Prosecution Insights
Last updated: August 17, 2026
Application No. 19/086,285

SYSTEMS AND METHODS FOR EXTENDING AUTHENTICATION

Non-Final OA §103
Filed
Mar 21, 2025
Priority
Mar 22, 2024 — provisional 63/569,064
Examiner
WANG, HARRIS C
Art Unit
Tech Center
Assignee
Mastercard International Incorporated
OA Round
1 (Non-Final)
70%
Grant Probability
Favorable
1-2
OA Rounds
2y 5m
Est. Remaining
90%
With Interview

Examiner Intelligence

Grants 70% — above average
70%
Career Allowance Rate
379 granted / 543 resolved
+9.8% vs TC avg
Strong +20% interview lift
Without
With
+20.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 10m
Avg Prosecution
16 currently pending
Career history
560
Total Applications
across all art units

Statute-Specific Performance

§101
11.8%
-28.2% vs TC avg
§103
58.2%
+18.2% vs TC avg
§102
17.4%
-22.6% vs TC avg
§112
9.5%
-30.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 543 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 3, 5-7, 12, 16-18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kamal (US 20150294313) in view of Opushnyev (US 2022/0391908) Regarding Claim 1, Kamal (US 20150294313) teaches a computer-implemented method for extending authentication from a third party, the method comprising: receiving, at a computing device of a processing network, an authentication request associated with a transaction to an account, from an access control server (ACS) (Paragraph [0033] teaches the service platform transmits an authentication request message which is associated with a transaction to the user’s mobile device, also see Fig. 3B), requesting, by the computing device, authentication of a user of the account, from an issuer of the account, at a mobile device (Paragraph [0034] teaches requesting biometric authentication of the user at the user device); receiving, by the computing device, an authentication result, from the mobile device, which is signed by a private key (Paragraph [0035] teaches the authentication response from the user’s mobile device is signed by the user’s private key, also see Fig. 3B); verifying, by the computing device, the signed authentication result, based on a public key associated the mobile device; and returning, by the computing device, the authentication result, to the ACS, in response to the authentication request (Paragraph [0035] teaches validating the signed authentication response using a public key, sending the response confirming the unique entity identifier). Kamal does not explicitly teach the authentication request including an account number for the account; Opushnyev (US 2022/031908) teaches the authentication request including an account number for the account (Paragraph [0025] teaches an authentication request including a “primary account number”); It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the authentication request of Kamal to include an account number an the results would be predictable (i.e. the authentication request would include an account number) Regarding Claim 3, Kamal and Opushnyev teaches the computer-implemented method of claim 1. Opushnyev teaches wherein the application includes a software development kit (SDK) specific to the processing network (Paragraph [0036] teaches an SDK) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the authentication request of Kamal to include an SDK and the results would be predictable (i.e. the application would include an SDK) Regarding Claim 5, Kamal and Opushnyev teaches the computer-implemented method of claim 1. Kamal teaches further comprising: receiving the public key, from the mobile device, via an application included in the mobile device, the application specific to the issuer (Paragraph [0029] teaches a public key credential is stored by an authenticator application in the mobile device) storing the public key for the mobile device in the user profile (Paragraph [0030] teaches registering public key credential for user profile) Opushnyev teaches storing a device ID for the mobile device in the user profile of a data structure (Paragraph [0039] teaches device identifier is stored with an enrolled authenticator) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Kamal and Opushnyev with the method of storing a device ID for the mobile device in the user profile of a data structure and the results would be predictable (i.e. a user profile with a device ID and public key will be stored) Regarding Claim 6, Kamal and Opushnyev teaches the computer-implemented method of claim 5. Kamal teaches further comprising, prior to verifying the signed authentication result, retrieving the public key from a data structure based on a device ID of the mobile device (Paragraph [0036] teaches prior to verifying retrieving the public key). Regarding Claim 7, Kamal and Opushnyev teaches the computer-implemented method of claim 1. Kamal teaches further comprising: identifying one or more registered devices for the account, based on the account number; and returning a list of the identified one or more registered devices to the ACS (Paragraph [0043] teaches identifying a registered user with the mobile device, wherein the ACS can access the database of users); and wherein requesting authentication from the issuer is based on a selection, by the user, of the mobile device from the one or more registered devices (Paragraph [0043] teaches requesting authentication by the user of the registered device). Regarding Claims 12, 14, 16-18 Claims 12, 14, 16-18 are similar in scope to Claims 1, 3, 5-7 and are rejected for a similar rationale. Claim(s) 2, 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kamal (US 20150294313) in view of Opushnyev (US 2022/031908) in further view of Hubbard (US 2017/0063932) Regarding Claim 2, Kamal and Opushnyev teaches the computer-implemented method of claim 1, but does not explicitly teach wherein requesting an authentication notification includes requesting a push notification, from the issuer, to an application included in the mobile device of the user, the application specific to the issuer. Hubbard (US 2017/0063932) teaches requesting an authentication notification includes requesting a push notification, from the issuer, to an application included in the mobile device of the user, the application specific to the issuer (Paragraph [0049] teaches at the time of authentication a push notification containing the transaction details is generated to the mobile device if the user, the notification is from the merchant) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Kamal and Opushnyev with the push notification method of Hubbard and the results would be predictable (i.e. there would be a push authentication notification sent from the issuer to the mobile device) Regarding Claims 13 Claim 13 are similar in scope to Claims 2 and is rejected for a similar rationale. Claim(s) 4, 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kamal (US 20150294313) in view of Opushnyev (US 2022/031908) in further view of Snyder (US 2018/0075437) Regarding Claim 4, Kamal and Opushnyev teaches the computer-implemented method of claim 1, but does not explicitly teach further comprising: receiving, from the issuer, a mapping of the account number to the device ID; and storing the mapping in a user profile associated with the user in a data structure. Snyder (US 2018/0075437) teaches receiving, from the issuer, a mapping of the account number to the device ID; and storing the mapping in a user profile associated with the user in a data structure (Fig. 2, shows a user profile that maps account number to a device ID) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Kamal and Opushnyev with the method of mapping an account number with a device identifier and storing the mapping as a user profile and the results would be predictable (i.e. a user profile with a device ID and account number will be stored) Regarding Claims 15 Claim 15 are similar in scope to Claims 4 and is rejected for a similar rationale. Claim(s) 8, 10-11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kamal (US 20150294313) in view of Opushnyev (US 2022/031908) in further view of Hamid (US 2017/0048257) Regarding Claim 8, Kamal teaches a computer-implemented method for extending authentication from a third party, the method comprising: receiving, at a computing device of a processing network, an authentication request associated with a transaction to an account, from an access control server (ACS) (Paragraph [0033] teaches the service platform transmits an authentication request message to the user’s mobile device, also see Fig. 3B), transmitting, by the computing device, a request for authentication to a mobile device of the user (Paragraph [0034] teaches requesting biometric authentication of the user at the user device), receiving, by the computing device, an authentication result, from the mobile device, which is signed by a private key specific to the processing network (Paragraph [0035] teaches the authentication response from the user’s mobile device is signed by the user’s private key, also see Fig. 3B); verifying, by the computing device, the signed authentication result, based on a public key received from the mobile device, associated with a device ID of the mobile device, and specific to the processing network; and returning, by the computing device, the authentication result, to the ACS, in response to the authentication request (Paragraph [0035] teaches validating the signed authentication response using a public key, sending the response confirming the unique entity identifier) Kamal does not explicitly teach the authentication request including an account number for the account; Opushnyev (US 2022/031908) teaches the authentication request including an account number for the account (Paragraph [0025] teaches an authentication request including a “primary account number”); It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the authentication request of Kamal to include an account number an the results would be predictable (i.e. the authentication request would include an account number) Kamal and Opushnyev do not explicitly teach the authentication request including one of a quick response (QR) code and/or a operating system-based authentication identifier; Hamid (US 2017/0048257) teaches the authentication request including one of a quick response (QR) code and/or a operating system-based authentication identifier (Paragraph [0066] teaches authentication request includes a QR code); It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Kamal and Opushnyev with the method of including a QR code in an authentication request and the results would be predictable (i.e. the authentication code would include a QR code) Regarding Claims 10-11, Claims 10-11 are similar in scope to Claims 5-7 and are rejected for a similar rationale. Claim(s) 9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kamal (US 20150294313) in view of Opushnyev (US 2022/031908) in view of Hamid (US 2017/0048257) in further view of Snyder (US 2018/0075437) Regarding Claim 9, Kamal, Opushnyev, Hamid teaches the method of claim 8 but does not explicitly teach further comprising: receiving, from the issuer, a mapping of the account number to the device ID; and storing the mapping in a user profile associated with the user in a data structure. Snyder (US 2018/0075437) teaches receiving, from the issuer, a mapping of the account number to the device ID; and storing the mapping in a user profile associated with the user in a data structure (Fig. 2, shows a user profile that maps account number to a device ID) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Kamal and Opushnyev with the method of mapping an account number with a device identifier and storing the mapping as a user profile and the results would be predictable (i.e. a user profile with a device ID and account number will be stored) Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to HARRIS C WANG whose telephone number is (571)270-1462. The examiner can normally be reached M-F 9:00-5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, LUU PHAM can be reached at 571-270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HARRIS C WANG/Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Mar 21, 2025
Application Filed
Aug 04, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699805
UNLINKING APPLICATIONS FROM ACCOUNTS
1y 7m to grant Granted Aug 04, 2026
Patent 12695760
ACCESS CONTROL METHOD AND RELATED APPARATUS
2y 11m to grant Granted Jul 28, 2026
Patent 12676841
AUTHENTICATION OF NETWORK REQUEST
4y 6m to grant Granted Jul 07, 2026
Patent 12676795
Disaster recovery for cloud-based private application access
3y 2m to grant Granted Jul 07, 2026
Patent 12671717
NETWORK SECURITY WITH SERVER NAME INDICATION
1y 10m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
70%
Grant Probability
90%
With Interview (+20.0%)
3y 10m (~2y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 543 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month