DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 2/5/26 has been entered.
Status of Claims
Claims 1-5, 7-14, and 16-20 are pending in this application.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-5, 7-14, and 16-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Claims 1-5, 7-14, and 16-20 are directed to a system, method, or product, which are/is one of the statutory categories of invention. (Step 1: YES).
The Examiner has identified independent method claim 1 as the claim that represents the claimed invention for analysis and is similar to independent system claim 10 and product claim 17. Claim 1 recites the limitations of method of identifying unauthorized device by comparing reported transaction against tracked-online transaction and then updating a user’s preferences database for potential use in detecting deviation.
These limitations, under their broadest reasonable interpretation, cover performance of the limitation as certain methods of organizing human activity. Collecting online financial activities (“network telemetry”) tracked by user’s device; identifying financial activities by detecting patterns of network requests (that occur after credit card information is inserted on a web) that are triggered by online financial activities; receiving financial activity report; filtering either recurring-transaction OR card-not-present transactions; correlating reported financial activity to online financial activity tracked by the device; creating correlation record; detecting uncorrelated activity to detect unauthorized device; and taking security related action (including automatically confirming fraud and taking preventative action prior to issuing an alert), – specifically, the claim recites
“collecting network telemetry data corresponding to network traffic of one or more authorized devices including at least a first authorized device including a first telemetry tracker and a second authorized device including a second telemetry tracker, wherein the network telemetry data is collected from at least the first telemetry tracker and the second telemetry tracker;
identifying, from the collected network telemetry data, one or more financial activities on the one or more authorized devices including requests that occur after credit card information is inserted on a web form to create patterns of network requests that are triggered by online financial activities;
receiving data of one or more reported financial activities;
filtering… from the one or more reported financial activities, at least one of automated recurring transactions or transactions that do not correspond to card-not-present transactions;
correlating… the one or more reported financial activities to the identified one or more online financial activities using fuzzy matching between the one or more reported financial activities and the identified one or more online financial activities occurring in a similar time period,
wherein the fuzzy matching relies on correlations between multiple users making similar transactions to detect common patterns; creating, in a data structure, correlation records based on the correlation;
detecting… based on the correlation records in the data structure, uncorrelated activity of the one or more reported financial activities to detect an unauthorized device;
identifying… based on the detecting, that at least one of the reported financial activities was initiated by the unauthorized device; and performing… in response to the identification, a security action for the at least one of the reported financial activities that was initiated by the unauthorized device, wherein the security action includes automatically confirming fraud and taking preventative action prior to issuing an alert”, recites a fundamental economic practice, directed to mitigating risk.
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation as a fundamental economic practice or commercial or legal interactions, then it falls within the “Certain Methods of Organizing Human Activity” grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
The “at least one processor”, “network telemetry”, “authorized devices”, “a first authorized device”, “a first telemetry tracker”, “a second authorized device”, “a second telemetry tracker”, “network telemetry data”, “a data structure”, “fuzzy matching”, and “unauthorized device”, in claim 1; the additional technical element of “system”, and “physical memory”, in claim 10; and the additional technical element of “non-transitory computer-readable medium” in claim 17, are just applying generic computer components to the recited abstract limitations. The recitation of generic computer components in a claim does not necessarily preclude that claim from reciting an abstract idea. Claims 10 and 17 are also abstract for similar reasons. (Step 2A-Prong 1: YES. The claims recite an abstract idea)
This judicial exception is not integrated into a practical application. In particular, the claims recite the additional elements of: a computer such as at least one processor, authorized devices, unauthorized device, a first authorized device, a second authorized device, , and system; a storage unit such as physical memory, and non-transitory computer-readable medium; data and data types such as network telemetry data and a data structure; and software module and algorithm such as fuzzy matching, a first telemetry tracker, and a second telemetry tracker. The computer hardware/software is/are recited at a high-level of generality (i.e., as a generic processor performing a generic computer function) such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, these additional elements, when considered separately and as an ordered combination, do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea and are at a high level of generality. Therefore, claims 1, 10 and 17 are directed to an abstract idea without a practical application. (Step 2A-Prong 2: NO. The additional claimed elements are not integrated into a practical application)
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because, when considered separately and as an ordered combination, they do not add significantly more (also known as an “inventive concept”) to the exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a computer hardware amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. Accordingly, these additional elements, do not change the outcome of the analysis, when considered separately and as an ordered combination. Thus, claims 1, 10 and 17 are not patent eligible. (Step 2B: NO. The claims do not provide significantly more)
Dependent claims further define the abstract idea that is present in their respective independent claims 1, 10 and 17 and thus correspond to Certain Methods of Organizing Human Activity and hence are abstract for the reasons presented above.
Dependent claims 2, 11, and 18 disclose that one or more card-not-present financial transactions of an account and the one or more online financial activities correspond to one or more web-based financial transactions tracked in network telemetry on at least one of the one or more of the authorized devices that are authorized to perform online purchases using the account, which explains a process and description at a high level – both are abstract ideas.
Dependent claims 3, 12, and 19 disclose that reported financial activities correspond to one or more new accounts appearing on a credit report of a user and the one or more online financial activities correspond to one or more account opening activities tracked in network telemetry on at least one of the one or more authorized devices that are authorized to open new accounts on behalf of the user, which explains a process and description at a high level – both are abstract ideas.
Dependent claims 4 and 13 disclose that tracking the one or more online financial activities on at least one of the authorized devices that is authorized to perform the online financial activities, which is a description/explanation of the process at a high level and an abstract idea.
Dependent claims 5 and 14 disclose that identifying the one or more reported financial activities, which is a description/explanation of the process at a high level and an abstract idea.
Dependent claim 20 discloses that filtering, from the one or more reported financial activities, at least one of automated recurring transactions or transactions that do not correspond to card-not-present transactions, which is a description/explanation of the process at a high level and an abstract idea.
Dependent claims 7 and 16 disclose that performing the security action includes issuing an alert after taking the preventative action, which is a description/explanation of the process at a high level and an abstract idea.
Dependent claim 8 discloses that issuing the alert includes at least one of generating an alert in response to the identifying or issuing a potential fraud alert generated based on a fraud detection analysis of the one or more reported financial activities, which is a description/explanation of the process at a high level and an abstract idea.
Dependent claim 9 discloses that taking the preventative action includes at least one of placing a hold on an account or performing an automated credit freeze, which is a description/explanation of the process at a high level and an abstract idea.
Thus, the dependent claims do not include any additional elements that integrate the abstract idea into a practical application or are sufficient to amount to significantly more than the judicial exception when considered both individually and as an ordered combination. Therefore, the dependent claims are directed to an abstract idea. Thus, the claims 1-5, 7-14, and 16-20 are not patent-eligible.
Response to Arguments
Applicant's arguments filed 2/5/26 have been fully considered but they are not persuasive.
In response to applicant's argument that:
“35 U.S.C. § 101… Applicant has amended each independent claim to clarify a technical solution to a technical problem, tying the claims to elements that achieve certain technical benefits, as outlined in the as-filed specification,”
the examiner respectfully disagrees. In comparison to the prior version, the added elements (see underlined) and deleted elements (if any, struck out with a line) are essentially:
(1) “identifying, from the collected network telemetry data, one or more financial activities on the one or more authorized devices including requests that occur after credit card information is inserted on a web form to create ”; and
(2) “wherein the security action includes automatically confirming fraud and taking preventative action prior to issuing an alert”.
These changes are not sufficient to overcome the 35 U.S.C. § 101 rejections because: for 101 analysis purpose, this is just stating (corresponding to the numberings above):
an explanation of what data can include (i.e., those occur after credit card is inserted on a web form), this is just data definition – an abstract idea; and
an explanation of what security action can included (i.e., confirming fraud and taking preventative action), this is a procedure – another abstract idea.
These are abstract ideas. There is nothing technical about it.
In response to applicant's argument that:
“The amended claims also recite identifying financial activities by detecting requests that occur after credit card information is inserted on a web form, and creating patterns that enable purchase detection even when telemetry is collected without browser-extension visibility. This provides a specific improvement in how the system recognizes transactions in network traffic,”
the examiner respectfully disagrees. Gathering information after credit card information is inserted on a web form is a business idea. This is not technological innovation. It is not patentable.
In response to applicant's argument that:
“The claims further recite targeted filtering to enable telemetry correlation, including filtering automated recurring transactions and transactions that do not correspond to card-not present transactions… the claims recite fuzzy matching that relies on correlations to detect common patterns, which can eliminate spurious correlations,”
the examiner respectfully disagrees. This is just data processing according to a business goals. As stated in the prior office action (regarding the filtering process):
“This is a business process (removing recurring transactions and card-not-present transactions) carried out by “generic computer”. There is no technological improvement”.
In response to applicant's argument that:
“amended claims recite automatic fraud confirmation and preventative Action,”
the examiner respectfully disagrees. Again, this is just an explanation of what security action can included (i.e., confirming fraud and taking preventative action), this is a procedure – another abstract idea.
In response to applicant's argument that:
“practical application… The present claims do so by reciting a specific improvement to network fraud detection and security,”
the examiner respectfully disagrees. There is no technological improvement. Processing data to detect a pattern is not a technological improvement. The examiner has also determined that this judicial exception is not integrated into a practical application. In particular, the claims’ technical elements (e.g., the at least one processor, authorized devices, unauthorized device, a first authorized device, a second authorized device, etc.) when considered separately and as an ordered combination, do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea and are at a high level of generality. See Claim Rejections - 35 USC § 101 above.
In response to applicant's argument that:
“example, amended claim 1 recites "performing, by the at least one processor in response to the identification, a security action for the at least one of the reported financial activities that was initiated by the unauthorized device, wherein the security action includes automatically confirming fraud and taking preventative action prior to issuing an alert," which can achieve fraud confirmation more rapidly and avoid the delays of requiring customer interaction,”
the examiner respectfully disagrees. Again, this is just an explanation of what security action can included (i.e., confirming fraud and taking preventative action), this is a procedure – another abstract idea.
In response to applicant's argument that:
“technological mechanisms that improve the functioning of the computer-network security system and endpoint telemetry processing (e.g., pattern-based purchase recognition without full browser visibility, multi-user correlation techniques that eliminate spurious matches, automated confirmation workflows,”
the examiner respectfully disagrees. Again, processing multiple data points to detect a pattern is not a technological improvement.
In response to applicant's argument that:
“significantly more… The claim recites a non-conventional, non-generic arrangement of components and operations (e.g., multi-layer telemetry capture (browser/VPN), post-credit-card-form request patterning, a fuzzy matching technique that can eliminate spurious correlations, correlation records driving automated actions) that are all expressly disclosed as improvements to computer operation and security workflows,”
the examiner respectfully disagrees. The decision to capture browser and VPN data is a business decision. Similarly, the post-credit-card-form requesting timing is also a business decision. There is simply no technological innovation.
The fuzzy matching technique is mentioned at a high level. As stated in the prior office action:
“Applying an algorithm (fuzzy matching) by using generic computer is not patentable under 35 U.S.C. § 101”.
The examiner has determined that the claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because, when considered separately and as an ordered combination, they do not add significantly more (also known as an “inventive concept”) to the exception. See Claim Rejections - 35 USC § 101 above. The additional element of using a computer hardware amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MARK H GAW whose telephone number is (571)270-0268. The examiner can normally be reached Mon-Fri: 9am -5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Mike Anderson can be reached on 571 270-0508. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MARK H GAW/Examiner, Art Unit 3693