DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 3/2/2026 have been fully considered but they are not persuasive.
Applicant’s representative has amended the independent claims and argued that the claims as amended recite statutory subject matter.
Applicant’s representative argues that the claims integrate concepts into a practical application
because they recite a specific, encrypted network processing mechanism.
Applicant’s representative argues that the claims integrate the abstract idea into a practical
application. Applicant’s representative argues that the claims integrate concepts into a practical application because they recite a specific, encrypted network processing mechanism.
Applicant’s representative then states:
“This is not merely "using a computer as a tool," but rather a particular arrangement and data flow involving a cryptogram generator, cryptogram database, and authorization messaging by decrypting and verifying the cryptogram. The claims thus impose meaningful limits and do not preempt the general concept of "risk screening" or "commercial interactions".
In response, the claims fail to recite technological implementation details of how the claimed functions are being realized. Claims of this nature are almost always found to be ineligible for patenting under Section 101." Beteiro, LLC V. DraftKings Inc., 104 F.4th 1350, 1356 (Fed. Cir. 2024). The specification does not even provide details of a specific architecture or means or structures or specific computer executed modules for performing the claimed functions. Taken claim 1 as an example, Claim 1 recites an improvement to the business of:
receiving, a transmission from a risk-screening module, the transmission comprising a request for a cryptogram for a payment transaction with a merchant associated with the risk-screening module, the payment transaction comprising a prescreened status;
generating, the cryptogram by encrypting the prescreened status of the payment transaction and transaction information received in the transmission;
storing the cryptogram;
transmitting, the communication comprising the cryptogram;
receiving, from an acquirer:
an authorization request for the payment transaction, the authorization request by the merchant, and the cryptogram;
decrypting and validating, the cryptogram based to identify the prescreened status of the payment transaction;
and flag the authorization request to indicate the prescreened status of the payment transaction flagging, the authorization request to indicate the prescreened status of the payment transaction based on the authentication cryptogram. The claims "do[es] not improve the functioning of the payment network, the “risk-screening module”, the “cryptogram generator” or the “cryptogram database” make it operate more efficiently, or solve any technological problem." Trading Techs. Int'l, Inc. V. IBG LLC, 921 F.3d 1084, 1093 (Fed. Cir. 2019). "Nothing in the claim[s], understood in light of the specification, calls for anything but preexisting computers and displays, programmed using techniques known to skilled artisans, to present the new arrangement of information." Brumfield V. IBG LLC, 97 F Ath 854, 868 (Fed. Cir. 2024). The claims also do not show a technical improvement in the architecture of a processor using a computing logic of the computing system or the mobile device. The recited functions involve generic or conventional functions and setup of a basic computer system.
The mere recitation of a “payment network”, the “risk-screening module”, the “cryptogram generator” or the “cryptogram database” performing their expected functions cannot transform a patent-ineligible abstract idea into a patent-eligible invention as stated in Alice Corp., 134S.Ct. at 2358; DDR Holdings, LLC V. Hotels.com, L.P., 773 F.3d 1245, 1256 (Fed. Cri. 2014) ("And after Alice, there can remain no doubt: recitation of generic computer limitations does not make an otherwise ineligible claim patent-eligible. (citation omitted)). Thus, if a patent's recitation of a computer amounts to a mere instruction to 'implement' an abstract idea 'on a computer', that addition cannot impart patent eligibility." Alice Corp., 134 S. Ct. at 2358 (internal citation omitted). The claimed payment network, the “risk-screening module”, the “cryptogram generator” or the “cryptogram database are merely a field of use that attempts to limit the abstract idea to a particular technological environment.
Each of the independent claims uses generic computer technology for receiving data, generating data, storing and transmitting data as such do not recite an improvement to a particular computer technology. See, e.g., McRO, Inc. v. Bandai Namco Games Am. Inc., 837 F .3 d 1299, 1314-1315 (Fed. Cir. 2016) ( finding claims not abstract because they "focused on a specific asserted improvement in computer animation").
The claims are void of anything significantly more than the abstract idea itself.
Applicant’s representative then argues that the recited elements of at least the independent claims amount to a significantly more than the judicial exception.
In response, the claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because:
The additional elements when considered both individually and as a combination do not amount to significantly more than the abstract idea. The claims recite the additional elements of a payment network, the “risk-screening module”, the “cryptogram generator” or the “cryptogram database” which when taken individually or as a whole is/are seen as general purpose computer or a computer system (see the applicant’s specification). These claimed devices are noted to perform routine computer functions such as receiving, generating, storing and transmitting data.
These claimed client additional elements are seen as generic computers performing generic functions without an inventive concept as such do not amount to significantly more. These devices are simply a field of use that attempts to limit the abstract idea to a particular environment. The type of data being manipulated does not impose meaningful limitations. Looking at the elements as a combination does not add anything more than the elements analyzed individually. Therefore the claims do not amount to significantly more than the abstract idea itself.
Accordingly, the claims are not patent eligible.
Applicant’s representative argues and states that the instant claims as now amended and
submitted are statutory over 35 USC 101.
In response, the Examiner respectfully with the applicant’s arguments. A 35 USC 101 rejection on the claims as amended is found below.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-4, 6, 9, 14-17 and 19 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more.
Subject Matter Eligibility Standard
When considering subject matter eligibility under 35 U.S.C. 101, it must be determined whether the claim is directed to one of the four statutory categories of invention, i.e., process, machine, manufacture, or composition of matter.
Specifically, claims 1 and 10 are directed to a method. Each of the claims falls under one of the four statutory classes of invention.
If the claim does fall within one of the statutory categories, it must then be determined whether the claim is directed to a judicial exception (i.e., law of nature, natural phenomenon, and abstract idea).
Absent of the bolded elements, the claims recite the following abstract idea as:
Claim 1 recites :
A computer-implemented method of transaction risk-screening, the method comprising:
receiving, by an application programming interface (API) of a payment network, a transmission from a risk-screening module, the transmission comprising a request for a cryptogram for a payment transaction with a merchant associated with the risk-screening module, the payment transaction comprising a prescreened status;
generating, by a cryptogram generator of the payment network, the cryptogram by encrypting the prescreened status of the payment transaction and transaction information received in the transmission;
storing the cryptogram in a cryptogram database of the payment network;
transmitting, by the API of the payment network, a communication to the risk-screening module, the communication comprising the cryptogram;
receiving, by the payment network, from an acquirer:
an authorization request for the payment transaction, the authorization request by the merchant, and the cryptogram;
decrypting and validating, by the payment network, the cryptogram based on the cryptogram database to identify the prescreened status of the payment transaction;
and flag the authorization request to indicate the prescreened status of the payment transaction flagging, by the payment network, the authorization request to indicate the prescreened status of the payment transaction based on the authentication cryptogram.
Claim 2 recites comprising transmitting, to an issuer, the authorization request with the indicator of the prescreened status of the payment transaction.
Claim 3 recites receiving, by the payment network, from the issuer, an authorization response based on the transmitted authorization request.
Claim 4 recites wherein the authorization request comprises at least one of payment information, merchant information, or merchant information.
Claim 6 recites wherein the transaction information comprises at least one of a transaction identifier, a transaction amount, or a time stamp.
Claim 9 recites: the associating of the authorization request with the indicator comprises updating the authorization request to include the indicator.
Claim 14 recites: A transaction risk-screening system, comprising:
a payment network, comprising: a cryptogram database;
a cryptogram generator; and
an application programming interface (API), wherein the payment network is to:
receive, via the API, a transmission from a risk-screening module, the transmission comprising a request for a cryptogram for a payment transaction with a merchant associated with the risk-screening module, the payment transaction comprising a prescreened status;
generate, by the cryptogram generator, the cryptogram by encrypting the prescreened status of the payment transaction and transaction information received in the transmission;
store the cryptogram in the cryptogram database;
transmit, via the API, a communication to the risk-screening module, the communication comprising the cryptogram;
receive, by the payment network, from an acquirer:
an authorization request for the payment transaction, the authorization request by the merchant, and the cryptogram;
decrypting and validate the cryptogram based on the cryptogram database to identify the prescreened status of the payment transaction; and
flag the authorization request to indicate the prescreened status of the payment transaction.
Claim 15 recites: The transaction risk-screening system of Claim 14, wherein the payment network is to transmit, to an issuer, the flagged authorization request.
Claim 16 recites: wherein the payment network is to receive, from the issuer, an authorization response based on the transmitted authorization request.
Claim 17 recites: wherein the authorization request comprises at least one of payment information, merchant information, or merchant information.
Claim 19 recites: wherein the encrypted transaction information comprises at least one of a transaction identifier, a transaction amount, or a time stamp.
As per claims 1 and 14, applicant is to be noted that the steps or functions of “receive” or “receiving” are considered as data gathering functions.
The functions of “detecting”, “storing” and “generating” involve mental processes and/or generic computer functions.
The claimed “transmitting” functions involve an insignificant post solution activity.
The claimed functions of “validating” or “validate” and “flag” or flagging” involve a mental/manual process.
Here, the claimed concept falls into the category of functions of organizing human activities such as managing commercial or legal interactions (including agreements in the form of contracts; legal obligations; advertising, marketing or sales activities or behaviors; business relations) because it amounts to the functions of:
“validating the cryptogram to identify the prescreened status of the payment transaction, and flagging the authorization request to indicate the prescreened status of the payment transaction flagging, by the payment network, the authorization request to indicate the prescreened status of the payment transaction based on the cryptogram”.
Furthermore, the claimed functions of “generating”, “validating”, and “flagging” involve mental processing.
The BRI of the claimed limitations describes functions of “validating the cryptogram to identify the prescreened status of the payment transaction, and flag the authorization request to indicate the prescreened status of the payment transaction flagging, by the payment network, the authorization request to indicate the prescreened status of the payment transaction based on the cryptogram”.
Step 2A, Prong Two: The judicial exception is not integrated into a practical application, In particular, the clams recite the above noted bolded limitations understood to be additional limitations:
The limitations performing functions of:
“validating the cryptogram to identify the prescreened status of the payment transaction, and flagging the authorization request to indicate the prescreened status of the payment transaction flagging, by the payment network, the authorization request to indicate the prescreened status of the payment transaction based on the cryptogram” amount to instructions to implement an abstract idea on a computer or merely using a computer as a tool to perform an abstract idea (see MPEP 2106.05(1)), also see applicant's specification for guiding interpretation of these claim features, describing implementation with generic commercially available devices or any generic machine capable of executing a set of instructions.
The claimed “validating”, “generating” and “flagging” and “network” functions are similarly understood in light of applicant's specification as mere usage of any arrangement of computer software or hardware intermediate components potentially using networks to communicate with instructions are properly understood to be mere instructions to apply the abstraction using a computer or device or computer system.
The claims recite “validating”, “generating” and “flagging” and “network” using a network.
Performing steps by a generic machine merely limit the abstraction to computer field by execution by generic computers. See MPEP 2106.05¢h).
As noted in MPEP 2106.04(d), limitations which amount to instructions to implement an abstract idea on a computer or merely using a computer as a tool, limitations which amount to insignificant extra-solution activity, and limitations which amount to generally linking to a particular technological environment do not integrate a practical exception into a practical application.
Receiving and transmitting data from/to a machine using a payment network are similar to Alappat, which as noted in MPEP 2106. 05(b)(1) is superseded, and the correct analysis is to look whether the added elements integrate the exception into a practical application or provide significantly more than the judicial exception. The claims in the instant application are performed by a payment network which receives data, transmits data, validates data and flags data.
Consideration of these steps as a combination does not change the analysis as they do not add anything compared to when the steps are considered separately. The claims recite a particular sequence of functions of validating a prescribed status of a payment transaction.
Performance of these steps or functions technologically may present a meaningful limit to the scope of the claim does not reasonably integrate the abstraction into a practical application.
Step 2B: The elements discussed above with respect to the practical application in Step 2A, prong 2 are equally applicable to consideration of whether the claims amount to significantly more. Accordingly, the clams fail to recite additional elements which, when considered individually and in combination, amount to significantly more. Reconsideration of these elements identified as insignificant extra-solution activity as part of Step 2B does not change the analysis.
Receiving and transmitting data by electronic means or hardware amounts to receiving and transmitting information over a network has been recognized by the courts as routine, and conventional (See MPEP 2106.05(d)(ID, citing Symantec, 835 F.3d at 1321, 120 OSPQ2d at 1362 (Utilizing an intermediary computer to forward information); TL Communications LEC v. AV Auto. LLC, 823 F.3d 607, G10, L18 USPO2d 1744, 1748 (ed. Cir. 2016) Casing a telephone for image transmission); OFF Techs., fac. v. Amazon.com, fic., 788 B.Ad 1359, 1363, Lis USPO2d 1090, 1093 (ed, Cir. 2015) (sending messages over a network}, buySAFE, fic. v. Google, Inc.. 768 F.3d 1350, 1355, 112 USPQ2d 1093, 1996 (Pod, Cyr. 2014) (computer receives and sends information over a network).
Positively reciting a “network” and “modules” to enable communication does not change the analysis as these aspects are properly considered as additional elements which amount to instructions to apply it with a computer.
These claimed elements also as found in the dependent claims are also recited at a high level of generality such that they amount to no more than mere instructions to apply the exception using a generic component.
In processing the claims, it is noted that the recitation of these additional elements does not impact the analysis of the claims because these elements in combination are noted only to be a general purpose computer for performing basic or routine computer functions. These claimed elements are noted to be a generic computer for receiving or collecting data and performing routine and conventional functions. These additional elements do not overcome the analysis as these elements are merely considered as additional elements which amount to instructions to be applied to the generic computer.
The judicial exception is not integrated into a practical application. In particular, the claimed API, “payment network”, database and “modules” are recited at a high level of generality such they amount to no more than mere instructions to apply the exception using generic components. Accordingly, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
Accordingly, claims 1 and 14 are directed to an abstract idea.
The dependent claim(s) when analyzed and each taken as a whole are held to be patent ineligible under 35 U.S.C. 101 because the additional recited limitation(s) fail(s) to establish that the claim(s) is/are not directed to an abstract idea.
The following is an examiner's statement of reasons for allowance:
The prior art taken alone or in combination and as argued by the applicant failed to teach or suggest:
“receiving, by the payment network, from an acquirer: an authorization request for the payment transaction, the authorization request by the merchant, and the validating, by the payment network, the cryptogram based on the cryptogram database to identify the prescreened status of the payment transaction, and flag the authorization request to indicate the prescreened status of the payment transaction flagging, by the payment network, the authorization request to indicate the prescreened status of the payment transaction based on the cryptogram”, as recited in independent claim 1.
“receive, by the payment network, from an acquirer: an authorization request for the payment transaction, the authorization request by the merchant, and the cryptogram, validate the cryptogram based on the cryptogram database to identify the prescreened status of the payment transaction, and flag the authorization request to indicate the prescreened status of the payment transaction” as recited in independent claim 14.
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FRANTZY POINVIL whose telephone number is (571)272-6797. The examiner can normally be reached M-Th 7:00AM to 5:30PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Michael Anderson can be reached at 571-270-0508. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/FRANTZY POINVIL/Primary Examiner, Art Unit 3693
April 29, 2026