Prosecution Insights
Last updated: October 02, 2026
Application No. 18/826,858

SYSTEMS AND METHODS FOR CRYPTOGRAPHIC AUTHENTICATION OF CONTACTLESS CARDS

Final Rejection §103§DP
Filed
Sep 06, 2024
Priority
Oct 02, 2018 — provisional 62/740,352 +4 more
Examiner
KORSAK, OLEG
Art Unit
2492
Tech Center
2400 — Computer Networks
Assignee
Capital One Services LLC
OA Round
2 (Final)
86%
Grant Probability
Favorable
3-4
OA Rounds
5m
Est. Remaining
93%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
840 granted / 980 resolved
+27.7% vs TC avg
Moderate +8% lift
Without
With
+7.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
20 currently pending
Career history
1001
Total Applications
across all art units

Statute-Specific Performance

§101
6.7%
-33.3% vs TC avg
§103
36.8%
-3.2% vs TC avg
§102
24.7%
-15.3% vs TC avg
§112
12.3%
-27.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 980 resolved cases

Office Action

§103 §DP
DETAILED ACTION Response to Amendment This action is in response to amendment filed August 31, 2026 for the application # 18/826,858 filed on September 06, 2024. Claims 1-20 are pending and are directed toward SYSTEMS AND METHODS FOR CRYPTOGRAPHIC AUTHENTICATION OF CONTACTLESS CARDS. Any claim objection/rejection not repeated below is withdrawn due to Applicant's amendment. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Response to Arguments Applicant’s arguments with regards to claims 1-20 have been fully considered, but they are moot because of new grounds of rejection. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 2, 9, 10, 15, and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Yeager (US 8,151,345, Apr. 3, 2012), in view of Wang et al. (US 2023/0146453, priority Jan. 25, 2018), hereinafter referred to as Yeager and Wang. As per claim 1, Yeager teaches a contactless card configured to enable authentication of a user to perform a function (Referring to FIG. 16, a diagram of a mobile phone with contactless or NFC functionality is displayed. One purpose of a mobile phone or like device with NFC technology is to enable the mobile phone itself to act as a payment card in order to make payments at a contactless terminal that may be located at a retailer location. Yeager, Column 18, lines 34-39), comprising: processing circuitry coupled with a memory and a contactless interface (In this embodiment the SE is embedded in a Secure IC within the phone. Yeager, Column 18, lines 39-40) to process instructions to: generate a first diversified key based on a counter value (An example of this is that the data file of sensitive or licensed content may be encrypted with a key or a diversified key based on the key within the SE. This would allow only the card holder of the SE to successfully "unlock" and view or listen to the protected content. Many embodiments use a transaction counter that is stored and updated in the SE to uniquely identify a card holder as well as uniquely identify each given transaction or "swipe" from the card device. Yeager, Column 9, lines 18-27); encrypt identification data of the user using the first diversified key to create encrypted identification data (The middle 4 digits to be encrypted may be represented in 14 bits. The 14 bits to be encrypted of the original account number are also shown at the bottom of FIG. 13 .2. According to PIPS 81, using DES in OFB mode, the number of bits to encrypt can range from one to sixty-four during each iteration of the algorithm. Yeager, Column 16, lines 9-14); generate a second diversified key (The DES key ID may or may not be included is some embodiments. The purpose is to allow many different DES keys to be used by many different interrogators. Further on this subject, it is possible to create greater randomization of DES key by including a diversification process of the DES key in the interrogator application. A diversification process takes a master key and applies an algorithm to the key based on known data to produce a further randomized key to be used in the actual transaction. Yeager, Column 15, lines 65-67 - Column 16, lines 1-6); encipher the encrypted identification data with the second diversified key to create enciphered encrypted identification data (In order achieve the final cipher text; the first fourteen bits of the DES encrypted output text are XORed with the fourteen account bits that are to be encrypted. The resultant output is the fourteen bit cipher text to be placed back into the PAN, creating an encrypted PAN. Yeager, Column 16, lines 16-21); and transmit the enciphered encrypted identification data to authenticate the user and authorize a receiving device to perform the function, the function to authenticate the receiving device access sensitive information (Now, it is possible for this number to be processed in the exact same manner as a legitimate card PAN. The decryption device must be used to replace the encrypted PAN with the original PAN, but it is important to note that all the information for how to do so, including the transaction counter and DES key ID are included in the encrypted PAN. Yeager, Column 16, lines 27-33), transfer the sensitive information to another device (a communications controller affixed to the mounting structure and configured to receive the file information from the secure element reader and to convert at least a portion of the file information into transaction information and to transmit the transaction information to the computer terminal through the communications connector, Yeager, Column 20, lines 35-40), or authenticate performance of a sensitive operation (In preferred embodiments the interrogation process conforms to application level protocols (APis) established by ISO 7816-4. ISO 7816-4 defines two such application-level protocols: (a) File systemAPI providing a set of functions to manipulate files ( e.g. read, write, select etc.) (b) Security service API allowing the smart card and the reader to mutually authenticate themselves and also to encrypt data to be exchanged between the card and the reader. Yeager, Column 11, lines 29-38). Yeager teaches wherein the authentication key is diversified from a first/second master key (Security service API allowing the smart card and the reader to mutually authenticate themselves and also to encrypt data to be exchanged between the card and the reader. Yeager, Column 11, 35-38) but does not teach “based on a combination of the counter value and a data encryption key”, Wang however teaches (Further, the access token generation module 214 may include code enabling the processor 202 to generate diversified cryptographic keys from UDKs. For example, the access token generation module 214 may include code enabling the processor 202 to combine a UDK with a variable value and a salt, and then encrypt the combination to produce a diversified cryptographic key. This combination could be serial concatenation as described above, or another combination method, such as by calculating the exclusive or (XOR) of the UDK, salt, and variable value, then encrypting the combination to produce the diversified cryptographic key. Wang, [0083]). Yeager in view of Wang are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Yeager in view of Wang. This would have been desirable because there are a number of other ways in which an access token may be generated by combining user information and performing an encryption operation, (Wang, [0081]). As per claim 2, Yeager in view of Wang teaches the contactless card of claim 1, the processing circuitry to further process instructions to concatenate the encrypted identification data with one or more blocks of random data (An unpredictable number refers a number that may be used in algorithms of certain financial transaction authorization systems, such as VISA® or MASTERCARD®, in the encryption phase of a dynamic card verification code (DCVC). A DCVC is a 3 digit encrypted number that changes for each transaction (the dynamic aspect of the track data). The algorithm to create a DCVC typically uses a UN, a transaction counter, and DES key to derive a DCVC for each transaction. In some embodiments the financial transaction authorization system instructs a reader to create an unpredictable number. In some embodiments the communications controller may be configured to create a random UN and send it to the secure element during a transaction. Yeager, Column 17, lines 25-38) to create a concatenated encrypted identification data prior to enciphering the encrypted identification data (In FIG. 13 .1, and FIG. 13 .2, one embodiment of an encryption algorithm is shown. This embodiment used DES in OFB mode as described in PIPS 81 as defined by NIST. A known initialization vector is XOR with a transaction counter that is maintained by the reader-on-card. Every transaction that is committed to, the counter increases. This will effectively change the initialization vector for encrypting the PAN digits. Yeager, Column 15, lines 42-48). Claims 9, 10, 15, and 16 have limitations similar to those treated in the above rejection, and are met by the references as discussed above, and are rejected for the same reasons of obviousness as used above. Claims 3, 4, 6-8, 11, 12, 14, and 17-20 are rejected under 35 U.S.C. 103 as being unpatentable over Yeager (US 8,151,345, Apr. 3, 2012), in view of Wang et al. (US 2023/0146453, priority Jan. 25, 2018), in view of Amri (US 2004/0173686, Sep. 9, 2004), hereinafter referred to as Yeager, Wang and Amri. As per claim 3, Yeager in view of Wang teaches the contactless card of claim 1, and further teaches the function to authorize the receiving device to transfer (Further, there is a communications controller that is configured to receive the file information from the secure element reader and to convert at least a portion of the file information into transaction authorization information and to transmit the transaction authorization information to the cellular network device through the cellular network application interface. Yeager, Column 2, lines 33-38), but does not teach medical staff, Amri however teaches and further teaches insurance information to a medical provider, a doctor, medical staff, support staff, billing agent, or a combination thereof (This type of e-card (that complies e.g. with the ISO 7816 standard Parts 1-4 (T=0, T=l)) is used in a wide variety of applications including network security, vending, meal plans, loyalty, electronic cash, government IDs, campus IDs, e-commerce, health cards, and many more. Amri, [0020]). Yeager in view of Amri are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Yeager in view of Amri. This would have been desirable to be used in various administrative, financial and other applications, in particular bank cheques and other paper value documents that require authentication, boarding passes for transport systems, documents for access functions, and multipurpose uses (Amri, [0001]). As per claim 4, Yeager in view of Wang in view of Amri teaches the contactless card of claim 1, the function to authorize the receiving device to amend contact information, edit a password, or change portfolio positions (Amri, [0023]). Yeager in view of Amri are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Yeager in view of Amri. This would have been desirable to be used in various administrative, financial and other applications, in particular bank cheques and other paper value documents that require authentication, boarding passes for transport systems, documents for access functions, and multipurpose uses (Amri, [0001]). As per claim 6, Yeager in view of Wang in view of Amri teaches the contactless card of claim 1, the function to authorize the receiving device to access personal information, account information, transaction history, call history, previous notes, or other information (Amri, [0020]). Yeager in view of Amri are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Yeager in view of Amri. This would have been desirable to be used in various administrative, financial and other applications, in particular bank cheques and other paper value documents that require authentication, boarding passes for transport systems, documents for access functions, and multipurpose uses (Amri, [0001]). As per claim 7, Yeager in view of Wang in view of Amri teaches the contactless card of claim 1, the function to authorize the receiving device, or receiving devices, to access to a date of birth, an address, a password, a social security number, other identifying information, or a combination thereof (Amri, [0023]). Yeager in view of Amri are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Yeager in view of Amri. This would have been desirable to be used in various administrative, financial and other applications, in particular bank cheques and other paper value documents that require authentication, boarding passes for transport systems, documents for access functions, and multipurpose uses (Amri, [0001]). As per claim 8, Yeager in view of Wang in view of Amri teaches the contactless card of claim 1, the function to authorize the receiving device access to a home address, work address, phone number, credit card number, bank account number, billing zip code, security number, biometric identification information, or a combination thereof (Amri, [0137]). Yeager in view of Amri are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Yeager in view of Amri. This would have been desirable to be used in various administrative, financial and other applications, in particular bank cheques and other paper value documents that require authentication, boarding passes for transport systems, documents for access functions, and multipurpose uses (Amri, [0001]). Claims 11, 12, 14, and 17-20 have limitations similar to those treated in the above rejection, and are met by the references as discussed above, and are rejected for the same reasons of obviousness as used above. Claims 5 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Yeager (US 8,151,345, Apr. 3, 2012), in view of Wang et al. (US 2023/0146453, priority Jan. 25, 2018), in view of Brown (US 2011/0161232, Jun. 30, 2011), hereinafter referred to as Yeager, Wang and Brown. As per claim 5, Yeager in view of Wang teaches the contactless card of claim 1, and further teaches the function to authorize the receiving device to initiate (Further, there is a communications controller that is configured to receive the file information from the secure element reader and to convert at least a portion of the file information into transaction authorization information and to transmit the transaction authorization information to the cellular network device through the cellular network application interface. Yeager, Column 2, lines 33-38), but does not teach a secure chat or call with a customer service agent. Brown however teaches a secure chat or call with a customer service agent (the mobile device 202 can be synchronized through a vendor's website, or via phone, chat corporate IT administrator of the device ( e.g., Corporate RIM Blackberry devices) to ensure user authentication and authorization based upon registration data entered during the initial registration process and the server key recovery process 224 is used to clear out any registered cryptograms in server registered cryptogram database 228. Brown, [0036]). Yeager in view of Brown are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Yeager in view of Brown. This would have been desirable for Clearing either of the cryptogram databases 228 and 229 causes the registration processes 210 and 222 to engage the user for substitute objects to be registered. (Brown, [0036]). Claim 13 has limitations similar to those treated in the above rejection, and are met by the references as discussed above, and are rejected for the same reasons of obviousness as used above. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b). Claims 1-20 are rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over claims 1-20 of US patent No. 12,106,294. Although the conflicting claims are not identical, they are not patentably distinct from each other because all elements of claims 1-20 of the instant application correspond to elements of claims 1-20 of US patent No. 12,106,294. The above claims of the present application would have been obvious over claims 1-20 of US patent No. 12,106,294 because each element of the claims of the present application is anticipated by the claims of the US patent No. 11132698 and as such are unpatentable for obviousness-type double patenting (In re Goodman (CAFC) 29 USPQ2D 2010 (12/3/1993)). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to OLEG KORSAK whose telephone number is (571)270-1938. The examiner can normally be reached on 5:00 AM- 4:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal Dharia can be reached on (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /OLEG KORSAK/Primary Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Sep 06, 2024
Application Filed
Mar 31, 2026
Non-Final Rejection mailed — §103, §DP
Aug 31, 2026
Response Filed
Sep 23, 2026
Final Rejection mailed — §103, §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748862
FUNCTION-BASED SERVICE FRAMEWORK BASED ON TRUSTED EXECUTION ENVIRONMENT
4y 0m to grant Granted Sep 29, 2026
Patent 12748734
CANONICAL TRANSFORMATIONS USING MACHINE LEARNING LANGUAGE MODEL
3y 3m to grant Granted Sep 29, 2026
Patent 12749073
SYSTEMS AND METHODS FOR USER AUTHORIZATION AND ACCESS TO SERVICES USING CONTACTLESS CARDS
2y 6m to grant Granted Sep 29, 2026
Patent 12750208
MANAGING ENCRYPTION KEYS FOR CONTENT
2y 3m to grant Granted Sep 29, 2026
Patent 12748835
METHOD FOR SECURELY OPERATING A SOFTWARE COMPONENT
2y 0m to grant Granted Sep 29, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
86%
Grant Probability
93%
With Interview (+7.6%)
2y 6m (~5m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 980 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month