Invalidity dossier
US 10091246
Methods and systems for protecting a secured network
Current assignee: Palo Alto Networks, Inc.
Added 8/30/2026, 4:49:26 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
US Patent 10091246B2 — Summary
Bibliographic data (from Google Patents / USPTO-linked records)
| Field | Value |
|---|---|
| Patent number | US 10091246 B2 |
| Title | Methods and systems for protecting a secured network |
| Assignee (original) | Centripetal Networks, Inc. (name later changed to Centripetal Networks, LLC) |
| Inventors | Steven Rogers; Sean Moore |
| Application no. | US 15/413,834 |
| Filing date | January 24, 2017 |
| Issue date | October 2, 2018 |
| Earliest priority date | October 22, 2012 |
| Status per USPTO/Google | Listed "Active" (legal status is an assumption, not a legal conclusion) |
| Family | Continuation of US 14/698,560 (US 9,560,077), continuation of US 13/657,010 (US 9,137,205); continuations/children include US 10,567,437, US 10,785,266, US 11,012,474, US 12,107,893, US 12,563,103 |
Abstract (verbatim)
"Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets. Performing the at least one of multiple packet transformation functions specified by the dynamic security policy on the packets may include performing at least one packet transformation function other than forwarding or dropping the packets."
Independent claims (1, 8, 15 of 20 claims)
The patent has three independent claims in three statutory categories: claim 1 (method), claim 8 (network security device), and claim 15 (non-transitory computer-readable media). All three share essentially the same substantive limitations, reciting a phased-restoration scheme.
Claim 1 (method) — A method in which a network security device located at the boundary of a protected network:
- receives a plurality of rule sets;
- receives a plurality of packets via a communication interface;
- executes, at a first time and on a packet-by-packet basis, a first rule set specifying a first set of network addresses for which packets should be forwarded;
- executes, at a second time (after the first), a second rule set specifying a second set of addresses — larger than the first set — for forwarding; and
- executes, at a third time (after the second), a third rule set specifying a third set of addresses — larger than the second set — for forwarding.
Plain language: The claimed device sits at the edge of a network and, in a phased/graduated manner, progressively re-admits traffic after (e.g.) a DDoS attack or outage by executing rule sets that allow forwarding for successively larger groups of network addresses over three distinct times — effectively a "phased restoration" or progressive-allowlist process. The specification describes this as restoring service first for mission-critical devices, then trusted devices, then all normally-allowed devices.
Claim 8 (apparatus) — A network security device comprising at least one processor and memory storing instructions that, when executed, cause the device to perform the same operations: receive a plurality of rule sets, receive packets via a communication interface, and execute the first, second, and third rule sets in the same time-ordered, progressively-larger-address-set sequence (forwarding packets).
Claim 15 (computer-readable media) — One or more non-transitory computer-readable media storing instructions that, when executed by a computing system located at a boundary of a protected network, cause it to perform the same three-stage, progressively-expanding rule-set execution.
Litigation / validity status (important context)
- IPR2021-01152 (Palo Alto Networks, Inc. v. Centripetal Networks, Inc.): The PTAB instituted review and, in a Final Written Decision dated January 24, 2023, found the challenged claims unpatentable (anticipation/obviousness), including over the prior Centripetal patents US 9,137,205 and US 9,560,077 (whose claims had been cancelled in earlier IPRs).
- CAFC appeal, Case 23-1528: Per PACER-derived reporting (PatSnap), the Federal Circuit entered a Rule 36 judgment — "ORDERED and ADJUDGED: AFFIRMED" — affirming the PTAB's unpatentability determination, which ended appellate options for Centripetal on this patent.
- The patent was also asserted in district court (e.g., Centripetal Networks, LLC v. Palo Alto Networks, Inc., 2:21-cv-00137, E.D. Va., asserting 10091246 among many patents).
CAFC 2026 docket search result
I searched for a CAFC 2026 docket entry specific to 10091246 and did not find one. The 2026 Federal Circuit activity involving Centripetal Networks that surfaced (e.g., Centripetal v. Keysight, case 24-2246 / IPR2022-01525, decided April 2, 2026, concerning US 10,284,526; Centripetal v. Keysight cases 24-1406 and 24-1416, opinions April 23, 2026; and Centripetal v. Cisco, docket 24-2097, argued April 7, 2026) concerns other Centripetal patents, not 10091246. The appeal for 10091246 was case 23-1528, which concluded earlier with the Rule 36 affirmance described above.
Uncertainties / caveats
- The exact date of the CAFC Rule 36 judgment in case 23-1528 is not stated in the sources I retrieved (only that the affirmance occurred and was final); I did not independently verify the CAFC docket entry.
- The full verbatim text of claims 8 and 15 was only partially reproduced in my sources; the first elements are confirmed (device/media preamble, receiving rule sets, receiving packets via a communication interface), and the remaining executing steps are stated by RPX/PTAB exhibit summaries to mirror claim 1's three-stage sequence, but I could not confirm the exact dependent-limitation wording.
- Google Patents' "Active" status tag predates or does not reflect the IPR/CAFC unpatentability outcome; the effective enforceability of the claims has been eliminated by the affirmed IPR decision.
- No authoritative evidence was found of any 2026 CAFC proceeding specifically docketed against patent 10091246.
Generated 8/31/2026, 12:46:54 AM
Cases on file (4)
Group view →Specific litigation cases in our database that name US patent 10091246. The free-form analysis below may also discuss cases beyond this list.
- Palo Alto Networks, Inc. v. Centripetal Networks, Inc.filed Jul 22, 2021IPR2021-01152Patent Trial and Appeal Board (PTAB)terminated Jan 24, 2023Final Written Decision; affirmed on appeal
Defendants: Centripetal Networks, Inc.
- Centripetal Networks, Inc. v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137 (orig. 1:21-cv-00313)U.S. District Court for the Eastern District of Virginia, Norfolk Division (originally Alexandria Division)Judgment as a matter of law granted in part and denied in part; new trial denied; dismissed in part as of October 3, 2024
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10785266, 10567343, 10567437, 10530903, 10567413, 10659573, 10757126, 10542028, 10503899, 10735380, 10749906, 10931797
- Centripetal Networks, LLC v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137U.S. District Court for the Eastern District of Virginia, Norfolk Divisionpost-judgment proceedings/appeal ongoing
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10749906, 10503899, 10530903, 10542028, 10567343, 10567413, 10567437, 10659573, 10735380, 10757126, 10785266, 10931797
- 25-1167U.S. Court of Appeals for the Federal Circuitactive
Defendants: Centripetal Networks, LLC
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
Based on searches of PACER dockets, the CAFC, PTAB records, Unified Patents, Docket Alarm, Justia, CourtListener, and PatSnap, I have identified the following litigation involving US Patent No. 10091246 ("Methods and Systems for Protecting a Secured Network," Centripetal Networks). All of the identified matters involve the same two parties: Centripetal Networks, Inc./LLC (patent owner/plaintiff) and Palo Alto Networks, Inc. (defendant/petitioner).
1. Centripetal Networks, Inc. v. Palo Alto Networks, Inc.
- Court: U.S. District Court, Eastern District of Virginia (Norfolk Division)
- Case No.: 2:21-cv-00137 (-RCY-RJK, later -EWH-LRL; Judge Elizabeth W. Hanes)
- Filed: March 12, 2021
- Plaintiff: Centripetal Networks, Inc. (later Centripetal Networks, LLC)
- Defendant: Palo Alto Networks, Inc.
- Patents in suit: Thirteen Centripetal patents, including US10091246 (along with, e.g., 10,503,899; 10,530,903; 10,542,028; 10,567,343; 10,567,413; 10,567,437; 10,659,573; 10,735,380; 10,749,906; 10,757,126; 10,785,266; 10,931,797)
- Status / Outcome: The case was stayed for a period pending PTAB IPRs. A jury trial was held in January 2024, and on January 31, 2024 the jury awarded Centripetal $151.5 million, finding infringement of four of the asserted patents (Reuters). Post-trial, the court (Oct. 2024) granted Palo Alto's JMOL motion in part and denied it in part, denied a new-trial motion, and entered judgment. Palo Alto appealed; the docket reflects an appeal at the Federal Circuit (No. 25-1167) and a December 22, 2025 order reactivating that appeal under FRAP 4(a)(4) (Docket Alarm, E.D. Va. 2:21-cv-00137, entry No. 1017). Note: I could not confirm from the available sources whether US10091246 was among the four patents the jury found infringed; by the time of trial, its claims had been invalidated in IPR (see No. 3 below), which may have limited its role in the damages verdict.
- Sources: https://portal.unifiedpatents.com/litigation/Virginia%20Eastern%20District%20Court/case/2%3A21-cv-00137 ; https://www.docketalarm.com/search/?f=party_obj.firm.name_exact-Clement+%26+Murphy&q=patent%3A%2810757126%29 ; https://www.ciplawyer.com/articles/[152741](/patent/152741).html ; https://www.patsnap.com/resources/blog/litigation/centripetal-networks-v-palo-alto-networks-ngfw-patent-dispute-patsnap/
2. Centripetal Networks, Inc. v. Palo Alto Networks, Inc.
- Court: U.S. District Court, Eastern District of Virginia (Alexandria Division, based on the "1:21" prefix)
- Case No.: 1:21-cv-00313
- Filed: March 12, 2021 (same day as the Norfolk case; complaint and exhibits filed by Centripetal Networks, Inc. against Palo Alto Networks, Inc.)
- Status: This matter is listed on the Google Patents litigation record for US10091246. The docket entries I located (e.g., a "Notice of Filing of Additional Exhibits" and a "Financial Interest Disclosure Statement" referencing Case No. 1:21-cv-00313) confirm it was opened on March 12, 2021 with the same parties. I could not confirm from the available search results whether this case was subsequently consolidated with 2:21-cv-00137 or its separate disposition; treat the current status as unverified.
- Sources: https://portal.unifiedpatents.com/litigation/Virginia%20Eastern%20District%20Court/case/1%3A21-cv-00313 ; https://www.docketalarm.com/cases/Virginia_Eastern_District_Court/2--21-cv-00137/Centripetal_Networks_Inc._v._Palo_Alto_Networks_Inc/7/ ; https://www.docketalarm.com/cases/Virginia_Eastern_District_Court/2--21-cv-00137/Centripetal_Networks_Inc._v._Palo_Alto_Networks_Inc/docs/10.pdf
3. Palo Alto Networks, Inc. v. Centripetal Networks, Inc. — IPR2021-01152 (PTAB)
- Tribunal: Patent Trial and Appeal Board (PTAB)
- Case No.: IPR2021-01152
- Petition filed: July 22, 2021
- Petitioner: Palo Alto Networks, Inc.
- Patent Owner: Centripetal Networks, Inc.
- Patent: US10091246 — all claims 1–20 challenged
- Institution decision: January 26, 2022
- Final Written Decision: January 24, 2023 — the Board found the challenged claims unpatentable (APJs Kevin F. Turner, Lynne E. Pettigrew, Aaron W. Moore; decision by Turner)
- Status: Final Written Decision; appealed by Centripetal to the Federal Circuit (see No. 4 below)
- Sources: https://portal.unifiedpatents.com/ptab/case/IPR2021-01152 ; https://services.patexia.com/lawsuits/Palo-Alto-Networks-Inc-v-Centripetal-Networks-Inc-id-[153644](/patent/153644) ; https://patents.justia.com/patent/[11477237](/patent/11477237)
4. Centripetal Networks, LLC v. Palo Alto Networks, Inc. — Appeal No. 23-1528 (CAFC)
- Court: U.S. Court of Appeals for the Federal Circuit
- Case No.: 23-1528
- Filed: February 22, 2023
- Appellant: Centripetal Networks, LLC
- Appellee: Palo Alto Networks, Inc.
- Subject: Appeal of the PTAB's Final Written Decision in IPR2021-01152 (invalidating all claims of US10091246)
- Decision: May 13, 2024 — Rule 36 judgment, AFFIRMED, nonprecedential (per curiam: Taranto, Hughes, and Stoll)
- Status / Outcome: Final affirmance of unpatentability. Per PatSnap's analysis, the affirmance eliminates US10091246B2 as an enforceable infringement threat — no further Federal Circuit appeal is available (certiorari would be discretionary). The PTAB's cancellation of the claims therefore stands.
- Sources: https://cafc.uscourts.gov/05-13-2024-23-1528-centripetal-networks-llc-v-palo-alto-networks-inc-rule-36-judgment-23-1528-rule_36_judgment-5-13-2024_2316704/ ; https://dockets.justia.com/docket/circuit-courts/cafc/23-1528 ; https://www.courtlistener.com/opinion/[9501692](/patent/9501692)/centripetal-networks-llc-v-palo-alto-networks-inc/ ; https://portal.unifiedpatents.com/litigation/Court%20of%20Appeals%20for%20the%20Federal%20Circuit/case/23-1528
Summary of current posture (as of April 26, 2026)
- Validity: All claims (1–20) of US10091246 were found unpatentable in IPR2021-01152 (FWD Jan. 24, 2023), and the Federal Circuit affirmed under Rule 36 on May 13, 2024 (No. 23-1528). The patent is effectively unenforceable.
- District court: The main infringement action (2:21-cv-00137, E.D. Va.) proceeded to a $151.5M jury verdict (Jan. 31, 2024), followed by a partial JMOL grant (Oct. 2024) and a pending/active appeal at the Federal Circuit (No. 25-1167, reactivated Dec. 22, 2025). US10091246 was one of 13 patents originally asserted in that action, but I could not verify from available sources that it was among the four patents on which the jury's damages award was based.
- Second E.D. Va. case (1:21-cv-00313): Confirmed filed March 12, 2021 against the same defendant; current status not verified in my searches.
Caveats: I could not confirm (a) whether 1:21-cv-00313 was consolidated with 2:21-cv-00137 or its individual disposition, or (b) the precise role of US10091246 in the jury verdict, given the intervening IPR invalidation. For authoritative docket-level verification, PACER (E.D. Va. cases 2:21-cv-00137 and 1:21-cv-00313; CAFC Nos. 23-1528 and 25-1167) and the PTAB's IPR2021-01152 record are the definitive sources.
Generated 8/31/2026, 12:47:07 AM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Palo Alto Networks, Inc.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
Proceedings overview
One AIA trial proceeding is confirmed for US 10091246 (the "'246 patent"): IPR2021-01152, an inter partes review filed by Palo Alto Networks, Inc. against Centripetal Networks, LLC. Status breakdown: 0 active, 0 settled, 0 institution-denied, and 1 in which all challenged claims (1–20) were invalidated — a Final Written Decision finding every claim unpatentable, affirmed by the Federal Circuit under Rule 36 on 2024-05-13. Bottom line for a defendant: the `'246 patent is dead. Every claim (1–20) has been canceled; there is no surviving claim of US 10091246 to infringe. Any demand letter or infringement theory built on this patent is sanction-bait.
Data-source flag: The structured USPTO ODP block in this prompt reports "no AIA trial proceedings on file," but that appears to be a stale ingest. Web research conclusively confirms IPR2021-01152 (filed 2021-07-22, FWD 2023-01-24, CAFC affirmance 2024-05-13), and Google Patents' own litigation metadata for US10091246 lists it with "Final Written Decision" status. The ODP absence should not be read as "never challenged."
IPR2021-01152 — Palo Alto Networks, Inc. v. Centripetal Networks, LLC
- Type: Inter Partes Review
- Filed: 2021-07-22 (petition executed/filed; filing date accorded 2021-07-28)
- Status: Final Written Decision — all challenged claims unpatentable; affirmed on appeal (the ODP block shows "none," which is stale — see flag above)
- Judge panel: Kevin F. Turner (authoring APJ), Lynne E. Pettigrew, Aaron W. Moore — FWD (Paper 32), 2023-01-24
- Petition grounds: Palo Alto challenged all 20 claims. As instituted (Decision on Institution, Paper 9, 2022-01-26), the § 103(a) grounds were:
- Claims 1–3, 5–10, 12–17, 19, 20 — obvious over Jungck (US 2009/0262741 A1) + Bhatia (US 2007/0118894 A1);
- Claims 4, 11, 18 — obvious over Jungck + Bhatia + RFC 2003 (IP Encapsulation within IP);
- Claims 6, 13, 20 — an additional obviousness ground over Jungck + Bhatia + a third reference the FWD identifies as "Turner" (FWD n.5; the reference's full citation was not captured in the sources available to me).
- The petition also pressed collateral estoppel based on the earlier Cisco IPRs against the parent patents 9,137,205 and 9,560,077 (FWD § C).
- Petitioner relied on the Declaration of Dr. Vijay Madisetti (Ex. 1004); Patent Owner responded with Dr. Michael T. Goodrich (Ex. 2017). Oral hearing held 2022-10-26.
- Institution decision: Granted in full on 2022-01-26 (Paper 9). The Board instituted on all challenged claims and all asserted grounds, rejecting Patent Owner's preliminary arguments on claim scope and discretionary denial (the parties filed supplemental briefing on § 314(a) discretion, Papers 7–8).
- Final Written Decision (Paper 32, 2023-01-24): "we determine that Petitioner has shown, by a preponderance of the evidence, that claims 1–20 ('the challenged claims') of U.S. Patent No. 10,091,246 B2 … are unpatentable." No claim survived — all 20 claims, independent and dependent alike, were canceled. The panel's key construction ruling rejected Centripetal's argument that the executed "rule sets" must be the same as the received "plurality of rule sets": "we no longer conclude that the independent claims require the receipt of 'a plurality of rule sets'… the number of network addresses included with specific rule sets applies to the rule sets being executed, rather than to the plurality of rule sets received." On that construction, the Jungck/Bhatia (and RFC 2003/Turner) combinations rendered the claims obvious.
- Settlement / termination: None — the case ran to a merits FWD. No settlement or confidential termination terms identified.
- Appeal: Yes. Centripetal filed a Notice of Appeal on 2023-02-14 (Paper 33); docketed at the Federal Circuit as No. 23-1528 on 2023-02-22. Issues on appeal: claim construction, the Board's unpatentability findings as to claims 1–20, and all adverse underlying rulings. Disposition: AFFIRMED by Rule 36 judgment entered 2024-05-13 (per curiam: Taranto, Hughes, Stoll) — "ORDERED and ADJUDGED: AFFIRMED. See Fed. Cir. R. 36." No certiorari petition was identified in my research; the affirmance is final.
- Defensive value: Maximum. The patent's claims are canceled, the cancellation is affirmed on appeal, and the patent owner is bound. In the parallel E.D. Va. case (Centripetal Networks, Inc. v. Palo Alto Networks, Inc., No. 2:21-cv-00137), the parties' own status filing reflects "All asserted claims unpatentable" for the
'246patent (asserted claims were 1–5, 7–12, 14–19). Any infringement theory tied to US 10091246 today has no valid claim to stand on.
Strategic summary
Claims CANCELED vs. SUSTAINED vs. UNTESTED. All 20 claims of US 10091246 were challenged in IPR2021-01152, and all 20 were found unpatentable and canceled — the FWD contains no patentable-claim hold. There are no surviving claims and no untested claims. The cancellation is confirmed on appeal (Fed. Cir. No. 23-1528, Rule 36 affirmance, 2024-05-13). The patent is, for enforcement purposes, a dead letter. Note that this result is consistent with the wider family history: the parent patents 9,137,205 and 9,560,077 were themselves invalidated in Cisco-filed IPRs (e.g., IPR2018-01443 on the '205 patent; the '077 IPR FWD was affirmed under Rule 36), and Palo Alto's coordinated 2021 IPR wave (IPR2021-01152, -01153, -01154, -01157, and others) invalidated six of the patents Centripetal asserted in the E.D. Va. litigation — the '028, '126, '413, '246, '906, and '899 patents.
Estoppel landscape. 35 U.S.C. § 315(e)(2) estops Palo Alto Networks (and its privies) from re-raising in district court any ground it raised or reasonably could have raised in IPR2021-01152 — but that bar is largely moot as to the '246 patent because the claims are gone. For a new defendant not in privity with Palo Alto, § 315(e)(2) does not apply, but something more powerful does: collateral estoppel runs against the patent owner. The FWD (affirmed) conclusively adjudicated all 20 claims unpatentable, and the E.D. Va. court in the related Centripetal/Palo Alto litigation has already applied collateral estoppel to bind Centripetal to PTAB factual findings on this same prior art (Jungck/Bhatia), even where the IPR petitioner differed from the litigation defendant. A defendant today can assert claim preclusion/collateral estoppel off the affirmed FWD and move to dismiss or strike the '246 patent from any case. If you are defending a different Centripetal family patent (e.g., 10,567,437 or 10,785,266), the Jungck + Bhatia combination is battle-tested and the PTAB factual findings on it are preclusive against Centripetal in E.D. Va.
Pattern signals. Palo Alto is a repeat, coordinated petitioner — it filed a wave of IPRs against Centripetal's entire asserted portfolio in 2021, and its IPR campaign has been highly successful (the '246 FWD being one of six invalidations). Cisco separately invalidated the parent patents. Centripetal has litigated and appealed aggressively — it appealed this FWD (affirmed), and has pursued CAFC review of other FWDs in its portfolio (23-1785 affirmed; 23-1654/23-1655 affirmed; 23-1636 vacated/remanded on a different patent, 10,530,903) — so expect the patent owner to exhaust appellate remedies, but here it lost. Notably, Unified Patents appears in the record only as the data aggregator behind Google Patents' PTAB/litigation metadata (its portal page for 10091246 carries the CC-licensed dataset); it was not the petitioner. The presence of a well-resourced, successful petitioner (Palo Alto) and the family-wide invalidation pattern means the validity of this patent's subject matter has been thoroughly and repeatedly tested — the absence of surviving claims is the whole story.
Recommended next steps
If you are a defendant being asserted against on US 10091246, put the FWD on the record and quote the disposition. The operative language from IPR2021-01152, Paper 32 (2023-01-24): "For the reasons discussed herein, we determine that Petitioner has shown, by a preponderance of the evidence, that claims 1–20 ('the challenged claims') of U.S. Patent No. 10,091,246 B2 … are unpatentable." The FWD is available via USPTO PTAB E2E (IPR2021-01152, Paper 32) and mirrored at DocketAlarm. Pair it with the Federal Circuit's Rule 36 judgment in No. 23-1528, entered 2024-05-13: "ORDERED and ADJUDGED: AFFIRMED. See Fed. Cir. R. 36." — available at CAFC and CourtListener. Because the CAFC affirmed with no written opinion, the judgment is non-precedential, but the claim cancellation is final and binding — move to dismiss or strike the
'246patent and consider Rule 11 exposure for any continued assertion.No active PTAB proceedings are pending on this patent, so there are no upcoming institution-decision deadlines, oral-hearing dates, or statutory one-year trial milestones to calendar. (For reference: institution decision issued 2022-01-26; oral hearing 2022-10-26; FWD 2023-01-24 — inside the 1-year statutory window.)
If the ODP "no proceedings" block is what you received from a due-diligence vendor, correct the record. The absence shown there is a data-ingest artifact, not reality. If your diligence relies on that block, cite IPR2021-01152 and the CAFC affirmance affirmatively — and, if Centripetal is asserting other family members against you, run the same PTAB check on each (10,567,437; 10,785,266; 10,749,906; 10,567,413; 10,757,126; 10,542,028; 10,530,903), because several have their own IPR/FWD histories with outcomes that cut both ways.
Caveats: I could not verify from available sources whether Centripetal sought certiorari after the 2024-05-13 affirmance (no cert petition surfaced in my searches), and I could not fully identify the third "Turner" reference cited in the FWD's additional ground for claims 6, 13, 20 (FWD n.5 not captured). Neither gap affects the bottom line: all claims are canceled and the cancellation is affirmed.
Generated 8/31/2026, 12:47:59 AM
Ownership chain (2)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2023-01-20 · Assignment
Steven Rogers; Sean MooreCentripetal Networks, Inc.
acquisition
2023-01-20 · Change of Name
Centripetal Networks, Inc.Centripetal Networks, Inc.
change of name only
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I was unable to pull the full USPTO Assignment Center reel/frame detail in the searches available to me (the Assignment Center's underlying records are not reliably surfaced through web search), so the chain below is reconstructed from the USPTO-derived legal-event feed shown on Google Patents and from litigation records. I am flagging every point where reel/frame numbers and correspondents could not be independently verified rather than inventing them.
Inventors
- Steven Rogers — co-founder/CEO of Centripetal Networks, Inc. at the time of filing (2012). He and Sean Moore co-founded the company; Rogers is publicly documented as the public face of the company in the Cisco and Palo Alto Networks litigations.
- Sean Moore — co-founder/CTO of Centripetal Networks, Inc. at the time of filing (2012). Co-author of the patent family; testified in the Cisco trial as a top-level employee.
Unusual pattern? Not observed. Both inventors remained with Centripetal through the Cisco trial (2020) and beyond — there is no "inventors depart within 12 months of filing" pattern that typically precedes a portfolio fire-sale.
Original assignee
- Centripetal Networks, Inc. (renamed Centripetal Networks, LLC in 2023; current assignee of record).
- Products: Yes — Centripetal shipped the Threat Intelligence Gateway (TIG) and related rule-based network-security products, developed in part with U.S. Department of Homeland Security funding. Its products embody the packet-filtering / packet-transformation functionality claimed in this patent.
- Line of business: Network security hardware/software vendor.
- Current status: Operating. Not acquired, not dissolved, not in bankruptcy. It has been an active plaintiff (Cisco, Palo Alto Networks, others) and also an active defendant/respondent in IPRs.
Assignment timeline
The USPTO Assignment Center database (https://assignmentcenter.uspto.gov/; legacy mirror at https://assignment.uspto.gov/patent/index.html) is the authoritative source. Based on the USPTO legal-event feed reflected on Google Patents, the recorded conveyances for this patent are:
Executed ~2012 (original application filing) / recordation event shown 2023-01-20 — Reel/frame not independently verified (search tools did not surface the number)
- Conveyance: Assignment of inventors' interest (ASSIGNMENT OF ASSIGNORS INTEREST)
- Assignor: Steven Rogers; Sean Moore
- Assignee: Centripetal Networks, Inc.
- Correspondent: Not retrievable from available search results — unable to verify whether a repeat-player attorney appears here.
- Context: Standard employer assignment from the two inventor-founders to their company at the time the original application (US 13/657,010, later US 9,137,205) was filed in October 2012; US 10091246 is a 2017 continuation of that chain.
Executed / recorded 2023-01-20 — Reel/frame not independently verified
- Conveyance: Change of Name (SEE DOCUMENT FOR DETAILS)
- Assignor: Centripetal Networks, Inc.
- Assignee: Centripetal Networks, LLC
- Correspondent: Not retrievable from available search results.
- Context: Pure corporate name change / internal reorg — no change in beneficial ownership, no transfer to a third party.
Note on completeness: I could not confirm whether a security agreement / lien is recorded against this patent (Centripetal has used debt financing, and security interests are commonly recorded against such portfolios). That is an open item for direct Assignment Center verification, not a finding. If the Assignment Center search by patent number returns only the two conveyances above, the finding is simply that the original operating assignee still owns the patent (now under its LLC name).
Timeline diagram
timeline
title Ownership of US 10091246
2012 : Filed by Centripetal Networks Inc
2015 : Continuation application filed
2017 : Continuation application filed
2018 : Patent issued
2020 : Cisco infringement verdict
2021 : Palo Alto Networks suit and IPR filed
2023 : Name change to Centripetal Networks LLC
NPE / troll-pattern signals
Shell-entity transfer — Not present. The only recorded conveyances are the inventor-to-company assignment and a Change of Name from Inc. to LLC. The LLC is the same operating company, not a single-purpose licensing vehicle; it ships the Threat Intelligence Gateway product line.
Known asserter in the chain — Not present. Neither Centripetal Networks, Inc. nor Centripetal Networks, LLC appears on the standard public NPE lists (Acacia, Marathon, IV, Wi-LAN, Conversant, Vringo, Innovatio, MPHJ, Spangenberg entities, etc.). Unified Patents challenged this patent in IPR2021-01152, which is an attack posture, not an ownership signal.
Repeat correspondent across the chain — Unclear. The correspondent names on the recorded conveyances could not be retrieved from the searches available. This is the one signal that requires a direct Assignment Center lookup; I will not speculate.
Cascading transfers — Not present. There is no chain of chained LLCs; only two events (inventor assignment + name change), with no evidence of common-principal shell assignees.
Pre-litigation transfer — Not present. Centripetal owned the patent (via its Inc. entity) when it sued Cisco in 2018 and when it sued Palo Alto Networks (EDVA cases 2:21-cv-00137, 1:21-cv-00313). No assignment was arranged within six months before either suit to manufacture standing or venue.
Bankruptcy fire-sale — Not present. No bankruptcy proceedings involving the assignee; the chain shows no court-supervised patent sale.
Privateering — Not present. Centripetal asserts its own patents in its own name against direct competitors (Cisco, Palo Alto Networks). There is no evidence it asserts on behalf of a third-party operating company, and no SEC filings surface a privateering arrangement (Centripetal is private).
Defensive aggregator (anti-NPE) — Not present. The chain terminates at Centripetal Networks, LLC, an operating company — not at RPX, AST, LOT, Unified Patents, or OIN. Inverse context: Unified Patents attacked the patent via IPR2021-01152, which resulted in a Final Written Decision and a Federal Circuit affirmance (case 23-1528) — the patent has been held unpatentable, but that is a validity outcome, not a defensive acquisition.
Verdict
Operating-company assertion.
Centripetal Networks, LLC is the current assignee, is an operating network-security vendor that shipped products embodying the claimed packet-transformation technology (the Threat Intelligence Gateway, developed with DHS), and asserted this patent against actual competitors (Cisco in 2018; Palo Alto Networks in 2021) in its own name. The assignment record shows no transfer to any licensing entity — only the original inventor-to-company assignment and a 2023 Change of Name from Inc. to LLC — so none of the shell-transfer, cascading-transfer, or pre-litigation-transfer NPE signals are present. The one caveat is that I could not independently verify the correspondent names and reel/frame numbers (and any unrecorded security agreements) directly from the Assignment Center, so a manual check at https://assignmentcenter.uspto.gov/ (search "10091246") is the recommended confirmation step; on the available evidence, this is an operating company asserting its own patents, not an NPE.
Generated 8/31/2026, 12:47:16 AM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll search for US Patent 10091246 and its cited prior art references.
I have initial data from the Unified Patents portal. Let me dig deeper into the complete list of cited references for US10091246B2 and verify each one.
Let me get the full list of citations from Google Patents and the USPTO for this patent.
I was able to retrieve the patent record and the beginning of its cited-art listing before hitting the search step limit. Here is my analysis based on the available data, with a clear caveat where the retrieval is incomplete.
1. Patent identification (verified)
| Field | Value |
|---|---|
| Patent No. | US10091246B2 |
| Title | Methods and systems for protecting a secured network |
| Inventors | Steven Rogers; Sean Moore |
| Assignee | Centripetal Networks LLC (originally Centripetal Networks, Inc.) |
| Application / Filing | US 15/413,834, filed 2017-01-24 |
| Priority date | 2012-10-22 (chain: US 13/657,010 → US 9,137,205; US 14/698,560 → US 9,560,077) |
| Grant date | 2018-10-02 |
| Status | Active in USPTO records, but challenged in IPR2021-01152; Final Written Decision found claims unpatentable; affirmed by the Federal Circuit (Case 23-1528) via Rule 36 on 2024-05-13 |
Claim structure (20 claims). Independent claim 1 (method) requires, at each of one or more packet security gateways associated with a security policy management server: (a) receiving a dynamic security policy from the security policy management server; (b) receiving packets associated with a protected network; and (c) performing, on a packet-by-packet basis, at least one of multiple packet transformation functions specified by the policy, including at least one function other than forwarding or dropping. Claims 19 and 20 are the system and computer-readable-medium counterparts. Dependent claims add: series gateways (2–3); blocklist/allowlist (4–5); VoIP-derived rules (6); phased restoration (7); differential queueing (8); SIP-URI-based rerouting to a monitoring device with encapsulation (9–10); IPsec/forward/drop transforms (11); five-tuple rules (12); DSCP rules (13); network-layer-transparent operation and management interface (14–15); malicious-address subscription lists (16); anti-spoofing boundary-specific policies (17); and gateway-at-every-boundary (18).
2. Cited prior art references (retrieved from Unified Patents portal listing for US10091246, "Patent Art" section)
Important caveat: The Unified Patents portal lists 210 items of patent art associated with this patent (citations of record plus IPR-related art). I was able to retrieve 12 complete entries before the search limit was reached; the rest of the list was truncated. For each reference below, the full citation fields shown were verified against the portal; the brief description is based on the reference title/assignee and general knowledge; and the § 102 claim mapping is my preliminary analytical assessment (a formal anticipation opinion requires a claim-by-claim element comparison against each reference's full disclosure, which I could not perform for all references here).
Ref. 1 — US 2006/0136987 A1
- Full citation: Fujitsu Ltd., "Communication Apparatus," U.S. Patent App. Pub. US 2006/0136987 A1; priority date 2004-12-19.
- Description: A communication apparatus for network packet handling, including filtering/forwarding of received packets.
- Potential § 102 anticipation: Independent claims 1, 19, 20 (receiving packets at a network device and applying a packet transformation function on a per-packet basis). Dependent claims 11 (forward/drop transforms) and 12 (header-based matching) are the most plausible targets, subject to full-text verification.
Ref. 2 — US 2005/0251570 A1
- Full citation: Secerno Ltd., "Intrusion Detection System," U.S. Patent App. Pub. US 2005/0251570 A1; filed 2002-04-17.
- Description: An intrusion detection system that inspects traffic and applies security policies, including dropping/blocking of malicious traffic.
- Potential § 102 anticipation: Claims 1, 19, 20 (policy-driven packet disposition at a network security device); claims 4–5 (block/allow sets) and 16 (rules derived from known-malicious addresses) if the disclosure teaches policy generation from threat data.
Ref. 3 — EP 1864226 B1
- Full citation: Wake Forest University, "Methods, Systems, and Computer Program Products for Network Firewall Policy Optimization," EP 1 864 226 B1; priority 2005-03-27.
- Description: Firewall policy optimization, including representation/ordering of rule sets (e.g., firewall decision diagrams) for high-speed packet filtering — directly relevant to the '91246 specification's discussion of rule merging/ordering.
- Potential § 102 anticipation: Claims 1, 19, 20 (rule-based per-packet filtering); claim 12 (five-tuple matching); claims 2–3 (sequential/ordered rule execution across gateways) if the disclosure addresses distributed rule ordering.
Ref. 4 — US 2006/0048142 A1
- Full citation: Enterasys Networks, Inc., "System and Method for Rapid Response Network Policy Implementation," U.S. Patent App. Pub. US 2006/0048142 A1; filed 2004-09-01.
- Description: Dynamically implementing network security policies across network devices in rapid response to detected conditions — close to the "security policy management server pushes dynamic security policy to gateways" model of claim 1.
- Potential § 102 anticipation: Claim 1, 19, 20 (receiving/implementing a dynamic security policy at gateways); claims 4–5 (block/allow policies); claim 7 (time-sequenced policy deployment) if the disclosure teaches phased policy rollout.
Ref. 5 — US 2004/0093513 A1
- Full citation: Hewlett-Packard / Trend Micro, Inc., "Active Network Defense System and Method," U.S. Patent App. Pub. US 2004/0093513 A1; filed 2002-11-06.
- Description: Active network defense that detects attacks and automatically reconfigures network devices (routers/firewalls) to block attack traffic.
- Potential § 102 anticipation: Claims 1, 19, 20 (dynamic policy-based packet handling); claims 4–5 (drop/forward rule sets); claim 16 (rules based on known-malicious address lists).
Ref. 6 — US 2010/0211678 A1
- Full citation: Verizon Patent and Licensing, Inc., "External Processor for a Distributed Network Access System," U.S. Patent App. Pub. US 2010/0211678 A1; priority 2000-11-27.
- Description: An external packet-processing device in a distributed network access system performing filtering/forwarding functions on traffic at the network edge.
- Potential § 102 anticipation: Claims 1, 19, 20 (per-packet transformation at a network gateway); claim 11 (forward/drop functions); claims 14–15 (transparent operation/management interface) if disclosed.
Ref. 7 — US 2006/0133377 A1
- Full citation: Fortinet, Inc., "System and Method for Integrated Header, State, Rate and Content Anomaly Prevention with Policy Enforcement," U.S. Patent App. Pub. US 2006/0133377 A1; filed 2004-12-21.
- Description: Integrated anomaly prevention (header/state/rate/content inspection) with policy enforcement in network security appliances.
- Potential § 102 anticipation: Claims 1, 19, 20; claims 11–13 (packet transformation functions; five-tuple and DSCP-based rule matching).
Ref. 8 — US 2003/0154399 A1
- Full citation: Juniper Networks, Inc., "Multi-method Gateway-based Network Security Systems and Methods," U.S. Patent App. Pub. US 2003/0154399 A1; filed 2002-02-07.
- Description: Gateway-based network security (e.g., NetScreen-style firewall/VPN gateways) supporting multiple security methods and tunnel/encryption processing.
- Potential § 102 anticipation: Claim 1, 19, 20; claim 11 (forwarding to an IPsec stack / security association); claim 12 (five-tuple matching typical of firewall rules).
Ref. 9 — US 2005/0141537 A1
- Full citation: Intel Corp., "Auto-learning of MAC Addresses and Lexicographic Lookup of Hardware Database," U.S. Patent App. Pub. US 2005/0141537 A1; filed 2003-12-28.
- Description: Layer-2 address auto-learning and hardware database lookup for forwarding decisions — relevant to link-layer (transparent) operation.
- Potential § 102 anticipation: Claim 14 (link-layer send/receive with network-layer transformation); claim 1, 19, 20 only to the extent the device performs packet transformation; otherwise more likely a § 103 (obviousness) component than a standalone § 102 anticipator.
Ref. 10 — US 2007/0240208 A1
- Full citation: Zyxel Communications Corp., "Network Appliance for Controlling Hypertext Transfer Protocol (HTTP) Messages Between a Local Area Network and a Global Communications Network," U.S. Patent App. Pub. US 2007/0240208 A1; filed 2006-04-09.
- Description: A network appliance filtering/controlling HTTP messages between a LAN and the Internet — protocol-specific packet control at a network boundary.
- Potential § 102 anticipation: Claim 1, 19, 20 (packet transformation at a boundary device); claim 12 (protocol/port-based rule matching); claims 17–18 (boundary placement) if disclosed.
Ref. 11 — US 2011/0055916 A1
- Full citation: Great Wall Systems, "Methods, Systems, and Computer Readable Media for Adaptive Packet Filtering," U.S. Patent App. Pub. US 2011/0055916 A1; filed 2009-08-27.
- Description: Adaptive packet filtering in which filtering rules are dynamically updated/adapted — highly relevant to the "dynamic security policy" concept of claim 1.
- Potential § 102 anticipation: Claim 1, 19, 20; claims 4–5 (dynamic allow/block sets); claim 7 (progressively expanded rule sets over time); claim 16 (threat-feed-driven rule updates).
Ref. 12 — US 2013/0254766 A1
- Full citation: Microsoft Technology Licensing LLC, "Offloading Packet Processing for Networking Device Virtualization," U.S. Patent App. Pub. US 2013/0254766 A1; filed 2012-03-20.
- Description: Offloading packet processing tasks to hardware/accelerators in virtualized networking environments.
- Potential § 102 anticipation: Claim 1, 19, 20 (per-packet processing at a network device); claim 14 (transparent operation) if the offload path operates without a network-layer-addressed interface.
3. Key observations
Incomplete retrieval. The full citation list on the face of US10091246 (USPTO/Google Patents "Citations" tab) contains more references than the 12 retrievable above. The 210-item "Patent Art" listing on the Unified Patents portal aggregates citations of record with IPR2021-01152 art. To complete the § 102 analysis for every citation, direct access to the USPTO or Google Patents citation tab is required; I did not reach it before the search limit.
All retrieved references predate the 2012-10-22 priority date, so each is available as prior art under both pre-AIA § 102 (the application family predates the March 16, 2013 AIA transition) and AIA § 102. None are by the named inventors or commonly owned, so no § 102(b)(2)(C)/pre-AIA § 103(c) disqualification is apparent from the retrieved data.
Litigation context is material. IPR2021-01152 (Unified Patents v. Centripetal) resulted in a Final Written Decision of unpatentability, and the Federal Circuit affirmed on 2024-05-13 (Case 23-1528, Rule 36). Per the PatSnap article retrieved, the challenged claims of US10091246B2 are treated as cancelled/invalid as a result. The art in that IPR (likely including several of the references above) is the most probative set for anticipation/obviousness, and I recommend pulling the IPR's final written decision for the exact grounds if you need a definitive § 102/§ 103 mapping.
Claim-mapping caveat. The "potential § 102 anticipation" assessments above are based on reference titles, assignees, dates, and general subject-matter knowledge. Anticipation requires a single reference disclosing every claimed element, arranged as in the claim. None of these mappings should be treated as a final legal conclusion without a full-text, element-by-element comparison.
To complete the analysis, the next steps would be: (a) pull the Google Patents "Citations" tab for US10091246B2 to enumerate the complete examiner-cited list; (b) pull the IPR2021-01152 Final Written Decision for the instituted grounds; and (c) download the full texts of each reference for claim-element mapping. Let me know if you'd like me to continue with any of those when the search limit resets.
Generated 8/31/2026, 12:47:47 AM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
Obviousness Analysis — U.S. Patent No. 10,091,246 B2 under 35 U.S.C. § 103
Preliminary note on sources
The "Prior Art" section of the source page was not included in the materials provided to me, so I have grounded this analysis in the authoritative adversarial record that actually decided obviousness for this patent: IPR2021-01152, Palo Alto Networks, Inc. v. Centripetal Networks, LLC (P.T.A.B.), whose Final Written Decision (FWD) dated January 24, 2023 found all claims 1–20 unpatentable under pre-AIA § 103(a), and which the Federal Circuit affirmed (Rule 36) in Appeal No. 23-1528. Where I could verify the underlying reference teachings from retrieved exhibits, I describe them; where I could not (noted explicitly), I flag the uncertainty.
1. Claim scope at issue
As established in the earlier sections of this analysis, the independent claims (1 = method, 8 = apparatus, 15 = computer-readable media) all recite the same phased-restoration scheme performed at a network security device located at a protected-network boundary:
- receive a plurality of rule sets;
- receive a plurality of packets;
- execute, at a first time and on a packet-by-packet basis, a first rule set specifying a first set of network addresses to forward;
- execute, at a second, later time, a second rule set specifying a larger second set of addresses to forward;
- execute, at a third, still-later time, a third rule set specifying a still-larger third set of addresses to forward.
In plain terms: after an attack or outage, the device progressively re-admits traffic — first mission-critical addresses, then a larger trusted set, then the full normal set — by executing successively larger forwarding rule sets at three distinct times (spec: "phased restoration service").
2. Legal framework
Because the patent claims priority to an application filed before March 16, 2013 (earliest priority: October 22, 2012), the PTAB applied pre-AIA § 103(a). The FWD applied the Graham v. John Deere framework (scope/content of prior art; differences; level of ordinary skill; secondary considerations) and KSR International Co. v. Teleflex (known techniques, predictable combinations, "obvious to try," design incentives). See FWD (Paper 32) at § IV.D.
3. Primary combination: Jungck (US 2009/0262741 A1) in view of Bhatia (US 2007/0118894 A1)
Ground 1 — claims 1–3, 5–10, 12–17, 19, 20 — found obvious over Jungck + Bhatia. (FWD at § I.A.; Petition at 7, 15–70; Madisetti Decl., Ex. 1004.)
3.1 What Jungck teaches
Jungck (US Pat. App. Publ. 2009/0262741 A1, filed June 29, 2009, published October 22, 2009; Ex. 1051; related to granted US 8,204,082) describes a packet-processing/filtering device through which network traffic flows, with a rule engine in which rules may be dynamically modified by external devices. Its disclosed actions map directly onto the claimed "packet transformation functions": "releasing the packet unmodified, deleting the packet, modifying the packet, logging/storing information about the packet or forwarding the packet to an external device for subsequent processing" (US 8,204,082, col. on actions; see also claim-comparison chart, Ex. 1011, characterizing Jungck as teaching the claimed receiving/rule-based filtering functions).
Jungck therefore supplies:
- the network security device at a traffic boundary;
- receipt of rule sets (dynamically configurable rules);
- packet-by-packet evaluation against rules;
- forwarding and dropping transformation functions, plus modification/redirection — i.e., "packet transformation functions other than forwarding or dropping."
3.2 What Bhatia teaches
Bhatia (US Pat. App. Publ. 2007/0118894 A1, "Method for Responding to Denial of Service Attacks at the Session Layer or Above," filed November 23, 2005, published May 24, 2007; Ex. 1080; granted as US 7,716,729; assignee NexTone Communications) is the crucial reference for the time-phased, progressively-expanding allowlist concept. Its abstract and specification disclose:
- a packet filter inspection layer interposed between higher and lower protocol layers;
- dynamically created rules in the packet-filter layer identifying likely DoS traffic;
- white list / black list construction, with IP addresses progressively pushed into the whitelist (e.g.,
WL = {204.180.228.4}→WL = {204.180.228.4, 207.180.228.4}), with "Rest = ALL" wildcard handling; - time-limited rule lifecycles: "After a predetermined time period, stopping use of the rule to prevent packet information from being sent through to the application layer" — i.e., rules are created, applied, and discontinued on a temporal schedule;
- while unlisted "Rest" traffic is rate-limited or dropped, matching whitelisted traffic is processed normally.
3.3 Mapping to the claims
| Claimed limitation (paraphrase) | Jungck | Bhatia |
|---|---|---|
| Device at boundary of protected network | Packet-processing/filtering device in the traffic path | Packet-filter inspection layer at network edge |
| Receive a plurality of rule sets | Dynamically modifiable rule sets | Dynamically created white/black-list rules |
| Execute first rule set at first time (forward small address set) | Rule engine applies rules to forward packets | Initial whitelist of allowed addresses; all else dropped/rate-limited |
| Execute second rule set at later time (larger set) | — | IPs progressively pushed into whitelist over time |
| Execute third rule set at still-later time (largest set) | — | Continued expansion of whitelist; rules used then discontinued after predetermined periods |
| Packet-by-packet execution | Line-rate per-packet rule evaluation | Per-packet inspection against WL/BL/Rest |
3.4 Why a POSITA would combine them
A person of ordinary skill addressing the known problem of DDoS-driven network restoration would have a straightforward, predictable reason to combine:
- Jungck provides the scalable filtering platform — a device capable of applying many dynamically-managed rules to high-volume traffic at high resolution (the very scalability problem the '246 patent claims to solve). Bhatia does not itself describe a line-rate, general packet-transformation engine; it describes a methodology for phased DoS response.
- Bhatia provides the missing temporal/phased methodology — dynamic creation of an allowlist, progressive expansion of allowed address sets, and scheduled discontinuation of rules after predetermined time periods. That is precisely the "phased restoration" sequence the claims recite. Jungck's dynamically-modifiable rule sets are the obvious mechanism for implementing Bhatia's phased whitelist on a per-address-set basis.
- The combination is a classic KSR "known technique applied to a known device with predictable results." Using a packet filter to progressively admit larger sets of legitimate addresses after an attack, rather than flipping a single all-or-nothing rule, was not a new concept — Bhatia's white-list construction (with "Rest = ALL") teaches the core idea, and Jungck's dynamic rules give the POSITA the obvious implementation vehicle. The PTAB credited the Madisetti declaration on precisely these points and rejected Patent Owner's contrary arguments (Goodrich Decl., Ex. 2017) that the combination improperly used the claims as a roadmap. Notably, the FWD observed that "the combination of Jungck and Bhatia was previously before the [Board]" — the same combination had been considered in prior IPRs involving Centripetal's earlier patents in this family (US 9,137,205 and US 9,560,077), reinforcing that it was a known, non-speculative combination by the time of the '246 IPR.
- No teaching away. Bhatia affirmatively describes restoring normal service over time (rules discontinued after predetermined periods), and Jungck describes dynamic rule modification — neither discourages the phased, expanding-allowlist implementation.
The PTAB found this ground proven by a preponderance of the evidence for all challenged claims in this group, and the CAFC affirmed.
4. Secondary combination: Jungck + Bhatia + RFC 2003 (claims 4, 11, 18)
Ground 2 — claims 4, 11, 18 — obvious over Jungck, Bhatia, and RFC 2003 (C. Perkins, "IP Encapsulation within IP," Network Working Group RFC 2003, IBM, October 1996; Ex. 1054).
The dependent claims at issue add the limitation (per the specification's multi-dimensional routing/monitoring embodiment) of routing/rerouting matching packets to a network address different from the destination address — e.g., by encapsulating the packets with an IP header specifying the alternate address (here, typically a monitoring device that copies the packets and forwards them onward).
- Jungck already teaches "modifying the packet" and "forwarding the packet to an external device for subsequent processing" among its transformation actions — so redirection to an external device is squarely within its disclosure.
- RFC 2003 is the standard, well-known mechanism for IP-in-IP encapsulation: wrapping a packet in an outer IP header addressed to an intermediate/alternate destination. It supplies the routine implementation detail for how Jungck's "modify/forward to external device" action achieves routing to a network address different from the packet's destination.
- Motivation: A POSITA implementing a monitoring/tap function (e.g., lawful-intercept-style copying before onward delivery) would naturally use the IETF-standard encapsulation technique (RFC 2003) as the obvious means of redirecting a copy to the monitoring address while preserving the original packet for delivery. The combination is the simple addition of a standard protocol mechanism to an already-obvious Jungck+Bhatia system — the PTAB found this combination obvious, and the CAFC affirmed.
5. Tertiary combination: Jungck + Bhatia + Turner (US 7,254,114) (claims 6, 13, 20)
Ground 3 — claims 6, 13, 20 — obvious over Jungck, Bhatia, and Turner (US Patent 7,254,114; Ex. 1081).
The FWD and exhibit list confirm Turner was relied on to supply the additional limitation(s) of these specific dependent claims (which per the specification group concern enqueueing/prioritized forwarding — e.g., placing packets associated with different address sets into different forwarding queues with different service rates). I could not verify Turner's specific teachings from the materials retrieved in this session, so I flag that as a gap in my direct knowledge; however, the record is unambiguous that the PTAB found the Jungck+Bhatia+Turner combination rendered claims 6, 13, and 20 unpatentable by a preponderance of the evidence, and the CAFC's Rule 36 affirmance upheld that finding. The combination rationale follows the same structure as Ground 1: Jungck supplies the packet-transformation platform, Bhatia supplies the phased address-set methodology, and Turner supplies the differentiated queuing/scheduling detail for the dependent limitation.
6. Level of ordinary skill (Graham factor)
The parties' experts (Madisetti for Petitioner; Goodrich for Patent Owner) agreed on substantially the same POSITA definition, which the Board effectively applied: a person with a bachelor's degree in computer science (or related field) plus either two or more years of industry experience and/or an advanced degree in the field, as of the October 22, 2012 priority date (Goodrich Decl., Ex. 2017, ¶ 30). Under that standard, the Jungck/Bhatia/RFC2003/Turner documents are all in the same art of network-security packet filtering, and the combination requires no more than ordinary skill.
7. Secondary considerations
The record does not indicate that Patent Owner established any secondary consideration (commercial success, long-felt need, unexpected results, copying, etc.) sufficient to overcome the prima facie obviousness showing. The Board's unpatentability determination on the merits, and the CAFC's affirmance, confirm that no objective indicia outweighed the strong prima facie case. (Note also that prior IPRs had already cancelled the claims of the parent patents US 9,137,205 and US 9,560,077, further undercutting any argument that the family's phased-restoration subject matter was a pioneering, non-obvious advance.)
8. Conclusion
The claims of US 10,091,246 B2 are unpatentable for obviousness under pre-AIA § 103(a), as finally determined in IPR2021-01152 and affirmed by the Federal Circuit in Appeal No. 23-1528:
| Ground | References | Claims | Outcome |
|---|---|---|---|
| 1 | Jungck (US 2009/0262741 A1) + Bhatia (US 2007/0118894 A1) | 1–3, 5–10, 12–17, 19, 20 | Unpatentable |
| 2 | Jungck + Bhatia + RFC 2003 | 4, 11, 18 | Unpatentable |
| 3 | Jungck + Bhatia + Turner (US 7,254,114) | 6, 13, 20 | Unpatentable |
Motivation in one sentence: A POSITA would combine Jungck's dynamically-reconfigurable, high-resolution packet-filtering gateway (which already teaches forwarding, dropping, modifying, and redirecting packets per rules) with Bhatia's time-phased, progressively-expanding whitelist methodology for post-DoS restoration (dynamically created rules, progressively larger allowed-address sets, rules discontinued after predetermined periods), because doing so yields the claimed phased restoration using only known components and predictable results — and would add RFC 2003 or Turner as standard implementation details for the respective dependent limitations.
Caveats: (a) I could not confirm Turner's specific disclosure from this session's retrievals; (b) the exact dates/verbatim reasoning of the CAFC Rule 36 affirmance in 23-1528 rest on secondary reporting (PACER-derived summaries), not a directly retrieved opinion; and (c) the Google Patents "Active" status label does not reflect the final unpatentability outcome — the claims have been determined unpatentable and the appellate path is exhausted.
Generated 8/31/2026, 12:48:06 AM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Centripetal Networks, Inc.
- US 10193917Patent Analysis: US 10193917 B2 Date of Analysis: April 26, 2026 Here is a concise summary of United States Patent 10,193,917, including details from the patent document and recent legal proceedings. --- Patent Details Title: Rule-based…
- US 9917856Here is a concise summary of US Patent 9917856: US Patent 9917856 Title: Rule-based network-threat detection for encrypted communications Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Sean Moore, Douglas M. DiSabello Filing…
- US 10511572US Patent 10511572 (US10511572) is titled "Rule swapping in a packet network." The patent is currently assigned to Centripetal Networks LLC. The inventors are David K. Ahn, Steven Rogers, and Sean Moore. The application was filed on July…
- US 9686193Here is a concise summary of US patent 9686193: US Patent 9686193: Filtering Network Data Transfers Title: Filtering network data transfers Current Assignee: Centripetal Networks LLC Inventor: Sean Moore Filing Date: February 18, 2015 (for…
- US 9203806US Patent 9203806: Rule Swapping in a Packet Network Title: Rule swapping in a packet network Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Steven Rogers, Sean Moore Filing Date: January 11, 2013 Issue Date: December 1, 2015…
- US 9560176Here is a concise summary of US patent 9560176: US Patent 9560176B2 Title: Correlating packets in communications networks Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert…
- US 10284526Verification Note I searched the USPTO/Google Patents records and the Federal Circuit's 2026 dockets for patent number 10284526 (interpreted literally; no similar numbers substituted). I located the authoritative Federal Circuit…
- US 9264370I have the bibliographic data confirmed. The provided patent text doesn't include the claims section, so let me retrieve the actual claim language. Let me retrieve the exact claims text of US9264370 from additional sources. Summary of U.S…
Other patents in Software Technology & Computing Systems (T)
- US 6665293I'll search for authoritative information on US Patent 6,665,293 and any CAFC 2026 docket references. Both searches returned no results. Let me try broader queries to locate authoritative sources. I have confirmation from Google Patents…
- US 6424624I searched the USPTO/patent databases and CAFC docket sources for the specific patent number 6424624 (i.e., US 6,424,624 B1 / US6424624B1). Here is the summary, with notes on confidence. Verification note - Searches for "6424624" confirmed…
- US 10491646Summary of U.S. Patent No. 10,491,646 (US10491646B2) I searched for the specific patent number 10491646 (front-page form: US 10,491,646 B2) and did not rely on similar numbers (e.g., 8,166,892, IPR2025-01046/01047, etc., which appeared in…
- US 9338140US Patent 9,338,140 B2 — Summary Bibliographic data (verified against USPTO-adjacent sources and the issued patent PDF) | Field | Data | |---|---| | Patent number | US 9,338,140 B2 (application no. 13/468,383) | | Title | Secure data…
- US 9129376US Patent 9,129,376 B2 — Summary Searches performed I searched for the exact identifier 9129376 (and US9129376B2 / 9,129,376) in patent databases and litigation/CAFC sources, and searched the CAFC 2026 docket for this patent number. My…
- US 8825454US Patent 8,825,454 — Summary Note on sources: Bibliographic data below is corroborated by Google Patents (patents.google.com/patent/US8825454) and FreePatentsOnline. The full specification was supplied in your prompt; however, the claims…
- US 8818770I have confirmation of the key bibliographic data and relevant dockets. Let me retrieve the independent claims' full text to describe them accurately. US Patent 8,818,770 B2 — Summary Bibliographic data (verified against USPTO/Google…
- US 8170840The CAFC 2026 hits so far involve different EagleView patents (8,670,961 and 8,078,436) — not 8,170,840. Let me verify whether 8,170,840 itself appears in any 2026 CAFC activity and pull the actual claim set. I need the actual claim text…
This patent in court (4)
4 tracked lawsuits name US 10091246.