Prosecution Insights
Last updated: August 17, 2026
Application No. 18/428,764

DEVICE-SPECIFIC PASSKEY COMMUNICATION SYSTEMS AND TECHNIQUES

Final Rejection §103
Filed
Jan 31, 2024
Examiner
ZHANG, DUAN
Art Unit
3699
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Wells Fargo Bank N A
OA Round
4 (Final)
61%
Grant Probability
Moderate
5-6
OA Rounds
6m
Est. Remaining
78%
With Interview

Examiner Intelligence

Grants 61% of resolved cases
61%
Career Allowance Rate
111 granted / 181 resolved
+9.3% vs TC avg
Strong +17% interview lift
Without
With
+16.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
28 currently pending
Career history
203
Total Applications
across all art units

Statute-Specific Performance

§101
27.8%
-12.2% vs TC avg
§103
48.6%
+8.6% vs TC avg
§102
6.1%
-33.9% vs TC avg
§112
14.4%
-25.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 181 resolved cases

Office Action

§103
DETAILED ACTION Acknowledgements This Office Action is in response to Applicant’s response/application filed on 06/12/2026. The Examiner notes that citations to United States Patent Application Publication paragraphs are formatted as [####], #### representing the paragraph number. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims Claims 1, 2, 7, 9, 10, 11, 16, 18, 19, 20 have been amended. Claims 4, 13 have been canceled. No claims have been added. Claims 1-3, 5-12, 14-22 are currently pending and have been examined. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103(a) are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 1, 2, 5, 9, 10, 11, 14, 18, 19, 20, 22 is/are rejected under 35 U.S.C. 103 as being unpatentable over Osborn (US 20250173705), in view of Murmfeld (US 20210049583), further in view of Matsugashita (US 20190068377). Regarding claim(s) 1, 10, 19, Osborn discloses: receiving, via the network from the remote banking server, in response to determining that the customer is a registered user, a passkey paired to an account of the customer and paired to a wallet of the customer; and sending, from the banking device via a proximity-based wireless communication protocol, the passkey to the mobile device of the customer. (By disclosing, “As another nonlimiting example, the authentication credential can be associated with an account number, routing number, customer identification number, password, PIN number, or some other datum associated with a specific financial or banking account.” ([0097]); “Having validated the credential, the server in action 735 can retrieve the encrypted private key, encrypted public key, and KEK that were previously provisioned to the user.” ([0100]); “Next, in action 740 the server can transmit the encrypted private key, encrypted public key, and KEK to the ATM…. Having received the keys, the ATM in action 745 can transmit the encrypted private key, encrypted public key, and KEK to the user device.” ([0101]-[0102], [0038]); and “The private key can be used to access the crypto wallet.” ([0067])). Osborn does not disclose: initiating an authentication of a customer at a banking device based on a mobile device of the customer being physically proximate to the banking device; receiving, from the mobile device via a proximity-based communication protocol, information tied to the mobile device of the customer; determining, at the banking device, that the customer is a registered mobile app user, based on verification of the received information tied to the mobile device with user information stored at a remote banking server; wherein the passkey comprises a private key to be stored on the mobile device, and wherein the private key is paired with a corresponding public key stored at the remote banking server; wherein the passkey is stored at the mobile device in response to receipt of the passkey, and wherein the passkey is a device-specific credential that is registered to the mobile device; and cryptographically verifying information encrypted or signed with the passkey, using the remote banking server, wherein the information encrypted or signed with the passkey is subsequently provided from the mobile device to the remote banking server additional proof of identity of the customer, in connection with a subsequent access to or use of the account at the remote banking server. However, Wurmfeld teaches: initiating an authentication of a customer at a banking device based on a mobile device of the customer being physically proximate to the banking device (By disclosing, “The ATM 130 may detect the user device 120 in its immediate proximity. The user device 120 may then connect to the ATM 130 in order to initiate, conduct, or complete a financial transaction.” ([0039] of Wurmfeld); and “At step 602, the user device 120 may authenticate via the authentication system access to a customer account via a mobile application on the device. For example, the user device 120 may authenticate the user 160 to access a financial account of the user 160 stored on the financial service provider device 140 by communicating via the application 260 with the financial service provider device 140.” ([0084] of Wurmfeld)); receiving, from the mobile device via a proximity-based communication protocol, information tied to the mobile device of the customer (By disclosing, “At step 610, the user device 120 may send to the ATM 130 via the first communications means identifying information of a user who is using the user device 120. The user 160 may log into the financial service provider device 140 via the application 260 on the user device 120 to retrieve the identifying information and send the identifying information to the ATM 130” ([0090] of Wurmfeld)); determining, at the banking device, that the customer is a registered mobile app user, based on verification of the received information tied to the mobile device with user information stored at a remote banking server ([0091]-[0092], [0077]-[0079] of Wurmfeld). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the invention of Osborn in view of Wurmfeld to include techniques of initiating an authentication of a customer at a banking device based on a mobile device of the customer being physically proximate to the banking device; receiving, from the mobile device via a proximity-based communication protocol, information tied to the mobile device of the customer; and determining, at the banking device, that the customer is a registered mobile app user, based on verification of the received information tied to the mobile device with user information stored at a remote banking server. Doing so would result in an improved invention because this would leverage the advantages of using near-field communication (e.g., enhanced security, speed and efficiency, etc.). And Matsugashita teaches: wherein the passkey comprises a private key to be stored on the mobile device, and wherein the private key is paired with a corresponding public key stored at the remote banking server; wherein the passkey is stored at the mobile device in response to receipt of the passkey, and wherein the passkey is a device-specific credential that is registered to the mobile device (By disclosing, “The authorization server 200 having received the registration request generates a client ID for identifying the client 400 and a key pair of an encryption key and a decryption key (or a public key and a private key) for authenticating the client 400. According to this embodiment, a private key and an encryption key will be exemplarily described below. The authorization server 200 returns the generated client ID and the private key as a registration response to the client 400 (S3.1). The client ID and the private key are saved in association with each other in the client 400 while the client ID and the public key are saved in association with each other in the authorization server 200.” ([0052] of Matsugashita)); and cryptographically verifying information encrypted or signed with the passkey, using the remote banking server, wherein the information encrypted or signed with the passkey is subsequently provided from the mobile device to the remote banking server additional proof of identity of the customer, in connection with a subsequent access to or use of the account at the remote banking server. (By disclosing, “The authorization server 200 having received the token request in S5.0 verifies a signature in the JWT by using a public key identified from the client ID. If the verification succeeds and the client 400 is authenticated, the authorization server 200 issues an authorization token and transmits a token response to the client 400 (S2.1).” ([0069 of Matsugashita); and “More specifically, the HTTP server unit 220 is configured to receive a user authentication request from the web browser 510, generate an authorization token associated with user information on a user who have been successfully authenticated, and notify the authorization token to the web browser 510. The authorization token here may be a token indicating that a user is logging in the authorization server 200 or a token for verifying whether a user has been authenticated by the authorization server 200. Use of the authorization token enables the authorization server 200 to identify a user. An authorization code, on the other hand, is a token indicating that the client 400 to which authority is transferred through an authorization operation performed by an authenticated user is permitted to access an API of the resource server 300 on behalf of the user.” ([0041] of Matsugashita)). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the invention of Osborn and Wurmfeld, in view of Matsugashita to include techniques of “wherein the passkey comprises a private key to be stored on the mobile device, and wherein the private key is paired with a corresponding public key stored at the remote banking server; wherein the passkey is stored at the mobile device in response to receipt of the passkey, and wherein the passkey is a device-specific credential that is registered to the mobile device; and cryptographically verifying information encrypted or signed with the passkey, using the remote banking server, wherein the information encrypted or signed with the passkey is subsequently provided from the mobile device to the remote banking server additional proof of identity of the customer, in connection with a subsequent access to or use of the account at the remote banking server.” Doing so would result in an improved invention because this would allow the system to identify/authenticate the user/user device based on the passkey. Additionally, regarding claim 10, Osborn discloses: at least one non-transitory machine-readable medium including instructions ([0007]). Additionally, regarding claim 19, Osborn discloses: a banking server configured to: store a passkey and a corresponding public key; and store a list of registered mobile app users ([0093], [0040]). Regarding claim(s) 2, Osborn discloses: wherein the proximity-based wireless communication protocol is a near-field communication (NFC) protocol. ([0095]-[0097], [0038]). Regarding claim(s) 5, 14, and 22, Osborn discloses: wherein the passkey is configured to be used in a stepped-up authentication for a login to the account or a transaction using the account ([0114]-[0118])). Regarding claim(s) 9, 18, Osborn discloses: wherein the proximity-based wireless communication protocol includes at least one of Bluetooth technologies, radio frequency identification (RFID) technologies, or ultrawide band technologies. ([0095]-[0097]). Regarding claim(s) 11, 20, Osborn discloses: wherein the proximity-based communication protocol includes at least one of Bluetooth technologies, radio frequency identification (RFID) technologies, ultrawide band technologies, or a near-field communication (NFC) protocol. ([0095]-[0097]). Claim(s) 3, 12, and 21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Osborn (US 20250173705), in view of Murmfeld (US 20210049583), further in view of Matsugashita (US 20190068377), and Hou (CN 101807319 A). Regarding claim(s) 3, 12, and 21 Osborn does not disclose, but Hou teaches: wherein sending the passkey to the mobile device occurs in response to determining that the mobile device has tapped the banking device (By disclosing, a user taps the ATM to input user’s phone number, and the ATM sends a passcode to the user’s mobile device in response to detecting the tapped phone number ([0066] of Hou)). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the combination of Osborn, Wurmfeld and Matsugashita, in view of Hou to include techniques of wherein sending the passkey to the mobile device occurs in response to determining that the mobile device has tapped the banking device. Doing so would result in an improved invention because this would allow the user obtain the passcode at an automatic teller machine. Claim(s) 6, 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Osborn (US 20250173705), in view of Murmfeld (US 20210049583), further in view of Matsugashita (US 20190068377), and Kaladgi (US 20190303928). Regarding claim(s) 6, 15, Osborn does not disclose, but Kaladgi teaches: wherein the passkey conforms with a FIDO (Fast IDentity Online) authentication specification (By disclosing, “the public/private key pair are generated according to the Fast ID Online (FIDO) protocol” ([0023] of Kaladgi)). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the combination of Osborn, Wurmfeld, and Matsugashita, in view of Kaladgi to include techniques of wherein the passkey conforms with a FIDO (Fast IDentity Online) authentication specification. Doing so would result in an improved invention because this would leverage the advantages of using FIDO protocol (e.g. simplifying user experience, reducing costs for business, enhancing security, etc.). Claim(s) 7, 8, 16, 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Osborn (US 20250173705), in view of Murmfeld (US 20210049583), further in view of Matsugashita (US 20190068377), Androulaki (US 20220150073), and Arora (US 20190340584). Regarding claim(s) 7, 16, Osborn does not disclose, but Matsugashita teaches: receiving, at the banking device, an indication from the mobile device corresponding to a transaction, wherein the indication includes the information encrypted or signed by the passkey; authenticating the information encrypted or signed by the passkey with a public key stored at a banking server; (By disclosing, “The authorization server 200 having received the token request in S5.0 verifies a signature in the JWT by using a public key identified from the client ID. If the verification succeeds and the client 400 is authenticated, the authorization server 200 issues an authorization token and transmits a token response to the client 400 (S2.1).” ([0069 of Matsugashita); and “More specifically, the HTTP server unit 220 is configured to receive a user authentication request from the web browser 510, generate an authorization token associated with user information on a user who have been successfully authenticated, and notify the authorization token to the web browser 510. The authorization token here may be a token indicating that a user is logging in the authorization server 200 or a token for verifying whether a user has been authenticated by the authorization server 200. Use of the authorization token enables the authorization server 200 to identify a user. An authorization code, on the other hand, is a token indicating that the client 400 to which authority is transferred through an authorization operation performed by an authenticated user is permitted to access an API of the resource server 300 on behalf of the user.” ([0041] of Matsugashita)). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the invention of Osborn and Wurmfeld, in view of Matsugashita to include techniques of receiving, at the banking device, an indication from the mobile device corresponding to a transaction, wherein the indication includes the information encrypted or signed by the passkey; authenticating the information encrypted or signed by the passkey with a public key stored at a banking server. Doing so would result in an improved invention because this would leverage the advantages of using private/public key pair authentication (e.g. improved security, etc.). And Arora teaches: outputting, for display on the banking device, approval for the transaction in response to authenticating the passkey (By disclosing, “The display device 208 may be configured to, for example, display messages indicating successful or unsuccessful approval of use of the check 106 based on the validations discussed herein.” ([0036] of Arora)). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the invention of Osborn, Wurmfeld, Matsugashita, and Androulaki, in view of Arora to include techniques of outputting, for display on the banking device, approval for the transaction in response to authenticating the passkey. Doing so would result in an improved invention because this would allow the user to acknowledge the result of the authentication from the bank. Regarding claim(s) 8, 17, Osborn does not disclose, but Arora teaches: wherein the transaction includes at least one of sending a wire transfer, opening a new account, or cashing a check ([0021] of Arora). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the invention of Osborn, Wurmfeld, and Matsugashita, in view of Arora to include techniques of wherein the transaction includes at least one of sending a wire transfer, opening a new account, or cashing a check. Doing so would result in an improved invention because this would allow the user to use a check to pay for a transaction. Response to Arguments Applicant’s arguments with regard to the 35 U.S.C. § 103 rejection have been considered but are moot in view of new grounds of rejection initiated by applicant’s amendment to the claims. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20170330179 to Song for disclosing: A method for issuing authentication information is provided. The method includes steps of: (a) a managing server, if identification information of a specific user is acquired from a user device in response to a request for issuing the authentication information and the identification information is determined to be registered, creating a transaction whose output includes: (i) the specific user's public key and (ii) a hash value of the identification information or its processed value to thereby record or support other device to record it on a blockchain; and (b) the managing server acquiring a transaction ID representing location information of the transaction recorded on the blockchain. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DUAN ZHANG whose telephone number is (571)272-4642. The examiner can normally be reached Mon - Fri 10 AM-5 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha Patel can be reached at 571-270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DUAN ZHANG/Primary Examiner, Art Unit 3699
Read full office action

Prosecution Timeline

Show 5 earlier events
Jan 12, 2026
Request for Continued Examination
Feb 19, 2026
Response after Non-Final Action
Mar 12, 2026
Non-Final Rejection mailed — §103
May 29, 2026
Interview Requested
Jun 09, 2026
Examiner Interview Summary
Jun 09, 2026
Applicant Interview (Telephonic)
Jun 12, 2026
Response Filed
Jul 14, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699987
TRANSACTION SYSTEM WITH ACCOUNT MAPPING
6y 8m to grant Granted Aug 04, 2026
Patent 12699990
AUTOMATED APPLICATION PROGRAMMING INTERFACE (API) SYSTEM AND METHOD
1y 6m to grant Granted Aug 04, 2026
Patent 12688499
DEVICE AND SYSTEMS FOR PROVISIONING AND VERIFYING TOKENS WITH STRONG IDENTITY AND STRONG AUTHENTICATION
2y 11m to grant Granted Jul 21, 2026
Patent 12675789
DESTINATION ADDRESSING ASSOCIATED WITH A DISTRIBUTED LEDGER
4y 8m to grant Granted Jul 07, 2026
Patent 12664545
MULTI-INPUT TRANSACTIONS
2y 1m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
61%
Grant Probability
78%
With Interview (+16.9%)
3y 0m (~6m remaining)
Median Time to Grant
High
PTA Risk
Based on 181 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month