DETAILED ACTION
Acknowledgments
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This action is in reply to the application filed on 12/31/2025.
Claims 1-20 are currently pending and have been examined.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-patent eligible subject matter because the claim(s) as a whole, considering all claim elements both individually and in combination, do not amount to significantly more than an abstract idea.
Step 1:
The claims recite a process, system, apparatus, article of manufacture, and/or a nontransitory storage medium with instructions, each of which are proper statutory categories.
Step 2A (prong 1):
Claim 1 (representative of claims 8 and 15):
The claim limitations are grouped as shown immediately following:
starting, by a service client in a user terminal in an authorization system, an acquiring institution software package in response to an authorization request of a user, (Certain Methods Of Organizing Human Activity - business relations or interactions between people including and following rules or instructions)
wherein the service client is installed in the user terminal, and wherein the service client comprises the acquiring institution software package; (Certain Methods Of Organizing Human Activity - business relations or interactions between people including and following rules or instructions)
obtaining, by the acquiring institution software package, risk control data of the service client; (Certain Methods Of Organizing Human Activity - business relations or interactions between people including and following rules or instructions)
sending the risk control data to the electronic wallet server through the acquiring institution server, (Certain Methods Of Organizing Human Activity - business relations or interactions between people including and following rules or instructions)
wherein the electronic wallet server determines a risk level of the authorization request based on the risk control data and sends the risk level to the acquiring institution software package through the acquiring institution server; (Certain Methods Of Organizing Human Activity - business relations or interactions between people including and following rules or instructions)
receiving, by the acquiring institution software package, the risk level; (Certain Methods Of Organizing Human Activity - business relations or interactions between people including and following rules or instructions)
executing an authorization procedure corresponding to the risk level. (Certain Methods Of Organizing Human Activity - business relations or interactions between people including and following rules or instructions)
Additional dependent claims 2-7, 9-14, and 16-20 do not appear remedy the deficiency.
Step 2A (prong 2):
Claim 1 (representative of claims 8 and 15):
wherein the authorization system comprises the user terminal, an acquiring institution server, and an electronic wallet server,
These remaining claim limitations are delineated as shown immediately preceding. The abstract idea is not integrated into a practical application. There are no improvements to the functioning of a computer, other technology or technical field, a particular machine is not cited, nothing is transformed to a different state or thing, the abstract idea is not more than a drafting effort designed to monopolize the abstract idea. The claim merely uses a computer as a tool to perform the abstract idea, which is generally linked to a particular field of use, in this case, marketing and advertising. Thus, these limitations are recited at a high-level of generality (i.e., as a generic processor and memory performing a generic computer function of processing and storing data) such that it amounts no more than mere instructions to apply the exception using a generic computer component – MPEP 2106.05(f). Further, receiving data, evaluating data and distributing data are data gathering and data outputting, which has no effect on technology and does no more than generally link the use of the judicial exception to a particular technological environment or field of use – see MPEP 2106.05(h).
Step 2B:
The claim limitations do not provide an Inventive Concept. The claim limitations do not recite additional elements that amount to significantly more that the abstract idea because the additional elements of the system comprising a computer processor, computer readable storage medium with instructions, and a memory configured to store information, each recited at a high level of generality in a computer network which only perform the universal computer functions of accessing, receiving, storing, and processing data, transmitting and presenting information. Taking the elements both individually and as an ordered combination, the function performed by the computer at each step of the process is purely orthodox. Using a computer to obtain and display data are some of the most basic functions of a computer. As shown, the individual limitations claimed are some of the most rudimentary functions of a computer. The technical solution described in this invention does not alter hardware structure or its routine, does not transform the character of the information being processed, does not identify a novel source or type of data, does not advance the functionality of a computer as a tool, and does not incorporate specific rules enabling the computer to accomplish innovative utilities. In summary, the individual step and/or component does no more than require a general computer to perform standard computer functions. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of a computer devices amounts to no more than mere instructions to apply the exception using a generic computer component - requiring the use of software to tailor information and provide it to the user on a generic computer, Intellectual Ventures I LLC v. Capital One Bank (USA), 792 F.3d 1363, 1370-71, 115 USPQ2d 1636, 1642 (Fed. Cir. 2015).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under U.S.C. 103 as being unpatentable over Carpenter et al. (USPGP 2016/0086184 A1), hereinafter CARPENTER.
Claims 1, 8, 15:
CARPENTER as shown below discloses the following limitations:
starting, by a service client in a user terminal in an authorization system, an acquiring institution software package in response to an authorization request of a user, (see at least paragraphs 0044, 0049, 0069, 0070)
wherein the authorization system comprises the user terminal, an acquiring institution server, and an electronic wallet server, wherein the service client is installed in the user terminal, and wherein the service client comprises the acquiring institution software package; (see at least paragraphs 0044, 0049, 0069, 0070; Figures 1, 2 as well as associated and related text)
obtaining, by the acquiring institution software package, risk control data of the service client; (see at least paragraphs 0009, 0011, 0013, 0098)
sending the risk control data to the electronic wallet server through the acquiring institution server, (see at least Figure 3 as well as associated and related text)
wherein the electronic wallet server determines a risk level of the authorization request based on the risk control data and sends the risk level to the acquiring institution software package through the acquiring institution server; (see at least Figure 3 as well as associated and related text)
receiving, by the acquiring institution software package, the risk level; (see at least Figure 3 as well as associated and related text)
executing an authorization procedure corresponding to the risk level. (see at least Figures 4, 5 as well as associated and related text)
CARPENTER does not specifically disclose each of the above limitations within a single embodiment. In this case, each of the elements claimed are all shown by the prior art of record but not combined as claimed. However, the technical ability exists to combine the elements as claimed and the results of the combination are predictable. Therefore, when combined, the elements perform the same function as they did separately. (KSR v. Teleflex, 127 S. Ct. 1727 (2007)). Consequently, it would have been obvious to one of ordinary skill in the art at the effective filing date to combine/modify the method of CARPENTER because, “One major concern in provisioning credentials to user devices is whether the payment account that is being provisioned on the device belongs to the rightful owner of the device. This may happen when an unauthorized person tries to provision a payment card on his/her device. The payment card may have been reported stolen or may have been given to the person by the rightful owner for other purposes, e.g. for payment at a merchant location.” (CARPENTER: paragraph 0007). Additionally, there is a recognized problem or need in the art including market pressure, design need, etc., and there are a finite number of identified predictable solutions. Accordingly, those in the art could have pursued known solutions with reasonable expectation of success. (KSR v. Teleflex, 127 S. Ct. 1727 (2007)). Fundamentally, in the competitive business climate, there is a profit-driven motive to maximize the profitability of goods and services that are provided or marketed to customers. Enterprises typically use business planning to make decisions in order to maximize profits.
Claims 2, 9, 16:
CARPENTER discloses the limitations as shown in the rejections above. CARPENTER further discloses the following limitations:
wherein, when the risk level is less than a preset level, the executing an authorization procedure corresponding to the risk level, comprises:
receiving an original authentication code sent by the electronic wallet server by using an SMS message;
displaying, by the acquiring institution software package, an authentication code input box in the service client;
obtaining a submitted authentication code entered by the user;
sending a token application to the electronic wallet server through the acquiring institution server,
wherein the token application comprises the submitted authentication code, so that the electronic wallet server determines whether the submitted authentication code is consistent with the original authentication code;
receiving, by the service client, an authorization result of the electronic wallet server.
See at least paragraphs 0011, 0034, 0038, 0062, and 0118.
Claims 3, 10, 17:
CARPENTER discloses the limitations as shown in the rejections above. CARPENTER further discloses the following limitations:
wherein: an electronic wallet client is further installed in the user terminal;
when the risk level is not less than a preset level, the executing an authorization procedure corresponding to the risk level comprises:
invoking, by the acquiring institution software package, the electronic wallet client;
displaying, by the electronic wallet client, an authentication page, to notify the user of authorization information, and notify the user to enter authentication information;
obtaining, by the electronic wallet client, submitted authentication information entered by the user; s
ending the submitted authentication information to the electronic wallet server, so that the electronic wallet server performs identity authentication based on the submitted authentication information;
receiving, by the service client, an authorization result of the electronic wallet server.
See at least paragraphs 0011 and 0013.
Claims 4, 11, 18:
CARPENTER discloses the limitations as shown in the rejections above. CARPENTER further discloses the following limitations:
wherein, when the risk level is less than a preset level:
receiving, by the acquiring institution software package, a risk score sent by the electronic wallet server; determining the risk level and an authentication method, wherein the risk score is determined by the electronic wallet server based on the risk control data, and the authentication method is at least one of password authentication, SMS message authentication, fingerprint authentication, and facial recognition authentication;
displaying, by the acquiring institution software package, an authentication page corresponding to the authentication method, to notify the user to enter authentication information;
obtaining submitted authentication information that corresponds to the authentication method and that is entered by the user; sending, by the acquiring institution software package, a token application to the electronic wallet server through the acquiring institution server, wherein the token application comprises the submitted authentication information, so that the electronic wallet server determines whether the submitted authentication information is consistent with original authentication information corresponding to the authentication method;
receiving, by the service client, an authorization result of the electronic wallet server.
See at least paragraphs 0011, 0013, and 0134.
Claims 5, 12, 19:
CARPENTER discloses the limitations as shown in the rejections above. CARPENTER further discloses the following limitations:
wherein: an electronic wallet client is further installed in the user terminal;
when the risk level is not less than the preset level:
invoking, by the acquiring institution software package, the electronic wallet client.
See at least paragraphs 0063, 0129-0131, and 0134.
Claims 6, 13, 20:
CARPENTER discloses the limitations as shown in the rejections above. CARPENTER further discloses the following limitations:
wherein, when the risk level is not less than the preset level:
displaying, by the electronic wallet client, an authentication page corresponding to the authentication method, to notify the user of authorization information, and notify the user to enter authentication information.
See at least paragraphs 0063, 0129-0131, and 0134.
Claims 7, 14:
CARPENTER discloses the limitations as shown in the rejections above. CARPENTER further discloses the following limitations:
wherein when the risk level is not less than the preset level:
obtaining, by the electronic wallet client, the submitted authentication information that corresponds to the authentication method and that is entered by the user;
sending the submitted authentication information to the electronic wallet server, so that the electronic wallet server determines whether the submitted authentication information is consistent with original authentication information corresponding to the authentication method;
receiving, by the service client, the authorization result of the electronic wallet server.
See at least paragraphs 0011, 0013, and 0134.
CONCLUSION
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Non-Patent Literature:
Jin Lim et al. “Comparative Analysis of Security Features and Risks in Digital Asset Wallets”. (15 June 2025). Retrieved online 08/19/2026. Comparative Analysis of Security Features and Risks in Digital Asset Wallets
Relevancy: “This paper examines the concepts, technologies, and services of various types of electronic wallets and compares and analyzes their security features. Additionally, it presents specialized security threats through cases of breaches of key information that need to be managed according to the type of electronic wallet. One of the main contributions of this paper is that, unlike existing studies, it provides explanations and discussions encompassing both traditional e-wallets and cryptocurrency-based wallets. It identifies and insightfully examines the functions of electronic wallets according to the type of digital asset while also incorporating scenario-based quantitative analysis to assess how effectively certain security requirements mitigate identified risks. In particular, the classification of wallet types in this paper is based on an analysis of the existing literature that has studied the services, functionality, and security of each wallet. Through this, we suggest a future direction for universal wallets by highlighting critical security requirements that may arise when identity (ID), payment, and cryptocurrency services converge in a single interface. Rather than proposing an exhaustive universal wallet architecture, this paper focuses on key technical elements that future e-wallet environments should consider to withstand the multifaceted threat landscape posed by integrated digital asset management.” (Abstract/Introduction)
Adi Badiozaman Ruhani et al. “Modelling Security Factors Influencing E-Wallet Adoption in Malaysia.” (2024). Retrieved online 08/19/2026. Modelling Security Factors Influencing E-Wallet Adoption in Malaysia
Relevancy: “This study aims to develop an effective framework that addresses the security concerns and user behavior related to e-wallet adoption. The research methodology entails quantitative data collection through a literature review and surveys of e-wallet users using convenience sampling, and the proposed model is tested using the Partial Least Squares Structural Equation Modelling (PLS-SEM). The proposed security factors in this study include phone stolen protection, app security performance, secure authentication, data privacy protection, secure online transaction and banking info security. The online survey form was disseminated to Malaysian citizens, and 186 respondents participated in the survey. Using a two-step approach, this study employed a measurement model to assess indicator loadings, convergent validity, and reliability. Additionally, a structural model was utilized for path analysis. This study selects the measurement or dependent variable for e-wallet adoption as "usage behavior." The findings indicate a significant positive relationship between e-wallet adoption behavior and online trans-action security. The inclusion of secure online transactions in digital wallets reassures users, fostering confidence and promoting engagement in secure online transactions, thereby bolstering the efficacy of e-wallet services, especially for critical financial activities. The significance of the research project lies in its potential to overcome the barriers hindering e-wallet adoption by addressing the security concerns of potential users. By enhancing security measures and increasing user trust, the adoption of e-wallets can be accelerated. Through an in-depth analysis of these factors, the research may provide recommendations and contribute to the country’s overall development and adoption of e-wallets.” (Abstract/Introduction)
WAQAS AHMED et al. “Security in Next Generation Mobile Payment Systems: A Comprehensive Survey.” (August 26, 2021). Retrieved online 08/19/2026. IEEE Xplore Full-Text PDF:
Relevancy: “Cash payment is still king in several markets, accounting for more than 90% of the payments in almost all the developing countries. The usage of mobile phones is pretty ordinary in this present era. Mobile phones have become an inseparable friend for many users, serving much more than just communication tools. Every subsequent person is heavily relying on them due to multifaceted usage and affordability. Every person wants to manage his/her daily transactions and related issues by using his/her mobile phone. With the rise and advancements of mobile-specific security, threats are evolving as well. In this paper, we provide a survey of various security models for mobile phones. We explore multiple proposed models of the mobile payment system (MPS),their technologies and comparisons, payment methods, different security mechanisms involved in MPS, and provide analysis of the encryption technologies, authentication methods, and firewall in MPS. We also identify current challenges and future directions of mobile phone security.” Abstract/Introduction)
Foreign Art:
Kumra et al. “PREDICTING SUCCESSFUL EXEMPTIONS TO STRONG AUTHENTICATION REQUIREMENTS.” (WO 2021/034589 A1)
Relevancy: “Disclosed are various embodiments for predicting successful exemptions to strong authentication requirements. A first payment transaction associated with a first user is submitted for processing by a particular payment issuer along with a request for an exemption from an authentication requirement. It is determined whether the first payment transaction was successfully processed. Subsequently, it is determined whether to include the request for the exemption from the authentication requirement for a second payment transaction associated with a second user in submitting the second payment transaction for processing with the particular payment issuer based at least in part on whether the first payment transaction was successfully processed.” (Abstract/Introduction)
PLIASUNOV et al. “ELIGIBILITY DETERMINATION FOR DELEGATION EXEMPTION TO STRONG AUTHENTICATION REQUIREMENTS.” (WO 2021/041168 A1)
Relevancy: “Disclosed are various embodiments for determining eligibility for the delegation exemption to strong customer authentication requirements. In one embodiment, a payee entity determines that a payment transaction using a payment instrument issued by a payment issuer is eligible for a delegation exemption from an authentication challenge by the payment issuer based at least in part on a previous authentication challenge by the payment issuer being successfully completed for a previous payment transaction using the payment instrument and a returned payment history associated with the payment instrument. Subsequently, the payee entity generates an alternative authentication challenge that does not involve the payment issuer instead of the authentication challenge by the payment issuer.” (Abstract/Introduction)
GAIVIRONSKY et al. “USER INTERFACES THAT DIFFERENTIATE PAYMENT INSTRUMENTS HAVING A TRUSTED BENEFICIARY.” (WO 2021/041277 A1)
Relevancy: “Disclosed are various embodiments for user interfaces that differentiate payment instruments having a trusted beneficiary. It is determined that a payee entity has been designated as a trusted beneficiary for a particular payment instrument issued by a particular payment issuer. A user interface is generated that facilitates a user selection of one of a plurality of payment instruments associated with a user account. The plurality of payment instruments include the particular payment instrument. The user interface differentiates the particular payment instrument based at least in part the payee entity being designated as the trusted beneficiary for the particular payment instrument.” (Abstract/Introduction)
Any inquiry of a general nature or relating to the status of this application or concerning this communication or earlier communications from the Examiner should be directed to James A. Reagan (james.reagan@uspto.gov) whose telephone number is 571.272.6710. The Examiner can normally be reached Monday through Friday from 9 AM to 5 PM. If attempts to reach the examiner by telephone are unsuccessful, the Examiner’s supervisor, John Hayes, can be reached at 571.272.6708.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://portal.uspto.gov/external/portal/pair . Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866.217.9197 (toll-free).
Any response to this action should be mailed to:
Commissioner for Patents
PO Box 1450
Alexandria, Virginia 22313-1450
or faxed to 571-273-8300.
Hand delivered responses should be brought to the United States Patent and Trademark Office Customer Service Window:
Randolph Building
401 Dulany Street
Alexandria, VA 22314.
/JAMES A REAGAN/Primary Examiner, Art Unit 3697
james.reagan@uspto.gov
571.272.6710 (Office)
571.273.6710 (Desktop Fax)