Prosecution Insights
Last updated: October 01, 2026
Application No. 18/312,402

MUTUAL AUTHENTICATION OF PEER-TO-PEER PAYMENTS

Non-Final OA §101
Filed
May 04, 2023
Examiner
KHATRI, NILESH B
Art Unit
3699
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Visa International Service Association
OA Round
3 (Non-Final)
62%
Grant Probability
Moderate
3-4
OA Rounds
0m
Est. Remaining
86%
With Interview

Examiner Intelligence

Grants 62% of resolved cases
62%
Career Allowance Rate
116 granted / 188 resolved
+9.7% vs TC avg
Strong +24% interview lift
Without
With
+24.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
16 currently pending
Career history
213
Total Applications
across all art units

Statute-Specific Performance

§101
30.7%
-9.3% vs TC avg
§103
41.2%
+1.2% vs TC avg
§102
5.4%
-34.6% vs TC avg
§112
17.4%
-22.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 188 resolved cases

Office Action

§101
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on July 30, 2026, has been entered. Status of Claims This communication is responsive to the submission filed July 30, 2026. Claim 18 is amended. Claims 1-17 are canceled. Claims 18-37 are pending. Response to Remarks 35 U.S.C. § 101 Applicant contends that the claims are directed towards patent eligible subject matter. First, Applicant contends that the additional elements were not considered individually and in combination to determine whether the claims recite a practical application. Examiner notes that Applicant’s remarks do not identify any other additional elements than those identified in the final Office Action. As to the contention that the additional elements were not considered individually and in combination, Examiner respectfully disagrees. As the final Office Action pp. 5-6 detail, the abstract ideas were first identified. Then, the additional elements were considered, both individually and in combination, and were found to be computers that perform the identified abstract ideas. Therefore, the additional elements were considered both individually and in combination. Therefore, Applicant’s contention that the additional elements were not properly evaluated both individually and in combination is unpersuasive. Applicant next contends that evaluating the additional elements of the processor, memory, and authentication server recite an improvement to the technical field of financial transactions by securely facilitating payments to an intended recipient. Examiner respectfully disagrees that securely facilitating payments to an intended recipient is an example of a technical improvement. It is important to keep in mind that an improvement in the abstract idea itself (e.g. a recited fundamental economic concept) is not an improvement in technology. See MPEP 2106.05(a)(II). Increasing security of payments to an intended recipient using abstract ideas appears to be an improvement to an abstract idea rather than an improvement in technology. Therefore, Applicant’s contention that the claims recite a technical improvement is unpersuasive. Applicant also contends that the amended language of using a first communication path and a second communication path recite additional elements that recite a practical application of the abstract ideas. Examiner respectfully disagrees. First, the claimed system, i.e., the client device, is recited as transmitting the encrypted message and the model hash key to the authentication server. The amended language recites that the encrypted message is configured to be transmitted to the recipient through the first communication path and the model hash key is configured to be transmitted to the recipient using the second communication path. However, as such subject matter is currently recited, the claimed client device is not transmitting the encrypted message through the first communication path to the recipient and the model hash key through the second communication path to the recipient. Rather, all that the claimed device is positively recited as performing is transmitting the encrypted message and the model hash key to the authentication server. Therefore, it does not appear that such subject matter serves to limit the functionality of the claimed client device. Second, sending messages through two different messengers, for example, recite an abstract idea that falls under the managing relationships between entities sub-category. Further, use of a computer or other machinery in its ordinary capacity for economic or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., a fundamental economic practice or mathematical equation) does not integrate a judicial exception into a practical application or provide significantly more. See MPEP 2106.05(f). Here, transmitting messages through two different communication channels is an example of using a computer to transmit data, which fails to recite a practical application or significantly more than the abstract idea. Therefore, Applicant’s contention that the amended language recites a practical application is unpersuasive. Accordingly, this ground of rejection is maintained. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 18-37 are rejected under 35 U.S.C. 101 because the claimed invention is directed to abstract ideas without significantly more. There are two criteria for subject matter eligibility. The first is that the claimed invention must be to one of the four statutory categories, i.e., a process, machine, manufacture, or composition of matter. See MPEP 2106(I). Second, the claimed invention also must qualify as patent-eligible subject matter, i.e., the claim must not be directed to a judicial exception unless the claim as a whole includes additional limitations amounting to significantly more than the exception. See MPEP 2106(I). Here, claims 18-37 are directed towards a machine. Therefore, the analysis proceeds to determine whether the claims recite abstract ideas. Per Claim 18: Claim 18, as a whole, is directed towards the abstract idea of generating a transaction request with recipient authentication information. In particular, the claim recites receiving an encryption key and using the encryption key to generate an encrypted transaction. The system generates a model hash key including an answer to a challenge, a payor identifier, and payee identifier. The claim transmits the encrypted transaction and model hash key to an authentication entity and receives a notification from the authentication entity of a confirmation of a successful validation or failed validation. In other words, the claim recites Certain Methods of Organizing Human Activities recognized as reciting abstract ideas. More specifically, the following underlined claim elements recite abstract ideas while the non-underlined claim elements recite additional elements according to MPEP 2106.04(a). a processor and a memory storing instructions, the instructions executable by the processor to: send a request to an authentication server for a public key of a recipient account or device; receive the public key from the authentication server; encrypt a transaction to generate an encrypted message, wherein the encrypted message comprises a challenge, the public key of the recipient account or device, and transaction details; generate a model hash key, the model hash key comprising a model answer to the challenge, an initiator user account identifier, and a recipient user account identifier; and transmit the encrypted message and the model hash key to the authentication server, wherein the encrypted message is configured to be transmitted to the recipient account or device through a first communication path, wherein the model hash key is configured to be transmitted to the recipient account or device through a second communication path, wherein the first communication path and the second communication path are different communication paths, and wherein the second communication path comprises an out-of-band communication channel; and receive a notification from the authentication server, wherein the notification comprises at least one of a confirmation of a successful validation or a failed validation. Because the claim recites abstract ideas, the analysis proceeds to determine whether the claim recites additional elements that recite a practical application of the abstract ideas. According to MPEP 2106.04(d), additional elements that recite an instruction to apply the abstract ideas using a computer, that recite insignificant extra-solution activities, or that generally link the use of the abstract ideas to a particular technological environment or field of use are not indicative of a practical application. Here, the additional elements of a processor, memory, and server are used to implement the abstract ideas using computers. In other words, these additional elements are instructions to apply the abstract ideas using computers. Therefore, the claim as a whole fails to recite a practical application of the abstract ideas. The analysis then proceeds to determine whether the additional elements, when considered individually and in combination, recite significantly more than the abstract ideas. According to MPEP 2106.05, additional elements that recite an instructions to apply the abstract ideas using a computer, that recite insignificant extra-solution activities, that generally link the use of the abstract ideas to a particular technological environment or field of use, or that recite well-understood, routine, and conventional activities are not indicative of reciting significantly more than the abstract ideas. Claim elements previously considered to recite insignificant extra-solution activities are reevaluated at this step to determine whether they recite well-understood, routine, and conventional activities. Such findings must be supported by the evidentiary requirements set forth in the Berkheimer Memo. Here, the additional elements of a processor, memory, and server are used to implement the abstract ideas using computers. In other words, these additional elements are instructions to apply the abstract ideas using computers. Therefore, the additional claim elements, when considered individually and in combination, fail to recite significantly more than the abstract ideas. Accordingly, claim 18 is rejected as being directed towards patent ineligible subject matter. Per Claims 19-37: Claims 19-37 have also been analyzed for subject matter eligibility. However, these claims also fail to recite patent eligible subject matter for the following reasons: Claim 19 recites the abstract idea of transferring funds from an initiator user account to an escrow account, which is a Certain Method of Organizing Human Activities. Claim 20 recites the abstract idea that the transaction details include amount of funds sent, amount of funds requested, type of funds send, type of funds requested, currency, bank account details, payment platform details, or transaction type, which is a Certain Method of Organizing Human Activities. Claim 21 recites the abstract idea of transferring funds from the escrow account to a recipient account based on a successful validation, which is a Certain Method of Organizing Human Activities. Claim 22 recites the abstract idea of transferring funds from the escrow account to an initiator account based on a failed validation, which is a Certain Method of Organizing Human Activities. Claim 23 recites the abstract idea that a successful validation is based on a match between the model answer and response from the recipient account within a time limit, which is a Certain Method of Organizing Human Activities. Claim 24 recites the abstract idea that a successful validation is based on a response from the recipient account satisfying an accuracy threshold corresponding to the model answer, which is a Certain Method of Organizing Human Activities. Claim 25 recites the abstract idea that a failed validation is based on an absence of a match between the model answer and response from the recipient account within a time limit, which is a Certain Method of Organizing Human Activities. Claim 26 recites the abstract idea of generating a second encrypted message and a second model hash key, i.e., a second transaction, which is a Certain Method of Organizing Human Activities. Claim 27 recites the abstract idea of that the first encrypted message and model hash key correspond to a first transaction and the second encrypted message and model hash key correspond to a second transaction, which is a Certain Method of Organizing Human Activities. Claim 28 recites the abstract idea that the first transaction is a pseudo transaction and the second transaction is a real transaction, which is a Certain Method of Organizing Human Activities. Claim 29 recites the abstract idea that the first and second transactions are real transactions, which is a Certain Method of Organizing Human Activities. Claim 30 recites the abstract idea that the two encrypted messages are identical and the two model hash keys are identical, which is a Certain Method of Organizing Human Activities. Claim 31 recites the abstract idea that the two encrypted messages are different and the two model hash keys are different, which is a Certain Method of Organizing Human Activities. Claim 32 recites the abstract idea that the recipient or the authentication entity store the public encryption key, which is a Certain Method of Organizing Human Activities. Claim 33 recites the abstract idea that the encrypted message and model hash key are stored by the authentication entity, which is a Certain Method of Organizing Human Activities. Claim 34 recites the abstract idea that the encrypted message and model hash key are stored for a certain amount of time, which is a Certain Method of Organizing Human Activities. Claim 35 recites the abstract idea that the transaction is completed based on a successful validation and the transaction is canceled based on a failed validation, which is a Certain Method of Organizing Human Activities. Claim 36 recites the abstract idea that a transaction is completed based on a successful negotiation between the client and recipient, which is a Certain Method of Organizing Human Activities. Claim 37 recites the abstract idea that a transaction is canceled based on an unsuccessful negotiation between the client and recipient, which is a Certain Method of Organizing Human Activities. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. U.S. Patent No. 11,074,581 discloses that an electronic device includes a communication module, a memory configured to store payment information registered in a payment application, and a processor. The processor is configured to select at least one of a plurality of authentication servers based on the payment information, receive authentication information from the at least one authentication server by using the communication module, select at least one payment information of the payment information registered in the payment application based on a user input, select first authentication information, which corresponds to the selected payment information, from among the authentication information, and send second authentication information, which is generated based on the selected first authentication information, to the at least one authentication server corresponding to the selected first authentication information. U.S. Patent Pub. No. 2004/0159700 discloses financial or other confidential information to be securely imported in electronic form into a PTD. The information to be imported is first encrypted. The encrypted information is then transmitted from a source to the PTD. The encrypted information is then stored by the PTD. A decryption key is sent to the PTD user in a manner establishing a strong non-repudiation scheme. For example, the decryption key could be sent from a second device, or through a second communication channel separate and distinct from the first communication channel. Utilizing the decryption key delivered through the second communication channel, the user is able to decrypt and access the information in the PTD for transactional purposes. U.S. Patent Pub. No. 2015/0213560 discloses a system, apparatus, and method for processing payment transactions that are conducted using a mobile device that includes a contactless element, such as an integrated circuit chip. An account holder is enabled to generate transaction related data and append that data to a transaction record or transaction identifier. The appended data and transaction record or identifier may be stored in the mobile payment device and/or provided to an Issuer. If provided to an Issuer, the transaction related data generated by the account holder may be used to supplement an account statement. The additional information generated by the account holder may be used to assist the account holder in determining if a transaction is valid by providing information that helps the account holder to recall the location or other aspect of the transaction. NPL “Adding Channel Binding for an Out-of-Band OTP Authentication Protocol in an Industrial Use-Case” by Sven Plaga, et al. (dated May 28, 2018) discloses that One Time Passwords (OTPs) are used to increase the security of the authentication process of networked applications. Smartphone based OTP schemes already brought usable and affordable multi-factor authentication to web applications. These schemes are also a promising approach for authentication in industrial applications. This paper introduces an industrial remote maintenance use-case that uses a smartphone based OTP authentication scheme using Quick-Response (QR) codes. In addition to a main communication and password authentication channel, the proposed scheme requires an out-of-band communication channel to transmit OTPs via smartphone. While baseline security for the channels can be achieved with Transport Layer Security (TLS), Out-of-Band Authentication (OOBA) remains vulnerable to Man-in-the-Middle (MitM) attacks in environments where the authenticity of a communicating party cannot be guaranteed. In order to mitigate this problem, it is crucial to establish a secure channel association. The enhancement proposed in this paper thus cryptographically binds successful out-of-band OTP authentications to the previously established data-channel with the help of TLS channel binding. Recommendations include common TLS libraries that support this feature as well as further considerations for a secure implementation. Any inquiry concerning this communication or earlier communications from the examiner should be directed to NILESH B KHATRI whose telephone number is (571)270-7083. The examiner can normally be reached 8:30 AM - 5:30 PM Monday-Friday, alternating Fridays off. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha Patel can be reached at (571) 270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NILESH B KHATRI/Primary Examiner, Art Unit 3699
Read full office action

Prosecution Timeline

May 04, 2023
Application Filed
Jun 12, 2025
Non-Final Rejection mailed — §101
Sep 12, 2025
Response Filed
Apr 30, 2026
Final Rejection mailed — §101
Jun 30, 2026
Response after Non-Final Action
Jul 30, 2026
Request for Continued Examination
Aug 03, 2026
Response after Non-Final Action
Sep 10, 2026
Non-Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743691
DIGITAL ASSET VAULT
1y 0m to grant Granted Sep 22, 2026
Patent 12737746
SYSTEMS AND METHODS OF ENCRYPTING TRANSACTION DATA
4y 0m to grant Granted Sep 15, 2026
Patent 12737805
METHODS AND SYSTEMS FOR ACCESSING ACCOUNT INFORMATION ELECTRONICALLY
2y 1m to grant Granted Sep 15, 2026
Patent 12737936
METHODS AND SYSTEMS FOR SECURE AUTHENTICATION IN A VIRTUAL OR AUGMENTED REALITY ENVIRONMENT
1y 9m to grant Granted Sep 15, 2026
Patent 12718231
CONVERSION OF CRYPTOCURRENCY TRANSACTIONS TO CENTRAL BANK DIGITAL CURRENCY FOR MERCHANT SYSTEMS
3y 6m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
62%
Grant Probability
86%
With Interview (+24.2%)
3y 2m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 188 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month