Invalidity dossier
US 10032171
Systems and methods for secure application-based participation in an interrogation by mobile device
Current assignee: SIMPLYTAPP Inc
Added 7/14/2026, 6:03:47 AM
Active provider: Google · gemini-2.5-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
US Patent 10032171, titled "Systems and methods for secure application-based participation in an interrogation by mobile device," was filed on August 30, 2012, and issued on July 24, 2018. [cite: The full patent text provided as authoritative information.] The inventor is Douglas C. Yeager. [cite: The full patent text provided as authoritative information.] The original assignee was SIMPLYTAPP Inc, and the current assignees are SIMPLYTAPP Inc and OV Loop Inc. [cite: The full patent text provided as authoritative information.]
The abstract of the patent states that the disclosure relates to payment and authorization methods, specifically using a mobile computing device with a remotely hosted Secure Element representation to facilitate payments, authorizations, or information exchange with other devices. [cite: The full patent text provided as authoritative information.]
Regarding litigation, a case related to this patent has been filed in the Court of Appeals for the Federal Circuit, identified as case 26-1055. [cite: The full patent text provided as authoritative information.]
A plain-language overview of the independent claims is as follows:
Independent Claim 1: This claim describes a method for a point-of-sale (POS) terminal to get digital credential data from a mobile device to authorize a financial transaction. The key aspect is that a "remote permanent cryptographic key," stored remotely from the mobile device, is used to calculate an "expected cryptogram." The mobile device itself does not store a duplicate of this key. During an "interrogation," the POS sends a command to the mobile device requesting the data, and the mobile device responds with the expected cryptogram, enabling the transaction to be authorized. [cite: The full patent text provided as authoritative information.]
Independent Claim 10: This method also involves a POS terminal acquiring digital credential data from a mobile device for transaction authorization. In this scenario, the POS sends a command that includes a request for digital credential data (expected to contain a cryptogram calculated from unpredictable data and a permanent cryptographic key) and the unpredictable data itself. However, the mobile device responds with an "unexpected cryptogram" that is substituted in place of the expected cryptogram, yet still results in the financial transaction being authorized. [cite: The full patent text provided as authoritative information.]
Independent Claim 17: This claim outlines a method for a POS terminal to get digital credential data from a secure mobile device for transaction authorization, with additional verification steps involving a remote application system. The POS interrogates the secure mobile device, sending unpredictable data and requesting an expected cryptogram (calculated from that unpredictable data and a permanent cryptographic key). The secure mobile device responds with this expected cryptogram. Separately, the secure mobile device sends the unpredictable data to a remote application system, and the POS also sends an authorization request (including the expected cryptogram and the unpredictable data) to the same remote application system. The application system then verifies both the expected cryptogram and the unpredictable data (by comparing what it received from the mobile device with what it received from the POS). Finally, the application system sends an authorization response to the POS, which is determined by these verification steps, thereby authorizing the financial transaction. [cite: The full patent text provided as authoritative information.]
Generated 7/14/2026, 6:45:49 AM
Cases on file (2)
Group view →Specific litigation cases in our database that name US patent 10032171. The free-form analysis below may also discuss cases beyond this list.
- Untitled casefiled 202626-1055Court of Appeals for the Federal CircuitActive litigation
- IPR2023-01289Patent Trial and Appeal Board (PTAB)Final Written Decision
Defendants: SIMPLYTAPP Inc., OV Loop Inc.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
Known litigation involving US patent 10032171 includes the following:
US Court of Appeals for the Federal Circuit
- Jurisdiction: Court of Appeals for the Federal Circuit
- Case Number: 26-1055
- Status: Active litigation
- Plaintiff(s): Not explicitly stated in the provided information or search results.
- Defendant(s): Not explicitly stated in the provided information or search results.
- Filing Date: The case number '26-1055' indicates a filing year of 2026.
New York Southern District Court
- Jurisdiction: New York Southern District Court
- Case Number: 7:23-cv-01773
- Status: Active litigation
- Plaintiff(s): Not explicitly stated in the provided information or search results.
- Defendant(s): Not explicitly stated in the provided information or search results.
- Filing Date: The case number '7:23-cv-01773' indicates a filing year of 2023.
PTAB Inter Partes Review (IPR)
- Jurisdiction: Patent Trial and Appeal Board (PTAB)
- Case Number: IPR2023-01289
- Plaintiff(s): Unified Patents
- Defendant(s): The Patent Owner (referring to the owner of US10032171, which is SIMPLYTAPP Inc, and current assignee OV Loop Inc.)
- Filing Date: 2023 (indicated by "IPR2023")
- Outcome/Status: Final Written Decision
PTAB Inter Partes Review (IPR)
- Jurisdiction: Patent Trial and Appeal Board (PTAB)
- Case Number: IPR2023-01290
- Plaintiff(s): Unified Patents
- Defendant(s): The Patent Owner (referring to the owner of US10032171, which is SIMPLYTAPP Inc, and current assignee OV Loop Inc.)
- Filing Date: 2023 (indicated by "IPR2023")
- Outcome/Status: Not Instituted - Procedural. The Board exercised its discretion to deny institution of this second-ranked petition, as it was a parallel petition to IPR2023-01289 and lacked sufficient justification for multiple petitions against the same patent.
Worldwide Family Litigation
- Status: First worldwide family litigation filed.
- Jurisdiction, Plaintiff(s), Defendant(s), Case Number, Filing Date, and Outcome: Specific details directly pertaining to US10032171 within this family litigation are not available from the provided patent text or general search results.
Generated 7/14/2026, 6:45:57 AM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
Proceedings overview
Two AIA trial proceedings have been filed against US patent 10032171. One Inter Partes Review (IPR2023-01289) resulted in a Final Written Decision, though the specific outcomes for the challenged claims are not publicly detailed in the immediately available search results. The other, IPR2023-01290, was denied institution on procedural grounds. This gives a defendant a mixed defensive posture; while one IPR was instituted and concluded, the specific impact on the patent's claims is currently undetermined from the provided information, and the patent has not been significantly hardened by prevailing in an IPR on the merits.
IPR2023-01289 — Mastercard Inc., Mastercard International Inc. v. OV Loop Inc.
- Type: Inter Partes Review
- Filed: 2023-09-06
- Status: Final Written Decision, expected 2025-08-07
- Judge panel: Information not publicly available in search results.
- Petition grounds: Claims 1-33 of US10032171 were challenged. The petition in IPR2023-01289 assumed that these claims were not entitled to a priority date earlier than August 30, 2012, the filing date of the non-provisional application for the '171 Patent. This IPR was ranked by the Petitioner as the primary challenge in a parallel petition scenario.
- Institution decision: Instituted on 2024-03-20. The specific reasoning for institution is not detailed in the available search results, beyond the fact that it was preferred over IPR2023-01290 due to the Patent Owner's stipulation regarding priority dates.
- Final Written Decision (if issued): The Final Written Decision was issued, but the outcome regarding the patentability of individual claims (i.e., which claims were canceled or sustained) is not publicly detailed in the provided search results. The due date for the Final Written Decision was 2025-08-07.
- Settlement / termination: Information not publicly available in search results.
- Appeal: Information not publicly available in search results.
- Defensive value: This IPR proceeding challenged all claims of the patent, but the specific outcome of the Final Written Decision is unknown. Without knowing if claims were invalidated or sustained, its defensive value is uncertain. If claims were invalidated, it would significantly weaken the patent.
IPR2023-01290 — Mastercard Inc., Mastercard International Inc. v. OV Loop Inc.
- Type: Inter Partes Review
- Filed: 2023-09-06
- Status: Not Instituted - Procedural, terminated 2024-03-21
- Judge panel: Information not publicly available in search results.
- Petition grounds: This petition challenged claims 1-33 of US10032171 and relied on references that would qualify as prior art even assuming an alleged August 30, 2011 priority date (the earliest provisional application filing date).
- Institution decision: Denied on 2024-03-21. The denial was procedural because it was a second-ranked parallel petition challenging the same claims as IPR2023-01289. The Patent Owner stipulated that it would not challenge the status of the asserted prior art (Chueh or Srinivasan) or allege an earlier priority date than August 30, 2012, in the primary IPR (IPR2023-01289), thereby eliminating the justification for multiple petitions based on different priority date assumptions.
- Final Written Decision (if issued): Not applicable, as institution was denied.
- Settlement / termination: The proceeding was procedurally terminated on 2024-03-21 due to the denial of institution.
- Appeal: Not applicable, as institution was denied.
- Defensive value: The denial of this IPR means the specific grounds raised in this petition were not fully litigated on the merits at the PTAB. However, the denial was procedural and related to the existence of a parallel IPR, rather than the merits of the prior art arguments themselves. Therefore, a defendant might still be able to use similar prior art arguments in other forums, subject to the nuances of estoppel and the specific prior art.
Strategic summary
Claims 1-33 of US10032171 were challenged in IPR2023-01289, which proceeded to a Final Written Decision. However, the precise outcome of this decision—which, if any, claims were found unpatentable or sustained—is not detailed in the available public information. Therefore, it is currently unknown which claims of 10032171 are CANCELED vs. SUSTAINED vs. UNTESTED. For defensive purposes, this lack of specific outcome means a defendant cannot definitively rely on any claims being invalidated by this IPR.
Regarding the estoppel landscape, for IPR2023-01289, the petitioner, Mastercard Inc. and Mastercard International Inc., and its privies, would be estopped under 35 U.S.C. § 315(e)(2) from asserting in a civil action or ITC proceeding any invalidity arguments they raised or reasonably could have raised during the IPR, assuming a Final Written Decision was reached and not overturned on appeal. The denial of IPR2023-01290 on procedural grounds means no estoppel applies to the petitioner from that specific proceeding on its own. However, given that it was a parallel petition by the same petitioner, and the denial was explicitly to avoid duplicative proceedings after a stipulation, the arguments intended for IPR2023-01290 may be considered as "reasonably could have raised" in IPR2023-01289, depending on their overlap with the instituted grounds.
A clear pattern signal is the filing of two parallel IPR petitions by the same petitioner (Mastercard Inc. and Mastercard International Inc.) against the same patent (US10032171), albeit with different priority date assumptions, and the patent owner (OV Loop Inc.) making a stipulation to influence the PTAB's discretionary institution decision. This indicates a targeted effort to challenge the patent's validity.
Recommended next steps
Given that a Final Written Decision has been issued in IPR2023-01289, the critical next step for any defendant facing assertion of US10032171 is to obtain and thoroughly review the complete Final Written Decision for IPR2023-01289 to ascertain the patentability of each challenged claim. This document will definitively state which claims, if any, were cancelled, which were found patentable, and the Board's reasoning. This information is essential for assessing the patent's strength and for guiding any potential invalidity defenses.
The official decision can be accessed via the USPTO PTAB E2E portal using the proceeding number IPR2023-01289. Without this document, the current status of the claims remains uncertain for a defendant.
Generated 7/14/2026, 6:46:08 AM
Ownership chain (3)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
2013-11-20 · recorded 2018-09-06 · reel 045145/0961 · ASSIGNMENT OF ASSIGNORS INTEREST
YEAGER, DOUGLAS CSIMPLYTAPP, INC.
Correspondent: · VENABLE
internal reorg
2018-07-03 · recorded 2018-09-06 · reel 045145/0961 · ASSIGNMENT OF ASSIGNORS INTEREST
Correspondent: · VENABLE
2019-10-18 · recorded 2019-10-23 · reel 050012/0329 · ASSIGNMENT OF ASSIGNORS INTEREST
YEAGER, CHARLES DOUGLASOV LOOP INC.
Correspondent: WILLIAM S PARKS · OV LOOP
acquisition
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
Inventors
The sole named inventor is Douglas C. Yeager. His employer at the time of filing was SIMPLYTAPP Inc., as the application was filed by SIMPLYTAPP Inc. and he later assigned his interest to the company.
Original Assignee
The original assignee, as named on the issued patent and at the time of initial application, was SIMPLYTAPP Inc. SIMPLYTAPP Inc. developed NFC-based mobile payment systems, specifically pioneering Host Card Emulation (HCE) before it was natively supported by Android. They aimed to enable mobile phones to emulate payment cards using remote secure elements. SIMPLYTAPP Inc. was acquired by MasterCard in 2015. Following this acquisition, SIMPLYTAPP Inc. assigned its interest in this patent back to the inventor in 2018.
Assignment timeline
2013-11-20 (executed) / recorded 2018-09-06 — Reel 045145/0961
- Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST
- Assignor: YEAGER, DOUGLAS C
- Assignee: SIMPLYTAPP, INC.
- Correspondent: VENABLE LLP, 1290 AVENUE OF THE AMERICAS, NEW YORK, NY 10104. This correspondent recurs in this chain.
- Context: Inventor assigning patent rights to the company.
2018-07-03 (executed) / recorded 2018-09-06 — Reel 045145/0961
- Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST
- Assignor: SIMPLYTAPP INC.
- Assignee: YEAGER, DOUG
- Correspondent: VENABLE LLP, 1290 AVENUE OF THE AMERICAS, NEW YORK, NY 10104. This correspondent recurs in this chain.
- Context: Company assigning patent rights back to the inventor.
2019-10-18 (executed) / recorded 2019-10-23 — Reel 050012/0329
- Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST
- Assignor: YEAGER, CHARLES DOUGLAS
- Assignee: OV LOOP INC.
- Correspondent: WILLIAM S PARKS, OV LOOP INC., 201 SPEAR ST STE 1100, SAN FRANCISCO, CA 94105.
- Context: Inventor assigning patent rights to a new entity.
Timeline diagram
timeline
title Ownership of US 10032171
2012 : Filed by SIMPLYTAPP Inc
2013 : Inventor assigned to SIMPLYTAPP Inc
2018 : Patent Issued
: SIMPLYTAPP Inc assigned to inventor
2019 : Inventor assigned to OV Loop Inc
2023 : Litigation activity begins
NPE / troll-pattern signals
- Shell-entity transfer — Not present. The patent transferred from an operating company (SIMPLYTAPP Inc.) to the inventor, then to another operating company (OV Loop Inc.). OV Loop Inc. develops payment and commerce platforms and appears to be an operating entity.
- Known asserter in the chain — Not present. None of the assignees (SIMPLYTAPP Inc., Douglas C. Yeager, OV Loop Inc.) are listed as known patent asserters or NPEs.
- Repeat correspondent across the chain — Present. VENABLE LLP, located at 1290 AVENUE OF THE AMERICAS, NEW YORK, NY 10104, acted as the correspondent for both the 2013-11-20 assignment from Douglas C. Yeager to SIMPLYTAPP, INC. and the 2018-07-03 assignment from SIMPLYTAPP INC. to YEAGER, DOUG (both recorded on Reel 045145/0961).
- Cascading transfers — Not present. The assignments (2018-07-03 and 2019-10-18 executed dates) are approximately 15 months apart, which does not indicate rapid, chained transfers.
- Pre-litigation transfer — Not present. The latest assignment to OV LOOP INC. was executed on 2019-10-18 and recorded on 2019-10-23. The earliest public litigation identified for this patent is around 2023 (e.g., case 7:23-cv-01773 in New York Southern District Court), which is more than 6 months after the transfer.
- Bankruptcy fire-sale — Not present. SIMPLYTAPP Inc. was acquired by MasterCard, not involved in a bankruptcy sale. No other parties in the chain show evidence of bankruptcy.
- Privateering — Unclear. There is no public information from SEC filings or other sources to suggest that OV Loop Inc. is asserting the patent on behalf of a third-party operating company. OV Loop Inc. appears to be using the patent in relation to its own business.
- Defensive aggregator (anti-NPE) — Not present. The patent is not currently assigned to any known defensive aggregator.
Verdict
Operating-company assertion
This verdict is based on the fact that the patent originated with an operating company (SIMPLYTAPP Inc.) that developed and commercialized related technology. It was subsequently acquired by another operating company, OV Loop Inc., which is active in the payment technology sector. The identified litigation against the patent began well after its transfer to OV Loop Inc., suggesting assertion by an operating company for its own business interests rather than a shell entity.
For verification, refer to the USPTO Patent Assignment Search for US10032171.
Generated 7/14/2026, 6:46:09 AM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
To identify the most relevant prior art for US patent 10032171, I will access the USPTO database and examine the patent's citations. The USPTO's Patent Public Search tool can be used to search for patents by publication number.
Here's an analysis of the prior art cited by US Patent 10032171, based on the provided patent text:
The full patent text lists "Prior art keywords" as "data," "cryptogram," "mobile device," "account," and "cryptographic key." [cite: The full patent text provided as authoritative information.] It also explicitly incorporates by reference U.S. Pat. No. 8,151,345, issued to C. Douglas Yeager from U.S. patent application Ser. No. 12/019,318. [cite: The full patent text provided as authoritative information.]
Given the information provided in the patent document itself, U.S. Pat. No. 8,151,345 is a highly relevant piece of prior art.
Prior Art Reference: U.S. Pat. No. 8,151,345
- Full Citation: U.S. Pat. No. 8,151,345 (no specific issue date or full title is provided in the current text, but it's stated as "issued to C. Douglas Yeager"). [cite: The full patent text provided as authoritative information.]
- Publication/Filing Date: The patent is stated to be "issued to C. Douglas Yeager from U.S. patent application Ser. No. 12/019,318". The filing date for US10032171 is August 30, 2012, and its priority date is August 30, 2011. Therefore, U.S. Pat. No. 8,151,345 would predate the current patent.
- Brief Description: The patent states that U.S. Pat. No. 8,151,345 describes examples of mobile devices that support NFC functionality. [cite: The full patent text provided as authoritative information.] Specifically, Figure 5 of US10032171, which illustrates the inner architecture of a mobile device supporting NFC, refers to devices described in U.S. Pat. No. 8,151,345. [cite: The full patent text provided as authoritative information.]
- Which claim(s) it potentially anticipates under 35 U.S.C. § 102: This patent likely anticipates aspects of the mobile device's architecture and NFC capabilities as broadly claimed in US10032171. For example, the independent claims 1, 10, and 17 all refer to a "mobile device" and its interaction with a point-of-sale terminal. U.S. Pat. No. 8,151,345 would be relevant to the foundational understanding of mobile devices with NFC as described in the background and enablement of these claims. However, it's not clear from the brief description whether it anticipates the specific secure application-based participation in an interrogation by mobile device aspects, particularly the remote secure element representation or cryptogram substitution/verification described in claims 1, 10, and 17. It would likely anticipate the general concept of a mobile device having NFC capabilities and acting as a payment instrument.
Generated 7/14/2026, 6:45:57 AM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
Obviousness Analysis of US10032171 under 35 U.S.C. § 103
This analysis aims to identify combinations of prior art that would render the independent claims of US Patent 10032171 obvious to a person having ordinary skill in the art (PHOSITA). The patent, titled "Systems and methods for secure application-based participation in an interrogation by mobile device," primarily concerns secure payment and authorization methods using mobile devices and remote Secure Element (SE) representations.
A PHOSITA in this field would likely have knowledge of mobile payment systems, cryptographic security, NFC/RFID technologies, and remote server architectures for handling financial transactions. The Cooperative Patent Classification (CPC) codes associated with US10032171B2 reflect these areas, including G06Q20/40975 (Device specific authentication in transaction processing using mutual authentication between devices and transaction partners using encryption therefor), H04L9/321 (Cryptographic mechanisms including means for verifying identity involving a third party or trusted authority), G06Q20/326 (Payment applications installed on the mobile devices), and G06Q20/385 (Payment protocols using an alias or single-use codes).
Obviousness of Independent Claim 1
Independent Claim 1 describes a method for a point-of-sale (POS) terminal to acquire digital credential data from a mobile device for financial transaction authorization. It specifies the use of a remote permanent cryptographic key, stored remotely from the mobile device, to calculate an expected cryptogram, with the mobile device not storing a duplicate local permanent cryptographic key. The method involves an interrogation where the POS sends a command requesting data, and the mobile device responds with the expected cryptogram. [cite: The full patent text provided as authoritative information.]
A combination of prior art references could render this claim obvious:
Potential Combination: Prior art demonstrating mobile payment systems using NFC/RFID (e.g., similar to those described in US Pat. No. 8,151,345, which is incorporated by reference in US10032171B2) combined with prior art detailing remote secure elements or centralized key management systems for cryptographic operations.
Reasoning for Obviousness:
- Mobile Payment and Interrogation: The concept of a mobile device being interrogated by a POS terminal via NFC/RFID to obtain digital credential data for a financial transaction was well-established prior to the priority date of US10032171B2 (August 30, 2011). US Pat. No. 8,151,345, cited within the patent itself, describes mobile devices with NFC functionality emulating payment cards and interacting with RFID POS readers. This demonstrates the "performing an interrogation" step and the exchange of digital credential data. [cite: The full patent text provided as authoritative information.]
- Remote Cryptographic Keys and Secure Elements: The idea of securing cryptographic keys and performing cryptographic operations remotely, rather than solely on an end-user device, would have been evident to a PHOSITA. Centralized security modules, like Hardware Security Modules (HSMs), are explicitly mentioned in US10032171B2 as devices commonly used in the banking and processing industry for securely containing encryption keys and algorithms. [cite: The full patent text provided as authoritative information.] A PHOSITA would understand the security benefits of storing sensitive keys remotely to prevent compromise if the mobile device is lost or stolen. The patent itself highlights the "significant advantage of extracting and delivering data that are contained within an SE is provided by an ability to know beyond reasonable doubt that the data string being delivered indeed came from a particular SE or card." [cite: The full patent text provided as authoritative information.] This implies that the security inherent in a separate, trusted element was recognized.
- Motivation for Combination: A PHOSITA would be motivated to combine these concepts to enhance the security and flexibility of mobile payment systems. By centralizing the permanent cryptographic key at a remote, secure location (e.g., within an application system with an HSM, as detailed in FIG. 21 of US10032171B2 [cite: The full patent text provided as authoritative information.]), the security posture of the entire system is improved. The mobile device no longer needs to store the highly sensitive permanent key, reducing the risk of its compromise. The communication between the mobile device and the remote system to obtain cryptograms (or instructions for their calculation) would be a logical extension of existing remote authorization and data exchange mechanisms. For example, FIG. 11 of US10032171B2 illustrates how an NFC-enabled mobile device can access a remote SE via the internet, passing interrogation commands and responses. [cite: The full patent text provided as authoritative information.] This demonstrates a clear understanding within the patent itself of the motivation for, and feasibility of, such a remote architecture.
Therefore, the combination of known mobile payment interrogation techniques with the well-understood principle of remote, centralized cryptographic key management would render the subject matter of Claim 1 obvious.
Obviousness of Independent Claim 10
Independent Claim 10 describes a method where a POS requests digital credential data, including an "expected cryptogram" calculated from unpredictable data and a permanent cryptographic key, and provides the unpredictable data. However, the mobile device responds with an "unexpected cryptogram" that is substituted in place of the expected cryptogram, yet still authorizes the financial transaction. [cite: The full patent text provided as authoritative information.]
This claim introduces the concept of "cryptogram substitution" where the mobile device sends an "unexpected cryptogram" instead of the expected one based on the card specification. [cite: The full patent text provided as authoritative information.]
Potential Combination: Prior art demonstrating mobile payment systems that handle cryptographic responses (as for Claim 1), combined with prior art related to tokenization or dynamic data generation for security in transactions, and further combined with prior art disclosing verification systems that can accommodate variations in transaction data, such as single-use codes or aliases.
Reasoning for Obviousness:
- Mobile Payment and Cryptographic Responses: As discussed for Claim 1, mobile payment systems involving cryptographic responses from a device during POS interrogation are known.
- Dynamic Data and Tokenization: The use of dynamic data or single-use tokens/aliases in financial transactions to enhance security was a recognized practice. The CPC classification G06Q20/385, relating to "Payment protocols; Details thereof using an alias or single-use codes," indicates that this concept was known in the field of payment architectures. A PHOSITA would understand that replacing static or easily predictable data with dynamic or substituted values can improve security by making it harder for fraudsters to replay intercepted transaction data.
- Remote Verification: The patent describes "cryptogram substitution" as using a predetermined cryptogram or unpredictable cryptogram, which may not be accurately calculated with the input data from the POS, but is accepted because the POS "simply receives the cryptogram and relays it for verification to the application system, which has access to the input data used to create the original pre-determined cryptogram." [cite: The full patent text provided as authoritative information.] This highlights that the ultimate verification happens at a remote application system. Prior art in secure communication and transaction processing would include systems capable of verifying data against a known "expected" value, or against a value that has been pre-generated or dynamically created and recorded by a trusted third party. The concept of an application system storing pre-generated cryptograms or temporary keys (e.g., in a transaction table 210 as shown in FIG. 22 [cite: The full patent text provided as authoritative information.]) for later verification by a remote system would be a logical step for improving efficiency or security.
- Motivation for Combination: A PHOSITA would be motivated to introduce an "unexpected cryptogram" for several reasons:
- Enhanced Security: By not directly using the POS's unpredictable data to calculate the cryptogram on the mobile device (or by using a temporary key instead of a permanent one, as described in the patent as forming an unpredictable cryptogram), the system can add another layer of security. If the mobile device's calculation mechanism were compromised, this substitution could prevent a malicious actor from generating valid cryptograms that would be accepted by the application system.
- Improved Performance/Caching: As illustrated in FIG. 17 of US10032171B2, 100% transaction caching can be achieved by pre-calculating and storing all APDU commands and responses, including cryptograms, on the mobile device. [cite: The full patent text provided as authoritative information.] This eliminates network latency during the actual POS interrogation. An "unexpected cryptogram" that is predetermined or calculated using a temporary key (known to the remote system) would facilitate this caching without requiring real-time interaction with the remote SE during the transaction. This would be a clear motivation for a PHOSITA to combine pre-computation or substitution techniques with existing mobile payment systems.
The combination of existing mobile payment methodologies, known dynamic data/tokenization security practices, and the recognized need for efficient remote verification in transaction systems, would make the concept of an "unexpected cryptogram" and its remote verification obvious.
Obviousness of Independent Claim 17
Independent Claim 17 describes a method where a POS interrogates a secure mobile device, receiving an expected cryptogram. The secure mobile device also sends the unpredictable data (from the POS) to a remote application system. Concurrently, the POS sends an authorization request, including the expected cryptogram and the unpredictable data, to the same remote application system. The application system then performs a "corroborative authorizing step" by verifying both the cryptogram and the unpredictable data (comparing what it received from the mobile device with what it received from the POS). [cite: The full patent text provided as authoritative information.]
This claim introduces a mutual verification process involving both the mobile device and the POS communicating with a remote application system.
Potential Combination: Prior art related to secure payment systems involving mobile devices (as for Claims 1 and 10), combined with prior art on mutual authentication between devices and transaction partners (e.g., as indicated by CPC G06Q20/40975) and prior art on secure communication protocols and trusted third parties for transaction authorization (e.g., H04L9/321).
Reasoning for Obviousness:
- Secure Mobile Device Interaction with POS: As established, mobile payment interactions with POS terminals using cryptographic responses were known.
- Trusted Third Party/Application System for Authorization: The role of a remote application system or trusted third party in authorizing financial transactions, especially for verifying cryptographic data, is fundamental to secure payment architectures. The patent explicitly states that an HSM (a component of such an application system) can be configured for "authorizing or verifying the output data (digital credential data) for any of the SEs contained in its repository data." [cite: The full patent text provided as authoritative information.]
- Dual Channel Communication and Corroboration: The concept of using multiple communication channels or corroborating information received from different sources to enhance security is a well-known principle in cryptography and secure systems design. The CPC classification H04L9/321 pertains to cryptographic mechanisms involving a third party or a trusted authority for identity verification or message authentication. Sending the unpredictable data from the mobile device to the remote application system, and also receiving it from the POS in the authorization request, provides a robust cross-check. This "corroborative authorizing step" directly addresses potential man-in-the-middle attacks or data tampering. If the unpredictable data received from the mobile device doesn't match what the application system receives from the POS, it indicates a potential security breach.
- Motivation for Combination: A PHOSITA would be strongly motivated to implement such a dual-channel corroboration system to increase the security and integrity of mobile financial transactions.
- Fraud Prevention: By comparing the unpredictable data from both the mobile device and the POS at a trusted remote system, the system can detect if either the mobile device or the POS (or the communication channels in between) has been compromised. This adds a critical layer of fraud prevention.
- Enhanced Trust: The corroborative verification builds a higher level of trust in the transaction, benefiting the merchant, card issuer, and card associations by reducing risk. The patent itself emphasizes the importance of knowing "beyond reasonable doubt that the data string being delivered indeed came from a particular SE or card." [cite: The full patent text provided as authoritative information.] Dual verification contributes to this certainty.
- Meeting Security Standards: The banking and payment industry constantly evolves its security standards. A PHOSITA would seek to implement robust verification mechanisms to meet or exceed these standards.
The combination of established secure mobile payment techniques with the general principles of mutual authentication, trusted third-party verification, and dual-channel data corroboration for enhanced security would render Claim 17 obvious to a PHOSITA.
Generated 7/14/2026, 6:46:49 AM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Unified Patents
- US 10749859A concise summary of US Patent 10,749,859 is as follows: Title: File format and platform for storage and verification of credentials Assignee: Cortex MCP Inc Inventor: Shaunt M. Sarkissian Filing Date: May 24, 2019 Issue Date: August 18…
- US 8224794Here is a concise summary of US Patent 8,224,794. Title: Clearinghouse system, method, and process for inventorying and acquiring infrastructure, monitoring and controlling network performance for enhancement, and providing localized…
- US 7930575US Patent 7930575, titled "Microcontroller for controlling power shutdown process," was filed on September 10, 2007, and issued on April 19, 2011. The inventors are Yukari Suginaka, Toshifumi Hamaguchi, Yoshitaka Kitao, and Shinya…
- US 10735488Here's a concise summary of US patent 10735488: US Patent 10735488: Method of downloading digital content to be rendered Title: Method of downloading digital content to be rendered Assignee: Audio Pod Ip LLC (Current Assignee); Audio Pod…
- US 9512025Here is a concise summary of US Patent 9512025: US Patent 9512025 Title: Methods and apparatuses for reducing heat loss from edge directors Assignee: Corning Inc. Inventors: Ren Hua Chung, Ahdi El-Kahlout, David Scott Franzen, Brendan…
- US 10715806US Patent 10,715,806: Video Transcoding with Metadata Title: Systems, methods, and media for transcoding video data Assignee: Divx LLC Inventors: Ivan Vladimirovich Naletov, Sergey Zurpal Filing Date: March 11, 2019 Issue Date: July 14…
- US 9070374Here's a concise summary of US patent 9070374: Patent Number: US9070374B2 Title: Communication apparatus and condition notification method for notifying a used condition of communication apparatus by using a light-emitting device attached…
- US 11744686Summary of US Patent 11744686: Intraoral Device Title: Intraoral device Current Assignee: Solmetex LLC (though reassignment history also lists Incept Inc., Dryshield, LLC, and security interests by Midcap Financial Trust and Churchill…
Other patents in Financial Technology (FT)
- US 11416898US Patent 11416898B2, titled "Methods, systems, and apparatus for financing projects," was issued on August 16, 2022, from an application filed on May 24, 2019 (Application number US16/422,106). The inventor is John E. DeTitta. The current…
- US 11693938US patent 11693938, titled "Facial recognition authentication system including path parameters," was issued to Facetec Inc. The sole inventor listed is Kevin Alan Tussy. The patent has a filing date of August 27, 2020, and an issue date of…
- US 9123034US Patent 9123034, titled "Methods and systems for electronic payment for parking using autonomous position sensing," was issued to TRANSPARENT WIRELESS SYSTEMS LLC. Here is a summary of the patent: Title: Methods and systems for…
- US RE45971I am unable to provide a concise summary of US patent RE45971, including its abstract, detailed independent claims, assignee, inventors, filing dates, and issue dates, because direct retrieval of the patent's full text and claims from the…
- US 11018724US Patent 11018724: Concise Summary Title: Method and apparatus for emulating multiple cards in mobile devices Assignee: RFCyber Corp Inventors: Xiangzhen Xie, Liang Seng Koh, Hsin Pan Filing Date: March 1, 2013 Issue Date: May 25, 2021…
- US 10600046US Patent 10,600,046: Method and Apparatus for Mobile Payments Title: Method and apparatus for mobile payments Assignee: RFCyber Corp Inventors: Xiangzhen Xie, Liang Seng Koh, Hsin Pan Filing Date: June 2, 2015 Issue Date: March 24, 2020…
- US 8620039Here's a concise summary of US Patent 8620039: US Patent 8620039: Card device security using biometrics Title: Card device security using biometrics Current Assignee: Cpc Patent Technologies Pty Ltd Inventor: Christopher John Burke Filing…
- US 10796296US Patent 10,796,296 Summary Title: Kit, system and associated method and service for providing a platform to prevent fraudulent financial transactions Assignee: Paygeo LLC Inventors: Rabih S. Ballout Filing Date: May 22, 2020 Issue Date…
This patent in court (2)
2 tracked lawsuits name US 10032171.