DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This communication is a Final Office Action. This communication is further in response to telephonic communications held with Applicant’s representative. See attached interview summary.
Claims 1-4, 6-13, and 15-20 have been examined in this application.
No new information disclosure statement (IDS) has been filed.
Response to Arguments
Applicant's arguments filed April 23, 2026, regarding claim rejections under 35 U.S.C. 101 have been fully considered but they are not persuasive.
Applicant argues a system that is utilized to provision secure transaction account data. Applicant further argues that the system has a particular architecture and provides detailed functions of each one of the multiple entities that make up the system. Based on this argued architecture, Applicant believes the claims “define a concrete, multi-device cryptographic handshake that ties account provisioning, cross-device token capture, sever-side token validation, and short-range wireless deliver to a point of sale terminal into a unified technical workflow performed within the same HTTP session;” id., 10-11. Applicant further argues that the claimed scope recites “specific, coordinated technical operations among distinct devices… [providing] an improvement to computer security and to the technical field of cross-device transaction account provisioning;” id., 12-13.
The Examiner respectfully disagrees. Under MPEP 2106, the claims are analyzed thoroughly and determined to be directed to statutory categories, yet recite an abstract idea. The abstract idea amount to merely provisioning transaction account data to an entity to process a transaction. The abstract idea, is further clearly characterized under two groupings of abstract ideas; mental processes and certain methods of organizing human activity. The subgroupings of these abstract idea groupings include concepts performed in a human mind such as observation, evaluation, judgement, and opinion and commercial interactions such as sales activities and business relations; accordingly. Next, and under Step-2A, Prong II, we analyze the additional elements in the claims. Contrary to Applicant’s arguments, the claims are not directed to a specific technical architecture comprising multiple entities. Instead, the claims are strictly and clearly directed to a client device and what the client device does. The first computing device and what it does including the amended limitations in the first limitation in the independent claims are outside the scope of the claims, per claim 1 and 15, and amount further to mere non-functional descriptive material in the method claim. When analyzing claims under 101, the broadest reasonable interpretation (BRI) must be applied. Here the claims include only the following additional elements: A client device comprising a processor, a memory and at least one application stored in the memory, a non-transitory computer-readable medium comprising instructions, one or more processors, a Hypertext Transfer Protocol (HTTP) session and a short-range wireless communication channel. There are no other additional elements other than these. The other entities are not considered; i.e. point of sale, first device, etc. because the claims do not focus on these entities and instead attempt to recite language that introduces the entities to try and limit the claims and scope but fail because the entities are not part of the claimed system and none of the entities are recited as positively carrying out any of the claimed limitations. Encoding and decoding data as claimed is high level and does not involve any technical elements that would be deemed additional elements. Capturing data is broad, which could include using any manner to capture the data. However, since the dependent claims recite use of a QR-code, such code is also high level and does not amount to an additional element. The claimed scope, under BRI, can be carried by a human using their brain, and pen-and-paper. The pen-and-paper allow the user to obtain a code or encoded token (code written on paper or verbally spoken), wherein the obtaining of the code is done in the same session with the provider of the code (i.e. another user). Likewise the human mind can be used to decode the code using basic encryption techniques and pen-and-paper. Furthermore, the request can be communicated via verbal or written means and comprises any necessary data before receiving transaction account information that is based on the decoded information and finally to send (via paper or verbally) the transaction account data (i.e. to yet another human). The above clearly describe/capture sales activities/business relations under certain methods of organizing human activity. Assuming arguendo that the abstract idea is not classified under mental processes, it is without question that is falls under certain methods of organizing human activity including commercial interactions such as sales activities and business relations. Therefore, the additional elements are recited at a high level of generality, wherein the claims merely amount to an abstract idea that is implemented using generic computers, performing generic computer functions such as capturing data, analyzing the data, sending data, receiving data, and causing an output. Each of the additional elements / limitations are no more than mere instructions to apply the exception using generic computer components or a generic device. Accordingly, even in combination, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Furthermore, the abstract idea is determined to be generally linked to a particular technological environment, use of bar-codes, high level cryptography, and payment settlement. The claims including the additional elements merely add insignificant extra solution activity to the judicial exception. Likewise, the claims and the additional elements merely link the use of the judicial exception to a particular technological environment or field of use.
The claims do not amount to significantly more than the abstract idea. The dependent claims fail to include any additional elements that would amount to a practical application or significantly more than the abstract idea. The dependent claims further describe the abstract idea.
The rejection is maintained.
Applicant's arguments filed April 23, 2026, regarding claim rejections under 35 U.S.C. 102 have been fully considered but they are not persuasive.
Applicant argues that the reference to Mendes fails to disclosed the claimed scope as a whole. The Examiner notes that the arguments are moot in light of a newly relied upon reference.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-4, 6-13, and 15-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter.
Claims 1-4, 6-13, and 15-20 fall within at least one of the four categories of patent eligible subject matter (process, machine, manufacture, or composition of matter).
Claims 1-4, 6-13, and 15-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea of provisioning transaction account data as a result of manipulating data without significantly more.
The abstract idea is categorized under certain methods of organizing human activity, including commercial interactions such as sales activities and business relations. The relationship between the claimed entity and other entities that provide the information to the entity in order allow the entity to send the transaction account data highlight the abstract idea grouping and subgroupings identified. Furthermore, the claims are clearly directed to using transaction account data, which is evident of a sale activity rooted in commercial interactions. Under BRI, the abstract idea further falls under mental processes, including concepts performed in a human mind such as observation, evaluation, judgement, opinion and carrying out these concepts using pen-and-paper.
Claim 8, in pertinent part, recites:
A method, comprising:
in a same… session in which an application by a user has been approved and a secure provisioning token has been generated indicating a creation of a transaction account for the user and encoded into an encoded token by a first computing device and transmitted to a second computing device for display to the user, capturing, by… the user, the encoded token displayed…;
decoding… the encoded token to obtain a secure provisioning token;
sending… a request for transaction account data associated with a transaction account…, wherein the request comprises a client-provided token that is based on the encoded token;
receiving… the transaction account data in response to the client-provided token being validated, based on a determination that the client-provided token matches the secure provisioning token; and
sending… the transaction account data to a point of sale terminal…
The judicial exception is not integrated into a practical application. The claims recite the following additional elements: A client device comprising a processor, a memory and at least one application stored in the memory, a non-transitory computer-readable medium comprising instructions, one or more processors, a Hypertext Transfer Protocol (HTTP) session and a short-range wireless communication channel. The additional elements are recited at a high level of generality, wherein the claims merely amount to an abstract idea that is implemented using generic computers, performing generic computer functions such as reading, capturing, or receiving data, decrypting or analyzing the data, manipulating data and outputting a result such as sending data. Each of the additional elements / limitations are no more than mere instructions to apply the exception using generic computer components or a generic device. Accordingly, even in combination, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Furthermore, the abstract idea is determined to be generally linked to a particular technological environment, use of bar-codes, high level cryptography, and payment settlement. The claims, including the additional elements, merely add insignificant extra solution activity to the judicial exception. Likewise, the claims and the additional elements merely link the use of the judicial exception to a particular technological environment or field of use.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements amount to merely instructions to apply the exception using generic computer components. The claim limitations do not improve another technology or technical field, improve the functioning of a computer itself, apply the abstract idea with, or by use of, a particular machine (not a generic computer, not adding the words "apply it" or words equivalent to "apply the abstract idea", not mere instructions to implement an abstract idea on a computer, adding insignificant extra solution activity to the judicial exception, generally linking the user of the judicial exception to a particular technological environment or field of use), effects a transformation or reduction of a particular article to a different state or thing, or adds meaningful limitations that amount to more than generally linking the use of the abstract idea to a particular technological environment. Mere instructions to apply an exception using generic computer components cannot provide an inventive concept.
The dependent claims do not include additional elements that integrate the abstract idea into a practical application or that provide significantly more than the abstract idea. The dependent claims fail to recite additional elements that would amount to a practical application or amount to significantly more than the judicial exception as discussed above. For example, the dependent claims include a quick response (QR) code. This is a high-level additional element, which fails to amount to a practical application or significantly more than the abstract idea. The dependent claims further describe the abstract idea.
The claims are not patent eligible.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-4, 6-13, and 15-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Patent Application Publication 2014/0279469 to Mendes (Mendes), in view of U.S. Patent Application Publication 2014/0149293 to Laracey (Laracey).
Per claims 1, 8, and 15, Mendes teaches all of the claim limitations:
A system, comprising: a client device associated with a user, the client device comprising a processor and a memory; and at least one application stored in the memory that, when executed by the client device, causes the client device, in a same Hypertext Transfer Protocol (HTTP) session in which an application by the user has been approved and a secure provisioning token has been generated indicating a creation of a transaction account for the user and encoded into an encoded token by a first computing device and transmitted to a second computing device for display to the user, to [Abstract, Paragraphs 0013-0015, and, 0035, 0051 and 0057 and 0071]:
Examiner notes that the following limitation is outside the scope of the claims: “an application by the user has been approved and a secure provisioning token has been generated indicating a creation of a transaction account for the user and encoded into an encoded token by a first computing device and transmitted to a second computing device for display to the user.” As a result, the limitation has no patentable weight.
capture the encoded token displayed on the second computing device [Abstract, Paragraphs 0055, and 0094]
decode the encoded token displayed on the second computing device (the token is decoded to determine information within the code including secure data and other related unique data that is interpreted as token data such as the hash key) [Paragraph 0094],
send a request for transaction account data associated with a transaction account to a first computing device, wherein the request comprises a client-provided token that is based on the encoded token (the information obtain from the decoding of the code allows for the device to send a request for a funding account, the account information being later received by the device) [Paragraphs 0095-0096],
receive, from the first computing device, the transaction account data in response to the client-provided token being validated, based on a determination that the client-provided token matches the secure provisioning token (account details are received by the device wherein said details are interpreted as the transaction account data received in response to the user providing secure information interpreted as the client provided token data such as a password, pin, etc.) [Paragraphs 0071, and 0098-0099], and
send the transaction account data to a point-of-sale terminal via a short-range wireless communication channel (the communication capable of being carried out by the client device includes short-range communication such as near-field communication, Bluetooth®, and so on, which Mendes teaches as being utilized by the client device to communicate data and that such communication methods are settled in the art) [Paragraphs 0099-0102 and 0006, 0009, 0031, and 0052, and 0093].
Mendes teaches utilizing secure and wireless communication networks to scan, decrypt, and request account information to settle a transaction. However, Mendes does not explicitly disclose an application by the user has been approved and a secure provisioning token has been generated indicating a creation of a transaction account for the user and encoded into an encoded token by a first computing device and transmitted to a second computing device for display to the user, which does not have any patentable weight since it is not positively recited and is outside the scope of the claims.
Laracey teaches an application by the user has been approved and a secure provisioning token has been generated indicating a creation of a transaction account for the user and encoded into an encoded token by a first computing device and transmitted to a second computing device for display to the user [Abstract, Paragraphs 0046, 0052-0060 and claim 1].
It would have been obvious to one of ordinary skill in the art before the effective filing date to combine the teachings of Mendes, as indicated above, to include the teachings of Laracey to utilize the same HTTP session to obtain account related data based on obtained token information in motivation of ensuring that the data is maintained within the same session during processing of the transaction, enhancing security measures.
Per claim 2, 9 and 16, Mendes teaches wherein the encoded token is a quick response (QR) code [Paragraphs 0099-0102 and 0006, 0009, 0031, and 0052, and 0093].
Per claims 3, 13 and 19, Mendes teaches wherein the secure provisioning token comprises at least one of: a first identifier that identifies the at least one application for the transaction account, a second identifier that identifies an approval of the at least one application, or a third identifier that identifies the transaction account created as a result of the approval of the at least one application [Paragraphs 0035, 0090, and 0098-0099].
Per claims 4, 10, and 17, Mendes teaches wherein the transaction data received by the client device is encoded into a two-dimensional code [Paragraphs 0099-0102 and 0006, 0009, 0031, and 0052, and 0093].
Per claims 6, 12, and 20 Mendes teaches wherein the client device receives the transaction account from the second computing device [Paragraphs 0071, and 0098-0099].
Per claims 7, 11, and 18, Mendes teaches wherein the transaction account data comprises at least one of: a transaction account identifier, an expiration date, or a user name [Paragraphs 0094-0098].
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure is listed on for PTO-892.
For instance, see PGPUB 2014/0263618 to McCarthy et al. (McCarthy). McCarthy teaches all of the Applicant’s claimed scope. See Figures 4-5 and related text. It would have been obvious to communicate the account information received from the mobile device to the merchant. Such teachings are well settled in the art and as Mendes teaches, teach away from providing secure transaction capabilities because a fraudster would be able to intercept the data transfer from the user device to the merchant.
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EL MEHDI OUSSIR whose telephone number is (571)270-0191. The examiner can normally be reached M-F 9AM - 5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, NEHA PATEL can be reached on 571-270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Sincerely,
/EL MEHDI OUSSIR/Primary Examiner, Art Unit 3699