DETAILED ACTION
Acknowledgements
The amendment filed 7/14/2026 is acknowledged.
Claims 1-12 and 14-21 are pending.
Claims 1-12 and 14-21 have been examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after allowance or after an Office action under Ex Parte Quayle, 25 USPQ 74, 453 O.G. 213 (Comm'r Pat. 1935). Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, prosecution in this application has been reopened pursuant to 37 CFR 1.114. Applicant's submission filed on 7/14/2026 has been entered.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claim 20 is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention
Claim 20 recites “encrypting, using a symmetric encryption scheme, the user identity and payment credential information transmitted, from the contactless card, to the authentication application on the user device with a symmetric encryption.” This limitation requires encrypting the user identity and payment credential information using a symmetric encryption scheme, but also states that this user identity and payment credential information is transmitted from the contactless card to the authentication application already encrypted with symmetric encryption. The specification does not provide support for encrypting user identity and payment credential information that is already transmitted from the contactless card in an encrypted format. Rather, the specification states that the contactless card has a symmetrically encrypted NFC channel, which is used to transmit the encrypted identity and payment credential information to the authentication application on the user device (See Specification ¶ 35). Paragraph 38 additionally states that the transmission of data from the contactless card may be facilitated across a symmetrically encrypted NFC link, and the symmetric encryption may be associated with a common private cryptographic key shared between the contactless card, the target application and authentication application on the authentication server. However, the specification does not provide support for using symmetric encryption to perform a second encryption on information already encrypted with symmetric encryption when it was transmitted from the contactless card. Therefore, the specification does not provide support for this limitation.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 3 and 12 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 3 and 12 recite “wherein the authentication functionality is provided by the authentication application stored on the user device and operationally coupled with the data-collection application,” However, claims 1 and 10, on which each of claims 3 and 12, respectively depend, recite “an authentication functionality provided by an external authentication system.” Therefore, the description of the authentication functionality in claims 3 and 12 contradicts that of parent claims 1 and 10, because the parent claims require that the authentication functionality be provided “by an external authentication system,” while claims 3 and 12 require that the authentication functionality be provided “by the authentication application stored on the user device and operationally coupled with the data-collection application.” If the authentication functionality is provided by the external authentication system, it is not provided by the authentication application on the user device, and vice-versa. Therefore, the limitations of claims 3 and 12 are indefinite.
Allowable Subject Matter
The following is a statement of reasons for the indication of allowable subject matter:
Claims 1-12 and 14-21 are allowable over the prior art.
The present claims are directed to using custom and universal links to perform context-switching authentication, and then using a contactless card to auto-populate an interface on a merchant website. Specifically, the claims involve providing, by a merchant server, a custom link at an interface of a website of a merchant associated with the merchant server, wherein the website is integrated with an authentication functionality provided by an external authentication system, and in response to a user selection of the custom link, transmitting, by the merchant server to the external authentication system, a data request message including an initial user identifying information of the user. The claims then involve generating, by the external authentication system in response to receiving the data request message, a universal link, wherein the universal link comprises an application identifier for an authentication application associated with the external authentication system, determining, by the external authentication system based on the initial user identifying information, a device identifier identifying a user device of the user, and transmitting, by the external authentication system, the universal link to the user device, wherein the universal link is configured to launch the authentication application based on the application identifier prompting the user for an authentication action, the authentication action comprising bringing, within data communication range of the user device, a contactless card with a tag storing one or more user identity and payment credential information as transmittable data. The claims further involve receiving, by the external authentication system from the contactless card through the user device, the one or more user identity and payment credential information, and transmitting, by the external authentication system to the merchant server, the one or more user identity and credential information to be auto-populated by the merchant server on the interface of the website.
The closest prior art of Torii (US 2021/0312437) discloses providing or displaying a custom link at an interface of a website, wherein the website is integrated with an authentication functionality provided by an external authentication system (Torii ¶¶ 125-126); generating, in response to a user selection of the custom link, a universal link (Torii ¶ 126), wherein the universal link comprises: a website identifier identifying the website where the custom link is activated by the user selection (Torii ¶ 126, “store ID”), a unique user identifier, the unique user identifier generated by the website to track a particular user session (Torii ¶ 126, “transaction ID”), and an identifier for an authentication application associated with the external authentication system, wherein the authentication application is stored on a user device from which the website is accessed (Torii ¶¶ 125-126, approval URL including deep link to launch authentication application 2022); and transmitting the universal link to the user device, wherein the universal link is configured to launch the authentication application prompting the user for an authentication action (Torii ¶¶ 124-126). Tsui, et al. (US 2016/0026997) (“Tsui”) additionally discloses bringing, within near field communication (NFC) range of the user device, a contactless card with an NFC tag storing one or more user identity and payment credential information as NFC transmittable data during authentication, and transmitting the one or more user identity and credential information, retrieved via an NFC from the contactless card, to be auto-populated on the interface of the website where the custom link is activated by the user selection (Tsui ¶¶ 71-82, 84-86, 127-132, 134-137, 147-149. 163). Further, Shrivastava (US 2014/0019352) discloses generating, in response to the user selection of a link, a virtual card number (VCN) and transmitting the VCN to the user device (Shrivastava ¶¶ 470-473). Additionally, Rule, et al. (US 10,467,622) (“Rule”) discloses the use of authenticating information that is retrieved via NFC from the contactless card (Rule 6:27-50; 11:6-26; 11:60-12:2; 13:11-14:15; 15:19-37). Finally, Martini (US 8,613,069) discloses generating a data packet that includes a URL redirection command to cause a wireless device’s browser to launch an authentication application, and if authentication app is not installed on user’s device, the link can go to the app store to download it. Martini discloses that the redirect command can include an application identifier that identifies the authentication application (Martini Figure 4; 4:23-35; 5:44-6:34; 7:34-62). Martini further discloses that the redirection command can include data items (Martini 8:14-29).
However, the prior art does not disclose, neither singly nor in combination, the specific steps performed by the claimed invention in which the merchant server and external authentication system work in cooperation to provide context-switching authentication using a series of links, and then use information from a contactless card to auto-populate a website on the merchant server. Specifically, the prior art does not disclose the merchant server first providing a custom link at an interface of a website of a merchant associated with the merchant server, and then in response to a user selection of the custom link, the external authentication system generating a universal link based on a data request message sent through the custom link, the external authentication system determining a user device to send the universal link to, and transmitting the universal link to the user device, where the universal link launches an authentication application on the user device which reads user identity and payment credential information from a contactless card, and finally the external authentication receiving the user identity and payment credential information read from the card and transmitting it to the merchant server where it is auto-populated on the interface of the merchant’s website.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Mohammad A. Nilforoush whose telephone number is (571)270-5298. The examiner can normally be reached Monday-Friday 12pm-7pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John W. Hayes can be reached at 571-272-6708. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Mohammad A. Nilforoush/Primary Examiner, Art Unit 3697