DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
This is the office action on the merits in response to the application filed on 03/09/2026.
Claims 1-8,10-12 and 14-15 are currently pending and have been examined.
Response to Arguments
Applicant's arguments filed 03/09/2026 with respect to the rejection(s) of claim(s) 1-8,10-12 and 14-15 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
5. Claims 1-8, 10-11, and 14-15 are rejected under 35 U.S.C. 103 as being unpatentable over Corner et al. (US 20120295580 A1), in view of Murphy et al. (US 20200005295A1), in view of Lai et al. (US 8185051 B2), in view of Nambiar et al. (US 20140157376 A1), and further in view of Agarwal et al. (US 20190362333 A1).
6. Regarding claims 1, 14 and 15, Corner discloses an electronic device (method, a computer program product stored on a non-transitory computer-readable medium, the computer program product comprising instructions which, when the program is executed by the computer, cause the computer to carry out a method of instructing performance of a transaction which has been requested at an automated teller machine comprising circuitry configured to, (Para. 0414-0415; and Para. 0290-0291)):
one or more processors; and at least one memory comprising a plurality of program instructions which, when executed by the one or more processors, cause the one or more processors to: receive a transaction request, requesting a transaction, in response to a user initiating a transaction at an automated teller machine, the transaction request conforming to a transaction request protocol and including at least a first field for a value of the transaction and a second field for identification of an account for which the transaction is requested; (Para. 0007; and Para. 0280-0290, FIG. 32 illustrates an example of using a phone number (123) at an ATM (221) to withdraw cash. In FIG. 32, the ATM (221) is configured to receive a phone number (123) (e.g., via a keypad or a touch screen of the ATM (221)). In response to the phone number (123) being received in the ATM (221) to withdraw an amount of cash, the ATM (221) sends a charge request (179) to the interchange (101) to request a funds transfer (227). In some embodiments, the ATM (221) sends the charge request (179) via the server (113) associated with the ATM (221). In one embodiment, the interchange (101) communicates with the mobile phone (117) for a confirmation (173) of the charge request (179). If the mobile phone (117) at the phone number (123) confirms the charge request (179), the interchange (101) provides funds to the server (113) associated with the ATM (221) via a funds transfer (227). The funds transfer (227) provides the amount of funds for the cash withdrawal and for any transaction fees the server (113) associated with the ATM (221) may charge. In one embodiment, the user of the mobile phone (117) at the phone number (123) has an account (122) with the interchange (101). The account (122) is associated with the phone number (123) stored in the data storage facility (107). The user may provide funds to the account (122) via the mobile phone (117). The interchange (101) transfers funds from the account (122) to the server (113). [0283] In one embodiment, when the balance of the account (122) is not sufficient to provide the funds to satisfy the charge request (179), the interchange (101) may communicate with the mobile phone (117) for a confirmation to send one or more premium messages (225) to the mobile phone (117) to collect funds into the account (122)…The ATM (221) is configured to access the account (122) hosted on the data storage facility (107) of the interchange (101), via funds transfer (227) between the server (113) and the interchange (101). For example, the ATM (221) may provide cash based on funds transferred out of the account (122), or receive a deposit via funds transferred to the account (122). FIG. 33 shows another example in which the ATM (221) uses the interchange (101) to confirm a transaction performed at the ATM (221)…Before operating on the account (122) (e.g., for cash withdrawal, for deposit, for funds transfer), the ATM (221) sends a request (229) to the interchange (101) to request a confirmation (228). In response to the request (229), the interchange (101) communicates with the mobile phone (117) to obtain a confirmation (173) for the transaction that is being processed at the ATM (221). After the interchange (101) obtains the confirmation (173) from the mobile phone (117), the interchange (101) sends a confirmation (228) as a response to the request (229). The confirmation (228) allows the ATM (221) to operate on the account (122). In some embodiments, the ATM (221) may receive a different identifier (e.g., a banking card number) to identify the account (122). The server (113) identifies the phone number (123) to request a confirmation (228). In some embodiments, the ATM (221) of a bank sends the request (229) and receives the confirmation (228) via the server (113) of the bank.)
retrieve from storage, based on the transaction request, an electronic device identifier associated with the account for which the transaction is requested (Para. 0289, In some embodiments, the ATM (221) may receive a different identifier (e.g., a banking card number) to identify the account (122). The server (113) identifies the phone number (123) to request a confirmation (228).; and Para. 0332, In one embodiment, multiple security measures are used together for certain requests. For example, when the amount of a request is above a threshold, or an accumulated transaction amount within a predetermined period of time is above a threshold. For example, access to certain accounts (e.g., online account (609)) may require less security measures, and access to some accounts (e.g., bank accounts (e.g., 611, 613, or 621)) may require more security measures.)
transmit a transaction instruction to the automated teller machine based on a condition of a response to the request for authentication of the user, (Fig. 32 and Fig. 33; and Para. 0124-0126, In one embodiment, the user is required to provide the approval in response to the confirmation message (217), as illustrated in FIG. 9, within a predetermined period of time. If the user fails to provide the approval from the mobile phone (117) within the predetermined period of time, the payment request may be rejected; and the user interface (201) may present a message indicating the failure and then redirect the user back to the website of the payee. In some embodiments, instead of redirecting the user back to the website of the payee after the expiration of a predetermined period of time (e.g., after the failure of the payment process, or after the completion of the payment), the user interface (201) may provide a link to the website of the payee to allow the user to manually select the link to go back to the website of the payee to continue the process at the website of the payee… FIG. 12 illustrates a user interface to receive payment options according to one embodiment. In FIG. 12, the interchange (101) sends a message (217) to the mobile phone (117) to provide a number of options to the user.; and Para. 0280-0289, FIG. 32 illustrates an example of using a phone number (123) at an ATM (221) to withdraw cash. In FIG. 32, the ATM (221) is configured to receive a phone number (123) (e.g., via a keypad or a touch screen of the ATM (221)). In response to the phone number (123) being received in the ATM (221) to withdraw an amount of cash, the ATM (221) sends a charge request (179) to the interchange (101) to request a funds transfer (227). In some embodiments, the ATM (221) sends the charge request (179) via the server (113) associated with the ATM (221). In one embodiment, the interchange (101) communicates with the mobile phone (117) for a confirmation (173) of the charge request (179). If the mobile phone (117) at the phone number (123) confirms the charge request (179), the interchange (101) provides funds to the server (113) associated with the ATM (221) via a funds transfer (227)… In some embodiments, the user may deposit funds into the ATM (221) and request the ATM (221) to transfer the deposited funds to the account (122) hosted on the data storage facility (107) of the interchange (101). In some embodiments, the user may have an account with the bank of the ATM (221) and the server (113). The ATM (221) is configured to receive the requests from the user to transfer funds between the account (122) hosted on the data storage facility (107) of the interchange (101) and the account with the bank of the ATM (221) and the server (113). In some embodiments, the user does not have an account with the bank of the ATM (221) and the server (113). The ATM (221) is configured to access the account (122) hosted on the data storage facility (107) of the interchange (101), via funds transfer (227) between the server (113) and the interchange (101). For example, the ATM (221) may provide cash based on funds transferred out of the account (122), or receive a deposit via funds transferred to the account (122). FIG. 33 shows another example in which the ATM (221) uses the interchange (101) to confirm a transaction performed at the ATM (221). In FIG. 33, the ATM (221) may receive a phone number (123) to identify an account (122) stored on the server (113) associated with the ATM (221). Before operating on the account (122) (e.g., for cash withdrawal, for deposit, for funds transfer), the ATM (221) sends a request (229) to the interchange (101) to request a confirmation (228). In response to the request (229), the interchange (101) communicates with the mobile phone (117) to obtain a confirmation (173) for the transaction that is being processed at the ATM (221). After the interchange (101) obtains the confirmation (173) from the mobile phone (117), the interchange (101) sends a confirmation (228) as a response to the request (229). The confirmation (228) allows the ATM (221) to operate on the account (122). In some embodiments, the ATM (221) may receive a different identifier (e.g., a banking card number) to identify the account (122). The server (113) identifies the phone number (123) to request a confirmation (228). In some embodiments, the ATM (221) of a bank sends the request (229) and receives the confirmation (228) via the server (113) of the bank.). Examiner interprets the term portable electronic device is analogous for the term mobile phone (117) in the cited prior art. Under broad reasonable interpretation, “When it is determined that the authentication of the user should be requested and a response to the transmitted ping is received within a predetermined amount of time” is interpreted as the atm receiving an identifier, such as a phone number and then sending a request for confirmation. A confirmation is sent to the mobile device and the user must respond within the predetermined time period in the cited prior art. The examiner also interprets that “the one or more processors are further caused to: transmit a request for authentication of the user to the portable electronic device identified by the electronic device identifier; and transmit a transaction instruction to the automated teller machine based on a condition of a response to the request for authentication of the user” is interpreted as the atm communicates with the mobile device to request confirmation of the transaction in the cited prior art and fig. 9, fig. 12, and figs. 32-33 describes transmitting the request and the transaction instruction to the atm based on the authentication response sent from the mobile device in the cited prior art.
Corner does not explicitly disclose determine whether authentication of the user should be requested based at least on a property of the requested transaction, a geographical location of the automated teller machine, and the location of the portable electronic device.
However, Murphy teaches determine whether authentication of the user should be requested based at least on a property of the requested transaction, a geographical location of the automated teller machine, and the location of the portable electronic device, (Abstract Section, Accordingly, the location of the consumer performing the financial transaction is included within the process. Embodiments include a consumer being physically present to authorise irrespective of authorisation of their credentials, a consumer may establish preferred locations for transactions, a retailer and consumer may perform the transaction once the consumer has left the retail location through stored location data of the user's device. Embodiments of the invention also support financial transactions without a direct PoS transaction as the user's device and the PoS terminal broker the transaction in the cloud using location data.; and Para. 0012, establishing via a remote server the presence of an authorizer of the financial transaction (FT) within a predetermined threshold with respect to a geolocation associated with a requester of the financial transaction, and Para. 0016, In accordance with an embodiment of the invention there is provided a method of authorizing a financial transaction comprising authorizing an electronic transaction based upon establishing via a remote server the presence of an authorizer of the electronic transaction within a predetermined threshold with respect to a geolocation associated with a requester of the electronic transaction.)
One of ordinary skill in the art would have recognized that applying the known technique of Murphy to the known invention of Corner would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate machine learning model features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the electronic device to include determine whether authentication of the user should be requested based at least on a property of the requested transaction, a geographical location of the automated teller machine, and the location of the portable electronic device results in an improved invention because applying said technique ensures the system authenticates the user when needed, thus improving the overall performance of the invention.
Corner does not explicitly disclose transmit a notification to a portable electronic device associated with the account identifier requesting a location of the portable electronic device.
However, Murphy teaches transmit a notification to a portable electronic device associated with the account identifier requesting a location of the portable electronic device, (Fig. 3; and Para. 0012,establishing via a remote server the presence of an authorizer of the financial transaction (FT) within a predetermined threshold with respect to a geolocation associated with a requester of the financial transaction; and Para. 0239-0242, Accordingly, a merchant may communicate with an authenticated user, or to the device of a user, in order to: update the user or user's device in respect of its location information; prompt the user of available features, products, services, methods etc. with respect to the location; trigger a notifying alert on the user's device interface; and Para. 0045, A “device” as used herein and throughout this disclosure, refers to an assembly of components and elements of mechanical and/or electronic hardware either discretely or in combination with at least one of firmware and software employed to perform or execute one or more tasks or functions as determined either by its configuration or its firmware and/or software programming. Accordingly, a device may include but not be limited a portable electronic device, a fixed electronic device, a wearable device, a computer server, a computing device, a computer or other devices supporting and/or executing embodiments of the invention.).
One of ordinary skill in the art would have recognized that applying the known technique of Murphy to the known invention of Corner would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate machine learning model features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the electronic device to include wherein determination whether authentication of the user should be requested is based on an outcome of a machine learning model in response to the requested transaction results in an improved invention because applying said technique will ensure that the system can verify transactions more quickly, thus improving the overall performance of the invention.
Corner as modified does not explicitly disclose transmit a ping to the portable electronic device to confirm that the portable electronic device is able to communicate with the electronic device
However, Lai teaches transmit a ping to the portable electronic device to confirm that the portable electronic device is able to communicate with the electronic device, (Column 1/line 46, According to a broad aspect, there is provided a pinging electronic device comprising a ping function and a transmitter wherein the ping function is adapted to generate and the transmitter is adapted to transmit over an ad hoc wireless network at least one associated ping control message to at least one pingable electronic device paired to the pinging electronic device for actuation of at least one indicator element of the at least one pingable electronic device.
In some embodiments, the pinging electronic device is a master device. In other embodiments, the pinging electronic device is a peripheral device. According to a further broad aspect, the invention provides a pingable electronic device comprising a receiver, a ping message processor, and at least one indicator element wherein the receiver is adapted to receive a ping control over an ad hoc wireless network message and the ping message processor is adapted to actuate the at least one indicator element in response to the ping control message.)
One of ordinary skill in the art would have recognized that applying the known technique of Lai to the known invention of Corner as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate notification features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the electronic device to include transmit a ping to the portable electronic device to confirm that the portable electronic device is able to communicate with the electronic device results in an improved invention because applying said technique will ensure that there are communications between devices, thus improving the overall performance of the invention.
Corner as modified does not explicitly disclose determine whether a response to the ping is received within a predetermined amount of time.
However, Nambiar teaches determine whether a response to the ping is received within a predetermined amount of time, (Claim 20. further comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including: determining a timeout value corresponding to the entry in the network layer (L3) cache; determining that a time period corresponding to the timeout value has elapsed; transmitting a ping message, wherein receiving a ping message at a client causes the client to generate a ping response; receiving a ping response within a predetermined time interval after transmitting the ping message, wherein the ping response corresponds to the client; and maintaining the entry in the network layer (L3) cache.; and Para. 0043, Accordingly, the disclosed system will maintain two different timeout values—the first timeout value or a station timeout value (which is typically set to a longer period) is for the period of time of the association between the client and the access point; and, the second timeout value or a user timeout value (which is typically set to a shorter period) is for the traffic to or from the client on the radio link. For example, the system may configure 15 minutes to be the station timeout value that indicates the maximum period of time before the user entry gets deleted if the station has been idle, i.e., there has been no traffic to or from a client on the radio link between the client and an access point. On the other hand, the system may configure 5 minutes to be the user timeout value that indicates the maximum period of time before a user entry gets deleted if the user has been idle. )
One of ordinary skill in the art would have recognized that applying the known technique of Nambiar to the known invention of Corner as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate notification features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the electronic device to include determine whether a response to the ping is received within a predetermined amount of time results in an improved invention because applying said technique will ensure that the portable electronic device is available and responsive before proceeding with authentication, thus improving the overall performance of the invention.
Corner as modified does not explicitly disclose responsive to determining that the authentication of the user should be requested and the response to the transmitted ping was received within the predetermined amount of time, the one or more processors are further caused to: transmit a request for authentication of the user to the portable electronic device identified by the electronic device identifier.
However, Agarwal teaches responsive to determining that the authentication of the user should be requested and the response to the transmitted ping was received within the predetermined amount of time, the one or more processors are further caused to: transmit a request for authentication of the user to the portable electronic device identified by the electronic device identifier, (Para. 0052-0053, In response to receiving the instructions 606 for scanning smart devices, the user device 110 begins a scan of smart devices in the vicinity. The scan involves the smart device interface module 224c of the user device 110 generating a ping signal 608 which is sent to all of the smart devices 112a-c. The ping signal 608 may cause smart devices in the vicinity to couple with the user device 110. The smart device request/ping information is determined from the instructions 606 for scanning smart devices. The instructions 606 for scanning smart devices comprise indications of the steps which are required to ping the smart device. The instructions 606 for scanning smart devices can be in the form of API calls or scripts or another software paradigm. In response to receiving the ping signal 608 each of the smart devices 112a-c generates a ping response 610. The ping responses 610 are received by the smart device interface module 224c of the user device 110. The smart device interface module 224c of the user device 110 uses the ping responses 610 to identify the network addresses of the smart devices 112a-c and sends a smart device information request 612 to each of the smart devices 112a-c. In response to the smart device information request 612 each smart device 112a-c sends a smart device information response 614 to the user device. After receiving the smart device information responses 614, the browser module 224a of the user device 110 generates a user authentication request 616. It is noted that responses may not be received from all of the smart devices in the vicinity of the user device 110. For example, depending upon various conditions such as non-availability of a smart device, the smart device being switched off, and a particular smart device not being linked to the current geo-location of the user device 110, a response may not be received from that smart device. The user authentication request 616 comprises indications of the smart device information of the plurality of smart devices 112a-c. The user authentication request 616 may also comprise information of the user device 110 such as the geo-location of the user device and information an indication of an identifier of the user device.)
One of ordinary skill in the art would have recognized that applying the known technique of Agarwal to the known invention of Corner as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate notification features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the electronic device to include responsive to determining that the authentication of the user should be requested and the response to the transmitted ping was received within the predetermined amount of time, the one or more processors are further caused to: transmit a request for authentication of the user to the portable electronic device identified by the electronic device identifier results in an improved invention because applying said technique will ensure that the authentication request is sent to a verified to a responsive device, thus improving the overall user convenience of the invention.
7. Regarding claim 2, Corner discloses wherein the condition of the response is whether a response to the request for authentication of the user is received within a predetermined time of the request for authentication of the user, (Para. 0330-0332, For example, to authenticate a request made at a user terminal (111), the interchange (101) may assign a one-time code to the request, transmit the one-time code to the user via the mobile phone (117) and request the one-time code at the user terminal (111) for verification. Alternatively, the interchange (101) may assign a one-time code to the request, transmit the one-time code to the user via the user terminal (111) and request the one-time code from the mobile phone (117) for verification. For example, to authenticate the mobile phone (117), the interchange (101) may request a one-time password generated on the mobile phone (117) (or generated on a separate device assigned to the user). In one embodiment, access to the one-time password generator (361) is password protected for enhanced security. In one embodiment, multiple security measures are used together for certain requests. For example, when the amount of a request is above a threshold, or an accumulated transaction amount within a predetermined period of time is above a threshold. For example, access to certain accounts (e.g., online account (609)) may require less security measures, and access to some accounts (e.g., bank accounts (e.g., 611, 613, or 621)) may require more security measures.)
8. Regarding claim 3, Corner discloses wherein when the response to the request for authentication of the user is received within the predetermined time, and when the response is indicative of an unsuccessful authentication of the user, the transaction instruction instructs the automated teller machine not to perform the transaction, (Para. 0146-0149, In one embodiment, the application is configured on the mobile phone (117) to present a user interface (350) to confirm a transaction according to one embodiment, as illustrated in FIG. 15. In FIG. 15, the application communicates with the interchange (101) to present information that identifies aspects of the transaction, such as the payee, the amount involved in the transaction, a description of the product or service in the transaction, etc. In FIG. 15, the user interface (350) includes an entry box (353) to receive a PIN from the user. When the PIN received in the user interface (350) is invalid, the user interface (350) may reject the input and prevent the user from sending the confirmation message via the user interface (350). In some embodiments, the user interface (350) and/or the interchange (101) may prevent the user from using the user interface (350) after the user fails to provide the correct PIN after a predetermined number of attempts.)
9. Regarding claim 4, Corner discloses wherein when the response to the request for authentication of the user is received within the predetermined time, and when the response is indicative of a successful authentication of the user, the transaction instruction instructs the automated teller machine to perform the transaction, (Para. 01530-0154, In some embodiments, the interchange (101) may allow the user interface (350) to resubmit the input for the PIN a number of times if the one-time code (351) is valid. For example, the user interface (350) may be presented in response to a message from the interchange (101) requesting the confirmation of the transaction. The one-time code (351) is required in the entry box to ensure that the user has knowledge about the transaction submitted via the user terminal (111). The PIN is required in the entry box (353) to ensure that the user is authorized. In some embodiments, the one-time code (351) is optional. In some embodiments, the interchange (101) provides the one-time code (351) to the user via the user interface (350). The application may send the one-time code (351) back to the interchange (101) to identify the transaction being confirmed by the user.)
10. Regarding claim 5, Corner discloses wherein when the response to the request for authentication of the user is not received within the predetermined time, the transaction instruction instructs the automated teller machine to perform the transaction, (Para. 0148, Alternatively, the user interface (350) may accept the user input without checking the input for validity and transmit the confirmation with the received PIN to the interchange (101). The interchange (101) then checks the received PIN for validity. If the interchange (101) determines that the received PIN is valid for the phone number (123) of the mobile phone (117), the interchange (101) accepts the confirmation and performs the requested transaction. If the interchange (101) determines that the received PIN is invalid, the user interface (350) may prompt the user to re-enter the PIN.; and Para. 0245, and the interchange (101) may associate the phone number (123) with such identifiers until the expiration of a predetermined time period, or after the user signals an end of the session using the user terminal (111) or using the mobile phone (117) at the phone number (123). In one embodiment, the interchange (101) associates a plurality of identifiers of the user terminal (111) with the phone number (123) for the session. When at least one of the identifiers of the user terminal (111) is changed, the interchange (101) may terminate the session automatically.)
11. Regarding claim 6, Corner discloses, wherein the transaction instruction instructs the automated teller machine to perform the transaction only when the transaction request is successfully authorized, (Para. 0266, In one embodiment, an ATM is configured to accept the phone number (123) entered by a customer to withdraw cash. The ATM transmits the phone number (123) in a request for funds to the interchange (101). In response to the request, the interchange (101) sends a text message to the mobile phone (117) at the phone number (123) to allow the user to confirm or authorize the request. After the customer gets the text message on the mobile phone (117), the customer may reply to the text message to confirm/approve and then withdraw cash from the ATM. The interchange (101) provides to the bank of the ATM the corresponding funds collected from the user.)
12. Regarding claim 7, Corner discloses wherein the transaction request is successfully authorized when the transaction request includes, in a third field, a security hash and when the security hash matches a hash associated with the account for which the transaction is requested, (Para. 0222, In FIG. 24, the user (371) may use the user terminal (111) to sign in the account (531) hosted on the server (113). To authenticate the user (371), the interchange (101) transmits a message to the mobile phone (117) at the phone number (123) to request a PIN from the user (371). When the PIN received via the mobile phone (117) matches with the account information (121) stored on the data storage facility (107), the interchange (101) provides information to the server (113) to allow the user (371) to access the account (531) using the user terminal (111), which is typically a device distinct and separate from the mobile phone (117).
0231] In one embodiment, the interchange (101) redirects the web browser (501) from the website of the interchange (101) to the server (113) hosting the account (531); and the information provided by the interchange (101) to the sever (113) includes an identifier to uniquely represent the user (371) among a plurality of users (or to uniquely identify the account (531) among a plurality of accounts hosted on the server (113)). In one embodiment, the identifier is generated from hashing the mobile phone number (123) and the PIN; in another embodiment, the identifier is pre-associated with the phone number (123) and the host.)
13. Regarding claim 8, Corner discloses wherein when a response to the request for authentication of the user indicative of an unsuccessful authentication of the user is received after the transaction has been performed, the one or more processors are further configured to generate a notification message reporting the transaction as a fraudulent transaction, (Para. 0356-0359 For example, in one embodiment, the interchange (101) is configured to further make use of the data collected by the mobile telecommunication carriers in identifying fraudulent activities. In one embodiment, the data collected by the mobile telecommunication carriers can be used to generate signals characterizing the use of a mobile phone (117) as a function of time. Examples of such signals include: time patterns for calls initiated from a mobile phone (117) at a given phone number (123), time patterns for calls received at a mobile phone (117) having a given phone number (123), length of phone calls connected to or from a mobile phone (117) at a given phone number (123), time patterns for sent/received text messages (e.g., transmitted via short message service (SMS)), geographic locations of phone numbers dialed on a mobile phone (117) having a given phone number (123), data usage patterns of a mobile phone (117) having a given phone number (123), mobile application usage patterns of a mobile phone (117) having a given phone number (123), location patterns of a mobile phone (117) at a given phone number (123), and patterns in Internet connection duration for the mobile phone (117). In one embodiment, the signals generated from the data collected by the mobile telecommunication carriers are used to detect a recent abnormality in the usage of the mobile phone (117) at the phone number (123). The interchange (101) uses the indication of recent abnormality to further determine the likelihood of the payment activity being fraudulent. In one embodiment, the signals generated from the data collected by the mobile telecommunication carriers are used to determine a likelihood that the mobile phone (117) has been stolen. When a potentially fraudulent payment activity correlates with a strong indication that the mobile phone has been stolen, a security measure is applied to the payment activity, such as blocking/rejecting the payment request, freezing the payment services provided to the phone number (123) of the mobile phone (117), requesting additional authentications, disabling the telecommunication services provided to the mobile phone (117), etc. For example, the interchange (101) and/or the telecommunication carrier may initiate a communication with the registered user of the mobile phone (117) to confirm the stolen or lost status of the mobile phone (117). The communication can be performed using a user terminal (111) other than the mobile phone (117), via calling a landline phone of the registered user, sending an email message to the registered user, etc.)
14. Regarding claim 10, Corner does not explicitly disclose wherein one or more processors are further configured to: transmit a notification to the portable electronic device associated with the account identifier requesting a location of the electronic device.
However, Murphy teaches wherein one or more processors are further configured to: transmit a notification to the portable electronic device associated with the account identifier requesting a location of the electronic device; (Para. 0111; and Para. 0035-0036, FIG. 3 depicts an exemplary process flow according to an embodiment of the invention relating to establishing geolocation-based database within an authorizing device. FIGS. 4 and 5 depict an exemplary process relating to establishing an association between a requesting device and authorizing device via a remote system according to an embodiment of the invention; and Para. 0040, FIG. 9 depicts an exemplary message flow relating to establishing a transaction upon remote system based upon transaction and location data from requesting device and authorizing device; and Para. 0046, A “portable electronic device” (PED) or “mobile electronic device” (commonly referred to as a mobile) as used herein and throughout this disclosure, refers to a device used for communications and other applications that requires a battery or other independent form of energy for power. A PED may be recharged from a fixed interface to obtain power and also be connected to one or more of a wired communications interface, a wireless communications interface (e.g. radio frequency, microwave, and acoustic) and an optical communications interface. This includes devices, but is not limited to, such as a cellular telephone, smartphone, personal digital assistant (PDA), portable computer, pager, portable multimedia player, portable gaming console,).
One of ordinary skill in the art would have recognized that applying the known technique of Murphy to the known invention of Corner would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate machine learning model features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the electronic device to include wherein one or more processors are further configured to: transmit a notification to the portable electronic device associated with the account identifier requesting a location of the electronic device results in an improved invention because applying said technique ensures that the system can quickly verify transactions, thus improving the overall performance of the invention.
15. Regarding claim 11, Corner discloses wherein the determination whether the authentication of the user should be requested is based on a fraud score calculated for the requested transaction, (Para. 0359-0361, In one embodiment, the signals generated from the data collected by the mobile telecommunication carriers are used to determine a likelihood that the mobile phone (117) has been stolen. When a potentially fraudulent payment activity correlates with a strong indication that the mobile phone has been stolen, a security measure is applied to the payment activity, such as blocking/rejecting the payment request, freezing the payment services provided to the phone number (123) of the mobile phone (117), requesting additional authentications, disabling the telecommunication services provided to the mobile phone (117), etc. For example, the interchange (101) and/or the telecommunication carrier may initiate a communication with the registered user of the mobile phone (117) to confirm the stolen or lost status of the mobile phone (117). The communication can be performed using a user terminal (111) other than the mobile phone (117), via calling a landline phone of the registered user, sending an email message to the registered user, etc. In one embodiment, the interchange (101) receives the signals from the telecommunication carrier and uses the signals to produce a fraudulent likelihood score for a payment request (e.g., in combination with payment records stored in the data storage facility (107) of the interchange (101)). In one embodiment, the interchange (101) receives, from the telecommunication carrier, data summarizing the typical patterns identified from the signals, and matches the attributes of a payment request with the typical patterns to produce a fraudulent likelihood score for the payment request.)
16. Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Corner et al. (US 20120295580 A1), in view of Murphy et al. (US 20200005295A1), in view of Lai et al. (US 8185051 B2), and further in view of Patel et al. (WO 2020171974 A1).
17. Regarding claim 12, Corner as modified does not explicitly disclose wherein the determination whether authentication of the user should be requested is based on an outcome of a machine learning model in response to the requested transaction.
However, Patel teaches wherein determination whether authentication of the user should be requested is based on an outcome of a machine learning model in response to the requested transaction, (Para. 0063, In some embodiments, decision data 1006 (also referred to herein as “authentication decision”) includes an authentication outcome (e.g., valid, invalid, verified, fraud detected, fraud not detected, rejected, reference and authentication images match, reference and authentication images do not match, a fault was detected in the image, and so forth). The authentication outcome is the result of machine learning module 126 applying authentication model 136 to image data 1004. Alternatively, the authentication outcome is the result of human review, as described above with reference to Figure 5-9. In some embodiments, machine learning module 126 uses supervised training 130, unsupervised training 132, and/or adversarial training 134 to refine the authentication module 136 using the human reviewer-sourced authentication outcome.; and Para. 0083-0087, In some embodiments, image data 1204 includes a reference image 300, an authorization image 350, or both. Alternatively, image data 1204 includes one or more components of a reference image 300 or an authorization image 350. In some embodiments, decision data 1206 (also referred to herein as “authentication decision”) includes an authentication outcome (e.g., valid, invalid, verified, fraud detected, fraud not detected, rejected, reference and authentication images match, reference and authentication images do not match, a fault was detected in the image, and so forth). The authentication outcome is the result of machine learning module 126 applying authentication model 136 to image data 1204. Alternatively, the authentication outcome is the result of human review, as described above with reference to Figure 5-9. In some embodiments, machine learning module 126 uses supervised training 130, unsupervised training 132, and/or adversarial training 134 to refine the authentication module 136 using the human reviewer-sourced authentication outcome…Figure 12B illustrates validation information for an example authentication request 1202a. For a first request 1202a, a user transmitted a reference image 300 to the authentication server 100 as part of an authentication request 124a. The reference image 300 is stored as image data 1204a, and either a human reviewer uses one or more of the techniques described above with reference to Figures 5-9 to classify the image 300 as fraudulent, or the machine learning module 126 applies the authentication model 136 to the image 300 and the model outputs a decision that the image 300 is fraudulent. As such, decision data 1206a stores the authentication result“Invalid.” In some embodiments, if a decision 1206 corresponding to any of the authorization request data 1202 is determined by human review, the image 1204 corresponding to the decision 1206 is used as machine learning input during subsequent training (refining) of the authentication model 136, and each image 1204 is labeled with corresponding decision data 1206. Specifically, the model 136 is trained using an array of pairs, for example, designated by (x, y), wherein x = an input image, and y = an authentication decision corresponding to the input image. Stated another way, machine learning module 126 trains the authentication model 136 using labeled input data, wherein the input data is the image data x, and the label is the authentication decision y. As a result of the training, the authentication model 136 includes a plurality of weights representing rules for determining decisions 1206 corresponding to input image data 1204.)
One of ordinary skill in the art would have recognized that applying the known technique of Patel to the known invention of Corner as modified would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate machine learning model features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the electronic device to include wherein determination whether authentication of the user should be requested is based on an outcome of a machine learning model in response to the requested transaction results in an improved invention because applying said technique will make the device more intelligent and secure by using machine learning models learning verification decisions, thus improving the overall performance and security of the invention.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Security for Electronic Transactions and User Authentication (US 20170004506 A1) teaches system and method for generating, disseminating, controlling, and processing limited-life security codes used to authenticate users, particularly for electronic financial transactions, such as payment transactions or interacting with automated teller machines and the like. Providing a user with a single security code usable across multiple accounts or other secured systems is contemplated, each security code having a limited lifetime (e.g., one day). In a particular example of the present invention, a plurality of similarly situated users (each needing authenticated access to a plurality of accounts or other secured systems using the security code) are each assigned a set or group of respective security codes. In a preferred example, each security code is a random number from a random number generator. The respective security codes for each user correspond to a respective security code validity period of limited duration. Thus, a table or matrix that associates the plurality of users with the respective sets of randomly selected security codes (each having their respective validity periods) is generated, and that matrix is provided to the respective entities (such as banks, payment processors, computer networks generally, etc.) to which each user requires secured access. In parallel, at least a current security code (for example, for the current validity period) is provided to each user, and this is how the respective entities being accessed can track which code from which user is currently valid.
In addition to the foregoing, other aspects are described in the claims, drawings, and text. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Davida L. King whose telephone number is (571) 272-4724. The examiner can normally be reached M-F 8am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha Patel can be reached on (571) 270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/D.L.K./Examiner, Art Unit 3699
/NEHA PATEL/Supervisory Patent Examiner, Art Unit 3699