DETAILED ACTION
Acknowledgements
The amendment filed 7/16/2026 is acknowledged.
Claims 1-2, 4-12, and 14-20 are pending.
Claims 1-2, 4-12, and 14-20 have been examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 7/16/2026 has been entered.
Response to Amendment/Argument
Regarding the double patenting rejection of the claims, examiner notes that the amendments to claims 1 and 7 do not overcome the rejection, because the claims of the ‘229 Patent are obvious over Bjorn, as described in the updated double patenting rejection below.
Regarding the rejection of the claims under 35 USC 101, applicant states that examiner’s analysis evaluates the claims at a high level of abstraction and ignores the specific technological architecture.
Examiner notes that every limitation of the claim is analyzed in the rejection, and identifier as either part of the abstract idea, or as an additional element beyond the abstract idea. Specifically, the rejection identifies the limitations of “receiving . . . biometric authentication data to authenticate an account holder,” “comparing . . . the biometric authentication data with biometric data present . . . wherein the biometric data present . . . is stored securely . . . and is not accessible and never shared . . . wherein the comparing identifies a match between the biometric authentication data and the biometric data . . ., transmitting an authentication message . . . . indicating the match,” and “transmitting . . . upon the comparing identifying a match between the biometric authentication data and the biometric data . . ., and an authentication message indicating the match together with an account identifier that enables . . . to retrieve a pre-staged transaction . . .,” in claim 1, “receiving . . . biometric authentication data to authenticate an account holder,” “comparing . . . the biometric authentication data with . . . biometric data present . . . wherein the . . . biometric data present . . . is stored securely . . . and is not accessible and never shared . . .,” “wherein the comparing identifies a match between the biometric authentication data and the . . . biometric data . . . and transmits an authentication message . . . indicating the match,” and “transmitting . . . upon the comparing identifying a match between the biometric authentication data and the biometric data . . ., an authentication message indicating the match together with an account identifier that enables . . . to retrieve a pre-staged transaction . . .,” in claim 7, and “receive biometric data from . . . to obtain an authentication of the biometric data . . . wherein . . . stores biometric data securely . . . and the stored biometric data is not accessible and never shared . . .,” “transmit the biometric data . . .,” “receive an authentication message . . . when . . . identifies a match between the biometric data and stored biometric data, wherein the authentication message includes an account identifier” and “retrieve pre-staged transaction data . . . based on the account identifier upon receipt of the authentication message, where in the pre-staged transaction data was pre-staged . . . prior to . . . arriving at the system for [access] upon authentication of an account holder” in claim 18 as reciting the abstract idea, and identifies the additional elements as the use of a wireless communication device, a self-service terminal (SST), a mobile device, a mobile device application executing on the mobile device, a server, and a system comprising a biometric reading device, a wireless communication device, at least one processor, at least one memory, and the establishment of a peer-to-peer wireless connection with the mobile device via the communication interface, to perform the steps.
Applicant also states the present claims recite establishing a peer-to-peer wireless connection, performing the biometric comparison locally on the mobile device against data that is stored securely by the mobile device application and is not accessible and never shared by the mobile device application, and transmitting, upon a match, an authentication message that includes an account identifier that enables the SST to retrieve a pre-staged transaction from a server. Regarding Desjardins, applicant further states that the present claims are at least as technically specific as those in Desjardins, as the specification expressly identifies the technical problem addressed, and discloses a specific technical architecture to address this problem. Applicant states that the features of peer-to-peer connection establishment, local on-device biometric matching, and account identifier enabled pre-staged transaction retrieval parallel the type of improvement in Desjardins. Applicant further compares the claims to those in Ex Parte Kelley, and states that the claims do not merely use biometric authentication in a new environment, but recite a specific distributed architecture that improves how biometric authentication itself operates. Applicant further states that the claims specify how the interactions between the SST, mobile device, and server are structured, and the claims provide a non-conventional arrangement that provides a specific technical solution.
Examiner notes, however, that the features recited in the claim are broadly recited and do not include any technical details. For example, although the claims recite establishing a peer-to-peer wireless connection, they do not recite any technical details regarding the manner in which the connection is established. Simply establishing a peer-to-peer connection describes establishing a known type of connection between two devices to allow them to communicate. Similarly, performing the on-device biometric matching describes a broad manner of authenticating a user by comparing received information to stored information to perform a financial transaction. It does not provide any technical details regarding the manner in which these steps are performed. The fact that the biometric authentication data is received from an SST, the comparison is performed on the mobile device, and the result is transmitted to the SST, only identifies the parties or entities involved in the authentication as being devices, but does not require any improvements to the technical functionality of the mobile device or SST. Therefore, the use of these additional elements only involves using a computer as a tool to automate and/or implement the abstract idea. Further, the fact that the biometric data is stored on the mobile device by a mobile device application and is not accessible and never shared by the mobile device application also does not provide a practical application or significantly more than the abstract idea because it only describes the result of the storage of the data on the mobile device, but does not describe any technical steps or mechanism by which this result is achieved. Finally, regarding the use of a specific distributed architecture, examiner notes that claims 1 and 7 are directed to a mobile device, and claim 18 is directed to the SST. Each of these claims are directed to distinct individual devices, and neither includes a distributed architecture, nor does any claim include the SST, mobile device, and server such that it could reflect an improvement to the interaction or network between them.
Regarding the rejection of claims 1 and 7 over the prior art, applicant states Bjorn does not disclose “connecting, wirelessly via the wireless communication device, to the SST to establish a peer-to-peer wireless connection between a mobile device and the SST.” Applicant states that the wireless token of Bjorn communicates with a terminal via a short-range wireless transceiver upon receiving a “ping” from the terminal but Bjorn does not disclose establishing a peer-to-peer wireless connections between a mobile device and an SST as claimed. Examiner notes, however, that Bjorn discloses that the wireless token establishes a secure wireless connection with the terminal (See, e.g., Bjorn Figure 5, step 520; ¶¶ 21, 40, 46, 51-54, 59, 99-106). This is a peer-to-peer connection because it is a connection between two peer (i.e., the token and the terminal) and is established without the use of a separate centralized server. According to the Microsoft Computer Dictionary (Fifth Edition), “peer-to-peer communications” are defined as “[i]nteraction between devices that operate on the same communications level on a network based on a layered architecture.” (“Definition of peer-to-peer communications,” Microsoft Computer Dictionary, p. 397, Microsoft Press, Fifth Edition, 2002). Therefore, because the token and the terminal communicate directly on the same level via a wireless connection, the connection in Bjorn reads on a peer-to-peer wireless connection.
Further, regarding the limitation that “the biometric data present on the mobile device is stored securely by a mobile device app executing on the mobile device and is not accessible and never shared by the mobile device app,” applicant states that paragraph 40 of Bjorn does not disclose this feature because Bjorn’s wireless token is not a mobile device executing a mobile device application. Examiner notes, however, that Bjorn discloses this feature as it discloses that the biometric data is stored on a secure memory that can only be accessed by a cryptographic co-processor. Thus, the biometric data is not accessible and can never be shared. Further, examiner notes that Bjorn states that the functionality described in the reference may be performed by software executed by a processor (See, e.g., ¶ 34). Thus, Bjorn discloses a mobile device application.
Applicant additionally states that the combination of Bjorn and Treadwell does not yield the integrated system that includes the features of establishing a peer-to-peer wireless connection with the mobile device, transmitting biometric data to the mobile device over that connection, receiving an authentication message including an account identifier from the mobile device when the mobile device identifies a match, and retrieving pre-staged transaction data from a server based on the account identifier. Applicant states that this is because In Bjorn, the wireless token receives biometric data from the terminal and performs matching on the token, while in Treadwell authentication is not performed by a mobile device receiving biometric data from the ATM.
Examiner notes, however, that Treadwell discloses pre-staging a transaction to a server from a mobile device app prior to arriving at the SST, and the SST then retrieving this pre-staged transaction upon authentication, and specifically using a mobile device application to pre-stage the transaction, and the pre-staging occurring prior to the mobile device arriving at the system, because Treadwell discloses that a customer logs in to an online banking system from their device (which may be a mobile terminal, see e.g. Treadwell ¶ 20) to initiate an ATM transaction, inputs ATM transaction information, the online banking system stores the pending ATM transaction in a banking system queue, and then after the user travels to an ATM, the user is authenticated at the ATM and the ATM queries the banking system queue to retrieve the stored pre-staged transaction and process it (See, e.g., Treadwell ¶¶ 24-26, 29-34). Although Treadwell does not specifically disclose that the mobile device performs biometric authentication when arriving at a terminal, Bjorn discloses this feature as discussed in relation to the 103 rejection. Therefore, the combination of the teachings of Bjorn and Treadwell render the claimed features obvious.
Additionally, applicant states that there is no motivation to combine Treadwell with Bjorn because the combination would require a modification of the fundamental operation of both references and a fundamental restructuring of both systems.
Examiner notes, however, that Bjorn discloses that the biometric authentication is used to provide the terminal with access to account information. Integrating this with Treadwell’s pre-staging functionality would only involve the information that is accessed being used to retrieve pre-staged transaction information on the server. Because either Bjorn or Treadwell disclose these features and one of ordinary skill would have been motivated to combine these references in order to allow an ATM to access multiple queued transactions prepared by a user when the user arrives at the ATM, and allow the user to select which ones to complete (Treadwell ¶¶ 32-33), the modifications would have been obvious to one of ordinary skill.
Additionally, applicant states that the specification discloses pre-staging a transaction prior to the customer arriving at the SST, and the mobile device app transmitting back to the SST via the previously established wireless connection, data identifying the match and an account identifier that enables the SST to retrieve the pre-staged transaction from the server where it is stored. Applicant states that the references do not disclose this integrated workflow where pre-staging occurs on one wireless channel, and then authenticating occurs via a peer-to-peer connection.
In response to applicant's argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., the manner in which the transaction is pre-staged one wireless channel prior to the customer arriving at the SST) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993).
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-2, 4-12, and 14-17 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-5 of U.S. Patent No. 12,217,229 (‘229 Patent) in view of Bjorn (US 2007/0198848).
As shown in the table below, the claims of the ‘229 Patent include all the limitations of the claims of the present application, but do not specifically recite that the wireless connection is a “peer-to-peer” wireless connection.
Bjorn discloses a wireless peer-to-peer connection (Bjorn Figure 5, step 520; ¶¶ 21, 40, 46, 51-54, 59, 99-106).
Therefore, it would have been obvious to one of ordinary skill to modify the method of claim 1 of the ‘229 Patent to include a wireless peer-to-peer connection, as disclosed in Bjorn, because claim 1 of the ‘229 Patent discloses the use of a wireless connection between the two devices, and using the known peer-to-peer wireless connection disclosed in Bjorn for the wireless connection of claim 1 of the ‘229 Patent only involves simple substitution of one known type of connection for another to yield a predictable result. (KSR International Co. v. Teleflex Inc., 82 USPQ2d 1385 (U.S. 2007))
Claims of Present Application
Language from Claims of ‘229 Patent
1. A method comprising:
receiving, via a wireless communication device from a self-service terminal (SST), biometric authentication data to authenticate an account holder;
connecting, wirelessly via the wireless communication device, to the SST to establish a wireless connection between a mobile device and the SST;
comparing, on a mobile device, the biometric authentication data with biometric data that is present on the mobile device wherein the biometric data present on the mobile device is stored securely by a mobile device application executing on the mobile device and is not accessible and never shared by the mobile device application;
wherein the comparing identifies a match between the biometric authentication data and the biometric data on the mobile device, transmitting an authentication message via the wireless communication device to the SST indicating the match; and
transmitting, via the wireless communication device to the SST over the wireless connection upon the comparing identifying a match between the biometric authentication data and the biometric data on the mobile device, an authentication message indicating the match together with an account identifier that enables the SST to retrieve a pre-staged transaction from a server.
Claim 1:
“authenticating the customer by receiving, via the second wireless communication device of the mobile device, biometric data provided by a biometric reading device of the SST to authenticate the customer as the account holder who is operating the mobile device for the purchase transaction at the SST;”
“establishing a communication link with the SST by connecting, wirelessly via a second wireless communication device to the mobile device.”
“matching, on the mobile device by the mobile device app, the received biometric data with stored biometric data of the account holder by: retrieving the stored biometric data stored on the mobile device; and comparing the received biometric data and the retrieved stored biometric data to identify a match and determining a confidence level thereof, wherein the stored biometric data stored on the mobile device is stored securely by the mobile device app and is not accessible and never shared by the mobile device app”
“finalizing the purchase transaction upon matching the received biometric data and the stored biometric data of the account holder on the mobile device, wherein finalizing further includes transmitting an authentication message via the second wireless communication device to the SST”
“finalizing the purchase transaction upon matching the received biometric data and the stored biometric data of the account holder on the mobile device, wherein finalizing further includes transmitting an authentication message via the second wireless communication device to the SST, wherein the transmitted authentication message includes an account identifier for the account, a security code or security certificate, and a transaction identifier for the purchase transaction, wherein transmitting the authentication message further causes the SST to receive, the data defining the purchase transaction from the server and causes the SST to process the data defining the purchase transaction on behalf of the customer on the SST.”
2. The method of claim 1, wherein:
the comparing of the biometric authentication data with the biometric data on the mobile device includes: retrieving mobile device biometric data stored on the mobile device; and comparing the biometric data and the mobile device biometric data to identify whether there is a match and when there is a match, determining a confidence level of the match; and
the transmitting of the authentication message to the SST includes transmitting the confidence level.
Claim 2:
From claim 1:“matching, on the mobile device by the mobile device app, the received biometric data with stored biometric data of the account holder by: retrieving the stored biometric data stored on the mobile device; and comparing the received biometric data and the retrieved stored biometric data to identify a match and determining a confidence level thereof”
From claim 2: “wherein transmitting the authentication message to the SST includes transmitting the confidence level.”
4. The method of claim 1, wherein the SST is an automated teller machine (ATM).
Claim 1: “wherein the SST is an automated teller machine”
5. The method of claim 1,
wherein the authentication message includes an account identifier of a customer account, the account identifier instructing the SST to retrieve a pre-staged transaction associated with the customer account to be completed on the SST.
Claim 1:
“wherein the transmitted authentication message includes an account identifier for the account, a security code or security certificate, and a transaction identifier for the purchase transaction, wherein transmitting the authentication message further causes the SST to receive, the data defining the purchase transaction from the server and causes the SST to process the data defining the purchase transaction on behalf of the customer on the SST”
6. The method of claim 5,
wherein the authentication message further includes security data indicating validity of the authentication message to the SST.
Claim 1:
“wherein the transmitted authentication message includes an account identifier for the account, a security code or security certificate”
7. A method comprising:
receiving, via a wireless communication device from a self-service terminal (SST), biometric authentication data to authenticate an account holder;
connecting, wirelessly via the wireless communication device, to the SST to establish a wireless connection between a mobile device and the SST;
comparing, on a mobile device, the biometric authentication data with mobile device biometric data present on the mobile device, wherein the mobile device biometric data present on the mobile device is stored securely by a mobile device application executing on the mobile device and is not accessible and never shared by the mobile device application; and
wherein the comparing identifies a match between the biometric authentication data and the mobile device biometric data on the mobile device and transmits an authentication message via the wireless communication device to the SST indicating the match; and
transmitting, via the wireless communication device to the SST over the wireless connection upon the comparing identifying a match between the biometric authentication data and the mobile device biometric data on the mobile device, an authentication message indicating the match together with an account identifier that enables the SST to retrieve a pre-staged transaction from a server.
Claim 1:
“authenticating the customer by receiving, via the second wireless communication device of the mobile device, biometric data provided by a biometric reading device of the SST to authenticate the customer as the account holder who is operating the mobile device for the purchase transaction at the SST;”
“establishing a communication link with the SST by connecting, wirelessly via a second wireless communication device to the mobile device.”
“matching, on the mobile device by the mobile device app, the received biometric data with stored biometric data of the account holder by: retrieving the stored biometric data stored on the mobile device; and comparing the received biometric data and the retrieved stored biometric data to identify a match and determining a confidence level thereof, wherein the stored biometric data stored on the mobile device is stored securely by the mobile device app and is not accessible and never shared by the mobile device app”
“finalizing the purchase transaction upon matching the received biometric data and the stored biometric data of the account holder on the mobile device, wherein finalizing further includes transmitting an authentication message via the second wireless communication device to the SST”
“finalizing the purchase transaction upon matching the received biometric data and the stored biometric data of the account holder on the mobile device, wherein finalizing further includes transmitting an authentication message via the second wireless communication device to the SST, wherein the transmitted authentication message includes an account identifier for the account, a security code or security certificate, and a transaction identifier for the purchase transaction, wherein transmitting the authentication message further causes the SST to receive, the data defining the purchase transaction from the server and causes the SST to process the data defining the purchase transaction on behalf of the customer on the SST.”
8. The method of claim 7,
wherein the authentication message includes a security code or security certificate.
Claim 1:
“wherein the transmitted authentication message includes an account identifier for the account, a security code or security certificate”
9. The method of claim 7,
wherein comparing the biometric authentication data includes determining a confidence level of the match.
Claim 1:
“comparing the received biometric data and the retrieved stored biometric data to identify a match and determining a confidence level thereof”
11. The method of claim 7,
wherein the authentication message enables retrieval of a pre-staged transaction from a server.
Claim 1:
“wherein the transmitted authentication message includes an account identifier for the account, a security code or security certificate, and a transaction identifier for the purchase transaction, wherein transmitting the authentication message further causes the SST to receive, the data defining the purchase transaction from the server and causes the SST to process the data defining the purchase transaction on behalf of the customer on the SST”
12.The method of claim 7,
wherein the wireless communication device is one of a Wi-Fi data communication device, a BLUETOOTH® communication device, and a Near Field Communication (NFC) device.
Claim 5:
“the first wireless communication device is one of a mobile wireless radio data communication device and a Wi-Fi data communication device of the mobile device; and the second wireless communication device is one of the Wi-Fi data communication device, a BLUETOOTH® communication device, and a Near Field Communication (NFC) device of the mobile device.”
14. The method of claim 7,
wherein the SST is an automated teller machine (ATM).
Claim 1:
“wherein the SST is an automated teller machine”
15. The method of claim 7,
wherein the authentication message includes an account identifier instructing the SST to retrieve a pre-staged transaction.
Claim 1:
“wherein the transmitted authentication message includes an account identifier for the account, a security code or security certificate, and a transaction identifier for the purchase transaction, wherein transmitting the authentication message further causes the SST to receive, the data defining the purchase transaction from the server and causes the SST to process the data defining the purchase transaction on behalf of the customer on the SST”
16. The method of claim 7,
wherein comparing the biometric authentication data includes retrieving mobile device biometric data from the mobile device.
Claim 1:
“matching, on the mobile device by the mobile device app, the received biometric data with stored biometric data of the account holder by: retrieving the stored biometric data stored on the mobile device; and comparing the received biometric data and the retrieved stored biometric data to identify a match and determining a confidence level thereof”
17. The method of claim 7 further comprising
flushing a secure memory of the mobile device biometric data on the SST upon completion of authentication.
Claim 1:
“flushing a secure memory of the biometric data on the SST upon completion of authentication ensuring the biometric data of the customer is not stored or compromised on the SST.”
Regarding claim 10, claim 1 of ‘229 Patent in view of Bjorn renders obvious discloses all the limitations of claim 7, on which claim 10 depends, as shown above.
The claims of the ‘229 Patent do not specifically disclose that the biometric authentication data includes at least one of fingerprint data, retina scan data, and facial recognition data.
Bjorn further discloses that the biometric authentication data includes at least one of fingerprint data, retina scan data, and facial recognition data (Bjorn ¶¶ 18, 31, 64).
Therefore, it would have been obvious to one of ordinary skill to further modify the method of claim 1 of the ‘229 Patent to include authentication data that includes at least one of fingerprint data, retina scan data, and facial recognition data, as disclosed in Bjorn, because claim 1 of the ‘229 Patent discloses that the authentication data is biometric data, and using at least one of fingerprint data, retina scan data, and facial recognition data as disclosed in Bjorn for the biometric data of claim 1 of the ‘229 Patent only involves simple substitution of one known type of biometric data for another to yield a predictable result. (KSR International Co. v. Teleflex Inc., 82 USPQ2d 1385 (U.S. 2007))
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1, 2, 4-12, 14-16 and 18-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
In the instant case, claims 1, 2, 4-12, and 14-16 are directed to a method and claims 18-20 are directed to a system comprising biometric reading device, a wireless communication interface, at least one processor, and at least one memory. Therefore, these claims fall within the four statutory categories of invention.
The claims recite authenticating a user for a transaction using pre-staged transaction information by comparing received identification information of the user with stored identification information and outputting the result along with account information, which is an abstract idea. Specifically, the claims recite “receiving . . . biometric authentication data to authenticate an account holder,” “comparing . . . the biometric authentication data with biometric data present . . . wherein the biometric data present . . . is stored securely . . . and is not accessible and never shared . . . wherein the comparing identifies a match between the biometric authentication data and the biometric data . . ., transmitting an authentication message . . . . indicating the match,” and “transmitting . . . upon the comparing identifying a match between the biometric authentication data and the biometric data . . ., and an authentication message indicating the match together with an account identifier that enables . . . to retrieve a pre-staged transaction . . .,” in claim 1, “receiving . . . biometric authentication data to authenticate an account holder,” “comparing . . . the biometric authentication data with . . . biometric data present . . . wherein the . . . biometric data present . . . is stored securely . . . and is not accessible and never shared . . .,” “wherein the comparing identifies a match between the biometric authentication data and the . . . biometric data . . . and transmits an authentication message . . . indicating the match,” and “transmitting . . . upon the comparing identifying a match between the biometric authentication data and the biometric data . . ., an authentication message indicating the match together with an account identifier that enables . . . to retrieve a pre-staged transaction . . .,” in claim 7, and “receive biometric data from . . . to obtain an authentication of the biometric data . . . wherein . . . stores biometric data securely . . . and the stored biometric data is not accessible and never shared . . .,” “transmit the biometric data . . .,” “receive an authentication message . . . when . . . identifies a match between the biometric data and stored biometric data, wherein the authentication message includes an account identifier” and “retrieve pre-staged transaction data . . . based on the account identifier upon receipt of the authentication message, where in the pre-staged transaction data was pre-staged . . . prior to . . . arriving at the system for [access] upon authentication of an account holder” in claim 18, which is grouped within the “certain methods of organizing human activity” grouping of abstract ideas in prong one of step 2A of the Alice/Mayo test (MPEP 2106.04 & 2106.04(a)) because the claims describe a process for authenticating the identity of a user for a financial transaction by obtaining a user’s identifying information, sending it to an entity that compares it to stored information which is protected, receiving back an indication that the user is authenticated based on the comparison along with account information, and obtaining pre-staged transaction information, which is a commercial or legal interaction. Accordingly, the claims recite an abstract idea (See MPEP 2106.04(a)).
This judicial exception is not integrated into a practical application because, when analyzed under prong two of step 2A of the Alice/Mayo test (See MPEP 2106.04(d)), the additional element of the claims such as the use of a wireless communication device, a self-service terminal (SST), a mobile device, a mobile device application executing on the mobile device, a server, and a system comprising a biometric reading device, a wireless communication device, at least one processor, at least one memory, and establishing a peer-to-peer wireless connection with the mobile device via the communication interface, to perform the steps, merely use a computer as a tool to perform an abstract idea. Specifically, these additional elements perform the steps or functions of “receiving . . . biometric authentication data to authenticate an account holder,” “comparing . . . the biometric authentication data with biometric data present . . . wherein the biometric data present . . . is stored securely . . . and is not accessible and never shared . . . wherein the comparing identifies a match between the biometric authentication data and the biometric data . . ., transmitting an authentication message . . . . indicating the match,” and “transmitting . . . upon the comparing identifying a match between the biometric authentication data and the biometric data . . ., and an authentication message indicating the match together with an account identifier that enables . . . to retrieve a pre-staged transaction . . .,” in claim 1, “receiving . . . biometric authentication data to authenticate an account holder,” “comparing . . . the biometric authentication data with . . . biometric data present . . . wherein the . . . biometric data present . . . is stored securely . . . and is not accessible and never shared . . .,” “wherein the comparing identifies a match between the biometric authentication data and the . . . biometric data . . . and transmits an authentication message . . . indicating the match,” and “transmitting . . . upon the comparing identifying a match between the biometric authentication data and the biometric data . . ., an authentication message indicating the match together with an account identifier that enables . . . to retrieve a pre-staged transaction . . .,” in claim 7, and “receive biometric data from . . . to obtain an authentication of the biometric data . . . wherein . . . stores biometric data securely . . . and the stored biometric data is not accessible and never shared . . .,” “transmit the biometric data . . .,” “receive an authentication message . . . when . . . identifies a match between the biometric data and stored biometric data, wherein the authentication message includes an account identifier” and “retrieve pre-staged transaction data . . . based on the account identifier upon receipt of the authentication message, where in the pre-staged transaction data was pre-staged . . . prior to . . . arriving at the system for [access] upon authentication of an account holder” in claim 18. Viewed as a whole, the use of a processor/computer as a tool to implement the abstract idea does not integrate the abstract idea into a practical application because it requires no more than a computer performing functions that correspond to acts required to carry out the abstract idea. The additional elements do not involve improvements to the functioning of a computer, or to any other technology or technical field (MPEP 2106.05(a)), and the claims do not apply or use the abstract idea in some other meaningful way beyond generally linking the use of the abstract idea to a particular technological environment, such that the claim as a whole is more than a drafting effort designed to monopolize the exception (MPEP 2106.05(e) and Vanda Memo). Therefore, the claims do not, for example, purport to improve the functioning of a computer. Nor do they effect an improvement in any other technology or technical field. Accordingly, the additional elements do not impose any meaningful limits on practicing the abstract idea, and the claims are directed to an abstract idea.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because, when analyzed under step 2B of the Alice/Mayo test (See MPEP 2106.05), the additional elements of using a wireless communication device, a self-service terminal (SST), a mobile device, a mobile device application executing on the mobile device, a server, and a system comprising a biometric reading device, a wireless communication device, at least one processor, at least one memory, and establishing a peer-to-peer wireless connection with the mobile device via the communication interface to perform the steps amounts to no more than using a computer or processor to automate and/or implement the abstract idea of authenticating a user for a transaction using pre-staged transaction information by comparing received identification information of the user with stored identification information and outputting the result along with account information. As discussed above, taking the claim elements separately, these additional elements perform the steps or functions of “receiving . . . biometric authentication data to authenticate an account holder,” “comparing . . . the biometric authentication data with biometric data present . . . wherein the biometric data present . . . is stored securely . . . and is not accessible and never shared . . . wherein the comparing identifies a match between the biometric authentication data and the biometric data . . ., transmitting an authentication message . . . . indicating the match,” and “transmitting . . . upon the comparing identifying a match between the biometric authentication data and the biometric data . . ., and an authentication message indicating the match together with an account identifier that enables . . . to retrieve a pre-staged transaction . . .,” in claim 1, “receiving . . . biometric authentication data to authenticate an account holder,” “comparing . . . the biometric authentication data with . . . biometric data present . . . wherein the . . . biometric data present . . . is stored securely . . . and is not accessible and never shared . . .,” “wherein the comparing identifies a match between the biometric authentication data and the . . . biometric data . . . and transmits an authentication message . . . indicating the match,” and “transmitting . . . upon the comparing identifying a match between the biometric authentication data and the biometric data . . ., an authentication message indicating the match together with an account identifier that enables . . . to retrieve a pre-staged transaction . . .,” in claim 7, and “receive biometric data from . . . to obtain an authentication of the biometric data . . . wherein . . . stores biometric data securely . . . and the stored biometric data is not accessible and never shared . . .,” “transmit the biometric data . . .,” “receive an authentication message . . . when . . . identifies a match between the biometric data and stored biometric data, wherein the authentication message includes an account identifier” and “retrieve pre-staged transaction data . . . based on the account identifier upon receipt of the authentication message, where in the pre-staged transaction data was pre-staged . . . prior to . . . arriving at the system for [access] upon authentication of an account holder” in claim 18. These functions correspond to the actions required to perform the abstract idea. Viewed as a whole, the combination of elements recited in the claims merely recite the concept of authenticating a user for a transaction using pre-staged transaction information by comparing received identification information of the user with stored identification information and outputting the result along with account information. Therefore, the use of these additional elements does no more than employ the computer as a tool to automate and/or implement the abstract idea. The use of a computer or processor to merely automate and/or implement the abstract idea cannot provide significantly more than the abstract idea itself (MPEP 2106.05 (f) & (h)). Therefore, the claim is not patent eligible.
Dependent claims 2, 4-6, 8-12, 14-16, and 19-20 further describe the abstract idea of authenticating a user for a transaction using pre-staged transaction information by comparing received identification information of the user with stored identification information and outputting the result along with account information. Specifically, claims 2, 9, and 16 further describe the comparison of the biometric or identification information, which is part of the abstract idea. Claims 4 and 14 describe the SST, but do not require any steps or functions to be performed beyond those involved in the abstract idea. Claims 5-6, 8, 10-11, 15, and 19 describe data included in the authentication message or the data that the authentication data is comprised of, but do not require any steps or functions to be performed beyond those involved in the abstract idea. Claims 12 and 20 the wireless communication device, but do not require any steps or functions to be performed beyond those involved in the abstract idea. The dependent claims do not include additional elements that integrate the abstract idea into a practical application or that provide significantly more than the abstract idea. Therefore, the dependent claims are also not patent eligible.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-2, 4-12, and 14-17 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Claim 1 recites “wherein the comparing identifies a match between the biometric authentication data and the biometric data on the mobile device, transmitting an authentication message via the wireless communication device to the SST indicating the match,” and then recites “transmitting, via the wireless communication device to the SST over the peer-to-peer wireless connection upon the comparing identifying a match between the biometric authentication data and the biometric data on the mobile device, an authentication message indicating the match together with an account identifier that enables the SST to retrieve a pre-staged transaction from a server.” Claim 7 recites similar limitations. These limitations require transmitting an authentication message to the SST twice. However, the specification only discloses sending a single authentication message (See, e.g., Specification ¶¶ 18, 22-26, 29-30). Therefore, the specification does not provide support for both of these limitations.
Claims 2, 4-6, 8-12, and 14-17 are also rejected as each depends on either claim 1 or 7.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-2, 4-12, and 14-17 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 1 recites “connecting . . . to the SST to establish a . . . connection between a mobile device . . .,” and “comparing, on a mobile device, the biometric authentication data . . .,” and claim 7 recites similar limitations. It is unclear whether each reference to “a mobile device” refers to the same mobile device or to different mobile devices. Additionally, the claims each later recite “the mobile device.” It is unclear to which of the instances of “a mobile device” the phrase “the mobile device” refers.
Claims 2, 4-6, 8-12, and 14-17 are also rejected as each depends on either claim 1 or 7.
Claim 5 recites “wherein the authentication message includes an account identifier of a customer account, the account identifier instructing the SST to retrieve a pre-staged transaction associated with the customer account to be completed on the SST.” Claim 15 recites a similar limitation. Claims 1 and 7, however, also recite “transmitting, via the wireless communication device to the SST over the peer-to-peer wireless connection upon the comparing identifying a match between the biometric authentication data and the biometric data on the mobile device, an authentication message indicating the match together with an account identifier that enables the SST to retrieve a pre-staged transaction from a server.” It is unclear whether the account identifier recites in claims 5 and 15 is the same account identifier recites in claims 1 and 7, and if the account identifier is the same, it is unclear whether the limitations of claims 5 and 15 require any further features beyond those already recited in claims 1 and 7, because claims 1 and 7 already recite that the authentication message includes an account identifier that enables the SST to retrieve a pre-staged transaction from a server.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 4-8, 10-12, 14-16, 18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Bjorn (US 2007/0198848) in view of Treadwell, et al. (US 2010/0017327) (“Treadwell”).
Regarding claims 1 and 7, Bjorn discloses a method comprising:
receiving, via a wireless communication device from a self-service terminal (SST), biometric authentication data to authenticate an account holder (Bjorn Figure 5, step 560; ¶¶ 2, 18, 21, 40, 46-47, 56, 59, 61-63, 83, 107-108, 129);
connecting, wirelessly via the wireless communication device, to the SST to establish a peer- to-peer wireless connection between a mobile device and the SST (Bjorn Figure 5, step 520; ¶¶ 21, 40, 46, 51-54, 59, 99-106);
comparing, on a mobile device, the biometric authentication data with biometric data present on the mobile device (Bjorn Figure 5, step 570; ¶¶ 21, 47, 64, 109), wherein the biometric data present on the mobile device is stored securely by a mobile device application executing on the mobile device and is not accessible and never shared by the mobile device application (Bjorn ¶ 40); and
wherein the comparing identifies a match between the biometric authentication data and the biometric data on the mobile device, transmitting an authentication message via the wireless communication device to the SST indicating the match (Bjorn Figure 5, steps 580-590; ¶¶ 18, 21, 40, 47, 56, 64-66, 84, 109-111, 117, 129).
transmitting, via the wireless communication device to the SST over the peer-to-peer wireless connection upon the comparing identifying a match between the biometric authentication data and the biometric data on the mobile device, an authentication message indicating the match together with an account identifier that enables the SST to perform an operation (Bjorn Figure 5, steps 580-590; ¶¶ 18, 21, 40, 47-49, 56, 64-66, 84-88, 109-114).
Bjorn does not specifically disclose that the account identifier enables the SST to retrieve a pre-staged transaction from a server.
Treadwell discloses that the account identifier enables the SST to retrieve a pre-staged transaction from a server (Treadwell ¶¶ 24-26, 29-34).
Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the method of Bjorn to include the account identifier enabling the SST to retrieve a pre-staged transaction from a server, as disclosed in Treadwell, in order to allow an ATM to access multiple queued transactions prepared by a user when the user arrives at the ATM, and allow the user to select which ones to complete (Treadwell ¶¶ 32-33).
Regarding claims 4 and 14, Bjorn does not specifically disclose that the SST is an automated teller machine (ATM).
Treadwell discloses that the SST is an automated teller machine (ATM) (Treadwell ¶¶ 18, 28-29).
Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the method of Bjorn to include the SST being an automated teller machine (ATM), as disclosed in Treadwell, in order to allow a user to prepare ATM transactions to be queued before the user arrives at an ATM, and then complete the transaction when the user arrives at the ATM (Treadwell ¶¶ 32-33).
Regarding claims 5 and 15, Bjorn does not specifically disclose that the authentication message includes an account identifier of a customer account, the account identifier instructing the SST to retrieve a pre-staged transaction associated with the customer account to be completed on the SST.
Treadwell discloses that the authentication message includes an account identifier of a customer account, the account identifier instructing the SST to retrieve a pre-staged transaction associated with the customer account to be completed on the SST (Treadwell ¶¶ 24-26, 29-34).
Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the method of Bjorn to include the authentication message including an account identifier of a customer account, the account identifier instructing the SST to retrieve a pre-staged transaction associated with the customer account to be completed on the SST, as disclosed in Treadwell, in order to allow an ATM to access multiple queued transactions prepared by a user when the user arrives at the ATM, and allow the user to select which ones to complete (Treadwell ¶¶ 32-33).
Regarding claim 6, Bjorn discloses the authentication message further includes security data indicating validity of the authentication message to the SST (Bjorn ¶¶ 52-53 111).
Regarding claim 8, Bjorn discloses that the authentication message includes a security code or security certificate (Bjorn ¶¶ 52-53 111).
Regarding claim 10, Bjorn discloses that the biometric authentication data includes at least one of fingerprint data, retina scan data, and facial recognition data (Bjorn ¶¶ 18, 31, 64).
Regarding claim 11, Bjorn does not specifically disclose that the authentication message enables retrieval of a pre-staged transaction from a server.
Treadwell discloses that the authentication message enables retrieval of a pre-staged transaction from a server (Treadwell ¶¶ 24-26, 29-34).
Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the method of Bjorn to include the authentication message enabling retrieval of a pre-staged transaction from a server, as disclosed in Treadwell, in order to allow an ATM to access multiple queued transactions prepared by a user when the user arrives at the ATM, and allow the user to select which ones to complete (Treadwell ¶¶ 32-33).
Regarding claim 12, Bjorn discloses that the wireless communication device is one of a Wi-Fi data communication device, a BLUETOOTH® communication device, and a Near Field Communication (NFC) device (Bjorn ¶¶ 25-26).
Regarding claim 16, Bjorn discloses that comparing the biometric authentication data includes retrieving mobile device biometric data from the mobile device (Bjorn Figure 5, step 570; ¶¶ 21, 40, 47, 64, 109).
Regarding claim 18, Bjorn discloses a system comprising:
a biometric reading device (Bjorn Figure 3, Biometric Sensor 130 ¶¶ 25, 31, 44);
a wireless communication interface (Bjorn Figure 3, Transceiver 360 ¶¶ 25-26, 44);
at least one processor (Bjorn Figure 3, Processor 355/140 ¶¶ 25, 28); and
at least one memory storing instructions (Bjorn ¶ 28) executable by the at least one processor to:
receive biometric data from the biometric reading device (Bjorn ¶¶ 55, 61-62, 80-82) to obtain an authentication of biometric data on a mobile device (Bjorn ¶¶ 18, 21, 40, 47, 56, 64-66, 84, 109-111, 117, 129), wherein the mobile device stores biometric data securely via a mobile device application and the stored biometric data is not accessible and never shared by the mobile device application (Bjorn ¶ 40);
establish a peer-to-peer wireless connection with the mobile device via the wireless communication interface (Bjorn Figure 5, step 520; ¶¶ 21, 40, 46, 51-54, 59, 99-106);
transmit the biometric data via the wireless communication interface to a mobile device over the peer-to-peer wireless connection (Bjorn ¶¶ 56, 63, 83);
receive an authentication message from the mobile device over the peer-to-peer wireless connection when the mobile device identifies a match between the biometric data and stored biometric data (Bjorn ¶¶ 56, 65-67, 84-85), wherein the authentication message includes an account identifier (Bjorn Figure 5, steps 580-590; ¶¶ 18, 21, 40, 47-49, 56, 64-66, 84-88, 109-114); and
retrieve protected data upon receipt of the authentication message (Bjorn ¶¶ 56-57, 85-87).
Bjorn does not specifically disclose retrieving pre-staged transaction data from a server based on the account identifier, wherein the pre-staged transaction data was pre-staged to a server prior to the mobile device arriving at the system for download by the system upon authentication of an account holder.
Treadwell discloses retrieving pre-staged transaction data from a server based on the account identifier, wherein the pre-staged transaction data was pre-staged to a server prior to the mobile device arriving at the system for download by the system upon authentication of an account holder (Treadwell ¶¶ 20, 24-26, 29-34).
Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the method of Bjorn to include retrieving pre-staged transaction data from a server based on the account identifier, wherein the pre-staged transaction data was pre-staged to a server prior to the mobile device arriving at the system for download by the system upon authentication of an account holder, as disclosed in Treadwell, in order to allow an ATM to access multiple queued transactions prepared by a user when the user arrives at the ATM, and allow the user to select which ones to complete (Treadwell ¶¶ 32-33).
Regarding claim 20, Bjorn discloses that the wireless communication interface includes at least one of a Wi-Fi interface, a BLUETOOTH® interface, and a Near Field Communication (NFC) interface (Bjorn ¶¶ 25-26).
Claims 2, 9, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Bjorn in view of Treadwell as applied to claims 1, 7, and 18 above, and further in view of Stern, et al. (US 8,458,465) (“Stern”).
Regarding claim 2, Bjorn discloses that the comparing of the biometric authentication data with the biometric data on the mobile device includes: retrieving mobile device biometric data stored on the mobile device; and comparing the biometric data and the mobile device biometric data to identify whether there is a match (Bjorn Figure 5, step 570; ¶¶ 21, 47, 64, 109).
Bjorn in view of Treadwell does not specifically disclose that when there is a match, determining a confidence level of the match, and the transmitting of the authentication message includes transmitting the confidence level.
Stern discloses that when there is a match, determining a confidence level of the match, and the transmitting of the authentication message includes transmitting the confidence level (Stern 2:51-65; 6:47-61; 8:4-16).
Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the method of Bjorn in view of Treadwell to include when there is a match, determining a confidence level of the match, and transmitting the confidence level, as disclosed in Stern, in order to allow a requester to determine whether biometric authentication should occur in situations where the biometric data may not exactly match biometric templates (Stern 2:55-63).
Regarding claim 9, Bjorn in view of Treadwell does not specifically disclose that comparing the biometric authentication data includes determining a confidence level of the match.
Stern discloses that comparing the biometric authentication data includes determining a confidence level of the match (Stern 2:51-65; 6:47-61; 8:4-16).
Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the method of Bjorn in view of Treadwell to include comparing the biometric authentication data includes determining a confidence level of the match, as disclosed in Stern, in order to allow a requester to determine whether biometric authentication should occur in situations where the biometric data may not exactly match biometric templates (Stern 2:55-63).
Regarding claim 19, Bjorn does not specifically disclose that the authentication message includes an account identifier and a confidence level of the match.
Treadwell discloses that the authentication message includes an account identifier (Treadwell ¶¶ 24-26, 29-34).
Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the method of Bjorn to include the authentication message including an account identifier, as disclosed in Treadwell, in order to allow an ATM to access multiple queued transactions prepared by a user when the user arrives at the ATM, and allow the user to select which ones to complete (Treadwell ¶¶ 32-33).
Bjorn in view of Treadwell does not specifically disclose that the authentication message includes a confidence level of the match.
Stern discloses that the authentication message includes a confidence level of the match (Stern 2:51-65; 6:47-61; 8:4-16).
Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the method of Bjorn in view of Treadwell to include an authentication message having a confidence level of the match, as disclosed in Stern, in order to allow a requester to determine whether biometric authentication should occur in situations where the biometric data may not exactly match biometric templates (Stern 2:55-63).
Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Bjorn in view of Treadwell as applied to claim 7 above, and further in view of Clark (US 2004/0020984).
Regarding claim 17, Bjorn in view of Treadwell does not specifically disclose flushing a secure memory of the mobile device biometric data on the SST upon completion of authentication.
Clark discloses flushing a secure memory of the mobile device biometric data on the SST upon completion of authentication (Clark ¶¶ 43-45, 50).
Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the method of Bjorn in view of Treadwell to include flushing a secure memory of the mobile device biometric data on the SST upon completion of authentication, as disclosed in Clark, in order to allow a subsequent transaction to be performed, and to prevent unauthorized access to the biometric data by not maintaining the biometric data after the transaction involving the biometric data is complete (Clark ¶¶ 43-45, 50).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Mohammad A. Nilforoush whose telephone number is (571)270-5298. The examiner can normally be reached Monday-Friday 12pm-7pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John W. Hayes can be reached at 571-272-6708. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Mohammad A. Nilforoush/Primary Examiner, Art Unit 3697