Prosecution Insights
Last updated: August 18, 2026
Application No. 19/474,151

SHIELD-UP SYSTEM AND METHOD FOR PAYMENT TRANSACTIONS

Non-Final OA §101§102§103
Filed
Oct 09, 2025
Priority
May 09, 2023 — nonprovisional of PCTUS2023021593 +1 more
Examiner
BRIDGES, CHRISTOPHER
Art Unit
3693
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Visa International Service Association
OA Round
1 (Non-Final)
45%
Grant Probability
Moderate
1-2
OA Rounds
2y 3m
Est. Remaining
56%
With Interview

Examiner Intelligence

Grants 45% of resolved cases
45%
Career Allowance Rate
158 granted / 349 resolved
-6.7% vs TC avg
Moderate +10% lift
Without
With
+10.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
20 currently pending
Career history
368
Total Applications
across all art units

Statute-Specific Performance

§101
53.2%
+13.2% vs TC avg
§103
24.0%
-16.0% vs TC avg
§102
6.4%
-33.6% vs TC avg
§112
12.0%
-28.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 349 resolved cases

Office Action

§101 §102 §103
DETAILED ACTION This office action is in response to Applicant’s communication of 10/9/2025. Claims 1-20 are pending and have been examined. The rejections are stated below. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 1/9/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claims do fall within at least one of the four categories of patent eligible subject matter because claims 1 and 17 are directed to a process and claim 17 is directed to a system; Step 1-yes. Under Step 2A, prong 1, representative claim 1 recites a series of steps for providing user-specific security framework to authorize a payment transaction, i.e. mitigating transaction risk, which is a fundamental economic practice and commercial or legal interaction and thus grouped as “Certain Methods of Organizing Human Activity”. The claim as a whole and the limitations in combination recite this abstract idea. Specifically, the limitations of representative claim 1, stripped of all additional elements, recite the abstract idea as follows: 1. A computer-implemented method, comprising: determining, at a communication device, whether a user of a payment application on the communication device desires additional security underlying the payment application; when the user of the communication device desires the additional security, generating a payment transaction shield underlying the payment application; ascertaining user-specific information from the payment application; generating, as part of the payment transaction shield, a frontend security framework specific to the user of the payment application; mapping the frontend security framework to the user-specific information; and utilizing the frontend security framework to authorize a payment transaction conducted using the payment application. The claimed limitations, identified above, recite a process that, under its broadest reasonable interpretation, covers performance of a fundamental economic practice and commercial or legal interaction, but for the recitation of generic computer components. That is, other than the mere nominal recitation of a “communication device” and payment “application” in in claim 1, “a processor; and a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium including code” and “a payment application on the communication device” in claim 9 and “A computer-implemented method” in claim 17, there is nothing in the claim element which takes the steps out of the methods of organizing human activity abstract idea grouping. Thus, the claim recites an abstract idea. Under step 2A, prong 2, this judicial exception is not integrated into a practical application. In particular, the claim only recites using generic, commercially available, off-the-shelf computing devices, i.e. processors suitably programmed communicating over a generic network, to perform the steps of determining, generating, ascertaining, generating, mapping and authorize. The computer components are recited at a high-level of generality (i.e., as generic processors with memory suitably programmed communicating information over a generic network, see at least FIG.2, at least paragraphs [0010], [0023], [0032] and [0038-0039] of the specification) such that it amounts no more than adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform the abstract idea, see MPEP 2106.05(f). Accordingly, the additional elements claimed do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. Under step 2B, the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of using generic computer processors with memory suitably programmed communicating over a generic network to perform the limitation steps amounts no more than adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform the abstract idea, see MPEP 2106.05(f). Mere instructions to apply an exception using generic computer components interacting in a conventional manner cannot provide an inventive concept. The claim is not patent eligible. For instance, in the process of claim 1, the limitation steps, claimed at a high level of generality, recite steps that are considered mere instructions to apply an exception akin to a commonplace business method or mathematical algorithm being applied on a general purpose computer, Alice Corp. Pty. Ltd.; Gottschalk and Versata Dev. Group, Inc.; see MPEP 2106.05(f)(2). Applicant has leveraged generic computing elements to perform the abstract idea of providing user-specific security framework to authorize a payment transaction, i.e. mitigating transaction risk, without significantly more. Dependent claims 2-8, 10-16, 18 and 19 when analyzed as a whole and in an ordered combination are held to be patent ineligible under 35 U.S.C. 101 because the additional recited limitation(s) fail(s) to establish that the claim(s) is/are not directed to an abstract idea, as detailed below. The additional recited limitations in the dependent claims only refine the abstract idea. For instance, claims 2, 10 and 18 further refine the abstract idea by performing a behavior-based analysis of a user, i.e. interactions with their device, to determine whether to secure the payment transaction. This is claimed at a very high level of generality with no technical implementation details. Claims 3, 4, 5, 11, 12, 13, 19 and 20 further refines the abstract idea by generating a risk score based on the behavior analysis, use said risk score to determine whether to allow the payment transaction and authorizing the payment transaction when the risk score is over a threshold value. Again, these steps are claimed at a very high level of generality with no technical implementation details such that a human could not perform these abstract idea steps. Claims 6, 7, 8, 14, 15 and 16 further refine the abstract idea by “assessing”, i.e. analyzing, spending patterns, commonly used merchants and a commonly used person to determine whether to allow the payment transaction. There are no technical details to define the term “assessing” other than a generic computing device programmed to automate an otherwise manual and mental analysis. Clearly, the additional recited limitations in the dependent claim only refines the abstract idea further. Further refinement of an abstract idea does not convert an abstract idea into something concrete. The claims merely amount to the application or instructions to apply the abstract idea (i.e. a series of steps for providing user-specific security framework to authorize a payment transaction, i.e. mitigating transaction risk) on one or more computers, and are considered to amount to nothing more than requiring a generic computer system (e.g. processors suitably programmed and communicating over a network) to merely carry out the abstract idea itself. As such, the claims, when considered as a whole, are nothing more than the instruction to implement the abstract idea (i.e. a series of steps for providing user-specific security framework to authorize a payment transaction, i.e. mitigating transaction risk) in a particular, albeit well-understood, routine and conventional technological environment. Accordingly, the Examiner concludes that there are no meaningful limitations in the claims that transform the judicial exception into a patent eligible application such that the claims amount to significantly more than the judicial exception itself or integrate the judicial exception into a practical application. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-16 and 18-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Legault et al.(US 2019/0068604 Al)(Legault hereinafter) Regarding claims 1 and 9: Legault discloses computer-implemented method and system (see at least Abstract) comprising: determining, at a communication device, whether a user of a payment application on the communication device desires additional security underlying the payment application; when the user of the communication device desires the additional security, generating a payment transaction shield underlying the payment application; (at least [0048], “…whether there is a co-signer or authorized user associated with client, profile and/or account….. may also consider whether the client has security features, such as two-factor authentication enabled.” reads on a client enabling, i.e. desiring, additional security factor authentication when accessing a payment application). ascertaining user-specific information from the payment application; (at least [0024], “…the system may determine that the request is consistent with the client's past behavior or the behavior is expected based on a new data”, at least [0045], “…focus on client behavior information so that the system may better understand and predict a client's payment and transaction behavior. According to another example, a financial institution may recognize that a certain payment or other action may seem to diverge from a client's pattern of behavior.). generating, as part of the payment transaction shield, a frontend security framework specific to the user of the payment application; mapping the frontend security framework to the user-specific information; (at least [0047], “….the system may determine that the request is consistent with the client's past behavior or the behavior is expected based on a new data……. to identify a client's expected behavior and then establish a range so that when an action is outside of the expected behavior and range, the system may be alerted and further update or adjust the client's risk score.”, the risk score, based on specific user behaviors, reads on front end security framework because the fraud risk score can allow/deny a transaction) and utilizing the frontend security framework to authorize a payment transaction conducted using the payment application, (at least Abstract, “…generate a risk score based on the aggregated combination of the client data, client device data, claims data and cyber data to determine whether the requester is authenticated to access the account; and automatically apply an authentication determination to the authorization request.”) Regarding claims 2, 10 and 18: Legault further discloses further comprising: performing a behavior-based analysis of the communication device as part of a behavior-based authentication to determine whether to secure the payment transaction, (at least [0005], “…retrieve, from the memory, a client profile, wherein the client profile is based on an aggregation of client data, client device data, claims data and cyber data; the client data comprises client account data, client behavior data and transaction activity data;…”, at least [0014], “…aggregates, merges, and analyzes available data elements across client identity, transactions, behavior, and claims histories as well as cyber fraud data sets to generate a risk score for client authentication decisions across various entry points and payment channels…”). Regarding claims 3, 11 and 19: Legault further discloses further comprising: generating a risk score based upon the behavior-based analysis, at least [0014], “…aggregates, merges, and analyzes available data elements across client identity, transactions, behavior, and claims histories as well as cyber fraud data sets to generate a risk score for client authentication decisions across various entry points and payment channels…”). Regarding claims 4, 12 and 20: Legault further discloses, further comprising: utilizing the risk score to determine whether to allow the payment transaction conducted using the payment application, (at least [0014], “An embodiment of the present invention is directed to a risk-based approach that allows banks and other entities to make an informed and accurate authentication decision regarding the identity of clients.”, at least [0042], “For example, if the risk is determined to be low, the transaction may proceed. If there is some risk involved, the system may allow the transaction to proceed with a monitoring feature on the funds.). Regarding claims 5 and 13: Legault further discloses, wherein: when the risk score is greater than a risk score threshold, the payment transaction conducted by the user using the payment application is authorized, (at least [0015], “…develop an authentication score to be used by lines of business (LOBs) and/or other teams when identifying clients. Based on a risk threshold and/or level of confidence, a line of business may allow a requesting entity to proceed with corresponding responses or actions.”, at least [0038]). Regarding claims 6 and 14: Legault further discloses, further comprising: assessing a spending pattern of the user of the communication device to determine whether to allow the payment transaction conducted using the payment application, (at least [0045], “…focus on client behavior information so that the system may better understand and predict a client's payment and transaction behavior. According to another example, a financial institution may recognize that a certain payment or other action may seem to diverge from a client's pattern of behavior.”). Regarding claims 7 and 15: Legault further discloses, further comprising: assessing commonly used merchants of the user of the communication device to determine whether to allow the payment transaction conducted using the payment application, at least [0039], “The number and quality of indicators may be based on an initial threshold inquiry regarding the authentication request, entity requesting, geographic location, etc.”, at least [0049], “…a date/time pattern of historical authentication activity (e.g., geographic location of prior authentication activity, etc.);…”, geographic location reads on commonly used merchants). Regarding claims 8 and 16: Legault further discloses, further comprising: assessing a commonly used person of the user of the communication device to determine whether to allow the payment transaction conducted using the payment application, (at least [0024], “…although an authentication request may initially appear risky ( e.g., a high risk score), the system may determine that the request is consistent with the client's past behavior or the behavior is expected based on a new data…”, the client is a commonly used person). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Legault et al.(US 2019/0068604 Al)(Legault hereinafter) in view of Rathod (US 2021/0042724 Al) Regarding claim 17: Legault discloses a computer-implemented method, comprising: attaining user-specific information from a user of Unified Payments Interface (UPI)-based payment application; generating a user-specific frontend security framework based upon the user-specific information; overlaying the user-specific security framework over the UPI-based payment application; and utilizing the user-specific security framework to secure a payment transaction utilizing the UPI-based payment application, the user-specific security framework being configured to self-correct the payment transaction based upon user conduct, (See rejection of claims 1 and 9 above). Although Legault substantially discloses the limitations of claims 1 and 9 above which are similar to claim 17, it appears that Legault does not disclose, however, Rathod discloses “Unified Payments Interface (UPI)-based payment”, (see at least [0219], “Unified Payments Interface (UPI) is an instant real-time payment system developed by NPCI facilitating inter-bank transactions…”, reads on application, [0220-0221]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include in the system for aggregating client data and cyber data for authentication determinations of Legault the ability to access and use Unified Payments Interface (UPI)-based payment system as disclosed by Rathod since the claimed invention is merely a combination of old elements and, in combination, each element would merely have performed the same function as it did separately. One of ordinary skill in the art would have recognized that applying the features disclosed by Rathod, to the known invention of Legault, would have yielded predictable results and resulted in an improved invention. The motivation to combine is that Unified Payments Interface (UPI)-based payment system is a well known payment application. Applied with the security features of Legault would provide a more robust payment system. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure are listed on the enclosed PTO-892. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER J BRIDGES whose telephone number is (571)270-5451. The examiner can normally be reached 7:00am-3:30pm M-F EDT. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ryan Donlon can be reached at 571-270-3602. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHRISTOPHER BRIDGES/Primary Examiner, Art Unit 3693
Read full office action

Prosecution Timeline

Oct 09, 2025
Application Filed
Jul 30, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12694389
Data Processing Apparatus with a Logic Processing Device for Processing Network Data Records Transmitted from a Plurality of Remote, Distributed Terminal Devices
2y 10m to grant Granted Jul 28, 2026
Patent 12682345
GATED CONTROL FOR BLOCKCHAIN UNITS
2y 0m to grant Granted Jul 14, 2026
Patent 12664009
DISTRIBUTED REGULATORY TANGLEGRAPH CONSORTIUM SYSTEM FOR EXECUTING PROCESSES IN A VIRTUAL COMPUTING ENVIRONMENT
4y 0m to grant Granted Jun 23, 2026
Patent 12659155
PROCESSING A CONTINGENT ACTION TOKEN SECURELY
2y 7m to grant Granted Jun 16, 2026
Patent 12647288
Systems and Methods for Generation of Energy-Backed Digital Units Stored in a Decentralized Ledger
3y 10m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
45%
Grant Probability
56%
With Interview (+10.5%)
3y 2m (~2y 3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 349 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month