DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
This communication is responsive to the submission filed June 25, 2026.
Claims 1, 8, and 10-17 are amended.
Claims 23-24 are new.
Claims 1-20 and 23-24 are pending.
Response to Remarks
35 U.S.C. § 101
Applicant contends that the claims are directed towards patent eligible subject matter. First, Applicant contends that the claims do not recite Mental Processes as the human mind cannot perform cryptographic decryption and re-encryption on machine-formatted data and because the claim recites receiving data from a reader as well as one of a plurality of different merchant applications on a computer. Examiner respectfully disagrees. First, regarding the decryption and re-encryption, the claim recites such functionality generally. Therefore, the claim encompasses the most basic encryption techniques, which may be performed in the human mind, i.e., a Mental Process. Further, use of a computer or other machinery in its ordinary capacity for economic or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., a fundamental economic practice or mathematical equation) does not integrate a judicial exception into a practical application or provide significantly more. See MPEP 2106.05(f). Here, while the receiving and transmitting data may not be able to be performed in a human mind, such limitations recite using a computer to receive and transmit data. As the MPEP notes, such subject matter amounts to applying the abstract idea, i.e., the general decryption and re-encryption discussed above, using computers. Therefore, Applicant’s contention that the claims do not recite a Mental Process are unpersuasive.
Applicant also contends that the claims are not directed towards Certain Methods of Organizing Human Activities as the claims encompass a technical mechanism. Examiner respectfully disagrees because receiving encrypted payment data, generally decrypting the payment data, generally encrypting the payment data, and then transmitting the re-encrypted payment data to another entity, such as a payment processor, encompasses commercial interactions between, for example, a point of sale, a payment network, and a financial institution. As noted above, the encrypting and re-encrypting are recited at a level of generality that they do not necessarily require a technical implementation. Therefore, Applicant’s contention that the claims do not recite Certain Methods of Organizing Human Activities is unpersuasive.
Applicant also contends that the claims recite a practical application of the abstract and significantly more than the abstract ideas. Examiner respectfully disagrees. Examiners evaluate integration into a practical application by: (1) identifying whether there are any additional elements recited in the claim beyond the judicial exception(s); and (2) evaluating those additional elements individually and in combination to determine whether they integrate the exception into a practical application. See MPEP 2106.04(d)(II). Step 2B asks: Does the claim recite additional elements that amount to significantly more than the judicial exception? Examiners should answer this question by first identifying whether there are any additional elements (features/limitations/steps) recited in the claim beyond the judicial exception(s), and then evaluating those additional elements individually and in combination to determine whether they contribute an inventive concept. See MPEP 2106.05(II). While Applicant contends that the hardware security module is an additional element that recites a particular machine, Examiner respectfully disagrees that such hardware is recited as part of the claimed system. Rather, the claimed system only comprises a hardware processor; the claim fails to recite that the system also comprises a hardware security module. Therefore, as recited, the hardware security module is outside the scope of the claim. However, even if the hardware security module, as currently claimed, were to be considered part of the claimed system, the hardware security module performs abstract ideas. In other words, it amounts to an instruction to apply the abstract ideas using a second computer processor. Therefore, Applicant’s contention that the claims recite a practical application of the abstract idea and significantly more than the abstract idea is unpersuasive.
Accordingly, this ground of rejection is maintained.
35 U.S.C. § 103
Applicant’s arguments with respect to claim(s) 1-22 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Objections
The numbering of claims is not in accordance with 37 CFR 1.126 which requires the original numbering of the claims to be preserved throughout the prosecution. When claims are canceled, the remaining claims must not be renumbered. When new claims are presented, they must be numbered consecutively beginning with the number next following the highest numbered claims previously presented (whether entered or not).
Misnumbered claims 21-22 have been renumbered 23-24.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 and 23-24 are rejected under 35 U.S.C. 101 because the claimed invention is directed to abstract ideas without significantly more. There are two criteria for subject matter eligibility. The first is that the claimed invention must be to one of the four statutory categories, i.e., a process, machine, manufacture, or composition of matter. See MPEP 2106(I). Second, the claimed invention also must qualify as patent-eligible subject matter, i.e., the claim must not be directed to a judicial exception unless the claim as a whole includes additional limitations amounting to significantly more than the exception. See MPEP 2106(I). Here, claims 1-20 are directed towards a machine and claims 23-24 are directed towards a process. Therefore, the analysis proceeds to determine whether the claims recite abstract ideas.
Per Claim 1: Claim 1, as a whole, is directed towards the abstract idea of receiving various transaction data and transmitting the transaction data to a payment server to complete a transaction. In particular, the claim recites receiving a payment request for a transaction. The payment request includes payment information including a merchant code. The claim also receives encrypted payment data from a payment card reader. The encrypted payment data includes an account number associated with a customer. The system then transmits this information to a payment entity. The payment entity, which is not claimed as part of the system, then determines a payment service provider associated with the merchant code. In other words, the claim recites both Mental Processes as well as Certain Methods of Organizing Human Activities recognized as reciting abstract ideas. More specifically, the following underlined claim elements recite abstract ideas while the non-underlined claim elements recite additional elements according to MPEP 2106.04(a).
a. a hardware processor configured to:
i. receive a payment request for a payment transaction from one of a plurality of different merchant applications associated with a computing device wherein the request comprises payment information comprising a merchant code;
ii. in response to receiving the payment request, receive encrypted payment data from a reader coupled to the computing device wherein the payment data comprises an account number associated with a user wherein the account number is encrypted according to a first key; and
iii. transmit the payment information and the encrypted payment data to a payment server to determine a payment service provider associated with the merchant code, wherein the hardware processor is configured to cause the encrypted payment data to be transmitted to a hardware security module and wherein the hardware security module is configured to decrypt the encrypted payment data using the first key and to re-encrypt the decrypted payment data using an encryption key associated with the determined payment service provider.
Because the claim recites abstract ideas, the analysis proceeds to determine whether the claim recites additional elements that recite a practical application of the abstract ideas. According to MPEP 2106.04(d), additional elements that recite an instruction to apply the abstract ideas using a computer, that recite insignificant extra-solution activities, or that generally link the use of the abstract ideas to a particular technological environment or field of use are not indicative of a practical application. Here, the additional elements of a hardware processor, applications associated with a computing device, and a server are tools that are used to implement the abstract ideas on computers. In other words, they amount to an instruction to apply the abstract ideas using computers. Therefore, the claim as a whole fails to recite a practical application of the abstract ideas.
The analysis then proceeds to determine whether the additional elements, when considered individually and in combination, recite significantly more than the abstract ideas. According to MPEP 2106.05, additional elements that recite an instruction to apply the abstract ideas using a computer, that recite insignificant extra-solution activities, that generally link the use of the abstract ideas to a particular technological environment or field of use, or that recite well-understood, routine, and conventional activities are not indicative of reciting significantly more than the abstract ideas. Claim elements previously considered to recite insignificant extra-solution activities are reevaluated at this step to determine whether they recite well-understood, routine, and conventional activities. Such findings must be supported by the evidentiary requirements set forth in the Berkheimer Memo. Here, the additional elements of a hardware security module, applications associated with a computing device, and a server are tools that are used to implement the abstract ideas on computers. In other words, they amount to an instruction to apply the abstract ideas using computers. Therefore, the additional claim elements, when considered individually and in combination, fail to recite significantly more than the abstract ideas.
Accordingly, claim 1 is rejected as being directed towards patent ineligible subject matter.
Per Claim 23: Claim 23 recites abstract ideas similar to those discussed above in connection with claim 1 and does so in the context of a process. However, claim 23 fails to recite any additional elements not already considered in connection with claim 1. Therefore, claim 23 also fails to recite a practical application of the abstract ideas or significantly more than the abstract ideas.
Accordingly, claim 23 is rejected as being directed towards patent ineligible subject matter.
Per Claims 2-20 and 24: Claims 2-20 and 24 have also been analyzed for subject matter eligibility. However, these claims also fail to recite patent eligible subject matter for the following reasons:
Claim 2 recites the abstract idea of additional transaction specific information such as a location, a hardware identifier, and a merchant code, which are Certain Methods of Organizing Human Activities.
Claim 3 recites the abstract idea of receiving an encrypted personal identification number encrypted using a different key, which is a Certain Method of Organizing Human Activities.
Claim 4 recites the abstract idea of transmitting additional transaction specific data such as a merchant code and transaction identifier, which is a Certain Method of Organizing Human Activities.
Claim 5 recites the abstract idea that the data includes, for example, a transaction number and merchant code, which is a Certain Method of Organizing Human Activities.
Claim 6 recites the abstract idea of transmitting the payment data to a particular payment service provider based on a payment service provider identifier, which is a Certain Method of Organizing Human Activities.
Claim 7 recites the abstract idea of routing the payment request based on region of a merchant, which is a Certain Method of Organizing Human Activities.
Claim 8 recites the abstract idea of using a look-up table to determine a payment service provider key to transmit, which is a Mental Process and Certain Method of Organizing Human Activities.
Claim 9 recites the abstract idea of determining to which payment service provider to route the payment request based on a merchant code, location information, workstation identifier, and a look-up table, which is a Mental Process and Certain Method of Organizing Human Activities.
Claim 10 recites receiving an encrypted payment service provider key. This is insignificant extra-solution activity as it recites data gathering. See MPEP 2106.05(g). Further, it is well-understood, routine, and conventional activity as it recites receiving data over a network. See MPEP 2106.05(d)(II).
Claim 11 recites performing a key exchange based on a source identifier. This is insignificant extra-solution activity as it recites data gathering. See MPEP 2106.05(g). Further, it is well-understood, routine, and conventional activity as it recites receiving data over a network. See MPEP 2106.05(d)(II).
Claim 12 recites the abstract idea of transmitting the encrypted payment data and an encrypted payment service provider key to another entity, which is a Certain Method of Organizing Human Activities.
Claim 13 recites the abstract idea of decrypting the payment data using two keys, which is a Mental Process as it is recited at a high level of generality.
Claim 14 recites the abstract idea of decrypting an encrypted payment service provider key and re-encrypt the decrypted payment data using the decrypted payment service provider key, which is a Mental Process as it is recited at a high level of generality.
Claim 15 recites the abstract idea of encrypting payment data according to a particular payment service provider format, which is a Mental Process as it is recited at a high level of generality.
Claim 16 recites the abstract idea of transmitting the payment data to a security entity, which is a Certain Method of Organizing Human Activities.
Claim 17 recites the abstract idea of transmitting the payment data to a payment entity, which is a Certain Method of Organizing Human Activities.
Claim 18 recites the abstract idea that the reader receives a validation response, which is a Certain Method of Organizing Human Activities.
Claim 19 recites the abstract idea that the payment data is encrypted, which is a Mental Process as it is recited at a high level of generality.
Claim 20 recites the abstract idea that the payment data is secured at all stages of communication, which is a Certain Method of Organizing Human Activities.
Claim 24 is directed towards a non-transitory computer-readable medium that performs the method of claim 23. However, it fails to recite any additional elements not considered in connection with claim 23. Therefore, it also fails to recite a practical application of the abstract ideas or significantly more than the abstract ideas.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 1, 4, 15-20, and 23-24 is/are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Patent Pub. No. 2021/0312339 to Stogo et al. in view of U.S. Patent Pub. No. 2010/0318468 to Carr et al., and U.S. Patent Pub. No. 2010/0017332 to Kight et al.
Per Claim 1: Stogo discloses:
A payment processing system comprising: (see Stogo at Abstract: A method and system may reduce latency and improve connectivity by performing offline authorization of products and services related to airline reservations.)
a hardware processor configured to: (see Stogo at ¶ 21: Moreover, the server device 102 may include a memory 140, one or more processors 132 such as a microcontroller or a microprocessor, a random-access memory, and/or an input/output (I/O) circuit, all of which may be interconnected via an address/data bus.)
i. receive a payment request for a payment transaction from one of a plurality of different merchant applications associated with a computing device wherein the request comprises payment information [[comprising a merchant code]]; (see Stogo at ¶ 38: The client device 106-116 transmits 202 a request for a product or service related to an airline reservation to the server device 102, such as an airline ticket for a departing flight, a seat assignment on the departing flight, an upgrade to a different travel class on the departing flight, fees for the departing flight, etc. The request may include payment information for the product or service, such as a credit or debit card number, a credit or debit card expiration date, a credit or debit card security code, a card type (e.g., MasterCard®), a cardholder name, etc.)
ii. in response to receiving the payment request, receive [[encrypted]] payment data from a reader coupled to the computing device wherein the payment data comprises an account number associated with a user [[wherein the account number is encrypted according to a first key]]; and (see Stogo at ¶ 54: The offline retry engine 135 transmits 414 a message to the client device 106-116 indicating that the transaction has been declined and requesting an alternative method of payment. The user may then provide an alternative method of payment via the client device 106-116 which is sent 416 to the offline retry engine 135.)
iii. transmit the payment information and the [[encrypted]] payment data to a payment server [[to determine a payment service provider associated with the merchant code]], (see Stogo at ¶ 54: Accordingly, the offline retry engine 135 transmits 418 the payment information for the alternative method of payment to the payment service provider 142, which may authorize the payment and transmit a payment authorization including a valid approval code to the offline retry engine 135. See also ¶ 41: In any event, the payment authorization module 134 transmits 206 payment information for the product or service related to the airline reservation to a payment service provider 142.)
However, Stogo fails to disclose but Carr, an analogous art of encrypting and re-encrypting transaction information, discloses:
wherein the request comprises payment information comprising a merchant code; (see Carr at ¶ 91: In the exemplary embodiment, this means that the MID is transmitted in encrypted form from Zone 1 to Zone 2.)
receive encrypted payment data, wherein the account number is encrypted according to a first key (see Carr at ¶ 80: Those fields of the transaction data generated by the Zone 1 application processing that are considered to be sensitive (and therefore needing of protection, such as the Merchant Identifier—“MID”) are then encrypted using the merchant device-specific symmetric key (step 309) in order to further protect other sensitive data that may have been added as a result of the Zone 1 application processing (e.g., other data elements that are sensitive to the implementing entity's payment card processing operations but not necessarily payment card data, such as a Merchant Identifier). In some embodiments the fields that are encrypted include track data, PAN, and MID. In alternative embodiments, other fields, such as Card Verification Value 2 (CVV2), may also be encrypted.)
wherein the hardware processor is configured to cause the encrypted payment data to be transmitted to a hardware security module and (see Carr at ¶ 96: Accordingly, here as well as in the claims, any description of the Zone 2 Gateway “encrypting” or “decrypting” data should be construed to include the Zone 2 Gateway 400 making suitable requests of the Hardware Security Module 411 to have the desired action carried out on its behalf, with the results being returned. In this sense, the Hardware Security Module is made a virtual part of the Zone 2 Gateway, even though it may be a physically distinct element within the entire electronic payment system.)
wherein the hardware security module is configured to decrypt the encrypted payment data using the first key and to re-encrypt the decrypted payment data using an encryption key associated with the determined payment service provider. (see Carr at ¶ 98: The merchant device-specific symmetric key is then used to decrypt the received encrypted transaction data (step 507). In the exemplary embodiment, the host-specific encryption key is a symmetric key that is then used to encrypt the decrypted transaction data, thereby forming re-encrypted transaction data (step 509). The re-encrypted transaction data is then communicated to a Zone 3 server (step 511).)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that the payment information is decrypted and then re-encrypted to send to a third-party processor using the techniques disclosed in Carr. One of ordinary skill in the art would have been motivated to do so to increase the security of the transactions.
However, the combination of Stogo and Carr fails to disclose but Kight, an analogous art of determining a third-party transaction processor, discloses:
iii. transmit the payment information and the encrypted payment data to a payment server to determine a payment service provider associated with the merchant code, (see Kight at ¶ 26: The first payment service provider transmits a request to determine the payment network with which the payee is associated. This transmitted request preferably includes any identifying information included in the received payment request, though it could include only a portion of this information, or it could include information other than that included in the received payment request. That is, the first payment service provider could add to or modify the information identifying the payee. In response to the transmitted request, the first payment service provider receives information indicating that the payee is associated with the second payment network. The first payment service provider then transmits a payment instruction to the second payment service provider.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that a request is sent to determine a payment network associated with the merchant using the techniques disclosed in Kight. One of ordinary skill in the art would have been motivated to do so to determine the correct payment network for processing the transaction given a merchant.
Per Claim 23: Claim 23 recites subject matter similar to that discussed above in connection with claim 1 and does so in the context of a process, which Stogo discloses (see ¶ 7: In an embodiment, a method for reducing latency and improving connectivity when processing airline transactions is provided.)
Per Claim 24: Claim 24 recites subject matter similar to that discussed above in connection with claim 23 and does so with a non-transitory computer readable medium, which Stogo discloses (see ¶ 9: In yet another embodiment, a non-transitory computer readable memory includes computer-executable instructions stored thereon.)
Per Claim 4: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 4 depends. Stogo further discloses:
wherein the hardware processor is further configured to transmit further data comprising a serial device number, a transaction identifier for merchant tracking information to the payment server and wherein the data transmitted from a module executed by the hardware processor to the payment server is transmitted in a source identifier message. (see Stogo at ¶ 39: The server device 102 may then communicate with an airline reservations database 124, such as SHARES, Amadeus, Travelport, SABRE, etc., to generate 204 an airline reservation indicator (e.g., a PNR) for the user indicating that the product or service has been reserved for the user. The airline reservation indicator may be stored in the airline reservations database 124. Additionally, when the product or service related to the reservation is a seat assignment for example, the server device 102 and/or the airline reservations database 124 may not generate a new airline reservation indicator, but instead may update the information associated with a previously generated airline reservation indicator for the departing flight in which the seat assignment is selected. This may also be the case when the product or service related to the reservation is fees. The server device 102 may then store the updated information (e.g., fees have been paid for two bags for PNR 12345 corresponding to flight 1111 from Los Angeles to Denver on Dec. 7, 2019 at 4 p.m., seat 28C has been selected for PNR 12345 corresponding to flight 1111, etc.) in the airline reservations database 124.)
However, Stogo fails to disclose but Carr discloses:
wherein the hardware processor is further configured to transmit data comprising any one or more of a merchant code, a workstation name, and a location identifier or code to the payment server and (see Carr at ¶ 91: In the exemplary embodiment, this means that the MID is transmitted in encrypted form from Zone 1 to Zone 2.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that various merchant information is used to authorize a transaction as disclosed in Carr. One of ordinary skill in the art would have been motivated to do so to increase the security of the transaction.
Per Claim 15: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 15 depends. However, Stogo fails to disclose but Carr discloses:
wherein a hardware security module is further configured to encrypt the payment data according to a particular payment service provider format. (Examiner’s Note: this claim element has been considered and determined to be outside the scope of the claim. It is outside the scope of the claim because a hardware security module has not been recited as being part of the claimed payment processing system. However, for compact prosecution purposes, the following citation is provided: see Carr at ¶ 123: The first approach is format-preserving encryption (FPE). FPE generates an encrypted number that fits the industry-standard 16 digit format of PANs. This has the benefit of enabling standard Application software to process encrypted data without encountering formatting errors (e.g., incorrect encoding of digits, missing self-references within the digits, etc.))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that the payment request is in a format of the payment processor using the techniques disclosed in Carr. One of ordinary skill in the art would have been motivated to do so to ensure that the payment processor can properly process the transaction request.
Per Claim 16: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 16 depends. However, Stogo fails to disclose but Carr discloses:
wherein a further hardware security module is further configured to transmit the payment data encrypted using a payment service provider key to the security module. (Examiner’s Note: this claim element has been considered and determined to be outside the scope of the claim. It is outside the scope of the claim because a security module has not been recited as being part of the claimed payment processing system. However, for compact prosecution purposes, the following citation is provided: see Carr at ¶ 98: The merchant device-specific symmetric key is then used to decrypt the received encrypted transaction data (step 507). In the exemplary embodiment, the host-specific encryption key is a symmetric key that is then used to encrypt the decrypted transaction data, thereby forming re-encrypted transaction data (step 509). The re-encrypted transaction data is then communicated to a Zone 3 server (step 511).)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that the payment information is decrypted and then re-encrypted to send to a third-party processor using the techniques disclosed in Carr. One of ordinary skill in the art would have been motivated to do so to increase the security of the transactions.)
Per Claim 17: The combination of Stogo, Sheets, and Kight discloses the subject matter of claim 1, from which claim 17 depends. However, Stogo fails to disclose but Carr discloses:
wherein a hardware security module is further configured to transmit the payment data encrypted using a payment service provider key to the payment server. (Examiner’s Note: this claim element has been considered and determined to be outside the scope of the claim. It is outside the scope of the claim because a security module has not been recited as being part of the claimed payment processing system. However, for compact prosecution purposes, the following citation is provided: see 98: The merchant device-specific symmetric key is then used to decrypt the received encrypted transaction data (step 507). In the exemplary embodiment, the host-specific encryption key is a symmetric key that is then used to encrypt the decrypted transaction data, thereby forming re-encrypted transaction data (step 509). The re-encrypted transaction data is then communicated to a Zone 3 server (step 511).)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that the payment information is decrypted and then re-encrypted to send to a third-party processor using the techniques disclosed in Carr. One of ordinary skill in the art would have been motivated to do so to increase the security of the transactions.
Per Claim 18: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 18 depends. Stogo further discloses:
wherein the reader is further configured to receive a validation response of the payment request via the hardware processor and further via the payment server. (see Stogo at ¶ 44: Then the payment authorization module 134 transmits 218 an order confirmation message to the client device 106-116 indicating that the payment was successful and that the product or service has been reserved for the user. The order confirmation message may also include the airline reservation indicator.)
Per Claim 19: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 19 depends. However, Stogo fails to disclose but Carr discloses:
wherein the payment data is encrypted at a message level and wherein the payment data comprises payment card information in particular any one or more of a card number, expiry date, owner name, security code and payment transition validation data. (see Carr at ¶ 80: Those fields of the transaction data generated by the Zone 1 application processing that are considered to be sensitive (and therefore needing of protection, such as the Merchant Identifier—“MID”) are then encrypted using the merchant device-specific symmetric key (step 309) in order to further protect other sensitive data that may have been added as a result of the Zone 1 application processing (e.g., other data elements that are sensitive to the implementing entity's payment card processing operations but not necessarily payment card data, such as a Merchant Identifier). In some embodiments the fields that are encrypted include track data, PAN, and MID. In alternative embodiments, other fields, such as Card Verification Value 2 (CVV2), may also be encrypted.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that cardholder information is encrypted using the techniques disclosed in Carr. One of ordinary skill in the art would have been motivated to do so to increase the security of the transaction.
Per Claim 20: The combination of Stogo, Sheets, and Kight discloses the subject matter of claim 1, from which claim 20 depends. However, Stogo fails to disclose but Sheets discloses:
wherein the payment data is encrypted at all stages between the reader and the payment service provider. (see Carr at ¶ 149: This section describes at a high level end-to-end encryption (“E3”) features at a terminal.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that end-to-end encryption is used using the techniques disclosed in Carr. One of ordinary skill in the art would have been motivated to do so to increase the security of the transaction.
Claim(s) 2, 5-6, and 9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Stogo, Carr, and Kight as applied to claim 1 above, and further in view of U.S. Patent Pub. No. 2015/0019443 to Sheets et al.
Per Claim 2: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 2 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Sheets, an analogous art of encrypting and re-encrypting transaction information, discloses:
wherein the hardware processor is further configured to determine a location identifier associated with an application based on the location of hardware on which the application is installed and to determine a workstation identifier associated with the hardware and further to determine a merchant code based on a received merchant code. (see Sheets at ¶ 41: For example, transaction information may include a transaction amount, transaction time, transaction date, merchant information (e.g., registered merchant identifier, address, merchant computer IP address, etc.), product information (e.g., serial numbers, product names or other identifiers, etc.). See also ¶ 78: An authorization request message may also comprise “transaction information,” such as any information associated with a current transaction, such as the transaction amount, merchant identifier, merchant location, etc., as well as any other information that may be utilized in determining whether to identify and/or authorize a transaction.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that various merchant information is used to authorize a transaction as disclosed in Sheets. One of ordinary skill in the art would have been motivated to do so to increase the security of the transaction.
Per Claim 5: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 5 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Sheets discloses:
wherein the payment request comprises device information in particular any one or more of a device serial number, a terminal type, a transaction number, a merchant code as well as location information associated with the computing device or a location identifier or code. (see Sheets at ¶ 41: For example, transaction information may include a transaction amount, transaction time, transaction date, merchant information (e.g., registered merchant identifier, address, merchant computer IP address, etc.), product information (e.g., serial numbers, product names or other identifiers, etc.). See also ¶ 78: An authorization request message may also comprise “transaction information,” such as any information associated with a current transaction, such as the transaction amount, merchant identifier, merchant location, etc., as well as any other information that may be utilized in determining whether to identify and/or authorize a transaction.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that various merchant information is used to authorize a transaction as disclosed in Sheets. One of ordinary skill in the art would have been motivated to do so to increase the security of the transaction.
Per Claim 6: The combination of Stogo, Carr, Kight, and Sheets discloses the subject matter of claim 5, from which claim 6 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Sheets discloses:
wherein the payment server is further configured to transmit the payment data to a particular payment service provider based on a determined payment service provider identifier. (Examiner’s Note: this claim element has been considered and determined to recite subject matter outside the scope of the claim. It is outside the scope of the claim because it recites functions performed by the payment server, which is not claimed. However, for compact prosecution purposes, the following citation is provided: see Sheets at ¶ 206: Accordingly, the payment information may be encrypted with a third party server computer public key (e.g., mobile wallet provider public key) and the encrypted payment information may be sent to the third party service provider server computer (e.g., mobile wallet provider) for further remote transaction processing.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that the transaction is sent to the payment processor based on the identifier as disclosed in Sheets. One of ordinary skill in the art would have been motivated to do so transmit the transaction request to the correct payment processor.
Per Claim 9: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 9 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Sheets discloses:
wherein the hardware processor is further configured to determine one of a plurality of different payment service providers to route the payment request to based on any one or more of a merchant code and a location information or code and a workstation identifier and a particular payment service provider identifier and a comparison with a look-up table. (see Sheets at ¶ 155: The merchant identifier may be included in a payment request which may allow the transaction processing module 161(C) of the payment processing network 160 to identify the appropriate transaction processor public key associated with the transaction.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that merchant information is used to determine to which payment processor to forward the transaction request using the techniques disclosed in Stogo. One of ordinary skill in the art would have been motivated to do so to route the transaction request to the correct payment processor.
Claim(s) 3 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Stogo, Carr, and Kight as applied to claim 1 above, and further in view of U.S. Patent Pub. No. 2013/0212026 to Powell et al.
Per Claim 3: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 3 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Powell, an analogous art of encrypting transaction information, discloses:
wherein the hardware processor is further configured to receive further encrypted payment data comprising a PIN number encrypted according to a second key for the PIN number wherein the first key is different from the second key. (see Powell at ¶ 47: The PIN may be encrypted using a first transaction key derived from the initial key and sensitive data may be encrypted using a second transaction key derived from the initial key.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that a personal identification number is encrypted using the techniques disclosed in Powell. One of ordinary skill in the art would have been motivated to do so to protect sensitive transaction information.
Per Claim 13: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 13 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Powell discloses:
wherein a further security module is configured to decrypt the encrypted payment data using the first key and using a second key. (Examiner’s Note: this claim element has been considered and determined to be outside the scope of the claim as the claim does not recite that the system also comprises a further security module. However, for compact prosecution purposes, the following citation is provided: see Powell at ¶ 51: Translation by merchant host TRSM 110 can include decryption of PIN and sensitive data in the authorization request message received from access device 104 and re-encryption of the PIN and sensitive data using one or more Zone Encryption Keys (ZEK). See also ¶ 47: The PIN may be encrypted using a first transaction key derived from the initial key and sensitive data may be encrypted using a second transaction key derived from the initial key.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that the data is decrypted using the techniques disclosed in Powell. One of ordinary skill in the art would have been motivated to do so to process the payment data.
Claim(s) 7 is/are rejected under 35 U.S.C. 103 as being unpatentable over Stogo, Carr, and Kight as applied to claim 1 above, and further in view of U.S. Patent Pub. No. 2007/0233603 to Schmidgall et al.
Per Claim 7: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 7 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Schmidgall, an analogous art of routing transactions, discloses:
wherein the hardware processor is further configured to transmit data which allows the payment request to be routed from one of a plurality of different merchants in different regions to one of a plurality of different payment service providers in each region. (see Schmidgall at ¶¶ 150-152: Send transactions that have originated from the US and exceed or equal $200 to the first MID; Send transactions that have originated from the US and are less than $200 to the second MID; Send transactions that have originated outside the US to the third MID.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that transactions are routed based on geography using the techniques disclosed in Schmidgall. One of ordinary skill in the art would have been motivated to do so to decrease the latency.
Claim(s) 8 is/are rejected under 35 U.S.C. 103 as being unpatentable over Stogo, Carr, Kight, and Schmidgall as applied to claim 7 above, and further in view of EP 2,996,079 to Tahon et al.
Per Claim 8: The combination of Stogo, Carr, Kight, and Schmidgall discloses the subject matter of claim 7, from which claim 8 depends. However, the combination of Stogo, Carr, Kight, and Schmidgall fails to disclose but Tahon, an analogous art of secured transactions, discloses:
wherein a first module determines which of a plurality of payment service provider keys to transmit to a second module based on a look-up table of a plurality of payment service provider identifiers and associated payment service provider keys and wherein each payment service provider key is encrypted. (Examiner’s Note: this claim element has been considered and determined to be outside the scope of the claim as the claim fails to recite that the system comprises either the second module or the third module. However, for compact prosecution purposes, the following citation is provided: see Tahon at ¶¶ 17-20: In some embodiments, an operator-specific master-transport key is transmitted from at least one payment provider to the controlling entity in a confidentiality-securing manner. This operator-specific master-transport key is unique per operator and controlling entity. It is, for example, generated securely in the payment provider's tamper-resistant security module (TRSM) and then communicated to the controlling entity in the confidentiality-securing manner. The controlling entity stores the operator-specific master-transport key, for example, in another tamper-resistant security module (TRSM). An operator- and terminal-specific transport key is derived, both at the payment provider's end and the controlling entity's end, e.g. in the respective TRSMs, from the operator-specific master-transport key using the terminal-identification number, which is, for example, a serial number of the payment terminal. The operator- and terminal-specific transport key, derived by the controlling entity is symmetrically encrypted, with the terminal-specific access key and then the encrypted operator- and terminal-specific transport key is transmitted to the payment terminal.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that a plurality of encryption keys is transmitted to a kiosk using the techniques disclosed in Tahon. One of ordinary skill in the art would have been motivated to do so to enable multiple merchants to use a single kiosk.
Claim(s) 10-12 and 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Stogo, Carr, and Kight as applied to claim 1 above, and further in view of Tahon.
Per Claim 10: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 10 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Tahon discloses:
further comprising a module configured to receive an encrypted payment service provider key from a server. (see Tahon at ¶ 20: The operator- and terminal-specific transport key, derived by the controlling entity is symmetrically encrypted, with the terminal-specific access key and then the encrypted operator- and terminal-specific transport key is transmitted to the payment terminal.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that a plurality of encryption keys is transmitted to a kiosk using the techniques disclosed in Tahon. One of ordinary skill in the art would have been motivated to do so to enable multiple merchants to use a single kiosk.
Per Claim 11: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 11 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Tahon discloses:
wherein a second module is configured to perform a key exchange function with a Payment Service provider associated with the merchant or transaction and wherein a module is configured to perform a key exchange ceremony based on a source ID or source identifier. (Examiner’s Note: this claim element has been considered and determined to be outside the scope of the claim as the claim does not recite that the system comprises a second module. However, for compact prosecution purposes, the following citation is provided: see Tahon at ¶¶ 67-68: The payment-provider system is arranged to transmit the operator-specific master-transport key to a controlling entity in a confidentiality-securing manner, wherein the payment terminal is associated with the controlling entity. Alternatively, the payment-provider system is arranged to transmit the operator- and terminal-specific transport key to the controlling entity in a confidentiality-securing manner. The payment-provider system may encrypt the operator- and terminal-specific initial-encryption key symmetrically with the operator- and terminal-specific transport key and may feed the operator- and terminal-specific initial-encryption key into the payment terminal by transmitting the encrypted operator- and terminal-specific initial-encryption key to the payment terminal.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that encryption keys are exchanged using the techniques disclosed in Tahon. One of ordinary skill in the art would have been motivated to do so to enable encrypted communications of sensitive information.
Per Claim 12: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 12 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Tahon discloses:
wherein a module is configured to transmit the encrypted payment data and an encrypted payment service provider key to a further security module. (Examiner’s Note: this claim element has been considered and determined to be outside the scope of the claim as the claim does not recite that the system comprises the second module. However, for compact prosecution purposes, the following citation is provided: see Tahon at ¶ 118: Hence, the actual encrypted transmission of sensitive data S 17 of the payment transaction 26 between the payment terminal 1 and the payment provider 2 can be performed using the above-mentioned transaction keys.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that encrypted payment data and encryption key are provided to another module using the techniques disclosed in Tahon. One of ordinary skill in the art would have been motivated to do so to increase the security of the system.
Per Claim 14: The combination of Stogo, Carr, and Kight discloses the subject matter of claim 1, from which claim 14 depends. However, the combination of Stogo, Carr, and Kight fails to disclose but Tahon discloses:
wherein a further security module is further configured to decrypt an encrypted payment service provider key using a further key and to re-encrypt the decrypted payment data using the decrypted payment service provider key. (Examiner’s Note: this claim element has been considered and determined to be outside the scope of the claim as the system does not comprise a further security module. However, for compact prosecution purposes, the following citation is provided: see Tahon at ¶ 114: As another sub-process, after the operator- and terminal-specific initial-encryption key K6 has been obtained and decrypted at the payment terminal 1 (either in advance, or "on the fly" during the initialization-of-a-transaction stage), transaction keys for further transaction activities can be derived from the decrypted operator- and terminal-specific initial-encryption key K6 using a transaction-specific number 27, which is labeled as S 14 in Fig. 4 . As indicated by the labeling, the derivation S 14 of the operator- and transaction-specific encryption key K7 from the operator- and terminal-specific initial-encryption key K6 by the payment terminal 1 using the transaction-specific number 27 is one of these transaction keys. The derivation is performed in an analogous manner at the payment provider 2, there labeled as S 13.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Stogo so that encryption keys are securely distributed as disclosed in Tahon. One of ordinary skill in the art would have been motivated to do so to increase the security of the system.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
U.S. Patent Pub. No. 2007/0282756 discloses that a user may select or create a PIN at a non-secure input device, such as a web-enabled personal computer. PINs are stored at a financial host in encrypted form, as PIN offsets. The user selected PIN and a corresponding account number are sent in clear text form to the host, which selects a base PIN offset corresponding to the PIN. A host security module within the host converts the base PIN offset to an actual PIN offset using the actual account number. The actual PIN offset (corresponding to the new PIN and the account number) is then stored at the financial host.
U.S. Patent Pub. No. 2009/0281949 discloses that a mobile payment device 130 obtains a password from a customer for processing a payment transaction. The mobile payment device 130 encrypts the password using a public key. The mobile payment device 130 transmits the public key encrypted password via a network 140 to a cryptographic conversion host 150 which decrypts it using a private key corresponding to the public key. The cryptographic conversion host 150 re-encrypts the decrypted password with a secret key and provides the secret key encrypted password to a transaction host 160. The transaction host 160 decrypts the secret key encrypted password using an identical secret key and applies the decrypted password to process the payment transaction.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to NILESH B KHATRI whose telephone number is (571)270-7083. The examiner can normally be reached 8:30 AM - 5:30 PM Monday-Friday, alternating Fridays off.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha Patel can be reached at (571) 270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/NILESH B KHATRI/Primary Examiner, Art Unit 3699