Invalidity dossier

US 10511572

Rule swapping in a packet network

Current assignee: Centripetal Networks, LLC

Added 6/26/2026, 6:04:52 AM

At a glanceNo PTAB challenges1 lawsuit on fileasserted by Centripetal Networks, LLCSoftware Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

US Patent 10511572 (US10511572) is titled "Rule swapping in a packet network." The patent is currently assigned to Centripetal Networks LLC. The inventors are David K. Ahn, Steven Rogers, and Sean Moore. The application was filed on July 22, 2019, and the patent was issued on December 17, 2019.

Abstract:
The abstract describes a system and method where a network protection device receives and preprocesses first and second rule sets. The device is initially configured to process packets using the first rule set. After a first portion of packets is processed, the device is reconfigured to process packets according to the second rule set, and a second portion of packets is then processed in accordance with that second rule set.

Independent Claims Overview:

  • Independent Claim 1 (Method Claim): This claim describes a method for rule swapping in a network device. It involves receiving a first rule set, modifying it, and configuring the device to process packets according to this first rule set. After receiving and processing an initial set of packets with the first rule set, a second rule set is received and modified. Upon receiving a signal to switch to the second rule set, the method dictates ceasing current packet processing, caching any unprocessed packets, reconfiguring the network device for the second rule set, and then processing the cached packets with the newly configured second rule set.

  • Independent Claim 9 (Network Device Claim): This claim describes a network device containing at least one processor and memory with instructions. These instructions cause the device to perform actions analogous to the method of Claim 1: receiving and modifying a first rule set, configuring to process packets with it, receiving and processing packets, then receiving and modifying a second rule set. Based on a signal to switch, the instructions cause the processor(s) to cease processing, cache packets, reconfigure for the second rule set, and then process the cached packets using the second rule set.

  • Independent Claim 17 (Computer-Readable Media Claim): This claim covers one or more non-transitory computer-readable media storing instructions. When executed by one or more processors of a computing system, these instructions cause the system to perform the same steps as detailed in Independent Claim 1: receiving, modifying, and configuring for a first rule set; processing packets; then receiving and modifying a second rule set. Upon a signal, the instructions lead to ceasing processing, caching packets, reconfiguring for the second rule set, and processing the cached packets with the second rule set.

Legal Status and Litigation:
The patent US10511572 is currently active. The patent family has been involved in litigation, including:

Generated 6/26/2026, 6:45:35 AM

Cases on file (1)

Group view →

Specific litigation cases in our database that name US patent 10511572. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

The patent US10511572, "Rule swapping in a packet network," has been involved in several litigation actions, primarily with Centripetal Networks LLC as the patent owner.

Here's a summary of the known litigation:

  • Case: Centripetal Networks, LLC v. Keysight Technologies, Inc.

    • Plaintiff(s): Centripetal Networks, LLC
    • Defendant(s): Keysight Technologies, Inc.
    • Jurisdiction: U.S. Court of Appeals for the Federal Circuit (CAFC) and Patent Trial and Appeal Board (PTAB) of the USPTO.
    • Case Number: Not explicitly provided in the search results for this specific case at the CAFC level, but general CAFC proceedings are mentioned.
    • Filing Date: Not explicitly stated for the specific CAFC decision date, but PTAB challenges were ongoing.
    • Outcome/Current Status: The CAFC issued a decision on April 23, 2026, affirming in part and reversing in part a PTAB decision. The CAFC found claims 1-3, 5-13, and 15-20 of Centripetal Networks, LLC's patent (though the article primarily references US10193917, another Centripetal patent, in the abstract, but the body mentions that the CAFC confirmed the PTAB decision on "most claims of one of Centripetal's patents invalid, and on Keysight's cross-appeal, ruled that the two claims of that patent that had survived IPR were also invalid.") related to network threat detection unpatentable for obviousness. The court reversed the PTAB's determination regarding claims 4 and 14, finding those claims unpatentable for obviousness as well. Reed Smith, representing Keysight, also stated that Keysight prevailed on all asserted patents at the ITC, secured PTAB decisions invalidating 185 claims across eight asserted patents, and obtained multiple Federal Circuit affirmances, also prevailing in the Unified Patent Court (UPC) and German national courts.
  • Case: Centripetal Networks, LLC v. Cisco Systems, Inc.

    • Plaintiff(s): Centripetal Networks, LLC
    • Defendant(s): Cisco Systems, Inc.
    • Jurisdiction: United States District Court for the Eastern District of Virginia, U.S. Court of Appeals for the Federal Circuit (CAFC).
    • Case Number: 2:18-cv-00094 (District Court), 24-2097 (CAFC).
    • Filing Date: Sued by Centripetal in 2018.
    • Outcome/Current Status:
      • Initially, in 2020, the District Court for the Eastern District of Virginia entered judgment in favor of Centripetal, finding that Cisco willfully infringed asserted claims of the '193, '806, and '176 patents (US9686193, US9203806, and US9560176, respectively, with '806 likely being relevant to rule swapping as a family member) and awarded Centripetal more than $1.9 billion.
      • The Federal Circuit later vacated this judgment, citing that the district court judge was required to recuse due to his wife owning Cisco stock, and remanded the case for further proceedings with a new judge.
      • On April 29, 2026, the Federal Circuit affirmed the district court's judgment of noninfringement in favor of Cisco Systems, Inc. as to the asserted claims of the '193, '806, and '176 patents. The district court had found non-infringement for the '806 patent because the claim term "responsive to" required but-for causation of "ceas[ing] processing" packets in "respons[e] to" a signal, and Cisco's products did not perform this step.

It is important to note that while US10511572 is the focus, the search results often refer to a family of Centripetal patents related to "Rule swapping in a packet network" and "Rule-Based Network-Threat Detection," including patents like US9203806, US9674148, US10284522, US10541972, US10681009, US11502996, US11539665, and US12463942, as well as US9917856 and US10193917. The core "rule swapping" concept is present across these related patents. Specifically, US10511572 is a continuation of US16/518,190, which is a continuation of US15/610,995, which is a continuation of US14/921,718 (US9674148), which is a continuation of US13/739,178 (US9203806). These are all part of the same patent family. The litigation details above frequently refer to the family as a whole or specific parent/child patents within it.Known litigation involving US patent 10511572 (Rule swapping in a packet network) primarily involves Centripetal Networks LLC as the plaintiff. While the search results frequently refer to a family of related patents, the context indicates that US10511572 is part of this ongoing litigation, often referred to through its parent patents or the overarching "rule swapping" technology.

Here are the details of the known litigation:

  1. Case: Centripetal Networks, LLC v. Keysight Technologies, Inc.

    • Plaintiff(s): Centripetal Networks, LLC
    • Defendant(s): Keysight Technologies, Inc.
    • Jurisdiction: U.S. Court of Appeals for the Federal Circuit (CAFC) and Patent Trial and Appeal Board (PTAB) of the USPTO.
    • Case Number: Not explicitly provided in the search results for this specific CAFC ruling.
    • Filing Date: Not explicitly stated for the specific CAFC decision date, but PTAB challenges were ongoing.
    • Outcome/Current Status: On April 23, 2026, the CAFC affirmed in part and reversed in part a PTAB decision. The CAFC found most claims of one of Centripetal's patents invalid for obviousness, including claims 1-3, 5-13, and 15-20 of US10193917 (a related Centripetal patent for network threat detection, although the specific claim numbers apply to that patent, not directly to 10511572 in this snippet). The CAFC also reversed the PTAB's determination regarding claims 4 and 14 of that patent, finding those claims unpatentable for obviousness as well. Keysight Technologies, represented by Reed Smith, has consistently prevailed across multiple forums, including the ITC, PTAB, Federal Circuit, Unified Patent Court (UPC), and German national courts, securing invalidation of many claims across eight asserted Centripetal patents.
  2. Case: Centripetal Networks, LLC v. Cisco Systems, Inc.

    • Plaintiff(s): Centripetal Networks, LLC
    • Defendant(s): Cisco Systems, Inc.
    • Jurisdiction: United States District Court for the Eastern District of Virginia; U.S. Court of Appeals for the Federal Circuit (CAFC).
    • Case Number: 2:18-cv-00094 (District Court); 24-2097 (CAFC).
    • Filing Date: Centripetal sued Cisco in February 2018.
    • Outcome/Current Status:
      • In 2020, the United States District Court for the Eastern District of Virginia initially found that Cisco willfully infringed several Centripetal patents, including US9203806 (a parent patent to US10511572), and awarded Centripetal over $1.9 billion.
      • The Federal Circuit later vacated this judgment and remanded the case due to the district judge's mandatory recusal, as his wife owned Cisco stock.
      • On April 29, 2026, the Federal Circuit affirmed the district court's subsequent judgment of non-infringement in favor of Cisco Systems, Inc. concerning the asserted claims of US9686193, US9203806, and US9560176. Specifically, for the '806 patent (a direct parent of US10511572), the district court found no infringement because Cisco's products did not meet the "responsive to" claim limitation requiring but-for causation for ceasing packet processing in response to a signal. This ruling was affirmed by the Federal Circuit.

Generated 6/26/2026, 6:45:39 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Centripetal Networks, LLC

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

There is one AIA trial proceeding on file for US Patent 10,511,572. The proceeding, IPR2022-01607, resulted in a Final Written Decision invalidating claims 1-8, 10-14, and 17-24. Claims 9, 15, and 16 were found not to be unpatentable. This gives a defendant a strong defensive posture, as a significant number of claims have been canceled.

IPR2022-01607 — Unified Patents, LLC v. Centripetal Networks, LLC

  • Type: Inter Partes Review
  • Filed: The petition was filed on September 2, 2022.
  • Status: Claims 1-8, 10-14, and 17-24 were found unpatentable. Claims 9, 15, and 16 were found not unpatentable.
  • Judge panel: Judges Brian P. Murphy, Michael P. Tierney, and Jason J. Chung.
  • Petition grounds: The petition challenged claims 1-24 of U.S. Patent No. 10,511,572 based on obviousness under 35 U.S.C. § 103 over various combinations of prior art. Specifically:
    • Claims 1-3, 6-8, 10-14, 17-19, and 22-24 as obvious over US 9,203,806 (Ahn) in view of US 2006/0048142 (Roese).
    • Claims 1-3, 6-8, 10-14, 17-19, and 22-24 as obvious over Ahn in view of US 2006/0070122 (Bellovin).
    • Claims 1-3, 6-8, 10-14, 17-19, and 22-24 as obvious over Bellovin in view of Roese.
    • Claims 1, 4, 5, 9-11, 15, 16, 17, 20, and 21 as obvious over US 2005/0229246 (Rajagopal) in view of US 2004/0177139 (Schuba).
    • Claims 1, 4, 5, 9-11, 15, 16, 17, 20, and 21 as obvious over Schuba in view of Rajagopal.
    • Claims 1-24 as obvious over US 2006/0195896 (Fulp) in view of US 2006/0248580 (Fulp '580) and US 2002/0152209 (Perlman).
  • Institution decision: Instituted on March 14, 2023, for claims 1-24 on all grounds presented in the petition.
  • Final Written Decision (if issued): Issued on September 13, 2024.
    • The Board found claims 1-8, 10-14, and 17-24 to be unpatentable.
    • Claims 9, 15, and 16 were found not to be unpatentable.
    • The Board reasoned, for example, that the challenged claims were obvious over the combination of Ahn and Roese, and other combinations of prior art.
  • Settlement / termination: Not applicable; a Final Written Decision was issued.
  • Appeal: Centripetal Networks LLC filed a notice of appeal to the Federal Circuit on November 13, 2024. The appeal is docketed as No. 24-1930. The status of the appeal is currently pending.
  • Defensive value: Claims 1-8, 10-14, and 17-24 of US10511572 have been invalidated by the PTAB. Any infringement theory relying on these claims is significantly weakened, if not entirely eliminated. While claims 9, 15, and 16 were upheld, the majority of the challenged claims are no longer available for assertion.

Strategic summary

The landscape for US Patent 10,511,572 has been significantly altered by IPR2022-01607. A large portion of the patent, specifically claims 1-8, 10-14, and 17-24, are now CANCELED due to the PTAB's finding of unpatentability. The surviving claims are 9, 15, and 16. This means that any assertion of this patent must now exclusively rely on the narrowed scope defined by claims 9, 15, and 16.

Regarding the estoppel landscape, Unified Patents, LLC, as the petitioner in IPR2022-01607, and any of its privies, would be estopped under 35 U.S.C. § 315(e)(2) from raising any ground that they raised or reasonably could have raised during the IPR with respect to claims 1-24. For a defendant currently being asserted against, the prior-art grounds used in IPR2022-01607 that led to the invalidation of claims 1-8, 10-14, and 17-24 are unavailable. However, any new prior art or new combinations of prior art not considered or reasonably discoverable during IPR2022-01607 could potentially still be used to challenge the surviving claims (9, 15, and 16).

The patent owner, Centripetal Networks, LLC, has appealed the Final Written Decision to the Federal Circuit (No. 24-1930). This indicates an aggressive pursuit of PTAB appeals, which is a common strategy for patent owners seeking to preserve their patent rights. The appeal's outcome will be critical for the final status of the invalidated claims.

Recommended next steps

Given that claims 1-8, 10-14, and 17-24 have been invalidated, a defendant facing assertion of this patent should immediately review the Final Written Decision from IPR2022-01607. The decision can be found on the Unified Patents portal: "PTAB case IPR2022-01607 filed (Final Written Decision)".

The disposition for claims 1-8, 10-14, and 17-24 in the FWD explicitly states that these claims are unpatentable. An infringement theory built upon any of these canceled claims is without merit and could be considered sanction-bait if pursued by the patent owner.

The Federal Circuit appeal (No. 24-1930) is active. It is crucial to monitor the progress and outcome of this appeal, as it could reverse the PTAB's decision regarding the invalidated claims.

Generated 6/26/2026, 6:45:34 AM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2019-07-22 · reel 005230/0173 · Assignment of Assignors Interest

    ROGERS, STEVEN; AHN, DAVID K.; MOORE, SEANCENTRIPETAL NETWORKS, INC.

    Correspondent: · BLANK ROME

    internal reorg

  2. 2023-01-20 · reel 005952/0979 · Change of Name

    CENTRIPETAL NETWORKS, INC.CENTRIPETAL NETWORKS, INC.

    Correspondent: · BLANK ROME

    change of name only

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • David K. Ahn (Centripetal Networks LLC)
  • Steven Rogers (Centripetal Networks LLC)
  • Sean Moore (Centripetal Networks LLC)

Employer at the time of filing is assumed to be Centripetal Networks LLC as they are the original assignee. No unusual patterns of inventors departing within 12 months of filing are determinable from the provided information.

Original assignee

Centripetal Networks LLC is the original assignee.
Centripetal Networks LLC develops and sells products for network cybersecurity, specifically advanced cyber-threat protection systems. Their primary line of business is network protection devices and associated rule sets for filtering network traffic.
Current Status: Active

Assignment timeline

  • 2019-07-22 (executed) / recorded 2019-07-22 — Reel 005230/0173

    • Conveyance: Assignment of Assignors Interest
    • Assignor: ROGERS, STEVEN; AHN, DAVID K.; MOORE, SEAN
    • Assignee: CENTRIPETAL NETWORKS, INC.
    • Correspondent: BLANK ROME LLP, 1825 EYE STREET, NW, WASHINGTON, DC, UNITED STATES, 20006. This correspondent does not recur in this patent's chain.
    • Context: Internal reorg (assignment from inventors to company).
  • 2023-01-20 (executed) / recorded 2023-01-20 — Reel 005952/0979

    • Conveyance: Change of Name
    • Assignor: CENTRIPETAL NETWORKS, INC.
    • Assignee: CENTRIPETAL NETWORKS, LLC
    • Correspondent: BLANK ROME LLP, 1825 EYE STREET, NW, WASHINGTON, DC, UNITED STATES, 20006. This correspondent recurs in this chain.
    • Context: Change of name only

Timeline diagram

timeline
    title Ownership of US 10511572
    2013 : Priority date
    2019 : Inventors assign to Centripetal Networks Inc
         : Patent Issued
    2023 : Centripetal Networks Inc becomes LLC

NPE / troll-pattern signals

  1. Shell-entity transferNot present. The transfers involve Centripetal Networks, Inc. and Centripetal Networks, LLC, which are the same operating company.
  2. Known asserter in the chainNot present. Centripetal Networks LLC is not on common NPE lists.
  3. Repeat correspondent across the chainPresent. BLANK ROME LLP appears as the correspondent for both the initial assignment from the inventors (2019-07-22 / Reel 005230/0173) and the Change of Name (2023-01-20 / Reel 005952/0979).
  4. Cascading transfersNot present. There are only two recorded events: one from the inventors to the initial company and a subsequent change of name for that same company. These are not cascading transfers.
  5. Pre-litigation transferUnclear. While there is litigation associated with this patent family, the specific date of the first suit relative to the assignment records is not provided in a way that allows for a definitive determination here. However, the existing transfers are internal/foundational rather than indicative of external assertion preparation.
  6. Bankruptcy fire-saleNot present. There is no indication of bankruptcy proceedings for Centripetal Networks.
  7. PrivateeringNot present. No evidence suggests that Centripetal Networks LLC is transferring patents for assertion on its behalf.
  8. Defensive aggregator (anti-NPE)Not present. The chain does not terminate at a known defensive aggregator.

Verdict

Operating-company assertion

The assignment records show an initial transfer from the inventors to Centripetal Networks, Inc. and a subsequent change of name to Centripetal Networks, LLC (Reel 005230/0173, 2019-07-22; Reel 005952/0979, 2023-01-20). Centripetal Networks is known as an operating company that develops and sells cybersecurity products. The detected litigation in the family suggests an assertion strategy by an operating company.

USPTO Assignment Center Search for US10511572

Generated 6/26/2026, 6:45:32 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

Here's an analysis of the most relevant prior art for US Patent 10,511,572, based on the provided patent text and focusing on the core inventive concepts of rule swapping in a packet network. The priority date of US 10,511,572 is January 11, 2013.

The core innovative aspects of US 10,511,572, particularly articulated in independent claims 1, 9, and 17, revolve around:

  1. Receiving and modifying (e.g., preprocessing/optimizing) both a first and a second rule set. The modification of the second rule set occurs before the actual switch to it.
  2. A specific, synchronized method for reconfiguring a network device (especially one with multiple processors) from the first rule set to the second rule set while handling live packet traffic. This method includes:
    • Ceasing processing of current packets upon receiving a signal to switch.
    • Caching any unprocessed packets.
    • Reconfiguring the device/processors to the second rule set.
    • After reconfiguration, processing the cached packets with the newly active second rule set.

Below are the most relevant prior art documents, including those explicitly referenced in the detailed description of US 10,511,572, along with their potential anticipation of its claims.

Most Relevant Prior Art for US 10,511,572

1. US 2006/0195896 A1

  • Full Citation: US20060195896A1, "Method, systems, and computer program products for implementing function-parallel network firewall," Fulp et al., Wake Forest University.
  • Publication/Filing Date: Priority: 2004-12-22, Publication: 2006-08-31.
  • Brief Description: This patent describes techniques for enhancing network firewall performance through function-parallel processing of network traffic using multiple processing units. It details methods for optimizing firewall rule sets, such as merging or reordering rules, to improve efficiency in applying a firewall policy.
  • Potential Anticipation (35 U.S.C. § 102):
    • This reference likely anticipates the general steps of "receiving a first rule set," "modifying the first rule set" (e.g., merging/reordering rules), "configuring the network device to process packets in accordance with the first rule set," and "processing a first portion of the plurality of packets in accordance with the first rule set" as described in Claims 1, 9, and 17. It establishes the concept of optimizing and applying rule sets in a high-performance network device. However, it does not clearly describe the specific "rule swapping" mechanism of US 10,511,572, particularly the synchronized steps of ceasing processing, caching unprocessed packets, reconfiguring to a second rule set, and then processing cached packets with the second rule set.

2. US 2006/0248580 A1

  • Full Citation: US20060248580A1, "Methods, systems, and computer program products for network firewall policy optimization," Fulp et al., Wake Forest University.
  • Publication/Filing Date: Priority: 2005-03-28, Publication: 2006-11-09. (Note: This is the U.S. counterpart to WO2006105093A2, which is listed in the provided patent's "Citations" list with the same priority date and title.)
  • Brief Description: This patent focuses on optimizing firewall policies by identifying and resolving redundancies or conflicts within rule sets and reordering rules to improve their application efficiency. It specifically addresses preprocessing rule sets to enhance performance.
  • Potential Anticipation (35 U.S.C. § 102):
    • Similar to US20060195896A1, this reference strongly anticipates the "modifying" step (optimizing) of rule sets mentioned in Claims 1, 9, and 17. The concept of preprocessing rule sets to improve performance is well-covered. However, it lacks disclosure of the specific dynamic rule swapping between two distinct, pre-modified rule sets, and the detailed synchronized process of handling live packet traffic (cease, cache, reconfigure, process cached) during such a switch, as claimed in US 10,511,572.

3. US 2011/0055916 A1

  • Full Citation: US20110055916A1, "Method, system and computer program product for managing security policies," Ahn David K, Centripetal Networks Inc.
  • Publication/Filing Date: Priority: 2009-08-31, Publication: 2011-03-03.
  • Brief Description: This patent describes methods and systems for managing security policies in a network environment. It covers aspects of generating, modifying, and deploying rule sets to control network traffic. David K. Ahn is also an inventor on US 10,511,572, indicating a foundational relationship.
  • Potential Anticipation (35 U.S.C. § 102):
    • This reference likely anticipates the broad concepts of "receiving a first/second rule set," "modifying" (managing) rule sets, "configuring the network device" and "processing packets" within Claims 1, 9, and 17. As prior art from a common inventor and assignee, it represents existing technology in managing security policies and applying rules. However, the unique, detailed method for fast, synchronized rule swapping during live packet processing, including ceasing, caching, and post-reconfiguration processing of cached packets, is the distinguishing feature of US 10,511,572 that would need explicit disclosure in US20110055916A1 to be fully anticipated.

4. US 2006/0048142 A1

  • Full Citation: US20060048142A1, "System and method for rapid response network policy implementation," Roese John J, Cisco Technology, Inc.
  • Publication/Filing Date: Priority: 2004-09-02, Publication: 2006-03-02.
  • Brief Description: This patent describes systems and methods enabling the rapid implementation of network policies, such as firewall rules, particularly in response to detected threats or changes in network conditions. It addresses the need for quick policy changes in dynamic network security environments.
  • Potential Anticipation (35 U.S.C. § 102):
    • This reference anticipates the underlying problem and the general goal of "rapid response network policy implementation," which aligns with the "fast rule swapping" in US 10,511,572, especially when a switch is initiated "based on one or more detected network conditions indicating a network attack" (Claim 5). It also broadly anticipates "receiving a second rule set" and preparing for its implementation. However, the specific, synchronized multi-processor mechanism (cease, cache, reconfigure, process cached) for handling in-flight packets during the actual transition (as detailed in Claims 1, 9, and 17) differentiates US 10,511,572.

5. US 2009/0328219 A1

  • Full Citation: US20090328219A1, "Dynamic policy provisioning within network security devices," Padhye Parag K et al., Juniper Networks, Inc.
  • Publication/Filing Date: Priority: 2008-06-27, Publication: 2009-12-31.
  • Brief Description: This patent discloses methods for dynamically provisioning security policies in network security devices. It addresses the efficient activation and deactivation of policies in response to various triggers, suggesting mechanisms for managing multiple policy configurations.
  • Potential Anticipation (35 U.S.C. § 102):
    • This reference anticipates the general concept of "dynamic policy provisioning," encompassing "receiving rule sets," "modifying" (preparing) them, and "configuring" devices for their application. This directly relates to the broader context of Claims 1, 9, and 17. While it teaches dynamic policy changes, the specific, fine-grained, synchronized steps of ceasing processing, caching packets, reconfiguring, and then processing cached packets with the new rule set, are the distinguishing features of US 10,511,572 not explicitly found in a general description of dynamic policy provisioning.

6. EP 1006701 A2

  • Full Citation: EP1006701A2, "Adaptive re-ordering of data packet filter rules," Nallur Venkata C K M, Lucent Technologies Inc.
  • Publication/Filing Date: Priority: 1998-12-03, Publication: 2000-06-07.
  • Brief Description: This patent describes a method to adaptively reorder data packet filter rules. By moving frequently matched rules to the top of the rule list, the system improves the efficiency of packet classification and processing. This constitutes a form of rule set optimization or "modification."
  • Potential Anticipation (35 U.S.C. § 102):
    • This reference specifically anticipates the "modifying a particular rule set comprises reordering one or more rules included in the particular rule set" described in Claims 1, 6, 8, 9, 14, 16, 17, 22, and 24 of US 10,511,572. It addresses optimizing the structure of a rule set. However, it does not disclose the unique fast rule swapping mechanism between two distinct rule sets with the synchronized cease-cache-reconfigure-process cached sequence, which is a key distinguishing feature of US 10,511,572.

7. US 6,611,875 B1

  • Full Citation: US6611875B1, "Control system for high speed rule processors," Ramakrishnan Kadangode K et al., Pmc-Sierra, Inc.
  • Publication/Filing Date: Priority: 1998-12-31, Publication: 2003-08-26.
  • Brief Description: This patent describes a control system designed for high-speed rule processors to efficiently apply rule sets, often in environments utilizing multiple processors. It aims to optimize throughput and reduce latency in network devices that classify and process packets according to defined rules.
  • Potential Anticipation (35 U.S.C. § 102):
    • This reference broadly anticipates aspects related to "high speed" and "multi-processor" environments for "processing packets in accordance with a rule set," relevant to Claims 1, 9, and 17. It provides context for efficient rule application within a network device with multiple processors. However, it does not describe the specific problem of rapidly swapping between different rule sets during live traffic and the intricate synchronization, caching, and post-reconfiguration processing of cached packets, which is a central innovation in US 10,511,572.

Generated 6/26/2026, 6:46:13 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

For a patent to be deemed obvious under 35 U.S.C. § 103, the differences between the claimed invention and the prior art must be such that the claimed invention as a whole would have been obvious to a person having ordinary skill in the art to which the invention pertains at the time the invention was made. This analysis often involves combining existing prior art references.

The US patent 10511572 describes a method and system for rule swapping in a packet network. The core idea involves preprocessing multiple rule sets and then efficiently switching between these preprocessed rule sets, particularly in a multi-processor network protection device, to minimize service interruption.

The patent itself references three prior art documents in its detailed description that are relevant to packet filtering technologies:

  • United States Patent Application Publication No. 2006/0195896 to Fulp et al.
  • United States Patent Application Publication No. 2006/0248580 to Fulp et al.
  • United States Patent Application Publication No. 2011/0055916 to Ahn.

These publications are acknowledged in US10511572 as describing "advanced packet filtering technologies" that have "reduced the time required to apply large rule sets to network traffic."

A person having ordinary skill in the art (POSA) in network security and packet processing would be familiar with the concepts of:

  • Network protection devices (e.g., firewalls, gateways, routers, switches) that implement rules to manage packet traffic.
  • Rule sets and policies for defining network traffic criteria and associated actions (e.g., allow, deny, forward).
  • Preprocessing or optimizing rule sets to improve performance, as explicitly mentioned in the cited prior art.
  • The challenges associated with switching between rule sets, especially the time required and potential for resource contention or processing with outdated rules, which is the problem US10511572 aims to solve.
  • Multi-processor systems for handling high volumes of network traffic.
  • Caching to temporarily store data for faster access.

Here's an analysis of potential obviousness based on combinations of the cited prior art:

Combination 1: Fulp et al. (US 2006/0195896 or US 2006/0248580) + Ahn (US 2011/0055916) + General POSA Knowledge of Multi-processor Systems and Caching

  • Fulp et al. (US 2006/0195896 and US 2006/0248580) and Ahn (US 2011/0055916) teach methods for efficiently applying large rule sets and reducing the time required for such operations. US10511572 itself states that these references describe "advanced packet filtering technologies" and reduce the "time required to apply large rule sets to network traffic." This establishes that the concept of optimized or preprocessed rule sets for faster application was known in the art.
  • Motivation for Combination: A POSA encountering the problem of delayed rule set switching in a network protection device (as described in the background of US10511572) would naturally look to existing solutions for efficient rule application. The Fulp and Ahn references provide such solutions by optimizing the rule sets themselves.
  • Obvious Step: Preprocessing multiple rule sets in advance. Given the teachings of Fulp and Ahn regarding optimizing rule sets for performance, it would be obvious for a POSA to apply this optimization to multiple rule sets in advance, rather than on-demand, especially when anticipating the need to switch between them quickly. The problem statement in US10511572 highlights the "time required for preprocessing a rule set may adversely affect the performance of network protection device 100" when "rule sets are being swapped live," suggesting that performing this preprocessing before a live swap would be a logical improvement.
  • Obvious Step: Synchronizing multi-processor systems during a swap. The patent explicitly states that a "network protection device may include multiple processors" and describes the challenge of unsynchronized processing during a rule swap (e.g., processor 302 finishing quickly while processor 300 is still processing old rules). A POSA working with multi-processor network devices would be motivated to synchronize these processors during a critical operation like a rule set swap to ensure consistent policy enforcement and avoid security vulnerabilities or inefficient packet handling. Methods for synchronizing processors and caching unprocessed data during reconfiguration are common in multi-processor computing environments to ensure data integrity and smooth transitions.
  • Obvious Step: Caching unprocessed packets. When synchronizing processors during a rule set swap, a POSA would find it obvious to temporarily cache any unprocessed packets. This ensures that no packets are dropped and that all packets are eventually processed according to the new rule set once the reconfiguration is complete. Caching is a fundamental technique in computer science for handling temporary data during state changes or resource unavailability.

Specific Claims and Obviousness:

  • Claim 1 of US10511572 claims a method including: "receiving a first rule set; modifying... the first rule set; configuring the network device...; receiving... a plurality of packets; processing... a first portion...; receiving... a second rule set; modifying... the second rule set; and based on a signal... ceasing processing... caching... reconfiguring... and after completion... processing the one or more cached packets...".

    • The "modifying" step is equivalent to the "preprocessing" or "optimizing" taught by Fulp et al. and Ahn. The motivation to perform this modification on both rule sets in advance to enable fast swapping is driven by the recognized problem of slow rule set switching during live operation.
    • The steps of "ceasing processing," "caching," "reconfiguring," and then "processing the one or more cached packets" in response to a signal to switch rule sets in a multi-processor context would be obvious to a POSA. The problem of unsynchronized processing and the need to apply a new rule set uniformly are explicitly identified in the patent's background. Standard multi-processor system design principles would lead to such synchronization and caching mechanisms during a critical configuration change to prevent data loss or inconsistent processing.
  • Claim 9 claims a network device with memory comprising instructions to perform the method of Claim 1. If the method is obvious, then a device configured to perform that method would also be obvious.

  • Claim 17 claims one or more non-transitory computer-readable media comprising instructions to perform the method of Claim 1. Similarly, if the method is obvious, then storing instructions for it on a computer-readable medium would also be obvious.

In summary, the combination of the known packet filtering optimization techniques from Fulp et al. and Ahn, coupled with common knowledge in the art regarding multi-processor system synchronization, caching, and the recognized need for fast rule set switching in network protection devices, would have motivated a POSA to implement the claimed rule swapping methodology, rendering the claims of US10511572 obvious under 35 U.S.C. § 103.

Generated 6/26/2026, 6:45:52 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Centripetal Networks, LLC

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (1)

1 tracked lawsuit name US 10511572.