DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 02/09/2026 with respect to the rejection(s) of claim(s) 1-15, and 18-22 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made. See remarks on page 26-31.
The rejection of pending claims 1-15, and 18-22 under 35 U.S.C. 101 as directed to an abstract idea without significantly more, is maintained in view of MPEP 2106.04(d). Applicant’s argument of the claim integrate the abstract idea into a practical application by requiring token validation, replay prevention, vendor authorization verification, successful transaction processing, and notification to the third-party vendor is not persuasive because the claims remain directed to managing and authorizing an e-commerce transaction using token-based authentication. The newly added limitations recite that the e-commerce systems performs the transaction when authentication is successful and when the third-party vendor is authorized to generate the token, and then transmit a notification indicating successful processing, which falls under the abstract idea of certain methods of organizing human activity. Under certain methods of organizing human activity is fundamental economic practices (mitigating risk). The claims do not recite a specific improvement to the Simple Mail Transfer Protocol, the e-commerce system, the token datastore, or computer/network functionality. Therefore, the mere implementation of the steps above does not integrate the abstract idea into a practical application under Step 2A, Prong Two, and individually and as a ordered combination, do not amount to significantly more under Step 2B. See remarks on page 12-26.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-15, and 18-22 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more.
Subject Matter Eligibility Criteria – Step 1:
Claims 1-6 and 19-20 are directed to a method, claims 7-12 are directed to a system, and claims 13-15,18, and 21-22 are directed to an article of manufacture. Therefore, these claims fall within the four statutory categories of invention.
Subject Matter Eligibility Criteria – Step 2A – Prong One:
Regarding Prong One of Step 2A of the Alice/Mayo test, the claim limitations are to be analyzed to determine whether, under their broadest reasonable interpretation, they “recite” a judicial exception or in other words whether a judicial exception is “set forth” or “described” in the claims. MPEP 2106.04(II)(A)(1). An “abstract idea” judicial exception is subject matter that falls within at least one of the following groups: a) certain methods of organizing human activity, b) mental processes, and/or c) mathematical concepts. MPEP 2106.04(a).
Representative independents claims 1, 7, and 13 include limitations that recite at least one abstract idea.
Claims 1, 7, and 13 are directed to the abstract idea of “receiving, by an e-commerce system, an email message that contains a token, wherein the email message is generated in response to activating a mail to link, wherein the token comprises (i) a vendor identifier, (ii) transaction data identifying at least one of a product identifier, a price, or a quantity, (iii) an expiration time, and (iv) a nonce or one-time-use value; _decoding, by the e-commerce system, the token to form a decoded token, wherein the decoded token identifies [[the]]a third -party vendor and a customer email address; validating, by the e-commerce system, the token by (i) determining that the expiration time has not elapsed and (ii) determining, using a token-use datastore, that the nonce or one-time-use value has not previously been used; recording, by the e-commerce system, in the token-use datastore, use of the nonce or one-time-use value; authenticating, the e-commerce system, a sender of the email message as a customer based on an email address of the sender and the decoded token; determining, by the e-commerce system, that the third-party vendor is authorized to generate the token by verifying a token-authenticator that is bound to the token and that is associated with the third-party vendor, the token-authenticator comprising at least one of a cryptographic signature, a message authentication code, or an encrypted token portion that is verifiable using vendor authorization data stored by the e-commerce system; performing, by the e-commerce system, the e-commerce transaction when(a) authenticating the sender as the customer is successful, (b) validating the token is successful, and (c) determining that the third party vendor is authorized to generate the token is successful; and notifying, by the e-commerce system, the third-party vendor of successful processing of the e-commerce transaction.” Under its broadest reasonable interpretation, this claim is performing an e-commerce transaction by using emails containing tokens to verify customers, vendors, and complete purchases, and hence falls under organizing human activity (i.e., as fundamental economic practices).
Dependent Claims:
Claims 2, 8, and 14 recites: wherein the mailto link is included in an offer message provided by the third-party vendor; further describes the abstract idea of organizing human activity (i.e., as fundamental economic practices).
Claims 3, 9, and 15 recites wherein offer message includes a plurality of mailto links corresponding to a plurality of tokens; further describes the abstract idea of organizing human activity (i.e., as fundamental economic practices).
Claims 4, 10, and 16 recites: wherein at least two of the plurality of tokens are associated with different transaction data identifying different products, different prices, different quantities, or a combination thereof; further describes the abstract idea of organizing human activity (i.e., as fundamental economic practices).
Claims 5, 11, and 17 recites: wherein the offer message is distributed using at least one of email, a website, or a social media platform; further describes the abstract idea of organizing human activity (i.e., as fundamental economic practices).
Claims 6, 12, and 18 recites: further comprising: monitoring, by the e-commerce system, which tokens are in use based on entries in the token-use datastore; further describes the abstract idea of organizing human activity (i.e., as fundamental economic practices).
Subject Matter Eligibility Criteria – Step 2A – Prong Two:
Claim 1, 7, and 13 recites to a generic computer as additional elements to the judicial exception in the preamble. Viewed individually and in combination, this additional element to the identified judicial exception of Step 2A.1, amounts to no more than mere instructions for performing an e-commerce transaction by using emails containing tokens to verify customers, vendors, and complete purchases on a generic computer. Therefore, at Step 2A.2, these additional elements do not act in combination to integrate the abstract idea into a practical application. The additional elements of claims 1, 7, and 13 considered both individually and as an ordered combination, do not amount to significantly more than the judicial exception because the additional element of a generic computer does no more than “[s]imply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception, e.g., a claim to an abstract idea requiring no more than a generic computer to perform generic computer functions that are well-understood, routine and conventional activities previously known to the industry.” See MPEP 2106.05 (citing to Alice Corp. Pty. Ltd. v. CLS Bank Int'l, 573 U.S. 208, 225 (2014)).
Therefore claims 1, 7, and 13 is found ineligible under 35 U.S.C. 101.
Step 2B:
Viewed as a whole, instructions/method claims recite the concept of “organizing human activity” (i.e., as fundamental economic practices) in performing an e-commerce transaction by using emails containing tokens to verify customers, vendors, and complete purchases are performed by a generic computer. The method claims do not, for example, purport to improve the functioning of the computer itself. Nor do they effect an improvement in any other technology or technical field. Instead, the claims at issue amount to nothing significantly more than an instruction to apply the abstract idea using some unspecified, generic computer. See Alice Corp. Pty. Ltd., 573 U.S. 208. Mere instructions to apply the exception using a generic computer component and limitations to a particular field of use or technological environment cannot integrate a judicial exception into a practical application at Step 2A or provide an inventive concept in Step 2B. The use of a computer server is to merely automate and/or implement the abstract idea cannot provide significantly more than the abstract idea itself (MPEP 2106.05(I)(A)(f) & (h)). Therefore, the claim is not patent eligible.
Claim Rejections - 35 USC § 103
5. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-15 and 18-22 are rejected under 35 U.S.C. 103 as being unpatentable over Custer et al. (US 9704190 B2), in view of Killoran et al. (US 8775263 B2), and further in view of Hammad et al. (US 20140061302 A1).
7. Regarding claims 1, 7, and 13, Custer discloses a method (a system, and a non-transitory computer readable storage medium storing instructions for improving security in an e-commerce transaction between a third party vendor and a customer using Simple Mail Transfer Protocol (SMTP), (Column 4/line 12)),
comprising: receiving, by an e-commerce system, an email message that contains a token, wherein the email message is generated in response to activating a mailto link, (Column 2/line 36, With the email based payment system, a customer has the option of completing a transaction and making a payment using one or more emails. The customer receives an email message that contains a mailto: hyperlink and predefined body. The body of the email message may include a button graphic embedded with code that the customer may click when selecting their payment amount or item to purchase. By selecting the button, a reply email message may be generated confirming or cancelling the purchase. The reply email message may include a token. A payment server may receive the reply email message, including the token that has been submitted by the user's email client. The payment server may parse the sender of the message, attempt to find the sender in its database, and, assuming success, it parses the token in a novel decoding process. The first stage in the decoding process may determine the merchant for which this token is valid. In a second stage, after discovery of the merchant, a public key for the merchant is used to decrypt an encrypted portion of the token and then validate the authenticity of the token and provide further instructions for how to process the payment.)
decoding, by the e-commerce system, the token to form a decoded token, wherein the decoded token identifies a third party vendor and customer email address, (Column 2/line 46, A payment server may receive the reply email message, including the token that has been submitted by the user's email client. The payment server may parse the sender of the message, attempt to find the sender in its database, and, assuming success, it parses the token in a novel decoding process. The first stage in the decoding process may determine the merchant for which this token is valid. In a second stage, after discovery of the merchant, a public key for the merchant is used to decrypt an encrypted portion of the token and then validate the authenticity of the token and provide further instructions for how to process the payment.
In one embodiment, the methods allow for this feature to “plug in” on any website checkout page such that the user is able to complete the transaction by email. This is a much more desirable method of completing the transaction for mobile users.)
authenticating, by the e-commerce system, a sender of the email message as a customer based on an email address of the sender and the decoded token, (Column 2/line 15, A system for leveraging email to complete an online checkout from a customer accessing a third party vendor website is disclosed. The system may store customer information including a name, email address, shipping address, and billing information. The system may receive a request for a purchase from the third party vendor including a customer email address and an item to be purchased. The system may authenticate the customer email address. The system may send a first email to the customer email address that requests authorization to complete a purchase. The system may receive a second email, from the customer email address, encoded with the token and confirming or canceling the purchase. The system may authenticate the second email using the customer email address and the token. And the system may transmit a confirmation of the purchase to the third party vendor website…A payment server may receive the reply email message, including the token that has been submitted by the user's email client. The payment server may parse the sender of the message, attempt to find the sender in its database, and, assuming success, it parses the token in a novel decoding process. The first stage in the decoding process may determine the merchant for which this token is valid. In a second stage, after discovery of the merchant, a public key for the merchant is used to decrypt an encrypted portion of the token and then validate the authenticity of the token and provide further instructions for how to process the payment.)
wherein the token comprises (i) a vendor identifier, (ii) transaction data identifying at least one of a product identifier, a price, or a quantity, (iii) an expiration time, and (iv) a nonce or one-time-use value; validating, by the e-commerce system, the token by (i) determining that the expiration time has not elapsed and (ii) determining, using a token-use datastore, that the nonce or one-time-use value has not previously been used; determining, by the e-commerce system, that the third-party vendor is authorized to generate the token by verifying a token-authenticator that is bound to the token and that is associated with the third-party vendor, the token-authenticator comprising at least one of a cryptographic signature, a message authentication code, or an encrypted token portion that is verifiable using vendor authorization data stored by the e-commerce system, (Abstract Section, A system for leveraging email to complete an online checkout from a customer accessing a third party vendor website is disclosed. The system may store customer information including a name, email address, shipping address, and billing information. The system may receive a request for a purchase from the third party vendor including a customer email address and an item to be purchased. The system may authenticate the customer email address. The system may send a first email to the customer email address requesting authorization to complete a purchase. The system may receive a second email, from the customer email address, encoded with the token and confirming or canceling the purchase. The system may authenticate the second email using the customer email address and the token. And the system may transmit a confirmation of purchase of the at least one item to the third party vendor website.; and Column 2/line 46, A payment server may receive the reply email message, including the token that has been submitted by the user's email client. The payment server may parse the sender of the message, attempt to find the sender in its database, and, assuming success, it parses the token in a novel decoding process. The first stage in the decoding process may determine the merchant for which this token is valid. In a second stage, after discovery of the merchant, a public key for the merchant is used to decrypt an encrypted portion of the token and then validate the authenticity of the token and provide further instructions for how to process the payment.; and Column 4/line 42, The vendor server 120 may include an HTTP server module 121, a token generator 122, a button generator 123, a processor 124, memory 125, a payment gateway 126 and a communications unit 127.; and Column 3/line 46, the term “token” may refer a string or file used to authenticate a transaction. A token may be one or multiple encrypted strings, files, passwords, cyphers or other data which may contain information used to perform or authenticate a transaction when sent to payment servers. These tokens may be encrypted using a public-private key encryption system. The vendor or a party with knowledge of the vendor's private key may generate an encrypted token. Alternatively, a payment system or e-commerce site may generate this token on behalf of the vendor.; and Column 5/line 5, The token generator 122 may generate tokens for use in e-commerce transactions. Tokens may be encrypted strings which contain information to perform a transaction when sent to the payment server(s) 140. A token may be one or multiple encrypted strings, files, passwords, cyphers or other data which may contain information used to perform or authenticate a transaction. A token may include one or more of the following parameters or other parameters not listed below:..j) --amount, -o<f>: [token] The amount a user should be charged for the transaction the token is generated for. k) --user-data, -s<s>: [token] Data to pass back as a reference. This data may include custom data that the vendor may want to pass through the payment server 140 and receive back when a transaction has completed. It may include an item reference number or SKU, customer address, or other piece of data that is not required by payment server 140 to complete a transaction, but that the vendor wants associated with that transaction. l) --expires, -x<i>: [token] Expiration date for token, integer value of seconds since epoch. m) --header-user-agent, -h<s>: [site-token] The HTTP USER AGENT from the request header (if ‘type’ is ‘site’).
performing, by the e-commerce system, the e-commerce transaction when(a) authenticating the sender as the customer is successful, (b) validating the token is successful, and (c) determining that the third party vendor is authorized to generate the token is successful; and notifying, by the e-commerce system, the third-party vendor of successful processing of the e-commerce transaction, (Column 2/line 15, A system for leveraging email to complete an online checkout from a customer accessing a third party vendor website is disclosed. The system may store customer information including a name, email address, shipping address, and billing information. The system may receive a request for a purchase from the third party vendor including a customer email address and an item to be purchased. The system may authenticate the customer email address. The system may send a first email to the customer email address that requests authorization to complete a purchase. The system may receive a second email, from the customer email address, encoded with the token and confirming or canceling the purchase. The system may authenticate the second email using the customer email address and the token. And the system may transmit a confirmation of the purchase to the third party vendor website.; and Column 2/line 46, A payment server may receive the reply email message, including the token that has been submitted by the user's email client. The payment server may parse the sender of the message, attempt to find the sender in its database, and, assuming success, it parses the token in a novel decoding process. The first stage in the decoding process may determine the merchant for which this token is valid. In a second stage, after discovery of the merchant, a public key for the merchant is used to decrypt an encrypted portion of the token and then validate the authenticity of the token and provide further instructions for how to process the payment.)
Custer does not explicitly disclose wherein the email message is generated in response to activating a mailto link.
However, Killoran teaches wherein the email message is generated in response to activating a mailto link, (Column 4/line 4, The message processing module 110 (in conjunction with the email interface module 112) may generate and transmit advertisement email messages to customers that are registered with the e-commerce system 100, such as the user of the customer client device 120. The advertisement email messages may be HyperText Markup Language (HTML) email messages, Rich Text Format (RTF) email messages, and/or may be defined according to any other appropriate format. The advertisement email messages may include Uniform Resource Identifiers (URIs) or hyperlinks that are defined according to the mailto URI scheme. Each mailto URI or hyperlink may describe an email message that may be generated by an email client module (such as the email client module 122) when that URI or hyperlink is selected. The generated message may include a number of parameters that indicate, for example, a product that was advertised in the advertisement email that the customer wishes to purchase. The generated message may then be sent to the e-commerce system 100, and received by the message processing module 110; when the generated message is received by the message processing module 110, the message processing module 110 may then initiate a transaction to purchase the product indicated in the message on behalf of the customer. In such an instance, the message processing module 110 may interact with the order execution module 108 to perform the transaction.)
One of ordinary skill in the art would have recognized that applying the known technique of Custer to the known invention of Killoran would have yielded predictable results and resulted in an improved invention. It would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such mailto link features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the method to include wherein the email message is generated in response to activating a mailto link results in an improved invention because applying said technique ensures that users can complete transactions through emails, thus improving the overall user convenience of the invention.
Custer as modified does not explicitly recording, by the e-commerce system, in the token-use datastore, use of the nonce or one-time-use value.
However, Hammad teaches recording, by the e-commerce system, in the token-use datastore, use of the nonce or one-time-use value, (Para. 0050, A first validation test that validation entity 80 may apply pertains to verifying that verification token 40 is authentic. For this, verification token 40 may send its serial number to validation entity 80, along with a message encrypted by an encryption key, with the message and encryption key being known to token 40 and entity 80 (but not the general public), and with the encryption key further being uniquely assigned to the token's serial number (uniquely assigned to the token). Validation entity 80 has a database of serial numbers and corresponding uniquely assigned encryption keys, and can validate that verification token 40 has sent the correct message for the serial number. Validation of the correct message serves to authenticate verification token 40. If the first validation test is failed, validation entity 80 may record the serial number of the failed token 40 and the source IP address from which the failed token 40 made the request in a database (such as a database 86 described below). A second validation test that validation entity 80 may apply pertains to verifying that verification token 40 has not been involved in fraudulent transactions. For this, validation entity 80 may also have a database that tracks the serial numbers of verification tokens that have been used in fraudulent activities, and may check the serial number of verification token 40 against this database. The second validation test may further comprise checking the token serial number and/or the IP address from which an incoming dCVV2 request was originated (the source IP address of the message) against the previously-described database that stores token serial numbers and IP addresses associated with requests that have failed the first validation test. If a token serial number or IP address is found in this database, the second validation test may be deemed to have been failed. Checking the token serial numbers and/or the IP addresses in this way prevents replay attacks by fraudsters. It may be appreciated that the database of serial numbers of tokens that failed the first validation test may be combined with the database of serial numbers of tokens involved in fraudulent activities. This combined database, as well as the two other databases, may be generically termed as a database of serial numbers of suspicious tokens. If the first and second validation tests are passed (e.g., encrypted serial number matches value in database, and no fraudulent use and/or suspicious activity by the token), validation entity 80 may send a dCVV2 value to verification token 40, or may apply additional validation tests before sending a dCVV2 value.)
One of ordinary skill in the art would have recognized that applying the known technique of Hammad to the known invention of Custer as modified would have yielded predictable results and resulted in an improved invention. It would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such token features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the method to include recording, by the e-commerce system, in the token-use datastore, use of the nonce or one-time-use value ensures that the same token is being monitored on its usage to reduce duplicate transactions or fraud, thus improving the overall security of the invention.
8. Regarding claims 2, 8, and 14, Custer does not explicitly disclose wherein the mailto link is included in an offer message provided by the third-party vendor.
However, Killoran teaches wherein the mailto link is included in an offer message provided by the third-party vendor, (Claim 1. an advertising email message that is addressed to the email address of the customer and that includes a plurality of mailto hyperlinks respectively associated with a plurality of predetermined and mutually different quantities of a specific product, and each mailto hyperlink for generating an order reply email message that includes: a destination address field that indicates an email address of the e-commerce system; and a body field that indicates the identifier of the customer, the identifier of the specific product and the predetermined and mutually different quantity of the specific product; transmitting, by an email server, the advertising email message to the email address of the customer; receiving, by the email server, an order reply email message that indicates an order by the customer for the specific product in the predetermined and mutually different quantity, wherein the order reply email message is responsive to the advertising email message, wherein the order reply email message is addressed to the email address of the e-commerce system, and wherein the order reply email message includes the identifier of the customer, the identifier of the specific product and the mutually different quantity of the specific product; and the at least one processor and the email server performing an order execution procedure based on the order reply email message, wherein the order execution procedure includes purchasing the specific product in the predetermined and mutually different quantity for the customer.)
One of ordinary skill in the art would have recognized that applying the known technique of Custer to the known invention of Killoran would have yielded predictable results and resulted in an improved invention. It would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such mailto link features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the method to include wherein the mailto link is included in an offer message provided by the third-party vendor results in an improved invention because applying said technique allows for the user to have multiple purchase options to be offered through email, thus improving the overall user convenience of the invention.
9. Regarding claims 3, 9, and 15, Custer does not explicitly disclose wherein offer message includes a plurality of mailto links corresponding to a plurality of tokens.
However, Killoran teaches wherein offer message includes a plurality of mailto links corresponding to a plurality of tokens, (Column 1/line 40, A method for use in an e-commerce system may include a database storing information that includes an identifier of a customer, an email address of the customer, and an identifier of a product offered by a vendor. The method may further include at least one processor generating an advertising email message. The advertising email message may be addressed to the email address of the customer, and may include a mailto hyperlink. The mailto hyperlink may include a destination address field that indicates an email address of the e-commerce system, and a body field that indicates an email body that includes the identifier of the customer and the identifier of the product. The method may further include a network interface transmitting the advertising email message, and the network interface receiving an order email message. The order email message may indicate an order by the customer for the product. The order email message may be responsive to the advertising email message, and may be addressed to the email address of the e-commerce system. The body of the order email message may include the identifier of the customer and the identifier of the product. The at least one processor and the network interface may perform an order execution procedure based on the order email message, wherein the order execution procedure includes purchasing the product for the customer.)
One of ordinary skill in the art would have recognized that applying the known technique of Custer to the known invention of Killoran would have yielded predictable results and resulted in an improved invention. It would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such mailto link features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the method to include wherein offer message includes a plurality of mailto links corresponding to a plurality of tokens results in an improved invention because applying said technique ensures that vendors can offer multiple different products at once, thus improving the overall user convenience of the invention.
10. Regarding claims 4, 10, and 16, Custer does not explicitly disclose wherein at least two of the plurality of tokens are associated with different transaction data identifying different products, different prices, different quantities, or a combination thereof.
However, Killoran teaches wherein at least two of the plurality of tokens are associated with different transaction data identifying different products, different prices, different quantities, or a combination thereof, (Claim 1. an advertising email message that is addressed to the email address of the customer and that includes a plurality of mailto hyperlinks respectively associated with a plurality of predetermined and mutually different quantities of a specific product, and each mailto hyperlink for generating an order reply email message that includes: a destination address field that indicates an email address of the e-commerce system; and a body field that indicates the identifier of the customer, the identifier of the specific product and the predetermined and mutually different quantity of the specific product; transmitting, by an email server, the advertising email message to the email address of the customer; receiving, by the email server, an order reply email message that indicates an order by the customer for the specific product in the predetermined and mutually different quantity, wherein the order reply email message is responsive to the advertising email message, wherein the order reply email message is addressed to the email address of the e-commerce system, and wherein the order reply email message includes the identifier of the customer, the identifier of the specific product and the mutually different quantity of the specific product; and the at least one processor and the email server performing an order execution procedure based on the order reply email message, wherein the order execution procedure includes purchasing the specific product in the predetermined and mutually different quantity for the customer.)
One of ordinary skill in the art would have recognized that applying the known technique of Custer to the known invention of Killoran would have yielded predictable results and resulted in an improved invention. It would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such mailto link features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the method to include wherein at least two of the plurality of tokens are associated with different transaction data identifying different products, different prices, different quantities, or a combination thereof results in an improved invention because applying said technique allow users to see and select price options, thus improving the overall user convenience of the invention.
11. Regarding claims 5, 11, and 17, wherein the
However, Killoran teaches wherein the(Column 3/line 28, The account management module 102 in the e-commerce system 100 may manage data related to accounts for customers and vendors that participate in commerce via the e-commerce system 100. The account management module 102 may be or include, for example, a web application. Vendors may interact with the account management module 102 via a web browser such as the web browser module 134 in the vendor client device 130. As one example, a user of the vendor client device 130 may provide information to the account management module 102 such as: product and pricing information to be used for email advertisements to be sent to customers in email campaigns; email formatting information to be used for email advertisements to be sent to customers; financial information related to bank accounts and/or other types of financial accounts (such as e-Payment accounts such as PayPal accounts) that may be used to received payments from customers of the e-commerce system 100, such as account numbers and/or other identifying information; and/or other information. Customers may register with the e-commerce system 100 by interacting with the account management module 102 via a web browser such as a web browser module (not depicted) in the customer client device 120. A user of the customer client device 120 may provide information to the account management module 102 via the web browser such as: an email address associated with the customer; financial information associated with the customer, such as a credit card information (such as a credit card number and expiration date), and/or other information related to bank accounts and/or other types of financial accounts (such as e-Payment accounts) that may be used to make payments to vendors via the e-commerce system 100; shipping address information; billing address information; preferences regarding which vendors the customer would like to receive email advertisements from; and/or other information. The account management module 102 may, via the database module 104, store information received from the customer client device 120 and/or the vendor client device 130 in the e-commerce database 106. The account management module 102 may also add information to the e-commerce database 106 when customers and vendors register with the e-commerce system 100, such as customer identifiers, vendor identifiers, and other identifying information.)
One of ordinary skill in the art would have recognized that applying the known technique of Custer to the known invention of Killoran would have yielded predictable results and resulted in an improved invention. It would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such social media platforms features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the method to wherein the offer message is distributed using at least one of email, a website, or a social media platform results in an improved invention because applying said technique ensures that purchases can be initiated through social media as well, thus improving the overall user convenience of the invention.
12. Regarding claims 6, 12, and 18, Custer as modified does not explicitly disclose further comprising: monitoring, by the e-commerce system, which tokens are in use based on entries in the token-use datastore.
However, Hammad teaches further comprising: monitoring, by the e-commerce system, which tokens are in use based on entries in the token-use datastore, ((Para. 0050, A first validation test that validation entity 80 may apply pertains to verifying that verification token 40 is authentic. For this, verification token 40 may send its serial number to validation entity 80, along with a message encrypted by an encryption key, with the message and encryption key being known to token 40 and entity 80 (but not the general public), and with the encryption key further being uniquely assigned to the token's serial number (uniquely assigned to the token). Validation entity 80 has a database of serial numbers and corresponding uniquely assigned encryption keys, and can validate that verification token 40 has sent the correct message for the serial number. Validation of the correct message serves to authenticate verification token 40. If the first validation test is failed, validation entity 80 may record the serial number of the failed token 40 and the source IP address from which the failed token 40 made the request in a database (such as a database 86 described below). A second validation test that validation entity 80 may apply pertains to verifying that verification token 40 has not been involved in fraudulent transactions. For this, validation entity 80 may also have a database that tracks the serial numbers of verification tokens that have been used in fraudulent activities, and may check the serial number of verification token 40 against this database. The second validation test may further comprise checking the token serial number and/or the IP address from which an incoming dCVV2 request was originated (the source IP address of the message) against the previously-described database that stores token serial numbers and IP addresses associated with requests that have failed the first validation test. If a token serial number or IP address is found in this database, the second validation test may be deemed to have been failed. Checking the token serial numbers and/or the IP addresses in this way prevents replay attacks by fraudsters. It may be appreciated that the database of serial numbers of tokens that failed the first validation test may be combined with the database of serial numbers of tokens involved in fraudulent activities. This combined database, as well as the two other databases, may be generically termed as a database of serial numbers of suspicious tokens. If the first and second validation tests are passed (e.g., encrypted serial number matches value in database, and no fraudulent use and/or suspicious activity by the token), validation entity 80 may send a dCVV2 value to verification token 40, or may apply additional validation tests before sending a dCVV2 value.))
One of ordinary skill in the art would have recognized that applying the known technique of Hammad to the known invention of Custer as modified would have yielded predictable results and resulted in an improved invention. It would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such mailto link features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the method to include further comprising: monitoring, by the e-commerce system, which tokens are in use based on entries in the token-use datastore results in an improved invention because applying said technique ensures that the same token is being monitored on its usage to reduce duplicate transactions or fraud, thus improving the overall security of the invention.
13. Regarding claims 20, Custer as modified does not explicitly disclose wherein validating the token further comprises generating, by the e-commerce system, a checksum of the token or of the decoded token, storing the checksum in the token-use datastore as a used-token record, and rejecting any subsequently received token that matches the used-token record.
However, Hammad teaches wherein validating the token further comprises generating, by the e-commerce system, a checksum of the token or of the decoded token, storing the checksum in the token-use datastore as a used-token record, and rejecting any subsequently received token that matches the used-token record, (Para. the verification token comprises code that directs the data processor to communicate with a computer by way of the verification token's peripheral interface and to gain access to a networking facility of the computer, code that directs the data processor to receive identification information read from a portable consumer device by the reader, code that directs the data processor to transmit at least a portion of the received identification information to an entity that can provide a device verification value (e.g., validation entity or gateway) by way of the networking facility of the computer, and code that directs the data processor to receive, after transmitting said identification information, a device verification value from the entity by way of the networking facility of the computer. The verification token may send the identification information to the computer in a number of forms, including: (1) unaltered form (“clear form”), (2) encrypted form, (3) hashed formed (e.g., encoded), (4) signed form, (5) or any combination of these forms. These forms may be generated by the portable consumer device, the verification token, the computer, or any combination thereof. In addition, the verification token and the entity (e.g., validation entity or gateway) may perform a mutual authentication process before the verification token sends the identification information.; and Para. 0050, validation entity 80 may record the serial number of the failed token 40 and the source IP address from which the failed token 40 made the request in a database (such as a database 86 described below). A second validation test that validation entity 80 may apply pertains to verifying that verification token 40 has not been involved in fraudulent transactions. For this, validation entity 80 may also have a database that tracks the serial numbers of verification tokens that have been used in fraudulent activities, and may check the serial number of verification token 40 against this database. The second validation test may further comprise checking the token serial number and/or the IP address from which an incoming dCVV2 request was originated (the source IP address of the message) against the previously-described database that stores token serial numbers and IP addresses associated with requests that have failed the first validation test. If a token serial number or IP address is found in this database, the second validation test may be deemed to have been failed. Checking the token serial numbers and/or the IP addresses in this way prevents replay attacks by fraudsters. It may be appreciated that the database of serial numbers of tokens that failed the first validation test may be combined with the database of serial numbers of tokens involved in fraudulent activities. This combined database, as well as the two other databases, may be generically termed as a database of serial numbers of suspicious tokens. If the first and second validation tests are passed (e.g., encrypted serial number matches value in database, and no fraudulent use and/or suspicious activity by the token), validation entity 80 may send a dCVV2 value to verification token 40, or may apply additional validation tests before sending a dCVV2 value.)
One of ordinary skill in the art would have recognized that applying the known technique of Hammad to the known invention of Custer as modified would have yielded predictable results and resulted in an improved invention. It would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such token features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the method to include wherein validating the token further comprises generating, by the e-commerce system, a checksum of the token or of the decoded token, storing the checksum in the token-use datastore as a used-token record, and rejecting any subsequently received token that matches the used-token record results in an improved invention because applying said technique ensures the system generates a checksum of the token, thus improving the overall performance of the invention.
14. Regarding claims 21, Custer as modified does not explicitly disclose, wherein at least two of the plurality of tokens are associated with different transaction data identifying different products, different prices, different quantities, or a combination thereof.
However, Hammad teaches wherein at least two of the plurality of tokens are associated with different transaction data identifying different products, different prices, different quantities, or a combination thereof, (Abstract Section, A system for leveraging email to complete an online checkout from a customer accessing a third party vendor website is disclosed. The system may store customer information including a name, email address, shipping address, and billing information. The system may receive a request for a purchase from the third party vendor including a customer email address and an item to be purchased. The system may authenticate the customer email address. The system may send a first email to the customer email address requesting authorization to complete a purchase. The system may receive a second email, from the customer email address, encoded with the token and confirming or canceling the purchase. The system may authenticate the second email using the customer email address and the token. And the system may transmit a confirmation of purchase of the at least one item to the third party vendor website.; and Column 2/line 46, A payment server may receive the reply email message, including the token that has been submitted by the user's email client. The payment server may parse the sender of the message, attempt to find the sender in its database, and, assuming success, it parses the token in a novel decoding process. The first stage in the decoding process may determine the merchant for which this token is valid. In a second stage, after discovery of the merchant, a public key for the merchant is used to decrypt an encrypted portion of the token and then validate the authenticity of the token and provide further instructions for how to process the payment.; and Column 4/line 42, The vendor server 120 may include an HTTP server module 121, a token generator 122, a button generator 123, a processor 124, memory 125, a payment gateway 126 and a communications unit 127.; and Column 3/line 46, the term “token” may refer a string or file used to authenticate a transaction. A token may be one or multiple encrypted strings, files, passwords, cyphers or other data which may contain information used to perform or authenticate a transaction when sent to payment servers. These tokens may be encrypted using a public-private key encryption system. The vendor or a party with knowledge of the vendor's private key may generate an encrypted token. Alternatively, a payment system or e-commerce site may generate this token on behalf of the vendor.; and Column 5/line 5, The token generator 122 may generate tokens for use in e-commerce transactions. Tokens may be encrypted strings which contain information to perform a transaction when sent to the payment server(s) 140. A token may be one or multiple encrypted strings, files, passwords, cyphers or other data which may contain information used to perform or authenticate a transaction. A token may include one or more of the following parameters or other parameters not listed below:..j) --amount, -o<f>: [token] The amount a user should be charged for the transaction the token is generated for. k) --user-data, -s<s>: [token] Data to pass back as a reference. This data may include custom data that the vendor may want to pass through the payment server 140 and receive back when a transaction has completed. It may include an item reference number or SKU, customer address, or other piece of data that is not required by payment server 140 to complete a transaction, but that the vendor wants associated with that transaction. l) --expires, -x<i>: [token] Expiration date for token, integer value of seconds since epoch. m) --header-user-agent, -h<s>: [site-token] The HTTP USER AGENT from the request header (if ‘type’ is ‘site’).)
One of ordinary skill in the art would have recognized that applying the known technique of Hammad to the known invention of Custer as modified would have yielded predictable results and resulted in an improved invention. It would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such token features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the method to include wherein at least two of the plurality of tokens are associated with different transaction data identifying different products, different prices, different quantities, or a combination thereof results in an improved invention because applying said technique allows different tokens to be tied to different transaction data, thus improving the overall performance of the invention.
15. Regarding claims 22, Custer as modified does not explicitly disclose wherein the offer message is distributed using at least one of email, a website, or a social media platform.
However, Hammad teaches wherein the offer message is distributed using at least one of email, a website, or a social media platform, (Abstract Section, A system for leveraging email to complete an online checkout from a customer accessing a third party vendor website is disclosed. The system may store customer information including a name, email address, shipping address, and billing information. The system may receive a request for a purchase from the third party vendor including a customer email address and an item to be purchased. The system may authenticate the customer email address. The system may send a first email to the customer email address requesting authorization to complete a purchase. The system may receive a second email, from the customer email address, encoded with the token and confirming or canceling the purchase. The system may authenticate the second email using the customer email address and the token. And the system may transmit a confirmation of purchase of the at least one item to the third party vendor website.; and Column 10/line 38, In the example shown in FIG. 8, the confirmation request email message 800 is an HTML encoded email with two input fields 815-820. The input fields solicit input from the user to confirm or delete the order. The input fields 815-820 are coded with information to automatically generate confirmation email messages, to confirm or delete a purchase request. Input fields 815-820 may be encoded with a mailto hyperlink that included an embedded token.; and Column 2/line 36, In the example shown in FIG. 8, the confirmation request email message 800 is an HTML encoded email with two input fields 815-820. The input fields solicit input from the user to confirm or delete the order. The input fields 815-820 are coded with information to automatically generate confirmation email messages, to confirm or delete a purchase request. Input fields 815-820 may be encoded with a mailto hyperlink that included an embedded token.; and Column 3/line 56, The system and method may use an email server/account to complete checkout of any type of product (e.g., items/services/events/donations) for a transfer of funds from a customer to a vendor (e.g. retail site, charity, political organization or other vendor.) The system allows the customer at checkout to bypass the e-commerce site's credit card and shipping address required fields by pushing the products in the e-commerce checkout cart through an e-commerce personal account. While the technologies described herein are discussed using email as an example, they may also be applicable to similar communication mediums, such as SMS and MMS communication channels.)
One of ordinary skill in the art would have recognized that applying the known technique of Hammad to the known invention of Custer as modified would have yielded predictable results and resulted in an improved invention. It would have been recognized that the application of the technique would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such mailto link features into a similar invention. Further, it would have been recognized by those of ordinary skill in the art that modifying the method to include wherein the offer message is distributed using at least one of email, a website, or a social media platform results in an improved invention because applying said technique allows the offer message to be sent through email, a website, or social media, thus improving the overall user convenience of the invention.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
System And Methods For Facilitating a Secure Transaction at a Non-Financial Institution System (US 20160321625 A1) teaches securely transferring funds over a private network. Receiving transaction data related to a fund transfer including a tokenized financial instrument, providing to a sender financial institution the tokenized financial instrument to enable the sender financial institution to de-tokenize the tokenized financial instrument and identify an account of the sender, receiving a sender private identifier generated by the sender financial institution, providing to the sender financial institution the transfer amount of the fund transfer to enable the sender financial institution to transfer funds, providing a transaction identifier and a recipient private identifier to the recipient financial institution to enable the recipient financial institution to receive an ACH message from the sender financial institution over the ACH network, the ACH message indicating payment from the sender financial institution to the recipient financial institution to perform the fund transfer with funds over the ACH network.
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
In addition to the foregoing, other aspects are described in the claims, drawings, and text. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Davida L. King whose telephone number is (571) 272-4724. The examiner can normally be reached M-F 8am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha Patel can be reached on (571) 270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/D.L.K./Examiner, Art Unit 3699