Invalidity dossier

US 10284526

Efficient SSL/TLS proxy

Current assignee: Centripetal Networks, LLC

Added 8/29/2026, 12:00:25 PM

At a glanceNo PTAB challenges3 lawsuits on fileasserted by Centripetal Networks, LLCSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Verification Note

I searched the USPTO/Google Patents records and the Federal Circuit's 2026 dockets for patent number 10284526 (interpreted literally; no similar numbers substituted). I located the authoritative Federal Circuit disposition for this exact patent: Centripetal Networks, LLC v. Keysight Technologies, Inc., No. 24-2246 (Fed. Cir., decided April 2, 2026, nonprecedential), which is the appeal of PTAB IPR2022-01525. I did not obtain the full verbatim text of all 20 claims from the patent itself, so the claim overviews below rely on the claim language as quoted in the PTAB Final Written Decision and the CAFC opinion; where I rely on that secondary sourcing, I flag it.


Bibliographic Summary — US Patent 10,284,526 B2

Field Data
Title Efficient SSL/TLS proxy
Patent Number US 10,284,526 B2 (the "'526 patent")
Inventor Sean Moore
Original Assignee Centripetal Networks, Inc. (name later changed to Centripetal Networks, LLC per 2023 assignment record)
Application / Filing Date US 16/039,896, filed July 19, 2018
Priority Date July 24, 2017 (Provisional Application 62/536,254)
Issue (Grant) Date May 7, 2019
Claim Count 20 claims (claims 1–20); independent claims are claims 1 and 11 (per PTAB/CAFC)
Current Status Listed "Active" on Google Patents, but all claims 1–20 were found unpatentable in IPR2022-01525, and the CAFC affirmed that decision on April 2, 2026

Abstract (as issued)

"Systems, devices, and methods are disclosed for selectively decrypting SSL/TLS communications. Contents of the decrypted communications that may result in some action; for example, to terminate the communications, or to log and store the plaintext packets of the communications for subsequent content inspection and analysis. A SSL/TLS proxy may examine the information contained in the TLS handshake protocol and/or examine other information associated with the connection. Based on the examination, a proxy may determine whether or not to decrypt the encrypted communications. The proxy may take additional actions based on content inspection."


Plain-Language Overview of the Independent Claims

Claim 1 (method): A computing device (e.g., an SSL/TLS proxy) receives one or more packets that initiate at least one encrypted communication flow (e.g., a TLS/HTTPS session handshake). It identifies "flow identification data" associated with those initiating packets (e.g., SNI/domain-name data, IP addresses, or flow tuples) and compares that data against a list of identification data (e.g., a "decrypt-list" of domain names, FQDNs, URIs, or IP addresses). If a match is found, the device:

  1. decrypts each packet of the encrypted communication flow associated with the match, and
  2. performs a corresponding action on each such packet (per the PTAB/CAFC construction upheld in 2026, this "corresponding action" includes any action — even merely allowing the packet to proceed, i.e., it need not be blocking, logging, or transforming), and then
  3. re-encrypts each packet after performing that action, and transmits each packet to its intended destination.

In short: selectively decrypt only the flows that match a policy list, act on the plaintext, then re-encrypt and forward — rather than decrypting all TLS traffic passing through the proxy.

Claim 11 (system / computer-readable-media counterpart): The PTAB and CAFC treat claim 11 as the independent apparatus/media claim carrying the same core limitations as claim 1 — receiving packets initiating an encrypted flow, identifying flow data, comparing against a list of identification data, and, on a match, decrypting each packet, performing a corresponding action, re-encrypting, and transmitting to the intended destination. (The dependent claims, e.g., claims 2 and 12, add features such as the device creating the list based on network addresses and domain names received from a security application.)

Caveat on claim text: I was not able to retrieve the complete, verbatim text of claims 1 and 11 from the patent PDF in this session. The phrasing above is reconstructed from the limitation-by-limitation quotes in the PTAB Final Written Decision (IPR2022-01525) and the CAFC opinion, which quote limitations 1[e] ("comparing the identified flow data with the list of the identification data"), 1[f] ("decrypting … and performing a corresponding action …"), and 1[g] ("re-encrypting, after performing the corresponding action, each packet … and transmitting each packet … to its intended destination"). I have high confidence in the substance but recommend verifying exact claim wording against the USPTO full-text if precise claim language is needed.


Litigation / CAFC 2026 Status (for this exact patent)

  • PTAB IPR2022-01525 (Keysight Techs., Inc. v. Centripetal Networks, LLC): Final Written Decision dated April 15, 2024, finding claims 1–20 unpatentable as anticipated or obvious. Claim 1 was held anticipated by the Cisco IronPort AsyncOS 7.1 for Web User Guide ("IPUG") and by U.S. Patent App. 2012/0290829 ("Altman"), and obvious over IPUG and over Altman combined with U.S. Pat. App. 2015/0121449.
  • CAFC No. 24-2246 (the 2026 docket for this patent): Decided April 2, 2026 — the Federal Circuit (Lourie, Prost, and District Judge Burroughs) affirmed, holding that the Board correctly construed "corresponding action" to include merely allowing a packet to proceed, and that substantial evidence supported the finding that IPUG was a publicly accessible printed publication that anticipates claim 1. The court did not reach the alternative obviousness grounds (moot). Opinion is nonprecedential.
  • Related district-court cases (per patent-family records): Virginia Eastern District Court cases 2:22-cv-00002 and 1:22-cv-00001, and ITC Investigation 337-TA-1314, with a related CAFC matter listed under the family as No. 24-1416. Note: the separate April 23, 2026 ITC appeal (referenced in coverage as involving the '917 and '370 patents) appears to concern different Centripetal patents; I could not confirm from this session's results whether the '526 patent was also implicated in that ITC appeal, so treat that point as unverified.

Uncertainty Notes

  1. Exact claim language — not fully verified against the issued patent text; reconstructed from PTAB/CAFC quotations (high confidence in substance, lower confidence in verbatim wording).
  2. CAFC docket 24-1416 / ITC 337-TA-1314 scope — the '526 patent appears in the litigation family for these matters, but I could not confirm from the search results exactly which patents were asserted in that ITC appeal; do not assume the '526 patent's claims were at issue there.
  3. Legal status — although the patent record shows "Active," the binding 2026 CAFC affirmance upholds invalidation of all claims in IPR, which is the controlling current status for claims 1–20; the "Active" flag reflects the USPTO register rather than post-IPR enforceability.

Generated 8/29/2026, 6:48:37 PM

Cases on file (3)

Group view →

Specific litigation cases in our database that name US patent 10284526. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research litigation involving US Patent 10284526 across multiple sources.

I have good initial results. Let me dig deeper into the specific district court cases, ITC investigation, and CAFC appeals involving this patent.

Let me verify the other cases listed on the patent's litigation record — the second Virginia case (1:22-cv-00001) and the CAFC appeal 24-1416.

Based on my research, here is the known litigation involving US Patent 10,284,526 B2 ("Efficient SSL/TLS proxy," owned by Centripetal Networks). Note: I could not complete verification of every docket due to search limits, so where I am not confident of current status I say so explicitly.


1. IPR2022-01525 — Keysight Technologies, Inc. v. Centripetal Networks, Inc. (PTAB)

  • Petitioner: Keysight Technologies, Inc.
  • Patent Owner/Respondent: Centripetal Networks, Inc. (now Centripetal Networks, LLC)
  • Jurisdiction: USPTO Patent Trial and Appeal Board (PTAB)
  • Case No.: IPR2022-01525
  • Filed: September 12, 2022
  • Instituted: April 17, 2023 (all claims 1–20 challenged; institution granted)
  • Final Written Decision: April 15, 2024 — all claims 1–20 of the '526 patent held unpatentable as anticipated and/or obvious (four alternative grounds: anticipation by the Cisco IronPort AsyncOS 7.1 for Web User Guide ("IPUG"); anticipation by U.S. Pub. App. 2012/0290829 ("Altman"); obviousness over IPUG; obviousness over Altman + U.S. Pub. App. 2015/0121449).
  • Status: Final Written Decision appealed by Centripetal (Notice of Appeal filed August 20, 2024; Director Review denied June 21, 2024). Appeal docketed at the Federal Circuit as No. 24-2246 (below).

2. Centripetal Networks, LLC v. Keysight Technologies, Inc., No. 24-2246 (Fed. Cir.)

  • Appellant: Centripetal Networks, LLC
  • Appellee: Keysight Technologies, Inc.
  • Jurisdiction: U.S. Court of Appeals for the Federal Circuit
  • Case No.: 2024-2246
  • Filing date: Appeal from IPR2022-01525 (Centripetal's notice of appeal was filed August 20, 2024)
  • Outcome: Decided April 2, 2026 (non-precedential) — AFFIRMED. The court upheld the Board's construction of "corresponding action" and its finding that IPUG was a publicly accessible printed publication anticipating claim 1; the remaining grounds were moot. This affirmance upholds the invalidation of all claims 1–20 of the '526 patent.

3. Centripetal Networks, Inc. v. Keysight Technologies, Inc., 1:22-cv-00001 → 2:22-cv-00002 (E.D. Va.)

  • Plaintiff: Centripetal Networks, Inc.
  • Defendant: Keysight Technologies, Inc.
  • Jurisdiction: U.S. District Court for the Eastern District of Virginia (filed in Alexandria Division as 1:22-cv-00001; transferred intradistrict to the Norfolk Division on January 4, 2022, and re-docketed as 2:22-cv-00002)
  • Case Nos.: 1:22-cv-00001 / 2:22-cv-00002 (same case; both numbers appear on the patent's litigation record)
  • Filed: January 1, 2022
  • Judges: Arenda L. Wright Allen (district judge); Douglas E. Miller (magistrate)
  • Patents asserted: Included the '526 patent (along with U.S. Patent Nos. 9,264,370, 10,193,917, and 9,565,213)
  • Status: The case was stayed pending the parallel ITC investigation (Inv. No. 337-TA-1314). As of the last records I could verify (a September 8, 2023 joint status notice), the case remained stayed while the ITC and PTAB proceedings ran. I could not verify a later final disposition (e.g., dismissal or judgment) from the records retrieved; the ITC's no-violation/invalidity findings on the '526 patent would be highly relevant to its outcome.

4. Inv. No. 337-TA-1314 — In the Matter of Certain Computer Network Security Equipment and Systems, Related Software, Components Thereof, and Products Containing Same (ITC)

  • Complainant: Centripetal Networks, LLC
  • Respondents: Keysight Technologies, Inc. (primary respondent)
  • Jurisdiction: U.S. International Trade Commission (Administrative Law Judge MaryJoan McNamara)
  • Case No.: 337-TA-1314
  • Complaint filed: April 19, 2022; Notice of Investigation published at 87 Fed. Reg. 31581 (May 24, 2022); trial held March 1–7, 2023
  • Asserted '526 claims: Claims 1, 3, 11, 13, and 16
  • Initial Determination (August 8, 2023): No Section 337 violation. The ALJ found, among other things, that Keysight did not infringe the asserted '526 claims and that the asserted '526 claims were invalid; Centripetal's domestic industry product satisfied the technical prong for the '526 patent, but that did not salvage the case.
  • Status: Centripetal petitioned for Commission review of the ID (including as to the '526 patent); per the later Federal Circuit decision, Centripetal ultimately did not appeal the Commission's '526 invalidity/non-infringement findings. The Commission's final determination adopted the no-violation findings.

5. Centripetal Networks, LLC v. International Trade Commission (with Keysight Technologies, Inc. as Intervenor), No. 24-1416 (Fed. Cir.)

  • Appellant: Centripetal Networks, LLC
  • Appellee: International Trade Commission; Intervenor: Keysight Technologies, Inc.
  • Jurisdiction: U.S. Court of Appeals for the Federal Circuit
  • Case No.: 2024-1416 (listed on the '526 patent's litigation record as an appeal from the ITC)
  • Status/Outcome: This is the appeal of the ITC investigation above. Critically, the Federal Circuit noted in the companion ITC appeal that Centripetal did not appeal the Commission's finding that the '526 patent is invalid and not infringed (Appellant Br. at 17 n.1). The CAFC's April 2026 decision in the related ITC appeal therefore addressed the other asserted patents (the '917 and '370 patents) rather than the '526 patent. I was unable to retrieve the specific 24-1416 decision text before hitting search limits, but based on the record, the '526 patent's ITC findings were not challenged on appeal.

Summary of Current Status

  • The '526 patent has been held invalid in two parallel proceedings: (a) the PTAB's Final Written Decision in IPR2022-01525 (claims 1–20 unpatentable), which the Federal Circuit affirmed on April 2, 2026 in No. 24-2246; and (b) the ITC's Initial Determination in 337-TA-1314 (no infringement; asserted claims invalid), which Centripetal did not appeal as to the '526 patent.
  • The only district court case asserting the '526 patent (E.D. Va. 2:22-cv-00002, formerly 1:22-cv-00001) was stayed pending the ITC; I could not confirm its final disposition.
  • All litigation involving the '526 patent is between Centripetal (plaintiff/patent owner) and Keysight Technologies (defendant/petitioner) — I found no litigation involving this specific patent against any other party (e.g., the older Cisco and Palo Alto Networks cases in the E.D. Va. predate or do not assert the '526 patent).

Caveat: I was unable to fully verify the post-September-2023 docket status of the stayed E.D. Va. case (2:22-cv-00002) or pull the specific 24-1416 opinion within my search limits. If you need those, the best sources are PACER (E.D. Va.) and the CAFC opinions page (cafc.uscourts.gov), plus the Unified Patents litigation portal.

Generated 8/29/2026, 6:48:44 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Centripetal Networks, LLC

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

There is one AIA trial proceeding on file for US 10,284,526 — IPR2022-01525 (Keysight Technologies v. Centripetal) — which went to a Final Written Decision holding all twenty claims (1–20) unpatentable, was affirmed by the Federal Circuit on 2026-04-02, and is therefore best characterized as claims invalidated (fully); there are no active proceedings, no settlements, and no institution denials. The bottom line for a defendant: the '526 patent is dead — every claim (1–20) has been canceled, so any demand letter or complaint citing US 10,284,526 is built on claims that no longer exist. Note a data discrepancy up front: the USPTO ODP block in this prompt says "no AIA trial proceedings" as of the most recent ingest, but web-verified sources — including the Google Patents metadata on the patent itself, which lists "PTAB case IPR2022-01525 filed (Final Written Decision)" — confirm this proceeding exists. The ODP ingest is stale; treat IPR2022-01525 as canonical.


IPR2022-01525 — Keysight Technologies, Inc. v. Centripetal Networks, LLC

  • Type: Inter Partes Review
  • Filed: 2022-09-12
  • Status: "Final Written Decision - Appealed" (per PTAB docket aggregators) — plain-English gloss: FWD issued 2024-04-15 holding all claims unpatentable; patent owner's Director Review request was denied 2024-06-21; patent owner appealed to the Federal Circuit, which affirmed on 2026-04-02. The proceeding is fully concluded with the claims canceled.
  • Judge panel: Final Written Decision panel — Minn Chung (author), Kevin F. Turner, Brian J. McNamara (per Patexia). Steven Amundson was on the panel earlier in the case; a Panel Change Order was entered 2023-08-14.
  • Petition grounds (challenged claims 1–20, i.e., all claims):
    1. Anticipated under § 102 by the Cisco IronPort AsyncOS 7.1 for Web User Guide ("IPUG") — a printed publication;
    2. Anticipated under § 102 by U.S. Patent Application Pub. 2012/0290829 ("Altman");
    3. Obvious under § 103 over IPUG;
    4. Obvious under § 103 over Altman in view of U.S. Patent Application Pub. 2015/0121449 ("CP").
  • Institution decision: Granted — 2023-04-17. The Board instituted review of all challenged claims (the CAFC later confirmed Keysight "challeng[ed] all claims of the '526 patent, which the Board granted"). Institution followed the Patent Owner Preliminary Response (2023-01-20); key case events thereafter: PO Response 2023-07-10, Petitioner Reply 2023-11-03, PO Sur-Reply 2023-12-07, oral hearing transcript 2024-02-07.
  • Final Written Decision (issued 2024-04-15, titled "Final Written Decision Determining All Challenged Claims Unpatentable 35 U.S.C. § 318(a)"): All challenged claims 1–20 were held unpatentable. The Board found claim 1 — treated as representative — unpatentable on all four grounds: anticipated by IPUG, anticipated by Altman, obvious over IPUG, and obvious over Altman + CP. The remaining claims fell with claim 1. The key construction was that "corresponding action" "includes any action, including the action of allowing a further transmission of a packet, without any further action" — a construction the CAFC later endorsed. No claims were held patentable.
  • Settlement / termination: None. The case was decided on the merits; there was no settlement (terms, if any ever existed, are not public — but nothing in the docket indicates a settlement).
  • Appeal: Yes. Centripetal filed a Notice of Appeal 2024-08-20 → Federal Circuit No. 24-2246, Centripetal Networks, LLC v. Keysight Technologies, Inc., decided 2026-04-02 (nonprecedential; panel of Lourie, Prost, and District Judge Burroughs sitting by designation). Issues: (1) the Board's construction of "corresponding action" in claim 1, and (2) whether IPUG qualified as a "printed publication" under § 102. The court affirmed on the IPUG-anticipation ground, finding no error in claim construction ("Allowing a packet is the opposite of blocking it and would naturally be considered an action") and substantial evidence of public accessibility of IPUG before the priority date; the other three grounds were moot. See CAFC opinion PDF and CourtListener.
  • Defensive value: Maximum possible. The FWD found all 20 claims unpatentable, Director Review was denied, and the Federal Circuit affirmed. Claims 1–20 of the '526 patent are canceled; any infringement theory built on this patent is not merely weak — it is sanction-bait. Sources: Unified Patents PTAB portal, Patexia summary, IPVerse/GreyB docket.

Strategic summary

Claim status — CANCELED vs. SUSTAINED vs. UNTESTED. This is the cleanest possible outcome for a defendant: all 20 claims of US 10,284,526 (claims 1–20) are CANCELED. There are no sustained claims and no untested claims. The patent has effectively been emptied; the USPTO will have issued a certificate of cancellation following the affirmed FWD. As context, the same family has been litigated heavily — Centripetal asserted the '526 patent (claims 1–3, 6, 11–13, 16) in ITC Investigation 337-TA-1314 against Keysight, where the Final Initial Determination (2023-08-08) found those claims not infringed and invalid as anticipated under § 102, and the Commission terminated that investigation with no violation (2023-12); the Federal Circuit's related appeal (No. 24-1416, decided 2026-04-23) affirmed the ITC as to the companion '370/'917 patents. So the '526 patent has now been invalidated or found non-infringed on every front where it has been tested — PTAB (all claims), ITC (asserted claims), and CAFC (both).

Estoppel landscape. Because the claims are canceled, § 315(e)(2) estoppel is largely academic on the merits — there is nothing left to assert. If a defendant is facing assertion of a continuation (e.g., US 11,233,777 or US 12,034,710, filed from this family), note that Keysight (and its privies) is barred by § 315(e)(2) from re-litigating grounds raised or reasonably available in IPR2022-01525 — which include IPUG and Altman, the very references that felled the parent. A new defendant not in privity with Keysight faces no such bar and can freely deploy IPUG, Altman, and CP, plus any other § 102/§ 103 art, against any family member. Given that Cisco's IPUG user guide and Altman both anticipate the parent's claim 1, those references are obvious first-line ammunition against the continuations.

Pattern signals. The petitioner is Keysight Technologies — the same company that was the respondent in Centripetal's ITC complaint (337-TA-1314) and the defendant in parallel district-court litigation in the Eastern District of Virginia — i.e., this IPR was a counterattack by a litigation defendant, not a defensive-aggregator strike. Centripetal litigated aggressively (Director Review request, then a full CAFC appeal) and lost at every stage. There is no Unified Patents involvement in this proceeding (Unified Patents merely hosts the public docket portal). No second IPR on this patent exists — none was needed, because the first one wiped out 100% of the claims.

Recommended next steps

  • *If you are a defendant receiving a demand letter citing US 10,284,526: respond in writing that all claims (1–20) were canceled following IPR2022-01525, quote the FWD's disposition ("Final Written Decision Determining All Challenged Claims Unpatentable"), and cite the Federal Circuit's affirmance in Centripetal Networks, LLC v. Keysight Technologies, Inc., No. 24-2246 (Fed. Cir. Apr. 2, 2026)* ("we affirm the Board's decision"). Link to the CAFC opinion and the CourtListener record. If suit is filed anyway, move to dismiss or for judgment on the pleadings — the claims are gone as a matter of law, and continued assertion risks Rule 11 exposure.
  • No active PTAB proceeding is pending, so there are no upcoming PTAB milestones (institution deadlines, oral hearings, or FWD due dates) to track. If Centripetal pivots to a continuation patent (11,233,777 / 12,034,710 / others in the family), consider a prompt IPR or ex parte reexamination using IPUG and Altman — the references are proven, and the claim language in the continuations is presumed to be closely related.
  • Watch the ODP gap: the USPTO Open Data Portal's "no proceedings" entry for this patent is outdated; if you rely on ODP for diligence, note that IPR2022-01525 exists and is fully resolved. The absence of any other IPR is not a weakness signal here — it simply reflects that one IPR finished the job.

Generated 8/29/2026, 6:49:07 PM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2018-09-19 · Assignment

    Sean MooreCentripetal Networks, Inc.

  2. ? · recorded 2023-01-17 · Change of Name

    Centripetal Networks, Inc.Centripetal Networks, Inc.

    change of name only

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll reconstruct the assignment chain for US 10284526, cross-referencing the USPTO assignment records, the Google Patents legal events already visible in the specification, and public litigation/NPE databases.

Good initial results. The European family register shows a later transfer to "Centripetal Limited" (Ireland), and a 2022 Virginia suit against Keysight asserts this patent. Now let me dig for the specific USPTO reel/frame records and the litigation context.

I've reconstructed what's available. I was not able to pull the raw USPTO reel/frame numbers for this patent in my search session (the Assignment Center and Google Patents pages didn't surface them to me), so I will present the two recorded transactions that are documented on the Google Patents legal-events feed for this patent (which is populated from USPTO assignment records), flag what is confirmed versus unverified, and avoid fabricating reel/frame identifiers.


Inventors

  • Sean Moore — sole named inventor. Employer at filing: Centripetal Networks (he is the company's founder/CTO). Inventor address at filing: Hollis, New Hampshire (per the Concord Monitor patent-assignment listing and the issued patent's face). No unusual inventor-departure pattern: the sole inventor is the founder of the original assignee and remains with the company (he is the named inventor on the continuation, US 11,233,777, and the 2024 continuation US 2025/0141854 A1, both assigned to Centripetal Networks).

Original assignee

  • Centripetal Networks, Inc. (originally organized as Centripetal Networks LLC at filing; formally assigned to the Inc. entity on 2018-09-19). Current assignee per Google Patents: Centripetal Networks, LLC (after a recorded 2023-01-17 change of name from Inc.).
  • Product status: Operating company. Centripetal designs and sells network-security appliances/software (e.g., CleanINTERNET, RuleGate, ThreatAvert) and its security gateways perform the SSL/TLS selective-decryption claimed here. It is not a paper company.
  • Line of business: Cybersecurity / network security (threat-intelligence-driven packet filtering and encrypted-traffic inspection).
  • Current status: Operating (private company). Highly litigious: won a $2.75B jury verdict against Cisco in the E.D. Va. (later vacated/remanded; settled), and filed the 2022 Keysight district court and ITC actions. The European family member (EP 4 084 402) shows the family proprietor as Centripetal Limited (Galway, Ireland) as of 2024-02-28 — evidence of an international corporate restructuring of the family, though no corresponding US-recorded transfer to an Irish entity is visible in the US legal events for this patent.

Assignment timeline

Per the Google Patents legal-events feed for US 10284526 (populated from USPTO assignment records). Reel/frame identifiers were not retrievable in this session; the entries below reflect the recorded transactions as published on the patent's legal-event page.

  • 2018-07-19 — Application filed by Centripetal Networks LLC (original applicant; not yet a recorded "assignment" per se).
  • 2018-09-19 (recorded) — Conveyance: Assignment of Assignor's Interest
    • Assignor: Sean Moore
    • Assignee: Centripetal Networks, Inc.
    • Correspondent: not shown in the legal-event feed (reel/frame not retrievable here). Prosecution attorney of record on the patent face is Banner & Witcoff, Ltd. — a mainstream patent prosecution firm, not an NPE-concentration firm.
    • Context: Standard inventor-to-employer assignment following filing; not a transfer to a licensing shell.
  • 2023-01-17 (recorded) — Conveyance: Change of Name
    • Assignor: Centripetal Networks, Inc.
    • Assignee: Centripetal Networks, LLC
    • Correspondent: not shown in the legal-event feed.
    • Context: Corporate-name/entity-formality change only (Inc. → LLC), matching the 2023 "CHANGE OF NAME" reassignment shown on Google Patents; no change in beneficial ownership.

No other recorded assignments (no transfers to IP-holding LLCs, no security agreements, no licenses, no releases) appear in the legal events for this patent. The chain is: Moore → Centripetal Networks, Inc. → Centripetal Networks, LLC (name change only).

Timeline diagram

timeline
    title Ownership of US 10284526
    2017 : Provisional filed
    2018 : Filed by Centripetal Networks LLC
         : Assigned to Centripetal Networks Inc
    2019 : Patent issued
    2022 : First suit filed vs Keysight
    2023 : Change of name to Centripetal Networks LLC
    2024 : IPR final written decision invalidates claims
    2026 : Federal Circuit affirms invalidity

NPE / troll-pattern signals

  1. Shell-entity transferNot present. The only post-filing assignees are "Centripetal Networks, Inc." and (by change of name) "Centripetal Networks, LLC" — the operating company itself. No "IP Holdings / Licensing / Ventures" entity, no registered-agent mailbox, no single-purpose LLC appears in the chain (2018-09-19 assignment; 2023-01-17 name change).

  2. Known asserter in the chainNot present. No Acacia, Marathon, Intellectual Ventures, Conversant, Vringo, or other listed NPE appears in the chain. Centripetal Networks is an operating security vendor; Unified Patents' portal lists it as assignee but not as a high-frequency NPE plaintiff.

  3. Repeat correspondent across the chainUnclear. Reel/frame correspondent data was not retrievable in this session, and only two routine transactions exist (inventor assignment + name change), so no recurrence pattern can be established. The prosecution attorney of record (Banner & Witcoff, Ltd.) is a general IP firm; litigation counsel (Herbert Smith Freehills for Centripetal; Reed Smith for Keysight) are operating-company litigators, not NPE-firm repeat players.

  4. Cascading transfersNot present. Only two recorded events, over four years apart, with no chained LLCs.

  5. Pre-litigation transferNot present. The inventor assignment (2018-09-19) predates the first infringement suits naming this patent (E.D. Va. 1:22-cv-00001 and 2:22-cv-00002, filed 2022-01-01; ITC 337-TA-1314) by more than three years. The 2023 name change postdates the suits and is a formality.

  6. Bankruptcy fire-saleNot present. Centripetal is an operating, privately held company; no Chapter 7/11 and no court-supervised patent sale.

  7. PrivateeringNot present / unclear. No SEC filings or press coverage indicate Centripetal is asserting on behalf of another operating company; it asserts its own patents in its own name.

  8. Defensive aggregator (anti-NPE)Not present. The chain terminates at Centripetal Networks, LLC, an operating company — not RPX, AST, LOT, Unified, or OIN. (Note: the '526 patent has been neutralized in the sense that IPR2022-01525 held all claims 1–20 unpatentable, affirmed by the Federal Circuit on 2026-04-02 — but that is validity status, not defensive aggregation.)

Verdict

Operating-company assertion.

Centripetal Networks is a product company that ships security gateways implementing the selective SSL/TLS decryption claimed in this patent, and the only two recorded chain events are an ordinary inventor-to-employer assignment (2018-09-19) and a later name change (2023-01-17) — the classic signature of an operating company owning its own patents, not an NPE acquisition chain. The assertion posture (E.D. Va. cases 1:22-cv-00001 and 2:22-cv-00002 against Keysight, plus ITC 337-TA-1314, filed in January 2022) is Centripetal enforcing its own portfolio against a vendor of network-test equipment; while Keysight is not a head-to-head firewall competitor, the assignee plainly ships products embodying the claims, so the assertion is by an operating company rather than a shell. Caveat: the patent's claims were invalidated in IPR2022-01525 (Final Written Decision 2024-04-15; affirmed Fed. Cir. 2026-04-02), and I could not verify reel/frame numbers or correspondent names from the USPTO Assignment Center in this session, so the correspondent-level NPE screen remains only partially tested.

Verification links:

Generated 8/29/2026, 6:49:35 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research the cited prior art for US 10284526. Let me search for the patent record and its citations.

I found the Unified Patents record listing some "Patent Art." Now let me get the formal "Patent Citations" section from the patent record itself, plus the IPR petition's prior art.

I have the IPR prior art. Now I need the formal "References Cited" (Patent Citations / Non-Patent Citations) listed on the face of the '526 patent. Let me pull that specific section.

I've reached my search limit for this session, so I'll consolidate the verified findings with clear confidence flags. Here is the prior-art analysis for US 10,284,526 B2 ("Efficient SSL/TLS proxy").


Scope note on "patent citations"

There are two distinct sets of prior art relevant to the '526 patent:

  1. The art actually applied to invalidate the claims — the four grounds in IPR2022-01525 (PTAB Final Written Decision, Apr. 15, 2024; affirmed by the Federal Circuit in Centripetal Networks, LLC v. Keysight Technologies, Inc., No. 24-2246, decided April 2, 2026). This is the most relevant prior art and the only art with a binding § 102/§ 103 determination.
  2. References cited during prosecution (front-page "References Cited"). I could not retrieve the complete, verbatim front-page citation list in this session — the Google Patents fetch of the patent text did not include the citations section, and the secondary source I found (Unified Patents) aggregates a broad "Patent Art (254)" set that mixes examiner citations with later patents citing the '526 patent. I flag the prosecution-citation entries below as candidate/partial, not fully verified.

The '526 patent's effective filing date is July 24, 2017 (priority to Provisional 62/536,254; non-provisional filed July 19, 2018), so AIA § 102(a)(1)/(a)(2) governs.


Part 1 — Most relevant prior art (IPR2022-01525; controlling as of April 2026)

1. Cisco IronPort AsyncOS 7.1 for Web User Guide ("IPUG") — non-patent printed publication

Field Data
Full citation Cisco Systems, Inc., Cisco IronPort AsyncOS 7.1 for Web User Guide (documentation for the Cisco IronPort Web Security Appliance / Web Proxy)
Date AsyncOS 7.1-era documentation; the Board found it publicly accessible before July 24, 2017 (the '526 priority date), based on a Wayback Machine–archived version timestamped before that date plus expert testimony that a POSITA would locate vendor technical documentation with reasonable diligence. The CAFC affirmed this finding as supported by substantial evidence.
Description Vendor user guide for Cisco's web security gateway. The Board found it discloses a proxy that selectively decrypts HTTPS/TLS traffic based on URL/domain policy or reputation data, performs an action on the decrypted packets (block, redirect, allow, log — with "allowing a packet to proceed" itself counting as an action under the Board's construction), then re-encrypts and forwards allowed traffic toward its intended destination.
§ 102 anticipation Board: anticipates claims 1–20 under § 102 (Ground 1). CAFC (Apr. 2, 2026): affirmed anticipation of claim 1 (representative); the other grounds were not reached as moot. Because claim 1 is representative and the Board's FWD held all challenged claims unpatentable on this ground, IPUG is the single most consequential § 102 reference.

2. U.S. Patent Application Publication 2012/0290829 A1 ("Altman")

Field Data
Full citation Altman, U.S. Patent Application Publication US 2012/0290829 A1
Date Published November 15, 2012 (before the July 24, 2017 effective filing date; AIA § 102(a)(1) prior art). Exact filing date not confirmed in this session.
Description Disclosed a network-security monitoring architecture involving two computing entities: an SIA that decrypts and re-encrypts in-transit encrypted traffic, and an NMC (network monitoring console) that receives copies of plaintext packets and applies actions to them. The Board found this combination discloses the claimed "decrypt → corresponding action → re-encrypt → transmit" flow. (I could not confirm the published title from the available records; inventor surname "Altman" per the PTAB/CAFC designation.)
§ 102 anticipation Board: anticipates claims 1–20 under § 102 (Ground 2). Not separately addressed on appeal because the CAFC affirmed on IPUG (moot).

3. U.S. Patent Application Publication 2015/0121449 A1 ("CP")

Field Data
Full citation US 2015/0121449 A1 (designated "CP" in the IPR — presumably the named inventors' initials; title not confirmed in this session)
Date Published April 30, 2015 (before the effective filing date).
Description Used only as the secondary reference in the obviousness ground (Ground 4: Altman in view of CP), to supply features the petitioner argued Altman lacked.
§ 102 anticipation No standalone § 102 anticipation was asserted or found. It is a § 103 combination reference only.

Verification note: The PTAB FWD (J.A. 1–66) held claims 1–20 unpatentable on all four grounds (IPUG anticipation; Altman anticipation; IPUG obviousness; Altman+CP obviousness). The CAFC opinion states: "The Board determined that claim 1, which is representative for purposes of this appeal, is unpatentable on four grounds: (1) anticipated by [IPUG], (2) anticipated by [Altman], (3) obvious over IPUG, and (4) obvious over Altman in combination with [CP]." The CAFC affirmed on Ground 1 and did not reach Grounds 2–4.


Part 2 — Candidate prosecution-history citations (front-page references; PARTIALLY VERIFIED)

The Unified Patents record for 10284526 lists a "Patent Art (254)" set. The visible portion includes the following — but I cannot confirm with high confidence which of these are examiner citations on the face of the issued patent versus later patents that merely cite the '526 patent (the count of 254 strongly suggests both directions are aggregated). None of these were asserted in the IPR. Presenting them as candidates:

Reference Pub./Priority Date Brief description
US 2015/0106930 A1 (Fujitsu) Priority Oct. 10, 2013 Log analysis device and method
US 2013/0059527 A1 Priority Mar. 9, 2010 Relay device
US 2004/0199629 A1 (IBM) Filed Mar. 31, 2003 Debugging utility based on a TCP tunnel
US 7,237,267 B2 (Cisco) Filed Oct. 15, 2003 Policy-based network security management
US 2007/0211644 A1 Filed Mar. 6, 2006 Graphical representation of packet flow through a network device
US 2008/0077705 A1 (CA Technologies) Filed Jul. 28, 2006 Traffic inspection and classification for session/content control
US 2016/0119365 A1 (Comsec Consulting) Filed Oct. 27, 2014 Cyber intelligence hub
US 2003/0142681 A1 (Ericsson/Toyota) Filed Jan. 30, 2002 Distributing/conditioning traffic for mobile networks
US 2004/0093513 A1 (HP/Trend Micro) Filed Nov. 6, 2002 Active network defense system and method
US 2006/0080733 A1 Filed Oct. 7, 2004 Offline analysis of packets
US 2014/0201123 A1 Filed Jan. 10, 2013 Rule swapping in a packet network
US 2015/0237012 A1 Filed Mar. 11, 2013 Filtering network data transfers
US 6,484,261 B1 Filed Feb. 16, 1998 Graphical network security policy management

Anticipation assessment for this group: Unknown from available records. None of these references was the basis of any § 102 holding in the IPR, and I found no evidence that the examiner relied on them to reject the claims. If a precise front-page list is needed, it must be pulled from the issued patent's "References Cited" page (USPTO Patent Center / Google Patents citations section), which was not fully retrievable in this session.


Bottom line

  • Most relevant § 102 prior art: the Cisco IronPort AsyncOS 7.1 for Web User Guide (IPUG) — found to anticipate claims 1–20 (Board), affirmed on claim 1 by the Federal Circuit on April 2, 2026 — and US 2012/0290829 A1 (Altman) — found to anticipate claims 1–20 (Board; not reached on appeal as moot).
  • US 2015/0121449 A1 (CP) is a § 103 combination reference only; it does not potentially anticipate any claim under § 102 per the IPR record.
  • The prosecution-history citations listed in Part 2 are candidate, partially verified entries; their § 102 relevance was never adjudicated.

Explicit uncertainty: (1) exact front-page "References Cited" list — not fully verified; (2) Altman's and CP's published titles — not confirmed; (3) whether any Part 2 entry appears on the patent's face — unconfirmed.

Generated 8/29/2026, 6:49:42 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis of US Patent 10,284,526 B2 Under 35 U.S.C. § 103

Scope note. This analysis draws on the Prior Art section developed earlier in this session and on targeted verification searches performed today (April 26, 2026). Key verified sources: the PTAB Final Written Decision in Keysight Techs., Inc. v. Centripetal Networks, LLC, IPR2022-01525 (Apr. 15, 2024) ("FWD"); the Federal Circuit's affirmance in Centripetal Networks, LLC v. Keysight Technologies, Inc., No. 24-2246 (Fed. Cir. Apr. 2, 2026) (nonprecedential) ("CAFC Op."); and the IPR petition/patent-owner papers. I have additionally confirmed that US 2015/0121449 A1 ("CP") is titled "Agent assisted malicious application blocking in a network environment."


I. Legal framework and the operative claim construction

Under § 103, a claim is unpatentable if the differences between it and the prior art are such that the claimed subject matter as a whole would have been obvious at the time of invention to a person having ordinary skill in the art (POSITA). Graham v. John Deere Co., 383 U.S. 1 (1966), requires evaluating (1) the scope and content of the prior art; (2) the differences between the prior art and the claims; (3) the level of ordinary skill in the art; and (4) secondary considerations. KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007), reinforces that the analysis is flexible: a POSITA is a person of ordinary creativity, not an automaton, and motivation to combine may come from common sense, design incentives, market pressure, and the "obvious to try" doctrine, rather than from an explicit teaching, suggestion, or motivation in the references themselves.

The single most consequential fact for this § 103 analysis is the Board's claim construction of "corresponding action," which the Federal Circuit expressly endorsed on April 2, 2026. The Board construed "performing a corresponding action on each of the one or more packets" to include any action — including merely allowing the packet to proceed without any further action. The CAFC agreed: "Allowing a packet is the opposite of blocking it and would naturally be considered an action." CAFC Op. at 2; see also IPWatchdog, "Federal Circuit Affirms PTAB Finding that Centripetal Patent Claims are Unpatentable as Anticipated" (Apr. 2, 2026). Under this construction, the "action" limitation of claims 1 and 11 is satisfied by the default forwarding behavior of any proxy that passes inspected traffic onward — a limitation that is nearly impossible to avoid and correspondingly easy to show obvious. Every combination below should be read against this construction.

The claims (as reconstructed from the FWD/CAFC quotations). Claim 1 (method) and claim 11 (apparatus/media counterpart) require, in substance: receiving packet(s) initiating an encrypted communication flow (e.g., a TLS handshake); identifying "flow identification data" associated with the initiating packets; comparing that data against a list of identification data (domain names, FQDNs, URIs, IP addresses); and, on a match, decrypting each packet of the flow, performing a corresponding action on each, re-encrypting after the action, and transmitting each packet to its intended destination. Dependent claims (e.g., claims 2 and 12) add features such as list creation from network addresses and domain names received from a security application.


II. Level of ordinary skill in the art

A POSITA for the '526 patent would be a person with a bachelor's or master's degree in computer science, computer engineering, or electrical engineering (or equivalent experience), with roughly 2–5 years of hands-on experience in computer networking and network security, including working knowledge of: TCP/IP, the TLS/SSL protocol and its handshake (including Server Name Indication), HTTP/HTTPS, proxy and man-in-the-middle architectures, packet filtering, and policy/threat-intelligence-driven traffic inspection. This is the profile the IPR record assumes, and nothing in the FWD or CAFC opinion suggests a narrower or more specialized POSITA.

Critically, the '526 patent's own Background section concedes that the problem the invention addresses was well known: SSL/TLS proxies are "computer-resource intensive"; there is "no way to stop the decrypt/re-encrypt process" once a session is intermediated; and "for some applications or policies, including cybersecurity and privacy protection, often only a relatively small percentage of the SSL/TLS-tunneled traffic needs to be decrypted." Those admissions frame the obviousness inquiry: the claimed invention is a policy-driven selective-decryption proxy, and the record shows that the relevant prior art already solved that problem.


III. Record-based § 103 combinations (found by the PTAB in IPR2022-01525)

The Board found claim 1 (representative) unpatentable on four grounds, two of which are § 103 grounds, and held all claims 1–20 unpatentable on each of the four grounds:

"The Board determined that claim 1, which is representative for purposes of this appeal, is unpatentable on four grounds: (1) anticipated by [IPUG], (2) anticipated by [Altman], (3) obvious over IPUG, and (4) obvious over Altman in combination with [CP]." — CAFC Op. at 3 (quoting FWD, J.A. 1–66)

The Federal Circuit affirmed on Ground 1 (anticipation by IPUG) and did not reach Grounds 2–4 as moot. The two § 103 grounds are therefore Board findings that were not independently reviewed on appeal, but they remain the best-documented obviousness analysis in the record for this patent.

Combination A — Obviousness over IPUG (Ground 3)

Element IPUG (Cisco IronPort AsyncOS 7.1 for Web User Guide)
What it is Vendor documentation for the Cisco IronPort Web Security Appliance, a commercial web proxy/security gateway; found publicly accessible before the July 24, 2017 priority date (Wayback-archived version plus expert testimony), a finding the CAFC affirmed as supported by substantial evidence
What it discloses A proxy that selectively decrypts HTTPS/TLS traffic based on URL/domain policy or reputation data, performs an action on decrypted packets (block, redirect, allow, log), and then re-encrypts and forwards allowed traffic toward its destination

Why this combination is obvious. Because the Board found IPUG anticipates claim 1 — i.e., IPUG discloses every limitation arranged as in the claim — obviousness over IPUG follows a fortiori: a reference that inherently discloses all claimed limitations necessarily renders the claimed subject matter obvious to a POSITA. The Board separately and independently reached this result as Ground 3. The only meaningful "combination" question here is IPUG combined with the general knowledge of a POSITA (e.g., knowledge that an "allow" disposition in a security proxy implies forwarding the packet toward its intended destination after inspection). No second reference is needed; the claim adds nothing beyond what the IronPort product already did. On appeal, Centripetal did not dispute the substance of the obviousness-over-IPUG ground independently of its two failed arguments — the "corresponding action" construction and IPUG's public accessibility — both of which the CAFC rejected.

Combination B — Obviousness over Altman in view of CP (Ground 4)

This is the only ground in the IPR where § 103 was the operative theory for the primary reference, and it is the combination most directly on point for a § 103 analysis.

Reference Key disclosures (per the IPR record)
Altman — US 2012/0290829 A1 A network-security monitoring architecture with a Secure data Inspection Appliance (SIA) that decrypts and re-encrypts in-transit encrypted traffic and a Network Monitor Center (NMC) that dynamically establishes selection rules (e.g., rule tables including identification data such as IP addresses), selects encrypted connections matching the rules, receives plaintext copies of decrypted connections, inspects them, and applies "predefined consequent actions" (e.g., blocking or copying/logging). The record also reflects Altman's teaching that when a connection is inspected and no threat is found, the communication proceeds (i.e., is allowed onward) — the factual basis on which the Board found the "corresponding action" (allow) and re-encrypt/transmit limitations satisfied. Altman's architecture appears to correspond to the system of US 8,959,329 B2, "System and Method for Selective Inspection of Encrypted Traffic" (SIA/NMC/rule-table disclosure matches), though I did not verify that publication-to-patent identity with certainty
CP — US 2015/0121449 A1, "Agent assisted malicious application blocking in a network environment" As used in the IPR, CP teaches "identifying metadata for connections" — e.g., IP addresses — in an agent-assisted network-security context. The petitioner relied on CP solely for the "identifying flow identification data" limitation of claims 1[d]/11[f]

The claim gap CP fills. The petitioner's theory was that Altman's application of selection rules "expressly include[s] identification data such as IP addresses" and that a POSITA "would have understood that in order to apply the selection rules, like items must be compared to like (e.g. IP addresses from the flow request to IP addresses in the rule table)." To the extent any explicit disclosure of identifying flow metadata was thought lacking, CP supplies it: CP discloses identifying connection metadata (such as IP addresses) in a network-security environment, which is precisely the "flow identification data" that claim 1 compares against the decrypt-list.

Why a POSITA would combine Altman and CP. The motivation is textbook under KSR:

  1. Same field, same problem. Altman and CP are both in the field of network security and encrypted-traffic inspection. Altman's problem — inspecting only selected encrypted connections to conserve resources — is the identical problem the '526 patent addresses. CP addresses malicious-application blocking in a network environment, a complementary security function that presupposes the ability to identify connection metadata.

  2. Known design need and predictable solution. Altman's rule-based selection requires comparing flow attributes against a rule table. A POSITA seeking to implement Altman's selection rules would naturally look to the well-known technique of reading connection metadata (source/destination IP addresses, ports, protocol, hostnames) from the packets that initiate the connection — a technique CP expressly discloses. Combining CP's metadata-identification teaching with Altman's rule-table-driven selective decryption is the application of a known technique to a known problem, yielding a predictable result: a device that identifies flow data, compares it to a list, and decrypts only matching flows.

  3. "Obvious to try." There is a finite set of known ways to identify the subject of an encrypted flow before decryption: inspect the TCP/IP tuple (IP addresses and ports), inspect the TLS Server Name Indication (SNI) in the plaintext ClientHello, or inspect the server certificate's Common Name after the server's Certificate message. Altman's rule table (IP-address-based) and CP's metadata identification together point to the most basic member of that finite set — comparing IP-address metadata from initiating packets against the rule table. This is precisely the "obvious to try" scenario KSR describes: a known design need, a finite number of identified, predictable solutions.

  4. No teaching away and no incompatibility. Nothing in either reference discourages combining rule-based connection selection with metadata identification; the references are architecturally compatible (agent/console security architecture in CP complements the SIA/NMC split in Altman).

Disputed point fairly noted. The patent owner argued on appeal/rehearing that (a) Altman allegedly does not re-encrypt and transmit a communication back toward its destination after applying "consequent actions," because the actions are "block" or "copy and log"; and (b) the petitioner allegedly did not provide a reasoned motivation to combine Altman and CP. The Board rejected these arguments in the FWD (having found all four grounds meritorious), and the CAFC did not revisit them because affirmance on IPUG made them moot. The patent owner's "no re-encryption" argument is also substantially weakened by the Board's "corresponding action" construction: where Altman discloses that an inspected communication with no detected threat proceeds onward (per the record), the "allow" is itself the "corresponding action," and the ordinary proxy behavior of forwarding the (re-encrypted) communication supplies limitations 1[f] and 1[g].


IV. Additional § 103 combinations a POSITA would find obvious (analyst-constructed, using the Part 2 prosecution-history candidates)

The following combinations are not part of the IPR record but follow from the same § 103 logic, and they are most relevant to the dependent claims (e.g., claims 2 and 12, which require the device to create the decrypt-list from network addresses and domain names received from a security application):

Combination C — Altman or IPUG combined with cyber-threat-intelligence (CTI) list-generation art

  • References: Altman or IPUG (base selective-decryption proxy) + US 2016/0119365 A1 ("cyber intelligence hub") and/or US 2015/0237012 A1 ("filtering network data transfers") — both candidate front-page references; + US 7,237,267 B2 (Cisco, policy-based network security management).
  • Claim gap filled: The dependent claims' requirement that the list of identification data be created from network addresses and domain names supplied by a security application. CTI-fed filtering was well established by 2017 — the '526 patent's own Background describes collecting "cyber threat intelligence (CTI) on the network addresses of endpoints operated/controlled by malicious actors" and filtering traffic against it as a known approach.
  • Motivation: A POSITA implementing a selective-decryption proxy for cybersecurity (the patent's stated primary use case) would obviously populate the decrypt-list from the same CTI feeds already used for conventional filtering; the "cyber intelligence hub" and "filtering network data transfers" references teach exactly that data flow (security application → list of addresses/domains → enforcement device). This is the routine application of a known data source to a known enforcement mechanism.

Combination D — Base reference combined with SNI/TLS-handshake knowledge (for claims reciting server-name identification)

  • References: IPUG or Altman + the TLS/SNI standard (RFC 6066, Server Name Indication) as general POSITA knowledge, optionally with US 2008/0077705 A1 (traffic inspection/classification for session/content control).
  • Claim gap filled: Dependent-claim features involving extraction of the SNI value from the plaintext ClientHello or the certificate CN during the handshake. SNI has been standard in TLS since 2003 precisely so that intermediaries and virtual hosts can identify the intended server before decryption.
  • Motivation: Any POSITA building a TLS-intermediating proxy knows SNI is the only plaintext server-identifier in the handshake; using it to drive the selective-decryption decision is the most natural implementation of a "domain-name-decrypt-list," and IPUG (a commercial web proxy) would necessarily have confronted this exact design choice.

Combination E — Altman + IPUG (mutually reinforcing, no new teachings needed)

  • Both references independently disclose selective TLS decryption with policy-based selection, action, and re-encryption/forwarding. Combining two references that teach the same solution to the same problem is obviousness by redundancy: a POSITA would have had every reason to consult both vendor documentation (IPUG) and a published patent application (Altman) when designing a selective-decryption proxy, and the combination would have required no modification of either teaching.

Combination F — Hybrid decrypt / do-not-decrypt lists (privacy-use dependent claims)

  • References: Base reference (IPUG/Altman) + knowledge of privacy compliance (or CP's agent-based policy distribution). The '526 patent discloses both "decrypt-list" and "do-not-decrypt-list" variants driven by competing policies (cybersecurity vs. privacy).
  • Motivation: The patent itself admits the dual-policy scenario was a known real-world tension. A POSITA implementing policy-driven selective decryption would obviously support both an allow-decrypt list and a deny-decrypt list, prioritizing one over the other, because both mechanisms are the same rule-table technology already present in Altman (selection rules) and IPUG (policy lists).

V. Holistic motivation analysis under Graham and KSR

  1. Scope and content of the prior art. By 2017, selective decryption of TLS traffic was a commercially implemented and heavily documented technique: Cisco's IronPort Web Security Appliance (IPUG) shipped selective HTTPS decryption with policy/reputation-based selection; Altman/US 8,959,329 B2 disclosed a rule-table-driven SIA/NMC selective-inspection system; and Netronome's SSL Inspector (which Altman incorporates by reference, per the IPR record) exposed plaintext of selected flows to security appliances. The claimed combination of "identify → compare to list → decrypt → act → re-encrypt → transmit" was the standard architecture for such products.

  2. Differences between the prior art and the claims. The Board found, and the CAFC effectively confirmed on the representative claim, that there was no meaningful difference between claim 1 and IPUG (anticipation) — and the same was found for Altman. The only real disputes were the meaning of "corresponding action" (resolved against the patent owner) and IPUG's public accessibility (resolved against the patent owner). With no non-obvious difference surviving, the § 103 inquiry collapses: a claim that reads on a prior-art product manual and a prior-art patent application cannot present a patentable difference.

  3. Level of skill. As noted above, a POSITA familiar with TLS, proxies, and policy-based security would have found the claimed architecture an obvious design choice, not an inventive leap.

  4. Motivation to combine (the KSR factors).

    • Known problem: decrypting all TLS traffic is resource-intensive (the patent concedes this); selective decryption was the known fix.
    • Design incentives: efficiency, CAPEX/OPEX savings, and privacy compliance all push toward selective decryption — the patent's own Summary lists these as the motivations.
    • Market pressure: commercial web proxies (Cisco IronPort) and inspection appliances (Netronome, Packet Forensics — both cited in Altman's disclosure) already offered selective SSL inspection; a POSITA had market-driven reason to combine rule-based selection (Altman) with connection-metadata identification (CP) and CTI list generation (Part 2 art).
    • Obvious to try: the finite set of plaintext-visible identifiers available before decryption (IP tuple, SNI, certificate CN) made the "identify flow data from initiating packets" limitation an obvious implementation detail.
    • No teaching away: none of the references discourages combination; all are architecturally compatible.
  5. Secondary considerations. The IPR record contains no persuasive objective indicia of non-obviousness — no commercial-success, long-felt-need, or unexpected-results showing that overcame the strong prima facie case. Centripetal lost on the merits at every stage (FWD; Director Review denial June 21, 2024; CAFC affirmance April 2, 2026), and the ITC's parallel investigation (337-TA-1314) likewise found the asserted claims invalid/not infringed.


VI. Bottom line and confidence flags

  • The strongest § 103 combination in the record is Altman + CP (IPR Ground 4): Altman supplies the selective-decrypt/act/re-encrypt proxy architecture; CP supplies explicit "identifying metadata for connections" (IP addresses) for the flow-identification limitation; and the motivation — implementing rule-based selection by comparing initiating-packet metadata against a rule table — is a routine, predictable design step that KSR treats as obvious.
  • Obviousness over IPUG alone (Ground 3) is effectively conclusive, since IPUG anticipates the representative claim; the CAFC's April 2, 2026 affirmance of the IPUG anticipation ground, together with the endorsed "corresponding action" construction (any action, including allowing), makes any § 103 challenge to claims 1–20 exceptionally strong.
  • For dependent claims, the CTI-feed, SNI/standard-knowledge, and hybrid-list combinations above supply the added limitations using well-known art (including Part 2 candidate references) and standard POSITA knowledge.

Confidence flags:

  1. Record-based: The Board's four-ground FWD holding claims 1–20 unpatentable, and the CAFC's affirmance on Ground 1 with Grounds 2–4 moot, are verified (FWD, J.A. 1–66; CAFC Op.; IPWatchdog Apr. 2, 2026).
  2. Partially verified: CP's title ("Agent assisted malicious application blocking in a network environment") is now confirmed; CP's exact remaining teachings are known only through the IPR record's characterization ("identifying metadata for connections"). Altman's identity with US 8,959,329 B2 is probable but not confirmed.
  3. Analyst-inferred: Combinations C–F are my own § 103 constructions using candidate front-page references; they were not adjudicated in the IPR, and the Part 2 reference list remains only partially verified as examiner citations on the patent face.
  4. The verbatim text of the dependent claims was not independently verified in this session; the analysis of dependent-claim limitations relies on the FWD/CAFC characterizations.

Sources: PTAB FWD, IPR2022-01525 (Apr. 15, 2024); Centripetal Networks, LLC v. Keysight Technologies, Inc., No. 24-2246 (Fed. Cir. Apr. 2, 2026), https://www.cafc.uscourts.gov/opinions-orders/24-2246.OPINION.4-2-2026_2670414.pdf; IPWatchdog coverage (Apr. 2, 2026); IPVerse/GreyB IPR docket (https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2022-01525); PTACTS petition documents for IPR2022-01525; Google Patents record for US 10284526.

Generated 8/31/2026, 12:47:18 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Keysight Technologies, Inc.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (3)

3 tracked lawsuits name US 10284526.