Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Applicant filed an amendment on 6/26/26. Claims 1-20 are pending and are rejected in this Application.
Claims 1, 10, and 16 are amended, along with certain dependent claims.
After careful consideration of applicant arguments and amendments, the examiner finds them to be moot in view of new grounds of rejection. This action is a Final Rejection.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because they are directed to an abstract idea without significantly more.
Claims 1-20 are directed to a system, method and computer readable medium (1, 10 and 16) respectively which are statutory categories of invention. Step 1 (yes) Claim 10 has been identified as the representative claim for analysis.
Claim 10 is directed to a computer method for better controlling payment for recurring transactions.
The limitations under their broadest reasonable interpretation cover performance of the limitation as certain methods of organizing human activity. In this case a commercial or legal interaction which is considered to be part of the grouping of abstract ideas.
The abstract elements of claim 10 include;
receiving an updated data file from a … associated with a verified issuer of the updated data file,
the updated data file corresponding to an accountholder and comprising an update to at least one data element of a plurality of data elements included within the updated data file; storing the updated data file in a secure data store based on a unique identifier;
storing, in the …., at least one verification rule including one or more conditions for verifying [[a]] the requesting third-party as a legitimate receiving party before transmitting the updated data file to the then verified requesting third-party; monitoring network traffic of a … for the processing of data associated with the updated data file by an identified enrolled third-party processed within a predefined period of time; in response to detecting the processing of data associated with the updated data file by the identified third-party over the processing network, creating an additional verification rule for the identified enrolled third-party; receiving a query for an updated data file query from a …. of a candidate requesting third-party, the query including a third-party identifier associated with the candidate requesting third-party, the unique identifier for a corresponding updated data filet and a request of the updated data file; applying the at least one verification rule to the query and the candidate requesting third-party; applying the additional verification rule to data associated with the candidate requesting third-party identifier to confirm that determine whether the candidate requesting third- party has been identified as processing is authorized to receive data associated with the requested updated data file over the processing network within the predefined period of time, thereby verifying the candidate requesting third-party as a legitimate receiving party of the requested updated data file; [[and]] in response to verifying determining that the candidate requesting third-party as the legitimate receiving party is authorized to receive the data associated with the requested updated data file, automatically transmitting the requested updated data file to the verified candidate requesting third-party, thereby ensuring data security including that the legitimate an authorized third-party is receiving the updated data file before the updated data file is transmitted thereto;
and in response to determining that the candidate requesting third-party is not authorized to receive the data associated with the requested updated data file, (i) automatically discontinuing enrollment of the candidate requesting third-party and (ii) blocking transmission of the requested updated data file to the candidate requesting third-party.
Here the non abstract elements include “a first remote computing device”, “one or more memory devices”, “a processing network” and a “third party computing device” By amendment, the added steps are not “technical” components.
The recitation of generic computing elements does not necessarily preclude a claim from reciting an abstract idea. Claims 10, 16 are abstract similar to claim 1. Step 2A Prong 1 Yes, the claims recite an abstract idea.
This judicial exception is not integrated into a practical application. In particular the claims recite the additional elements of
“a first remote computing device”, “one or more memory devices”, “a processing network” and a “third party computing device”
The computer hardware/software are recited at a high level of generality such that it amounts to no more than mere instructions to apply the exception using a generic computing component.
Accordingly these additional elements when considered separately and as an ordered combination, do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea and are of a high level of generality. Therefore claims 1, 10 and 16, are directed to an abstract idea without a practical applicant. (Step 2A prong 2 No, the additional claimed element not integrated into a practical application. The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because when considered separately and as an ordered combination they do not add significantly more (also known as inventive concept) to the exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a computer hardware amounts to no more than mere instructions to apply the exception using generic computing components.
Mere instructions to apply an exception using a generic computing component cannot provide an inventive concept.
Applicant’s specification includes an “abu computer” (0047). Which might be incorporated into the independent claims.
Thus claims 1, 10 and 16 are not patent eligible. (step 2B No the claims do not provide significantly more). Dependent claims 2-9 and 11-15 and 17-20 do not include additional elements that integrate the abstract idea into a practical application or are sufficient to amount to significantly more than the judicial exception when considered both individually and as an ordered combination. Therefore the dependent claims are directed to an abstract idea. Thus the claims 1-20 are not patent eligible.
Here, the applicant appears to have considered “Network Monitoring” example from 2019 PEG where additional elements for monitoring network traffic and comparing traffic to a threshold were enough to create a practical application out of a mental process, with the end result of using less memory and avoiding excess traffic volume, thereby a practical application. The support found in the specification would have to be commensurate but it appears that this is what applicant is attempting to achieve. The examiner reviewed the offered advice with the supervisor and it was determined to not be sufficient of itself because the inventive concept is not cyber security.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-20 is/are rejected under 35 U.S.C. 103 as being anticipated by US Patent Publication to Knudsen 20140365363 in view of US Patent Publication to Bonalle 20050035192
As per claim 10 Knudsen discloses;
receiving an updated data file from a first remote computing device associated with a verified issuer of the updated data file, Knudsen(0123)
the updated data file corresponding to an accountholder and comprising an update to at least one data element of a plurality of data elements included within the updated data file; storing the updated data file in a secure data store based on a unique identifier;
Knudsen(0138, identifier for the access device for example)
storing, in the one or more memory devices, at least one verification rule including one or more conditions for verifying [[a]] the requesting third-party as a legitimate receiving party before transmitting the updated data file to the then verified requesting third-party;
Knudsen(0169)
monitoring network traffic of a processing network for the processing of data associated with the updated data file by an identified enrolled third-party processed within a predefined period of time; in response to detecting the processing of data associated with the updated data file by the identified third-party over the processing network, creating an additional verification rule for the identified enrolled third-party;
Knudsen(0095)
receiving a query for an updated data file query from a third-party computing device of a candidate requesting third-party, the query including a third-party identifier associated with the candidate requesting third-party, the unique identifier for a corresponding updated data filet and a request of the updated data file;
Knudsen(0088 unique tokens)
applying the at least one verification rule to the query and the candidate requesting third-party;
Knudsen(0076 verification code)
applying the additional verification rule to data associated with the candidate requesting third-party identifier to confirm that determine whether the candidate requesting third- party has been identified
Knudsen(0076 verification code)
as processing is authorized to receive data associated with the requested updated data file over the processing network within the predefined period of time, thereby verifying the candidate requesting
Knudsen(0088 specified period of time)
third-party as a legitimate receiving party of the requested updated data file; [[and]] in response to verifying determining that the candidate requesting third-party as the legitimate receiving party is authorized to receive the data associated with the requested updated data file, automatically transmitting the requested updated data file to the verified candidate requesting third-party, thereby ensuring data security including that the legitimate an authorized third-party is receiving the updated data file before the updated data file is transmitted thereto;
Knudsen(0029, “ensuring security” is more of intended use, and “legitimate” is similar)
Bonalle teaches what Knudson fails to disclose;
and in response to determining that the candidate requesting third-party is not authorized to receive the data associated with the requested updated data file, (i) automatically discontinuing enrollment of the candidate requesting third-party and (ii) blocking transmission of the requested updated data file to the candidate requesting third-party.
(0123, in regards to blocking transmission, 0074 for expiration date, it is noted that applicant support in 0043-5 of the spec. appears to be related to expiring or inactive accounts. Bonnalle teaches expired cards for example, after which the user becomes inactive, expired and effectively blocked.)
It would therefore have been obvious to one of ordinary skill in the art before the effective filing date of the invention to combine Bonnalle’s blocking, usage after an expiration date with Knudsen’s security to end enrollment of inactive actions for the motivation of of decrease the volume of accounts (0006), for various reasons including loess data to manage.
claims 1, 16 are similar to claim 10
As per claims 2, 11 Knudsen discloses;
The computing system of Claim 1, wherein the at least one verification rule is derived from one or more data sets including one or more of (i) account activity data, (ii) fraud data, or (iii) merchant activity data, and wherein the candidate requesting third-party is a merchant.
Knudsen(0092)
As per claims 3, 17, Knudsen discloses; The computing system of Claim 2, wherein the one or more processors are further programmed to access one or more data sources that store at least one of (i) the account activity data, (ii) the fraud data, or (iii) the merchant activity data.
Knudsen(one of is a choice, “activity data including suspicious” 0092)
As per claims 4, 12 and 18 Knudsen discloses;
The computing system of Claim 1, wherein the one or more processors are further programmed to:
in response to verifying the candidate requesting third-party as not being the legitimate receiving party,
automatically transmit a denial message in response to the query to the candidate requesting third-party, the denial message including one or more reasons for denial of the query.
Knudsen(reject/approve, 0092)
As per claims 5,13 Knudsen discloses;
The computing system of Claim 1, wherein the one or more processors are further programmed to: continually monitor network traffic for prior approved transactions associated with the updated data file and the candidate requesting third-party within the predefined period of time.
Knudsen(0114,0118)
As per claim 6, Knudsen discloses;
The computing system of Claim 1, wherein the one or more processors are further programmed to: generate one or more party-specific reports to at least one party associated with the processing network, wherein the one or more party-specific reports contain data specific to the at least one party; and transmit the one or more party-specific reports to the at least one party via the processing network.
Knudsen(0099 reports….. various)
As per claims 7, 14 Knudsen discloses;
The computing system of Claim 6, wherein the at least one party is at least one of the verified issuer or the candidate requesting third-party, and the one or more party-specific reports is formatted using one of (i) extensible markup language (XML), or (ii) a standard including one of ISO 8583 or ISO 20022.
Knudsen (0111 8583 or XLM)
As per claim 19 Knudsen discloses; The at least one non-transitory computer-readable storage medium of Claim 16, wherein the updated data file comprises a message transmitted from the verified issuer to the computing system via the processing network.
Knudsen (0126)
As per claim 8 Knudsen discloses;
The computing system of Claim 1, wherein the additional verification rule is based on an account identifier associated with an account of the accountholder, and wherein the one or more processors are further programmed to: verify the candidate requesting third-party as the legitimate receiving party based in part upon the account identifier.
Knudsen(0173, history of transactions)
As per claims 9, 15 and 20 Knudsen discloses;
The computing system of Claim 8, wherein the one or more processors are further programmed to: verify the candidate requesting third-party as the legitimate receiving party based in part upon one of (i) whether the candidate requesting third-party has prior approved transactions corresponding to the account identifier, or (ii) whether the query was received beyond a predetermined time period since a last approved transaction corresponding to the account identifier.
Knudsen(0173, history of transactions)
Response to Arguments
Applicant filed an amendment on 6/26/26.
Claims 1-20 are pending and are rejected in this Application.
Claims 1, 10, and 16 are amended, along with certain dependent claims.
After careful consideration of applicant arguments and amendments, the examiner finds them to be moot in view of new grounds of rejection. This action is a Final Rejection.
Claim Objections- moot
35 U.S.C. 101 Rejection
The rejection of Claims 1-20 under 35 U.S.C. § 101 for allegedly reciting non-statutory subject matter is respectfully traversed.
A. Applicant's Claims Are Not Directed to an Abstract Idea
The pending claims are not directed to an abstract idea under Step 2A. The MPEP requires a two-prong inquiry. In the first prong, examiners evaluate whether the claim recites a judicial exception. If so, in the second prong, examiners evaluate whether the claim recites additional elements that integrate the identified judicial exception into a practical application. If a claim both recites a judicial exception and fails to integrate that exception into a practical application, then the claim is "directed to" a judicial exception. See MPEP § 2106.04(II)(A).
In the first prong, examiners evaluate whether a claim recites a judicial exception, and in particular an abstract idea, by (a) identifying the specific limitation(s) in the claim under examination (individually or in combination) that the examiner believes recites the abstract idea; and (b) determining whether the identified limitation(s) falls within the subject matter groupings of abstract ideas (i.e., mathematical concepts, certain methods of organizing human activity, and mental processes). See MPEP § 2106.04(a).
The Office Action alleges, at page 3, that the "limitations under their broadest reasonable interpretation cover performance of the limitation as certain methods of organizing human activity. In this case a commercial or legal interaction which is considered to be part of the grouping of abstract ideas." Applicant respectfully disagrees and submits that the pending claims solve a technical problem rooted in cybersecurity of computer technology.
Here the claims are directed to more of a process than humans can implement. The generalized language sounds similar to examples in cybersecurity but the process is more of a business process as claimed.
In particular, the pending claims recite a computing system that securely manages and controls automated distribution of updated data files across a processing network by storing issuer-provided updates in a secure data store, monitoring network traffic to dynamically identify legitimate third-party participants, generating additional verification rules based on observed network activity, and applying multiple authorization rules to validate requests before transmitting sensitive data. The claimed system further implements an automated lockdown mechanism that, upon determining that a requesting third party is unauthorized, automatically blocks transmission of the requested data file and discontinues the third party's enrollment, thereby preventing future unauthorized access attempts. By dynamically generating and enforcing verification rules based on observed network activity and automatically isolating unauthorized entities through the lockdown functionality, the claimed system increases cybersecurity, enhances protection against unauthorized data access and
transmission, and improves the security, integrity, and reliability of computerized data-sharing networks.
These are technical solutions directed to securing electronic communications and controlling access to network-stored data files, rather than merely organizing commercial or legal interactions. Accordingly, the pending are submitted to be patent-eligible under the first prong of Step 2A.
In any event, even assuming arguendo that the independent claims recite a judicial exception, the present claims are subject-matter eligible under the second prong of Step 2A. In the second prong, the Office evaluates whether a claim as a whole integrates the judicial exception into a practical application of the exception. Examiners evaluate integration into a practical application by: (a) identifying whether there are any additional elements recited in the claim beyond the judicial exception(s); and (b) evaluating those additional elements individually and in combination to determine whether they integrate the exception into a practical application. Importantly, "Step 2A specifically excludes consideration of whether the additional elements represent well-understood, routine, conventional activity. Accordingly, in Step 2A Prong Two, examiners should ensure that they give weight to all additional elements, whether or not they are conventional, when evaluating whether a judicial exception has been integrated into a practical application." See MPEP 2106.04(d)(I).
One path to establishing a practical application is to show an improvement to another technology. See MPEP § 2106.04(d)(1). Here, as explained in the published application at, for example paras. [0004]-[0009], conventional account updater systems lack mechanisms for monitoring and verifying data-access requests, allowing unauthorized or potentially fraudulent entities to obtain sensitive account data.
The claimed system addresses the technical problems identified in Applicant's by implementing a computing system that monitors network activity, dynamically applies verification rules to authenticate requesting parties, and automatically blocks or locks out unauthorized entities, thereby improving cybersecurity and protecting the integrity of electronic data transmissions. In particular, the pending claims recite a computing system that securely manages and controls automated distribution of updated data files across a processing network by storing issuer-provided updates in a secure data store, monitoring network traffic to dynamically identify legitimate third-
party participants, generating additional verification rules based on observed network activity, and applying multiple authorization rules to validate requests before transmitting sensitive data. The claimed system further implements an automated lockdown mechanism that, upon determining that a requesting third party is unauthorized, automatically blocks transmission of the requested data file and discontinues the third party's enrollment, thereby preventing future unauthorized access attempts. By dynamically generating and enforcing verification rules based on observed network activity and automatically isolating unauthorized entities through the lockdown functionality, the claimed system increases cybersecurity, enhances protection against unauthorized data access and transmission, and improves the security, integrity, and reliability of computerized data-sharing networks.
By doing so, the claimed system provides the following technical improvements: "(a) reducing the likelihood that account-on-file payment card transactions will be fraudulent; (b) identifying and blocking merchant update requests that are likely fraudulent, similarly reducing up-to-date account information from being disseminated; (c) controlling and policing access to ABU systems; and (d) increasing issuer participation in ABU systems.." (See Applicant's specification at para. [0029].)
Accordingly, in this case, "the specification sets forth an improvement in technology ... [and] the claim includes the components or steps of the invention that provide the improvement described in the specification," which is sufficient to establish a practical application. See MPEP § 2104.04(d)(1). Accordingly, the present claims are eligible under the second prong of Step 2A.
In summary, the claims at issue here are not "directed to" a judicial exception. Accordingly, the Section 101 rejection should be withdrawn because the pending claims are not directed to an abstract idea.
Here while an attempt was made to create a cyber security type application. The general parallels to the example where blocking transmission was considered a practical application, the claims are not fully comparable.
B. Applicant's Claims Are Directed to "Significantly More" Than the Abstract Idea
With that said, even assuming for the sake of argument that the pending claims are directed to an abstract idea (which Applicant does not concede), the claims are directed to something "significantly more" than the idea itself.
One path to show that a claim recites "significantly more" is to identify "a specific limitation other than what is well-understood, routine, conventional activity in the field, or ... unconventional steps that confine the claim to a particular useful application." See MPEP § 2106.05(I)(A)(v). Moreover, at this second step of the analysis, the elements of each claim must be examined both individually and as an ordered combination to determine whether the additional elements transform the nature of the claim into a patent eligible application. See MPEP § 2106.05(d). "Even if one or more additional elements are well-understood, routine, conventional activity when considered individually, the combination of additional elements may amount to an inventive concept." See MPEP § 2106.05(d)(I)(3) ("For example, a microprocessor that performs mathematical calculations and a clock that produces time data may individually be generic computer components that perform merely generic computer functions, but when combined may perform functions that are not generic computer functions and thus be an inventive concept.").
In the instant Application, the pending claims clearly recite more than well-understood, routine, or conventional activities at least with respect to implementing computer-based mechanisms for monitoring and verifying data-access requests by providing a computing system that securely manages and controls automated distribution of updated data files across a processing network by storing issuer-provided updates in a secure data store, monitoring network traffic to dynamically identify legitimate third-party participants, generating additional verification rules based on observed network activity, and applying multiple authorization rules to validate requests before transmitting sensitive data. The claimed system further implements an automated lockdown mechanism that, upon determining that a requesting third party is unauthorized, automatically blocks transmission of the requested data file and discontinues the third party's enrollment, thereby preventing future unauthorized access attempts. By dynamically generating and enforcing verification rules based on observed network activity and automatically isolating unauthorized entities through the lockdown functionality, the claimed system increases cybersecurity, enhances protection against unauthorized data access and transmission, and improves the security, integrity, and reliability of computerized data-sharing networks. In summary, the claimed computing system monitors network activity, dynamically applies verification rules to authenticate requesting parties, and automatically blocks or locks out unauthorized entities, thereby improving cybersecurity and protecting the integrity of electronic data transmissions.
Notably, the claimed combination of processor-implemented operations, distributed network communications, and lockdown functionality operates in a non-conventional and non- generic manner to electronically monitor and verify requests to determine whether to block or grant access sensitive data to requesting parties. (Emphasis added.) The fact that the pending claims overcome the prior art, as discussed below in the traversal of the Section 102 rejection, strengthens the conclusion that these steps are not well understood, routine, and conventional.
In summary, at a minimum, Applicant respectfully submits that the Section 101 rejection should be withdrawn because the claimed invention recites significantly more than the alleged abstract idea.
Accordingly, for these additional reasons, Applicant respectfully requests that the Section 101 rejection of the pending claims be withdrawn.
Significantly more and practical application are also in the examiner’s purview to interpret as such.
35 U.S.C. 102 Rejection- moot in view of Bonnalle
Claims 10,16 are argued similar to claim 1
The dependent claims by virtue of dependency.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Card-Present Transactions on the Internet Using the Smart Card Web Server, IEEE 2013
Emerging ecommerce credit and debit card protocols, IEEE, 2002
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRUCE I EBERSMAN whose telephone number is (571)270-3442. The examiner can normally be reached 8:00 am - 5:00 pm Monday-Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Michael W Anderson can be reached at 571-270-0508. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BRUCE I EBERSMAN/Primary Examiner, Art Unit 3693