Prosecution Insights
Last updated: October 02, 2026
Application No. 19/216,299

SYSTEMS AND METHODS FOR SCALABLE CRYPTOGRAPHIC AUTHENTICATION OF CONTACTLESS CARDS

Non-Final OA §103§112
Filed
May 22, 2025
Priority
Jun 21, 2021 — continuation of 12/335,412
Examiner
AVERY, BRIAN WILLIAM
Art Unit
Tech Center
Assignee
Capital One Services LLC
OA Round
1 (Non-Final)
59%
Grant Probability
Moderate
1-2
OA Rounds
1y 9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 59% of resolved cases
59%
Career Allowance Rate
54 granted / 91 resolved
-0.7% vs TC avg
Strong +57% interview lift
Without
With
+56.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
15 currently pending
Career history
120
Total Applications
across all art units

Statute-Specific Performance

§101
2.0%
-38.0% vs TC avg
§103
72.2%
+32.2% vs TC avg
§102
8.8%
-31.2% vs TC avg
§112
15.6%
-24.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 91 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to the amendment filed on 12/01/2025. Claims 21-40 are pending in the amendment filed 12/01/2025, with claims 1-20 being cancelled and claims 21-40 being newly added. Claims 1-20 were pending in the filing of application 5/22/2025. Information Disclosure Statements The information disclosure statement(s) (IDS) submitted on 3/12/2026 have been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement(s) have been considered by the examiner. Claim Objections Claim 32 is objected to because of the following informalities: claim 32 fails to end with a period. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 24 and 31 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Specifically, dependent claims 24 and 31 recite features which have insufficient antecedent support for features included in these claims. Claim 24 recites, “wherein the contactless card is further configured to generate a set of session keys using one or more secret keys combined with the counter to generate the cryptogram.” (emphasis added) Claim 31 recites, “wherein: the contactless card is configured to generate a set of session keys using one or more secret keys combined with the counter to generate the cryptogram, …” In both cases the examiner will interpret “the cryptogram” instead as “the first cryptogram”. Independent claims 21 and 28, from which claims 24 and 31 depend, both recite “a first cryptogram” and “a second cryptogram”, however neither recites, “a cryptogram.” Appropriate correction is required. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 21-32, 34-36, and 38-40 are rejected under 35 U.S.C. 103 as being unpatentable over US 20200104841 to Osborn et al. (hereinafter Osborn), in view of US 20130111598 to Marcovecchio et al. (hereinafter Marcovecchio). Regarding claim 21, Osborn teaches, A method comprising: generating, by a contactless card, a first cryptogram based on a tag read and responsive to receipt of an authentication request; (fig. 1b, [0042] teaches authenticated access using client and contactless card, [0044] teaches NFC tag read being performed, and MAC cryptogram / “first cryptogram” being created by contactless card 105.) transmitting, by the contactless card to a computing device, a first response to the authentication request, the first response including the first cryptogram, a public key, (Fig. 1b & [0044-46] teaches generating and transmitting MAC cryptogram using contactless card. [0047-50] teach client application or server verifying MAC cryptogram. [0011] teaches cryptogram stores FIDO public key. Also, [0185] teaches client transmitting public key to server.) (Applicant’s printed publication at [0040] teaches the first cryptogram serves as a message authentication code (MAC).) receiving, (Fig. 13 & [0192] teaches server 1310 transmitting challenge to client device 1320 and contactless card 1330. Additionally, fig. 2 & [0060-65] teach encrypting data between devices and server using rotating / diversified symmetric keys. [0011] teaches contactless card stores master key, diversified key, FIDO public / private keys, and counters, thus, contactless card performs fig 2 encryption.) decrypting, ([0011] teaches contactless card stores master key, diversified key, FIDO public / private keys, and counters and creating a cryptogram. Fig. 2 & [0061-65] teach encryption between client devices and server, and [0066-67] teach decryption of encrypted data using diversified symmetric key. Thus, challenge of [0192-194] may be decrypted by symmetric encryption of fig. 2.) generating, by the contactless card, a second cryptogram in response to the decrypted first challenge; and ([0192] teaches the contactless card receiving a signal (challenge) from the client device, allowing the contactless card to perform the authentication / signature. [0011] teaches contactless card stores master key, diversified key, FIDO public / private keys, and counters and may create a cryptogram.) transmitting, by the contactless card to the computing device, the second cryptogram. ([0192] client device acts as relay between card and server.) Osborn fails to explicitly teach a contactless card providing version number, signing, and decrypting, However, Marcovecchio teaches, transmitting, by the contactless card to a computing device, a first response to the authentication request, the first response including the first cryptogram, ([0024-25] teaches level of security and channel protocol being supported exchanged, and cryptograms being exchanged using DES / block cipher encryption. [0023] teaches sign and encrypt which uses public keys, and [0024-25] teaches the details of challenge response.) receiving, by the contactless card, an encrypted first challenge from the computing device; ([0023] teaches challenge response and session keys for APDUs. [0024-25] teaches exchange of random data / “challenge”.) decrypting, by the contactless card, the encrypted first challenge; ([0023-25] teaches APDU, card to off-card challenge response including passing of encrypted data during the session, generating keys for the session using counters, MAC creating and passing, and host cryptogram and card cryptograms.) generating, by the contactless card, a second cryptogram in response to the decrypted first challenge; and ([0025] teaches generating host and card cryptograms.) transmitting, by the contactless card to the computing device, the second cryptogram. ([0025] teaches card cryptogram being sent to off-card entity.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Osborn, which teaches FIDO authentication using challenges (Abstract) and a contactless card which creates a cryptogram ([0011]), with Marcovecchio, which also teaches contactless cards ([0005]) and additionally teaches cards performing encryption, decryption, and signing ([0023-24]) and providing security protocols / security levels in the communication between card and off-card entity ([0024-25]). One of ordinary skill in the art would have been motivated to perform such an addition to provide Osborn with the added ability to perform encryption / decryption, signatures, and key generation in the smart card and the exchange of version number, as taught by Marcovecchio, for the purpose of increasing security by maintaining, within the smart card, the keys used to encrypt, decrypt, and sign communications Regarding claim 22, Osborn and Marcovecchio teach, The method of claim 21, wherein the encrypted first challenge is received by the contactless card via a command application protocol data unit (C-APDU) and the second cryptogram is transmitted via a response APDU (R-APDU). (Marcovecchio, [0022-24] teach using application protocol data units (APDU) in transmissions and responses or challenge / responses. [0025-26] teaches specific communications between card and off-card entity including host and card cryptograms being generated.) Regarding claim 23, Osborn and Marcovecchio teach, The method of claim 21, wherein the tag read includes a near field communication (NFC) data exchange format (NDEF) read performed by an application executing on the computing device. (Osborn, [0044] teaches NDEF in NFC.) (Marcovecchio, teaches read JSR-177 in fig. 1, which may be NFC, and NFC device 36.) Regarding claim 24, Osborn and Marcovecchio teach, The method of claim 21, wherein the contactless card is further configured to generate a set of session keys using one or more secret keys combined with the counter to generate the cryptogram. (Marcovecchio, [0025] teaches “card, using its internal Sequence Counter and static keys, creates new secret session keys and generates a first cryptographic value (card cryptogram) using one of its newly created session keys.”) (Osborn, [0056] teaches generating keys from master key and counter value.) Regarding claim 25, Osborn and Marcovecchio teach, The method of claim 21, further wherein generating the second cryptogram includes combining, by the contactless card, the decrypted first challenge with a private card key. (Marcovecchio, teaches using challenge response including encryption and signature. [0025] teaches the card cryptogram including random data from host challenge.) Regarding claim 26, Osborn and Marcovecchio teach, The method of claim 21, wherein the encrypted first challenge includes a random number that identifies a function. (Marcovecchio, [0025] teaches generating host challenge with random data that is unique to the session, and also teaches identifying security protocol / “function”.) Regarding claim 27, Osborn and Marcovecchio teach, The method of claim 26, wherein the second cryptogram transmitted from the contactless card to the computing device includes the random number. (Marcovecchio, [0025] teaches generating the card challenge using the random data of host challenge.) Regarding claim 28, Osborn and Marcovecchio teach, A computing device comprising: a processing circuit configured to execute an application; and a memory having executable instructions stored thereon, including instructions for the application, wherein, in response to the processing circuit executing the instructions, the processing circuit is caused to: forward an authentication request to a contactless card, perform a tag read on the contactless card, receive a first cryptogram, a public key, and a version number from the contactless card in response to the authentication request, transmit the first cryptogram, the public key, and the version number to an authentication server for validation of the first cryptogram, receive an encrypted first challenge from the authentication server and forward the encrypted first challenge to the contactless card, receive a second cryptogram from the contactless card, the second cryptogram generated based on a decrypted version of the first challenge, and forwarding the second cryptogram to the authentication server for validation of the second cryptogram. Claim 28 is rejected using the same basis of arguments used to reject claim 21 above. Regarding claim 29, Osborn and Marcovecchio teach, The computing device of claim 28, wherein the encrypted first challenge is generated based on the version number from the contactless card. (Marcovecchio, [0024-25] teaches security level and/or secure channel protocol being exchanged.) Regarding claim 30, Osborn and Marcovecchio teach, The computing device of claim 28, wherein the tag read includes a near field communication (NFC) read performed by the application executing on the computing device. Claim 30 is rejected using the same basis of arguments used to reject claim 23 above. Regarding claim 31, Osborn and Marcovecchio teach, The computing device of claim 28, wherein: the contactless card is configured to generate a set of session keys using one or more secret keys combined with the counter to generate the cryptogram, and (Osborn, [0056] teaches generating keys using master keys and counter. [0044] teaches MAC cryptogram being encrypted with a session key of the session keys.) (Marcovecchio, [0023] & [0025] teach generating session keys using counter and static keys, and encrypting with a key.) (See also rejection of claim 24) the cryptogram is further encrypted using one of the session keys in the set of session keys. (See above.) Regarding claim 32, Osborn and Marcovecchio teach, The computing device of claim 28, wherein: the encrypted first challenge includes a random number that identifies a function, and (Marcovecchio, [0025] teaches generating host challenge with random data that is unique to the session, and also teaches identifying security protocol / “function” of the session.) (See also rejection of claim 26) the second cryptogram received by the computing device from the contactless card includes the random number (Marcovecchio, [0025] teaches generating the card challenge using the random data of host challenge.) (See also rejection of claim 27) Regarding claim 34, Osborn and Marcovecchio teach, The computing device of claim 32, wherein the random number is a secret salt that is unique to identify the function from among a plurality of functions (Marcovecchio, [0025] teaches generating host challenge with random data that is unique to the session, and also teaches identifying security protocol / “function” of the session.) and wherein the random number is to be compared by the authentication server to a reference random number in order to associate the second cryptogram with the function identified by the random number. (Marcovecchio, [0024-25] teaches using random number in both cryptograms.) Regarding claim 35, Osborn and Marcovecchio teach, A non-transitory computer-readable storage medium having executable instructions stored thereon, which when executed by a processing circuit, cause the processing circuit to: forward an authentication request to a contactless card, the authentication request received from an authentication server; perform a tag read on the contactless card; receive a first cryptogram, a public key, and a version number from the contactless card in response to the authentication request; transmit the first cryptogram, the public key, and the version number to the authentication server for validation of the first cryptogram; receive an encrypted first challenge from the authentication server and forward the encrypted first challenge to the contactless card; receive a second cryptogram from the contactless card, the second cryptogram generated based on a decrypted version of the first challenge; and forwarding the second cryptogram to the authentication server for validation of the second cryptogram. Claim 35 is rejected using the same basis of arguments used to reject claim 21 above. Regarding claim 36, Osborn and Marcovecchio teach, The non-transitory computer-readable storage medium of claim 35, wherein: the encrypted first challenge is forwarded to the contactless card via a command application protocol data unit (C-APDU), and the second cryptogram is received via a response APDU (R-APDU) from the contactless card. Claim 36 is rejected using the same basis of arguments used to reject claim 22 above. Regarding claim 38, Osborn and Marcovecchio teach, The non-transitory computer-readable storage medium of claim 35, wherein the contactless card is further configured to generate a set of session keys using one or more secret keys combined with the counter to generate the cryptogram. (Osborn, [0011] teaches contactless card generating keys and cryptogram.) (Marcovecchio, [0023-25] teaches card and off-card entity generating session keys to generate cryptograms that are signed and encrypted.) Regarding claim 39, Osborn and Marcovecchio teach, The non-transitory computer-readable storage medium of claim 35, wherein: the encrypted first challenge includes a random number that identifies a function; and the second cryptogram received by the computing device from the contactless card includes the random number. Claim 39 is rejected using the same basis of arguments used to reject claim 32 above. Regarding claim 40, Osborn and Marcovecchio teach, The non-transitory computer-readable storage medium of claim 39, wherein: the random number is a secret salt that is unique to identify the function from among a plurality of functions, and the random number is to be compared by the authentication server to a reference random number to associate the second cryptogram with the function identified by the random number. Claim 40 is rejected using the same basis of arguments used to reject claim 34 above. Claim 33 is rejected under 35 U.S.C. 103 as being unpatentable over Osborn, in view of Marcovecchio, in view of US 20210105139 to Choi et al. (hereinafter Choi). Regarding claim 33, Osborn and Marcovecchio teach, The computing device of claim 32, wherein the random number (Marcovecchio, [0025] teaches using random number to produce cryptograms.) Osborn and Marcovecchio fail to explicitly teach using logical operator on random number, However, Choi teaches, wherein the random number is modified using a logical operation before being included in the second cryptogram. (Choi, [0040] teaches using logical operator XOR with random number.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Osborn, which teaches FIDO authentication using challenges (Abstract) and a contactless card which creates a cryptogram ([0011]), with Marcovecchio, which also teaches contactless cards ([0005]) and additionally teaches cards performing encryption, decryption, and signing ([0023-24]) and providing security protocols / security levels in the communication between card and off-card entity ([0024-25]), with Choi, which also teaches FIDO ([0002]), and additionally teaches using logical operator XOR with random number ([0040]). One of ordinary skill in the art would have been motivated to perform such an addition to provide Osborn and Marcovecchio with the added ability to use logical operators with random numbers to generate data, as taught by Choi, for the purpose of increasing security by generating new data based on random numbers exchanged between devices. Claim 37 is rejected under 35 U.S.C. 103 as being unpatentable over Osborn, in view of Marcovecchio, in view of US 20100325427 to Ekberg et al. (hereinafter Ekberg). Regarding claim 37, Osborn and Marcovecchio teach, The non-transitory computer-readable storage medium of claim 35, wherein the public key is an encrypted (Osborn, [0011] & [0185] teaches public key exchange, and [0011] teaches encrypting data exchanged.) (Marcovecchio, [0023-25] teaches encrypting data exchanged during a session.) Osborn and Marcovecchio fail to explicitly teach use of a public key signature, However, Ekberg teaches, wherein the public key is an ([0050-52] teaches public key signature where signing uses the public key, which is then verified by private key holder.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Osborn, which teaches FIDO authentication using challenges (Abstract) and a contactless card which creates a cryptogram ([0011]), with Marcovecchio, which also teaches contactless cards ([0005]) and additionally teaches cards performing encryption, decryption, and signing ([0023-24]) and providing security protocols / security levels in the communication between card and off-card entity ([0024-25]), with Ekberg, which also teaches the use of challenges ([0050-51]), and additionally teaches the use of a public key signature for verification ([0050-52]). One of ordinary skill in the art would have been motivated to perform such an addition to provide Osborn and Marcovecchio with the added ability to public key signature where signing uses the public key, as taught by Ekberg, for the purpose of increasing security by using the other party’s public key for signatures. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRIAN WILLIAM AVERY whose telephone number is (571) 272-3942. The examiner can normally be reached on 9AM-5PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on (571) 272-3739. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /B.W.A./ /JASON K GEE/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

May 22, 2025
Application Filed
Dec 01, 2025
Response after Non-Final Action
Sep 11, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12732372
USE OF BIOMETRICS AND PRIVACY PRESERVING METHODS TO AUTHENTICATE ACCOUNT HOLDERS ONLINE
3y 0m to grant Granted Sep 08, 2026
Patent 12676839
Digital Rights Management DRM Method, Apparatus, and System
3y 10m to grant Granted Jul 07, 2026
Patent 12665773
SYSTEM AND METHOD FOR AUTHENTICATION IN A CLIENT-SERVER CONNECTION USING CHALLENGE APPLIED TO A SECRET KEY
3y 2m to grant Granted Jun 23, 2026
Patent 12619703
AUTHORIZED REMOTE MOBILE DEVICE MANAGEMENT OF A TARGETED MANAGED DEVICE
3y 8m to grant Granted May 05, 2026
Patent 12609925
SYSTEMS AND METHODS FOR MONITORING DECENTRALIZED DATA STORAGE
4y 1m to grant Granted Apr 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
59%
Grant Probability
99%
With Interview (+56.8%)
3y 1m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 91 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month