DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
The following is Office Action on the merits in response to the communication received on 8/5/26.
Claim status:
Amended claims: 21-26, 28-29, 31-32, 34-36, 38-39 and 41
Canceled claims: 1-20, 27, 37 and 40
Added New claims: 42-43
Pending claims: 21-26, 28-36, 38-39 and 41-43
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 21-26, 28-36, 38-39 and 41-43 are rejected under 35 U.S.C. § 101 because the claimed invention is not directed to statutory subject matter. Specifically, the invention of claims 21-26, 28-36, 38-39 and 41-43 is directed to an abstract idea without significantly more.
Independent claims 21, 28 and 35 are directed to a system (claim 21), a method (claim 28) and at least one first non-transitory computer-readable storage medium (claim 35). Therefore on its face, each of claims 21, 28 and 35 are directed to a statutory category of invention under Step 1 of the 2019 PEG. However each of claims 21, 28 and 35 are also directed to an abstract idea without significantly more, under Step 2A (Prong One and Prong Two) and Step 2B of the 2019 PEG, which is a judicial exception to 35 U.S.C. 101, as detailed below. Using the language of independent claim 21 to illustrate the claim recites the limitations of, (i) enhancing computer security, (ii) to exchange data messages associated with direct electronic transactions, including automated clearing house (ACH) transactions (iii) providing access (iv) wherein the computer application causes display of an interactive user interface; (v) receive, over Internet communication from the computer application executing, an authentication request for processing a direct electronic transaction initiated by a candidate payor previously inputting an account identifier associated with a candidate payor account into the computer application executing, the direct electronic transaction including instructions for a direct transfer of funds from the candidate payor account to a payee account, the authentication request including the account identifier, a transaction amount, and device information; (vi) apply a decisioning computer model to the device information and account data associated with the account identifier to output a risk score for the initiated direct electronic transaction, the risk score representing a likelihood that the candidate payor is a legitimate payor; in response to the outputted risk score not satisfying a threshold level and thereby indicating that the candidate payor initiating the direct electronic transaction is likely not the legitimate payor, electronically verify the candidate payor by:(i) generating, using a secure protocol and the account data, an authentication challenge including at least one of a code or an authentication challenge question, the authentication challenge generated to confirm that the candidate payor who initiated the direct electronic transaction is the legitimate payor;(ii) causing display of the authentication challenge, the authentication challenge prompting the candidate payor to respond to the authentication challenge by inputting at least one of (a) the code into the computer application executing, or (b) a challenge response to the authentication challenge question into the computer application executing; (iii) receiving, over the Internet communication, at least one of (a) the code, or (b) the challenge response;(iv) authenticating, using at least one of a set of authentication rules or modules, at least one of the code or the challenge response based on the account data, the authenticating comprising (a) confirming the candidate payor as the legitimate payor and (b) authenticating the direct electronic transaction including verifying that the candidate payor account includes funds greater than the transaction amount based on the account data; and(v) generating a first authentication response message by embedding in the first authentication response message a first indicator indicating the determination that the direct electronic transaction as authenticated; in response to the outputted risk score satisfying the threshold level and thereby indicating that the candidate payor initiating the direct electronic transaction is likely the legitimate payor:(i) bypass the verification of the candidate payor as the legitimate payor; (ii) determine that the direct electronic transaction as authenticated based on the risk score including verifying that the candidate payor account includes the funds greater than the transaction amount based on the account data; and (iii) generate a second authentication response message by embedding in the second authentication response message a second indicator indicating that the direct electronic transaction is authenticated without further authentication; and (vii) in response to authenticating the direct electronic transaction, (i) approve the direct electronic transaction on behalf of an issuer of the candidate payor account, and (ii) transmit a first data message, the first data message indicating that the direct electronic transaction has been approved; (viii) in response to authenticating the direct electronic transaction, complete the direct electronic transaction by exchanging a set of the data messages under the broadest reasonable interpretation (BRI) covers methods of organizing human activity – fundamental economic principles or practices - mitigating risk but for the recitation of generic computers and generic computer components. (Independent claims 28 and 35 recite similar limitations and the analysis is the same).
That is, other than reciting an authentication computing system, computer networks, a computer network, registered payor computing devices, registered payee computing devices, an authentication computing device, a communication interface, at least one processor, a memory, a first registered payee computing device, a first registered payor computing device, a second registered payor computing device and a second registered payee computing device nothing in the claim precludes the steps from being directed to organizing human activity – fundamental economic principles or practices - mitigating risk. If a claim limitation under its BRI, covers methods of organizing human activity but for the recitation of generic computers, then the limitations fall within the “methods of organizing human activity” grouping of abstract ideas. Therefore, claim 21 recites an abstract idea under Step 2A Prong One of the Revised Patent Subject Matter Eligibility Guidance 84 Fed.Reg 50 (“2019 PEG”).
These “methods of organizing human activity” are not integrated into a practical application under Step 2A prong Two of the 2019 PEG. In particular claim 21 recites the following additional elements of, an authentication computing system, computer networks, a computer network, registered payor computing devices, registered payee computing devices, an authentication computing device, a communication interface, at least one processor, a memory, a first registered payee computing device, a first registered payor computing device, a second registered payor computing device and a second registered payee computing device. This judicial exception is not integrated into a practical application. In particular, the claim only recites the additional elements – an authentication computing system, computer networks, a computer network, registered payor computing devices, registered payee computing devices, an authentication computing device, a communication interface, at least one processor, a memory, a first registered payee computing device, a first registered payor computing device, a second registered payor computing device and a second registered payee computing device.
The authentication computing system, computer networks, computer network, registered payor computing devices, registered payee computing devices, authentication computing device, communication interface, at least one processor, memory, first registered payee computing device, first registered payor computing device, second registered payor computing device and second registered payee computing device are recited at a high-level or generality (i.e. as a generic computer performing generic computer functions) such that, they amount to no more than instructions to apply the abstract idea with a computer (see MPEP 2106.05(h). Accordingly these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims are directed to an abstract idea.
Under Step 2B of the 2019 PEG independent claim 21 does not include additional elements that are sufficient to amount to significantly more than the abstract idea. The claim(s) do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of using an authentication computing system, computer networks, a computer network, registered payor computing devices, registered payee computing devices, an authentication computing device, a communication interface, at least one processor, a memory, a first registered payee computing device, a first registered payor computing device, a second registered payor computing device and a second registered payee computing device, enhancing computer security, to exchange data messages associated with direct electronic transactions, including automated clearing house (ACH) transactions, providing access, wherein the computer application causes display of an interactive user interface; receive, over Internet communication from the computer application executing, an authentication request for processing a direct electronic transaction initiated by a candidate payor previously inputting an account identifier associated with a candidate payor account into the computer application executing, the direct electronic transaction including instructions for a direct transfer of funds from the candidate payor account to a payee account, the authentication request including the account identifier, a transaction amount, and device information; apply a decisioning computer model to the device information and account data associated with the account identifier to output a risk score for the initiated direct electronic transaction, the risk score representing a likelihood that the candidate payor is a legitimate payor; in response to the outputted risk score not satisfying a threshold level and thereby indicating that the candidate payor initiating the direct electronic transaction is likely not the legitimate payor, electronically verify the candidate payor by:(i) generating, using a secure protocol and the account data, an authentication challenge including at least one of a code or an authentication challenge question, the authentication challenge generated to confirm that the candidate payor who initiated the direct electronic transaction is the legitimate payor;(ii) causing display of the authentication challenge, the authentication challenge prompting the candidate payor to respond to the authentication challenge by inputting at least one of (a) the code into the computer application executing, or (b) a challenge response to the authentication challenge question into the computer application executing; (iii) receiving, over the Internet communication, at least one of (a) the code, or (b) the challenge response;(iv) authenticating, using at least one of a set of authentication rules or modules, at least one of the code or the challenge response based on the account data, the authenticating comprising (a) confirming the candidate payor as the legitimate payor and (b) authenticating the direct electronic transaction including verifying that the candidate payor account includes funds greater than the transaction amount based on the account data; and(v) generating a first authentication response message by embedding in the first authentication response message a first indicator indicating the determination that the direct electronic transaction as authenticated; in response to the outputted risk score satisfying the threshold level and thereby indicating that the candidate payor initiating the direct electronic transaction is likely the legitimate payor:(i) bypass the verification of the candidate payor as the legitimate payor; (ii) determine that the direct electronic transaction as authenticated based on the risk score including verifying that the candidate payor account includes the funds greater than the transaction amount based on the account data; and (iii) generate a second authentication response message by embedding in the second authentication response message a second indicator indicating that the direct electronic transaction is authenticated without further authentication; and in response to authenticating the direct electronic transaction, (i) approve the direct electronic transaction on behalf of an issuer of the candidate payor account, and (ii) transmit a first data message, the first data message indicating that the direct electronic transaction has been approved; in response to authenticating the direct electronic transaction, complete the direct electronic transaction by exchanging a set of the data messages, amount to instructions to apply the abstract idea with a computer. The claims are not patent eligible.
The dependent claims have been given the full two part analysis including analyzing the additional limitations both individually and in combination. The Dependent claim(s) when analyzed individually are also held to be patent ineligible under 35 U.S.C. 101 because for the same reasoning as above and the additional recited limitation(s) fail to establish that the claim(s) are not directed to an abstract idea. The additional limitations of the dependent claim(s) when considered individually do not amount to significantly more than the abstract idea. Claims 22-26, 29-34, 36, 38-39 and 41-43 merely further explain the abstract idea.
When viewed individually the additional limitations do not amount to a claim as a whole that is significantly more than the abstract idea. Accordingly claims 21-26, 28-36, 38-39 and 41-43 are ineligible.
Response to Arguments
Applicant's arguments filed 8/5/26 have been fully considered but they are not persuasive.
The Applicant states “The pending claims are not directed to an abstract idea” (page 16), that “the claimed invention effects an improvement in computer functionality by enabling a distributed authentication process that cannot be performed by a single generic computer acting alone” (page 17), and that “the claims are directed to improving computer security of computer networks configured to process direct electronic transactions, rather than to a fundamental economic practice” (page 17). The Examiner disagrees with these sentences because the claims are an improvement of the abstract idea only. They are a business solution to the business problem of processing direct electronic transactions (e.g., ACH transactions). The applicant has not shown how the claims improve a computer or other technology, invoke a particular machine, transform matter, or provide more than a general link between the abstraction and the technology, MPEP 2106.05(a)-(c) & (e). The Examiner disagrees that “the pending claims include additional technical elements, outside any alleged abstract idea, that enable the claimed system to overcome the technical limitations of conventional computing systems that process direct electronic transactions” (page 19). The claimed invention operates in a conventional manner to verify the payor’s identity. The separate devices used for authentication and funds verification purposes operate in a conventional manner without any technical improvements being made to the generic, conventional devices. The Examiner disagrees that “the pending claims clearly recite more than well-understood, routine, or conventional activities, at least with respect to improvement of legacy direct electronic transaction networks, such as ACH networks” (page 19). The claims do not provide an improvement over prior systems and only add details to the abstract idea. The “wherein” clause only specifies what the network is configured to do (basically every computer dealing with payments does this). The claims do not address a problem particular to computer networks and merely apply the abstract idea on general computer components. The amended claims make the abstract idea more specific, and using separate devices for authentication and funds verification purposes when processing direct electronic transactions is not an unconventional activity. Applicant’s remarks about why these limitations provide a practical application fail to surface any technical improvement identified in the specification. Therefore this is not an inventive concept and significantly more.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MARLA HUDSON whose telephone number is (571)272-1063. The examiner can normally be reached M-F 9:30 a.m. - 5:30 p.m. ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bennett Sigmond can be reached at (303) 297-4411. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/M.H./Examiner, Art Unit 3694
/BENNETT M SIGMOND/Supervisory Patent Examiner, Art Unit 3694