DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The amendment filed 19 May 2026 has been entered. Applicant amended claims 21 and 32; previously cancelled claims 1-20, 23, 25-26, 34, and 36-37. Accordingly, claims 21-22, 24, 27-33, 35, and 38-40 remain pending.
Response to Arguments
Regarding the 35 USC 101 Rejection:
Applicant's arguments filed 19 May 2026 have been fully considered but they are not persuasive.
Applicant’s remarks:
Applicant respectfully submits that the amended claims are eligible under § 101,
at least because the claims integrate any alleged judicial exception into a practical
application at Step 2A, Prong Two of the Alice/Mayo test…the claims provide an improvement to account security by governing secure sharing of data between multiple parties, such as between a mobile network operator and a service provider, and ensuring that sensitive user data is not shared without the user's consent. This shared data can be used by the service providers to, for example, authenticate user accesses, further protecting users and user data.
In particular, amended claim 21 recites maintaining a "plurality of consent records"
including "consent data," where each consent data includes "a service provider identifier,
a consent status, and a consent method”. Furthermore, amended claim 21 recites that
"the consent status govern[s] sharing of data by the mobile network operator with a
service provider associated with the service provider identifier of the consent data when
the consent method conforms to a consent collection requirement associated with sharing
the data”. This reflects an improvement to account security at least in that the consent
status governs the sharing of data, by the mobile network operator with service providers,
according to the consent given by the users, allowing sensitive data to be protected while
also allowing the sensitive data to be used by the authorized service providers for tasks
such as user authentication. Furthermore, the consent method is used to govern the
sharing of data, by the mobile network operator, such that the data sharing is consistent
with consent collection requirements associated with sharing the data. The consent
collection requirements can, for example, be imposed by the mobile network operator and
can reflect legal requirements of a country in which the mobile network operator is
operating. Applicant's specification recites that countries may "require mobile network
operators to collect user consent via specific collection methods (e.g., an SMS-based opt-
in message from the user providing consent)”. (Specification at 1 [0033].) Thus, the
mobile network operator may be prevented from sharing data with service providers
unless the user consent was collected according to the consent collection requirements.
Therefore, maintaining the consent method further improves the ability of the mobile
network operators to securely share user data.
These improvements address technical issues associated with the sharing of
sensitive user data by mobile network operators. See MPEP 2106.05(a)(I) and Amdocs
(Israel), Ltd. V. Openet Telecom, Inc., 841 F.3d 1288, 1300-01, 120 USPQ2d 1527, 1536-
37 (Fed. Cir. 2016) (directed to a distributed network architecture that reduces network
congestion while generating networking accounting data records). Thus, amended claim
21 is eligible under Step 2A(2) of the Alice/Mayo inquiry because the claim integrates any
alleged abstract idea into a practical application by providing specific improvements to
account security and digital privacy.
Examiner’s remarks:
The limitation of “wherein each consent data includes a service provider identifier, a consent status, and a consent method” merely narrows the limitation of the consent data that is maintained or stored in the computer system. In other words, the limitations merely provide additional details about the consent data, but is not limiting or adding process steps to the claimed method.
It has been determined that the limitation of “the consent status govern[s] sharing of data by the mobile network operator with a service provider associated with the service provider identifier of the consent data when the consent method conforms to a consent collection requirement associated with sharing the data” is an intended result of the maintaining of the data and does not add significantly more to the abstract idea. The details of the governing of the sharing of the data is not utilized in the steps of the claims and therefore there is no functional relationship between the sharing of the data and the remaining steps of the claims.
Therefore, the claims do not provide additional elements that amounts to significantly more than the abstract idea.
The judicial exception alone is not eligible subject matter if there are no additional claim elements besides the judicial exception. Therefore, the claims fail to recites additional steps that apply or use the judicial exception in some other meaningful way beyond generally linking the use of the judicial exception to a particular technological environment.
Applicant’s remarks:
However, even if the claims were found to be directed to an abstract idea at Step
2A of the Alice framework, Applicant respectfully submits that the claims recite an
inventive concept at Step 2B. For example, the specific combination of maintaining a
plurality of consent records, each associated with a mobile device of a user and a mobile
network operator with which the user is subscribed, where each consent record includes
a plurality of consent data including a service provider identifier, a consent status, and a
consent method, where the sharing of data by mobile network operator with a service
provider is governed based on the consent status and the consent method, and updating
such a consent record with information from a consent update, represents a novel
technical improvement in the field of consent management systems. The specific
combination of claimed elements is not taught by the prior art and provides a technical
solution to a technical problem, thus demonstrating an inventive concept as required at
Step 2B. For at least the foregoing reasons, independent claim 21 complies with Section
101. Independent claim 32 has been amended to contain similar features and also comply
with Section 101 for at least the reasons indicated above with respect to claim 21. Thus,
Applicant respectfully requests withdrawal of the rejection under Section 101.
The preceding remarks are not to be used for claim construction or any other
similar purpose, but are presented solely in connection with a $101 analysis. Applicant
reserves the right to argue regarding the patent eligibility of the claims on any basis even
if not presented herein for the sake of clarity and conciseness.
Examiner’s remarks:
Maintaining the plurality of records at a computer system is merely storage of data which is activity that is well-understood routine and conventional. The limitation does not amount to more than the abstract idea of a mental process. Regarding the limitation of the consent record, please see examiner’s remarks above.
The judicial exception alone is not eligible subject matter if there are no additional claim elements besides the judicial exception. Therefore, the claims fail to recites additional steps that apply or use the judicial exception in some other meaningful way beyond generally linking the use of the judicial exception to a particular technological environment.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 21-22, 24, 27—33,35, and 39-40 are rejected under 35 U.S.C. 101 because the claimed invention is directed to the abstract idea of a mental process without significantly more. The independent claim(s) recite(s) “selecting, from the plurality of consent records, a consent record based on the user identifier of the consent record and the user identifier of the consent update”; “determining whether any of the plurality of consent data, of the selected consent record, is associated with the service provider identifier of the consent update”, “updating the selected consent record…”, “when it is determined that one of the consent data…updating the consent data based on the consent update”, “when it is determined that none of the consent data…generating a new consent data associated with the selected consent record…”.
The limitations above pertaining to the method for maintaining consent records for a plurality of users are directed to steps that under its broadest reasonable interpretation covers performance of the limitations being an abstract idea directed to a mental process. The steps can be manually performed by a human using pencil and paper. Therefore, nothing in the claimed elements preclude the steps from being practically performed manually by a human via a mental process using pencil and paper. If a claim under its broadest reasonable interpretation covers performance in the mind, or by a human using pencil and paper, then it falls within the mental processing grouping of abstract ideas. Accordingly, claims 21 and 32 recite an abstract idea.
This judicial exception is not integrated into a practical application. Claims 21 and 32 recite several additional elements which are “maintaining, at a computing system, a plurality of consent records, wherein each consent record comprises a user identifier associated with a mobile device of a user, a mobile network operator identifier associated with a mobile network operator with which the user is subscribed, and a plurality of consent data, wherein each consent data comprises a service provider identifier and a consent status”; “sharing of data…associated with the user, maintained by the mobile network operator …”; “receiving a consent update, the consent update comprising a user identifier and a consent status, wherein the consent update is associated with a service provider identifier”; and “computer-implemented …”/ “non-transitory computer-readable medium carrying instructions configured to cause one or more processors to perform operations”.
The additional elements of “maintaining consent records in a computer system” and “the consent status maintained at a mobile network operator computing system” are merely storage of data which is insignificant extra-solution activity and activity that is well-understood and conventional. Thus, the additional element do not integrate the abstract idea into a practical application.
The limitation of “wherein each consent record comprises a user identifier associated with a mobile device of a user, a mobile network operator identifier….,and a plurality of consent data” provides additional details for the consent record. The limitation does not add significant steps nor amounts to more than the abstract idea recited above.
The limitation of “wherein each consent data comprises a service provider identifier, a consent status, and a consent method” provides additional details for the consent data. The limitation does not add significant steps nor amounts to more than the abstract idea recited above.
The limitation of “the consent status governing sharing of data by the mobile operator…when the consent method conforms to a consent collection requirement associated with the sharing of data…” is an intended result. The claims fail to provide further steps for the sharing of data. The details of the governing of the sharing of the data is not utilized in the steps of the claims and therefore there is no functional relationship between the sharing of the data and the remaining steps of the claims. Therefore, the limitation does not add significant steps nor amounts to more than the abstract idea recited above.
The additional element of “…sharing of data…by the mobile network operator …” is merely generalize limitation of transmitting and receiving of data which is insignificant extra-solution activity and activity that is well-understood and conventional. Thus, the additional element do not integrate the abstract idea into a practical application.
The additional element of ““receiving a consent update, the consent update comprising a user identifier and a consent status, wherein the consent update is associated with a service provider identifier” is merely transmitting and receiving data which is insignificant extra-solution activity and activity that is well-understood and convention. In addition, the components of the consent updates further narrow the consent update limitation. Thus, the additional element do not integrate the abstract idea into a practical application.
The additional element of “computer-implemented …”/ “non-transitory computer-readable medium carrying instructions configured to cause one or more processors to perform operations” are computer components which entails the steps being computer implemented and are recited at a high level of generality such that the generic computer amounts to no more than mere instructions to apply the exception. Implementing an abstract idea on a generic computer does not integrate the abstract idea into a practical application or add significantly more.
Thus, the independent claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception. Accordingly, claims 21 and 32 are not eligible under 35 USC 101.
The limitations recited in claims 22 and 33, under the broadest reasonable interpretation, further narrow the consent record that is recited in the independent claims. Claims 22 and 33 do not provide additional elements that integrate the abstract idea into a practical application. Thus claims 22 and 33 are not eligible under 35 USC 101.
The limitations recited in claims 24 and 35, under the broadest reasonable interpretation, provide further limitations of selecting and updating the consent data, wherein these steps can further be performed mentally in the human mind and with the aid of pencil and paper. Thus, claims 24 and 35 do not provide additional elements that integrate the abstract idea into a practical application. Thus claims 24 and 35 are not eligible under 35 USC 101.
The limitations recited in claim 27 and 38, under the broadest reasonable interpretation, provide further limitations of updating the consent data, wherein these steps can further be performed mentally in the human mind and with the aid of pencil and paper. Thus, claims 27 and 38 do not provide additional elements that integrate the abstract idea into a practical application. Thus claims 27 and 38 are not eligible under 35 USC 101.
The limitations recited in claim 28 and 39, under the broadest reasonable interpretation, provide narrow limitations of consent update. Thus, claims 28 and 39 do not provide additional elements that integrate the abstract idea into a practical application. Thus claims 28 and 39 are not eligible under 35 USC 101.
The limitations recited in claim 29 and 40, under the broadest reasonable interpretation, provide narrow limitations of the selected consent data. Thus, claims 29 and 40 do not provide additional elements that integrate the abstract idea into a practical application. Thus claim 29 and 40 are not eligible under 35 USC 101.
The limitations recited in claim 30, under the broadest reasonable interpretation, involves the transmission of data which is well known insignificant extra solution activity that is well-understood and conventional. Thus, claim 30 does not provide additional elements that integrate the abstract idea into a practical application. Thus claim 30 is not eligible under 35 USC 101.
The limitations recited in claim 31, under the broadest reasonable interpretation, involves the transmission of data which is well known insignificant extra solution activity that is well-understood and conventional. In addition, the approval and denying a request for user data is a step that can further be performed mentally in the human mind and with the aid of pencil and paper. Thus, claim 31 does not provide additional elements that integrate the abstract idea into a practical application. Thus claim 31 is not eligible under 35 USC 101.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FELICIA FARROW whose telephone number is (571)272-1856. The examiner can normally be reached M - F 7:30am-4:00pm (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571)270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/F.F/Examiner, Art Unit 2437
/BENJAMIN E LANIER/Primary Examiner, Art Unit 2437