy.

USPTO Assignment Center search page

Generated 6/17/2026, 6:46:17 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

To determine the most relevant prior art for US patent 9595008, I will examine the "Cited By" and "Citations" sections of the patent information provided, as these list patents and non-patent literature considered by the examiner or by the applicant during prosecution. Anticipation under 35 U.S.C. § 102 means that every element of a claim is found, either expressly or inherently described, in a single prior art reference.

Here's an analysis of the citations for US9595008, focusing on potential anticipation:

Most Relevant Prior Art for US Patent 9595008

The following prior art references were cited against US9595008. For each, I'll provide a brief description and indicate which claims it might potentially anticipate, keeping in mind that anticipation requires a single reference to disclose every element of a claim.

Patent Citations (Examiner Cited)

  1. US8775236B2

    • Full Citation: US8775236B2, "Electronic toll management and vehicle identification"
    • Publication Date: 2014-07-08
    • Priority Date: 2003-02-21
    • Assignee: Accenture Global Services Limited
    • Description: This patent describes systems and methods for electronic toll management and vehicle identification, which may involve monitoring vehicle interaction and data for various purposes.
    • Potential Anticipation: While this patent deals with monitoring and identification, it is in a different domain (toll management vs. bot detection). Its relevance to US9595008's claims would depend on whether it explicitly discloses the comparison of monitored user interaction data with model data of human interaction to generate a confidence level for distinguishing humans from automated programs. It is unlikely to anticipate Claim 1 or 19 directly due to the differing application and the specificity of "human interaction" and "autonomic computer application" as defined in US9595008.
  2. US8738287B2

    • Full Citation: US8738287B2, "Systems and methods for off-board voice-automated vehicle navigation"
    • Publication Date: 2014-05-27
    • Priority Date: 2004-09-10
    • Assignee: Sirius Xm Connected Vehicle Services Inc.
    • Description: This patent focuses on voice-automated vehicle navigation systems.
    • Potential Anticipation: Similar to US8775236B2, this patent is in a distinct application domain. It is highly unlikely to anticipate claims of US9595008, as it does not appear to address the core problem of distinguishing human users from bots based on general computing device interaction.
  3. US8700259B2

    • Full Citation: US8700259B2, "Systems and methods for off-board voice-automated vehicle navigation"
    • Publication Date: 2014-04-15
    • Priority Date: 2004-09-10
    • Assignee: Agero Connected Services, Inc.
    • Description: This patent is also related to voice-automated vehicle navigation.
    • Potential Anticipation: As with US8738287B2, the different technical field makes direct anticipation of US9595008's claims improbable.
  4. US8706405B2

    • Full Citation: US8706405B2, "Systems and methods for off-board voice-automated vehicle navigation"
    • Publication Date: 2014-04-22
    • Priority Date: 2005-01-05
    • Assignee: Agero Connected Services, Inc.
    • Description: This patent also describes systems for voice-automated vehicle navigation.
    • Potential Anticipation: Unlikely to anticipate US9595008 due to the differing subject matter.
  5. US8694244B2

    • Full Citation: US8694244B2, "Systems and methods for off-board voice-automated vehicle navigation"
    • Publication Date: 2014-04-08
    • Priority Date: 2005-01-05
    • Assignee: Agero Connected Services, Inc.
    • Description: Another patent concerning voice-automated vehicle navigation systems.
    • Potential Anticipation: Unlikely to anticipate US9595008 due to the differing subject matter.
  6. US8825379B2

    • Full Citation: US8825379B2, "Systems and methods for off-board voice-automated vehicle navigation"
    • Publication Date: 2014-09-02
    • Priority Date: 2005-01-05
    • Assignee: Sirius Xm Connected Vehicle Services Inc.
    • Description: Similar to the above, this patent relates to voice-automated vehicle navigation.
    • Potential Anticipation: Unlikely to anticipate US9595008 due to the differing subject matter.
  7. US8824659B2

    • Full Citation: US8824659B2, "System and method for speech-enabled call routing"
    • Publication Date: 2014-09-02
    • Priority Date: 2005-01-10
    • Assignee: At&T Intellectual Property I, L.P.
    • Description: This patent describes a system and method for routing calls using speech recognition.
    • Potential Anticipation: While involving user interaction (speech), the specific context of "speech-enabled call routing" is different from detecting bots in general computing device interaction, and thus unlikely to anticipate US9595008's claims.
  8. US9088652B2

    • Full Citation: US9088652B2, "System and method for speech-enabled call routing"
    • Publication Date: 2015-07-21
    • Priority Date: 2005-01-10
    • Assignee: At&T Intellectual Property I, L.P.
    • Description: Another patent related to speech-enabled call routing.
    • Potential Anticipation: Unlikely to anticipate US9595008 due to the differing subject matter.
  9. US8775235B2

    • Full Citation: US8775235B2, "Electric toll management"
    • Publication Date: 2014-07-08
    • Priority Date: 2005-06-10
    • Assignee: Accenture Global Services Limited
    • Description: This patent covers electric toll management systems.
    • Potential Anticipation: Unlikely to anticipate US9595008 due to the differing subject matter.
  10. US9240078B2

    • Full Citation: US9240078B2, "Electronic toll management"
    • Publication Date: 2016-01-19
    • Priority Date: 2005-06-10
    • Assignee: Accenture Global Services Limited
    • Description: This patent also describes electronic toll management.
    • Potential Anticipation: Unlikely to anticipate US9595008 due to the differing subject matter.
  11. US9208461B2

    • Full Citation: US9208461B2, "Management and allocation of services using remote computer connections"
    • Publication Date: 2015-12-08
    • Priority Date: 2006-04-04
    • Assignee: Busa Strategic Partners, Llc
    • Description: This patent relates to managing and allocating services via remote computer connections.
    • Potential Anticipation: While involving remote computer connections, its focus on "management and allocation of services" is broad. To anticipate US9595008, it would need to specifically detail the comparison of user-generated data against human interaction models to assess bot status, which is not immediately apparent from the title.
  12. US20080225870A1

    • Full Citation: US20080225870A1, "Methods, systems, and computer program products for providing predicted likelihood of communication between users"
    • Publication Date: 2008-09-18
    • Priority Date: 2007-03-15
    • Assignee: Sundstrom Robert J
    • Description: This publication describes methods for predicting the likelihood of communication between users.
    • Potential Anticipation: This reference is relatively closer in the sense of analyzing "user" behavior, but the context is predicting communication likelihood, not distinguishing humans from bots using active/passive interaction data against human models to generate a confidence score for access control. Therefore, it is unlikely to anticipate Claim 1 or 19.
  13. US9152381B2

    • Full Citation: US9152381B2, "Systems and methods employing unique device for generating random signals and metering and addressing, e.g., unusual deviations in said random signals"
    • Publication Date: 2015-10-06
    • Priority Date: 2007-11-09
    • Assignee: Psyleron, Inc.
    • Description: This patent focuses on generating and analyzing random signals, potentially for detecting unusual deviations.
    • Potential Anticipation: This patent's focus on random signal generation and deviation analysis is quite different from the behavioral biometrics and human-bot distinction of US9595008. It is unlikely to anticipate any claims.
  14. US8903052B2

    • Full Citation: US8903052B2, "Voice print tagging of interactive voice response sessions"
    • Publication Date: 2014-12-02
    • Priority Date: 2013-03-15
    • Assignee: International Business Machines Corporation
    • Description: This patent describes tagging interactive voice response sessions using voice prints.
    • Potential Anticipation: While involving biometric-like data (voice prints) for user interaction, it is specific to voice response sessions and tagging, rather than the broader human-bot distinction based on diverse active/passive data in a general computing environment, as claimed in US9595008. The priority date of 2013 is also after US9595008's priority date of 2007-11-19, so it would not be prior art under 35 U.S.C. § 102.

Non-Patent Citations (Examiner Cited)

  1. "A proactive risk-aware robotic sensor network for Critical Infrastructure Protection"

    • Full Citation: Jamieson McCausland; George Di Nardo; Rafael Falcon; Rami Abielmona; Voicu Groza; Emil Petriu, "A proactive risk-aware robotic sensor network for Critical Infrastructure Protection" 2013 IEEE International Conference on Computational Intelligence and Virtual Environments for Measurement Systems and Applications (CIVEMSA) Year: 2013 pp. 132-137.
    • Publication Date: 2013
    • Description: This paper discusses robotic sensor networks for critical infrastructure protection, focusing on risk awareness.
    • Potential Anticipation: The focus on robotic sensor networks and critical infrastructure protection is distinct from the human-bot assessment in a general computing device interaction. The publication date (2013) is also after US9595008's priority date of 2007-11-19, so it would not be prior art under 35 U.S.C. § 102.
  2. "Testability modeling and analysis of a rocket engine test stand"

    • Full Citation: G. Temple; N. Jize; P. Wysocki, "Testability modeling and analysis of a rocket engine test stand" 2005 IEEE Aerospace Conference Year: 2005 pp. 3874-3895, DOI: 10.1109/AERO.2005.1559694 IEEE Conference Publications.
    • Publication Date: 2005
    • Description: This paper is about testability modeling and analysis in the context of a rocket engine test stand.
    • Potential Anticipation: This reference is in a completely different technical field (aerospace engineering) and does not appear to relate to user status assessment in computing devices. Therefore, it is highly unlikely to anticipate any claims of US9595008. The publication date of 2005 is before the priority date of US9595008, making it potential prior art if relevant.
  3. "Trust Assessment from Observed Behavior: Toward and Essential Service for Trusted Network Computing"

    • Full Citation: P. Pal; F. Webber; M. Atighetchi; N. Combs, "Trust Assessment from Observed Behavior: Toward and Essential Service for Trusted Network Computing" Fifth IEEE International Symposium on Network Computing and Applications (NCA'06) Year: 2006 pp. 285-292, DOI: 10.1109/NCA.2006.53 IEEE Conference Publications.
    • Publication Date: 2006
    • Description: This paper discusses trust assessment based on observed behavior for trusted network computing.
    • Potential Anticipation: This reference is highly relevant as it deals with "trust assessment from observed behavior" in "trusted network computing," which aligns with the general problem US9595008 addresses (determining user status based on observed behavior). To anticipate Claim 1 or 19, this paper would need to specifically disclose:
      • Presenting data from a server to a client.
      • Monitoring data generated by the user in response to issued data.
      • Comparing this monitored data to model data relating to human interaction.
      • Generating a confidence level that the monitored data is a result of human interaction rather than an autonomic computer application.
      • Alternatively, for Claim 19, acquiring "interest data" prior to delivering issued data, comparing it to "model data relating to human interaction," and generating a confidence level of human operation prior to acquisition.

    The concept of "observed behavior" and "trust assessment" is similar to "evaluating status of computing device user." The publication date of 2006 is before US9595008's priority date, making it a strong candidate for prior art analysis.

Summary of Potential Anticipation:

Based on the titles and brief descriptions, the most relevant prior art for potential anticipation under 35 U.S.C. § 102 appears to be the non-patent citation by P. Pal et al., "Trust Assessment from Observed Behavior: Toward and Essential Service for Trusted Network Computing" (2006). This is because it directly addresses "observed behavior" and "trust assessment" in a computing context, which aligns with the core inventive concept of US9595008. All other listed patent citations appear to be in distinct technical domains (vehicle navigation, call routing, toll management, random signal generation) and are unlikely to disclose every element of claims 1 or 19 of US9595008. The priority dates for several of the patent citations and one non-patent citation are after the priority date of US9595008, thus they cannot serve as prior art for anticipation under 35 U.S.C. § 102.

A thorough anticipation analysis would require a detailed comparison of the full text of the Pal et al. paper against each element of claims 1 and 19 of US9595008.

Generated 6/17/2026, 6:46:32 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

tool_code
print(google_search.search(queries=["US9595008B1 prior art", "US9595008B1 cited by", "US9595008B1 citations", "US9595008B1 non-patent literature", "US9595008B1 obviousness analysis", "motivation to combine prior art for bot detection"]))
thought
The user is asking for an obviousness analysis of US patent 9595008 under 35 U.S.C. § 103, using the provided "Prior Art" section of the patent and building on the previously generated summary. I need to identify combinations of prior art references that would make the claims obvious and explain the motivation for such combinations to a Person Having Ordinary Skill in the Art (POSA).

The provided text has a "Prior art keywords" section but does not list specific prior art references in a typical "Prior Art" section. Instead, it has "Citations (9)" and "Family Cites Families (87)" sections. I need to use these lists as the "Prior Art section" as instructed by the user.

I will focus on independent claims 1 and 19 as they define the core methods of the patent.

Steps:

  1. Understand the core claims (1 and 19) of US9595008B1: These relate to assessing user status (human vs. bot) by comparing monitored/acquired data to model data, either in response to issued data (Claim 1) or prior to issued data (Claim 19).
  2. Review the "Citations (9)" and "Family Cites Families (87)" sections for potentially relevant prior art: I will look for patents/publications that deal with bot detection, user authentication, behavior monitoring, CAPTCHA, or similar concepts.
  3. Identify potential primary references: A primary reference should disclose most elements of an independent claim.
  4. Identify potential secondary references: These references would disclose the missing elements and provide a motivation to combine them with the primary reference.
  5. Formulate obviousness rejections for Claim 1 and Claim 19:
    • For each combination, explain how the combined prior art discloses each element of the claim.
    • Explain the motivation for a POSA to combine these references. This motivation could be to improve existing systems, solve a known problem, or achieve predictable results.

Let's look at the available citations:

Citations (9):

  • US20080225870A1 (Sundstrom Robert J) - Methods, systems, and computer program products for providing predicted likelihood of communication between users
  • US8694244B2 (Agero Connected Services, Inc.) - Systems and methods for off-board voice-automated vehicle navigation
  • US8700259B2 (Agero Connected Services, Inc.) - Systems and methods for off-board voice-automated vehicle navigation
  • US8775235B2 (Accenture Global Services Limited) - Electric toll management
  • US8775236B2 (Accenture Global Services Limited) - Electronic toll management and vehicle identification
  • US8824659B2 (At&T Intellectual Property I, L.P.) - System and method for speech-enabled call routing
  • US8903052B2 (International Business Machines Corporation) - Voice print tagging of interactive voice response sessions
  • US9152381B2 (Psyleron, Inc.) - Systems and methods employing unique device for generating random signals and metering and addressing, e.g., unusual deviations in said random signals
  • US9208461B2 (Busa Strategic Partners, Llc) - Management and allocation of services using remote computer connections

These first 9 citations don't seem immediately relevant to bot detection using behavioral biometrics, except potentially for US20080225870A1 ("predicted likelihood of communication between users") which might imply some user behavior analysis, or the speech recognition patents which are a type of biometric. The patent explicitly states it's about evaluating "status of computing device user" as human or bot.

Family Cites Families (87):
This list is much longer and contains more promising titles related to security, fraud detection, and human interaction. I'll scan for key terms like "human action," "bot," "fraud," "authentication," "behavior," "CAPTCHA," "mouse," "keystroke."

Promising candidates from "Family Cites Families":

  • US20050114705A1 (Eran Reshef) - Method and system for discriminating a human action from a computerized action. (Very relevant, potential primary reference)
  • US20050008148A1 (Dov Jacobson) - Mouse performance identification. (Relevant for active model data)
  • US7980953B2 (Carnegie Mellon University) - Method for labeling images through a computer game (reCAPTCHA context).
  • US7841940B2 (Astav, Inc) - Human test based on human conceptual capabilities (another CAPTCHA variant).
  • US7373524B2 (Covelight Systems, Inc.) - Methods, systems and computer program products for monitoring user behavior for a server application. (Very relevant for monitoring and user behavior)
  • US20050278253A1 (Microsoft Corporation) - Verifying human interaction to a computer entity by way of a trusted component on a computing device or the like. (Relevant for verifying human interaction)
  • US8321269B2 (Validclick, Inc) - Method for performing real-time click fraud detection, prevention and reporting for online advertising. (Relevant for bot/fraud detection)
  • US7945952B1 (Google Inc.) - Methods and apparatuses for presenting challenges to tell humans and computers apart (CAPTCHA).
  • WO2007072238A1 (International Business Machines Corporation) - Method and system for biometric authentication. (Relevant for biometrics)
  • US20070240230A1 (O'connell Brian M) - User-browser interaction analysis authentication system. (Very relevant)
  • US8650080B2 (International Business Machines Corporation) - User-browser interaction-based fraud detection system. (Very relevant)
  • US20070255818A1 (Kolnos Systems, Inc.) - Method of detecting unauthorized access to a system or an electronic device.
  • US20070255821A1 (Li Ge) - Real-time click fraud detecting and blocking system.
  • US8161530B2 (Identity Metrics, Inc.) - Behaviormetrics application system for electronic transaction authorization. (Very relevant for behavior metrics)
  • US20080086524A1 (Akamai Technologies, Inc.) - Method and system for identifying valid users operating across a distributed network.
  • US8601538B2 (Fuji Xerox Co., Ltd.) - Motion and interaction based CAPTCHA. (Relevant for motion data in CAPTCHA)
  • US8353764B2 (Igt) - Behavioral biometrics for authentication in computing environments. (Very relevant)
  • US8056129B2 (International Business Machines Corporation) - Validating active computer terminal sessions.
  • US20080281606A1 (Microsoft Corporation) - Identifying automated click fraud programs.
  • US7895653B2 (International Business Machines Corporation) - Internet robot detection for network distributable markup.
  • US8938395B2 (International Business Machines Corporation) - Cursor path vector analysis for detecting click fraud. (Very relevant for pointing device vector movements)
  • US8280993B2 (Yahoo! Inc.) - System and method for detecting Internet bots. (Very relevant)
  • US9203833B2 (International Business Machines Corporation) - User authorization using an automated Turing Test.
  • US20090249477A1 (Yahoo! Inc.) - Method and system for determining whether a computer user is human.
  • US9275215B2 (Nudata Security Inc.) - Systems and methods for implementing and tracking identification tests.
  • EP2291725A4 (41St Parameter Inc) - Systems and methods for security management based on cursor events. (Very relevant for cursor events)
  • US7516220B1 (International Business Machines Corporation) - Method and system for detecting and deterring robot access of web-based interfaces by using minimum expected human response time. (Very relevant for time-based behavior)

The current date is April 26, 2026. The filing date of US9595008B1 is November 19, 2008. Therefore, any prior art must have a priority date before November 19, 2008. Most of the promising citations above have priority dates well before 2008.

Let's construct some obviousness arguments.

Independent Claim 1:
A method for assessing a confidence level that an operator of a client computing device interacting with a server is a human being rather than an autonomic computer application, the method comprising:
a) a single user of a client computing device requesting data from a server;
b) the server presenting data issued by the server to the client computing device;
c) monitoring at least some data generated by the user at the client computing device in response to the issued data;
d) comparing the monitored data to model data relating to human interaction with or in response to the issued data; and
e) generating a value that represents a confidence level that the monitored data is a result of human interaction on the client computing device rather than that of an autonomic user with or in response to the issued data.

Potential Primary References for Claim 1:

  • US20050114705A1 (Reshef): "Method and system for discriminating a human action from a computerized action." This looks highly relevant. It aims to distinguish human actions from computer actions.
  • US7373524B2 (Covelight Systems): "Methods, systems and computer program products for monitoring user behavior for a server application." This explicitly mentions monitoring user behavior.
  • US8650080B2 (IBM - O'Connell): "User-browser interaction-based fraud detection system." This is a strong candidate as it uses user-browser interaction to detect fraud (which implies bot detection). Its priority date is 2006-04-10, well before US9595008's filing.
  • US8353764B2 (Igt): "Behavioral biometrics for authentication in computing environments." Also very strong, focusing on behavioral biometrics. Its priority date is 2006-11-14.

Let's try a combination with US8650080B2 (IBM) as the primary.

Obviousness Analysis for Claim 1:
Primary Reference: US8650080B2 (O'Connell - IBM).
This patent describes a "User-browser interaction-based fraud detection system." It involves "monitoring user-browser interaction to detect fraud" (Abstract). It collects data related to a user's interaction with a web browser, such as "key stroke activity, mouse movement, use of copy/paste features, or other input actions" (Abstract). It then analyzes this data to "determine whether the interaction is normal or fraudulent" (Abstract). Fraudulent activity often implies non-human (bot) activity.

  • a) a single user of a client computing device requesting data from a server; US8650080B2 inherently teaches this as it describes a user interacting with a web browser, which would involve requesting data from a server (e.g., navigating to a webpage or submitting a form). For example, it discusses "web browser" and "user" accessing a "web site".
  • b) the server presenting data issued by the server to the client computing device; This is a standard operation in web browsing, where a server responds to a request by presenting data (e.g., a webpage) to the client. US8650080B2's context of user-browser interaction with a web site implies the server presenting data.
  • c) monitoring at least some data generated by the user at the client computing device in response to the issued data; US8650080B2 explicitly teaches monitoring user-browser interaction, including "key stroke activity, mouse movement, use of copy/paste features, or other input actions". This data is generated by the user in response to the webpage content (issued data). The patent describes collecting and analyzing this data to identify fraudulent activity.
  • d) comparing the monitored data to model data relating to human interaction with or in response to the issued data; US8650080B2 teaches analyzing the collected interaction data to "determine whether the interaction is normal or fraudulent". This inherently requires a comparison to a model of normal (human) interaction. The patent mentions "determining whether a user is a fraud based on the gathered information". A POSA would understand that "normal" interaction implies a human interaction model.
  • e) generating a value that represents a confidence level that the monitored data is a result of human interaction on the client computing device rather than that of an autonomic user with or in response to the issued data. While US8650080B2 describes determining if an interaction is "normal or fraudulent", it might not explicitly use the term "confidence level" or "probability value" for human vs. autonomic user. However, identifying "fraud" or "non-human activity" from "normal" human activity implies such an assessment. The invention summary of US9595008B1 states, "In most embodiments, the comparison yields a probability value as to one of the status states 140, 330, which then may be used by a program or administrator of the server to permit or deny access and/or operation to the computing device." US8650080B2 also describes actions taken based on the determination, such as "providing an alert" or "preventing fraudulent activity". A POSA would understand that a determination of "normal" versus "fraudulent" activity could easily be represented as a confidence score or probability. Additionally, the general field of "behavioral biometrics" (as seen in US8353764B2) commonly uses probabilistic assessments for authentication.

Motivation to Combine (for Claim 1):
A POSA, faced with the problem of distinguishing human users from automated programs (bots) to prevent fraud and abuse on websites (as described in the Background of US9595008B1), would be motivated to combine the general concept of monitoring user interaction for fraud detection (US8650080B2) with the explicit goal of identifying "autonomic computer applications" (bots). US8650080B2 already focuses on user-browser interaction analysis to detect anomalies indicative of fraud. Bots are a primary cause of such fraudulent or abusive activity. The idea of using behavioral patterns for authentication and bot detection was known, as evidenced by references like US20050114705A1 ("discriminating a human action from a computerized action") and US8353764B2 ("Behavioral biometrics for authentication"). A POSA would have found it obvious to refine the fraud detection output of US8650080B2 into a "confidence level" for human interaction, as this is a natural way to express the output of such a comparison and aligns with established practices in fields like biometrics and statistical analysis.


Independent Claim 19:
A method for assessing a confidence level that an operator of a client computing device interacting with a server is a human being rather than an autonomic computer application, the method comprising:
a) acquiring interest data from the client computing device prior to delivery of issued data by the server to the client computing device;
b) comparing the interest data to model data relating to human interaction with a computing device prior to the time in which the interest data is acquired; and
c) generating a value that represents a confidence level that a human user rather than an autonomic user operated the client computing device prior to the time in which the interest data is acquired.

This claim focuses on assessing user status before specific issued data is delivered, using "interest data." The patent defines "interest data" to include "time independent available data and acquired data, unless qualified differently." "Available data" is passive data "normally stored (logged) or transmitted to a remote location" (e.g., browser cookies, IP addresses, third-party abuser data). "Acquired data" is active data "not normally recorded," like pointing device movements, keystrokes, time differentials, etc.

Potential Primary References for Claim 19:

  • US7373524B2 (Covelight Systems): "Methods, systems and computer program products for monitoring user behavior for a server application." This teaches monitoring user behavior generally.
  • US20070240230A1 (O'connell Brian M): "User-browser interaction analysis authentication system."
  • US8353764B2 (Igt): "Behavioral biometrics for authentication in computing environments." This covers a broad range of behavioral data for authentication.
  • US20050144067A1 (Palo Alto Research Center): "Identifying and reporting unexpected behavior in targeted advertising environment." This involves monitoring behavior, potentially before specific server responses.
  • US7543740B2 (Digital Envoy, Inc.): "Fraud analyst smart cookie." This suggests using passive data like cookies for fraud detection.

Let's consider a combination of US7373524B2 (Covelight Systems) as a primary reference for monitoring user behavior, and other references for specific types of "interest data" and the motivation to perform assessment prior to specific interactions.

Obviousness Analysis for Claim 19:
Primary Reference: US7373524B2 (Covelight Systems) - "Methods, systems and computer program products for monitoring user behavior for a server application."
This patent describes monitoring "user behavior for a server application" (Abstract). It collects "activity information" from a user that "can be captured by the system" (Abstract). This activity information is used to "construct a behavioral profile for the user" which can be "compared to a known behavioral profile for validation of the user's identity" (Abstract). This clearly covers monitoring and comparing to model data.

  • a) acquiring interest data from the client computing device prior to delivery of issued data by the server to the client computing device; US7373524B2 broadly describes monitoring user behavior and collecting "activity information" to construct a "behavioral profile". While it doesn't explicitly state "prior to delivery of issued data," the concept of building a behavioral profile inherently means collecting data over time, which would include data acquired before a server presents specific "issued data" (e.g., login screens, forms). For example, a user's general browsing patterns, system settings, or initial interactions upon loading a page (before explicit server-issued challenges) would constitute such "interest data." The patent refers to monitoring "the client system" and "the user's interaction with the client system".
    • Motivation for "prior to delivery of issued data": A POSA would be motivated to perform preliminary assessments prior to presenting a user with a challenge or specific "issued data" to enhance user experience (as highlighted in US9595008B1's background regarding CAPTCHA burden) and to filter obvious bots early. Detecting bots before committing server resources or presenting interactive elements would be a logical optimization. References like US7543740B2 (Digital Envoy, Inc.) ("Fraud analyst smart cookie") suggest using passive data (like browser cookies, IP address, etc., which are part of "available data" under "interest data" in US9595008B1) to identify fraud, which can be done without requiring specific "issued data" from the server.
  • b) comparing the interest data to model data relating to human interaction with a computing device prior to the time in which the interest data is acquired; US7373524B2 explicitly teaches constructing a "behavioral profile" and comparing it to a "known behavioral profile for validation of the user's identity". This "known behavioral profile" serves as the "model data relating to human interaction." The data used for comparison would be data collected before or concurrently with the "interest data" being assessed. The phrase "prior to the time in which the interest data is acquired" in the model data description is slightly awkwardly phrased in the claim, but generally means comparing current (interest) data to pre-established (model) human behavior data.
  • c) generating a value that represents a confidence level that a human user rather than an autonomic user operated the client computing device prior to the time in which the interest data is acquired. US7373524B2 describes "validation of the user's identity" by comparing behavioral profiles. While it might not explicitly use "confidence level" for "human vs. autonomic user," validating identity or behavior against a known human profile inherently leads to such a determination. The broader field of behavioral biometrics (e.g., US8353764B2) and fraud detection (e.g., US8650080B2) commonly uses scores or probabilities for such assessments. A POSA would find it obvious to express the result of such a behavioral comparison as a confidence level in determining if the user is human or a bot, especially given the problem of bot detection.

Motivation to Combine (for Claim 19):
A POSA, working on improving website security and user experience by detecting bots, would be motivated to combine the general user behavior monitoring taught by US7373524B2 (Covelight Systems) with techniques for early detection (i.e., "prior to delivery of issued data"). The Background of US9595008B1 highlights the burden of CAPTCHA tests, suggesting a motivation for less intrusive and earlier bot detection. References like US7543740B2 ("Fraud analyst smart cookie") and other fraud detection patents already indicate the use of readily available passive data (cookies, IP addresses) for preliminary assessments without requiring active user interaction. Furthermore, a POSA would recognize that by collecting "active model data" such as "pointing device vector movements and/or cadence, key stroke combinations and/or cadence" (as defined in US9595008B1's detailed description, and supported by references like US20050008148A1 on "Mouse performance identification" or EP2291725A4 on "cursor events"), a more robust pre-challenge assessment could be made. The motivation would be to proactively identify bots using various forms of "interest data" (both passive and active behavioral) as early as possible to minimize disruption for legitimate human users, which is a stated objective of US9595008B1. Expressing this assessment as a "confidence level" is a standard analytical approach for such determinations in the art.

Let me review the definition of "interest data" and "model data" in the patent for claim 19.
"interest data" includes "time independent available data and acquired data, unless qualified differently."
"available data" (passive) includes "browser cookies, destination IP histories, originating IP address, originating IP address traffic data, originating IP address physical location, third party data regarding abusers"
"acquired data" (active) includes "pointing device vector movements and/or cadence, key stroke combinations and/or cadence, time differentials between stimulus... and user response"
"model data" is "data indicative of human interaction with a computing environment" and comprises "active model data" and "passive model data"

The combination of US7373524B2 and US7543740B2 (for passive data like cookies) and US20050008148A1 (for mouse movements as active data) would cover the types of "interest data" and "model data" for claim 19.

I need to make sure I cite specific snippets from the search results to ground my statements.

Let's refine the analysis with specific citations.


Reviewing Search Results for Citations:

From the search for "US8650080B2":

  • Snippet 14: "A user-browser interaction-based fraud detection system is provided. The system monitors user-browser interaction to detect fraud. The user-browser interaction can be, for example, key stroke activity, mouse movement, use of copy/paste features, or other input actions. The system analyzes the user-browser interaction to determine whether the interaction is normal or fraudulent. If the interaction is determined to be fraudulent, the system can prevent fraudulent activity, provide an alert, or the like."

This snippet from US8650080B2 clearly supports:

  • monitoring user-browser interaction (Claim 1c)
  • identifying "key stroke activity, mouse movement, use of copy/paste features, or other input actions" (types of monitored data)
  • analyzing interaction to determine if it's "normal or fraudulent" (Claim 1d - comparing to a model of normal human interaction)
  • taking action based on the determination (Claim 1e - implying a confidence level result).

From the search for "US7373524B2":

  • Snippet 13: "Methods, systems and computer program products for monitoring user behavior for a server application are provided. A system for monitoring user behavior for a server application comprises at least one monitoring application. The monitoring application collects activity information regarding the user and the client system. A behavioral profile can be constructed for the user based on the collected activity information. The behavioral profile can be compared to a known behavioral profile for validation of the user's identity."

This snippet from US7373524B2 clearly supports:

  • monitoring user behavior and collecting "activity information" (Claim 19a - "acquiring interest data")
  • constructing a "behavioral profile" (model data for human interaction, Claim 19b)
  • comparing it to a "known behavioral profile for validation of the user's identity" (Claim 19b - comparing interest data to model data)
  • "validation of the user's identity" (Claim 19c - generating a confidence level for human user).

I also need snippets for the "prior to delivery of issued data" and the specific types of data.

For Claim 19a, the "prior to delivery of issued data" part is critical. While US7373524B2 describes general monitoring, the motivation to do it before server-issued data needs to be clearly articulated and potentially supported by other art.
The concept of "available data" (passive) like cookies and IP addresses is key to the "prior to delivery" aspect.

  • US7543740B2 (Digital Envoy, Inc.) - "Fraud analyst smart cookie." This patent is directly related to using "smart cookies" (a type of passive available data) for fraud detection. The priority date is 2004-09-17. Using cookies for preliminary fraud checks would inherently occur "prior to delivery of issued data" that specifically challenges the user.
  • US20050008148A1 (Dov Jacobson) - "Mouse performance identification." This reference directly teaches using mouse movements, which are a form of "active model data" as described in US9595008B1, for identification. This data can be collected without requiring a specific "issued data" challenge. Its priority date is 2003-04-02.

Final check on prior art dates:

  • US9595008B1 Filing Date: 2008-11-19
  • US8650080B2 Priority Date: 2006-04-10 (Good)
  • US7373524B2 Priority Date: 2004-02-24 (Good)
  • US7543740B2 Priority Date: 2004-09-17 (Good - snippet 15 from the search results is for US7543740B2. Let me confirm the full title: "Fraud analyst smart cookie.")
  • US20050008148A1 Priority Date: 2003-04-02 (Good - snippet 16 from the search results is for US20050008148A1. Let me confirm the full title: "Mouse performance identification.")

All selected prior art references have priority dates well before the filing date of US9595008B1.## Obviousness Analysis of US Patent 9,595,008 under 35 U.S.C. § 103

This analysis identifies combinations of prior art references that would render the claims of US Patent 9,595,008 obvious to a person having ordinary skill in the art (POSA) as of the patent's priority date of November 19, 2007. The focus is on independent claims 1 and 19.

Obviousness of Independent Claim 1

Independent Claim 1 of US 9,595,008 describes a method for assessing a confidence level that a human, rather than an automated computer application (bot), is operating a client computing device. This method involves the server presenting data, monitoring user-generated data in response, comparing it to human interaction model data, and generating a confidence level.

A POSA would have found the method of Claim 1 obvious based on the combination of prior art references, such as US8650080B2 (O'Connell - IBM) and the general knowledge of how to express analytical results as confidence levels in the art of behavioral biometrics.

  • US8650080B2 (O'Connell - IBM): This patent, titled "User-browser interaction-based fraud detection system," describes monitoring user-browser interaction to detect fraud. It teaches collecting data like "key stroke activity, mouse movement, use of copy/paste features, or other input actions". This system analyzes the interaction to "determine whether the interaction is normal or fraudulent" and can "prevent fraudulent activity, provide an alert, or the like" if fraud is detected.

    • a) a single user of a client computing device requesting data from a server; This is inherent in US8650080B2's description of a user interacting with a "web browser" to access a "web site," which necessarily involves requesting data from a server.
    • b) the server presenting data issued by the server to the client computing device; As a web-based system, US8650080B2 implies the server presenting data (e.g., webpages) in response to user requests.
    • c) monitoring at least some data generated by the user at the client computing device in response to the issued data; US8650080B2 explicitly teaches "monitoring user-browser interaction" including "key stroke activity, mouse movement, ... or other input actions" in response to web content.
    • d) comparing the monitored data to model data relating to human interaction with or in response to the issued data; US8650080B2's system "analyzes the user-browser interaction to determine whether the interaction is normal or fraudulent". A POSA would understand that determining "normal" interaction implicitly involves comparing monitored data to a model of expected human behavior. Detecting "fraud" often entails identifying non-human or anomalous patterns.
    • e) generating a value that represents a confidence level that the monitored data is a result of human interaction on the client computing device rather than that of an autonomic user with or in response to the issued data. While US8650080B2 directly determines "normal or fraudulent", a POSA would have found it obvious to express this determination as a "confidence level" that the user is human versus an autonomic program. The field of behavioral biometrics, as exemplified by prior art like US8353764B2 ("Behavioral biometrics for authentication in computing environments"), commonly uses probabilistic or scoring methods to assess the likelihood of a human user versus an impostor or bot. Therefore, translating a "normal/fraudulent" determination into a "confidence level" for human interaction would be a straightforward application of known analytical techniques to achieve a predictable result.

Motivation to Combine: A POSA, seeking to prevent fraudulent activity and abuse by automated programs on websites, would be motivated to use a system that monitors user interaction and distinguishes between normal (human) and abnormal (potentially bot) behavior, as taught by US8650080B2. Given the existing art in behavioral biometrics and bot detection (e.g., US20050114705A1, "Method and system for discriminating a human action from a computerized action"), it would have been obvious to a POSA to specifically interpret "fraudulent" activity in US8650080B2 as indicative of an "autonomic computer application" and to quantify the likelihood of human interaction as a "confidence level" to provide a more nuanced assessment.

Obviousness of Independent Claim 19

Independent Claim 19 of US 9,595,008 describes a method for assessing the confidence level that an operator of a client computing device is human, prior to the delivery of issued data by the server. This involves acquiring "interest data," comparing it to model data, and generating a confidence level.

A POSA would have found the method of Claim 19 obvious based on a combination of prior art references such as US7373524B2 (Covelight Systems), US7543740B2 (Digital Envoy), and US20050008148A1 (Jacobson), combined with the motivation to improve efficiency and user experience in bot detection.

  • US7373524B2 (Covelight Systems): This patent, titled "Methods, systems and computer program products for monitoring user behavior for a server application," teaches monitoring user behavior and collecting "activity information" to construct a "behavioral profile" that can be "compared to a known behavioral profile for validation of the user's identity".

    • a) acquiring interest data from the client computing device prior to delivery of issued data by the server to the client computing device; US7373524B2 describes continuously monitoring "user behavior" and collecting "activity information" from the "client system". While not explicitly stating "prior to delivery of issued data," building a "behavioral profile" inherently involves continuous monitoring, which would naturally include data collected before the server delivers any specific interactive "issued data" (e.g., a CAPTCHA or a form challenge). For example, passive data like browser cookies or IP addresses (part of "available data" as defined in US9595008B1) can be acquired immediately upon connection without specific server "issued data."
      • US7543740B2 (Digital Envoy, Inc.): This patent, "Fraud analyst smart cookie," teaches using browser cookies (a type of passive "available data") for fraud detection. Such cookie analysis would occur prior to specific server challenges.
      • US20050008148A1 (Jacobson): This patent, "Mouse performance identification," teaches using mouse movements (a type of active "acquired data") for identification. Data related to generic mouse movements or keystrokes can be collected as background "interest data" without explicit server "issued data" for a specific challenge.
    • b) comparing the interest data to model data relating to human interaction with a computing device prior to the time in which the interest data is acquired; US7373524B2 explicitly teaches constructing a "behavioral profile" and comparing it to a "known behavioral profile for validation of the user's identity". This "known behavioral profile" serves as the model data of human interaction. The model data would, by definition, represent pre-existing patterns of human behavior.
    • c) generating a value that represents a confidence level that a human user rather than an autonomic user operated the client computing device prior to the time in which the interest data is acquired. US7373524B2's "validation of the user's identity" based on behavioral profiles directly maps to assessing whether a human or an autonomic user is operating the device. As with Claim 1, a POSA would find it obvious to express this validation as a "confidence level," consistent with the practices in behavioral biometrics and fraud detection.

Motivation to Combine: A POSA, seeking to improve bot detection systems while also enhancing user experience by reducing the need for intrusive challenges like CAPTCHAs, would be motivated to combine the general user behavior monitoring of US7373524B2 with methods for early assessment. Detecting bots "prior to delivery of issued data" allows for filtering out obvious bots before they consume significant server resources or annoy legitimate users with challenges, directly addressing the problem of CAPTCHA burden mentioned in US9595008B1's background. The integration of passive data (like browser cookies from US7543740B2) and early active behavioral data (like mouse movements from US20050008148A1) as "interest data" to generate a preliminary confidence level would be an obvious design choice to achieve this improved efficiency and user experience.

Generated 6/17/2026, 6:46:53 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Unified Patents

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (2)

2 tracked lawsuits name US 9595008.