DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to applicant's communication of January 23, 2026. The rejections are stated below. Claims 1-14 and 21-26 are pending and have been examined.
Response to Arguments
Applicant’s arguments concerning claims 1-14 and 21-26 rejected under 35 U.S.C. 101 have been considered and are persuasive so therefore the rejection has been withdrawn. The claims solve a technical problem of enabling secure service authorization close physical interaction. The claim improves computer network security by requiring multifactor authentication,
Claim Rejections – 35 USC 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that
form the rejections under this section made in this Office action.
A person shall be entitled to a patent unless -
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-5, 7-8, 11-14, and 21-25 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Brandli et al. [US Pub No. 2009/0121829 A1].
Regarding claim 1, Brandli discloses a method comprising:
receiving, by a service facilitation data processing system from an account holder
user device, a service request including identification of an automated service machine
(ASM) and a service to be provided by the ASM, the account holder user device being
associated with a card account and a card account vicinity card (Abstract, 0002-0003, 0018), wherein the ASM
comprises:
a network interface connecting the ASM to a computing network that
includes the service facilitation data processing system, a wireless communication protocol reader, and machinery for performing the service (Abstract, 0006, 0018, 0020, 0042, 0045);
transmitting, by the service facilitation data processing system to the ASM, a
service request notification including a card account identifier associated with the vicinity card and requested service information (Abstract, 0018, 0020);
receiving, by the service facilitation data processing system from the ASM, card
authentication information including an encrypted authentication block received by the
ASM from a presented vicinity card via the wireless communication protocol reader (0018);
verifying, by the service facilitation data processing system using the card
authentication information, that the presented vicinity card is the card account vicinity
card (0006, 0018), wherein the action of verifying comprises: determining a card-unique encryption key for the vicinity card, constructing a transaction-unique session key using the card-unique encryption key, and decrypting the encrypted authentication block (0006, 0011, 0015, 0018);
determining, by the service facilitation data processing system, a service
authorization result for the requested service (Abstract, 0018, 0042); and
transmitting, by the service facilitation data processing system to the ASM, a
control signal that activates the machinery to execute performance of the service based on the service authorization result indicating that the service is authorized (Abstract, 0018, 0042). Claim 11 is directed to a “service facilitation data processing system” that performs the method of claim 1 and is rejected for the same reasons as claim 1. Claim 21 is directed to a “non-transitory computer-readable storage medium having executable instructions stored thereon, which when executed by a processing circuit, cause the processing circuit to” perform the method of claim 1 and is rejected for the same reasons as claim 1.
Regarding claim 2, Brandli discloses the method of claim 1, wherein the action of
transmitting a service request notification is carried out after the action of receiving card
authentication information.
Regarding claim 3, Brandli discloses the method of claim 1, wherein the action
of determining a service authorization result includes at least one of the set consisting of
verifying an account parameter status for the card account meets predetermined
requirements for the requested service, verifying that the card account is authorized for the requested service, and verifying that the account holder user device is associated with a user who is authorized to request the requested service (0018).
Regarding claim 4, Brandli discloses the method of claim 1, wherein the action
of determining a service authorization result includes:
transmitting, to the account holder user device, a request for at least one
secondary authentication credential;
receiving, from the account holder user device, the at least one secondary
authentication credential; and
determining the service authorization result, at least in part, using the at least one
secondary authentication credential.
Regarding claim 5, Brandli discloses the method of claim 1, wherein
the at least one secondary authentication credential includes a user biometric characteristic for a user of the account holder user device, and the action of determining the service authorization result includes: retrieving an account holder biometric characteristic for an account holder associated with the card account, and
comparing the user biometric characteristic to the account holder biometric characteristic.
Regarding claim 7, Brandli discloses the method of claim 1, wherein the action of
determining a service authorization result includes:
transmitting a request for geolocation information to the account holder user
device, receiving the requested geolocation information from the account holder user
device, determining a location of the account holder user device using the geolocation
information, determining a separation distance between the account holder user device and the ASM, and determining whether the separation distance meets predetermined proximity criteria for the requested service.
Regarding claim 8, Brandli discloses the method of claim 1, wherein the action
of determining a service authorization result includes:
determining a service risk factor indicative of a relative degree of risk associated
with authorization of the requested service;
comparing the service risk factor to predetermined risk factor criteria; and
establishing a positive service authorization result only upon the service risk
factor meeting the predetermined risk factor criteria.
Regarding claim 12, Brandli discloses a service facilitation data processing system according to claim 11, wherein the authentication data processor is further configured to, as part of the action to determine a service authorization;
transmit, to the account holder user device, a request for geolocation
information; receive, from the account holder user device the requested geolocation
information; determine a location of the account holder user device using the geolocation information; determine a separation distance between the account holder user device and the requested ASM, and determine whether the separation distance meets predetermined proximity criteria for the requested service (Abstract, 0018).
Regarding claim 13, Brandli discloses a service facilitation data processing system according to claim 11, wherein the authentication data processor is further configured to, as part of the action to determine a service authorization;
transmit, to the account holder user device, a request for at least one secondary
authentication credential, receive, from the account holder user device, the at least one secondary authentication credential, and determine the service authorization result using the at least one secondary authentication credential (0006).
Regarding claim 14, Brandli discloses the apparatus of claim 11, wherein the ASM includes an automated car wash system, a key cutting machine, an automated teller machine (ATM), or a product or service vending machine (0018).
Regarding claim 22, Brandli discloses the non- -transitory computer-readable storage medium of claim 21, wherein transmitting the service request notification is carried out after receiving the card authentication information (Abstract, 0018, 0020).
Regarding claim 23, Brandli discloses the non- -transitory computer-readable storage medium of claim 21, wherein determining the service authorization result includes the processing circuit being caused to: verify an account parameter status for the card account meets predetermined requirements for the requested service,
verify that the card account is authorized for the requested service, or verify that the account holder user device is associated with a user who is authorized to request the requested service (0018).
Regarding claim 24, Brandli discloses the non- -transitory computer-readable storage medium of claim 21, wherein determining the service authorization result includes the processing circuit being caused to: transmit, to the account holder user device, a request for at least one secondary authentication credential, receive, from the account holder user device, the at least one secondary authentication credential, and
determine the service authorization result, at least in part, using the at least one secondary authentication credential (0006).
Regarding claim 25, Brandli discloses the non- -transitory computer-readable storage medium of claim 24, wherein: the at least one secondary authentication credential includes a user biometric characteristic for a user of the account holder user device, determining the service authorization result includes the processing circuit being
caused to: retrieve an account holder biometric characteristic for an account holder
associated with the card account, and compare the user biometric characteristic to the account holder biometric characteristic (0003).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all obviousness rejections set forth in this Office action:
(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the manner in which the invention was made.
Claims 6, 9-10, and 26 are rejected under 35 U.S.C. 103(a) as being unpatentable over Brandli et al. [US Pub No. 2009/0121829 A1] in view of Carlson [US Pub No. 2013/0246199 A1].
Regarding claim 6, Brandli does not disclose however Carlson teaches wherein the at least one secondary authentication credential includes a login credential provided through an account application on the account holder user device (0026). Before the effective filing date, it would have been obvious to a person of ordinary skill in the art to modify the disclosure of Brandli's system to incorporate the login credential and risk factor evaluation techniques of Carlson. Both references are in the same field of endeavor. The combination would have been a simple substitution or addition of known elements to improve security and authorization processes. The modification would have yielded predictable results. Therefore, the subject matter of the claims would have been obvious.
Regarding claim 9, Brandli does not disclose however Carlson teaches wherein the action of determining a service risk factor includes at least one of the set consisting of: determining a time interval since a most recent login into an account application associated with the card account; determining a time interval since a most recent transaction involving the card account, and determining a location of a most recent transaction involving the card account (0026). Before the effective filing date, it would have been obvious to a person of ordinary skill in the art to modify the disclosure of Brandli's system to incorporate the login credential and risk factor evaluation techniques of Carlson. Both references are in the same field of endeavor. The combination would have been a simple substitution or addition of known elements to improve security and authorization processes. The modification would have yielded predictable results. Therefore, the subject matter of the claims would have been obvious.
Regarding claim 10, Brandli does not disclose however Carlson teaches wherein the ASM comprises an automated car wash system, a key cutting machine, an automated teller machine (ATM), or a product or service vending machine (0081). Before the effective filing date, it would have been obvious to a person of ordinary skill in the art to modify the disclosure of Brandli's system to incorporate the login credential and risk factor evaluation techniques of Carlson. Both references are in the same field of endeavor. The combination would have been a simple substitution or addition of known elements to improve security and authorization processes. The modification would have yielded predictable results. Therefore, the subject matter of the claims would have been obvious.
Regarding claim 26, Brandli does not disclose however Carlson teaches wherein the at least one secondary authentication credential includes a login credential provided through an account application on the account holder user device (0026). Before the effective filing date, it would have been obvious to a person of ordinary skill in the art to modify the disclosure of Brandli's system to incorporate the login credential and risk factor evaluation techniques of Carlson. Both references are in the same field of endeavor. The combination would have been a simple substitution or addition of known elements to improve security and authorization processes. The modification would have yielded predictable results. Therefore, the subject matter of the claims would have been obvious.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KEVIN T POE whose telephone number is (571)272-9789. The examiner can normally be reached on Monday-Friday 9:30 am through 6pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ryan Donlon can be reached on 571-270-3602. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/K.T.P/Examiner, Art Unit 3692 /KEVIN T POE/
/RYAN D DONLON/Supervisory Patent Examiner, Art Unit 3692