Prosecution Insights
Last updated: October 01, 2026
Application No. 19/208,041

SYSTEMS AND METHODS FOR CONSENT MANAGEMENT BY ISSUERS ON BEHALF OF CARDHOLDERS

Final Rejection §101§103
Filed
May 14, 2025
Priority
Oct 01, 2020 — provisional 63/086,082 +3 more
Examiner
SHERR, MARIA CRISTI OWEN
Art Unit
3697
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Mastercard International Incorporated
OA Round
2 (Final)
26%
Grant Probability
At Risk
3-4
OA Rounds
4y 7m
Est. Remaining
40%
With Interview

Examiner Intelligence

Grants only 26% of cases
26%
Career Allowance Rate
108 granted / 411 resolved
-25.7% vs TC avg
Moderate +14% lift
Without
With
+14.2%
Interview Lift
resolved cases with interview
Typical timeline
6y 0m
Avg Prosecution
25 currently pending
Career history
442
Total Applications
across all art units

Statute-Specific Performance

§101
26.1%
-13.9% vs TC avg
§103
43.4%
+3.4% vs TC avg
§102
9.3%
-30.7% vs TC avg
§112
20.8%
-19.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 411 resolved cases

Office Action

§101 §103
9208041 DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office Action is in response to the Applicant’s Amendment filed June 23, 2026. Claims 1-3, 5-9, and 11-18 are pending and under examination in this case. Claims 4 and 10 are currently canceled. Claims 1, 5, and 13 are currently amended. Response to Arguments Applicant's arguments filed June 23, 2026, have been fully considered but they are not persuasive. Applicant argues, regarding claim 1, as currently amended, that the claims recite statutory subject matter. More specifically, Applicant argues CosmoKey Solutions GmbH & Co. KG V. Duo Security LLC, 15 F.4th 1091, 1096 (Fed. Cir. 2021). Examiner respectfully disagrees. The instant case is quite different from Cosmo key. Cosmo key recites transmitting a user identification from the terminal to a transaction partner via a first communication channel, providing an authentication step in which an authentication device uses a second communication channel for checking an authentication function that is implemented in a mobile device of the user, as a criterion for deciding whether the authentication to the transaction shall be granted or denied, having the authentication device check whether a predetermined time relation exists between the transmission of the user identification and a response from the second communication channel, ensuring that the authentication function is normally inactive and is activated by the user only preliminarily for the transaction, ensuring that said response from the second communication channel includes information that the authentication function is active, and thereafter ensuring that the authentication function is automatically deactivated. The instant case, however, recites consent management in behalf of cardholders by issuers through the generation and revocation of access tokens. Applicant further argues Ex Parte Desjardins. In Ex Parte Desjardins, Appeal No. 2024-000567 (PTAB September 26, 2025, Appeals Review Panel Decision) (precedential), the claimed invention was a method of training a machine learning model on a series of tasks. Note that in the instant case the claims are different from those of Desjardins. In this case, the claims recite consent management in behalf of cardholders by issuers through the generation and revocation of access tokens, a process that describes carrying out a commercial or legal interaction/transaction rather than training a machine learning model on a series of tasks. Applicant further argues that the claims are directed to specific improvements in computer (or Blockchain) functionality as in Enfish. (Enfish, LLC v. Microsoft Corp., 822 F.3d 1327, 1335-36 (Fed. Cir. 2016); Data Engine Techs. LLC v. Google LLC, 906 F.3d 999, 1022 (Fed. Cir. 2018). Note that the claims in the instant case are not in any way similar to Enfish (as the claims do not improve the function of the computer itself by providing “increased flexibility, faster search times, and smaller memory requirements” (Enfish at 1690) but merely serves to recite a consent management in behalf of cardholders by issuers through the generation and revocation of access tokens which is an abstract idea, and which is grouped within the "Certain methods of organizing human activity", specifically, "commercial or legal interactions... grouping(s) of abstract ideas because the claims involve data management in prong one of Step 2A (see MPEP 2106). Applicant argues regarding claim 1, as currently amended, that nothing in the cited references teaches, discloses, or suggests, a Bank Identification Number (BIN) mapping table. Examiner respectfully disagrees. Note firstly that a BIN is the first 6 to 8 digits on a credit, debit or prepaid card, which identify the bank or financial institution that issues the card, which are used to route payments, check transaction safety and stop fraud. Attention is directed to Nguyen where “Authorization data manager 40 may store the determined permissions 44 to storage units 34”at col 9 ln 18-22; store a set of permissions that specifies types of account data of one or more financial accounts to share with a third-party, the one or more financial accounts being associated with a user (mapping) and held by a financial institution at col 2 ln 18-22, where account data is equivalent to BIN. Applicant argues regarding claim 1, as currently amended, that nothing in the cited references teaches, discloses, or suggests, a token revocation request. Examiner respectfully disagrees. Attention is directed to Powell at par 167 “de-tokenization” (token revocation) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of token revocation and data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-18 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. In the instant case, claims 1-18 are directed to "a system." Therefore, these claims are directed to one of the four statutory categories of invention. Claims 1-18 are directed to the abstract idea of "consent management on behalf of cardholders by issuers," which is grouped under "Certain Methods of Organizing Human Activity, fundamental economic principles or practices" in prong one of step 2A (See 2019 Revised Patent Subject Matter Eligibility Guidance). Claim 1 recites "receiving a request message including client ID and encrypted transaction card details, decrypting transaction card detail, matching client ID to card details, generating access token, storing the access token, transmitting the token to the issuer, receiving a revocation request message, and disabling access to financial account data. Accordingly, the claim recites an abstract idea (See 2019 Revised Patent Subject Matter Eligibility Guidance). This judicial exception is not integrated into a practical application because, when analyzed under prong two of step 2A (See 2019 Revised Patent Subject Matter Eligibility Guidance), the additional elements of the claim such as "a computing system', "a database", "one or more processors", "a communication interface", "an issuer computing device", "an issuer access token", represent the use of a computer as a tool to perform an abstract idea and/or does no more than generally link the abstract idea to a particular field of use. Therefore, the additional elements do not integrate the abstract idea into a practical application as they do no more than represent a computer performing functions that correspond to (i.e., automate and/or implement) the acts of consent management on behalf of cardholders by issuers. When analyzed under step 2B (See 2019 Revised Patent Subject Matter Eligibility Guidance), the claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception itself. Viewed as a whole, the combination of elements recited in the claims merely describe the concept of consent management on behalf of cardholders by issuers using computer technology (e.g., "one or more processors", "a computing system"). Therefore, the use of these additional elements does no more than employ a computer as a tool to automate and/or implement the abstract idea, which cannot provide significantly more than the abstract idea itself (MPEP 2106.05(1) (A) (f) & (h)). Dependent claims 2-18, which depend from claim 1, do not remedy the deficiencies of the independent claim and are rejected accordingly. The dependent claims further refine the abstract idea, consent management on behalf of cardholders by issuers of the independent claims. The dependent claims do not recite any additional elements which when analyzed individually, and as an ordered combination with the other dependent claims, do not amount to significantly more. Claims 2-18 further use a computer performing functions that correspond to (i.e., automate and/or implement) the acts of consent management on behalf of cardholders by issuers. In this case, all claims have been reviewed and are found to be substantially similar and linked to the same abstract idea, "consent management on behalf of cardholders by issuers. (see Content Extraction and Transmission LLC V. Wells Fargo (Fed. Cir. 2014)). Hence, claims 1-18 are not patent eligible. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-18 are rejected under 35 U.S.C. 103 as being unpatentable over Nguyen et al (US 10,692,138) in view of Powell et al (US 2015/0127547). Regarding claim 1 – Nguyen discloses a computing system comprising: an issuer assets database storing a Bank Identification Number (BIN) mapping table; (“Authorization data manager 40 may store the determined permissions 44 to storage units 34”at col 9 ln 18-22; store a set of permissions that specifies types of account data of one or more financial accounts to share with a third-party, the one or more financial accounts being associated with a user and held by a financial institution at col 2 ln 18-22) a token mapping database storing a data mapping table that includes token-to-card mapping data; (“Authorization data manager 40 may store the determined permissions 44 to storage units 34”at col 9 ln 18-22; store a set of permissions that specifies types of account data of one or more financial accounts to share with a third-party, the one or more financial accounts being associated with a user and held by a financial institution at col 2 ln 18-22) a consents database storing cardholder consent data; (“store a set of permissions that specifies types of account data of one or more financial accounts to share with a third-party, the one or more financial accounts being associated with a user and held by a financial institution at col 2 ln 18-22, “user may define the set of permission such that account data from only particular accounts (e.g., a checking account, a savings account, a brokerage account, a mortgage account, a credit card account, or the like) is shared with third-parties” col 5 ln 10-16); “types of account data include types of accounts that are associated with the user (e.g., checking account XXXX1234, savings account XXXX5678, a credit card account XXXX9101, and a mortgage account XXX1213)” col 11 ln 4-10) a communication interface; (col 6 ln 10-20) one or more processors coupled to the issuer assets database, the token mapping database, the consents database, and the communication interface (col 2 ln 18-37); and a memory comprising computer-executable instructions therein, (col 2 ln 18-37) which when executed by the one or more processors, cause the one or more processors to perform operations comprising: receiving, via the communication interface, a request message from an issuer computing device requesting provisioning of an issuer access token, the request message including a client identifier (ID) col 2 ln 18-37, col 9 ln 35-53) and encrypted transaction card details for a transaction card account associated with an issuer (col 10 ln 45-50, claim 1); decrypting the encrypted transaction card details (col 10 ln 45-50, claim 1); matching the client ID to the transaction card details using the BIN mapping table; (col 9 ln 35-53) confirming, based on the matching, that the transaction card account is associated with the issuer identified by the client ID; (col 9 ln 35-53) in response to the confirming, generating the issuer access token associated with the transaction card account; (col 9 ln 18-35); storing the issuer access token in the token mapping database, including storing data that maps the issuer access token, via the transaction card account, to a digital access token previously generated for a third-party provider (TPP); (col 9 ln 18-35) transmitting, via the communication interface, the issuer access token to the issuer computing device. (abs, -- where authorization data is included in a token) Powell teaches, as Nguyen does not, a token revocation request message from the issuer computing device, the token revocation request message including the issuer access token; (par 167 “detokenization”), in response to the token revocation request message, identifying, using the data mapping table, the digital access token mapped to the issuer access token via the transaction card account, and disabling access to financial account data associated with the transaction card account (par 190) by, one of: suspending the digital access token by updating a token status in the data mapping table; (par 190 “The token service provider may indicate to the payment network when the tokens that have been deemed as lost/stolen have been marked as suspended. The token service provider may validate the token in an incoming authorization message against data elements, including token requestor ID, and provide the result to the payment network regarding the validity of the token within the token domain restriction controls. If the PAN is deemed compromised or at risk by the payment network or the issuer, the token service provider may notify the relevant token requestors of the compromise, and deactivate the associated tokens mapped to the PAN. The token service provider may continue to add and implement such capabilities as the use cases for lifecycle management of the token and PAN continue to evolve”) or deleting the digital access token from the data mapping table. (par 190) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 2 – Powel discloses storing the issuer access token comprises storing the issuer access token in the data mapping table, wherein the token-to-card mapping data includes data mapping the issuer access token to the transaction card account. (par 72) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 3 – Powel discloses wherein the data mapping table further includes data that maps the transaction card account to the digital access token, the digital access token associated with the cardholder consent data stored in the consents database. (par 72) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 5 – Powell discloses receiving, via the communication interface, a consents retrieval message from the issuer computing device, the consents retrieval message including the issuer access token. (par 72) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 6 – Powell discloses checking the token data mapping table using the issuer access token received with the consents retrieval message; (par 91) and identifying the digital access token mapped to the issuer access token via the transaction card account. (par 91) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 7 – Powell discloses retrieving third party provider (TPP) ID data associated with the digital access token and the cardholder consent data associated with the digital access token from the consents data mapping table. (par 91, 73) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 8 – Powell discloses wherein the cardholder consent data includes one or more of the following: consent parameters granted to the TPP; terms and conditions agreed to with the TPP; date and time of creation of the digital access token; and expiry date and time of the digital access token. (par 121, 109) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 9 – Nguyen discloses transmitting the TPP ID data and the cardholder consent data to the issuer computing device. (par 10 ln 45-50) Regarding claim 11 – Powell discloses receiving, via the communication interface, a watch account message from the issuer computing device, the watch account message including the issuer access token. par 72) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 12 – Powell discloses checking the data mapping table using the issuer access token received with the watch account message to identify the corresponding transaction card account; (par 91) and setting a watch flag in the data mapping table corresponding to the transaction card account, the watch flag indicating that the issuer is to be notified of any digital access token activity associated with the transaction card account. (par 91) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 13 – Powell discloses transmitting a notification message to the issuer computing device indicating that the watch flag is set in the data mapping table. (par 50) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 14 – Nguyen discloses receiving, via the communication interface, a digital access token generation request message from a third party provider (TPP) computing device. (col 2 ln 18-37, col 9 ln 35-53) Regarding claim 15 – Powell discloses reading the watch flag corresponding to the transaction card account; (par 167) and transmitting a watch notification message to the issuer computing device. (par 167) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Regarding claim 16 – Nguyen discloses transmitting a notification to the issuer computing device before generating a requested access token requested by the TPP computing device. (col 10 ln 45-50) Regarding claim 17 – Nguyen discloses receiving an authorization response from the issuer computing device, the authorization response declining to authorize the generation of the requested digital access token; (col 9 ln 18-35), and declining to generate the requested access token for the requesting TPP computing device. (col 9 ln 18-35), Regarding claim 18 – Nguyen discloses generating the digital access token; (col 9 ln 18-35), adding the digital access token to the token mapping database; (col 9 ln 18-35) and Powell discloses adding any related consent data to the consents database. (par 72) It would be obvious to one of ordinary skill in the art to combine Powell and Nguyen, as both are in the area of secure data exchange, with the added security of data encryption as in Nguyen (col 10 ln 45-50) and the token deletion/management of Powell for greater security. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Magary et al (US 2001/0056387) disclose a method and apparatus for providing financial transaction data via the internet THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CRISTINA OWEN SHERR whose telephone number is (571)272-6711. The examiner can normally be reached 8:30 - 5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John W Hayes can be reached at 571-272-6708. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Cristina Owen Sherr/Examiner, Art Unit 3697 /JOHN W HAYES/Supervisory Patent Examiner, Art Unit 3697
Read full office action

Prosecution Timeline

May 14, 2025
Application Filed
Mar 23, 2026
Non-Final Rejection mailed — §101, §103
Jun 23, 2026
Response Filed
Sep 21, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705606
Transfer Transaction Blockchain with Clawback Apparatuses, Processes and Systems
2y 11m to grant Granted Aug 11, 2026
Patent 12632911
OFF-CHAIN ABSTRACTION MECHANISM FOR DISTRIBUTING NON-FUNGIBLE TOKENS IN AN EDUCATIONAL ENVIRONMENT
4y 1m to grant Granted May 19, 2026
Patent 12619965
COMBINED SHUTTER AND USER INTERFACE PIN ENTRY
2y 4m to grant Granted May 05, 2026
Patent 12511641
SELECTION OF DIGITAL PROPERTIES FOR TRANSACTIONS
5y 10m to grant Granted Dec 30, 2025
Patent 12475452
Automated Transactions Across Multiple Blockchains with Cryptocurrency Swaps
3y 10m to grant Granted Nov 18, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
26%
Grant Probability
40%
With Interview (+14.2%)
6y 0m (~4y 7m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 411 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month