Prosecution Insights
Last updated: October 02, 2026
Application No. 18/973,728

CONTACTLESS CARD WITH MULTIPLE ROTATING SECURITY KEYS

Non-Final OA §103§DOUBLEPATENT
Filed
Dec 09, 2024
Priority
Apr 30, 2020 — continuation of 10/915,888 +2 more
Examiner
TOLENTINO, RODERICK
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Capital One Services LLC
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
1y 8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
558 granted / 719 resolved
+19.6% vs TC avg
Strong +35% interview lift
Without
With
+35.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
18 currently pending
Career history
742
Total Applications
across all art units

Statute-Specific Performance

§101
14.3%
-25.7% vs TC avg
§103
61.1%
+21.1% vs TC avg
§102
11.3%
-28.7% vs TC avg
§112
6.8%
-33.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 719 resolved cases

Office Action

§103 §DOUBLEPATENT
CTNF 18/973,728 CTNF 81478 Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. Detailed Action Office Action is in response to the instant Application 18/973,728 filed on 12/9/2024 and Preliminary Amendments filed on 2/19/2025. Claims 1-20 were cancelled in Preliminary Amendment. Claims 21-40 was added as New in Preliminary Amendment. Claim 21-40 is pending. This Office Action is Non-Final. Double Patenting 08-33 AIA The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg , 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman , 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi , 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum , 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel , 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington , 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA/25, or PTO/AIA/26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. 08-34 AIA Claim s 21, 33 and 38 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim s 1, 10 and 18 of U.S. Patent No. 12,205,103 . Although the claims at issue are not identical, they are not patentably distinct from each other because all the limitations of claims 21, 33 and 38 of the instant Application are anticipated by the limitations recited in 1, 10 and 18 of U.S. Patent No. 12,205,103 . Regarding claims 22-32, 34-37, 39 and 40; claims 22-32, 34-37, 39 and 40are also rejected under Double Patenting for similar reasons respectively and are dependent on claims 21, 33 and 38 and therefore inherit the rejection from issues of the independent claims . 08-34 AIA Claim s 53, 62 and 70 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim s 1, 9 and 15 of U.S. Patent No. 11,562,346 . Although the claims at issue are not identical, they are not patentably distinct from each other because all the limitations of claims 53, 62 and 70 of the instant Application are anticipated by the limitations recited in 1, 9 and 15 of U.S. Patent No. 11,562,346 . Regarding claims 22-32, 34-37, 39 and 40; claims 22-32, 34-37, 39 and 40are also rejected under Double Patenting for similar reasons respectively and are dependent on claims 21, 33 and 38 and therefore inherit the rejection from issues of the independent claims . 08-34 AIA Claim s 53, 62 and 70 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim s 1 and 11 of U.S. Patent No. 10,915,888 . Although the claims at issue are not identical, they are not patentably distinct from each other because all the limitations of claims 53, 62 and 70 of the instant Application are anticipated by the limitations recited in 1 and 11 of U.S. Patent No. 10/915,888 . Regarding claims 22-32, 34-37, 39 and 40; claims 22-32, 34-37, 39 and 40are also rejected under Double Patenting for similar reasons respectively and are dependent on claims 21, 33 and 38 and therefore inherit the rejection from issues of the independent claims . Claim Rejections - 35 USC § 103 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-20-02-aia AIA This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. 07-21-aia AIA Claim (s) 21, 33 and 38-40 is/are rejected under 35 U.S.C. 103 as being unpatentable over Mirza et al. (US 2017/0244685) in view of Covdy et al. (US 2018/0302400) . As per claim 21, Mirza teaches a method performed by a contactless card comprising a memory containing a plurality of keys and a key selection algorithm, a transceiver, and a processor in communication with the memory and the transceiver, the method comprising: receiving, from a client device, an input signal; selecting a selected key from the plurality of keys using the key selection algorithm and the input signal; encrypting a communication using the first selected key to obtain an encrypted communication (Mirza, Claim 1 recites “1. A system, comprising: at least one computing device comprising at least one processor and memory storing instructions that, when executed by the at least one computing device, cause the at least one computing device to at least: generate a plurality of segments of a data payload; select, for each of the plurality of segments, a respective encryption key from of a pool of encryption keys; encrypt each of the plurality of segments as a function of the respective encryption key; and communicate each of the plurality of segments to a network destination by distributing the plurality of segments amongst a plurality of network paths to the network destination.” And Claim 9 recites “9. The system of claim 1, wherein the respective encryption key is selected from the pool of encryption keys by, for each of the plurality of segments, selecting, as the respective encryption key, a next one of the pool of encryption keys in a rotation of use for the pool of encryption keys.”). But fails to teach transmitting, to the client device via the transceiver, the encrypted communication. However, in an analogous art Covdy teaches transmitting, to the client device via the transceiver, the encrypted communication (Covdy, Paragraph 0022 “In response to receiving the encrypted information from the security device, the server device can send the encrypted information to the client device for usage in accessing the instance.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Covdy’s authenticating access to an instance with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of a secure way to transmit data to a client. Regarding claims 33 and 38, claims 33 and 38 are directed to a device and a non-transitory readable medium associated with the method of claim 21. Claims 33 and 38 are of similar scope to claim 21, and are therefore rejected under similar rationale. As per claim 39, Mirza in combination with Covdy teaches the non-transitory computer-readable medium of claim 38, Mirza further teaches wherein the key selection algorithm is selecting the first selected key based on an assigned order Mirza, Claim 1 recites “1. A system, comprising: at least one computing device comprising at least one processor and memory storing instructions that, when executed by the at least one computing device, cause the at least one computing device to at least: generate a plurality of segments of a data payload; select, for each of the plurality of segments, a respective encryption key from of a pool of encryption keys; encrypt each of the plurality of segments as a function of the respective encryption key; and communicate each of the plurality of segments to a network destination by distributing the plurality of segments amongst a plurality of network paths to the network destination.” And Claim 9 recites “9. The system of claim 1, wherein the respective encryption key is selected from the pool of encryption keys by, for each of the plurality of segments, selecting, as the respective encryption key, a next one of the pool of encryption keys in a rotation of use for the pool of encryption keys.”) As per claim 40, Mirza in combination with Covdy teaches the non-transitory computer-readable medium of claim 39, Mirza further teaches assigning the assigned order to the plurality of keys; and transmitting, via the transceiver, the assigned order to the client device Mirza, Claim 1 recites “1. A system, comprising: at least one computing device comprising at least one processor and memory storing instructions that, when executed by the at least one computing device, cause the at least one computing device to at least: generate a plurality of segments of a data payload; select, for each of the plurality of segments, a respective encryption key from of a pool of encryption keys; encrypt each of the plurality of segments as a function of the respective encryption key; and communicate each of the plurality of segments to a network destination by distributing the plurality of segments amongst a plurality of network paths to the network destination.” And Claim 9 recites “9. The system of claim 1, wherein the respective encryption key is selected from the pool of encryption keys by, for each of the plurality of segments, selecting, as the respective encryption key, a next one of the pool of encryption keys in a rotation of use for the pool of encryption keys.”) 07-21-aia AIA Claim (s) 22 is/are rejected under 35 U.S.C. 103 as being unpatentable over Mirza et al. (US 2017/0244685) and Covdy et al. (US 2018/0302400) and in further view Villapakkam et al. (US 2021/0036851) . As per claim 22, Mirza in combination with Covdy teaches the method of claim 21, but fails to teach wherein the input signal comprises a date. However, in an analogous art Villapakkam teaches wherein the input signal comprises a date (Villapakkam, Paragraph 0025 recites “The key generation and rotation module 123 can be configured to rotate cryptographic keys in response to one or more different types of predefined key rotation events, which can vary depending on various factors with regard to security concerns and practices. For example, in some embodiments, a key rotation event is based on a predefined “regular rotation” schedule in which a cryptographic key for a given key proxy is change periodically to fulfill a key rotation mandate or a key expiration strategy or for other reasons. For example, a key rotation mandate could require that an encryption key be replaced with a new key after the lapse of a certain time interval (e.g., days, months, years, etc.).”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Villapakkam’s cryptographic key management using key proxies and generational indexes with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of having the flexibility to choose a key based on different needs . 07-21-aia AIA Claim (s) 23 is/are rejected under 35 U.S.C. 103 as being unpatentable over Mirza et al. (US 2017/0244685) and Covdy et al. (US 2018/0302400) and in further view of Tutt et al. (US 9,432,340) . As per claim 23, Mirza in combination with Covdy teaches the method of claim 21, but fails to teach wherein the input signal comprises location coordinates of the client device. However, in an analogous art Tutt teaches wherein the input signal comprises location coordinates of the client device (Tutt, Col. 6 Lines 26-33 recites “The server key rotation feature requires that the devices that all ARC clients associated with a particular installation are installed on and the server must be set to the same date/time. The key rotation happens based on UTC time to account for clients residing in varying time zones, but if the date on the device or server is set to an inaccurate value, the keys will not match and the client will not be able to connect to the server.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Tutt’s System And Method For Secure End-to-end Chat System with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of having the flexibility to choose a key based on different needs . 07-21-aia AIA Claim (s) 24-31 is/are rejected under 35 U.S.C. 103 as being unpatentable over Mirza et al. (US 2017/0244685) and Covdy et al. (US 2018/0302400) and in further view teaches Wang et al. (US 2020/0344058) . As per claim 24, Mirza in combination with Covdy teaches the method of claim 21, but fails to teach wherein the input signal comprises a counter value. However, in an analogous art Wang teaches wherein the input signal comprises a counter value (Wang, Paragraph 0044 recites “The process 300 includes creating the encrypted digitally-signed tokens corresponding to all of the encryption keys maintained by the issuer. For example, encryption key component 125 of the issuer computing system 115 can determine whether the currently created encrypted digitally-signed token is the nth encrypted digitally-signed token, where n corresponds to the number of encryption keys maintained by the encryption key component 125. If no, then the encryption key component 125 can increment the counter i 312, and select the next encryption key from the encryption keys maintained by the encryption key component 125. In this manner, the issuer computing system 115 can create n encrypted digitally-signed tokens, where each of the n encrypted digitally-signed tokens corresponds to a verifying party, for example the verifier computing systems 140.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Wang’s Systems and methods for distributed verification of online identity with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of the use of multiple keys is an added layer of security to prevent a simple key from being stolen and re-used for malicious intent. As per claim 25, Mirza in combination with Covdy and Wang teaches the method of claim 24, Wang further teaches wherein the counter value corresponds to a number of interactions between the contactless card and the client device (Wang, Paragraph 0044 recites “The process 300 includes creating the encrypted digitally-signed tokens corresponding to all of the encryption keys maintained by the issuer. For example, encryption key component 125 of the issuer computing system 115 can determine whether the currently created encrypted digitally-signed token is the nth encrypted digitally-signed token, where n corresponds to the number of encryption keys maintained by the encryption key component 125. If no, then the encryption key component 125 can increment the counter i 312, and select the next encryption key from the encryption keys maintained by the encryption key component 125. In this manner, the issuer computing system 115 can create n encrypted digitally-signed tokens, where each of the n encrypted digitally-signed tokens corresponds to a verifying party, for example the verifier computing systems 140.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Wang’s Systems and methods for distributed verification of online identity with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of the use of multiple keys is an added layer of security to prevent a simple key from being stolen and re-used for malicious intent. As per claim 26, Mirza in combination with Covdy and Wang teaches the method of claim 24, Wang further teaches wherein the counter value corresponds to the occurrence of an event (Wang, Paragraph 0044 recites “The process 300 includes creating the encrypted digitally-signed tokens corresponding to all of the encryption keys maintained by the issuer. For example, encryption key component 125 of the issuer computing system 115 can determine whether the currently created encrypted digitally-signed token is the nth encrypted digitally-signed token, where n corresponds to the number of encryption keys maintained by the encryption key component 125. If no, then the encryption key component 125 can increment the counter i 312, and select the next encryption key from the encryption keys maintained by the encryption key component 125. In this manner, the issuer computing system 115 can create n encrypted digitally-signed tokens, where each of the n encrypted digitally-signed tokens corresponds to a verifying party, for example the verifier computing systems 140.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Wang’s Systems and methods for distributed verification of online identity with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of the use of multiple keys is an added layer of security to prevent a simple key from being stolen and re-used for malicious intent. As per claim 27, Mirza in combination with Covdy and Wang teaches the method of claim 24, Wang further teaches wherein the counter value is incremented when the transceiver is within a range of a communication field of the client device (Wang, Paragraph 0044 recites “The process 300 includes creating the encrypted digitally-signed tokens corresponding to all of the encryption keys maintained by the issuer. For example, encryption key component 125 of the issuer computing system 115 can determine whether the currently created encrypted digitally-signed token is the nth encrypted digitally-signed token, where n corresponds to the number of encryption keys maintained by the encryption key component 125. If no, then the encryption key component 125 can increment the counter i 312, and select the next encryption key from the encryption keys maintained by the encryption key component 125. In this manner, the issuer computing system 115 can create n encrypted digitally-signed tokens, where each of the n encrypted digitally-signed tokens corresponds to a verifying party, for example the verifier computing systems 140.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Wang’s Systems and methods for distributed verification of online identity with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of the use of multiple keys is an added layer of security to prevent a simple key from being stolen and re-used for malicious intent. As per claim 28, Mirza in combination with Covdy teaches the method of claim 21, but fails to teach wherein the key selection algorithm is selecting the first selected key based on a mathematical function. However, in an analogous art Wang teaches wherein the key selection algorithm is selecting the first selected key based on a mathematical function (Wang, Paragraph 0044 recites “The process 300 includes creating the encrypted digitally-signed tokens corresponding to all of the encryption keys maintained by the issuer. For example, encryption key component 125 of the issuer computing system 115 can determine whether the currently created encrypted digitally-signed token is the nth encrypted digitally-signed token, where n corresponds to the number of encryption keys maintained by the encryption key component 125. If no, then the encryption key component 125 can increment the counter i 312, and select the next encryption key from the encryption keys maintained by the encryption key component 125. In this manner, the issuer computing system 115 can create n encrypted digitally-signed tokens, where each of the n encrypted digitally-signed tokens corresponds to a verifying party, for example the verifier computing systems 140.” A counter incrementing would be and addition function thus teaching a mathematical function). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Wang’s Systems and methods for distributed verification of online identity with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of the use of multiple keys is an added layer of security to prevent a simple key from being stolen and re-used for malicious intent. As per claim 29, Mirza in combination with Covdy teaches the method of claim 21, but fails to teach wherein the key selection algorithm is selecting the first selected key based on an assigned order. However, in an analogous art Wang teaches wherein the key selection algorithm is selecting the first selected key based on an assigned order (Wang, Paragraph 0044 recites “The process 300 includes creating the encrypted digitally-signed tokens corresponding to all of the encryption keys maintained by the issuer. For example, encryption key component 125 of the issuer computing system 115 can determine whether the currently created encrypted digitally-signed token is the nth encrypted digitally-signed token, where n corresponds to the number of encryption keys maintained by the encryption key component 125. If no, then the encryption key component 125 can increment the counter i 312, and select the next encryption key from the encryption keys maintained by the encryption key component 125. In this manner, the issuer computing system 115 can create n encrypted digitally-signed tokens, where each of the n encrypted digitally-signed tokens corresponds to a verifying party, for example the verifier computing systems 140.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Wang’s Systems and methods for distributed verification of online identity with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of the use of multiple keys is an added layer of security to prevent a simple key from being stolen and re-used for malicious intent. As per claim 30, Mirza in combination with Covdy and Wang teaches the method of claim 29, Wang further teaches wherein the assigned order is assigned when the plurality of keys are stored in the memory (Wang, Paragraph 0044 recites “The process 300 includes creating the encrypted digitally-signed tokens corresponding to all of the encryption keys maintained by the issuer. For example, encryption key component 125 of the issuer computing system 115 can determine whether the currently created encrypted digitally-signed token is the nth encrypted digitally-signed token, where n corresponds to the number of encryption keys maintained by the encryption key component 125. If no, then the encryption key component 125 can increment the counter i 312, and select the next encryption key from the encryption keys maintained by the encryption key component 125. In this manner, the issuer computing system 115 can create n encrypted digitally-signed tokens, where each of the n encrypted digitally-signed tokens corresponds to a verifying party, for example the verifier computing systems 140.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention effective filing date to use Wang’s Systems and methods for distributed verification of online identity with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of the use of multiple keys is an added layer of security to prevent a simple key from being stolen and re-used for malicious intent. As per claim 31, Mirza in combination with Covdy and Wang teaches the method of claim 29, Wang further teaches assigning, by the processor, the assigned order to the plurality of keys; and transmitting, by the processor via the transceiver, the assigned order to the client device (Wang, Paragraph 0044 recites “The process 300 includes creating the encrypted digitally-signed tokens corresponding to all of the encryption keys maintained by the issuer. For example, encryption key component 125 of the issuer computing system 115 can determine whether the currently created encrypted digitally-signed token is the nth encrypted digitally-signed token, where n corresponds to the number of encryption keys maintained by the encryption key component 125. If no, then the encryption key component 125 can increment the counter i 312, and select the next encryption key from the encryption keys maintained by the encryption key component 125. In this manner, the issuer computing system 115 can create n encrypted digitally-signed tokens, where each of the n encrypted digitally-signed tokens corresponds to a verifying party, for example the verifier computing systems 140.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Wang’s Systems and methods for distributed verification of online identity with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of the use of multiple keys is an added layer of security to prevent a simple key from being stolen and re-used for malicious intent . 07-21-aia AIA Claim (s) 32 is/are rejected under 35 U.S.C. 103 as being unpatentable over Mishra et al. (US 2007/0106911) and Wang et al. (US 2020/0344058) and in further view of Varadarajan et al. (US 2014/0040147) . As per claim 32, Mirza in combination with Covdy the method of claim 21, but fails to teach wherein: the memory further contains a transaction value for the last transaction conducted by the contactless card, and the key selection algorithm is selecting the selected key using the input signal and the last digit of the transaction value. However, in an analogous art Varadarajan teaches wherein: the memory further contains a transaction value for the last transaction conducted by the contactless card, and the key selection algorithm is selecting the selected key using the input signal and the last digit of the transaction value (Varadarajan, Paragraph 0086 recites “ At step 312, the payment application 128 utilizes the transaction information to select the appropriate keys and/or rules for authenticating the underlying transaction. When trusted software authentication is utilized, the payment application 128 applies any rules defined at step 306 to the transaction based on the conditions of the transaction defined by the transaction information. And when multiple key authentication is utilized, the payment application 128 will select the appropriate encryption key required to authenticate the transaction based on the conditions of the transaction defined by the transaction information.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Varadarajan’s secure and convenient mobile authentication techniques with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of the use of ensuring the proper key based on transaction ensures that a key is unique to a transaction . 07-21-aia AIA Claim (s) 34 and 35 is/are rejected under 35 U.S.C. 103 as being unpatentable over Mishra et al. (US 2007/0106911) and Wang et al. (US 2020/0344058) and in further view of Hersans et al. (US 2018/0375838) . As per claim 34, Mirza in combination with Covdy the contactless card of claim 33, but fails to teach wherein the input signal comprises a photo of the user taken at the terminal, a number provided by the user on the terminal. However, in an analogous art Hersans wherein the input signal comprises a photo of the user taken at the terminal, a number provided by the user on the terminal (Hersans, Paragraph 0068 recites “In a first example, data objects 530 stored in database 525 may use a first deterministic encryption key 510-b for encrypting a first data field. Key derivation server 505 may generate a new encryption key 510-a, and may send new encryption key 510-a to application cloud 520. In some cases, key derivation server 505 may generate new encryption key 510-a based on a user input (e.g., the user may select to rotate the keys 510 used to encrypt the first data field). In other cases, key derivation server 505 may generate new encryption key 510-a based on a time interval. For example, key derivation server 505 may generate encryption key 510-b at a first time, and may automatically generate new encryption key 510-a after a predetermined time interval has passed since the first time. In some cases, a user may select the time interval.” It would be obvious to vary the input based on user and system preferences). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Hersans’ filtering and unicity with deterministic encryption with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of ensuring the proper key based on a user input ensures that the proper key is used. As per claim 35, Mirza in combination with Covdy the contactless card of claim 33, but fails to teach wherein the input signal comprises a number provided by the user on the client device. However, in an analogous art Hersans teaches wherein the input signal comprises a number provided by the user on the client device (Hersans, Paragraph 0068 recites “In a first example, data objects 530 stored in database 525 may use a first deterministic encryption key 510-b for encrypting a first data field. Key derivation server 505 may generate a new encryption key 510-a, and may send new encryption key 510-a to application cloud 520. In some cases, key derivation server 505 may generate new encryption key 510-a based on a user input (e.g., the user may select to rotate the keys 510 used to encrypt the first data field). In other cases, key derivation server 505 may generate new encryption key 510-a based on a time interval. For example, key derivation server 505 may generate encryption key 510-b at a first time, and may automatically generate new encryption key 510-a after a predetermined time interval has passed since the first time. In some cases, a user may select the time interval.” It would be obvious to vary the input based on user and system preferences). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Hersans’ filtering and unicity with deterministic encryption with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of ensuring the proper key based on a user input ensures that the proper key is used . 07-21-aia AIA Claim (s) 36 and 37 is/are rejected under 35 U.S.C. 103 as being unpatentable over Mishra et al. (US 2007/0106911) and Wang et al. (US 2020/0344058) and in further view of Kummer (US 2014/0123170) . As per claim 36, Mirza in combination with Covdy the contactless card of claim 33, but fails to teach a timer to provide a time signal to the processor, and the key selection algorithm selects the selected key using the input signal and the time signal. However, in an analogous art Kummer teaches a timer to provide a time signal to the processor, and the key selection algorithm selects the selected key using the input signal and the time signal (Kummer, Paragraph 0060 recites “Such encryption key selection may be accomplished on a time-based rolling key change, an event-based rolling key change (e.g., per request), or a combination of both.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Kummer’s systems and methods for securely providing streaming media content on-demand with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of ensuring the proper key based on a user input ensures that the proper key is used. As per claim 37, Mirza in combination with Covdy the contactless card of claim 33, but fails to teach wherein: the processor receives a time signal from the client device, and the key selection algorithm selects the selected key using the input signal and the time signal. However, in an analogous art Kummer teaches wherein: the processor receives a time signal from the client device, and the key selection algorithm selects the selected key using the input signal and the time signal (Kummer, Paragraph 0060 recites “Such encryption key selection may be accomplished on a time-based rolling key change, an event-based rolling key change (e.g., per request), or a combination of both.”). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to use Kummer’s systems and methods for securely providing streaming media content on-demand with Mirza’s Multipath demultiplexed network encryption because it offers the advantage of ensuring the proper key based on a user input ensures that the proper key is used. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to RODERICK TOLENTINO whose telephone number is (571)272-2661. The examiner can normally be reached Mon- Fri 8am-4pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at 571-270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. RODERICK . TOLENTINO Examiner Art Unit 2439 /RODERICK TOLENTINO/ Primary Examiner, Art Unit 2439 Application/Control Number: 18/973,728 Page 2 Art Unit: 2439 Application/Control Number: 18/973,728 Page 3 Art Unit: 2439 Application/Control Number: 18/973,728 Page 4 Art Unit: 2439 Application/Control Number: 18/973,728 Page 5 Art Unit: 2439 Application/Control Number: 18/973,728 Page 6 Art Unit: 2439 Application/Control Number: 18/973,728 Page 7 Art Unit: 2439 Application/Control Number: 18/973,728 Page 8 Art Unit: 2439 Application/Control Number: 18/973,728 Page 9 Art Unit: 2439 Application/Control Number: 18/973,728 Page 10 Art Unit: 2439 Application/Control Number: 18/973,728 Page 11 Art Unit: 2439 Application/Control Number: 18/973,728 Page 12 Art Unit: 2439 Application/Control Number: 18/973,728 Page 13 Art Unit: 2439 Application/Control Number: 18/973,728 Page 14 Art Unit: 2439 Application/Control Number: 18/973,728 Page 15 Art Unit: 2439 Application/Control Number: 18/973,728 Page 16 Art Unit: 2439 Application/Control Number: 18/973,728 Page 17 Art Unit: 2439 Application/Control Number: 18/973,728 Page 18 Art Unit: 2439 Application/Control Number: 18/973,728 Page 19 Art Unit: 2439 Application/Control Number: 18/973,728 Page 21 Art Unit: 2439 Application/Control Number: 18/973,728 Page 22 Art Unit: 2439 Application/Control Number: 18/973,728 Page 23 Art Unit: 2439
Read full office action

Prosecution Timeline

Dec 09, 2024
Application Filed
Apr 29, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750405
FRAMEWORK FOR AUTOMATED DATA-DRIVEN DETECTION ENGINEERING
3y 5m to grant Granted Sep 29, 2026
Patent 12737235
REMOTELY MANAGING EXECUTION OF JOBS IN A CLUSTER COMPUTING FRAMEWORK
2y 11m to grant Granted Sep 15, 2026
Patent 12719899
SYSTEMS AND METHODS FOR USE IN ASSESSMENTS IN CONNECTION WITH CYBER ATTACKS
2y 6m to grant Granted Aug 25, 2026
Patent 12717888
PASSWORDLESS SECURE AUTHENTICATION
1y 8m to grant Granted Aug 25, 2026
Patent 12712736
DEVICE DATA HASHING
2y 1m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+35.2%)
3y 5m (~1y 8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 719 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month