DETAILED ACTION
This is a final office action on the merits. The U.S. Patent and Trademark Office (the Office) has received claims 1 – 25.
Claims 1-6 and 8-13 are amended.
Claims 14-20 canceled.
Claims 21-25 are new.
Claims 1-13 and 21-25 are pending and have been examined on the merits.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Claim Objections
Applicant’s arguments, filed 3/2/2026 with respect to the claim objections have been fully considered and are persuasive. The claim rejection of Claim 8 has been withdrawn.
Claim Rejections - 35 USC § 101
Applicant’s arguments, filed 3/2/2026 with respect to the 101 rejection have been fully considered and are not persuasive. The claims are still directed to authorizing use of payment access data by comparing device data and if authorized, providing payment credentials for use in a transaction. Please see rejection below.
Claim Rejections - 35 USC § 103
Applicant’s arguments, filed 3/2/2026 with respect to the 102/103 rejection have been fully considered and are not persuasive. The rejection does not rely on Chen alone for the newly amended payment card NFC features. Chen is relied upon for the core card device verification logic and Fisher is relied upon for the payment NFC environment. Even if Chen’s primary example is a SIM/UICC smart card, Fisher supplies the missing payment card and NFC transaction context. Please see rejection below.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-13 and 21-25 are rejected under 35 U.S.C. 101 because the claimed invention recites and is directed to a judicial exception to patentability (i.e., an abstract idea) and does not provide an integration of the recited abstract idea into a practical application nor include an inventive concept that is “significantly more” than the recited abstract idea to which the claim is directed. MPEP §2106.
In determining subject matter eligibility in an Alice rejection under 35 U.S.C. §101, it is first determined at Step 1 whether the claims are directed to one of the four statutory categories of an invention (i.e., a process, a machine, a manufacture, or a composition of matter). MPEP §2106.03. Here, it is determined that claims 1-7 and 14-20 are directed to a method. Claims 8-13 are directed to a machine. Under a Step 2A, Prong 1 analysis, it must be determined whether the claims recite an abstract idea that falls within one or more enumerated categories of patent ineligible subject matter that amounts to a judicial exception to patentability. MPEP §2106.04. Here, independent claim 1 recites (Abstract idea bolded):
A method comprising:
receiving, by a payment card comprising access data from a user device, a communication comprising second user device data via near field communications (NFC), wherein the access data comprises a payment account number or a payment token, and the payment card comprises a memory storing first user device data;
determining, by the payment card that the second user device data received from the user device corresponds to the first user device data on the payment card, and that the user device is authorized to receive the access data; and
in response to determining that the second user device data corresponds to the first user device data, then providing, by the payment card the access data to the user device via near field communications (NFC), wherein the user device initiates an interaction with an external computer using the access data.
Here, the claims are directed to the abstract idea, or combination of abstract ideas of controlling access to account data for commercial transactions/fraud prevention. This concept/abstract idea, which is seen above, falls within the Certain Methods of Organizing Human Activity grouping because it describes a commercial or legal interaction. Accordingly, it is determined that the claims recite an abstract idea since they fall within one or more of the three enumerated categories of patent ineligible subject matter.
Since it is determined that the claim(s) contain a judicial exception, it must then be determined, under Step 2A, Prong 2, whether the judicial exception is integrated into a practical application of the exception. MPEP §2106.04. Here, claim 1 recites the additional elements of: “payment card”, “device”, “near field communications (NFC)”, “token”, and “external computer.” Therefore, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
Under the Step 2B analysis, it is determined whether the recited additional elements amount to something “significantly more” than the recited abstract idea to which the claims are directed (i.e., provide an inventive concept). MPEP §2106.05. As discussed above with respect to integration of the abstract idea into a practical application, the additional element(s): “payment card”, “device”, “near field communications (NFC)”, “token”, and “external computer” to implement the abstract idea amounts to no more than performing generic computer functions. Mere instructions to apply an exception using generic computer components cannot provide an inventive concept. That is, simply implementing the abstract idea on a generic computer or merely using a computer as a tool to perform an abstract idea cannot integrate a judicial exception into a practical application at Step 2A or provide an inventive concept in Step 2B. Accordingly, taken alone, the additional elements do not amount to significantly more than a judicial exception. Looking at the limitations as an ordered combination adds nothing that is not already present when looking at the elements taken individually.
Independent claim 8 is similar and so are rejected under 35 U.S.C. §101 as not being patent eligible.
Dependent claims 2-7, 9-13, and 15-20 when analyzed are held to be patent ineligible under 35 U.S.C. §101 because the additional recited limitation(s) (BOLDED) fail to establish that the claim(s) is/are not directed to an abstract idea.
Dependent claim 2 recites “The method of claim 1, wherein the payment card determines if the stored first user device data matches the second user device data received from the user device.” The claim elaborates on the abstract idea without reciting any new additional elements. Therefore, when the limitations are considered individually and as a whole in combination with the independent claim from which they depend, the claims do not recite additional elements that amount to significantly more than the judicial exception.
Dependent claim 3 recites “The method of claim 2, wherein the first user device data comprises a user device identifier.” The new additional fails to recite a practical application or significantly more than the abstract idea because it merely serves as a tool to perform the abstract idea (MPEP § 2106.05(f)). The new additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
Dependent claim 4 recites “The method of claim 1, wherein the second user device data is a digital signature, and wherein the method further comprises verifying the digital signature. The new additional fails to recite a practical application or significantly more than the abstract idea because it merely serves as a tool to perform the abstract idea (MPEP § 2106.05(f)). The new additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
Dependent claim 5 recites “The method of claim 4, wherein the user device is a phone.” The new additional fails to recite a practical application or significantly more than the abstract idea because it merely serves as a tool to perform the abstract idea (MPEP § 2106.05(f)). The new additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
Dependent claim 6 recites “The method of claim 5, wherein the payment card is a credit or debit card.” .” The claim elaborates on the abstract idea without reciting any new additional elements. Therefore, when the limitations are considered individually and as a whole in combination with the independent claim from which they depend, the claims do not recite additional elements that amount to significantly more than the judicial exception.
Dependent claim 7 recites “The method of claim 1, wherein the user device is a mobile phone.” The new additional fails to recite a practical application or significantly more than the abstract idea because it merely serves as a tool to perform the abstract idea (MPEP § 2106.05(f)). The new additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
Dependent claim 9 recites “The payment card of claim 8, wherein the access data comprises the payment account number.” The claim elaborates on the abstract idea without reciting any new additional elements. Therefore, when the limitations are considered individually and as a whole in combination with the independent claim from which they depend, the claims do not recite additional elements that amount to significantly more than the judicial exception.
Dependent claim 10 recites “The payment card of claim 8, wherein the payment card is a credit card.” The claim elaborates on the abstract idea without reciting any new additional elements. Therefore, when the limitations are considered individually and as a whole in combination with the independent claim from which they depend, the claims do not recite additional elements that amount to significantly more than the judicial exception.
Dependent claim 11 recites “The payment card of claim 8, wherein the user device is a mobile phone.” The new additional fails to recite a practical application or significantly more than the abstract idea because it merely serves as a tool to perform the abstract idea (MPEP § 2106.05(f)). The new additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
Dependent claim 12 recites “The payment card of claim 8, further comprising a contactless element coupled to the processor, and the contactless element is configured to communicate using NFC (near field communications).” The new additional fails to recite a practical application or significantly more than the abstract idea because it merely serves as a tool to perform the abstract idea (MPEP § 2106.05(f)). The new additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
Dependent claim 13 recites “The payment card of claim 8, wherein the payment card has the access data embossed on the payment card.” The claim elaborates on the abstract idea without reciting any new additional elements. Therefore, when the limitations are considered individually and as a whole in combination with the independent claim from which they depend, the claims do not recite additional elements that amount to significantly more than the judicial exception.
Dependent claim 21 recites “The method of claim 1, wherein the user device comprising an SDK (software development kit), which can perform verification of the user device.” The new additional fails to recite a practical application or significantly more than the abstract idea because it merely serves as a tool to perform the abstract idea (MPEP § 2106.05(f)). The new additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
Dependent claim 22 recites “The method of claim 1, wherein the first user device data comprises a user device identifier that is stored when the payment card is being manufactured.” The new additional fails to recite a practical application or significantly more than the abstract idea because it merely serves as a tool to perform the abstract idea (MPEP § 2106.05(f)). The new additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
Dependent claim 23 recites “The method of claim 1, wherein the first user device data comprises a user device identifier that is stored after the payment card is manufactured.” The new additional fails to recite a practical application or significantly more than the abstract idea because it merely serves as a tool to perform the abstract idea (MPEP § 2106.05(f)). The new additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
Dependent claim 24 recites “The method of claim 1, wherein the second user device data is received by the payment card in a get processing options command from the user device.” The claim elaborates on the abstract idea without reciting any new additional elements. Therefore, when the limitations are considered individually and as a whole in combination with the independent claim from which they depend, the claims do not recite additional elements that amount to significantly more than the judicial exception.
Dependent claim 25 recites “The method of claim 1, wherein the user device and the payment card are specifically associated with a user.” The claim elaborates on the abstract idea without reciting any new additional elements. Therefore, when the limitations are considered individually and as a whole in combination with the independent claim from which they depend, the claims do not recite additional elements that amount to significantly more than the judicial exception.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 1-3, 7-12, 13 is/are rejected under 35 U.S.C. 103 as being unpatentable by Chen (US20120036282A1) in view of Fisher (US20120150601A1).
Regarding Claim 1, Chen teaches:
A method comprising: receiving, by a payment card comprising access data from a user device, a communication comprising second user device data…
Chen - Smart card 120 may include input/output circuitry 300, a processing unit 310, and a memory 320. Input/output circuitry 300 may include circuitry for inputting data to smart card 120 from device 110, and output circuitry for outputting data from smart card 120 to device 110. Processing unit 310 may include a processor, microprocessor, or processing logic that may interpret and execute instructions. Memory 320 may include RAM, ROM, and/or Electrically Erasable Programmable Read-Only Memory (EEPROM) that may store data (e.g., TPN, IMEI and/or ACTV values), and may store instructions for execution by processing unit 310 (¶ 0025).
…the payment card comprises a memory storing first user device data;
Chen - Smart card 120 may include input/output circuitry 300, a processing unit 310, and a memory 320. Input/output circuitry 300 may include circuitry for inputting data to smart card 120 from device 110, and output circuitry for outputting data from smart card 120 to device 110. Processing unit 310 may include a processor, microprocessor, or processing logic that may interpret and execute instructions. Memory 320 may include RAM, ROM, and/or Electrically Erasable Programmable Read-Only Memory (EEPROM) that may store data (e.g., TPN, IMEI and/or ACTV values), and may store instructions for execution by processing unit 310 (¶ 0025).
determining, by the payment card that the second user device data received from the user device corresponds to the first user device data on the payment card, and that the user device is authorized to receive the access data; and
Note – Smart card 120 compares retrieved device data with stored device data; if they differ, the device is effectively not the expected/authorized device.
Chen - The smart card compares the retrieved device identifier and the at least one application configuration value with a device identifier and at least one application configuration value previously stored in the smart card (Abstract). Smart card 120 may determine if IMEICARD is not equal to IMEIDEV, if TPNCARD is not equal to TPNDEV, or if ACTVCARD is not equal to ACTVDEV (block 415) (¶ 0032).
in response to determining that the second user device data corresponds to the first user device data, then providing…
Chen - FIG. 6 is a flow diagram illustrating an exemplary process for implementing smart card driven device configuration changes where smart card 120, instead of an OTA server, stores and supplies the application configuration parameter changes to device 110 (¶ 0036). Smart card 120 may then push the changed application configuration parameter(s) to device 110 (block 660). The messaging diagram of FIG. 7 depicts the changed application configuration parameters 730 being supplied via smart card 120 to device 110 (¶ 0039).
wherein the user device initiates an interaction with an external computer using the access data.
Note – APN/NAI and similar values are network access data that device 110 uses when it starts communication with network 150.
Chen - Exemplary embodiments described herein employ a smart card inserted into a device (e.g., into a mobile telephone) to drive configuration changes associated with the operation of the mobile device. Such configuration changes may include changes in Access Point Names (APNs), Network Access Identifiers (NAIs), Multi-Media Messaging Service (MMS) information, Wireless Application Protocol (WAP) information, application keys, and other data associated with the operation of the mobile device (¶ 0011). OMA DM OTA server 140 may configure the devices, including device 110, by supplying application parameters used in the operation of the devices, may enable and disable features of the devices (¶ 0016). Network 150 may include one or more networks of any type, such as, for example, a telecommunications network…and internet (¶ 0016).
Chen does not teach, however Fisher discloses:
…via near field communications (NFC), wherein the access data comprises a payment account number or a payment token, and…
Fisher - The invention describes how a consumer can hold their NFC enabled device in proximity to an NFC enabled point-of-sale terminal and with a single “wave” or “tap” to automatically redeem coupons, pay for a purchase using a default payment card or a selected card, view receipts view reward point balances, and receive relevant coupons and other digital artifacts both before and after the purchase. The NFC enabled device includes a secure element with a payment application, payment credentials, and other digital artifacts such as coupons. The secure element can be internal to the mobile device, externally affixed to the mobile device, or inserted into a slot within the body of the mobile device (Abstract).
by the payment card the access data to the user device via near field communications (NFC),
Fisher - The invention describes how a consumer can hold their NFC enabled device in proximity to an NFC enabled point-of-sale terminal and with a single “wave” or “tap” to automatically redeem coupons, pay for a purchase using a default payment card or a selected card, view receipts view reward point balances, and receive relevant coupons and other digital artifacts both before and after the purchase. The NFC enabled device includes a secure element with a payment application, payment credentials, and other digital artifacts such as coupons. The secure element can be internal to the mobile device, externally affixed to the mobile device, or inserted into a slot within the body of the mobile device (Abstract).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the device binding comparison of Chen with the security of the mobile payment environment of Fisher because doing so the payment credentials are only released or used when the payment card/secure element determines that the mobile device corresponds to stored device data.
Regarding Claim 2. The combination of Chen and Fisher further discloses:
The method of claim 1, wherein payment card stores the user device data and determines if the stored first user device data matches the user device data received from the user device.
Chen - A smart card determines if the smart card has been inserted into a device, and retrieves a device identifier and at least one application configuration value from the device if the smart card has been inserted into the device. The smart card compares the retrieved device identifier and the at least one application configuration value with a device identifier and at least one application configuration value previously stored in the smart card (Abstract).
Regarding Claim 3. The combination of Chen and Fisher further discloses:
The method of claim 2, wherein the first user device data comprises a user device identifier.
Chen - FIGS. 4A & 4B are flow diagrams illustrating an exemplary process for implementing smart card driven device configuration changes based on the use of a Terminal Profile Number (TPN), a device identifier, (e.g., IMEI), or an Application Configuration Tracking Value (ACTV) stored in both the smart card and the device into which the smart card is inserted (¶ 0006).
Regarding Claim 7. The combination of Chen and Fisher further discloses:
The method of claim 1, wherein the user device is a mobile phone.
Chen - Device 110 may include, for example, a cellular radiotelephone, a smart phone, a personal digital assistant (PDA) (¶ 0013). .
Regarding Claim 8. Chen teaches:
A portable device comprising: a processor; and
Chen - one or more processors (¶ 0042).
a memory storing a payment account number or a payment token, and first user device data, and a computer readable medium coupled to the processor, the computer readable medium comprising access data. and code executable by the processor for performing operations comprising:
Chen - Smart card 120 may perform certain operations or processes, as may be described in detail below. Smart card 120 may perform these operations in response to processing unit 310 executing software instructions contained in a computer-readable medium, such as memory 320 (¶ 0026).
receiving, from a user device, a communication comprising second user device data…
Chen - smart card 120 may retrieve TPN, IMEI, and/or ACTV values (i.e., TPNDEV, IMEIDEV, ACTVDEV) stored in device 110 (¶ 0030).
determining, that the second user device data received from the user device corresponds to the first user device data on the payment card, and that the user device is authorized to receive the access data; and
Chen - Smart card 120 may determine if IMEICARD is not equal to IMEIDEV, if TPNCARD is not equal to TPNDEV, or if ACTVCARD is not equal to ACTVDEV (¶ 0032).
in response to determining that the second user device data corresponds to the first user device data…wherein the user device initiates an interaction with an external computer using the access data.
Chen - Exemplary embodiments described herein employ a smart card inserted into a device (e.g., into a mobile telephone) to drive configuration changes associated with the operation of the mobile device. Such configuration changes may include changes in Access Point Names (APNs), Network Access Identifiers (NAIs), Multi-Media Messaging Service (MMS) information, Wireless Application Protocol (WAP) information, application keys, and other data associated with the operation of the mobile device (¶ 0011). OMA DM OTA server 140 may configure the devices, including device 110, by supplying application parameters used in the operation of the devices, may enable and disable features of the devices (¶ 0016). Network 150 may include one or more networks of any type, such as, for example, a telecommunications network…and internet (¶ 0016). FIG. 6 is a flow diagram illustrating an exemplary process for implementing smart card driven device configuration changes where smart card 120, instead of an OTA server, stores and supplies the application configuration parameter changes to device 110 (¶ 0036). Smart card 120 may then push the changed application configuration parameter(s) to device 110 (block 660). The messaging diagram of FIG. 7 depicts the changed application configuration parameters 730 being supplied via smart card 120 to device 110 (¶ 0039).
Chen does not teach, however Fisher discloses:
…via near field communications (NFC);
Fisher - The invention describes how a consumer can hold their NFC enabled device in proximity to an NFC enabled point-of-sale terminal and with a single “wave” or “tap” to automatically redeem coupons, pay for a purchase using a default payment card or a selected card, view receipts view reward point balances, and receive relevant coupons and other digital artifacts both before and after the purchase. The NFC enabled device includes a secure element with a payment application, payment credentials, and other digital artifacts such as coupons. The secure element can be internal to the mobile device, externally affixed to the mobile device, or inserted into a slot within the body of the mobile device (Abstract).
then providing by the payment card the access data to the user device via near field communications (NFC),
Fisher - The invention describes how a consumer can hold their NFC enabled device in proximity to an NFC enabled point-of-sale terminal and with a single “wave” or “tap” to automatically redeem coupons, pay for a purchase using a default payment card or a selected card, view receipts view reward point balances, and receive relevant coupons and other digital artifacts both before and after the purchase. The NFC enabled device includes a secure element with a payment application, payment credentials, and other digital artifacts such as coupons. The secure element can be internal to the mobile device, externally affixed to the mobile device, or inserted into a slot within the body of the mobile device (Abstract).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the device binding comparison of Chen with the security of the mobile payment environment of Fisher because doing so the payment credentials are only released or used when the payment card/secure element determines that the mobile device corresponds to stored device data.
Regarding Claim 9. The combination of Chen and Fisher further discloses:
The payment card of claim 8, wherein the access data comprises the payment account number.
Chen - application configuration parameters (¶ 0033).
Regarding Claim 10. The combination of Chen and Fisher further discloses:
The payment card of claim 8, wherein the payment card is a credit card.
Chen - Smart cards typically consist of pocket-sized, or smaller, cards with embedded integrated circuits (¶ 0001). Device 110 may include any type of communication device that uses a Universal Integrated Circuit Card (UICC)-based SIM for authentication and application enabling. Device 110 may include, for example, a cellular radiotelephone, a smart phone, a personal digital assistant (PDA (¶ 0013). Smart card 120 may include any type of smart card usable for inserting in device 110 and for storing information or data relevant to the operation of device 110. Smart card 120 may, for example, include a Universal Integrated Circuit Card (UICC), a removable user identity card (R-UIM), a SIM, a USIM, or an ISIM (¶ 0014).
Regarding Claim 11. The combination of Chen and Fisher further discloses:
The payment card of claim 8, wherein the user device is a mobile phone.
Chen - Device 110 may include, for example, a cellular radiotelephone, a smart phone, a personal digital assistant (PDA) (¶ 0013).
Regarding Claim 12. The combination of Chen and Fisher further discloses:
The portable device of claim 8, further comprising a contactless element coupled to the processor, and the contactless element is configured to communicate using NFC (near field communications).
Fisher - communicate wired and/or wirelessly with any other suitable computing device over any suitable computing network (¶ 0126 The invention describes how a consumer can hold their NFC enabled device in proximity to an NFC enabled point-of-sale terminal and with a single “wave” or “tap” to automatically redeem coupons, pay for a purchase using a default payment card or a selected card, view receipts view reward point balances, and receive relevant coupons and other digital artifacts both before and after the purchase. The NFC enabled device includes a secure element with a payment application, payment credentials, and other digital artifacts such as coupons. The secure element can be internal to the mobile device, externally affixed to the mobile device, or inserted into a slot within the body of the mobile device (Abstract).
Therefore, it would have been obvious to one of ordinary skilled of the art before the effective filing date of the claimed invention to modify the restricting a card of Chen with the NFC of Fisher because doing so protects the cards credentials so that a stolen secure element or cloned card can’t simply be used and to bind the card to a specific phone before allowing transaction.
Regarding Claim 13. The combination of Chen and Fisher further discloses:
The payment card of claim 8, wherein the payment card is a card with the access data embossed on the payment card.
Chen Smart cards typically consist of pocket-sized, or smaller, cards with embedded integrated circuits (¶ 0001).
Regarding Claim 21. The combination of Chen and Fisher further discloses:
The method of claim 1, wherein the user device comprising an SDK (software development kit), which can perform verification of the user device.
Chen - OMA DM OTA server 140 may include a server entity that may implement the OMA DM device management protocol for managing devices, such as for example, mobile phones, PDAs and palm top computers. OMA DM OTA server 140 may configure the devices, including device 110, by supplying application parameters used in the operation of the devices, may enable and disable features of the devices, and may change settings of the devices. OMA DM OTA server 140 may also provide software upgrades to the devices, and may provide fault management of the devices (e.g., report errors from the devices, etc.). In embodiments described herein (i.e., the exemplary embodiment described with respect to FIGS. 4A & 4B below), OMA DM OTA server 140 may send application configuration parameter changes to device 110 (¶ 0016).
Regarding Claim 22. The combination of Chen and Fisher further discloses:
The method of claim 1, wherein the first user device data comprises a user device identifier that is stored when the payment card is being manufactured.
Chen - OMA DM OTA server 140 may include a server entity that may implement the OMA DM device management protocol for managing devices, such as for example, mobile phones, PDAs and palm top computers. OMA DM OTA server 140 may configure the devices, including device 110, by supplying application parameters used in the operation of the devices, may enable and disable features of the devices, and may change settings of the devices. OMA DM OTA server 140 may also provide software upgrades to the devices, and may provide fault management of the devices (e.g., report errors from the devices, etc.). In embodiments described herein (i.e., the exemplary embodiment described with respect to FIGS. 4A & 4B below), OMA DM OTA server 140 may send application configuration parameter changes to device 110 (¶ 0016).
Regarding Claim 23. The combination of Chen and Fisher further discloses:
The method of claim 1, wherein the first user device data comprises a user device identifier that is stored after the payment card is manufactured.
Chen - Exemplary embodiments described herein employ a smart card inserted into a device (e.g., into a mobile telephone) to drive configuration changes associated with the operation of the mobile device. Such configuration changes may include changes in Access Point Names (APNs), Network Access Identifiers (NAIs), Multi-Media Messaging Service (MMS) information, Wireless Application Protocol (WAP) information, application keys, and other data associated with the operation of the mobile device (¶ 0011). OMA DM OTA server 140 may configure the devices, including device 110, by supplying application parameters used in the operation of the devices, may enable and disable features of the devices (¶ 0016). Network 150 may include one or more networks of any type, such as, for example, a telecommunications network…and internet (¶ 0016). FIG. 6 is a flow diagram illustrating an exemplary process for implementing smart card driven device configuration changes where smart card 120, instead of an OTA server, stores and supplies the application configuration parameter changes to device 110 (¶ 0036). Smart card 120 may then push the changed application configuration parameter(s) to device 110 (block 660). The messaging diagram of FIG. 7 depicts the changed application configuration parameters 730 being supplied via smart card 120 to device 110 (¶ 0039).
Regarding Claim 24. The combination of Chen and Fisher further discloses:
The method of claim 1, wherein the second user device data is received by the payment card in a get processing options command from the user device.
Chen - Exemplary embodiments described herein employ a smart card inserted into a device (e.g., into a mobile telephone) to drive configuration changes associated with the operation of the mobile device. Such configuration changes may include changes in Access Point Names (APNs), Network Access Identifiers (NAIs), Multi-Media Messaging Service (MMS) information, Wireless Application Protocol (WAP) information, application keys, and other data associated with the operation of the mobile device (¶ 0011). OMA DM OTA server 140 may configure the devices, including device 110, by supplying application parameters used in the operation of the devices, may enable and disable features of the devices (¶ 0016). Network 150 may include one or more networks of any type, such as, for example, a telecommunications network…and internet (¶ 0016). FIG. 6 is a flow diagram illustrating an exemplary process for implementing smart card driven device configuration changes where smart card 120, instead of an OTA server, stores and supplies the application configuration parameter changes to device 110 (¶ 0036). Smart card 120 may then push the changed application configuration parameter(s) to device 110 (block 660). The messaging diagram of FIG. 7 depicts the changed application configuration parameters 730 being supplied via smart card 120 to device 110 (¶ 0039).
Regarding Claim 25. The combination of Chen and Fisher further discloses:
The method of claim 1, wherein the user device and the payment card are specifically associated with a user.
Chen - Exemplary embodiments described herein employ a smart card inserted into a device (e.g., into a mobile telephone) to drive configuration changes associated with the operation of the mobile device. Such configuration changes may include changes in Access Point Names (APNs), Network Access Identifiers (NAIs), Multi-Media Messaging Service (MMS) information, Wireless Application Protocol (WAP) information, application keys, and other data associated with the operation of the mobile device (¶ 0011). OMA DM OTA server 140 may configure the devices, including device 110, by supplying application parameters used in the operation of the devices, may enable and disable features of the devices (¶ 0016). Network 150 may include one or more networks of any type, such as, for example, a telecommunications network…and internet (¶ 0016). FIG. 6 is a flow diagram illustrating an exemplary process for implementing smart card driven device configuration changes where smart card 120, instead of an OTA server, stores and supplies the application configuration parameter changes to device 110 (¶ 0036). Smart card 120 may then push the changed application configuration parameter(s) to device 110 (block 660). The messaging diagram of FIG. 7 depicts the changed application configuration parameters 730 being supplied via smart card 120 to device 110 (¶ 0039).
Claim(s) 4, 5, and 6 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen, in view of Fisher, and in further view of Guertler et al. (US20170208464A1) hereinafter Guertler.
Regarding Claim 4. Chen teaches in (BOLD):
The method of claim 1, wherein the user device data is a digital signature, and wherein the method further comprises verifying the digital signature using a cryptographic key.
Chen- stored in device 110 (¶ 0030).
Chen does not teach, however Guertler discloses (in BOLD):
The method of claim 1, wherein the user device data is a digital signature, and wherein the method further comprises verifying the digital signature using a cryptographic key.
Guertler - signs the transaction identifier using the private key and transmits the signed transaction identifier back to the authentication service, and the authentication service verifies the signature of the signed transaction identifier and, in the case of the presence of an authentic signature, transmits a confirmation of the query back to the application (Abstract).
Therefore, it would have been obvious to one of ordinary skilled of the art before the effective filing date of the claimed invention to modify the sensitive configuration/access data on a smart card of Chen with the digital signature of Guertler because doing so improves the security of the authentication between a phone and remote servers.
Regarding Claim 5. The combination of Chen and Fisher further discloses:
The method of claim 4, wherein the second user device is a phone.
Chen - Smart cards typically consist of pocket-sized, or smaller, cards with embedded integrated circuits (¶ 0001). Device 110 may include any type of communication device that uses a Universal Integrated Circuit Card (UICC)-based SIM for authentication and application enabling. Device 110 may include, for example, a cellular radiotelephone, a smart phone, a personal digital assistant (PDA (¶ 0013). Smart card 120 may include any type of smart card usable for inserting in device 110 and for storing information or data relevant to the operation of device 110. Smart card 120 may, for example, include a Universal Integrated Circuit Card (UICC), a removable user identity card (R-UIM), a SIM, a USIM, or an ISIM (¶ 0014).
Regarding Claim 6. Chen teaches in (BOLD):
The method of claim 5, wherein the card is a driver’s license, a payment card, or government issued ID card.
Chen - smart card 120 (¶ 0030).
Chen does not teach, however Guertler discloses (in BOLD):
The method of claim 5, wherein the card is a driver’s license, a payment card, or government issued ID card.
Guertler - in which credit card transactions can be confirmed or approved in real time via a mobile terminal (¶ 0005).
Therefore, it would have been obvious to one of ordinary skilled of the art before the effective filing date of the claimed invention to modify the sensitive configuration/access data on a smart card of Chen with the digital signature of Guertler because doing so improves the security of the authentication between a phone and remote servers.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Adam - (US20130145440A1) - Described herein are techniques for regulating access to a remote resource using two-factor authentication based on information regarding a host machine of a portable storage drive that stores an operating system that is booted by the host machine. The information regarding the host machine of a portable storage drive may be used as a second factor in a two-factor authentication. Such information regarding the host machine may include, in some embodiments, information retrieved from a secure storage of the host machine, such as from a cryptoprocessor of the host machine. The information may include an identifier for the host machine or may be a user credential pre-provisioned to the host machine to be used in two-factor authentication.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTINA C whose telephone number is (571)270-7280. The examiner can normally be reached on Monday-Friday from 8am to 5pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Patrick , can be reached at telephone number 571-272-7575. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center. Status information for published applications may be obtained from Patent Center. Status information for unpublished applications is available through Patent Center for authorized users only. Should you have questions about access to Patent Center, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/uspto-automated- interview-request-air-form.
/C.C.S./Examiner, Art Unit 3698
/PATRICK MCATEE/Supervisory Patent Examiner, Art Unit 3698