CTNF 19/118,103 CTNF 94541 Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. Claim Rejections - 35 USC § 101 07-04-01 AIA 07-04 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1 and 5-12 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. In the instant case, claims 1 and 5-11 are directed to a method and claim 12 is directed to a system. Therefore, these claims fall within the four statutory categories of invention. Claim 1 recites: A method comprising: receiving, by a resource provider computer from a client device , a checkout request for a transaction between a user operating the client device and a resource provider operating the resource provider computer, the resource provider computer and the client device communicating via a first communication channel ; obtaining, by the resource provider computer, a first one-time code ; displaying, by the resource provider computer, the first one-time code to the user on the client device; determining, by the resource provider computer, an indication that the first one-time code matches a second one-time code that was provided by the user through a second communication channel that is different than the first communication channel; and allowing, by the resource provider computer, the transaction to continue based on the determination that the first one-time code matches the second one-time code. (Additional element(s) emphasized in bold) The above claim describes a process for receiving, by a resource provider (e.g. a merchant), a checkout request for a transaction between a user and the resource provider via a first method of communication (e.g. in-person); obtaining a first code; presenting the first code to the user; determining an indication that the first code matches a second code provided by the user via a different method of communication (e.g. via mail); and allowing the transaction to continue based on the determination. Therefore, claim 1 is directed to the abstract idea of transaction verification via multifactor authentication which is grouped within the “certain methods of organizing human activity” grouping of abstract ideas under the “fundamental economic principles and practices) sub-grouping in prong one of step 2A. Accordingly, the claims recite an abstract idea (See MPEP 2106.04). This judicial exception is not integrated into a practical application because, when analyzed under prong two of step 2A (See MPEP 2106.04), the additional elements of the claim such as resource provider computer, client device, communication channels, and one-time codes merely use a computer as a tool to perform an abstract idea. The use of communication channels and one-time codes does no more than generally link the abstract idea to a particular field of use (e.g. electronic transactions) due to reciting such elements at no more than a high level of generality (e.g. the communication channels are merely substitutes for various methods of communication such as in-person, mail, etc.). Finally, the use of processors/computers (resource provider computer, client device) as tools to implement the abstract idea does not integrate the abstract idea into a practical application because it requires no more than a computer performing functions that correspond to acts required to carry out the abstract idea. Accordingly, the additional elements do not impose any meaningful limits on practicing the abstract idea, and the claims are directed to an abstract idea. The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because, when analyzed under step 2B (See MPEP 2106.05), the additional elements of resource provider computer, client device, communication channels, and one-time codes do not amount to significantly more than the abstract idea. As discussed above, taking the claim elements separately, the use of communication channels and one-time codes does no more than generally link the abstract idea to a particular field of use (e.g. electronic transactions) due to reciting such elements at no more than a high level of generality (e.g. the communication channels are merely substitutes for various methods of communication such as in-person, mail, etc.). Finally, the use of resource provider computer and client device does no more than use computers as tools to implement and/or automate the abstract idea (e.g. “apply it”). Viewed as a whole, the combination of elements recited in the claims merely recite the concept of verifying electronic transactions via multifactor authentication. Therefore, the use of these additional elements does no more than employ the computer as a tool to automate and/or implement the abstract idea. The use of a computer or processor to merely automate and/or implement the abstract idea cannot provide significantly more than the abstract idea itself (MPEP 2106.05(I)(A)(f) & (h)). Therefore, the claim is not patent eligible. Dependent claims 5-11 further describe characteristics of data (e.g. types of communication channels, types of one-time codes, etc.) and steps to implement the abstract idea. Furthermore, the additional elements of an authorizing entity computer, Internet and SMS channels, host site, and authentication server do no more than continue to generally link the abstract idea to particular fields of use (e.g. internet and/or SMS) and use computers to implement and/or automate the abstract idea. Accordingly, the dependent claims do not include additional elements that integrate the abstract idea into a practical application or that provide significantly more than the abstract idea. Therefore, the dependent claims are also not patent eligible. The same analysis pertaining to the abstract idea of transaction verification via multifactor authentication holds true for claim 12 as well, with the additional elements of memory and processor merely using a processor/computer as a tool to implement the abstract idea. Therefore, claim 12 is also not patent eligible. The Examiner suggests amending claims 1 and 12 to include the limitations directed to providing the second one-time use code to an authentication server through the second communication device using a mobile device (see claim 2) to overcome the instant rejection. Claim Rejections - 35 USC § 112 07-30-02 AIA The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. 07-34-01 Claims 12-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 12 recites, “ displaying the first one-time code to the user on the client device .” However, claim 12 is explicitly directed to a resource provider computer. It is unclear whether the displaying of the first one-time code is performed by the client device or the resource provider computer. Therefore, the scope of claim 12 is unclear ( In re Zletz, 13 USPQ2d 1320 (Fed. Cir. 1989)). Claim 13 recites, “ comparing , by the authentication server computer, the first one-time code to the second one-time code via a second communication channel .” It is unclear whether the limitation is directed to merely comparing the first one-time code with the second one-time code, wherein the second one-time code is received via a second communication channel. Or whether the limitation is directed to a particular algorithm/process for performing the comparing via a second communication channel. Therefore, the scope of claim 13 is unclear In re Zletz, 13 USPQ2d 1320 (Fed. Cir. 1989)). Claims 14-20 are also rejected due to their dependence on at least claim 13. Claim Rejections - 35 USC § 103 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-23-aia AIA The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 07-20-02-aia AIA This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. 07-21-aia AIA Claim s 1-8, 12-14, 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over Hirson et al. (US 2011/0185406 "Hirson") in view of Bhatnagar et al. (US 2012/0240204 "Bhatnagar") . Regarding claims 1 and 12, Hirson discloses: A method and resource provider computer, comprising: receiving, by a resource provider computer (“server 113”) from a client device (“user terminal 111”), a checkout request for a transaction between a user operating the client device and a resource provider operating the resource provider computer, the resource provider computer and the client device communicating via a first communication channel (Fig. 4, Fig. 7, 0078, 0090, 0093); displaying, by the resource provider computer, the first one-time code to the user on the client device (Fig. 7-9, 0104, 0106, 0138); determining, by the resource provider computer, an indication that the first one-time code matches a second one-time code that was provided by the user through a second communication channel that is different than the first communication channel (Fig. 15, 0138-0140, 0145); and allowing, by the resource provider computer, the transaction to continue based on the determination that the first one-time code matches the second one-time code (Fig. 15, 0107, 0139-0142, 0145). Hirson does not disclose: obtaining, by the resource provider computer, a first one-time code. However, in the same field of endeavor, Bhatnagar discloses: obtaining, by the resource provider computer, a first one-time code (Fig. 6-7, 0052); displaying, by the resource provider computer, the first one-time code to the user on the client device (Fig. 6-7, 0052); determining, by the resource provider computer, an indication that the first one-time code matches a second one-time code that was provided by the user through a second communication channel that is different than the first communication channel (Fig. 6-7, Fig. 9, 0042, 0052-0054); and allowing, by the resource provider computer, the transaction to continue based on the determination that the first one-time code matches the second one-time code (Fig. 6-7, 0053, 0062). It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify claims 1 and 12 disclosed by Hirson by including obtaining the first one-time code by the resource provider computer as disclosed by Bhatnagar. One of ordinary skill in the art would have been motivated to make this modification as a simple substitution of one known element for another to obtain predictable results ( KSR International Co. v. Teleflex Inc. , 550 U.S. 398, 82 USPQ2d 1385 (2007)). Regarding claim 13, Hirson discloses: A method comprising: receiving, by an authentication server computer ("interchange 101") from a resource provider computer ("server 113"), a request for a one-time code, after the resource provider computer receives from a client device ("user terminal 111"), a checkout request for a transaction between a user operating the client device and a resource provider operating the resource provider computer, the resource provider computer and the client device communicating via a first communication channel (Fig. 4, Fig. 8, Fig. 15, 0104, 0106, 0138, 0140); generating, by the authentication server computer, a first one-time code; transmitting, by the authentication server computer, the first one-time code to the client device; receiving, by the authentication server computer, a second one-time code from a mobile device (Fig. 15, 0138, 0145); comparing, by the authentication server computer, the first one-time code to the second one-time code via a second communication channel (Fig. 15, 0104, 0106-0107, 0138-0140). Hirson does not disclose: and transmitting, by the authentication server computer to the resource provider computer, an indication that the first one-time code and the second one- time code match, wherein the resource provider computer thereafter allows the transaction to proceed. However, in the same field of endeavor, Bhatnagar discloses: receiving, by the authentication server computer, a second one-time code from a mobile device (Fig. 6-7, Fig. 9, 0042, 0052-0054); comparing, by the authentication server computer, the first one-time code to the second one-time code via a second communication channel (Fig. 6-7, Fig. 9, 0042, 0052-0054); and transmitting, by the authentication server computer to the resource provider computer, an indication that the first one-time code and the second one- time code match, wherein the resource provider computer thereafter allows the transaction to proceed (Fig. 6-7, Fig. 9, 0042, 0052-0054). It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify claims 13 disclosed by Hirson by including transmitting an indication of successful match to the resource provider computer as disclosed by Bhatnagar. One of ordinary skill in the art would have been motivated to make this modification to allow the resource provider to determine if authentication was successful (Bhatnagar 0053). Regarding claim 2, Hirson in view of Bhatnagar discloses all limitations of claim 1. Bhatnagar further discloses: wherein the indication is received from an authentication server computer in communication with the resource provider computer, wherein the second one-time code was provided by the user to the authentication server computer through the second communication channel using a mobile device (Fig. 6-7, Fig. 9, 0042, 0052-0054). It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify claim 2 disclosed by Hirson in view of Bhatnagar by including an authentication server as disclosed by Bhatnagar. One of ordinary skill in the art would have been motivated to make this modification as a simple substitution of one known element for another to obtain predictable results ( KSR International Co. v. Teleflex Inc. , 550 U.S. 398, 82 USPQ2d 1385 (2007)). Regarding claim 3, Hirson in view of Bhatnagar discloses all limitations of claim 2. Hirson further discloses: wherein the client device includes the mobile device (0050, 0143). Regarding claims 4 and 16, Hirson in view of Bhatnagar discloses all limitations of claims 2 and 13. Bhatnagar further discloses: wherein the client device is a laptop computer and the mobile device is a mobile phone (0038, 0043). Regarding claim 5, Hirson in view of Bhatnagar discloses all limitations of claim 2. Hirson further discloses: generating, by the resource provider computer, an authorization request message ("charge request" Fig. 4, 0078--0080); and transmitting, by the resource provider computer, the authorization request message to an authorizing entity computer for authorization (Fig. 4, 0078-0080, 0107). Regarding claim 6, Hirson in view of Bhatnagar discloses all limitations of claims 1 and 13. Hirson further discloses: wherein the first communication channel is an Internet channel and the second communication channel is an SMS channel (Fig. 1, 0048, 0093, 0156). Bhatnagar also further discloses: wherein the first communication channel is an Internet channel and the second communication channel is an SMS channel (Fig. 9, 0042). Regarding claims 7 and 17, Hirson in view of Bhatnagar discloses all limitations of claims 1 and 13. Hirson further discloses: wherein the first one-time code is a randomly generated code (0104, 0106). Regarding claim 8, Hirson in view of Bhatnagar discloses all limitations of claim 1. Hirson further discloses: wherein the client device communicates with the resource provider computer via a host site on the resource provider computer (Fig. 7, 0054). Regarding claim 14, Hirson in view of Bhatnagar discloses all limitations of claim 13. Hirson further discloses: wherein the first communication channel includes a channel using an interaction application and the second communication channel includes a channel using a service application (Fig. 8, Fig. 15, 0087, 0133-0134). Regarding claim 18, Hirson in view of Bhatnagar discloses all limitations of claim 17. Hirson further discloses: wherein the authentication server computer comprises a one-time code generation module that generates the one-time code (0104, 0106, 0138, 0140). Regarding claim 19, Hirson in view of Bhatnagar discloses all limitations of claim 18. Hirson further discloses: wherein the one-time code generation module comprises a random number generator (0104, 0106). Regarding claim 20, Hirson in view of Bhatnagar discloses all limitations of claim 19. Hirson further discloses: wherein the authentication server computer is operated by an authorizing entity that operates an authorizing entity computer that authorizes the transaction (0052, 0055, 0107) . 07-22-aia AIA Claim s 9-11 are rejected under 35 U.S.C. 103 as being unpatentable over Hirson in view of Bhatnagar as applied to claim 1 above, and further in view of Neuman et al. (US 2016/0294821 "Neuman") . Regarding claim 9, Hirson in view of Bhatnagar discloses all limitations of claim 1. Hirson in view of Bhatnagar does not disclose: wherein obtaining, by the resource provider computer, the first one-time code comprises receiving the first one-time code from an authentication server computer. However, in the same field of endeavor, Neuman discloses: wherein obtaining, by the resource provider computer, the first one-time code ("Qsid/Qcode") comprises receiving the first one-time code from an authentication server computer (Fig. 3, 0107, 0124-0125). It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify claim 9 disclosed by Hirson in view of Bhatnagar by including obtaining the first one-time code from an authentication server by the resource provider computer as disclosed by Neuman. One of ordinary skill in the art would have been motivated to make this modification to maintain and follow user security policies by a trusted third party (Neuman 0071). Regarding claim 10, Hirson in view of Bhatnagar and further in view of Neuman discloses all limitations of claim 9. Bhatnagar further discloses: wherein determining, by the resource provider computer, the indication that the first one-time code matches the second one-time code occurs after the resource provider computer receives the indication from the authentication server computer (Fig. 6-7, Fig. 9, 0053). It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify claim 2 disclosed by Hirson in view of Bhatnagar and Neuman by including receiving an indication of a match from an authentication server as disclosed by Bhatnagar. One of ordinary skill in the art would have been motivated to make this modification as a simple substitution of one known element for another to obtain predictable results ( KSR International Co. v. Teleflex Inc. , 550 U.S. 398, 82 USPQ2d 1385 (2007)). Regarding claim 11, Hirson in view of Bhatnagar discloses all limitations of claim 1. Hirson in view of Bhatnagar does not disclose: wherein obtaining, by the resource provider computer, the first one-time code comprises receiving the first one-time code from an authentication server after the user of the client device enters a credential for an account into the resource provider computer However, in the same field of endeavor, Neuman discloses: wherein obtaining, by the resource provider computer, the first one-time code comprises receiving the first one-time code from an authentication server after the user of the client device enters a credential for an account into the resource provider computer (Fig. 3, 0107, 0124-0125). It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify claim 11 disclosed by Hirson in view of Bhatnagar by including obtaining the first one-time code from an authentication server by the resource provider computer as disclosed by Neuman. One of ordinary skill in the art would have been motivated to make this modification to maintain and follow user security policies by a trusted third party (Neuman 0071) . 07-22-aia AIA Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over Hirson in view of Bhatnagar as applied to claim 13 above, and further in view of Daga et al. (US 2021/0367954 "Daga") . Regarding claim 15, Hirson in view of Bhatnagar discloses all limitations of claim 13. Hirson in view of Bhatnagar does not disclose: determining, by the authentication server computer if a location of the mobile device and the client device match before transmitting the indication to the client device. However, in the same field of endeavor, Daga discloses: determining, by the authentication server computer if a location of the mobile device and the client device match before transmitting the indication to the client device (Fig. 4, 0105-0107). It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify claim 15 disclosed by Hirson in view of Bhatnagar by including location matching as disclosed by Daga. One of ordinary skill in the art would have been motivated to make this modification to detect fraudulent transactions (Daga 0013) . Conclusion 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Courtney et al. (US 20130152176) generally discloses systems and methods for secure authentication utilizing coded challenge/response images (e.g. QR codes) via a client device and mobile device. Kayyidavazhiyil et al. (USP 9805182) generally discloses a technique for authenticating a user to server equipment involving scanning a QR code displayed on a client device by a mobile device. Teller et al. (US 20210312251) generally discloses an apparatus and system for authentication utilizing tokens encoded in machine-readable codes sent to a first device and scanned by a second device. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAYLOR RAK whose telephone number is (571)270-1575. The examiner can normally be reached Monday-Friday 11:00-7:00 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John W Hayes can be reached at (571)-272-6708 . The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /T.R./Examiner, Art Unit 3697 /JOHN W HAYES/Supervisory Patent Examiner, Art Unit 3697 Application/Control Number: 19/118,103 Page 2 Art Unit: 3697 Application/Control Number: 19/118,103 Page 3 Art Unit: 3697 Application/Control Number: 19/118,103 Page 4 Art Unit: 3697 Application/Control Number: 19/118,103 Page 5 Art Unit: 3697