DETAILED ACTION
The following is a non-final, first office action in response to the application filed August 22, 2025. Claims 1-20 are currently pending and have been examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
1. Claims 6-8 and 15-17 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 6/15 recite, in pertinent part, “in response to determining that the risk score is greater than a risk threshold, authorizing, by the server system, the ongoing transaction.” Claim 7/16, which depends from claim 6/15 and therefore incorporates all of the limitations of claim 6/15, further recites “in response to determining that the risk score is at least equal to a risk threshold, denying, by the server system, the ongoing transaction.”
It is unclear how the server system is configured to process an ongoing transaction when the risk score is greater than the risk threshold. In particular, a risk score that is greater than the risk threshold necessarily also satisfies the condition that the risk score is “at least equal to” the risk threshold. Thus, when the risk score is greater than the risk threshold, claim 6 requires the server system to authorize the ongoing transaction, while dependent claim 7 simultaneously requires the server system to deny the same ongoing transaction.
Accordingly, one of ordinary skill in the art would not be reasonably apprised of the scope of the claimed invention because it is unclear whether an ongoing transaction having a risk score greater than the risk threshold is to be authorized or denied. Therefore, claims 6/15 and 7/16 are indefinite.
The Examiner notes that the Specification appears to indicate that an ongoing transaction is authorized when the risk score is less than the risk threshold, rather than greater than the risk threshold as presently recited in claim 6/15. Accordingly, claim 6/15 may be clarified by amending the limitation:
“in response to determining that the risk score is greater than a risk threshold, authorizing, by the server system, the ongoing transaction”
to recite:
“in response to determining that the risk score is less than a risk threshold, authorizing, by the server system, the ongoing transaction.”
Such an amendment would resolve the inconsistency identified above between claims 6/15 and 7/16, wherein claim 6 presently requires authorization when the risk score is greater than the risk threshold while dependent claim 7 requires denial when the risk score is at least equal to the risk threshold.
Dependent claims 8 and 17 do not act to cure the deficiencies of claims 6 and 15, and are thereby rejected for at least the same rationale.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (abstract idea) without significantly more.
Step 1: Statutory Category
(MPEP § 2106)
Claims 1-20 are directed towards a method and a system, and a computer-readable medium. The claims are directed to a statutory category: a process and a machine, as defined under 35 U.S.C. § 101.
Regarding Claim 1:
Step 2A, Prong One: Judicial Exception – Abstract Idea
(MPEP § 2106.04)
Claim 1 recites the following limitations:
requesting a user consent from a user for obtaining user-related information, the user-related information comprising a plurality of data elements;
receiving the user consent from the user, the user consent indicating consent of the user to access one or more data elements from the plurality of data elements;
accessing the one or more data elements;
accessing local data associated with the user; and
generating a personalized recommendation for the user based, at least in part, on the one or more data elements and the local data.
These limitations, when considered together, recite the concept of obtaining permission to access selected information, obtaining the permitted information and other available information, and evaluating the obtained information to generate a personalized recommendation. The steps of requesting and receiving permission to consider particular information, obtaining the information for which permission has been given, obtaining additional known information, and evaluating the information to formulate a recommendation constitute observations, evaluations, judgments, and opinions that can practically be performed in the human mind or with the aid of pen and paper. For example, a person may ask another person for permission to consider particular personal information, receive permission identifying the information that may be considered, obtain the permitted information and other locally available information regarding the person, and evaluate the information to formulate a personalized recommendation.
Accordingly, these limitations recite a mental process, which is one of the groupings of abstract ideas identified in MPEP § 2106.04(a).
Additionally, to the extent the personalized recommendation concerns products, services, merchants, offers, or other commercial recommendations, the limitations describe marketing or sales activities or behaviors and therefore also implicate certain methods of organizing human activity, specifically commercial interactions.
Step 2A, Prong Two: Integration into a Practical Application
(MPEP § 2106.04(d))
The claim further recites a “server system,” a “decentralized data store,” and a “database associated with the server system.”
These additional elements do not integrate the judicial exception into a practical application. The server system merely performs the abstract information-gathering and evaluation process in a computerized environment. The decentralized data store is recited as the source from which the permitted user-related information is obtained, and the database is recited as the source from which the local user data is obtained. Thus, the data store and database merely provide the information upon which the abstract evaluation is performed.
The claim does not recite a particular manner of implementing the decentralized data store, a particular data structure or protocol for obtaining the data, an improvement to the operation of the server system or decentralized data store, or any other technological improvement. Rather, the server system, decentralized data store, and database are used as tools for obtaining and processing the information necessary to perform the recited abstract idea.
Further, limiting the source of the user-related information to a decentralized data store does not meaningfully limit the judicial exception, but merely limits the technological environment in which the abstract information-gathering and recommendation process is performed. The claim therefore does not reflect an improvement to the functioning of a computer or another technology or technical field, does not apply the judicial exception with a particular machine that is integral to the claim, and does not otherwise apply or use the judicial exception in a meaningful way beyond generally linking its use to a particular technological environment.
Step 2B: Inventive Concept
(MPEP § 2106.05)
The claim is next evaluated to determine whether the additional elements, individually and as an ordered combination, amount to significantly more than the judicial exception.
The additional elements of the server system, decentralized data store, and database amount to no more than generic computer components performing their ordinary functions of requesting, receiving, accessing, storing, and processing data. The claim does not recite any specific technological implementation by which these components perform these functions.
Considering the additional elements as an ordered combination likewise does not add significantly more. The claimed combination merely instructs the generic computer components to perform the abstract process of requesting and receiving permission to use information, obtaining the permitted and locally available information, and using that information to generate a recommendation. The ordered combination does not improve computer functionality or another technology and does not impose any meaningful limitation beyond implementing the abstract idea using generic computer components and data storage systems.
Therefore, the claim is not directed to patent-eligible subject matter under 35 U.S.C. § 101.
Regarding Claims 10 and 19
Independent claims 10 and 19 are parallel in scope to claim 1 and ineligible for similar reasons.
Regarding Claims 2-9, 11-18, and 20
Dependent claims 2-9, 11-18, and 20 merely set forth further embellishments to the abstract idea, and therefore do not confer eligibility on the claimed invention and are ineligible for similar reasons to claim 1.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-4, 10-13, 19, and 20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Lavine et al (US 2021/0390196 A1).
Regarding claims 1, 10, and 19, Lavine discloses a computer-implemented method, comprising:
requesting, by a server system, a user consent from a user for obtaining user-related information from a decentralized data store, the user-related information comprising a plurality of data elements; receiving, by the server system, the user consent from the user, the user consent indicating consent of the user to access one or more data elements from the plurality of data elements stored with the decentralized data store; accessing, by the server system, the one or more data elements from the decentralized data store; (Lavine: Figure 6, 7 - privacy manager, Figure 10B - give us permission to use the data below);
accessing, by the server system, local data associated with the user from a database associated with the server system; and (Lavine: paragraph [0119] - The anonymizing data component 306 may then store the anonymized profiling data (e.g., browsing history, purchase data, etc.) in the data vault 308. This anonymized data may be linked to a personally identifiable data type of the user only if the user permits it.);
generating, by the server system, a personalized recommendation for the user based, at least in part, on the one or more data elements and the local data (Lavine: Figure 8).
Regarding claims 2, 11, and 19, Lavine discloses all of the limitations as noted above in claims 1, 10, and 20. Lavine further discloses wherein requesting the user consent from the user comprises: provisioning, by the server system, a plurality of options on an electronic device associated with the user, each option of the plurality of options corresponding to each data element of the plurality of data elements, wherein the user provides consent to allow the server system to access the one or more data elements from the decentralized data store by selecting one or more options corresponding to the one or more data elements (Lavine: Figure 7 - data preference, data sharing categories, Figure 10B - display area 1036 identifies multiple data categories and the particular user data within them; the user provides permission using a selectable UI element in display area 1034. The example identifies interests such as running/hiking and allows the brand to obtain that information only when permission is selected).
Regarding claims 3 and 12, Lavine discloses all of the limitations as noted above in claims 1 and 10. Lavine further discloses wherein requesting the user consent comprises: generating, by the server system, a user consent request for the user based, at least in part, on a set of predefined rules, the user consent request comprising a list of data requirements that has to be accessed from the decentralized data store; and transmitting, by the server system, the user consent request for requesting the user consent from the user to an electronic device associated with the user (Lavine: Figure 10B - a particular brand requesting access to specified information/categories).
Regarding claims 4 and 13, Lavine discloses all of the limitations as noted above in claims 1 and 10. Lavine further discloses wherein accessing the one or more data elements comprises: transmitting, by the server system, the user consent indicating consent of the user to access the one or more data elements to the decentralized data store, wherein in response to receiving the user consent, the decentralized data store is configured to allow the server system to access the one or more data elements (Lavine: Figure 3C-6, claim 10 - A computer-implemented method to securely access data in a data vault, the method comprising: generating a consent token, wherein the consent token is associated with user data of a user, and wherein the user data is stored in a data vault; recording the consent token on a ledger of a blockchain consent network; determining, based at least in part on the consent token, that a remote system is authorized to access the user data associated with the consent token; and providing access to the user data associated with the consent token to the remote system).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103(a) are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 5 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Lavine et al (US 2021/0390196 A1) in view of Faro et al (US 2012/0296724 A1).
Regarding claims 5 and 14, Lavine discloses all of the limitations as noted above in claims 1 and 10. Lavine does not expressly disclose in response to the user denying the user consent, generating, by the server system, the personalized recommendation for the user based, at least in part, on the local data. Faro discloses in response to the user denying the user consent, generating, by the server system, the personalized recommendation for the user based, at least in part, on the local data (Faro: paragraph [0051] - recommender system 121 receives payment card transaction information 602 comprising purchases previously made by cardholder 22 and generates a listing of merchant recommendations based on the previous transactions of cardholder 22; see FIG. 6; see also FIG. 8, steps 802, 810, 812, and recommendations window 718 of FIG. 7).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the method and apparatus of Lavine to have included in response to the user denying the user consent, generating, by the server system, the personalized recommendation for the user based, at least in part, on the local data, as taught by Faro because it would be a method of making an informed decision (Faro: paragraph [0002]).
Claims 6-9 and 15-18 are rejected under 35 U.S.C. 103 as being unpatentable over Lavine et al (US 2021/0390196 A1) in view of Wiesman (US 2018/0137514 A1).
Regarding claims 6 and 15, Lavine discloses all of the limitations as noted above in claims 1 and 10. Lavine does not expressly disclose receiving, by the server system, a transaction authorization request for an ongoing transaction associated with the user; extracting, by the server system, one or more transaction attributes from the transaction authorization request; generating, by the server system, a risk score associated with the ongoing transaction based, at least in part, on the one or more data elements, the local data, and the one or more transaction attributes; and in response to determining that the risk score is greater than a risk threshold, authorizing, by the server system, the ongoing transaction. Wiesman discloses receiving, by the server system, a transaction authorization request for an ongoing transaction associated with the user; extracting, by the server system, one or more transaction attributes from the transaction authorization request; generating, by the server system, a risk score associated with the ongoing transaction based, at least in part, on the one or more data elements, the local data, and the one or more transaction attributes; and in response to determining that the risk score is greater than a risk threshold, authorizing, by the server system, the ongoing transaction (Wiesman: Figures 1-2, Figures 6-7, paragraph [0044] - authorization/transaction attributes including PAN, amount, merchant identifier, acquirer identifier, transaction date/time and address verification, paragraph [0010] - he computer device is further configured to receive an authorization approval or denial based at least partially on the generated merchant assessment of trustworthiness, and complete the financial transaction based on the received authorization approval or denial).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the method and apparatus of Lavine to have included receiving, by the server system, a transaction authorization request for an ongoing transaction associated with the user; extracting, by the server system, one or more transaction attributes from the transaction authorization request; generating, by the server system, a risk score associated with the ongoing transaction based, at least in part, on the one or more data elements, the local data, and the one or more transaction attributes; and in response to determining that the risk score is greater than a risk threshold, authorizing, by the server system, the ongoing transaction, as taught by Wiesman because it would be improve the risk of fraud (Wiesman: paragraph [0009]).
Regarding claims 7 and 16, Lavine and Wiesman teach or suggest all the limitations of claims 6 and 15 as noted above. Wiesman further discloses in response to determining that the risk score is at least equal to a risk threshold, denying, by the server system, the ongoing transaction (Wiesman: paragraph [0010] - he computer device is further configured to receive an authorization approval or denial based at least partially on the generated merchant assessment of trustworthiness, and complete the financial transaction based on the received authorization approval or denial).
Regarding claims 8 and 17, Lavine and Wiesman teach or suggest all the limitations of claims 6 and 15 as noted above. Wiesman further discloses wherein the user is one of a cardholder or a merchant, and the local data is historical transaction data associated with the user (Wiesman: Figure 2 - 112 server, paragraph [0045] - Server system 112 may be associated with payment network 28. In the example embodiment, server system 112 is associated with a financial transaction processing network, such as payment network 28, and may be referred to as an interchange computer system).
Regarding claims 9 and 18, Lavine discloses all of the limitations as noted above in claims 1 and 10. Lavine does not expressly disclose wherein the server system is a payment server associated with a payment network. Wiesman discloses wherein the server system is a payment server associated with a payment network (Wiesman: Figure 2 - 112 server, paragraph [0045] - Server system 112 may be associated with payment network 28. In the example embodiment, server system 112 is associated with a financial transaction processing network, such as payment network 28, and may be referred to as an interchange computer system).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the method and apparatus of Lavine to have included wherein the server system is a payment server associated with a payment network, as taught by Wiesman because it would be improve the risk of fraud (Wiesman: paragraph [0009]).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US 2022/0261875 A1, Vashisht et al discloses ARTIFICIAL INTELLIGENCE BASED PRODUCT RECOMMENDATION METHODS AND SYSTEMS FOR ENHANCING APPROVALS OF PAYMENT PROCESSING REQUESTS.
US 2012/0109749 A1, Subramanian et al discloses Systems and Methods to Provide Recommendations.
PTO-892 Reference U discloses User consented federated recommender system against personalized attribute inference attack.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KATHLEEN G PALAVECINO whose telephone number is (571)270-1355. The examiner can normally be reached M-F 9-4.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Marissa Thein can be reached at (571) 272-6764. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
KATHLEEN GAGE PALAVECINO
Primary Examiner
Art Unit 3688
/KATHLEEN PALAVECINO/Primary Examiner, Art Unit 3688