Prosecution Insights
Last updated: August 17, 2026
Application No. 18/301,021

ENHANCED DATA MESSAGING SYSTEMS AND METHODS FOR AUTHENTICATING AN IDENTITY OF ONLINE USERS

Final Rejection §101
Filed
Apr 14, 2023
Examiner
YONO, RAVEN E
Art Unit
3694
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Mastercard International Incorporated
OA Round
6 (Final)
40%
Grant Probability
At Risk
7-8
OA Rounds
0m
Est. Remaining
72%
With Interview

Examiner Intelligence

Grants only 40% of cases
40%
Career Allowance Rate
72 granted / 182 resolved
-12.4% vs TC avg
Strong +33% interview lift
Without
With
+32.8%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
32 currently pending
Career history
217
Total Applications
across all art units

Statute-Specific Performance

§101
41.1%
+1.1% vs TC avg
§103
31.5%
-8.5% vs TC avg
§102
3.0%
-37.0% vs TC avg
§112
20.8%
-19.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 182 resolved cases

Office Action

§101
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims • This action is in reply to the amendments filed on June 12, 2026. • Claims 1, 11, and 20 have been amended and are hereby entered. • Claims 1-20 are currently pending and have been examined. • This action is made FINAL. Response to Arguments Applicant’s arguments filed June 12, 2026 have been fully considered but they are not persuasive. The Examiner is withdrawing the 35 USC § 112 rejections due to Applicant’s amendments. Applicant’s arguments with respect to 35 USC § 101 have been fully considered and are not persuasive. Regarding Applicant’s argument on pages 12-13, that claims do not recite an abstract idea, the Examiner respectfully disagrees. Applicant further argues on page 13 that the claims are directed to a specific technological problem addressing interoperability and messaging between computing components. The argument is not persuasive. As indicated in the 35 USC § 101 rejection below, the claimed inventions allows for using an authentication model to authenticate the identity of a user, and modify an authorization request by adding identity authentication data to the request. The Specification at [0002] states: “The need to authenticate online users before providing such online users with numerous different online services and/or confidential data is extremely important. For example, online transactions conducted over electronic payment networks are growing exponentially. For card-not-present transactions (e.g., online transactions in which the consumer does not actually provide a payment card to the merchant), fraud is markedly higher. Accordingly, for such transactions, authentication procedures are often implemented to verify that the alleged cardholder is, in fact, the actual or legitimate cardholder. In many cases, certain parties involved in the online transaction either do not have access to certain data that may be used to help authenticate the true identity of the online user or have access to only limited data. Thus, these parties are at a significant disadvantage when trying to authenticate the true identity of the online user prior to completing the purchase transaction.” Regrading Applicant’s arguments on page 13, that the claims improve a technical problem, the Examiner respectfully disagrees. The pending claims do not describe a technical solution to a technical problem. The pending claims are directed to addressing problems with fraud and various fraud detection methodologies and improving the process of authenticating an identity of an online user completing a transaction (see at least [0002] and [0060] of the Specification). The claims of the instant application describe an improvement to a business process i.e., addressing problems with fraud and various fraud detection methodologies and improving the process of authenticating an identity of an online user completing a transaction, not improvement in the functioning of the computer itself or an improvement to any other technology or technological field. Regarding Applicant’s arguments on pages 14-17, that the claims integrate a practical application, the Examiner respectfully disagrees. Under the Patent Subject Matter Eligibility analysis, Step 2A, prong two, integration into a practical application requires an additional element(s) or a combination of additional elements in the claim to apply, rely on, or use the judicial exception in a manner that imposes a meaningful limit on the judicial exception, such that the claim is more than a drafting effort designed to monopolize the exception. Limitations that are not indicative of integration into a practical application are those that generally link the use of the judicial exception into a particular technological environment or field of use-see MPEP 2106.05(h). Here the claims recite an authentication platform for use; an online user; the authentication platform comprising: a memory device; and at least one processor coupled to the memory device, the at least one processor programmed to perform claim functions and at least one non-transitory computer-readable storage media having computer-executable instructions embodied thereon for use in authenticating an online user, wherein when executed by at least one processor, the computer-executable instructions cause the at least one processor to perform claim functions; a payment processing network; a plurality of access control servers (ACSs) communicatively coupled to the authentication platform; a merchant computing device; computers of the payment processing network; an issuer computing device of the first issuer such that they amount to no more than generally linking the use of the judicial exception (e.g., authenticating an identity of a user) to a particular technological environment or field of use (e.g., a computer network) (see MPEP 2106.05(h)). Furthermore and in response to Applicant’s arguments on pages 14-17 that the claims address technical challenges and technical problems rooted in computer technology, in determining whether a claim integrates a judicial exception into a practical application, a determination is made of whether the claimed invention pertains to an improvement in the functioning of the computer itself or any other technology or technical field (i.e., a technological solution to a technological problem). Here, the claims recite generic computer components, i.e., a generic processor, a memory storing a computer program executable by the processor to perform the claimed method steps and system functions. The processor, memory and system are recited at a high level of generality and are recited as performing generic computer functions customarily used in computer applications. Furthermore, the Specification describes a problem and improvement to a business or commercial process at least at [0002], describing improving the process of authenticating the identity of an online user completing a transaction. Applicant’s reliance upon Claim 1 of Example 40, as argued on page 17, is misplaced. As an initial matter, with respect to USPTO Examples, the Examiner analyzes the claims under the two part framework under Alice/Mayo. The Examples provided in Office Guidance are hypothetical and intended to be illustrative only. While some of the fact patterns in the examples draw from U.S. Supreme Court and U.S. Court of Appeals for the Federal Circuit decisions, the examples do not carry the weight of court decisions. Furthermore, the claim 1 in hypothetical Example 40 were found to be eligible because the claim addressed problems relating to optimizing network performance, resolving network issues, and improving network security. Example 40 explains that continual generation and export of Netflow records substantially increases the traffic volume on the network which hinders network performance. The claim 1 in Example 40 directly address this challenge by varying the amount of network data collected based on monitored events in the network, particularly, by claiming a method that limits collection of additional Netflow protocol data to when the initially collected data reflects an abnormal condition, which avoids excess traffic volume on the network and hindrance of network performance. The collected data can then be used to analyze the cause of the abnormal condition. Turning to the instant application, the claims are not addressing a problem technical in nature, but are an improvement to a business process i.e., addressing problems with fraud and various fraud detection methodologies and improving the process of authenticating an identity of an online user completing a transaction. The Examiner finds no parallel between the Applicant’s claims and the hypothetical, patent-eligible Claim 1 described in Example 40 of the October 2019 update. Regarding Applicant’s arguments on pages 17-18, that the claims recite significantly more than the abstract idea, the Examiner respectfully disagrees. The limitations are directed to an abstract idea and when determining if the claims are directed to significantly more, the additional limitations of the claims in addition to the abstract idea are analyzed. In the instant application, the additional elements of the claim include an authentication platform for use; an online user; the authentication platform comprising: a memory device; and at least one processor coupled to the memory device, the at least one processor programmed to perform claim functions and at least one non-transitory computer-readable storage media having computer-executable instructions embodied thereon for use in authenticating an online user, wherein when executed by at least one processor, the computer-executable instructions cause the at least one processor to perform claim functions; a payment processing network; a plurality of access control servers (ACSs) communicatively coupled to the authentication platform; a merchant computing device; computers of the payment processing network; an issuer computing device of the first issuer. The additional limitations, when considered both individually and in combination, do not affect an improvement to another technology or technological field; the claims do not amount to an improvement to the functioning of the computer itself; and the claims do not move beyond a general link of use of an abstract idea to a particular technological environment. Therefore, the claims merely amount to merely generally linking the use of the abstract idea to a particular technological environment or field of use (e.g., a computer network), and is considered to amount to nothing more than requiring a generic computer network to carry out the abstract idea itself. The specifics about the abstract idea do not overcome the rejection. Applicant’s reliance upon BASCOM, as argued on pages 17-19, is misplaced. The claims here are not like those the Court found patent eligible in Bascom, in which the inventive concept was the unconventional arrangement of the installation of a filtering tool at a specific location, remote from the end-users, with customizable filtering features specific to each end user, this design permitted the filtering tool to have both the benefits of a filter on a local computer and the benefits of a filter on the [Internet Service Provider] server and was not conventional or generic, instead, the patent claimed and explained how a particular arrangement of elements was “a technical improvement over prior art ways of filtering such content.” (BASCOM, 827 F.3d at 1345.). In the instant application the claims do not have an inventive concept found in the non-conventional and non-generic arrangement of the additional elements. The claims are not patent eligible. For the reasons above, Applicant’s arguments are not persuasive. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention recites an abstract idea without significantly more. Independent claims 1, 11, and 20 are directed to an apparatus (claims 1 and 20) and a method (claim 11). Therefore, on its face, each independent claim 1, 11, and 20 are directed to a statutory category of invention under Step 1 of the Patent Subject Matter Eligibility analysis (see MPEP 2106.03). Under Step 2A, Prong One of the Patent Subject Matter Eligibility analysis (see MPEP 2106.04), claims 1, 11, and 20 recite, in part, an apparatus and a method of organizing human activity. Using the limitations in claim 1 to illustrate, the claim recites authenticating a user; generate a plurality of authentication models using historical data, each model associated with a respective issuer and having a respective plurality of criteria defined by the respective issuer, the historical data comprising at least historical consumer identity data from historical authentication and authorization transactions conducted, each associated with a respective plurality of issuers; receive an authentication request message for a current transaction, the authentication request message having a first format and including consumer identity data for the current transaction; extract the consumer identity data, an account identifier, and an ACS identifier from the authentication request message; retrieve a first authentication model of the plurality of authentication models that is associated with a first issuer that issued the financial account identified by the account identifier; and generate identity insight result data including an identity score, by inputting the extracted consumer identity data into the authentication model to leverage the historical data as compared to limited historical transaction data processed, identified by an identifier, wherein the identity insight data controls further messaging actions; wherein the identity insight result data meeting first criteria of the plurality of criteria of the first authentication model controls to: transform the authentication request message from the first format into an enhanced authorization request message of the current transaction, wherein the enhanced authorization request message has a second, standardized format and includes identity insight result data, and wherein the second, standardized format is suitable for processing, the second format being different from the first format; and transmit the enhanced authorization request message to an issuer to enable the first issuer to make an authentication decision with the identity insight result data prior to proceeding with authorization of the current transaction, without externally transmitting the consumer identity data, wherein the identity insight result data meeting second criteria of the plurality of criteria controls to authenticate the current transaction without transmitting any request message to the issuer and transmit an authentication response message, in the first format and including the identity insight result data, to the merchant indicating the current transaction has been authenticated, and wherein the identity insight result data meeting third criteria of the plurality of criteria controls to transmit an authentication response message, in the first format and including the identity insight result data, to the merchant indicating the current transaction has not been authenticated without transmitting any request message to the issuer, and flag the account identifier with a flag indicating the associated financial account is fraudulent to prevent further authentication thereof. The limitations, as drafted, is a process that, under its broadest reasonable interpretation, covers commercial and legal interactions (certain methods of organizing human activity), but for the recitation of generic computer components. The claims as a whole recite a method of organizing human activity. The claimed inventions allows for using an authentication model to authenticate the identity of a user, and modify an authorization request by adding identity authentication data to the request, which is a fundamental economic principle or practice of mitigating risk and a commercial and legal interaction of sales activities or behaviors. The mere nominal recitation of a memory device and processor do not take the claim out of the methods of organizing human activity grouping. Thus, the claims recite an abstract idea. Under Step 2A, Prong Two of the Patent Subject Matter Eligibility analysis (see MPEP 2106.04), the judicial exception is not integrated into a practical application. In particular, the additional elements of an authentication platform for use; an online user; the authentication platform comprising: a memory device; and at least one processor coupled to the memory device, the at least one processor programmed to perform claim functions and at least one non-transitory computer-readable storage media having computer-executable instructions embodied thereon for use in authenticating an online user, wherein when executed by at least one processor, the computer-executable instructions cause the at least one processor to perform claim functions; a payment processing network; a plurality of access control servers (ACSs) communicatively coupled to the authentication platform; a merchant computing device; computers of the payment processing network; an issuer computing device of the first issuer are recited at a high-level of generality (i.e., as a generic computer components performing generic computer functions of generating an authentication model, receiving an authentication request, extracting identity data from the request, generating identity insight result data, injecting an authorization request message and transmitting the authorization request message) such that it amounts to no more than generally linking the use of the judicial exception to a particular technological environment or field of use (e.g., a computer network).-see MPEP 2106.05(h). Accordingly, the combination of the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims are directed to an abstract idea. Under Step 2B of the Patent Subject Matter Eligibility analysis (see MPEP 2106.05), the claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements in the claims amount to no more than generally linking the use of the judicial exception to a particular technological environment or field of use (see MPEP 2106.05(h)). Generally linking the use of the judicial exception to a particular technological environment or field of use using generic computer components cannot provide an inventive concept. The claims are not patent eligible. The dependent claims have been given the full two part analysis including analyzing the additional limitations both individually and in combination. The dependent claim(s) when analyzed both individually and in combination are also held to be patent ineligible under 35 U.S.C. 101 because for the same reasoning as above and the additional recited limitation(s) fail(s) to establish that the claim(s) is/are not directed to an abstract idea. Dependent claims 2-4, 6-10, 12-13, and 15-19 simply help to define the abstract idea. Dependent claims 5, and 14 simply further describes the technological environment. Dependent claims 5 and 14 recite the additional elements of data stored in a database accessible by a processor, which merely further describes a data storage component of the generally linked computer network. The additional limitations of the dependent claim(s) when considered individually and as an ordered combination do not amount to significantly more than the abstract idea. Viewing the claim limitations as an ordered combination does not add anything further than looking at the claim limitations individually. When viewed either individually, or as an ordered combination, the additional limitations do not amount to a claim as a whole that is significantly more than the abstract idea. Accordingly, claims 1-20 is/are ineligible. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20150039506 A1 (“Groarke”) discloses conducting 3-D Secure transactions on-behalf-of (OBO) merchants. In an embodiment, a payer authentication response (PARes) message indicating enrollment in the 3-D Secure OBO merchants authentication service is received from an access control server by a computer and stored. The computer later receives a purchase transaction authorization request message, determines that data of the purchase transaction authorization request message matches stored PARes message data, and then injects a UCAF into the purchase transaction authorization request message to generate an updated transaction authorization request message. The updated transaction request message is then transmitted to an issuer financial institution for 3-D Secure purchase transaction authorization processing. US 10891610 B2 (“Powell”) discloses providing, along with a token, a token assurance level and data used to generate the token assurance level. At the time a token is issued, one or more Identification and Verification (ID&V) methods may be performed to ensure that the token is replacing a PAN that was legitimately used by a token requestor. A token assurance level may be assigned to a given token in light of the type of ID&V that is performed and the entity performing the ID&V. Different ID&Vs may result in different token assurance levels. An issuer may wish to know the level of assurance and the data used in generating the level of assurance associated with a token prior to authorizing a payment transaction that uses the token. US 20220044251 A1 (“Abouelenin”) discloses identifying types of network interactions. An example method includes generating, by a token service provider, a token for a payment account based on a request from a user, where the token includes an indicator of a type of transaction for which the token is available for use, and provisioning, by the token service provider, the token to a third party. In doing so, in response to use of the token in a transaction to the payment account, the indicator is included at a first data element of an authorization request for the transaction to the payment account thereby identifying the type of the transaction in the authorization request. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to RAVEN E YONO whose telephone number is (313)446-6606. The examiner can normally be reached Monday - Friday 8-5PM EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bennett M Sigmond can be reached on (303) 297-4411. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RAVEN E YONO/Primary Examiner, Art Unit 3694
Read full office action

Prosecution Timeline

Show 11 earlier events
Sep 26, 2025
Final Rejection mailed — §101
Dec 09, 2025
Applicant Interview (Telephonic)
Dec 09, 2025
Examiner Interview Summary
Dec 29, 2025
Request for Continued Examination
Feb 03, 2026
Response after Non-Final Action
Mar 12, 2026
Non-Final Rejection mailed — §101
Jun 12, 2026
Response Filed
Jun 29, 2026
Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699998
ONLINE AUTHENTICATION IN ACCESS TRANSACTIONS
1y 11m to grant Granted Aug 04, 2026
Patent 12646065
SYSTEMS AND METHODS FOR ACCOUNT MATCHING BASED ON PARTIAL PROFILE DATA
1y 9m to grant Granted Jun 02, 2026
Patent 12639689
SYSTEMS AND METHODS FOR MACHINE LEARNING INTEGRATION IN POINT-OF-SALE DEVICES
2y 5m to grant Granted May 26, 2026
Patent 12632859
HYBRID CONSENSUS MECHANISMS IN DISTRIBUTED TRUST COMPUTING NETWORKS IMPLICATING PROOF OF GEOGRAPHIC LOCATION
2y 9m to grant Granted May 19, 2026
Patent 12614234
GROUND TRUTH INSURANCE DATABASE
2y 11m to grant Granted Apr 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

7-8
Expected OA Rounds
40%
Grant Probability
72%
With Interview (+32.8%)
2y 8m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 182 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month