Prosecution Insights
Last updated: October 02, 2026
Application No. 18/560,893

CONTENT VERIFICATION

Non-Final OA §103
Filed
Nov 14, 2023
Priority
May 14, 2021 — GB 2106960.4 +1 more
Examiner
LEE, CLAY C
Art Unit
3699
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Mastercard International Incorporated
OA Round
3 (Non-Final)
55%
Grant Probability
Moderate
3-4
OA Rounds
6m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 55% of resolved cases
55%
Career Allowance Rate
133 granted / 243 resolved
+2.7% vs TC avg
Strong +58% interview lift
Without
With
+57.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
31 currently pending
Career history
279
Total Applications
across all art units

Statute-Specific Performance

§101
30.6%
-9.4% vs TC avg
§103
47.3%
+7.3% vs TC avg
§102
8.0%
-32.0% vs TC avg
§112
12.0%
-28.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 243 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on April 16, 2026 has been entered. Response to Amendment The amendment filed April 16, 2026 has been entered. Claims 1-15 and 18-19 remain pending in the application. Applicant' s amendments to the Claims have overcome each and every 101 rejections previously set forth in the Final Office Action mailed December 18, 2025. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-4, 6-15, and 18-19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen (WO 2020076845 A1; already of record in IDS) in view of Hammad (WO 2013075071 A1). Regarding Claims 1 and 18-19, Chen teaches A method of processing, at an authentication server, data provided during an interaction between a user and a third party platform, the method comprising (Chen: Abstract): A non-transitory computer-readable storage medium comprising instructions which, when executed by a computer, cause the computer to: (Chen: Abstract; Paragraph(s) 0034), A system including: a third party platform; an issuer and an authentication server arranged to process data provided during an interaction between a user and the third party platform, the authentication server configured to: (Chen: Abstract; Paragraph(s) 0034) receiving, at an authentication server, user verification data and content data from the third party platform (Chen: Paragraph(s) 0087-0088, 0092 teach(es) a biometric sample is received by the security device from a user; the security device may transmit the obtained biometric sample to a service provider; the service provider may identify a number of supplemental information that may be provided to the security device), wherein the user verification data includes payment card details of a payment card (Chen: Paragraph(s) 0031-0032 teach(es) A digital wallet may allow the user to load one or more payment cards onto the digital wallet so as to make a payment without having to enter an account number or present a physical card), wherein at least part of the content data is a date of a user transaction between the user and a merchant associated with the third party platform, wherein the user transaction was undertaken with the payment card (Chen: Paragraph(s) 0020, 0023, 0074 teach(es) Exemplary access request data may include information indicating an access request amount, an access request location, resources received (e.g., products, documents, etc.), information about the resources received (e.g., size, amount, type, etc.), resource providing entity data (e.g., resource provider data, document owner data, etc.), user data, date and time of an access request, a method utilized for conducting the access request (e.g., contact, contactless, etc.), and other relevant information; An “authorization request message” may be an electronic message that is sent to a payment processing network and/or an issuer of a payment card to request authorization for a transaction; An authorization request message may also comprise “transaction information,” such as any information associated with a current transaction, such as the transaction amount, merchant identifier, merchant location, etc.), …; transmitting, by the authentication server, a verification inquiry and a request to verify an accuracy of the content data to an issuer, wherein the verification inquiry comprises the payment card details; confirming, by the issuer, that the payment card details from the verification inquiry match an active payment account of the issuer (Chen: Paragraph(s) 0089, 0063-0064, 0023 teach(es) the service provider may receive the biometric sample. Upon receiving the biometric sample the process may involve the service provider identifying the user from which the biometric sample was obtained; The processing network computer may decrypt the transaction cryptogram using the cryptographic key to obtain the unpredictable number, the token, and the transaction amount, and may then compare this information to the information received in the authorization request message. If it matches, then the cryptogram can be validated; the processing network may route the authorization request message to the token service, which may identify a payment account mapped to the token; An “authorization request message” may be an electronic message that is sent to a payment processing network and/or an issuer of a payment card to request authorization for a transaction); analysing, by the issuer and based on the request, the received content data against pre-existing user data including historical transaction data associated with the payment card by determining that the date of the user transaction matches a date of a historical transaction from the historical transaction data and is associated with the merchant (Chen: Paragraph(s) 0092, 0057, 0074, 0020 teach(es) the service provider may identify a number of supplemental information that may be provided to the security device. For example, the service provider may retrieve demographic information for the user (e.g., age, race, income, etc.) or access level data associated with the user (membership, status, tickets, etc.); a security device may be provided with ticketing data for events that are to occur on the date that the biometric sample is received; the service provider may receive a location of the security device and may provide data based on that location. In this example, a security device determined to be at an airport may be provided with airplane ticketing information; the service provider may also initiate retrieval of a cryptographic key (e.g., a limited use key, which may be used for only a specific number of transactions or for a specific period of time) that can be used to form a transaction cryptogram, such as an EMV (Europay MasterCard Visa) transaction dynamic cryptogram, from the token service; the account management module may identify ticketing information stored for the user in relation to a date and/or time. For example, upon identification of an account, the account management module may identify a ticket associated with the user’s account which provides access to an event being held on the current day); returning, by the issuer, a confirmation to the authentication server that the payment card details are associated with the active payment account, and that the payment card undertook the historical transaction with the merchant on the date of the historical transaction (Chen: Paragraph(s) 0074 teach(es) the account management module may identify ticketing information stored for the user in relation to a date and/or time. For example, upon identification of an account, the account management module may identify a ticket associated with the user’s account which provides access to an event being held on the current day); generating, by the authentication server, a user identity status that indicates that the payment card details are associated with the active payment account based on the confirmation; generating, by the authentication server, a content data notification message indicating that the date of the historical transaction matches the date of the user transaction based on the confirmation (Chen: Paragraph(s) 0024, 0074 teach(es) The authorization response message may also include an authorization code, which may be a code that a credit card issuing bank returns in response to an authorization request message in an electronic message (either directly or through the payment processing network) to the merchant's access device (e.g., POS equipment) that indicates approval of the transaction); sending, from the authentication server to the third party platform, an authentication message, the authentication message comprising the user identity status and the content data notification message, … (Chen: Paragraph(s) 0093, 0087-0092 teach(es) the security device may receive and present an image and/or name of the user so that an operator of the security device may visually confirm the identity of the user. The security device may also present an age of the user so that an operator of the security device may determine whether the user qualifies to conduct age-restricted transactions. Once the user information has been received by the security device, that information may be used by the security device to complete a transaction); and granting, by the third party platform, access to a service for the review based on the authentication message, wherein the service is associated with a website for the third party platform (Chen: Paragraph(s) 0074, 0019, 0035, 0066 teach(es) the account management module 210 may identify access data from the access data store that indicates a level of access that should be granted to the user; Some examples of access devices include point of sale (POS) devices, cellular phones, PDAs, personal computers (PCs), tablet PCs, hand-held specialized readers, set-top boxes, electronic cash registers (ECRs), automated fuel dispensers (AFDs), automated teller machines (ATMs), virtual cash registers (VCRs), kiosks, security systems, access systems, Websites, and the like). However, Chen does not explicitly teach wherein the content data includes a review portion that is generated and submitted by the user to the third party platform and includes an analysis of the merchant, and wherein the authentication messages indicates whether the review portion is verified. Hammad from same or similar field of endeavor teaches wherein the content data includes a review portion that is generated and submitted by the user to the third party platform and includes an analysis of the merchant (Hammad: Paragraph(s) 0113, 0141, 0153 teach(es) the user may be able to perform additional operations in this view. For example, the user may (re)buy the item, obtain third-party reviews of the item, and write reviews of the item, add a photo to the item so as to organize information related to the item along with the item, add the item to a group of related items (e.g., a household), , provide ratings, or view quick ratings from the user's friends or from the web at large), and wherein the authentication messages indicates whether the review portion is verified (Hammad: Paragraph(s) 0113, 0141, 0153, as stated above). It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Chen to incorporate the teachings of Hammad for wherein the content data includes a review portion that is generated and submitted by the user to the third party platform and includes an analysis of the merchant, and wherein the authentication messages indicates whether the review portion is verified. There is motivation to combine Hammad into Chen because Hammad’s teaching of reviews of items would facilitate authentication process for transaction with merchants (Hammad: Paragraph(s) 0113, 0141, 0153). Regarding Claim 2, the combination of Chen and Hammad teaches all the limitations of claim 1 above; and Chen further teaches wherein the profile verification data stored in the user profile comprises user bank account data and the user verification data received at the authentication server comprises data associated with the user bank account (Chen: Paragraph(s) 0021-0022, 0024, 0032, 0044 teach(es) An “issuer” may typically include a business entity (e.g., a bank) that maintains an account for a user. An issuer may also issue payment credentials stored on a user device, such as a cellular telephone, smart card, tablet, or laptop to the user; An “electronic wallet” or “digital wallet” can include an electronic device that allows an individual to conduct electronic commerce transactions. A digital wallet may store user profile information, credentials, bank account information, one or more digital wallet identifiers and/or the like and can be used in a variety of transactions). Regarding Claim 3, the combination of Chen and Hammad teaches all the limitations of claim 2 above; and Chen further teaches wherein verification of the identity of the user comprises checking that the received data associated with the user bank account matches the user bank account data stored in the user profile (Chen: Paragraph(s) 0024 teach(es) The authorization response message may also include an authorization code, which may be a code that a credit card issuing bank returns in response to an authorization request message in an electronic message (either directly or through the payment processing network) to the merchant's access device (e.g., POS equipment) that indicates approval of the transaction). Regarding Claim 4, the combination of Chen and Hammad teaches all the limitations of claim 2 above; and Chen further teaches wherein the user profile comprises primary account number (PAN) data and the received user verification data comprises a PAN number (Chen: Paragraph(s) 0018, 0030, 0037 teach(es) "Access data" may include any suitable data that can be used to access a resource or create data that can access a resource. In some embodiments, access data may be account information for a payment account. Account information may include a PAN (primary account number), payment token, expiration date, verification values (e.g., CW, CW2, dCW, dCW2), etc.). Regarding Claim 6, the combination of Chen and Hammad teaches all the limitations of claim 5 above; and Chen further teaches wherein analysing the received content data against the pre-existing user data comprises determining if a match exists between the historical transaction data in the user profile and the user-merchant transaction contained in the received content data (Chen: Paragraph(s) 0024, 0035, 0027-0028, as stated above with respect to claim 5). Regarding Claim 7, the combination of Chen and Hammad teaches all the limitations of claim 1 above; and Chen further teaches wherein the content data received from the third party platform comprises an image of submitted by the user and the pre-existing user data comprises a profile image of the user (Chen: Paragraph(s) 0077). Regarding Claim 8, the combination of Chen and Hammad teaches all the limitations of claim 7 above; and Chen further teaches comprising analysing the submitted user image against the profile image to determine if a match exists between the user in the submitted image and the pre-existing user profile image (Chen: Paragraph(s) 0027, 0077 teach(es) a biometric sample of a user’s face may be image and/or depth data. In another example, a biometric sample of a user’s voice may be audio data). Regarding Claim 9, the combination of Chen and Hammad teaches all the limitations of claim 6 above; and Chen further teaches wherein the content data notification message comprises an indication whether or not a match exists between the content data received from the third party platform and the data within the user profile (Chen: Paragraph(s) 0043, 0077 teach(es) supplemental information may include any user-related information which is supplemental to payment account data for a user. Supplemental information may include any combination of demographic and/or biological details associated with the user (e.g., occupation, age, gender, etc.)). Regarding Claim 10, the combination of Chen and Hammad teaches all the limitations of claim 1 above; and Chen further teaches wherein the content data received from the third party platform comprises a request for pre-existing user data in order to populate a form and wherein analysing the received content data comprises extracting user data from the pre-existing user data (Chen: Paragraph(s) 0093, 0100-0101 teach(es) the security device may receive and present an image and/or name of the user so that an operator of the security device may visually confirm the identity of the user). Regarding Claim 11, the combination of Chen and Hammad teaches all the limitations of claim 10 above; and Chen further teaches wherein the content data notification message comprises the user data requested by the third party platform (Chen: Paragraph(s) 0100-0101 teach(es) the security device may receive an indication of an identity of the user as well as supplemental information associated with user; at least a portion of the received user information may be displayed upon the security device). Regarding Claim 12, the combination of Chen and Hammad teaches all the limitations of claim 11 above; and Chen further teaches wherein the content data received from the third party platform comprises a content formatting specification and the content data notification message comprises user data extracted from the pre-existing user data and formatted according to the content formatting specification (Chen: Paragraph(s) 0037 teach(es) a token may be “format preserving” and may have a numeric format that conforms to the account identifiers used in existing transaction processing networks (e.g., ISO 8583 financial transaction message format); the token format may be configured to allow the entity receiving the token to identify it as a token and recognize the entity that issued the token). Regarding Claim 13, the combination of Chen and Hammad teaches all the limitations of claim 1 above; and Chen further teaches comprising generating at the authentication server a consent notification message to send to the user to allow the user to consent to the verification of their verification data and analysis of the content data (Chen: Paragraph(s) 0100 teach(es) consider a scenario in which a security device obtains a biometric sample (in this case facial feature data) from a user. In this example, the biometric sample, or a derivation of the biometric sample, would be sent by the security device to a remote service provider. In response to sending the biometric sample, the security device may receive an indication of an identity of the user as well as supplemental information associated with user). Regarding Claim 14, the combination of Chen and Hammad teaches all the limitations of claim 13 above; and Chen further teaches wherein the consent notification message is sent via a second authenticated communications channel (Chen: Paragraph(s) 0040 teach(es) the security device may include one or more input sensors capable of obtaining biometric information as well as one or more communication means for communicating with other electronic devices). Regarding Claim 15, the combination of Chen and Hammad teaches all the limitations of claim 1 above; and Chen further teaches wherein the user is requesting a third party provider user account (Chen: Paragraph(s) 0042). However, the combination does not explicitly teach verifying the identity of the user comprises checking whether the received user verification data is already associated with another third party provider user account. Hammad from same or similar field of endeavor teaches wherein verifying the identity of the user comprises checking whether the received user verification data is already associated with another third party provider user account (Hammad: Paragraph(s) 00100 teach(es) a user may utilize a mobile device (e.g., smartphone, tablet computer, etc.) to conduct a purchase transaction for contents of a cart (e.g., physical cart at a brick-and-mortar store, virtual cart at an online shopping site), optionally at a point-of-sale (PoS) client (e.g., legacy terminal at a brick-and-mortar store, computing device at an online shopping site, another user with a virtual wallet application, for person-to-person funds transfers, etc.). The user may be able to choose from one or more cards to utilize for a transactions). It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of the combination of Chen and Hammad to incorporate the teachings of Hammad for wherein verifying the identity of the user comprises checking whether the received user verification data is already associated with another third party provider user account. There is motivation to combine Hammad into the combination of Chen and Hammad because Hammad’s teaching of a legacy terminal and choosing one from cards for a transaction would facilitate the user verification (Hammad: Paragraph(s) 00100). Response to Arguments Applicant's arguments filed April 16, 2026 have been fully considered but they are not persuasive. Regarding applicant’s argument under Claim Rejections - 35 USC § 103 that “Chen does not appear to mention the above feature, and in particular whether a date of the historical transaction matches the date of the user transaction,” examiner respectfully argues that Chen teaches identifying of ticketing information, which matches a date of the historical transaction matches the date of the user transaction (Chen: Paragraph(s) 0074). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Hoffman (US 20210133722 A1) teaches System And Method For On-Line Financial Transactions, including content, merchant, match, signature, bank, image, and biometrics. Yehuda (US 20180330355 A1) teaches Portable Device With Local Verification Data, including identity, image, and match. Zhang (US 20150186892 A1) teaches Methods And Systems For Verifying A Transaction, including merchant, verify, signature, and credential. Johnston (US 20150142660 A1) teaches Centralized Financial Account Migration System, including populate, form, history, verify, and formats. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CLAY LEE whose telephone number is (571)272-3309. The examiner can normally be reached Monday-Friday 8-5pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha Patel can be reached at (571)270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CLAY C LEE/ Primary Examiner, Art Unit 3699
Read full office action

Prosecution Timeline

Show 2 earlier events
Jul 22, 2025
Applicant Interview (Telephonic)
Jul 22, 2025
Examiner Interview Summary
Aug 20, 2025
Response Filed
Dec 18, 2025
Final Rejection mailed — §103
Mar 24, 2026
Response after Non-Final Action
Apr 16, 2026
Request for Continued Examination
Apr 28, 2026
Response after Non-Final Action
Aug 11, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12725153
METHOD AND APPARATUS FOR BOOKKEEPING, OWNING AND TRANSFERRING DIGITALLY LOCKED COINS
1y 3m to grant Granted Sep 01, 2026
Patent 12718223
USER AUTHENTICATION USING A BROWSER COOKIE SHARED BETWEEN A BROWSER AND AN APPLICATION
2y 2m to grant Granted Aug 25, 2026
Patent 12711508
REAL-TIME FRAUD SESSION TERMINATION IN DIRECT PAY SYSTEM
2y 7m to grant Granted Aug 18, 2026
Patent 12711509
SYSTEMS AND METHODS FOR IMPROVED FRAUD DETECTION
2y 8m to grant Granted Aug 18, 2026
Patent 12701013
MEDIA SHARING PLATFORM
1y 11m to grant Granted Aug 04, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
55%
Grant Probability
99%
With Interview (+57.5%)
3y 4m (~6m remaining)
Median Time to Grant
High
PTA Risk
Based on 243 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month