Prosecution Insights
Last updated: August 17, 2026
Application No. 18/772,759

VALIDATING ONLINE ACCESS TO SECURE DEVICE FUNCTIONALITY

Non-Final OA §101§DOUBLEPATENT
Filed
Jul 15, 2024
Priority
Feb 01, 2016 — provisional 62/289,656 +5 more
Examiner
DAGNEW, SABA
Art Unit
3621
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Apple Inc.
OA Round
3 (Non-Final)
38%
Grant Probability
At Risk
3-4
OA Rounds
2y 2m
Est. Remaining
55%
With Interview

Examiner Intelligence

Grants only 38% of cases
38%
Career Allowance Rate
226 granted / 600 resolved
-14.3% vs TC avg
Strong +18% interview lift
Without
With
+17.6%
Interview Lift
resolved cases with interview
Typical timeline
4y 4m
Avg Prosecution
35 currently pending
Career history
648
Total Applications
across all art units

Statute-Specific Performance

§101
32.6%
-7.4% vs TC avg
§103
41.2%
+1.2% vs TC avg
§102
13.1%
-26.9% vs TC avg
§112
8.2%
-31.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 600 resolved cases

Office Action

§101 §DOUBLEPATENT
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims This action is in response to the amendment filed 15 May 2026. Cl Claims 1-20 are currently pending and have been examined. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 15 May 2026 has been entered. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-20 are rejected on the ground of nonstatutory double patenting over claims 1-20 of U.S. Patent No. 11.170 071 B2 since the claims, if allowed, would improperly extend the “right to exclude” already granted in the patent. The subject matter claimed in the instant application is fully disclosed in the patent and is covered by the patent since the patent and the application are claiming common subject matter, as follows: 18/772,759 11,107,071 A method for facilitating transactions, the method comprising, by a merchant subsystem: interfacing with a computing device to initialize a transaction; providing transaction data to the computing device; issuing, to a commercial entity subsystem, a request to validate the merchant subsystem; receiving encrypted secure data from the computing device, wherein the encrypted secure data is based on at least a portion of the transaction data, at least a portion of validation data generated by the commercial entity subsystem in conjunction with validating the merchant subsystem, and at least a portion of secure data gathered at the computing device; and utilizing the encrypted secure data to complete the transaction. A method for providing a transaction between a merchant subsystem and an electronic device, the method comprising, at a commercial entity subsystem: receiving, from the merchant subsystem, a challenge request that includes a merchant identifier that is associated with (1) the merchant subsystem, and (2) a merchant online resource of the electronic device, wherein the challenge request includes a signature established using a merchant key associated with the merchant subsystem; obtaining the merchant key based on the merchant identifier; validating the signature using the merchant key; indicating to the electronic device that the merchant online resource is valid; receiving validation data and secure data from the electronic device; validating the electronic device based on the validation data; encrypting, using the merchant key, the secure data to establish encrypted secure data; and providing the encrypted secure data to the electronic device to cause the electronic device to execute the transaction with the merchant subsystem. Although the claims at issue are not identical, they are not patentably distinct from each other because it is clear the all the elements of present application to be found in the patented application. The difference between the present application and the patented application is in fact that the patent includes many more elements and is thus much more specific. Thus, the invention of the patent is in effect a “species” of the “generic” invention of the present application. It has been held that the generic invention is “anticipated” by the “species”. See In re Goodman, 29 USPQ2d 2010,2015-16 (Fed. Cir.1993). Since the present application’s claims are anticipated by the claims of the patented application. Claims 1-20 are rejected on the ground of nonstatutory double patenting over claims 1-20 of U.S. Patent No. 12,039,525 B2 since the claims, if allowed, would improperly extend the “right to exclude” already granted in the patent. 18,772,759 12,039,525 A method for facilitating transactions, the method comprising, by a merchant subsystem: interfacing with a computing device to initialize a transaction; providing transaction data to the computing device; issuing, to a commercial entity subsystem, a request to validate the merchant subsystem; receiving encrypted secure data from the computing device, wherein the encrypted secure data is based on at least a portion of the transaction data, at least a portion of validation data generated by the commercial entity subsystem in conjunction with validating the merchant subsystem, and at least a portion of secure data gathered at the computing device; and utilizing the encrypted secure data to complete the transaction. A method for facilitating transactions, the method comprising, by a computing device: interfacing with a merchant subsystem to cause the merchant subsystem to issue, to a commercial entity subsystem, a request to validate the merchant subsystem; receiving, from the merchant subsystem, transaction data in conjunction with initializing a transaction; receiving, from the commercial entity subsystem, first validation data that indicates the commercial entity subsystem has validated the merchant subsystem in response to the request; generating a package that includes (i) at least a portion of the transaction data received from the merchant subsystem, (ii) at least a portion of the first validation data received from the commercial entity subsystem, and (iii) secure data gathered at the computing device; identifying an encryption key that is accessible to the commercial entity subsystem; encrypting the package using the encryption key to produce an encrypted package; providing the encrypted package to the commercial entity subsystem; receiving encrypted secure data from the commercial entity subsystem in response to the commercial entity subsystem accessing and authenticating at least a portion of the package; and providing the encrypted secure data to the merchant subsystem to complete the transaction. Although the claims at issue are not identical, they are not patentably distinct from each other because it is clear the all the elements of present application to be found in the patented application. The difference between the present application and the patented application is in fact that the patent includes many more elements and is thus much more specific. Thus, the invention of the patent is in effect a “species” of the “generic” invention of the present application. It has been held that the generic invention is “anticipated” by the “species”. See In re Goodman, 29 USPQ2d 2010,2015-16 (Fed. Cir.1993). Since the present application’s claims are anticipated by the claims of the patented application. Furthermore, there is no apparent reason why applicant was prevented from presenting claims corresponding to those of the instant application during prosecution of the application which matured into a patent. See In re Schneller, 397 F.2d 350, 158 USPQ 210 (CCPA 1968). See also MPEP § 804. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Step 1: The claims 1-7 are a method, claims 8-14 are a medium and claims 15-20 are a system. Thus, each independent claim, on its face, is directed to one of the statutory categories of 35 U.S.C. §101. However, the claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Step 2-Prong 1: Independent claims (1,8 and 15) recite interfacing to initializing a transaction, providing transaction data, issuing a request to validate , receiving encrypted secure data receiving encrypted secure data from the computing device, wherein the encrypted secure data is based on (i) at least a portion of the transaction data, (ii) at least a portion of validation data generated by the commercial entity subsystem in conjunction with validating the merchant subsystem, and (iii) at least a portion of secure data gathered at the computing device; and utilizing the encrypted secure data to complete the transaction. These limitation as drafted, are a process, that under its broadest reasonable interpretation, cover commercial interaction or legal interaction, validation or marketing activity for the recitation of generic computer components. That is other than receiving “ a computing device” nothing in the claims element preclude the step from practically being performed by a certain interaction or activity between a person and a computer. For example, but for the “computing device” language, the claims encompasses the user issuing validating the merchant subsystem to utilizing to complete a transaction, which is a method of managing interactions between people. The mere nominal recitation of a generic computing device does not take the claim out of the methods of organizing human interactions grouping. Thus, the claim recites an abstract idea. Step 2-Prong 2: The claims as a whole merely describes how to generally “apply” the concept of validating data generating by the commercial entity subsystem in a computer environment. The claimed computer components are recited at a high level of generality and are merely invoked as tools to perform an existing medical records update process. Simply implementing the abstract idea on a generic computer is not a practical application of the abstract idea. Step 2B: As noted previously, the claim as a whole merely describes how to generally “apply” the concept of validating the merchant subsystem in a computer environment. Thus, even when viewed as a whole, nothing in the claim adds significantly more (i.e., an inventive concept) to the abstract idea. The claim is ineligible. Dependent claims 2-7 , 9-14, and 17-20, these claims recite limitation that futher define the same abstract idea noted in the claims 1,8 and 16. These claims do not contain any futher additional element per step 2A prong 2. Therefore, the considered patent ineligible for that same reason above. Claim Objections Claims 1-20 objected to as being rejected under 35 U.S.C 101 rejections Claims 1-20 would be allowable if they are written to overcome 35 U.S.C 101 reactions. Claims 1-20 would be allowable. An allowable subject matter has been indicated and the following is an examiner’s statement of reasons for allowance: The flowing prior arts are the closest prior art to the applicants claimed invention: Sheets et al (US Pub., No., (2015/0019443 A1) focused on embodiments of the present invention are directed to methods, apparatuses, computer readable media and systems for securely processing remote transactions. One embodiment of the invention is directed to a method of processing a remote transaction initiated by a mobile device comprising a server computer receiving a payment request including encrypted payment information. The encrypted payment information being generated by a mobile payment application of the mobile device and being encrypted using a third-party key. The method further comprises decrypting the encrypted payment information using the third-party key, determining a transaction processor public key associated with the payment information, and re-encrypting the payment information using the transaction processor public key(abstract), a method for facilitating transactions (paragraph [0056], discloses facilitate a payment transactions..), the method comprising, by a merchant subsystem: interfacing with a computing device to initialize a transaction (paragraph [0007], discloses allow consumers to user a mobile device comping secure and sensitive payment transactions initiated through merchant ..); providing transaction data to the computing device (paragraph [0010], discloses sending payment response including the re-encrypted payment information to a transaction processor) ; issuing, to a commercial entity subsystem, a request to validate the merchant subsystem (Fig. 4, and paragraph [0101] discloses merchant computer generates a public-private key pair, merchant computer sends public key to certificate authority [request to validate merchant subsystem], and certificate authority verify authenticity of merchant, certificate authority generates signed merchet certificate); receiving encrypted secure data from the computing device, wherein the encrypted (paragraph [0009], discloses the encrypted payment information being generated by the mobile payment application of the mobile device and the encrypted payment information being encrypted using a third-party key) utilizing the encrypted secure data to complete the transaction wherein utilizing encrypted secure data to complete the transaction included decrypting the encrypted secure data (paragraph [0144], discloses secure processing the remote payment transaction in order to pass sensitive information form a mobile payment application…, completing a remote payment transaction). Weller et al (US Pub., 2014/0244511 A1) discloses method for providing a transaction between a merchant subsystem and an electronic device (paragraph [0025], discloses cardholder/consumer conduct transaction with merchant) the method comprising: issuer or by a third party on the behalf of an issuer [a commercial entity subsystem] (Figs. 1-14, disclose issuer and paragraph [0007]) and receiving an authentication request from a merchants’ e-commerce site [merchant subsystem] .., user should be authenticating using a challenge response sequence(paragraphs [0011]-[0013]) Plomske et al (US Patent No., 10,339,524 B2) discloses systems and methods for multi-merchant tokenization may include receiving a transaction from a point-of-sale terminal of a merchant, validating the merchant ID against merchant logs, and generating a token for the transaction(abstract), receiving a transaction from a point-of-sale terminal of a merchant, validating the merchant ID against merchant logs, and generating a token for the transaction. The token includes a primary account number, expiration, and a group ID (Col. 2, lines 6-9) and he tokenizer encryption service 110 validates credentials 20 and identifies keys for the encrypted data. The tokenizer encryption service 110 may leverage a data tier 114 populated by analytics 116 system and CRM application(s) in order to perform validation and identification of keys (Col. 5, lines 20-29). Makhotin et al (US Pub., 2015/0088756 A1) discloses the method comprising a server computer receiving a payment request including encrypted payment information that is encrypted using a first key. The encrypted payment information including security information (encrypting secure data). The method further comprises decrypting the encrypted payment information using a second key (abstract), third party system may be used to validate a merchant application associated with a merchant certification , determine merchant key associated with the validated merchant application, decrypt payment information and re-encrypt the payment information using a trusted merchant’s public key (encrypt using merchant key) (paragraph [0027]) and transmit (provide) the payment request including the encrypted payment information , merchant certificate, and any transaction information to the remote key manager …, keys associated with the secure channel to communicate the payment request to the remote key manager 140 ( to execute the transaction) (paragraph [0160]) and the merchant identifier is associated with a registered merchant and may perform any other suitable validation that may ensure the payment request including the encrypted payment inform ion (paragraph [0165]) and remote key manager may validate a signature on any transaction data (paragraph [0166]). Ortiz et al (US Pub., No., 2016/0210626 A1) focused on systems , methods, and machine-executable data structures for the processing of data for the secure creation, administration, manipulation, processing, and storage of electronic data useful in the processing of electronic payment transactions and other secure data processes (abstract) and improved systems, methods, and programming structures for the rapid and secure negotiation, authorization, execution, and confirmation of multi-party data processes. In various embodiments, the disclosure provides systems, methods, and programming structures which are particularly well suited for the negotiation, authorization, execution, and confirmation of purchases and other electronic resource (including funds) transfers (paragraph [0031]). However, none of the above reference either in a combination or alone teaches or suggest that wherein the encrypted secure data is based on (i) at least a portion of the transaction data, (ii) at least a portion of validation data generated by the commercial entity subsystem in conjunction with validating the merchant subsystem, and (iii) at least a portion of secure data gathered at the computing device, and wherein the encrypted secure data is encrypted using a merchant key associated with the merchant subsystem to complete a transaction. Any comments considered necessary by applicant must be submitted no later than the payment of the issue fee and, to avoid processing delays, should preferably accompany the issue fee. Such submissions should be clearly labeled “Comments on Statement of Reasons for Allowance.” Response to Arguments Applicant's arguments of 35 U.S.C 101 rejections with respect to claim 1-20 filed on 18 September 2025 have been fully considered but they are not persuasive. Applicant arguments of independent claims 1, 8, 15 wherein amended to recite “wherein the encrypted sure data is encrypted using a merchant key associated with the merchant subsystem;” and “wherein utilizing the encrypted secure dat to complete the transactions includes decrypting the encrypted secure data” is not persuasive. The claims as unpatentable subject matter, typically arguing it is directed to an abstract idea (like mental steps or mathematical concepts) without an inventive concept. Furthermore, cryptographic data and encryption keys as "purely conventional" or "ordinary". They treat this as taking a standard transaction process and just "doing it with encryption," which courts have repeatedly found to be an abstract idea. Additionally, the claimed method is a process for conducting financial transactions using generic computers which is well-known activities and considered abstract. The described steps (initializing a transaction, providing data, validating an entity, receiving and utilizing secure data) are fundamental business practices or data processing steps that can, in principle, be performed by a human (albeit more slowly) or on paper. The use of "a computing device," "commercial entity subsystem," and "merchant subsystem" without further technical limitations suggests the use of generic technology. The encryption and decryption steps, while technical in nature, may be considered well-understood, routine, and conventional activities when implemented on a generic computer. In order to overcome the 35 U.S.C 101 rejection, an applicant should need to demonstrate that the claims are directed to a specific, non-generic technological improvement, perhaps by: Claiming a specific, unconventional method of encryption or decryption that improves the function of the computer itself, rather than just applying a known method. Specifying a particular, non-generic machine or a novel configuration of hardware components that is integral to the process, not just "a computing device". Clearly articulating how the claimed invention solves a specific technical problem in a non-abstract way, such as improving the efficiency or security of the system in a way that is not well-understood, routine, or conventional. Applicants’ arguments of the pending are not directed to an abstract idea is not persuasive. A method for facilitating transactions that relies on generic steps (interfacing, transmitting transaction data, validation requests, and encrypting/decrypting using a key) to complete a transaction on standard hardware will almost certainly face a 35 U.S.C. 101 rejection for claiming an abstract idea without an inventive concept. The claims directed to “fundamental economic practice” or a method or organizing human activity (e.g., verifying a merchant/transaction, gathering data, and completing a payment), which is performed a task on generic computer, using known cryptographic techniques, or calling standard sub-systems (like commercial entity subsystems) does not transform the abstract idea into a patentable invention. Merely saying "do it on a computer" is insufficient. Thus, the Examiner maintains the rejection of said claims under 35 U.S.C. 101, and Applicant’s arguments are considered to be non-persuasive. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SABA DAGNEW whose telephone number is (571)270-3271. The examiner can normally be reached 9-6:45. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Waseem Ashraf can be reached at (571) 270 -3948. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SABA DAGNEW/Primary Examiner, Art Unit 3621
Read full office action

Prosecution Timeline

Show 4 earlier events
Sep 18, 2025
Response Filed
Nov 25, 2025
Final Rejection mailed — §101, §DOUBLEPATENT
Apr 10, 2026
Request for Continued Examination
Apr 10, 2026
Response after Non-Final Action
Apr 22, 2026
Response after Non-Final Action
Jun 03, 2026
Non-Final Rejection mailed — §101, §DOUBLEPATENT
Jul 22, 2026
Examiner Interview Summary
Jul 22, 2026
Applicant Interview (Telephonic)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12688511
WEARABLE FORM-FACTOR DISPLAY OF A KEEPSAKE
2y 10m to grant Granted Jul 21, 2026
Patent 12670510
RECOMMENDATIONS TO PROMOTE CONTENT DISCOVERY
1y 10m to grant Granted Jun 30, 2026
Patent 12572959
SYSTEMS AND METHODS FOR OPTIMAL AUTOMATIC ADVERTISING TRANSACTIONS ON NETWORKED DEVICES
1y 7m to grant Granted Mar 10, 2026
Patent 12505426
AUTOMATED MULTI-PARTY TRANSACTION DECISIONING SYSTEM
1y 8m to grant Granted Dec 23, 2025
Patent 12488149
SYSTEM AND METHOD FOR OPTIMIZING ONLINE PRIVACY RECOMMENDATIONS FOR ENTITY USERS
2y 1m to grant Granted Dec 02, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
38%
Grant Probability
55%
With Interview (+17.6%)
4y 4m (~2y 2m remaining)
Median Time to Grant
High
PTA Risk
Based on 600 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month