DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Drawings
The drawings submitted on March 15, 2024 are acceptable.
Response to Amendment
The amendment filed on May 14, 2026 has been entered. Applicant has amended claims 9 and 14. Applicant has added claims 18-19. Applicant has cancelled claims 11-12 and 15-16. Claims 1-8 were previously withdrawn from consideration. Claims 1-10, 13-14 and 17-19 are now pending, from which claims 9-10, 13-14 and 18-19 have been examined and currently stand rejected.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 9-10, 13-14 and 17-19 are rejected under 35 U.S.C. 101 because the claimed invention recites and is directed to a judicial exception to patentability (i.e., an abstract idea) and does not provide an integration of the recited abstract idea into a practical application nor include an inventive concept that is “significantly more” than the recited abstract idea to which the claim is directed. MPEP §2106.
In determining subject matter eligibility in an Alice rejection under 35 U.S.C. §101, it is first determined as Step 1 whether the claims are directed to one of the four statutory categories of an invention (i.e., a process, a machine, a manufacture, or a composition of matter). MPEP §2106.03.
Here, the claims are directed to the statutory category of a system (claims 9-10 and 13) and a manufacture (claims 14 and 17-19). Therefore, we proceed to Step 2A, Prong 1. MPEP §2106.
Under a Step 2A, Prong 1 analysis, it must be determined whether the claims recite an abstract idea that falls within one or more enumerated categories of patent ineligible subject matter that amounts to a judicial exception to patentability. MPEP §2106.04. Independent Claim 9 is selected as being representative of the independent claims in the instant application. Claim 9 recites:
A mobile device, comprising:
a memory configured to store a mobile wallet application;
a contactless interface configured to contactlessly read information from a contactless payment card; and a processor configured to
receive a request from a user to contactlessly provision payment card information into the mobile wallet application;
contactlessly read payment card information from the contactless payment card;
cause the contactless payment card to generate a cryptogram including the payment card information;
generate a message requesting confirmation that the contactless payment card is eligible for contactless provisioning on the mobile wallet application;
receive a response message, the response message including a flag, the flag indicating at least one of (i) the contactless payment card is eligible for contactless provisioning on the mobile wallet application and (ii) the contactless payment card is not eligible for contactless provisioning on the mobile wallet application, wherein the response message further includes information indicating that issuer verification is required;
cause a message to be displayed to a user of the mobile device, the contents of the message based on the flag;
generate a provisioning message based on the flag of the response message, wherein the provisioning message is generated with information requesting issuer verification of the cryptogram
contactlessly provision a tokenized version of the payment card information in the mobile wallet application in the event that the contactless payment card is eligible for contactless provisioning on the mobile wallet application, wherein the provisioning message causes the generation of the tokenized version of the payment card information.
Here, the claims recite an abstract idea, or combination of abstract ideas of provisioning payment information (i.e., anonymized account number) to a user. The claim achieves this by functions comprising: receive a request …, read payment card information …, generate a cryptogram …, generate a message requesting confirmation …, received a response message …, cause a message to be displayed …, generate a provisioning message…, provision … As such, the claim recites abstract idea of certain method of organizing human activities, i.e., mitigating risk by provisioning anonymous account number.
Accordingly, it is determined that the claims recite an abstract idea since they fall within one or more of the three enumerated categories of patent ineligible subject matter. MPEP §2106.04.
Since it is determined that the claim(s) contain a judicial exception, it must then be determined, under Step 2A, Prong 2, whether the judicial exception is integrated into a practical application of the exception. MPEP §2106.04. In order to make this determination, the additional element(s) are analyzed to determine if the claim as a whole integrates the recited judicial exception into a practical application of that exception. Independent claim 9 recites the additional elements of a mobile device, a payment card, a memory, a mobile wallet application, contactless interface, and a processor. Independent claim 14 recites the additional elements of a non-transitory computer-readable storage medium, at least one programmable processor, a mobile device, a payment card and a mobile wallet application. These additional elements are all recited at a high-level of generality such that they amount to no more than mere instructions to apply the exception, or a portion thereof, using a generic computer component. See MPEP 2106.05(f). Additionally, Examiner finds no indication in the Specification, that the operations recited in the independent claims require any specialized computer hardware or other inventive computer components, i.e., a particular machine, invoke any allegedly inventive programming, or that the claimed invention is implemented using other than generic computer components to perform generic computer functions. Furthermore, there is no indication in the claim(s) that the use of a non-transitory computer-readable storage medium, a mobile device, a memory, a payment card, a mobile wallet application, contactless interface, processor and a storage device in combination with the abstract idea leads to an improvement of the processor, memory, another technology, or to a technical field. Accordingly, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Looking at the elements as a combination does not add anything more than the elements analyzed individually. Examiner further notes that even though the claims may not preempt all forms of the abstraction, this alone, does not make them any less abstract.
When analyzed under step 2B, the claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a generic computing component (e.g., a non-transitory computer-readable storage medium, a payment card, a mobile device, a memory, a mobile wallet application, contactless interface, processor and a storage device) to implement the abstract idea amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept or significantly more than the judicial exception. Considered as an ordered combination, the additional elements recited in the claim(s) add nothing that is not already present when the steps are considered separately.
Therefore, claim 9 and 14 are rejected under 35 U.S.C. §101 and are not patent eligible. Dependent claims 10, 13 and 17-19 when analyzed are held to be patent ineligible under 35 U.S.C. §101 because the additional recited limitation(s) fail to establish that the claim(s) is/are not directed to an abstract idea.
Dependent claims 10 further refine the abstract idea by identifying terms, describing the flag (e.g., indicates success of the contents of the message) receive information indicating user’s acceptance of terms. These claims fail to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea
Dependent claims 13 and 17 further refine the abstract idea by indicating that the flag indicates the contactless payment card is not eligible for contactless provisioning if the cryptogram cannot be verified. This claim fails to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
Dependent claim 18 recite operate the contactless interface in a reader mode to issue a read record command and a generate cryptogram command to the contactless payment card, and wherein the cryptogram comprises an application request cryptogram (ARQC). These new additional elements fail to integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
Dependent claim 19 further refine the abstract idea by describing the message requesting confirmation (e.g., comprises a Data Element 55 (DE55) field. This claim fails to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea.
In summary, the dependent claims considered both individually and as an ordered combination do not provide meaningful limitations to transform the abstract idea into a patent eligible application of the abstract idea such that the claims amount to significantly more than the abstract ideas itself. The claims do not recite an improvement to another technology or technical field, an improvement to the functioning of the computer itself, or provide meaningful limitations beyond generally linking an abstract idea to a particular technological environment. Therefore, the dependent claims are also not patent eligible.
Accordingly, it is determined that all claims are directed to non-statutory subject matter under 35 U.S.C. 101 and are ineligible.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 9-10 and 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wong et al. (US 2022/0327527 A1), “Wong ‘7527”, in view of Wong ‘2753 (US 2021/0042753 A1).
Regarding claims 9 and 14:
Claim 9: A mobile device, (See at least Wong ‘7527, Figs. 2-3; mobile device) comprising:
a memory configured to store a mobile wallet application (See at least Wong ‘7527, [0135] memory);
a contactless interface configured to contactlessly read information from a contactless payment card; and a processor configured to:
Claim 14: A non-transitory machine-readable medium (See at least Wong ‘7527, [0145] (claim 31) storing instructions that, when executed by at least one programmable processor, cause the at least one programmable processor to perform operations comprising:
receive a request from a user to contactlessly provision payment card information into the mobile wallet application; (See at least Wong ‘7527, Fig. 3 (step 302); [0011]; [0050]; [0056]; [0060]; [0073] at block 302 to initially request a provisioning of an account, credit card, or any other payment credentials for the mobile device 101).
contactlessly read payment card information from the contactless payment card; (See at least Wong, Wong ‘7527, Fig. 3 (step 302); [0011]; [0050]; [0056]; [0060]; [0073] e.g., payment card information is then transmitted (e.g., the card information is read).)
cause the contactless payment card to generate a cryptogram including the payment card information; (See at least Wong ‘7527, [0060] cause the contactless payment card (e.g., via the digital wallet application) to generate a cryptogram (i.e., cryptogram) including the payment card information (i.e., CVV2 for card verification based authentication processes).)
generate a message requesting confirmation that the contactless payment card is eligible for contactless provisioning on the mobile wallet application; (See at least Wong ‘7527, Fig. 3; [0073] upon affirming that the credentials 350 are correct and for a valid account, will transmit a check account message 352 (e.g., make an API call for a card eligibility request) for one or more accounts of the user 107 to the service provider 230.)
receive a response message, the response message including a flag, the flag indicating at least one of (i) the contactless payment card is eligible for contactless provisioning on the mobile wallet application and (ii) the contactless payment card is not eligible for contactless provisioning on the mobile wallet application, (See at least Wong ‘7527, Fig. 3 (308); [0077-0078]; At block 308, if an account is not eligible, the wallet provider 210 may transmit an ineligibility message 360 to the mobile device 101; If, at block 308, an account is eligible, the flow continues with the wallet provider 210 sending an enable payments query message 362 indicating that the account is eligible, and the user 107 and/or wallet application may, in response, cause another enable payments query response message 362 to be sent back to the wallet provider.)
cause a message to be displayed to a user of the mobile device, the contents of the message based on the flag; and (See at least Wong, Wong ‘7527, Fig. 3 (308); [0077-0078]; which may cause a message to be presented to the user 107 (e.g., via a display device) to indicate that the account is ineligible; sending an enable payments query message 362 indicating that the account is eligible.)
contactlessly provision a tokenized version of the payment card information in the mobile wallet application in the event that the contactless payment card is eligible for contactless provisioning on the mobile wallet application; wherein the provisioning message causes the generation of the tokenized version of the payment card information. (See at least Wong ‘7527, Fig. 3; [0090-0091]; [0093]; e.g., after determining account eligibility… generate and return a token, and may store a mapping between the token and the PAN for future translations; a token activation results message 380 to the wallet provider to confirm and/or deny whether the token (i.e., payment credential 207) was successfully provisioned (i.e., installed).))
Wong does not explicitly disclose; generate a provisioning message based on the flag of the response message.
However, Wong ‘7527 further teaches, that after eligibility check, an account eligibility request message 354 to the issuer 240, and the issuer 240 will then verify the eligibility at block 306 and return an account eligibility response message 356 indicating the eligibility of the account(s). transmits a provision request message 366, The provisioning request message 366 is sent by the mobile device 101 to wallet provider 210, which may generate a risk score (or perform a "risk check" or "risk analysis". (See at least Wong ‘7527, [0074]; [0080]).
In view of teachings provided by Wong ‘7527, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include:; generate a provisioning message based on the flag of the response message.
One of ordinary skilled in the art would have been motivated to generate the provisioning message based on the flag of the response message because Wong’s workflow already relies in issuer eligibility determination.
Wong ‘7527 disclose; in some embodiments the service provider 230 identifies the issuer 240 of the account (e.g., based upon the PAN), transmits a token activation request message 370 (which may include a risk value indicating the service provider assigned risk 314 and/or a risk value generated by the wallet provider 210) to the issuer 240 such that the issuer 240, at block 316, will determine/assign its own risk and return a token activation response message 372B back to the service provider 230.
However, Wong ‘7527 does not explicitly disclose wherein the response message further includes information indicating that issuer verification is required; the message is generated with information requesting issuer verification of the cryptogram.
Wong 2753, on the other hand teaches a response message further includes information indicating that issuer verification is required and the message is generated with information requesting issuer verification of the cryptogram; (See at least Wong ‘2753 claim 32; sending an authorization request message to an issuer to obtain authorization for the transaction from the issuer by verifying the transaction cryptogram with the issuer, the authorization request message including the token and the transaction cryptogram.)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Wong and include Wong ‘2753’s teachings in order to improve transaction security.
Regarding claim 10: The combination of Wong and Wong 2753‘ disclose the mobile device of claim 9. The combination further disclose wherein the contents of the message to be displayed to the user include terms and conditions to be accepted by the user, the terms and conditions identified based at least in part on the payment card information. (See at least Wong ‘7527, [0078] The enable payments query message 362 may cause the mobile device 101 to also present a set of terms and conditions to the user during this service activation phase, which the user must accept to continue.)
Claim(s) 13 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wong ‘7527 and Wong ‘2753 as applied to claims 9 and 14 above, and further in view of DESJARDINS (EP 3182315 A1) “Desjardins”.
Regarding claims 13 and 17: The combination of Wong ‘7527 and Wong ‘2753 disclose the mobile device of claim 9 and the non-transitory machine-readable medium storing instructions of claim 14.The combination further disclose; For example, if the request for provisioning included a PAN and a cryptogram, provisioning service module 225 may retrieve a master encryption key, use the master encryption key to decrypt the cryptogram, and ensure that the decrypted value is an expected value (e.g., corresponding to received value of the PAN) Wong ‘7527, [0061]. However, the combination do not explicitly disclose wherein the flag indicates the contactless payment card is not eligible for contactless provisioning if the cryptogram cannot be verified.
Desjardins, on the other hand teaches that it was known in the art, before the effective filing date of the claimed invention that if a cryptogram is not verified, user is not authenticated (e.g., wherein the flag indicates the contactless payment card is not eligible for contactless provisioning if the cryptogram cannot be verified. (See at least Desjardins, Abs.; [0006-0007]; [0034])
It would have been obvious to one of ordinary still in the art to include in the system/device of the above combination, the ability to not permit the payment card provision (e.g., not allow further authentication) if a cryptogram is not verified as taught by Desjardins since the claimed invention is merely a combination of old elements, and in the combination each element merely would have performed the same function as it did separately, and one of ordinary skill in the art would have recognized that the results of the combination were predictable.
Claim(s) 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wong ‘7527 and Wong ‘2753 as applied to claim 9 above, and further in view of Radu (US 20150287031 A1) “Radu”.
Regarding claim 18: The combination of Wong ‘7527 and Wong ‘2753 disclose the mobile device of claim 9. The combination further disclose a generate cryptogram command to the contactless payment card (See at least Wong ‘7527, [0060]; [0061] the request of provisioning including a cryptogram). The combination do not explicitly disclose; however Radu teaches; wherein the processor is further configured to operate the contactless interface in a reader mode to issue a read record command and wherein the cryptogram comprises an application request cryptogram (ARQC). (See at least Radu, [0050]; [0115]; [0178-0179]; to operate the contactless interface in a reader mode to issue a read record command (e.g., smartphone operating in reader mode) wherein the cryptogram comprises an application request cryptogram (ARQC) (i.e., ARQC cryptogram).)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the above combination and include Radu’s teachings in order to guarantee data integrity, enforces offline data protection.
Applicant is reminded that the phrase “mode to issue a read record command” is intended use of the contactless interface operating in a reader mode.
The applicant is reminded that these portions, i.e., intended use/result, do not further limit the scope of the claim as the limitations, or portions thereof, do not claim the functions as being positively recited actions or functions, and/or they do not add any meaning or purpose to the associated manipulative step(s). See MPEP 2103 C and 2111.04. Simply because the limitation recites something as being "for ... [performing a specific functionality]", etc. does not mean that the functions are required to be performed, or are actually performed.
Claim(s) 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wong ‘7527 and Wong ‘2753 as applied to claim 9 above, and further in view of Bhatt (US 20160364703 A1) “Bhatt”.
Regarding claim 19: The combination of Wong‘7527 and Wong ‘2753 disclose the mobile device of claim 9. The combination do not explicitly disclose; however Bhatt teaches; wherein the message requesting confirmation comprises a financial transaction message including a Data Element 55 (DE55) field, and wherein the cryptogram is included in the DE55 field. (See at least Bhatt, Claim 13; [0056]; wherein the cryptogram is included at a field designated DE55 in the authorization request.)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the above combination and include Bhatt’s teachings in order to prevent fraud.
Response to Arguments
35 USC 112(b)
Applicant as corrected the previously identified issues. Accordingly, the claim rejections under 112(b) are withdrawn.
USC 101
Applicant's arguments filed regarding the rejections under 35 USC 101 have been fully considered but they are not persuasive.
Applicant asserts that the claims recite a specific, distributed cryptographic validation architecture. Specifically, Applicant argues that the specific routing of cryptographic verification to an issuer based on a dynamic flag integrates the alleged abstract idea into a practical application (Remarks, p. 8). Examiner respectfully disagrees. The claims recite the abstract idea of provisioning a payment information (i.e., anonymized account number) to a user and the element of routing of cryptographic verification to an issuer based on a dynamic flag does not provide an improvement to the mobile device or any technological field.
Applicant further asserts that; it provides a specific technical solution to a problem in contactless provisioning network (namely, how to securely provision a device when the intermediate payment network lacks the necessary keys to validate a card-generated cryptogram). Examiner respectfully disagrees. The claims identifying when the issuer is required and route the verification request to the issuer based on information do not provide an improvement to the functioning of the provisioning system.
35 USC 102
Applicant asserts that Wong ‘7527 fails to teach or suggest requesting issuer verification of the cryptogram. Applicant further argues that Wong ‘7527 fails to disclose a response message indicating that issuer verification is required, or generating a provisioning message requesting issuer verification. Examiner agrees. However, upon further consideration of the newly introduced language, a new ground(s) of rejection is made in view of Wong ‘7527 and Wong ‘2753. Examiner notes these features are disclosed by “Wong 2753”.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Musil (US 20170352026 A1)validating a cryptogram included in the authorization request message based on the at least one cryptographic key prior to transmitting the authentication request message to the issuer of the first payment account. Musil [0068].
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KARLYANNIE M GARCIA whose telephone number is (571)272-6950. The examiner can normally be reached Monday - Friday 7:30am - 4:30-pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Patrick McAtee can be reached at (571) 272-7575. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/K.G.M/Examiner, Art Unit 3698
/PATRICK MCATEE/Supervisory Patent Examiner, Art Unit 3698