DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
This is a non-final action in response to the applicant’s communication received on May 22, 2026 (“Amendment”).
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 5/22/2026 has been entered.
Status of Claim
Claims 21, 28, 31, 33, and 34 have been amended.
Claims 21-34 are pending.
Claim Objection
Claim 21 is objected as the claim recites in part being unique to the installation of the of the first application program. The applicant is advised to remove one of of the expression.
Information Disclosure Statement (IDS)
IDS received on May 22, 2026 is being considered by the examiner.
Continuation
This application is a continuation application of U.S. application no. 17/752,212 filed on May 24, 2022, now U.S. Patent 12,100,003 ("Parent Applications") which is a continuation of U.S. application no. 15/919,621 filed on March 13, 2018, now U.S. Patent 11,361,313 ("Parent Applications") which is a continuation of U.S. application no. 14/557,974 filed on December 2, 2024, now U.S. Patent 9,953,315 (“Parent Applications”). See MPEP §201.07. In accordance with MPEP §609.02 A. 2 and MPEP §2001.06(b) (last paragraph), the Examiner has reviewed and considered the prior art cited in the Parent Application. Also in accordance with MPEP §2001.06(b) (last paragraph), all documents cited or considered ‘of record’ in the Parent Applications are now considered cited or ‘of record’ in this application. Additionally, Applicant(s) are reminded that a listing of the information cited or ‘of record’ in the Parent Application need not be resubmitted in this application unless Applicant(s) desire the information to be printed on a patent issuing from this application. See MPEP §609.02 A. 2.
Claim Interpretation
The term “installation” interpreted as “something that is installed for use” as opposed to “act of installing” as defined in Merriam-Webster dictionary as the specification is silent to installation process.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 21-34 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Per claims 21 and 28, the claims recite in part such that the encrypted payment credentials are accessible on the mobile device only by the installation of the first application program corresponding to the instance identifier used to generate the advanced storage key … wherein the encrypted payment credentials, as stored on the mobile device, remain accessible solely to the installation of the first application program corresponding to the instance identifier.
Instant publication discloses this concept of in paragraphs [0067], [0121], and [0123]:
[0067] The MPA 404 may also include an instance identifier 408. The instance identifier 408 may be a value unique to the specific MPA 404, which may be used in the generation of the advanced storage key used to secure data in the mobile device 104, such as the card database 208. By having the instance identifier 408 unique to the MPA 404, multiple MPAs 404 may be installed on the mobile device 104, without any one MPA 404 being able to access data that is securely stored by any other MPA 404, which can thereby ensure that payment profiles 302 for specific transaction accounts are not accessible by other programs. The instance identifier 408 may be a number, alphanumeric value, hexadecimal value, or any suitable value that may be unique to an MPA 404.
[0121] The processing unit 204 may also be configured to generate a diversifier value 1208 using the mobile device fingerprint 1204. The diversifier value may be generated by combining the mobile device fingerprint 1204 with the instance identifier 408 of the MPA 404 as well as a random value 1206. The random value 1206 may be a random or pseudo-random number generated by the processing unit 204. In some instances, the random value 1206 may be generated pursuant to one or more rules or algorithms stored in the memory 212. The combination of the mobile device fingerprint 1204, instance identifier 408, and random value 1206 may also be performed using one or more rules or algorithms, such as stored in the program code 406 of the MPA 404. Use of the instance identifier 408 to generate the diversifier value may result in the ability to securely store data associated with an instance of the MPA 404 such that multiple installations of the MPA 404 may be unable to access data stored by other instances of the MPA 404.
[0123] Once the advanced storage key 1210 has been generated, the processing unit 204 may use the advanced storage key 1210 to encrypt a local database 1210. The local database 1210 may be comprised of, for example, the card database 208, one or more payment profiles 302, part of the memory 212, or other suitable data source. In some instances, the local database 1210 may be a part of another database in the mobile device 104, such as the card database 208. For example, the card database 208 may include a plurality of local databases 1212, such as a separate local database 1212 for each instance of the MPA 404 for storing payment profiles 302 associated thereof. The resulting encrypted local database 1214 may thereby securely store data that is inaccessible by any other application program internal or external the mobile device 104 except the specific instance of the MPA 404 that includes the instance identifier 408. Accordingly, the encrypted local database 1214 may be ideal to store payment credentials 304, single use keys 306, and other account data, and may provide for secure storage of sensitive account information without the use of secure elements.
While the publication finds support for the data that remains accessible solely to a MPA (i.e., application program) corresponding to the instance identifier, there is no support for encrypted data that remains accessible solely to the MPA corresponding to the instance identifier. In other words, the disclosure allows the MPA sole access to the data by having an ability to decrypt the encrypted data using its instance identifier.
The dependent claims are rejected as they depend on the independent claims.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 21-34 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 2014/0297438 A1 (“Dua”) in view of US Patent No. 6,266,415 B1 (“Campinos”) and US 2009/0262926 A1 (“Kabra”).
Per claim 21 and 28, Dua fairly teaches a method comprising:
receiving, by a processing server (wireless credential manager), an instance identifier from a mobile device (wireless device) ([0042], wireless credential manager that causes the credential or set of credentials to be transmitted to wireless device; [0044]-[0046], wireless device initiate the credential issuance process to receive the credential using SIP, Internet; [0059], WCM received user’s mobile number);
encrypting, by the processing server, payment credentials using the generated advanced storage key ([0052], encrypted credentials; [0110], encrypted transport mechanism; [0149], session to exchange encryption key … authenticate the mobile user’s identity; [0173]; [0183], encryption of the credentials); and
transmitting, by the processing server, the encrypted payment credentials to the mobile device for storage on the mobile device, wherein the encrypted payment credentials, as stored on the mobile device, remain accessible to the installation of the first application program ([0042]; [0043], wireless device has processing and secure storage capabilities allowing it to host and operate a wallet application capable of receiving, storing, managing and transmitting multiple payment, identification, and other confidential information electronically; [0059]; [0062]; [0105], WCM delivers credential to wallet application on a wireless device).
Dua further teaches system comprising: a mobile device (wireless device) and a processing server (WCM).
Dua does not particularly teach receiving a random number and an instance identifier, the random value and the instance identifier being included in a first application program on the mobile device, and the instance identifier being unique to an instance of the first application program and advanced storage key by encrypting the random value using an encryption key.
Campinos discloses receiving a random number and generating an encryption key by encrypting the random value (col. 3, ll. 46-57, the transmitted random number is encrypted to produce an encryption key).
Hence, as Dua generally teaches use of encryption key in encrypting credential sent to the mobile device, it would have been obvious to one of ordinary skill in the art before the effective filing of instant claim to utilize any known technique of generation of the encryption key, including the key generation technique as taught by Campinos, as a key generation technique in Dua since the claimed invention is merely a combination of old elements, and in the combination each element merely would have performed the same function as it did separately, and one of ordinary skill in the art would have recognized that the results of the combination were predictable. Furthermore, it would have been obvious to one of ordinary skill in the art prior to the effective filing of instant claim(s) to include the encryption technique to prevent any pirate from discovering the encryption/decryption key K. (col. 3, ll. 64-65).
Dua/Campinos does not particularly teach that the key is generated further using an instance identifier being included in a first application program on a device, the first application program being one of a plurality of installations of an application on the device, and the instance identifier being unique to the installation of the first application program on the device such that the instance identifier of the first application program is different from a respective identifier of each other installation of the application on the device such that the encrypted data are accessible on the device only by the installation of the first application program corresponding to the instance identifier used to generate the key.
Kabra, however, teaches generating a key using an instance identifier that is included in a first application program on a device, the first application program being one of a plurality of installations of an application on the device, and the instance identifier being unique to the installation of the first application program on the device such that the instance identifier of the first application program is different from a respective identifier of each other installation of the application on the device such that the encrypted data are accessible on the device only by the installation of the first application program corresponding to the instance identifier used to generate the key (see [0002], a system where authorization to data is granted for a computer application and not for all computer applications on the device; [0016]-[0017], to decrypt encrypted data from the storage … ensuring that application data can be accessed (read successfully) only by the same (computer) application; [0019], computer program identifier is used to derive cryptographic key for encryption or decryption; [0028], unique device identifier 208 and an application identity 204 … may be used to derive application-specific cryptographic key 210 which may be used to encrypt or decrypt data).
It would have been obvious to one of ordinary skill in the art before the effective filing of instant claim to combine the technique of using the application identity in deriving the encryption key for storage as taught by Kabra to Dua/Campinos as the combination ensures that application data can be accessed only by the same computer application (see [0017]).
The applicant is reminded that the description of the first application program, i.e., being one of plurality of installations of a mobile payment application on the mobile device, does not move to distinguish over the method claim as the method claim is directed to steps performed by the processing server.
The applicant is also reminded that the description of the instance identifier, i.e., being unique to the installation of the first application program on the mobile device such that the instance identifier of the first program is different from a respective instance identifier of each other installation of the mobile payment application on the mobile device does, not move to distinguish over prior art as the description does not affect the step(s) of receiving such data, using the data (instance identifier) to generate the advanced storage key, encrypting payment credentials using the key, and transmitting the encrypted payment credentials to the mobile device, in steps of the method claim and the system claims (i.e., functionally).
The applicant is reminded that the description of the advanced storage key, i.e., being unique to the installation of the fist application program on the mobile device, does not move to distinguish over prior art as the description is merely intended result of the generating of the advanced storage key, i.e., encrypting the random value and the instance identifier using an encryption key.
The applicant is reminded that the expressions of such that the encrypted payment credentials are accessible on the mobile device only by the installation of the first application program corresponding to the instance identifier used to generate the advanced storage key, for storage on the mobile device, and wherein the encrypted payment credentials, as stored on the mobile device, remain accessible solely to the installation of the first application program corresponding to the instance identifier are intended use of the advance storage key, thereby do not move to distinguish over prior art.
As per claims 22 and 29, Dua/Campinos/Kabra further teaches wherein the random value is a random or pseudo-random number (see Campinos: col. 3, ll. 46-57, random number).
As per claims 23 and 30, Dua/Campinos/Kabra further teaches wherein the encryption key is a dynamic key (Campinos: col. 3, ll. 46-57, generated dynamically).
As per claims 24 and 31, Dua/Campinos/Kabra further teaches generating, by the processing server, one or more parameters; encrypting, by the processing server, the one or more parameters using the advanced storage key; transmitting, by the processing server, the one or more encrypted parameters to the mobile device (Dua: [0126]-[0127]).
As per claims 25 and 32, Dua is absent of secure element in description of mobile device (i.e., wireless device).
As per claims 26 and 33, Dua/Campinos/Kabra further teaches receiving, by the mobile device, the encrypted payment credentials from the processing server; and storing, by the mobile device, the encrypted payment credentials in a local storage (Dua: [0149], decrypt credential that is transmitted to the wireless device, [0245], stored within the wallet application).
Dua does not particularly teach that the local storage is a database. However, as Dua teaches storage means including database, it would have been obvious to one of ordinary skill in the art prior to the effective filing of the claim(s) to include any storage techniques, including database, as a storage technique of the wallet application in Dua.
As per claims 27 and 34, Dua/Campinos/Kabra teaches receiving, by the mobile device, the one or more encrypted parameters from the processing server (Dua: [0126]-[0127]). Dua does not particularly teach storing by the mobile device the one or more encrypted parameters in a local database. However, as Kabra generally teaches storing information on a mobile device in a database (see [0105]) and Dua teaches storing information received from the processing server as described above in within the wallet application as described above, it would have been obvious to one of ordinary skill in the art prior to the effective filing of the claim(s) to store any information received from the processing server in the wallet application using database with a predictable result of storing information on the mobile device.
Response to Argument(s)
101
The 101 rejection is withdrawn in light of the applicant’s argument in the amendment.
103
The argument is moot in light of new prior art introduced in light of the amendment.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US 20160119312A1 discloses encryption technique in which key is generated based on generated key;
US 20150254645 A1discloses a method and system for providing supplemental account information in digital wallets. The disclosure also discloses a digital wallet maintained on a user’s mobile device and the financial institution provisioning payment credential for use within the digital wallet;
US 9536243 B2 discloses wallet application that is stored in a secure memory element of NFC device or in a non-secured baseband memory.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to STEVEN S KIM whose telephone number is (571)270-5287. The examiner can normally be reached Monday -Friday: 7:00 - 3:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Patrick McAtee can be reached at 571-272-7575. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/STEVEN S KIM/Primary Examiner, Art Unit 3698