Prosecution Insights
Last updated: October 02, 2026
Application No. 17/883,232

SYSTEMS AND METHODS FOR CRYPTOGRAPHIC CONTEXT-SWITCHING AUTHENTICATION BETWEEN WEBSITE AND MOBILE DEVICE

Non-Final OA §112
Filed
Aug 08, 2022
Examiner
NILFOROUSH, MOHAMMAD A
Art Unit
3697
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Capital One Services LLC
OA Round
3 (Non-Final)
31%
Grant Probability
At Risk
3-4
OA Rounds
1y 0m
Est. Remaining
67%
With Interview

Examiner Intelligence

Grants only 31% of cases
31%
Career Allowance Rate
127 granted / 412 resolved
-21.2% vs TC avg
Strong +36% interview lift
Without
With
+36.1%
Interview Lift
resolved cases with interview
Typical timeline
5y 2m
Avg Prosecution
15 currently pending
Career history
435
Total Applications
across all art units

Statute-Specific Performance

§101
26.3%
-13.7% vs TC avg
§103
35.5%
-4.5% vs TC avg
§102
7.5%
-32.5% vs TC avg
§112
29.9%
-10.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 412 resolved cases

Office Action

§112
DETAILED ACTION Acknowledgements The amendment filed 7/14/2026 is acknowledged. Claims 1-12 and 14-21 are pending. Claims 1-12 and 14-21 have been examined. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after allowance or after an Office action under Ex Parte Quayle, 25 USPQ 74, 453 O.G. 213 (Comm'r Pat. 1935). Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, prosecution in this application has been reopened pursuant to 37 CFR 1.114. Applicant's submission filed on 7/14/2026 has been entered. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claim 20 is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention Claim 20 recites “encrypting, using a symmetric encryption scheme, the user identity and payment credential information transmitted, from the contactless card, to the authentication application on the user device with a symmetric encryption.” This limitation requires encrypting the user identity and payment credential information using a symmetric encryption scheme, but also states that this user identity and payment credential information is transmitted from the contactless card to the authentication application already encrypted with symmetric encryption. The specification does not provide support for encrypting user identity and payment credential information that is already transmitted from the contactless card in an encrypted format. Rather, the specification states that the contactless card has a symmetrically encrypted NFC channel, which is used to transmit the encrypted identity and payment credential information to the authentication application on the user device (See Specification ¶ 35). Paragraph 38 additionally states that the transmission of data from the contactless card may be facilitated across a symmetrically encrypted NFC link, and the symmetric encryption may be associated with a common private cryptographic key shared between the contactless card, the target application and authentication application on the authentication server. However, the specification does not provide support for using symmetric encryption to perform a second encryption on information already encrypted with symmetric encryption when it was transmitted from the contactless card. Therefore, the specification does not provide support for this limitation. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 3 and 12 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 3 and 12 recite “wherein the authentication functionality is provided by the authentication application stored on the user device and operationally coupled with the data-collection application,” However, claims 1 and 10, on which each of claims 3 and 12, respectively depend, recite “an authentication functionality provided by an external authentication system.” Therefore, the description of the authentication functionality in claims 3 and 12 contradicts that of parent claims 1 and 10, because the parent claims require that the authentication functionality be provided “by an external authentication system,” while claims 3 and 12 require that the authentication functionality be provided “by the authentication application stored on the user device and operationally coupled with the data-collection application.” If the authentication functionality is provided by the external authentication system, it is not provided by the authentication application on the user device, and vice-versa. Therefore, the limitations of claims 3 and 12 are indefinite. Allowable Subject Matter The following is a statement of reasons for the indication of allowable subject matter: Claims 1-12 and 14-21 are allowable over the prior art. The present claims are directed to using custom and universal links to perform context-switching authentication, and then using a contactless card to auto-populate an interface on a merchant website. Specifically, the claims involve providing, by a merchant server, a custom link at an interface of a website of a merchant associated with the merchant server, wherein the website is integrated with an authentication functionality provided by an external authentication system, and in response to a user selection of the custom link, transmitting, by the merchant server to the external authentication system, a data request message including an initial user identifying information of the user. The claims then involve generating, by the external authentication system in response to receiving the data request message, a universal link, wherein the universal link comprises an application identifier for an authentication application associated with the external authentication system, determining, by the external authentication system based on the initial user identifying information, a device identifier identifying a user device of the user, and transmitting, by the external authentication system, the universal link to the user device, wherein the universal link is configured to launch the authentication application based on the application identifier prompting the user for an authentication action, the authentication action comprising bringing, within data communication range of the user device, a contactless card with a tag storing one or more user identity and payment credential information as transmittable data. The claims further involve receiving, by the external authentication system from the contactless card through the user device, the one or more user identity and payment credential information, and transmitting, by the external authentication system to the merchant server, the one or more user identity and credential information to be auto-populated by the merchant server on the interface of the website. The closest prior art of Torii (US 2021/0312437) discloses providing or displaying a custom link at an interface of a website, wherein the website is integrated with an authentication functionality provided by an external authentication system (Torii ¶¶ 125-126); generating, in response to a user selection of the custom link, a universal link (Torii ¶ 126), wherein the universal link comprises: a website identifier identifying the website where the custom link is activated by the user selection (Torii ¶ 126, “store ID”), a unique user identifier, the unique user identifier generated by the website to track a particular user session (Torii ¶ 126, “transaction ID”), and an identifier for an authentication application associated with the external authentication system, wherein the authentication application is stored on a user device from which the website is accessed (Torii ¶¶ 125-126, approval URL including deep link to launch authentication application 2022); and transmitting the universal link to the user device, wherein the universal link is configured to launch the authentication application prompting the user for an authentication action (Torii ¶¶ 124-126). Tsui, et al. (US 2016/0026997) (“Tsui”) additionally discloses bringing, within near field communication (NFC) range of the user device, a contactless card with an NFC tag storing one or more user identity and payment credential information as NFC transmittable data during authentication, and transmitting the one or more user identity and credential information, retrieved via an NFC from the contactless card, to be auto-populated on the interface of the website where the custom link is activated by the user selection (Tsui ¶¶ 71-82, 84-86, 127-132, 134-137, 147-149. 163). Further, Shrivastava (US 2014/0019352) discloses generating, in response to the user selection of a link, a virtual card number (VCN) and transmitting the VCN to the user device (Shrivastava ¶¶ 470-473). Additionally, Rule, et al. (US 10,467,622) (“Rule”) discloses the use of authenticating information that is retrieved via NFC from the contactless card (Rule 6:27-50; 11:6-26; 11:60-12:2; 13:11-14:15; 15:19-37). Finally, Martini (US 8,613,069) discloses generating a data packet that includes a URL redirection command to cause a wireless device’s browser to launch an authentication application, and if authentication app is not installed on user’s device, the link can go to the app store to download it. Martini discloses that the redirect command can include an application identifier that identifies the authentication application (Martini Figure 4; 4:23-35; 5:44-6:34; 7:34-62). Martini further discloses that the redirection command can include data items (Martini 8:14-29). However, the prior art does not disclose, neither singly nor in combination, the specific steps performed by the claimed invention in which the merchant server and external authentication system work in cooperation to provide context-switching authentication using a series of links, and then use information from a contactless card to auto-populate a website on the merchant server. Specifically, the prior art does not disclose the merchant server first providing a custom link at an interface of a website of a merchant associated with the merchant server, and then in response to a user selection of the custom link, the external authentication system generating a universal link based on a data request message sent through the custom link, the external authentication system determining a user device to send the universal link to, and transmitting the universal link to the user device, where the universal link launches an authentication application on the user device which reads user identity and payment credential information from a contactless card, and finally the external authentication receiving the user identity and payment credential information read from the card and transmitting it to the merchant server where it is auto-populated on the interface of the merchant’s website. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Mohammad A. Nilforoush whose telephone number is (571)270-5298. The examiner can normally be reached Monday-Friday 12pm-7pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John W. Hayes can be reached at 571-272-6708. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Mohammad A. Nilforoush/Primary Examiner, Art Unit 3697
Read full office action

Prosecution Timeline

Show 3 earlier events
Oct 22, 2025
Final Rejection mailed — §112
Mar 10, 2026
Applicant Interview (Telephonic)
Mar 11, 2026
Examiner Interview Summary
Mar 23, 2026
Request for Continued Examination
Mar 26, 2026
Response after Non-Final Action
Jul 14, 2026
Request for Continued Examination
Jul 21, 2026
Response after Non-Final Action
Sep 23, 2026
Non-Final Rejection mailed — §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737735
MIXED TECHNIQUE TRANSACTION CLASSIFICATION
2y 10m to grant Granted Sep 15, 2026
Patent 12718230
SECURE CRYPTO CURRENCY POINT-OF-SALE (POS) MANAGEMENT
4y 9m to grant Granted Aug 25, 2026
Patent 12705599
TRUSTED QR CODE GENERATION FOR FINANCIAL TRANSACTIONS
3y 5m to grant Granted Aug 11, 2026
Patent 12701019
CONTROL METHOD, NON-TRANSITORY COMPUTER-READABLE RECORDING MEDIUM STORING CONTROL PROGRAM, AND INFORMATION PROCESSING DEVICE
2y 10m to grant Granted Aug 04, 2026
Patent 12689518
Quantum Proof of Consent for Orchestrating Event Processing Across a Distributed Network
2y 4m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
31%
Grant Probability
67%
With Interview (+36.1%)
5y 2m (~1y 0m remaining)
Median Time to Grant
High
PTA Risk
Based on 412 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month