Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 3, 5-7, 12, 16-18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kamal (US 20150294313) in view of Opushnyev (US 2022/0391908)
Regarding Claim 1,
Kamal (US 20150294313) teaches a computer-implemented method for extending authentication from a third party, the method comprising:
receiving, at a computing device of a processing network, an authentication request associated with a transaction to an account, from an access control server (ACS) (Paragraph [0033] teaches the service platform transmits an authentication request message which is associated with a transaction to the user’s mobile device, also see Fig. 3B),
requesting, by the computing device, authentication of a user of the account, from an issuer of the account, at a mobile device (Paragraph [0034] teaches requesting biometric authentication of the user at the user device);
receiving, by the computing device, an authentication result, from the mobile device, which is signed by a private key (Paragraph [0035] teaches the authentication response from the user’s mobile device is signed by the user’s private key, also see Fig. 3B);
verifying, by the computing device, the signed authentication result, based on a public key associated the mobile device; and returning, by the computing device, the authentication result, to the ACS, in response to the authentication request (Paragraph [0035] teaches validating the signed authentication response using a public key, sending the response confirming the unique entity identifier).
Kamal does not explicitly teach the authentication request including an account number for the account;
Opushnyev (US 2022/031908) teaches the authentication request including an account number for the account (Paragraph [0025] teaches an authentication request including a “primary account number”);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the authentication request of Kamal to include an account number an the results would be predictable (i.e. the authentication request would include an account number)
Regarding Claim 3,
Kamal and Opushnyev teaches the computer-implemented method of claim 1. Opushnyev teaches wherein the application includes a software development kit (SDK) specific to the processing network (Paragraph [0036] teaches an SDK)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the authentication request of Kamal to include an SDK and the results would be predictable (i.e. the application would include an SDK)
Regarding Claim 5,
Kamal and Opushnyev teaches the computer-implemented method of claim 1. Kamal teaches further comprising: receiving the public key, from the mobile device, via an application included in the mobile device, the application specific to the issuer (Paragraph [0029] teaches a public key credential is stored by an authenticator application in the mobile device)
storing the public key for the mobile device in the user profile (Paragraph [0030] teaches registering public key credential for user profile)
Opushnyev teaches storing a device ID for the mobile device in the user profile of a data structure (Paragraph [0039] teaches device identifier is stored with an enrolled authenticator)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Kamal and Opushnyev with the method of storing a device ID for the mobile device in the user profile of a data structure and the results would be predictable (i.e. a user profile with a device ID and public key will be stored)
Regarding Claim 6,
Kamal and Opushnyev teaches the computer-implemented method of claim 5. Kamal teaches further comprising, prior to verifying the signed authentication result, retrieving the public key from a data structure based on a device ID of the mobile device (Paragraph [0036] teaches prior to verifying retrieving the public key).
Regarding Claim 7,
Kamal and Opushnyev teaches the computer-implemented method of claim 1. Kamal teaches further comprising: identifying one or more registered devices for the account, based on the account number; and returning a list of the identified one or more registered devices to the ACS (Paragraph [0043] teaches identifying a registered user with the mobile device, wherein the ACS can access the database of users); and wherein requesting authentication from the issuer is based on a selection, by the user, of the mobile device from the one or more registered devices (Paragraph [0043] teaches requesting authentication by the user of the registered device).
Regarding Claims 12, 14, 16-18
Claims 12, 14, 16-18 are similar in scope to Claims 1, 3, 5-7 and are rejected for a similar rationale.
Claim(s) 2, 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kamal (US 20150294313) in view of Opushnyev (US 2022/031908) in further view of Hubbard (US 2017/0063932)
Regarding Claim 2,
Kamal and Opushnyev teaches the computer-implemented method of claim 1, but does not explicitly teach wherein requesting an authentication notification includes requesting a push notification, from the issuer, to an application included in the mobile device of the user, the application specific to the issuer.
Hubbard (US 2017/0063932) teaches requesting an authentication notification includes requesting a push notification, from the issuer, to an application included in the mobile device of the user, the application specific to the issuer (Paragraph [0049] teaches at the time of authentication a push notification containing the transaction details is generated to the mobile device if the user, the notification is from the merchant)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Kamal and Opushnyev with the push notification method of Hubbard and the results would be predictable (i.e. there would be a push authentication notification sent from the issuer to the mobile device)
Regarding Claims 13
Claim 13 are similar in scope to Claims 2 and is rejected for a similar rationale.
Claim(s) 4, 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kamal (US 20150294313) in view of Opushnyev (US 2022/031908) in further view of Snyder (US 2018/0075437)
Regarding Claim 4,
Kamal and Opushnyev teaches the computer-implemented method of claim 1, but does not explicitly teach further comprising: receiving, from the issuer, a mapping of the account number to the device ID; and storing the mapping in a user profile associated with the user in a data structure.
Snyder (US 2018/0075437) teaches receiving, from the issuer, a mapping of the account number to the device ID; and storing the mapping in a user profile associated with the user in a data structure (Fig. 2, shows a user profile that maps account number to a device ID)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Kamal and Opushnyev with the method of mapping an account number with a device identifier and storing the mapping as a user profile and the results would be predictable (i.e. a user profile with a device ID and account number will be stored)
Regarding Claims 15
Claim 15 are similar in scope to Claims 4 and is rejected for a similar rationale.
Claim(s) 8, 10-11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kamal (US 20150294313) in view of Opushnyev (US 2022/031908) in further view of Hamid (US 2017/0048257)
Regarding Claim 8,
Kamal teaches a computer-implemented method for extending authentication from a third party, the method comprising:
receiving, at a computing device of a processing network, an authentication request associated with a transaction to an account, from an access control server (ACS) (Paragraph [0033] teaches the service platform transmits an authentication request message to the user’s mobile device, also see Fig. 3B),
transmitting, by the computing device, a request for authentication to a mobile device of the user (Paragraph [0034] teaches requesting biometric authentication of the user at the user device),
receiving, by the computing device, an authentication result, from the mobile device, which is signed by a private key specific to the processing network (Paragraph [0035] teaches the authentication response from the user’s mobile device is signed by the user’s private key, also see Fig. 3B);
verifying, by the computing device, the signed authentication result, based on a public key received from the mobile device, associated with a device ID of the mobile device, and specific to the processing network; and returning, by the computing device, the authentication result, to the ACS, in response to the authentication request (Paragraph [0035] teaches validating the signed authentication response using a public key, sending the response confirming the unique entity identifier)
Kamal does not explicitly teach the authentication request including an account number for the account;
Opushnyev (US 2022/031908) teaches the authentication request including an account number for the account (Paragraph [0025] teaches an authentication request including a “primary account number”);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the authentication request of Kamal to include an account number an the results would be predictable (i.e. the authentication request would include an account number)
Kamal and Opushnyev do not explicitly teach the authentication request including one of a quick response (QR) code and/or a operating system-based authentication identifier;
Hamid (US 2017/0048257) teaches the authentication request including one of a quick response (QR) code and/or a operating system-based authentication identifier (Paragraph [0066] teaches authentication request includes a QR code);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Kamal and Opushnyev with the method of including a QR code in an authentication request and the results would be predictable (i.e. the authentication code would include a QR code)
Regarding Claims 10-11,
Claims 10-11 are similar in scope to Claims 5-7 and are rejected for a similar rationale.
Claim(s) 9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kamal (US 20150294313) in view of Opushnyev (US 2022/031908) in view of Hamid (US 2017/0048257) in further view of Snyder (US 2018/0075437)
Regarding Claim 9,
Kamal, Opushnyev, Hamid teaches the method of claim 8 but does not explicitly teach further comprising: receiving, from the issuer, a mapping of the account number to the device ID; and storing the mapping in a user profile associated with the user in a data structure.
Snyder (US 2018/0075437) teaches receiving, from the issuer, a mapping of the account number to the device ID; and storing the mapping in a user profile associated with the user in a data structure (Fig. 2, shows a user profile that maps account number to a device ID)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Kamal and Opushnyev with the method of mapping an account number with a device identifier and storing the mapping as a user profile and the results would be predictable (i.e. a user profile with a device ID and account number will be stored)
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HARRIS C WANG whose telephone number is (571)270-1462. The examiner can normally be reached M-F 9:00-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, LUU PHAM can be reached at 571-270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HARRIS C WANG/Primary Examiner, Art Unit 2439