Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to the application filed on 5/08/2025 and the claim amendments filed 8/28/2025. Claims 21-40 are currently pending in the filing of 8/28/2025, claims 1-20 were pending in the previous filing of the application 5/08/2025. Claims 1-20 were cancelled and claims 21-40 were newly added in the claim amendments filed on 8/28/2025.
Information Disclosure Statements
The information disclosure statement(s) (IDS) submitted on 4/29/2026 have been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement(s) have been considered by the examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 21-40 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Specifically, independent claims 21, 32, and 39 recite features which have insufficient antecedent support for the features. Claims 21, 32, and 39 all recite, “wherein the first FIDO key is generated based on an identifier associated with the FIDO authentication request.” (emphasis added) The examiner will interpret this feature as “wherein the first FIDO key is generated based on an identifier associated with a FIDO authentication request.” (emphasis added) Appropriate correction is required.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 21, 24-27, 29, 31-33, and 39-40 are rejected under 35 U.S.C. 103 as being unpatentable over US 20200104841 to Osborn et al. (hereinafter Osborn), in view of US 20210152357 to Wang et al. (hereinafter Wang).
Regarding claim 21, Osborn teaches,
A method of contactless Fast Identity Online (FIDO) authentication, the method comprising the steps of: (Abstract & [0008-9] teaches contactless card using FIDO authentication.)
receiving, by an application executing on an authenticator device, a FIDO challenge; ([0009] teaches “receive a challenge from a second server”.)
transmitting, by the application to a contactless card, an instruction including a request to retrieve a first FIDO key from the contactless card; ([0009] teaches transaction verification permits use of the FIDO private key, from contactless card, use with the challenge.)
signing, by the application using the first FIDO key, the FIDO challenge; and ([0009] teaches signing challenge using the private key / “first FIDO key”. See also [0184-185])
transmitting, by the application to a relying server, the signed FIDO challenge for validation using a second FIDO key, ([0185-186] teaches a FIDO public key / “second FIDO key” used to decrypt the signed challenge which was sent to the server.)
wherein the first ([0184] teaches generating keys based on identifiers and generating FIDO keys randomly. [0183-184] teaches registration and generating FIDO private key. Abstract teaches FIDO private key / “first FIDO key”.)
Osborn fails to explicitly teach generating a private key using an identifier that is associated with an authentication request,
However, Wang teaches,
wherein the first FIDO key is generated based on an identifier associated with the FIDO authentication request. (Wang, Abstract, teaches an identity verification request and generating a private key / “first FIDO key” using an identifier. [0140] teaches FIDO authentication / authorization.)
Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Osborn, which teaches an client device (“authenticator device”) that receives challenges during a FIDO authentication, and obtains FIDO public / private keys from a contactless card, where the FIDO private key is used to sign a challenge, and the FIDO public key (“second FIDO key”) is used to verify the signed challenge (i.e., server), with Wang, which also teaches Fast Identity Online (FIDO) ([0140]), and additionally teaches an identity verification request including generating a private key using an identifier (Abstract). One of ordinary skill in the art would have been motivated to perform such an addition to provide Osborn with the added ability to generate a private key using an identifier, as taught by Wang, for the purpose of increasing security by using private keys and increasing computational efficiency by using a user identifier to generate the private key.
Regarding claim 24, Osborn and Wang teach,
The method of claim 21, further comprising generating, by the relying server, the FIDO challenge. (Osborn, [0009] teaches server transmitting a challenge.)
Regarding claim 25, Osborn and Wang teach,
The method of claim 24, wherein the relying server generates the FIDO challenge in response to a FIDO authentication request received from a browser extension. (Osborn, [0009] teaches transmitting a transaction request to a server, in response to which a server transmits a challenge.)
Regarding claim 26, Osborn and Wang teach,
The method of claim 21, wherein the FIDO authentication request comprises a Fast Identity Online 2 (FIDO2) website registration. (Osborn, [0183] teaches registering credentials via FIDO2 framework. [0190] teaches user visiting website and registering. See also [0185].)
Regarding claim 27, Osborn and Wang teach,
The method of claim 21, wherein the first FIDO key is retrieved from the contactless card via entry of a communication interface associated with the contactless card into a communication field. (Osborn, [0009] teaches FIDO public / private key being provided by contactless card using communication interface. [0043] teaches NFC transfers between application and contactless card.)
Regarding claim 29, Osborn and Wang teach,
The method of claim 21, wherein the identifier includes a user identifier. (Wang, Abstract, teaches user identifier.)
Regarding claim 31, Osborn and Wang teach,
The method of claim 21, wherein the second FIDO key corresponds to a public key of the first FIDO key. (Osborn, [0184-186] teaches FIDO 2 framework including a FIDO private key used to sign a challenge, and a FIDO public key used by the server to confirm the signed challenge.)
Regarding claim 32, Osborn and Wang teach,
A Fast Identity Online (FIDO) authentication system, comprising:
an authenticator device, comprising a processor and a memory containing executable instructions,
wherein, when executing the instructions, the instructions cause the authenticator device to:
receive a Fast Identity Online (FIDO) challenge,
transmitting, by the application to a contactless card, an instruction including a request to retrieve a first FIDO key from the contactless card,
signing, by the application using the first FIDO key, the FIDO challenge, and
transmitting, by the application to a relying server, the signed FIDO challenge for validation using a second FIDO key,
wherein the first FIDO key is generated based on an identifier associated with the FIDO authentication request.
Claim 32 is rejected using the same basis of arguments used to reject claim 21 above.
Regarding claim 33, Osborn and Wang teach,
The FIDO authentication system of claim 32, wherein the instructions further cause the authenticator device to receive input data comprising at least one selected from the group of biometric data and credential data. (Osborn, [0183] teaches credentials used as authentication inputs during registration in the FIDO 2 framework.)
Regarding claim 39, Osborn and Wang teach,
A non-transitory computer readable medium comprising computer executable instructions that, when executed on a processor of an authenticator device, cause the authenticator device to perform procedures comprising the steps of:
receiving a Fast Identity Online (FIDO) challenge;
transmitting, by the application to a contactless card, an instruction including a request to retrieve a first FIDO key from the contactless card;
signing, by the application using the first FIDO key, the FIDO challenge; and
transmitting, by the application to a relying server, the signed FIDO challenge for validation using a second FIDO key,
wherein the first FIDO key is generated based on an identifier associated with the FIDO authentication request.
Claim 39 is rejected using the same basis of arguments used to reject claim 21 above.
Regarding claim 40, Osborn and Wang teach,
The non-transitory computer readable medium of claim 39, the procedures further comprising receiving input data comprising at least one selected from the group of biometric data and credential data.
Claim 40 is rejected using the same basis of arguments used to reject claim 33 above.
Claims 22-23 are rejected under 35 U.S.C. 103 as being unpatentable over Osborn, in view of Wang, in view of US 20210167945 to Yamakawa et al. (hereinafter Yamakawa).
Regarding claim 22, Osborn and Wang teach,
The method of claim 21,
wherein the first FIDO key is generated based on the identifier and a master key. (Osborn, [0184] teaches generating private key / “first FIDO key” and the use of master key.)
Osborn and Wang fail to explicitly teach deriving a first / private key using a master key and identifier,
However, Yamakawa teaches,
wherein the first FIDO key is generated based on the identifier and a master key. (Yamakawa, Abstract, teaches using a master key and identifier to generate private key / “first FIDO key”.)
Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Osborn, which teaches an client device (“authenticator device”) that receives challenges during a FIDO authentication, and obtains FIDO public / private keys from a contactless card, where the FIDO private key is used to sign a challenge, and the FIDO public key (“second FIDO key”) is used to verify the signed challenge (i.e., server), with Wang, which also teaches Fast Identity Online (FIDO) ([0140]), and additionally teaches an identity verification request including generating a private key using an identifier (Abstract), with Yamakawa, which also teaches public / private keys (Abstract), and additionally teaches using a master key and identifier to generate the public / private keys (Abstract). One of ordinary skill in the art would have been motivated to perform such an addition to provide Osborn and Wang with the added ability to using a master key and identifier to generate private key, as taught by Yamakawa, for the purpose of increasing security and increasing computational efficiency by using master keys and other information to generate keys, which enables the generated keys to be rotated.
Regarding claim 23, Osborn, Wang, and Yamakawa teach,
The method of claim 22, wherein the first FIDO key is generated based on the identifier and the master key using one or more cryptographic algorithms. (Yamakawa, Abstract, teaches using a master key and identifier to generate private key / “first FIDO key” using algorithms.) (See also, Osborn, [0184])
Claim 28 is rejected under 35 U.S.C. 103 as being unpatentable over Osborn, in view of Wang, in view of US 20190236215 to Agarwal et al. (hereinafter Agarwal).
Regarding claim 28, Osborn and Wang teach,
The method of claim 21,
wherein the identifier includes a site identifier. (Osborn, [0006] teaches FIDO2 Web Authentication. See also [0183-184]) (Wang, Abstract, teaches an identity verification request and generating a private key / “first FIDO key” using an identifier.)
Osborn and Wang fail to explicitly teach using a website identifier to generate keys, as recited in claim 21,
However, Agarwal teaches,
wherein the identifier includes a site identifier. (Agarwal, claim 10, teaches keys being generated based on URLs.)
Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Osborn, which teaches an client device (“authenticator device”) that receives challenges during a FIDO authentication, and obtains FIDO public / private keys from a contactless card, where the FIDO private key is used to sign a challenge, and the FIDO public key (“second FIDO key”) is used to verify the signed challenge (i.e., server), with Wang, which also teaches Fast Identity Online (FIDO) ([0140]), and additionally teaches an identity verification request including generating a private key using an identifier (Abstract), with Agarwal, which also teaches key generation (Abstract), and additionally teaches generating keys using URLs (Claim 10). One of ordinary skill in the art would have been motivated to perform such an addition to provide Osborn and Wang with the added ability to generate keys using URLs, as taught by Agarwal, for the purpose of increasing security by using URLs to generate keys to enable efficient key generation.
Claim 30 is rejected under 35 U.S.C. 103 as being unpatentable over Osborn, in view of Wang, in view of US 20200274866 to Vilmos (hereinafter Vilmos).
Regarding claim 30, Osborn and Wang teach,
The method of claim 21, further comprising (Osborn, Abstract teaches the FIDO private key being provided by the contactless card.)
Osborn and Wang fail to explicitly teach using a contactless card to generate the first FIDO key / private key,
However, Vilmos teaches,
further comprising generating, by the contactless card, the first FIDO key. (Vilmos, [0012] teaches FIDO keys in authentication. [0065] teaches generating asymmetric key pair in the smart card.)
Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Osborn, which teaches an client device (“authenticator device”) that receives challenges during a FIDO authentication, and obtains FIDO public / private keys from a contactless card, where the FIDO private key is used to sign a challenge, and the FIDO public key (“second FIDO key”) is used to verify the signed challenge (i.e., server), with Wang, which also teaches Fast Identity Online (FIDO) ([0140]), and additionally teaches an identity verification request including generating a private key using an identifier (Abstract), with Vilmos, which also teaches FIDO keys in authentication ([0012]), and additionally teaches ] teaches generating asymmetric key pair in the smart card ([0065]). One of ordinary skill in the art would have been motivated to perform such an addition to provide Osborn and Wang with the added ability to generate the FIDO private key in the smart card, as taught by Vilmos, for the purpose of increasing security by generating keys in the secure environment of the smart card.
Claims 34-35 are rejected under 35 U.S.C. 103 as being unpatentable over Osborn, in view of Wang, in view of US 20230179589 to Kopack (hereinafter Kopack).
Regarding claim 34, Osborn and Wang teach,
The FIDO authentication system of claim 33, wherein:
Osborn and Wang fail to explicitly teach a second device executing a second application that transmits input data,
However, Kopack teaches,
the input data is transmitted by a second application executing on a second device, and (Kopack, fig. 1 and [0004-5] login device 110 (“second device”), describing FIDO authentication, and [Abstract] describing use of a web browser of the login device for authentication. [0004] & [0044-46] teach the login device 110 (“computing device”) that cannot perform FIDO authentication, and [0047] teaching the authenticator device 120 that uses a FIDO key to sign a challenge because the login device 110 does not have FIDO capability.) (Examiner notes the Osborn [0006] & [0183] teach FIDO 2, W3C’s Web Authentication specification (WebAuthn), and CTAP FIDO, which support a device, which is not FIDO enabled, performing FIDO transaction by using another device that is FIDO enabled.)
the input data is transmitted after a determination, by the relying server, of one or more conditions. (Kopack, [0064] teaches using conditions / thresholds to determine if a transaction is too large.) (Applicant’s printed publication at [0049] describes “conditions” as conditions that indicate to many login requests, abnormal number of transactions, and conditions indicating misuse or fraud, abnormal transaction locations, and excessive purchases.)
Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Osborn, which teaches an client device (“authenticator device”) that receives challenges during a FIDO authentication, and obtains FIDO public / private keys from a contactless card, where the FIDO private key is used to sign a challenge, and the FIDO public key (“second FIDO key”) is used to verify the signed challenge (i.e., server), with Wang, which also teaches Fast Identity Online (FIDO) ([0140]), and additionally teaches an identity verification request including generating a private key using an identifier (Abstract), with Kopack, which also teaches FIDO authentication ([0004-5]), and which also teaches a smart card 150, a login device 110 (“computing device”) that is not FIDO authentication enabled ([0005]), authenticator device 120, which communicate with one another to have the FIDO enabled authenticator device 120 perform FIDO authentication, where the FIDO private key of the authenticator device is used to sign a challenge that is authenticated by a server in order to authenticate the login device, which does not have FIDO capability (fig. 1). One of ordinary skill in the art would have been motivated to perform such an addition to provide Osborn and Wang with the added ability to use a second device and use threshold conditions to determine if a transaction can be performed, as taught by Kopack, for the purpose of increasing security by using conditions and increasing computational efficiency by using a second device to perform FIDO authentication.
Regarding claim 35, Osborn, Wang, and Kopack teach,
The FIDO authentication system of claim 34, wherein one of the one or more conditions comprises determining, by the relying server, a threshold number of authentication requests over a predetermined time period. (Kopack, [0064] teaches using conditions / thresholds to determine if a transaction is problematic. [0079] teaches using a threshold number of attempts to lock out a user.)
Claims 36-38 are rejected under 35 U.S.C. 103 as being unpatentable over Osborn, in view of Wang, in view of Kopack, in view of US 20100037046 to Ferg et al. (hereinafter Ferg).
Regarding claim 36, Osborn, Wang, and Kopack teach,
The FIDO authentication system of claim 34, wherein one of the one or more conditions comprises determining, by the relying server, of (Kopack, [0064] teaches using conditions / thresholds to determine if a transaction is problematic.
Osborn, Wang, and Kopack fail to explicitly teach detecting fraud or misuse associated with an account,
However, Ferg teaches,
wherein one of the one or more conditions comprises determining, by the relying server, of fraud or misuse associated with an account or a user. ([0037] teaches detecting risk of fraud by network.)
Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Osborn, which teaches an client device (“authenticator device”) that receives challenges during a FIDO authentication, and obtains FIDO public / private keys from a contactless card, where the FIDO private key is used to sign a challenge, and the FIDO public key (“second FIDO key”) is used to verify the signed challenge (i.e., server), with Wang, which also teaches Fast Identity Online (FIDO) ([0140]), and additionally teaches an identity verification request including generating a private key using an identifier (Abstract), with Kopack, which also teaches FIDO authentication ([0004-5]), and which also teaches a smart card 150, a login device 110 (“computing device”) that is not FIDO authentication enabled ([0005]), authenticator device 120, which communicate with one another to have the FIDO enabled authenticator device 120 perform FIDO authentication, where the FIDO private key of the authenticator device is used to sign a challenge that is authenticated by a server in order to authenticate the login device, which does not have FIDO capability (fig. 1), with Ferg, which also teaches an authenticator (fig. 5), and additionally teaches detecting risk including fraud, excessive requests, and location ([0037]). One of ordinary skill in the art would have been motivated to perform such an addition to provide Osborn, Wang, and Kopack with the added ability to use risk detection to prevent malicious behavior, as taught by Ferg, for the purpose of increasing security.
Regarding claim 37, Osborn, Wang, Kopack, and Ferg teach,
The FIDO authentication system of claim 36, wherein the determination of fraud or misuse associated with the account or the user comprises determining whether a user transaction history is indicative of an excessive number of purchases. (Ferg, [0037] teaches risk detection including detecting excessive number of requests and excessive number of failed requests.)
Regarding claim 38, Osborn, Wang, Kopack, and Ferg teach,
The FIDO authentication system of claim 36, wherein the determination of fraud or misuse associated with the account or the user comprises determining whether a user transaction history is indicative of an abnormal location. (Ferg, [0037] teaches risk detection based on location and historical record.)
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRIAN WILLIAM AVERY whose telephone number is (571) 272-3942. The examiner can normally be reached on 9AM-5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on (571) 272-3739.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/B.W.A./
/MAUNG T LWIN/Primary Examiner, Art Unit 2495