DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed on 06/17/2026 have been fully considered but they are not persuasive.
With respect to U.S.C. 101 rejection, Applicant is of the opinion that claims do not recite commercial or legal interactions. Claims are directed to a practical application because claim recites physically alters the state of the access control system which improve process of accessing restricted physical space. Claims perform claimed functions in a multi-issuer environment. The systems discussed differ from previous solution because they provide a single platform for multiple issuers. Claims include significantly more than any alleged abstract idea. However, Examiner respectfully disagrees.
The claims are directed to performing access control which is an abstract idea. The claims involve a series of steps receiving credentials, determining based on credentials user account is authorized, determining geographic location and transmitting command to open the door based on geographic location within predefined distance and user account is authorized which grouped within “certain methods of organizing human activity” and deals with commercial or legal interactions such as determining visitors’ credentials before granting entry.
Applicant is of the opinion that claims physical alters the access control system therefore integrates the exception into practical application. This reasoning proves too much, nearly every automated abstract idea claim has some real-world consequence for example a payment is authorized, a record is updated, a door unlocks. The relevant question under Prong Two is not whether the claim produces a physical or tangible outcome, but whether the means of producing that outcome reflects a technical improvement. Here the claims recite receiving credentials, determining based on credentials user account is authorized, determining geographic location and transmitting command to open the door based on geographic location within predefined distance and user account is authorized. This is the automation of a security/access-control practice such as verifying a visitor’s credentials and confirming they are physically present at the correct location before granting entry, the same function performed by a security guard checking an ID and confirming the person is standing at the right door. Further, sending a control signal to alter the state of the access control system is functional, result oriented language, not a technical mechanism. The claim does not recite any specific signal format, encoding, authentication handshake between the mobile device and the control circuit, or any particular way the control circuit processes the signal differently from a conventional remote-actuation receiver. Likewise, routing encrypted data to an issuer server based on an included identifier to support “a plurality of issuers” reflects a business arrangement for commercial interoperability among card issuers, implemented using conventional identifier-based message routing, and does not reflect a technical improvement.
Viewed as a whole, the combination of elements recited in the claims merely recite the concept of storing data and performing access control. Therefore, the use of these additional elements does no more than employ the computer as a tool to automate and/or implement the abstract idea. The use of a computer or processor to merely automate and/or implement the abstract idea cannot provide significantly more than the abstract idea itself (MPEP 2106.05(I)(A)(f) & (h)).
Therefore, the rejection is maintained.
With respect to U.S. C. 103 arguments have been considered but are moot in view of the new ground of rejection.
Status of Claims
Claims 1, 3-4, 7-8, 10 and 14-26 have been examined.
Claims 2, 5-6, 9 and 11-13 have been canceled by the Applicant.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1, 3-4, 7-8, 10 and 14-26 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more.
In the instance case, claims 1,3-4, 7 and 21-25 are directed to a method, claims 8,10, 14 and 26 are directed to an apparatus and claims 15-20 are directed to a non-transitory computer-readable medium. Therefore, these claims fall within the four statutory categories of invention.
The claims are directed to performing access control which is an abstract idea. Specifically, the claims recite “receiving an identifier and encrypted data…; determining based on the encrypted data…; determining…a geographic location….; in response to the user account being authorized…and the geographic location…within predefined distance…” which grouped within the “certain methods of organizing human activity” grouping of abstract ideas in prong one of step 2A of the Alice/Mayo test (See MPEP 2106) because the claims involve a series of steps receiving credentials, determining based on credentials user account is authorized, determining geographic location and transmitting command to open the door based on geographic location within predefined distance and user account is authorized which is a process that deals with commercial or legal interactions. Accordingly, the claims recite an abstract idea (MPEP 2106).
This judicial exception is not integrated into a practical application because, when analyzed under prong two of step 2A of the Alice/Mayo test (See MPEP 2106), the additional elements of the claims such as, mobile device, access control system, authentication system, processor, memory and non-transitory computer-readable medium merely use a computer as a tool to perform an abstract idea. Specifically, mobile device, access control system, authentication system, processor, memory and non-transitory computer-readable medium perform the steps of receiving credentials, determining based on credentials user account is authorized, determining geographic location and transmitting command to open the door based on geographic location within predefined distance and user account is authorized. The use of a processor/computer as a tool to implement the abstract idea does not integrate the abstract idea into a practical application because it requires no more than a computer performing functions that correspond to acts required to carry out the abstract idea. The additional elements do not involve improvements to the functioning of a computer, or to any other technology or technical field (MPEP 2106.05(a)), the claims do not apply or use the abstract idea to effect a particular treatment or prophylaxis for a disease or medical condition (Vanda Memo), the claims do not apply the abstract idea with, or by use of, a particular machine (MPEP 2106.05(b)), the claims do not effect a transformation or reduction of a particular article to a different state or thing (MPEP 2106.05(c)), and the claims do not apply or use the abstract idea in some other meaningful way beyond generally linking the use of the abstract idea to a particular technological environment, such that the claim as a whole is more than a drafting effort designed to monopolize the exception (MPEP 2106.05(e) and Vanda Memo). Therefore, the claims do not, for example, purport to improve the functioning of a computer. Nor do they effect an improvement in any other technology or technical field. Accordingly, the additional elements do not impose any meaningful limits on practicing the abstract idea, and the claims are directed to an abstract idea.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because, when analyzed under step 2B of the Alice/Mayo test (MPEP 2106), the additional elements such as mobile device, access control system, authentication system, processor, memory and non-transitory computer-readable medium, to perform the steps amounts to no more than using a computer or processor to automate and/or implement the abstract idea of performing access control. As discussed above, taking the claim elements separately, mobile device, access control system, authentication system, processor, memory and non-transitory computer-readable medium perform the steps of receiving credentials, determining based on credentials user account is authorized, determining geographic location and transmitting command to open the door based on geographic location within predefined distance and user account is authorized. These functions correspond to the actions required to perform the abstract idea. Viewed as a whole, the combination of elements recited in the claims merely recite the concept of storing data and performing access control. Therefore, the use of these additional elements does no more than employ the computer as a tool to automate and/or implement the abstract idea. The use of a computer or processor to merely automate and/or implement the abstract idea cannot provide significantly more than the abstract idea itself (MPEP 2106.05(I)(A)(f) & (h)). Therefore, the claim is not patent eligible.
Dependent claims further describe the abstract idea of performing access control. Specifically, claims 3-4, 10 and 17-18 describing the authentication which is part of the abstract idea of access control. Claims 7, 14 and 20 are describing additional elements that merely use a computer as a tool to perform an abstract idea. Claim 21 recite receiving the data by utilizing additional element of NFC that merely use a computer as a tool to perform an abstract idea. Claim 22 recites additional element. Claim 23 and 26 recite receiving and outputting notification which is part of the abstract idea. Claim 24 recite determining a data which is part of the abstract idea. Claim 25 further describing the data i.e. unique identifier, which is part of the abstract idea. The dependent claims do not include additional elements that integrate the abstract idea into a practical application or that provide significantly more than the abstract idea. Therefore, the dependent claims are also not patent eligible.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-4, 7-10 and 14-24 are rejected under 35 U.S.C. 103 as being unpatentable over Cordiner (US 20170154483) in view of BOWERS (US 20230020843) in further view of Noe (US 20160307186).
With respect to claims 1, 8 and 15 Cordiner discloses:
receiving, by an application executing on a processor circuit of a mobile device, data associated with a user account (See paragraphs 0058);
determining, based on the data, whether the user account is authorized to alter a state of an access control system comprising: sending the received data to an authentication system associated with the user account (See paragraph 0019, 0058-0059, 0064, 0083-0085);
determining, by the mobile device, a geographic location thereof (See paragraph 0059-0060); and
in response to the user account being authorized to alter the state of the access control system and the geographic location of the mobile device being located within a predefined distance of the access control system, sending by the mobile device a control signal directly to a control circuit of the access control system to thereby alter the state of the access control system (See paragraph 0063-0065, 0067, 0070, and 0120).
Cordiner does not explicitly disclose that the data associated with a user account is encrypted and also include an identifier and received from a communications interface of a contactless card, BOWERS discloses: receiving, by an application executing on a processor circuit of a mobile device, an identifier and encrypted data from a communications interface of a contactless card associated with a user account; determining, based on the encrypted data, whether the user account is authorized (See paragraphs 0041-0043). Therefore, it would have been obvious to one of the ordinary skills in the art at the time invention was filed to modify the Cordiner reference with BOWSERS reference by adding extra security layer such as utilizing contactless card in order to authenticate a user securely and effective manner (See BOWERS paragraph 0020).
Cordiner in view of BOWERS does not explicitly disclose: sending encrypted data to an authentication system based on the received identifier and the authentication system comprising an issuer server associated with the identifier.
Noe discloses: sending encrypted data to an authentication system based on the received identifier (i.e. PAN) and the authentication system comprising an issuer server associated with the identifier (See paragraph 0037, 0076, 0084-0085). Therefore, it would have been obvious to one of the ordinary skills in the art at the time invention was filed to modify the combination of Cordiner and BOWERS references with Noe reference in order to fast routing of authentication request.
Additionally, with respect to “the authentication system comprising an issuer server associated with the identifier” this limitation does not have any patentable weight because this limitation is outside the scope of the claim.
With respect to claims 3, 10 and 16 Cordiner in view of BOWERS and in further view of Noe discloses all the limitations as described above. Cordiner further discloses: comparing, by the authentication system, the data to a list of authorized user accounts and their corresponding expected data; determining that the data matches the corresponding expected data for the user account; and sending an authorization message to the mobile device indicating that the user account is authorized to alter the state of the access control system (See paragraphs 0063-0065, 0067, 0070 and 0120). BOWERS discloses: comparing, by the authentication system, the encrypted data to a list of authorized user accounts and their corresponding expected encrypted data; determining that the encrypted data matches the corresponding expected encrypted data for the user account; and sending an authorization message to the mobile device (See paragraphs 0043, 0056-0057).
With respect to claims 4, and 17 Cordiner in view of BOWERS and in further view of Noe discloses all the limitations as described above. Cordiner further discloses: in response to the mobile device receiving the authorization message and the mobile device confirming that the geographic location of the mobile device is within the predefined distance of the access control system, sending, by the mobile device, the control signal to the access control system to alter the state of the access control system (See paragraphs 0060, 0067, 0070 and 0120).
With respect to claims 7, 14 and 19-20 Cordiner in view of BOWERS and in further view of Noe discloses all the limitations as described above. Cordiner further discloses: wherein the access control system comprises one or more of the following: an electronic door lock, or control circuit thereof; a garage door control circuit; a locker control circuit; an automobile door or trunk control circuit; and a manufacturing facility control circuit, and wherein altering the state of the access control system includes activating, deactivating, unlocking, locking, or altering a system setting of the access control system, including a control circuit thereof. (See paragraph 0053 and 0070); Cordiner does not explicitly disclose: wherein the encrypted data is generated based on one or more cryptographic algorithms and a cryptogram session key (ASK) and unique encipherment session key (DESK), the ASK and DESK stored in a memory of the contactless card and generated based on a unique card key (UDK) and a counter value stored in the memory of the contactless card. BOWERS discloses: wherein the encrypted data is generated based on one or more cryptographic algorithms and a cryptogram session key (ASK) and unique encipherment session key (DESK), the ASK and DESK stored in a memory of the contactless card and generated based on a unique card key (UDK) and a counter value stored in the memory of the contactless card (See paragraph 0094-0095 and 0104). Therefore, it would have been obvious to one of the ordinary skills in the art at the time invention was filed to modify the Cordiner reference with BOWSERS reference in order to authenticate a user securely and effective manner (See BOWERS paragraph 0020).
With respect to claim 18 Cordiner in view of BOWERS and in further view of Noe discloses all the limitations as described above. Cordiner further discloses: determining, by the mobile device that the geographic location of the mobile device is within the predefined distance of the access control system; sending, a message to a separate computing device in communication with the access control system, the message including instructions to cause the separate computing device to send the control signal to a control circuit of the access control system to alter the state thereof. (See paragraphs 0060, 0067, 0070).
With respect to claim 21 Cordiner in view of BOWERS and in further view of Noe discloses all the limitations as described above. BROWERS discloses: wherein the communications interface of the contactless card comprises a Near Field Communication (NFC) interface, and wherein receiving the encrypted data occurs in response to the contactless card being tapped against the mobile device (See paragraphs 0041-0043). Therefore, it would have been obvious to one of the ordinary skills in the art at the time invention was filed to modify the Cordiner reference with BOWSERS reference by adding extra security layer such as utilizing contactless card in order to authenticate a user securely and effective manner (See BOWERS paragraph 0020).
With respect to claim 22 Cordiner in view of BOWERS and in further view of Noe discloses all the limitations as described above. Cordiner further discloses: wherein the control signal is sent directly to the control circuit of the access control system via a Bluetooth Low Energy (BLE) communication protocol. (See paragraph 0056, 0120 and 0142).
With respect to claim 23 Cordiner in view of BOWERS and in further view of Noe discloses all the limitations as described above. Cordiner further discloses: receiving by the mobile device from the authentication system confirmation message indicating that user account is authorized to alter the state of the access control system (See paragraph 0120).
With respect to claim 24 Cordiner in view of BOWERS in further view of Noe discloses all the limitations as described above. Cordiner further discloses: wherein determining the geographic location of the mobile device being located within a predefined distance of the access control system comprises determining a distance between the determined geographic location of the mobile device and a location of the access control system and comparing the determined distance with the predefined distance (See paragraph 0067).
With respect to claim 25 Cordiner in view of BOWERS in further view of Noe discloses all the limitations as described above. Noe further discloses: wherein the encrypted data comprises a unique identifier associated with the user account, wherein the unique identifier is used to determine whether the user account is authorized to alter the state of the access control system uses (See paragraph 0086). Therefore, it would have been obvious to one of the ordinary skills in the art at the time invention was filed to modify the combination of Cordiner and BOWERS references with Noe reference in order to fast routing of authentication request.
With respect to claim 26 Cordiner in view of BOWERS in further view of Noe discloses all the limitations as described above. Cordiner further discloses: wherein the instructions further cause the processor circuit to, in response to the user account being unauthorized to alter the state of the access control system or the geographic location of the apparatus being located outside the predefined distance of the access control system, declining to send the control signal to the access control system (See paragraph 0072 and 0121).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZESHAN QAYYUM whose telephone number is (571)270-3323. The examiner can normally be reached Monday-Friday 9:00AM-6:00PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John W Hayes can be reached at (571) 272-6708. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ZESHAN QAYYUM/Primary Examiner, Art Unit 3697