DETAILED ACTION
Status of the Claims
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The following is in response to an application dated April 22, 2025. Claims 1-20 are pending. All pending claims are examined.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (abstract idea) without significantly more. The claim recites an abstract idea of organizing human activities. This judicial exception is not integrated into a practical application and the claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Analysis
The claims are directed to one or more of the following statutory categories: a process, a machine, a manufacture, and a composition of matter.
Independent Claim 1, which is illustrative of the independent claim includes claim 10 and recites:
1. A method comprising:
receiving, by a service provider computer from a security device, a biometric sample of a user or a biometric template thereof;
matching, by the service provider computer, the biometric sample or the biometric template to a user account, thereby authenticating the user;
providing, by service provider computer, to a token service computer, a request for an access token;
receiving, by the service provider computer from the token service computer, the access token; and
transmitting, by the service provider computer to the security device, the access token and supplemental information associated with the user account, wherein the security device displays the supplemental information and passes the access token to an access device, which generates an authorization request message comprising the access token and transmits the authorization request message to a processing network computer.”
The invention as claimed is directed to a process of identity verification (see App Spec. paras. 0001-0006).
This is a method of organizing human activity that is commercial or legal interactions (including agreements in the form of contracts; legal obligations; advertising, marketing or sales activities or behaviors; business relations), whereby transaction details are exchanged between transacting parties or sources to verify the identity of the user.
Besides reciting the abstract idea, the remaining claim limitations recite generic computer components (computer and security device - see App. specification, paras. 0069-0073). This recited abstract idea is not integrated into a practical application. In particular, the claim only recites generic computer components (e.g. computer, security device) for the exchange of data between the transacting parties.
The additional elements are recited at a high-level of generality such that they amount to no more than mere instructions to apply the exception using generic components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Therefore, the claim is directed to an abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements - (e.g. computer, security device) amount to no more than mere instructions to apply the abstract idea using generic computer components.
Further, the dependent claims 2-9 and 11-20 for example, recite additional descriptive details about the criteria applied to the account user identity verification process, however the recited abstract idea is not integrated into a practical application. In particular, the claims only recite generic computer components (e.g. general-purpose computer) to evaluate the submitted data based on predefined conditions.
For example, claims 2-35 provide additional details on the factors or elements that are used in the process of verifying the identity of transacting parties. The dependent claims provide additional descriptions of the components/elements of the claimed invention in a manner that merely refines and further limits the abstract idea of independent claims 1 and 10 and does not add any feature that is an “inventive concept” which cures the deficiencies of the independent claims.
None of the additional elements taken individually or when taken as an ordered combination amount to significantly more than the abstract idea. Accordingly, the dependent claims are patent-ineligible.
In conclusion, merely “applying” the exception using generic computer components cannot provide an inventive concept. Therefore, the claims 1-20 are not patent eligible under 35 USC 101.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3-4, 8, 11, 13 and 16-19 are rejected under 35 U.S.C. 103 as being unpatentable over Ravinathan, USP Pub. No. 20210406904 in view of Bennett, USP Pub. No. 20190370802.
As to claim 1, Ravinathan discloses A method comprising:
receiving, by a service provider computer from a security device, a biometric sample of a user or a biometric template thereof (Ravinathan, paras. 0034-0037; Figs. 3.5);
matching, by the service provider computer, the biometric sample or the biometric template to a user account, thereby authenticating the user (Ravinathan, paras. 0034-0037; Figs. 3.5);
Ravinathan does not directly disclose but Bennett discloses providing, by service provider computer, to a token service computer, a request for an access token (Bennett, paras. 0003-0017-0020, Figs. 4-5);
receiving, by the service provider computer from the token service computer, the access token (Bennett, paras. 0017-0020; Figs. 4-5) and
transmitting, by the service provider computer to the security device, the access token and supplemental information associated with the user account, wherein the security device displays the supplemental information and passes the access token to an access device, which generates an authorization request message comprising the access token and transmits the authorization request message to a processing network computer(Bennett, paras. 0020-0024, 0046; see also paras. 0003 and 0017; Figs. 4-5).
It would have been obvious to one skilled in the art before the effective filing date of the claimed invention to modify Ravinathan with Bennett because it provides a seamless way of executing a transaction in a manner that minimizes the exposure of the transacting parties underlying information.
As to claim 3, Ravinathan does not directly disclose but Bennett discloses the method of claim 1, wherein the access token has a same format as a credential (Bennett, paras. 0003, 0017-0020; Figs. 4-5 – see rationale for combination in claim 1).
As to claim 4, Ravinathan does not directly disclose but Bennett discloses the method of claim 1, wherein the security device is programmed to generate an interaction cryptogram by encrypting a transaction amount and an unpredictable number from the access device, and the access token using a cryptographic key, and is programmed to pass the interaction cryptogram to the access device, wherein the authorization request message includes the interaction cryptogram(Bennett, paras. 0017-0024 – see rationale for combination in claim 1).
As to claim 8, Ravinathan discloses the method of claim 1, wherein the access device comprises a POS terminal ((Ravinathan, paras. 0055-0058; see also paras. 0016, 0031).
Claims 11, 13 and 16-19 are similar to claims 1, 3-4 and 8 and are rejected in like manner.
Claims 2, 5-7 and 9-10, 12, 14-15 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Ravinathan, USP Pub. No. 20210406904 in view of Bennett, USP Pub. No. 20190370802 in further view of Guereque, USP Pub. No. 20240330909
As to claim 2, Ravinathan and Bennett do not directly disclose but Guereque discloses the method of claim 1, wherein the supplemental information comprises information that relates to an age of the user (Guereque, paras. 0030-0033. 0053)
It would have been obvious to one skilled in the art before the effective filing date of the claimed invention to modify Ravinathan and Bennett with Guereque because it offers different levels of access verification thereby adding an additional layer of security for digital information necessary executing a transaction.
As to claim 5, Ravinathan and Bennett do not directly disclose but Guereque discloses the method of claim 4, wherein the cryptographic key is a limited use key(Guereque, para. 0053 – see rationale for combination in claim 2).
As to claim 6, Ravinathan and Bennett do not directly disclose but Guereque discloses the method of claim 1, wherein at least a portion of the supplemental information associated with the user account is used to determine whether a transaction associated with the authorization request message is to be authorized (Guereque, para. 0030-0032 – see rationale for combination in claim 2).
As to claim 7, Ravinathan and Bennett do not directly disclose but Guereque discloses the method of claim 1, wherein the security device is further programmed to delete the access token within a predetermined period of time after transmitting the access token to the access device(Guereque, para. 0053 – see rationale for combination in claim 2).
As to claim 9, Ravinathan and Bennett do not directly disclose but Guereque discloses the method of claim 1, wherein the supplemental information comprises biological information about the user(Guereque, paras. 0030-0032 – see rationale for combination in claim 2).
As to claim 10, Ravinathan and Bennett do not directly disclose but Guereque discloses the method of claim 1, wherein the supplemental information comprises a photograph(Guereque, paras. 0030-0032 – see rationale for combination in claim 2).
As to claims 12, 14-15 and 20 contain limitations similar to claims 2, 5-7, 9-10 and are rejected in like manner.
biometric sample of a user or a biometric
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHIKA OJIAKU whose telephone number is (571)270-3608. The examiner can normally be reached Monday - Friday: 8.30 AM -5:00 PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Matthew Gart can be reached at 571 272-3955. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHIKAODINAKA OJIAKU/Primary Examiner, Art Unit 3696