Prosecution Insights
Last updated: October 02, 2026
Application No. 17/967,667

TRANSACTION AUTHENTICATION SYSTEMS AND METHODS

Final Rejection §101
Filed
Oct 17, 2022
Priority
Nov 07, 2017 — continuation of 11/042,845 +1 more
Examiner
HUDSON, MARLA LAVETTE
Art Unit
3694
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Mastercard International Incorporated
OA Round
8 (Final)
56%
Grant Probability
Moderate
9-10
OA Rounds
0m
Est. Remaining
79%
With Interview

Examiner Intelligence

Grants 56% of resolved cases
56%
Career Allowance Rate
66 granted / 119 resolved
+3.5% vs TC avg
Strong +24% interview lift
Without
With
+23.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
18 currently pending
Career history
148
Total Applications
across all art units

Statute-Specific Performance

§101
47.8%
+7.8% vs TC avg
§103
29.1%
-10.9% vs TC avg
§102
5.6%
-34.4% vs TC avg
§112
13.8%
-26.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 119 resolved cases

Office Action

§101
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims The following is Office Action on the merits in response to the communication received on 8/5/26. Claim status: Amended claims: 21-26, 28-29, 31-32, 34-36, 38-39 and 41 Canceled claims: 1-20, 27, 37 and 40 Added New claims: 42-43 Pending claims: 21-26, 28-36, 38-39 and 41-43 Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 21-26, 28-36, 38-39 and 41-43 are rejected under 35 U.S.C. § 101 because the claimed invention is not directed to statutory subject matter. Specifically, the invention of claims 21-26, 28-36, 38-39 and 41-43 is directed to an abstract idea without significantly more. Independent claims 21, 28 and 35 are directed to a system (claim 21), a method (claim 28) and at least one first non-transitory computer-readable storage medium (claim 35). Therefore on its face, each of claims 21, 28 and 35 are directed to a statutory category of invention under Step 1 of the 2019 PEG. However each of claims 21, 28 and 35 are also directed to an abstract idea without significantly more, under Step 2A (Prong One and Prong Two) and Step 2B of the 2019 PEG, which is a judicial exception to 35 U.S.C. 101, as detailed below. Using the language of independent claim 21 to illustrate the claim recites the limitations of, (i) enhancing computer security, (ii) to exchange data messages associated with direct electronic transactions, including automated clearing house (ACH) transactions (iii) providing access (iv) wherein the computer application causes display of an interactive user interface; (v) receive, over Internet communication from the computer application executing, an authentication request for processing a direct electronic transaction initiated by a candidate payor previously inputting an account identifier associated with a candidate payor account into the computer application executing, the direct electronic transaction including instructions for a direct transfer of funds from the candidate payor account to a payee account, the authentication request including the account identifier, a transaction amount, and device information; (vi) apply a decisioning computer model to the device information and account data associated with the account identifier to output a risk score for the initiated direct electronic transaction, the risk score representing a likelihood that the candidate payor is a legitimate payor; in response to the outputted risk score not satisfying a threshold level and thereby indicating that the candidate payor initiating the direct electronic transaction is likely not the legitimate payor, electronically verify the candidate payor by:(i) generating, using a secure protocol and the account data, an authentication challenge including at least one of a code or an authentication challenge question, the authentication challenge generated to confirm that the candidate payor who initiated the direct electronic transaction is the legitimate payor;(ii) causing display of the authentication challenge, the authentication challenge prompting the candidate payor to respond to the authentication challenge by inputting at least one of (a) the code into the computer application executing, or (b) a challenge response to the authentication challenge question into the computer application executing; (iii) receiving, over the Internet communication, at least one of (a) the code, or (b) the challenge response;(iv) authenticating, using at least one of a set of authentication rules or modules, at least one of the code or the challenge response based on the account data, the authenticating comprising (a) confirming the candidate payor as the legitimate payor and (b) authenticating the direct electronic transaction including verifying that the candidate payor account includes funds greater than the transaction amount based on the account data; and(v) generating a first authentication response message by embedding in the first authentication response message a first indicator indicating the determination that the direct electronic transaction as authenticated; in response to the outputted risk score satisfying the threshold level and thereby indicating that the candidate payor initiating the direct electronic transaction is likely the legitimate payor:(i) bypass the verification of the candidate payor as the legitimate payor; (ii) determine that the direct electronic transaction as authenticated based on the risk score including verifying that the candidate payor account includes the funds greater than the transaction amount based on the account data; and (iii) generate a second authentication response message by embedding in the second authentication response message a second indicator indicating that the direct electronic transaction is authenticated without further authentication; and (vii) in response to authenticating the direct electronic transaction, (i) approve the direct electronic transaction on behalf of an issuer of the candidate payor account, and (ii) transmit a first data message, the first data message indicating that the direct electronic transaction has been approved; (viii) in response to authenticating the direct electronic transaction, complete the direct electronic transaction by exchanging a set of the data messages under the broadest reasonable interpretation (BRI) covers methods of organizing human activity – fundamental economic principles or practices - mitigating risk but for the recitation of generic computers and generic computer components. (Independent claims 28 and 35 recite similar limitations and the analysis is the same). That is, other than reciting an authentication computing system, computer networks, a computer network, registered payor computing devices, registered payee computing devices, an authentication computing device, a communication interface, at least one processor, a memory, a first registered payee computing device, a first registered payor computing device, a second registered payor computing device and a second registered payee computing device nothing in the claim precludes the steps from being directed to organizing human activity – fundamental economic principles or practices - mitigating risk. If a claim limitation under its BRI, covers methods of organizing human activity but for the recitation of generic computers, then the limitations fall within the “methods of organizing human activity” grouping of abstract ideas. Therefore, claim 21 recites an abstract idea under Step 2A Prong One of the Revised Patent Subject Matter Eligibility Guidance 84 Fed.Reg 50 (“2019 PEG”). These “methods of organizing human activity” are not integrated into a practical application under Step 2A prong Two of the 2019 PEG. In particular claim 21 recites the following additional elements of, an authentication computing system, computer networks, a computer network, registered payor computing devices, registered payee computing devices, an authentication computing device, a communication interface, at least one processor, a memory, a first registered payee computing device, a first registered payor computing device, a second registered payor computing device and a second registered payee computing device. This judicial exception is not integrated into a practical application. In particular, the claim only recites the additional elements – an authentication computing system, computer networks, a computer network, registered payor computing devices, registered payee computing devices, an authentication computing device, a communication interface, at least one processor, a memory, a first registered payee computing device, a first registered payor computing device, a second registered payor computing device and a second registered payee computing device. The authentication computing system, computer networks, computer network, registered payor computing devices, registered payee computing devices, authentication computing device, communication interface, at least one processor, memory, first registered payee computing device, first registered payor computing device, second registered payor computing device and second registered payee computing device are recited at a high-level or generality (i.e. as a generic computer performing generic computer functions) such that, they amount to no more than instructions to apply the abstract idea with a computer (see MPEP 2106.05(h). Accordingly these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims are directed to an abstract idea. Under Step 2B of the 2019 PEG independent claim 21 does not include additional elements that are sufficient to amount to significantly more than the abstract idea. The claim(s) do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of using an authentication computing system, computer networks, a computer network, registered payor computing devices, registered payee computing devices, an authentication computing device, a communication interface, at least one processor, a memory, a first registered payee computing device, a first registered payor computing device, a second registered payor computing device and a second registered payee computing device, enhancing computer security, to exchange data messages associated with direct electronic transactions, including automated clearing house (ACH) transactions, providing access, wherein the computer application causes display of an interactive user interface; receive, over Internet communication from the computer application executing, an authentication request for processing a direct electronic transaction initiated by a candidate payor previously inputting an account identifier associated with a candidate payor account into the computer application executing, the direct electronic transaction including instructions for a direct transfer of funds from the candidate payor account to a payee account, the authentication request including the account identifier, a transaction amount, and device information; apply a decisioning computer model to the device information and account data associated with the account identifier to output a risk score for the initiated direct electronic transaction, the risk score representing a likelihood that the candidate payor is a legitimate payor; in response to the outputted risk score not satisfying a threshold level and thereby indicating that the candidate payor initiating the direct electronic transaction is likely not the legitimate payor, electronically verify the candidate payor by:(i) generating, using a secure protocol and the account data, an authentication challenge including at least one of a code or an authentication challenge question, the authentication challenge generated to confirm that the candidate payor who initiated the direct electronic transaction is the legitimate payor;(ii) causing display of the authentication challenge, the authentication challenge prompting the candidate payor to respond to the authentication challenge by inputting at least one of (a) the code into the computer application executing, or (b) a challenge response to the authentication challenge question into the computer application executing; (iii) receiving, over the Internet communication, at least one of (a) the code, or (b) the challenge response;(iv) authenticating, using at least one of a set of authentication rules or modules, at least one of the code or the challenge response based on the account data, the authenticating comprising (a) confirming the candidate payor as the legitimate payor and (b) authenticating the direct electronic transaction including verifying that the candidate payor account includes funds greater than the transaction amount based on the account data; and(v) generating a first authentication response message by embedding in the first authentication response message a first indicator indicating the determination that the direct electronic transaction as authenticated; in response to the outputted risk score satisfying the threshold level and thereby indicating that the candidate payor initiating the direct electronic transaction is likely the legitimate payor:(i) bypass the verification of the candidate payor as the legitimate payor; (ii) determine that the direct electronic transaction as authenticated based on the risk score including verifying that the candidate payor account includes the funds greater than the transaction amount based on the account data; and (iii) generate a second authentication response message by embedding in the second authentication response message a second indicator indicating that the direct electronic transaction is authenticated without further authentication; and in response to authenticating the direct electronic transaction, (i) approve the direct electronic transaction on behalf of an issuer of the candidate payor account, and (ii) transmit a first data message, the first data message indicating that the direct electronic transaction has been approved; in response to authenticating the direct electronic transaction, complete the direct electronic transaction by exchanging a set of the data messages, amount to instructions to apply the abstract idea with a computer. The claims are not patent eligible. The dependent claims have been given the full two part analysis including analyzing the additional limitations both individually and in combination. The Dependent claim(s) when analyzed individually are also held to be patent ineligible under 35 U.S.C. 101 because for the same reasoning as above and the additional recited limitation(s) fail to establish that the claim(s) are not directed to an abstract idea. The additional limitations of the dependent claim(s) when considered individually do not amount to significantly more than the abstract idea. Claims 22-26, 29-34, 36, 38-39 and 41-43 merely further explain the abstract idea. When viewed individually the additional limitations do not amount to a claim as a whole that is significantly more than the abstract idea. Accordingly claims 21-26, 28-36, 38-39 and 41-43 are ineligible. Response to Arguments Applicant's arguments filed 8/5/26 have been fully considered but they are not persuasive. The Applicant states “The pending claims are not directed to an abstract idea” (page 16), that “the claimed invention effects an improvement in computer functionality by enabling a distributed authentication process that cannot be performed by a single generic computer acting alone” (page 17), and that “the claims are directed to improving computer security of computer networks configured to process direct electronic transactions, rather than to a fundamental economic practice” (page 17). The Examiner disagrees with these sentences because the claims are an improvement of the abstract idea only. They are a business solution to the business problem of processing direct electronic transactions (e.g., ACH transactions). The applicant has not shown how the claims improve a computer or other technology, invoke a particular machine, transform matter, or provide more than a general link between the abstraction and the technology, MPEP 2106.05(a)-(c) & (e). The Examiner disagrees that “the pending claims include additional technical elements, outside any alleged abstract idea, that enable the claimed system to overcome the technical limitations of conventional computing systems that process direct electronic transactions” (page 19). The claimed invention operates in a conventional manner to verify the payor’s identity. The separate devices used for authentication and funds verification purposes operate in a conventional manner without any technical improvements being made to the generic, conventional devices. The Examiner disagrees that “the pending claims clearly recite more than well-understood, routine, or conventional activities, at least with respect to improvement of legacy direct electronic transaction networks, such as ACH networks” (page 19). The claims do not provide an improvement over prior systems and only add details to the abstract idea. The “wherein” clause only specifies what the network is configured to do (basically every computer dealing with payments does this). The claims do not address a problem particular to computer networks and merely apply the abstract idea on general computer components. The amended claims make the abstract idea more specific, and using separate devices for authentication and funds verification purposes when processing direct electronic transactions is not an unconventional activity. Applicant’s remarks about why these limitations provide a practical application fail to surface any technical improvement identified in the specification. Therefore this is not an inventive concept and significantly more. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MARLA HUDSON whose telephone number is (571)272-1063. The examiner can normally be reached M-F 9:30 a.m. - 5:30 p.m. ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bennett Sigmond can be reached at (303) 297-4411. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /M.H./Examiner, Art Unit 3694 /BENNETT M SIGMOND/Supervisory Patent Examiner, Art Unit 3694
Read full office action

Prosecution Timeline

Show 29 earlier events
Feb 23, 2026
Response after Non-Final Action
Mar 23, 2026
Request for Continued Examination
Mar 24, 2026
Response after Non-Final Action
Apr 06, 2026
Non-Final Rejection mailed — §101
Jul 14, 2026
Examiner Interview Summary
Jul 14, 2026
Applicant Interview (Telephonic)
Aug 05, 2026
Response Filed
Sep 25, 2026
Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12749059
SYSTEM AND PROCESS FOR ELECTRONIC PAYMENTS
2y 9m to grant Granted Sep 29, 2026
Patent 12699982
CONTACTLESS IDENTIFICATION AND PAYMENT
3y 2m to grant Granted Aug 04, 2026
Patent 12561744
DIFFERENTIAL EVOLUTION ALGORITHM TO ALLOCATE RESOURCES
1y 6m to grant Granted Feb 24, 2026
Patent 12530723
Optimization and Prioritization of Account Directed Distributions in an Asset Management System
1y 10m to grant Granted Jan 20, 2026
Patent 12469033
SERVICES FOR ENTITY TRUST CONVEYANCES
3y 0m to grant Granted Nov 11, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

9-10
Expected OA Rounds
56%
Grant Probability
79%
With Interview (+23.6%)
2y 8m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 119 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month