Invalidity dossier
US 10542028
Rule-based network-threat detection
Current assignee: Palo Alto Networks, Inc.
Added 8/30/2026, 4:49:29 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll search for this specific patent number across USPTO and court docket sources.
Let me verify the claim structure and check for any 2026 CAFC docket entries specific to this patent.
Let me confirm the full claim set and independent claim text for this patent.
US Patent 10,542,028 (10542028) — Verified Summary
Bibliographic data
| Field | Value |
|---|---|
| Patent number | US 10,542,028 B2 (US10542028B2) |
| Title | Rule-based network-threat detection |
| Assignee | Centripetal Networks, Inc. (name-changed 2023-01-20 to Centripetal Networks, LLC) |
| Inventors | David K. Ahn; Keith A. George; Peter P. Geremia; Pierre Mallett, III; Sean Moore; Robert T. Perry; Jonathan R. Rogers |
| Application | US 16/554,252, filed 2019-08-28 (a continuation) |
| Issue date | 2020-01-21 |
| Priority date | 2015-04-17 (chain: US 14/690,302 → US 9,866,576 → US 15/827,477 → US 10,193,917 → US 16/217,720 → US 16/554,252) |
| Status | Active grant (legal status); claims found unpatentable in IPR, affirmed by the CAFC — see litigation note below |
Abstract (verbatim from the patent)
"A packet-filtering device may receive packet-filtering rules configured to cause the packet-filtering device to identify packets corresponding to network-threat indicators. The packet-filtering device may receive packets and, for each packet, may determine that the packet corresponds to criteria specified by a packet-filtering rule. The criteria may correspond to one or more of the network-threat indicators. The packet-filtering device may apply an operator specified by the packet-filtering rule. The operator may be configured to cause the packet-filtering device to either prevent the packet from continuing toward its destination or allow the packet to continue toward its destination. The packet-filtering device may generate a log entry comprising information from the packet-filtering rule that identifies the one or more network-threat indicators and indicating whether the packet-filtering device prevented the packet from continuing toward its destination or allowed the packet to continue toward its destination."
Independent claims — plain-language overview
The patent has three independent claims (claims 1, 8, and 15), which are method, apparatus, and computer-readable-media counterparts of the same invention. (Per IPR2021-01147 records, claims 1–21 were challenged, indicating 21 total claims; the independent claims at 1, 8, and 15 are confirmed by the RPX claim listing. I did not retrieve the verbatim full text of claims 8 and 15, so their summaries below are based on the partial text recovered plus their parallel structure with claim 1.)
Claim 1 (method): A packet-filtering device receives packet-filtering rules keyed to network-threat indicators supplied by one or more independent network-threat-intelligence providers. It receives a plurality of packets (a first and a second packet). Responsive to determining that the first packet satisfies a first rule (based on the threat indicators specified by that rule), it applies an operator that allows the first packet to continue toward its destination and communicates information identifying the indicators and data that the packet was allowed. It then receives an update to at least one rule, modifies the operator to prevent (block) packets corresponding to those indicators, and — responsive to determining that the second packet satisfies the same rule — prevents the second packet from continuing and communicates data that it was prevented. In short: rule-driven allow → user/rule update flips the operator to block → subsequent matching packets are blocked, with both outcomes reported.
Claim 8 (packet-filtering device): A packet-filtering device comprising at least one processor and memory storing instructions that cause the device to perform essentially the same sequence as claim 1 — receiving the threat-indicator-based rules, allowing the first matching packet with communication of the indicators and allow-indication, receiving an update, modifying the operator, and preventing the second matching packet with communication of the block-indication. This is the system/apparatus embodiment of claim 1.
Claim 15 (computer-readable media): One or more non-transitory computer-readable media storing instructions that, when executed by processors of a packet-filtering device, cause the device to perform the same allow-then-reconfigure-to-block-and-report sequence. This is the software/storage-medium embodiment of claim 1.
Litigation / CAFC docket note (important caveats)
- CAFC Case 23-1654 — Centripetal Networks, LLC v. Palo Alto Networks, Inc.: On October 31, 2024, the Federal Circuit affirmed the PTAB's final written decision in IPR2021-01147 (instituted Feb. 10, 2022; final decision Feb. 9, 2023) finding the challenged claims of the '028 patent (and related '126 patent) unpatentable as obvious over the Sourcefire 3D System user guide. The CAFC rejected Centripetal's "responsive to" claim-construction argument. Multiple secondary sources describe the '028 patent as thereby unpatentable/unenforceable.
- 2026 CAFC dockets: I searched the CAFC's published opinions/orders for 2026. The 2026 Centripetal entries found — 24-1406 (v. Keysight, PTO, opinion 04/23/2026), 24-1416 (v. ITC, opinion 04/23/2026), and 24-2097 (v. Cisco, opinion 04/29/2026) — concern other Centripetal patents (e.g., the '526 patent), not 10542028. I found no 2026 CAFC docket entry specifically tied to patent 10542028. The most recent appellate disposition involving this patent remains the Oct. 31, 2024 affirmance in 23-1654. (Note: a DocketAlarm entry showed an appeal reactivation under FRAP 4(a)(4), appeal no. 25-1167, in E.D. Va. case 2:21-cv-00137 — the 2021 Palo Alto Networks suit in which '028 was one of 13 asserted patents — but I could not confirm from the search results whether that appeal involves the '028 patent specifically.)
Confidence notes
- High confidence: title, assignee, inventors, application/issue dates, priority chain, abstract, independent-claim structure (1, 8, 15), and the 2024 CAFC affirmance of unpatentability.
- Moderate/uncertain: the exact total claim count (21 per IPR records) and the verbatim text of claims 8 and 15 (only partial text retrieved); and whether any 2026 CAFC docket activity exists for this specific patent — none surfaced in my searches.
Generated 8/30/2026, 6:45:50 PM
Cases on file (3)
Group view →Specific litigation cases in our database that name US patent 10542028. The free-form analysis below may also discuss cases beyond this list.
- Palo Alto Networks, Inc. v. Centripetal Networks, Inc.filed Jul 19, 2021IPR2021-01147Patent Trial and Appeal Board (USPTO)terminated Feb 9, 2023Final Written Decision; claims 1-21 found unpatentable; affirmed on appeal
Defendants: Centripetal Networks, Inc.
- Centripetal Networks, Inc. v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137 (orig. 1:21-cv-00313)U.S. District Court for the Eastern District of Virginia, Norfolk Division (originally Alexandria Division)Judgment as a matter of law granted in part and denied in part; new trial denied; dismissed in part as of October 3, 2024
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10785266, 10567343, 10091246, 10567437, 10530903, 10567413, 10659573, 10757126, 10503899, 10735380, 10749906, 10931797
- Centripetal Networks, LLC v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137U.S. District Court for the Eastern District of Virginia, Norfolk Divisionpost-judgment proceedings/appeal ongoing
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10749906, 10091246, 10503899, 10530903, 10567343, 10567413, 10567437, 10659573, 10735380, 10757126, 10785266, 10931797
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
Known Litigation Involving U.S. Patent No. 10,542,028 ("Rule-Based Network-Threat Detection")
Based on searches of Unified Patents, Docket Alarm, PACER-derived sources, Justia, UniCourt, Patexia, and IPWatchdog, the following litigation matters involve U.S. Patent No. 10,542,028 (the "'028 patent," owned by Centripetal Networks, Inc./LLC). Note: I could not confirm every case's current docket status, so I flag uncertainties explicitly.
1. Centripetal Networks, Inc. v. Palo Alto Networks, Inc., No. 2:21-cv-00137 (E.D. Va., Norfolk Division)
- Plaintiff: Centripetal Networks, Inc. (later Centripetal Networks, LLC)
- Defendant: Palo Alto Networks, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Virginia, Norfolk Division
- Case number: 2:21-cv-00137 (with magistrate judge designation 2:21-cv-00137-RCY-RJK; District Judge Elizabeth W. Hanes, Magistrate Judge Lawrence R. Leonard)
- Filing date: March 12, 2021
- Patents asserted: The '028 patent is one of thirteen patents asserted (Docket Alarm lists 10091246; 10503899; 10530903; 10542028; 10567343; 10567413; 10567437; 10659573; 10735380; 10749906; 10757126; 10785266; 10931797)
- Cause: 35 U.S.C. § 271 patent infringement
- Status: Pending/active district court litigation, but directly impacted by the PTAB IPR and CAFC appeal below (claims of the '028 patent were found unpatentable). I could not confirm the current disposition of the district court docket from the sources available.
2. Centripetal Networks, Inc. v. Palo Alto Networks, Inc., No. 1:21-cv-00313 (E.D. Va., Alexandria Division)
- Plaintiff: Centripetal Networks, Inc.
- Defendant: Palo Alto Networks, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Virginia, Alexandria Division
- Case number: 1:21-cv-00313
- Filing date: March 12, 2021 (complaint for patent infringement filed the same day as the Norfolk case)
- Status: This case number appears on the Google Patents litigation list for the '028 patent and in Docket Alarm exhibits referencing "Activity in Case 1:21-cv-00313 VAED – Centripetal Networks, Inc. v. Palo Alto Networks, Inc." I could not definitively determine from available sources whether 1:21-cv-00313 is a separate parallel case or the original Alexandria Division filing that was later transferred and renumbered as 2:21-cv-00137 (Norfolk). I recommend PACER to confirm.
3. Palo Alto Networks, Inc. v. Centripetal Networks, Inc., IPR2021-01147 (P.T.A.B.)
- Petitioner: Palo Alto Networks, Inc.
- Patent Owner: Centripetal Networks, Inc.
- Jurisdiction: Patent Trial and Appeal Board (USPTO)
- Case number: IPR2021-01147
- Filing date: July 19, 2021
- Institution decision: February 10, 2022
- Final written decision: February 9, 2023 (Administrative Judges Lynne E. Pettigrew [writing], Kevin F. Turner, Brian J. McNamara)
- Scope: Challenged claims 1–21 of the '028 patent; the Board found the challenged claims unpatentable as obvious (over the Sourcefire 3D System user guides and related prior art)
- Status: Final Written Decision — Appealed to the Federal Circuit (see below). The IPR outcome invalidating the claims is the operative result after affirmance.
4. Centripetal Networks, Inc. v. Palo Alto Networks, Inc., No. 23-1654 (Fed. Cir.)
- Appellant: Centripetal Networks, Inc.
- Appellee: Palo Alto Networks, Inc.
- Jurisdiction: U.S. Court of Appeals for the Federal Circuit
- Case number: 23-1654 (also cited as 2023-1654)
- Subject: Appeal of the PTAB's Final Written Decision in IPR2021-01147
- Outcome: Affirmed. The Federal Circuit issued its ruling on October 31, 2024, affirming the PTAB's obviousness determinations that the '028 patent claims are unpatentable. Per IPWatchdog, the CAFC found substantial evidence supporting the Board's claim constructions (including the "responsive to" limitation) and rejected Centripetal's remaining arguments. The CAFC's judgment order states: "THIS CAUSE having been considered, it is ORDERED AND ADJUDGED: AFFIRMED."
- Status: Final at the Federal Circuit level; no further appeal identified in my search results.
5. Centripetal Networks, Inc. v. LookingGlass Cyber Solutions, Inc., et al., No. 1:21-cv-01051 (E.D. Va., Alexandria Division) → transferred to No. 3:21-cv-00597 (E.D. Va., Richmond Division)
- Plaintiff: Centripetal Networks, Inc.
- Defendants: LookingGlass Cyber Solutions, Inc.; Gilman Louie; Alsop Louie Management LLC; Alsop Louie Capital 2, L.P.; Alsop Louie Partners 2, LLC
- Jurisdiction: U.S. District Court for the Eastern District of Virginia (filed in Alexandria Division as 1:21-cv-01051; transferred intradistrict to the Richmond Division on September 16, 2021, and renumbered 3:21-cv-00597; Judge David J. Novak)
- Filing date: September 14, 2021
- Cause: Patent infringement (35 U.S.C. § 271), plus breach-of-contract and fiduciary-duty claims
- Patents asserted: The '028 patent is among those asserted (IPWatchdog's filing roundup lists 10542028, 10757126, 10785266, 10735380, 10567437)
- Status: Closed / disposed (UniCourt: "Disposed – Other Disposed"; ExParte: "Closed"). I could not confirm the precise disposition (e.g., settlement vs. dismissal) from the sources available.
Summary Table
| Case | Plaintiff(s) | Defendant(s) | Court | Case No. | Filed | Status |
|---|---|---|---|---|---|---|
| Centripetal v. Palo Alto Networks | Centripetal Networks, Inc./LLC | Palo Alto Networks, Inc. | E.D. Va. (Norfolk) | 2:21-cv-00137 | 2021-03-12 | District litigation; impacted by IPR invalidation |
| Centripetal v. Palo Alto Networks | Centripetal Networks, Inc. | Palo Alto Networks, Inc. | E.D. Va. (Alexandria) | 1:21-cv-00313 | 2021-03-12 | Relationship to 2:21-cv-00137 unconfirmed |
| Palo Alto Networks v. Centripetal (IPR) | Palo Alto Networks (petitioner) | Centripetal (patent owner) | P.T.A.B. | IPR2021-01147 | 2021-07-19 | Final Written Decision 2023-02-09 — claims 1–21 unpatentable |
| Centripetal v. Palo Alto Networks (appeal) | Centripetal (appellant) | Palo Alto (appellee) | Fed. Cir. | 23-1654 | (appeal of IPR) | Affirmed 2024-10-31 |
| Centripetal v. LookingGlass et al. | Centripetal Networks, Inc. | LookingGlass Cyber Solutions, Inc.; Gilman Louie; Alsop Louie entities | E.D. Va. (Alexandria → Richmond) | 1:21-cv-01051 → 3:21-cv-00597 | 2021-09-14 | Closed/Disposed |
Caveats
- Case 1:21-cv-00313 vs. 2:21-cv-00137: I could not conclusively determine from my searches whether these are two separate complaints or the same case renumbered after an intradistrict transfer. Both were filed March 12, 2021, against Palo Alto Networks. Verify via PACER.
- District court statuses: The final disposition of the Palo Alto district court cases (e.g., whether they were stayed pending the IPR and then dismissed after the CAFC affirmance) was not confirmed from the sources I could access. The CAFC affirmance (Oct. 31, 2024) found the '028 claims unpatentable, which effectively neutralizes assertion of this patent.
- Not included: Cases involving other Centripetal patents (e.g., Centripetal v. Cisco, Centripetal v. Keysight involving U.S. Patent 10,284,526) are not litigation over the '028 patent and were excluded per your instruction to avoid similar-but-different numbers.
Generated 8/30/2026, 6:46:00 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Palo Alto Networks, Inc.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
Proceedings overview
Web research confirms one AIA trial proceeding on US 10,542,028: IPR2021-01147, which went all the way to a Final Written Decision finding all 21 claims (1–21) unpatentable, affirmed by the Federal Circuit on 2024-10-31. Status breakdown: 0 active / 0 settled / 0 institution-denied / 21 claims invalidated (100% of the patent) / 0 claims sustained. The bottom-line defensive posture is as strong as it gets: every claim of the '028 patent has been canceled on the merits and the cancellation is final after appeal — if a demand letter cites US 10,542,028, the patentee has no viable case, and continued assertion post-affirmance invites sanctions.
⚠️ Data discrepancy flagged: The structured USPTO ODP block states "no AIA trial proceedings on file." That appears to be an ODP indexing gap rather than the true state of the world. Multiple independent sources — Patexia, Docket Alarm, USPTO PTAB E2E, the Federal Circuit's own opinion, and the Unified Patents portal (which is the data source labeled on Google Patents, not the petitioner) — all document IPR2021-01147 as a real, fully adjudicated proceeding. Per your operating rules, I've preferred the live web-search results. Also note the Google Patents "Petitioner: Unified Patents" label refers to the litigation-data aggregator that supplied the metadata; the actual petitioner was Palo Alto Networks, Inc.
IPR2021-01147 — Palo Alto Networks, Inc. v. Centripetal Networks, LLC
- Type: Inter Partes Review
- Filed: 2021-07-19
- Status: Final Written Decision — proceeding terminated 2023-02-09 (Paper 40). Plain-English gloss: fully adjudicated on the merits; all challenged claims held unpatentable; no settlement.
- Judge panel: FWD panel per Patexia — Lynne E. Pettigrew (author), Kevin F. Turner, Brian J. McNamara. (Other APJs appear on the docket across institution and interim phases, including Jon Jurgovan, Steven Amundson, Aaron Moore, and Stacey White.)
- Petition grounds: All 21 claims (1–21) challenged under 35 U.S.C. § 103 as obvious over the Sourcefire 3D System User Guide, alone or in combination with a second reference that was "not at issue on appeal." This was a single-reference obviousness attack: Sourcefire's 3D Sensor with its IPS component and customizable "intrusion rules" that log "intrusion events."
- Institution decision: Instituted on 2022-02-10 (Decision Granting Institution under 35 U.S.C. § 314). The Board adopted a claim construction of "responsive to" that permits the applying/communicating steps to be triggered by a rule match based on network-threat indicators in combination with other criteria — rejecting Centripetal's position that the steps must be triggered by network-threat indicators alone. The CAFC later found the Board "did construe 'responsive to' in the respect at issue" despite some conflation of construction and application.
- Final Written Decision: Issued 2023-02-09, Paper 40, Palo Alto Networks, Inc. v. Centripetal Networks, LLC, No. IPR2021-01147, 2023 WL 1861774 (P.T.A.B. Feb. 9, 2023). Verdict: all challenged claims — claims 1 through 21, i.e., every claim in the patent — are unpatentable under § 103. No claim survived; no substitute claims were at issue. The Board's core finding, as quoted in the CAFC opinion: "Sourcefire's 3D Sensor makes a 'determination' that a packet satisfies the rule 'based on' one or more of those source and destination IP addresses (i.e., the claimed network-threat indicators), as required by [the 'responsive to'] limitation," and "the 'applying' step is 'responsive to' a determination that the packet satisfies the rule." The Board also rejected Centripetal's secondary-considerations evidence and declined to give substantial weight to its objective indicia of non-obviousness.
- Settlement / termination: No settlement. The case was decided on the merits; termination on 2023-02-09 was entry of the FWD, not a joint motion to terminate.
- Appeal: Yes — affirmed. Centripetal appealed; docketed as Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 23-1654 (Fed. Cir.), consolidated with No. 23-1655 (the parallel appeal of IPR2021-01148 on the related '126 patent). Panel: Lourie, Taranto, and Stark. Issues on appeal: (1) whether the Board impermissibly declined to construe "responsive to"; (2) whether Sourcefire teaches the "responsive to" limitation; (3) the meaning of "comprising" (dependent on the first issue); and (4) PAN's collateral-estoppel argument, which the court declined to reach. Disposition: affirmed, 2024-10-31 (nonprecedential) — "the Board had substantial evidence to find that Sourcefire taught the limitation, and its determination of obviousness is correct on that basis." The mandate is now final; under 35 U.S.C. § 318(b) the Director is required to cancel the claims finally determined unpatentable, so claims 1–21 should now be canceled on the face of the patent.
- Defensive value: Total. Every claim of the '028 patent has been held unpatentable, and that holding is final after a CAFC affirmance. Any infringement theory built on any claim 1–21 of this patent is dead; continuing to assert it post-affirmance is sanction-bait. This is the strongest possible IPR outcome for a defendant.
Strategic summary
Claim status for US 10,542,028:
- CANCELED / held unpatentable (final): claims 1–21 — all of them, via IPR2021-01147, affirmed by the Federal Circuit on 2024-10-31.
- SUSTAINED: none.
- UNTESTED: none. The entire patent was challenged, and the entire patent fell. There is no remaining enforceable claim in the '028 patent. (Separate family members — e.g., 10,757,126, 10,567,413, 9,413,722, 10,284,526 — have their own IPR histories and, in several cases, their own invalidations; a demand letter citing a different family member needs a separate claims-level check, but the '028 patent itself is exhausted.)
Estoppel landscape (§ 315(e)(2)): Palo Alto Networks and its privies are estopped from raising in any later PTO or district-court proceeding any § 102/§ 103 ground they raised or reasonably could have raised during IPR2021-01147 — which effectively locks PAN out of Sourcefire-based and closely-related obviousness attacks on this family. But estoppel binds only the petitioner and privies. A new defendant is not estopped and can deploy any prior art, including the Sourcefire 3D System User Guide — and can do so more cheaply, because the Board's findings on what Sourcefire teaches are already made and were affirmed. Indeed, PAN argued at the CAFC that collateral estoppel (issue preclusion) bars Centripetal from relitigating the Board's Sourcefire findings against anyone; the CAFC did not need to reach that argument, but it remains a live and powerful tool for later defendants to press in district court.
Pattern signals: This is one leg of a coordinated Palo Alto Networks IPR campaign: PAN filed IPR2021-01147 ('028), IPR2021-01148 ('126), and IPR2021-01149 ('413) on the same day (2021-07-19), all on the Sourcefire guide, after Centripetal sued PAN in the Eastern District of Virginia (2:21-cv-00137) asserting a dozen patents. The patent owner, Centripetal, is a serial litigant that has appealed IPR losses to the Federal Circuit repeatedly (23-1654/23-1655, 24-2246, and others) and has lost those appeals almost uniformly — the CAFC affirmed the '028/'126 invalidations and, in 2026, the '526 invalidation as well. Unified Patents appears here only as the litigation/PTAB data aggregator cited on Google Patents — it is not a petitioner or party. The takeaway: this is a well-worn battlefield where the PTAB and CAFC have consistently sided with petitioners, and the '028 patent specifically is fully spent.
Recommended next steps
- If you are a defendant and the demand letter cites the '028 patent, move immediately on the final invalidity. Link explicitly to the Final Written Decision — Palo Alto Networks, Inc. v. Centripetal Networks, LLC, No. IPR2021-01147, Paper 40, 2023 WL 1861774 (P.T.A.B. Feb. 9, 2023), available via USPTO PTAB E2E (search "IPR2021-01147") — and to the affirmance, Centripetal Networks, LLC v. Palo Alto Networks, Inc., Nos. 23-1654, 23-1655 (Fed. Cir. Oct. 31, 2024) (CourtListener). The CAFC's disposition: "We affirm." Quote the FWD's § 103 holding on all of claims 1–21, note the mandate is final, and demand withdrawal of the '028 allegations. If the patentee persists after the CAFC affirmance, pursue Rule 11 / fee-shifting — assertion of a claim finally canceled on appeal is the paradigm case for sanctions.
- Confirm the certificate of cancellation on the USPTO Patent Center/assignment record for the '028 patent. With appeal rights exhausted, the Director's certificate canceling claims 1–21 should already be (or imminently be) recorded under 35 U.S.C. § 318(b) — cite that certificate as dispositive.
- Check the demand letter's other patents. If the letter also asserts family members (10,757,126; 10,567,413; 9,866,576; 10,193,917; 9,413,722; 10,284,526; and others), run the same PTAB check on each: several are already invalidated (e.g., '722 in IPR2018-01760, '126 in IPR2021-01148, '413 in IPR2021-01149, '526 in IPR2022-01525), with CAFC affirmances. The '028 patent, however, is a closed chapter.
- No pending milestones — there are no active proceedings on the '028 patent, so there is no institution deadline, oral-hearing date, or FWD due date to track. The only live question is enforcement behavior (and fee exposure) if Centripetal continues to assert a fully invalidated patent.
Generated 8/30/2026, 6:46:39 PM
Ownership chain (3)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
2017-04-17 · Security Agreement
Centripetal Networks, Inc.Douglas A. Smith
securitization
2022-12-30 · recorded 2023-01-20 · Change of Name
Centripetal Networks, Inc.Centripetal Networks, Inc.
change of name only
? · Assignment
Ahn, David K.; George, Keith A.; Geremia, Peter P.; Mallett, Pierre, III; Moore, Sean; Perry, Robert T.; Rogers, Jonathan R.Centripetal Networks, Inc.
acquisition
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll reconstruct the assignment record for US 10542028 using the USPTO Assignment Center data and cross-references. Let me search for the recorded assignments.
Let me dig for the specific reel/frame numbers and the recording correspondent.
Let me search for the specific reel/frame numbers on the '028 patent's assignment records.
Assignment / Chain-of-Title Reconstruction — US 10,542,028 B2
⚠️ Data-access caveat up front. I retrieved the substance of the recorded chain from corroborating records (Google Patents legal events derived from the USPTO assignment database; Centripetal's own filings in IPR2021-01147/01182 and in E.D. Va. 2:22-cv-00002 and 2:18-cv-00094; and the CAFC Rule 26.1 disclosure in 23-1654), but I was cut off before I could pull the individual reel/frame numbers from assignmentcenter.uspto.gov. Every entry below states plainly whether the reel/frame is verified or not. I have not invented reel/frame numbers. Verify each at the Assignment Center search page: https://assignmentcenter.uspto.gov/ (search by patent number 10542028).
One structural point that shapes everything below: US 10,542,028 issued from application 16/554,252, which is a continuation. The patent's title traces back to an assignment recorded against the original parent application 14/690,302 (filed 2015-04-17). Continuations are covered by the parent's recorded assignment, so the number of post-issuance recordings on the '028 patent itself is small — which is itself a finding here.
Inventors
Seven named inventors (all appearing as assignors of record in the USPTO assignment event for this family):
| # | Inventor | Residence of record | Employer at filing |
|---|---|---|---|
| 1 | David K. Ahn | Winston-Salem, NC | Centripetal Networks, Inc. |
| 2 | Keith A. George | Not confirmed | Centripetal Networks, Inc. (assignor of record) |
| 3 | Peter P. Geremia | Portsmouth, NH | Centripetal Networks, Inc. |
| 4 | Pierre Mallett, III | Herndon, VA | Centripetal Networks, Inc. |
| 5 | Sean Moore | Hollis, NH | Centripetal Networks, Inc. |
| 6 | Robert T. Perry | Ashburn, VA | Centripetal Networks, Inc. |
| 7 | Jonathan R. Rogers | Not confirmed | Centripetal Networks, Inc. (assignor of record) |
- Residences for Ahn, Geremia, Mallett, Moore, and Perry are confirmed from the patent file-history records reproduced in the PTAB petitions (Ex. 2025 / Ex. 1002 excerpts showing "David K. Ahn, Winston-Salem, NC; Peter P. Geremia, Portsmouth, NH; Pierre Mallett III, Herndon, VA; Sean Moore, Hollis, NH; Robert T. Perry, Ashburn, VA").
- The underlying application was filed with "Applicant Type: Assignee — Organization Name: Centripetal Networks, Inc.", i.e., all seven inventors were under an obligation to assign to Centripetal at filing. Centripetal was a small, geographically distributed cybersecurity firm (engineering staff in NH, VA, and NC), not a large corporate R&D campus.
- Unusual-pattern check: No evidence of the inventors departing the original assignee within 12 months of filing, and no evidence of a pre-fire-sale inventor exodus. The inventors remained tied to Centripetal through the 2021–2023 assertion campaigns (the CAFC Rule 26.1 certificate in 23-1654 confirms "Centripetal Networks, LLC has no parent corporation and no publicly held corporation owns 10% or more of its stock" — a private, closely held company). Not present.
Original assignee
Centripetal Networks, Inc. (Delaware corporation), Reston/Herndon, VA. On 2022-12-30 it converted under Delaware law to Centripetal Networks, LLC — the same legal entity by operation of law, not a sale.
- Primary line of business: network security / threat-intelligence-based packet filtering and DNS protection; the company commercialized its technology under the CleanINTERNET® product line (threat-intelligence-enriched network filtering). It is a real operating company, not a licensing shell.
- Product embodying the claims: Centripetal shipped commercial network-security product and marketed the same rule/operator/logging architecture described in the '028 specification. It also litigated as a practicing entity against direct market competitors.
- Current status: Operating (private, venture-backed). Not acquired, not dissolved, not in bankruptcy. Its patents have been judicially invalidated (see below), but the corporate entity is live and continued filing patents through 2025 (USPTO PatentsView shows ~119 granted patents, 2015–2025, under the "Centripetal Networks, LLC" assignee record).
- Public-company/SEC cross-reference: none applicable — Centripetal is privately held, so there are no 10-K/8-K assignment disclosures to cross-check.
Assignment timeline
Chronological. Reel/frame numbers were not retrieved for any entry — flagged each time.
2015-04-17 (application filing) / recorded date not confirmed — Reel NOT RETRIEVED
- Conveyance: Assignment of assignors' interest (inventors → company)
- Assignor: Ahn, David K.; George, Keith A.; Geremia, Peter P.; Mallett, Pierre, III; Moore, Sean; Perry, Robert T.; Rogers, Jonathan R.
- Assignee: Centripetal Networks, Inc.
- Correspondent: Banner & Witcoff, Ltd., USPTO Customer No. 22907, 1100 13th Street NW, Suite 1200, Washington, DC 20005-4051 (correspondence address of record for this patent family throughout prosecution; see "repeat correspondent" note below; the recorded "correspondent" field on the assignment cover sheet itself was not retrieved)
- Context: Routine original acquisition — employment/founder assignment to the operating company at filing.
- ⚠️ Discrepancy to flag: Google Patents' legal-events table carries this inventor→Centripetal event with a 2023-01-20 date, the same date as the change-of-name recording. That is either (a) a Google indexing artifact, or (b) an indication that a confirmatory / late-recorded assignment covering the family was lodged in January 2023 (contemporaneous with Centripetal's ownership-cleanup activity during the Cisco/Keysight/Palo Alto litigation). The execution date and true recording date are unverified. This is the single most important open item in the chain; I will not assert which reading is correct.
2017-04-17 (executed) / recorded date not confirmed — Reel NOT RETRIEVED (USPTO EPAS submission ID PAT4374169)
- Conveyance: Security interest (Patent and Trademark Security Agreement) — not a transfer of title
- Assignor / Grantor: Centripetal Networks, Inc.
- Assignee / Grantee: Douglas A. Smith, an individual, 12770 Merit Drive, Suite 800, Dallas, TX 75251
- Correspondent: not named in the retrieved record; the document carries a Boston-area fax number (617) 951-8736 (likely lender-side counsel — firm not identified, do not infer)
- Context: Securitization / venture-debt collateralization — a first-priority security interest over 14 patent properties granted to secure a Note and Warrant Purchase Agreement. This is classic venture-lender collateral, not an NPE roll-up.
- ⚠️ Material gap: I could not confirm whether the '028 patent (then application 14/690,302) was among the 14 encumbered properties. The only property number visible in the retrieved excerpt is application 14/625,486. I am not asserting the '028 was encumbered — only that Cenftripetal granted a portfolio-level security interest on that date. Likewise, no release of this security interest was found in my searches; whether it remains of record or was released without a recorded release is unclear.
- Note the date coincidence: executed exactly two years to the day after the '028's 2015-04-17 filing. That is a date match, not evidence of linkage — treat as coincidence unless the assignment record proves otherwise.
2020-01-21 — Patent grants (US 10,542,028 B2). No assignment recorded at issuance; title remained with Centripetal Networks, Inc.
2022-12-30 (effective) / recorded at USPTO 2023-01-20 per Google Patents legal events — Reel NOT RETRIEVED
- Conveyance: Change of name (Delaware statutory conversion; the USPTO event text reads "CHANGE OF NAME (SEE DOCUMENT FOR DETAILS)")
- Assignor: Centripetal Networks, Inc.
- Assignee: Centripetal Networks, LLC
- Correspondent: Banner & Witcoff, Ltd. (Customer No. 22907) — same prosecution correspondence address of record (inferred; the recorded correspondent field was not retrieved)
- Context: Internal reorganization / change of name only. Per Centripetal's Notice of Name Change filed in E.D. Va. 2:22-cv-00002 (Dkt. 55) and 2:18-cv-00094 (Dkt. 673): the Delaware certificates of conversion and formation were filed 2022-12-30, and "Centripetal has converted from a Delaware corporation to a Delaware limited liability company, Centripetal Networks, LLC, which remains the same entity by operation of law" under Del. Code Ann. tit. 6, § 18-214. The same explanation appears in Centripetal's Modification of Notice of Real Party in Interest in IPR2022-00182 (filed 2023-01-19), which states: "Due to a change of corporate name on December 30, 2022, the Real Party-In-Interest for the Patent Owner has changed from: Centripetal Networks, Inc. … To: Centripetal Networks, LLC … Patent Owner will be filing a recordation of the name change for the patent at the USPTO shortly."
- This is the last recorded event in the chain as of today. There is no assignment to any third party — no sale, no licensing vehicle, no defensive aggregator.
⚠️ Correspondent field: For every entry above, the recorded correspondent as shown on the USPTO assignment cover sheet was not retrieved. What I can confirm is the correspondence address of record for the '028 patent family: Banner & Witcoff, Ltd., Customer No. 22907, 1100 13th Street NW, Suite 1200, Washington, DC 20005-4051, with Kirk A. Sigmon (Reg. No. [not retrieved]) appearing as a Banner & Witcoff attorney in the family file history. One unverified lead: a 37 CFR 3.73(c) chain-of-title submission dated 2021-10-05 bearing "/Gregory M. Howison, Reg. #30646/" appears in a PTAB petition record I retrieved — I could not confirm it relates to the '028 patent, so do not treat it as this patent's correspondent.
Timeline diagram
timeline
title Ownership of US 10542028
2015 : Filed by seven inventors
: Assigned to Centripetal Networks Inc
2017 : Security interest granted to Douglas A Smith
2020 : Patent issued
2021 : Suits filed v Palo Alto Networks
: Suit filed v LookingGlass
2022 : Delaware conversion to LLC
2023 : Name change recorded at USPTO
: PTAB invalidates all 21 claims
2024 : CAFC affirms invalidity
NPE / troll-pattern signals
1. Shell-entity transfer — NOT PRESENT.
No transfer from an operating assignee to a licensing-only LLC. The only LLC in the chain is Centripetal Networks, LLC, and the support is explicit that this is a Delaware statutory conversion of the same entity ("remains the same entity by operation of law," Del. Code Ann. tit. 6, § 18-214), effective 2022-12-30, not a sale to a new vehicle. No "IP / Patents / Licensing / Holdings / Ventures" suffix appears. No registered-agent-service address; the recorded address is the company's own 1875 Explorer Street, Suite 900, Reston, VA 20190 (per IPR2022-00182 RPI modification).
2. Known asserter in the chain — NOT PRESENT.
No assignee in the chain matches the classic NPE roster (Acacia, Marathon, Intellectual Ventures, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation Corp, Spangenberg entities). Centripetal Networks is a private operating cybersecurity vendor that asserted against direct competitors. Caveat: at least one commercial directory (PatSnap) characterizes Centripetal as a "cybersecurity patent assertion entity"; that label is a characterization, not an assignment-record finding, and the record evidence (product line, competitor defendants, Rule 26.1 private-company certificate) points to an operating company. Do not treat Centripetal as a listed NPE on this record.
3. Repeat correspondent across the chain — UNclear / weak.
Banner & Witcoff, Ltd. (Customer No. 22907, Washington, DC) is the recurring correspondence address across Centripetal's entire patent family (confirmed in the '028, '903, '266, and '205 family file histories). That is recurrence, but it is prosecution counsel of record for an operating company's whole portfolio — the ordinary case, not the tell of a single lawyer running a stable of anonymous shells. The assignment-cover-sheet correspondent field was not retrieved, so I cannot confirm whether Banner & Witcoff also filed the recordings. A single appearance would not be a finding, and even the recurrence here is consistent with ordinary outside-counsel practice. Marked unclear, not present.
4. Cascading transfers — NOT PRESENT.
There are not multiple consecutive assignments through chained LLCs in under 24 months. The entire recorded chain is: inventors → Centripetal (Inc.) → (same entity) Centripetal (LLC). Total distinct assignee entities: one.
5. Pre-litigation transfer — NOT PRESENT.
No assignment recorded within 6 months before the first infringement suits. The '028 was asserted in March 2021 (E.D. Va. 2:21-cv-00137, Centripetal v. Palo Alto Networks) and September 2021 (E.D. Va. 3:21-cv-00597, Centripetal v. LookingGlass), while the only assignment activity — the name-change recording — is dated 2023-01-20, after the suits. Title was already with the plaintiff at filing. Note the residual risk flagged in §"Assignment timeline" item 1: if the inventor assignment was in fact recorded in 2023-01-20 (rather than merely re-indexed that day), that would raise a standing/ownership-of-record question for the 2021 complaints, not an NPE question. Resolve this before relying on the chain.
6. Bankruptcy fire-sale — NOT PRESENT.
No Chapter 7/11 of any assignor. Centripetal is operating; the CAFC Rule 26.1 certificate (23-1654, filed 2023-09-25) and the ITC investigation 337-TA-1314 (instituted 2022-05-24) both show a going concern. No Kodak/Nortel-style docket.
7. Privateering — NOT PRESENT.
No operating company transferred this patent to an NPE to assert against competitors. Centripetal is the operating company, and it asserted in its own name. (The 2017 Douglas A. Smith security interest is a lender collateral position, not privateering — it conveys no enforcement right, and Smith is an individual note-holder, not an assertion vehicle.)
8. Defensive aggregator — NOT PRESENT.
The chain does not terminate at RPX, AST, LOT Network, Unified Patents, or OIN. (Unified Patents appears on the Google Patents page only as the litigation/PTAB data aggregator supplying metadata — it is not a party, petitioner, or assignee here. The actual IPR petitioner was Palo Alto Networks, Inc.)
Verdict
Operating-company assertion.
The recorded chain for US 10,542,028 is: seven Centripetal inventors → Centripetal Networks, Inc. (original assignment, filing 2015-04-17), then a same-entity Delaware conversion to Centripetal Networks, LLC effective 2022-12-30 and recorded at the USPTO on about 2023-01-20 — with no third-party transfer of any kind. The assignee is a private, closely held operating cybersecurity vendor (CleanINTERNET product line; Rule 26.1 certifies no parent and no ≥10% public holder) that asserted this patent in its own name against direct market competitors — Cisco Systems (2:18-cv-00094), Palo Alto Networks (2:21-cv-00137), and Keysight/LookingGlass — which is the signature of an operating-company assertion, not an NPE roll-up. Conclusion is bounded by two caveats: (i) I could not retrieve the reel/frame numbers or the recorded correspondent for any entry, and (ii) the execution/recording date of the base inventor→Centripetal assignment is unresolved (Google dates it 2023-01-20 alongside the name change, which may be an indexing artifact or may indicate a late/confirmatory recording) — resolve both at the Assignment Center before treating the chain as fully proven. Separately, and regardless of the ownership analysis: all 21 claims of this patent were held unpatentable in IPR2021-01147 and that holding was affirmed on 2024-10-31, so the chain-of-title question is now academic to enforcement value.
Verify at: https://assignmentcenter.uspto.gov/ — patent number search 10542028; also confirm the certificate of cancellation under 35 U.S.C. § 318(b).
Generated 9/21/2026, 2:23:49 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll research US Patent 10542028, its cited prior art, and its claims. Let me start by locating the patent record and its citation list.
I have good context on the litigation history (IPR2021-01147 / IPR2021-01520 by Palo Alto Networks, affirmed by the Federal Circuit in October 2024, with the Sourcefire 3D System User Guide as the primary reference). Now let me retrieve the exact "References Cited" list printed on the face of US10542028B2, and the IPR decisions identifying applied prior art.
I need the precise citation list printed on the face of the '028 patent. Let me try to retrieve the Google Patents citation section and the USPTO record directly.
I have reached the search limit for this session, but I have enough verified information from the USPTO-facing records, the PTAB IPR docket, and the Federal Circuit opinion to give you a grounded report. I'll be explicit about what I could and could not verify.
Prior-Art Analysis — U.S. Patent No. 10,542,028 B2 ("Rule-Based Network-Threat Detection")
1. Patent identification and status (verified)
| Field | Value |
|---|---|
| Patent number | US10542028B2 (interpreted literally, as instructed) |
| Title | Rule-based network-threat detection |
| Inventors | David K. Ahn; Keith A. George; Peter P. Geremia; Pierre Mallett, III; Sean Moore; Robert T. Perry; Jonathan R. Rogers |
| Assignee | Centripetal Networks, Inc. (now Centripetal Networks, LLC) |
| Application / filing | US16/554,252, filed 2019-08-28 (continuation) |
| Priority date | 2015-04-17 (chain: 14/690,302 → US9,866,576 → 15/827,477 → US10,193,917 → 16/217,720 → 16/554,252) |
| Grant date | 2020-01-21 |
| Claims | 21 claims — independent claim 1 (method), claim 8 (device), claim 15 (non-transitory computer-readable media); dependents 2–7, 9–14, 16–21 |
| Status | "Active" in USPTO records, but all 21 claims were found unpatentable in IPR2021-01147 (PTAB Final Written Decision Feb. 9, 2023) and the Federal Circuit affirmed on Oct. 31, 2024 (Case 23-1654) — see below. |
Sources: https://patents.google.com/patent/[US10542028](/patent/US10542028)/en ; https://insight.rpxcorp.com/patent/US10542028B2 ; https://services.patexia.com/lawsuits/Palo-Alto-Networks-Inc-v-Centripetal-Networks-Inc-id-[153607](/patent/153607) ; https://ipwatchdog.com/2024/10/31/cafc-affirms-several-ptab-findings-centripetals-network-security-patent-claims-obvious/id=[182713](/patent/182713)/
2. Important verification caveat — the face-of-patent "References Cited" list
I was not able to retrieve the complete examiner-generated "References Cited" section printed on the face of US10542028B2 (the USPTO Patent Center record was not directly accessible through the search tools available to me, and the Google Patents text of the '028 patent does not reproduce its citation page).
I want to flag one trap explicitly: a 16-reference citation list appears on Google Patents pages for the later family application US20220232028A1 (search result for US20220232028A1/en#16). That list cannot be the '028 patent's citation list — it includes references published after the '028's 2020-01-21 issue date (e.g., US10659480B2, published 2020-05-19; US20170339192A1, published 2017-11-23). I will not present that list as the '028's cited references, per my instruction not to fabricate.
What I can verify with high confidence is the prior art that was actually applied against the '028 patent in the adversarial record — the IPR proceedings and the Federal Circuit affirmance — which is the most legally meaningful "prior art" for this patent today.
3. Most relevant prior art (verified from the IPR / Federal Circuit record)
3.1 Sourcefire 3D System User Guide (and related Sourcefire 3D System installation guides) — primary reference
- Citation form (NPL): Sourcefire 3D System User Guide (Sourcefire, Inc.; Sourcefire was later acquired by Cisco Systems). The IPR record also relies on the Sourcefire 3D System installation guides. Exact edition/version and publication date were not confirmed in my searches — I will not guess a version number or a date.
- Filing/publication date: Not confirmed from my searches. NPL predates the '028's 2015-04-17 priority date (Sourcefire 3D System documentation is from the late-2000s/early-2010s product generation); treat the exact date as unverified.
- Brief description (as found by the PTAB and Federal Circuit): The Sourcefire 3D System is an enterprise threat/intrusion-management system. A "3D Sensor" is placed at the network boundary (the installation guides describe placement between a border router and a firewall). The system analyzes traffic under intrusion rules whose rule headers specify source/destination IP addresses — which the Board expressly found to be "network-threat indicators" — plus optional additional conditions. When a packet satisfies a rule, the sensor applies a rule action/operator (e.g., alert, drop, pass/allow) and communicates event/alert information. The Board found this disclosed the claimed "determination," "applying," and "communicating" steps, including the "responsive to" limitation, and that Sourcefire's rule-update capability addresses rule reconfiguration. (Fed. Cir., Centripetal Networks, LLC v. Palo Alto Networks, Inc., Case 23-1654, Oct. 31, 2024; PTAB IPR2021-01147, FWD Feb. 9, 2023.)
- Claims it was applied against: All claims — the IPR petition challenged claims 1–21, the PTAB instituted on all, and the Final Written Decision found them unpatentable. The Board's holding was obviousness under 35 U.S.C. § 103 over Sourcefire, affirmed by the Federal Circuit (substantial evidence supporting the "responsive to" construction and the underlying factual findings).
- Potential § 102 anticipation analysis: On the record as decided, the adjudicated ground was § 103, not § 102 anticipation. A § 102 anticipation case would require Sourcefire alone to disclose every limitation of a claim in the claimed arrangement. The Board's decision is consistent with Sourcefire alone disclosing most of claim 1's elements — (a) receiving packet-filtering rules that identify packets corresponding to network-threat indicators (IP addresses), (b) receiving packets (first and second), (c)–(d) determining a packet satisfies a rule and applying an allow-type operator, (e) communicating information identifying the indicators and that the packet was allowed, (f)–(g) receiving a rule/operator update reconfiguring the device to block, and (h)–(j) blocking a later matching packet and communicating that it was prevented. The element most vulnerable to an anticipation challenge is claim 1's recitation that the indicators come from "network-threat-intelligence reports supplied by one or more independent network-threat-intelligence providers" — Sourcefire's own rule sets were vendor-supplied, but whether that satisfies the "independent providers" recitation is precisely the kind of dispute the Board resolved under its § 103 rationale rather than as a pure § 102 single-reference question.
3.2 Macaulay — US 2015/0207809 A1 (secondary reference)
- Citation form: U.S. Patent Application Publication No. US20150207809A1, inventor/applicant "Macaulay" (exact title not confirmed in my searches; do not want to fabricate it).
- Publication date: ~2015-07-23 (consistent with the publication-number pattern; treat as high-confidence but not independently re-verified). It is a printed publication well before the '028's 2015-04-17 priority date? — No: a July 2015 publication is after the 2015-04-17 priority date, so it is not § 102(a)(1) prior art as of the earliest priority date on its face; it was nevertheless used in the IPR as a § 103 secondary reference, meaning the Board treated it as prior art (a § 102(b)/(a)(2) analysis would turn on the specific effective-filing-date facts of the application, which I could not verify).
- Brief description (per the Federal Circuit's opinion in the companion '413 case, Case 23-1655): A real-time system for information sharing on threat agents that assigns reputation scores reflecting the degree to which network traffic has been compromised. This is directly relevant to the "network-threat-intelligence reports supplied by … independent network-threat-intelligence providers" and to rule-update/indicator-distribution aspects of the '028 claims.
- Claims it potentially anticipates: In the '028 IPR, Macaulay was part of the evidentiary record (the PTAB's '028 ground was Sourcefire-based; Macaulay was the combination reference in the parallel '413-patent IPR). Macaulay alone does not disclose the packet-filtering-device rule/operator/blocking mechanics of claims 1, 8, and 15, so on its own it is unlikely to anticipate any independent claim; it is more relevant to the "intelligence reports from independent providers" and "update" limitations (claim 1 elements (a), (f)–(g)) and any dependent claims touching threat scoring/ordering (e.g., the score-based ordering features in the specification).
3.3 Other references in the IPR record (verified as present, not as applied grounds)
The IPR exhibit list for IPR2021-01147 (and companion IPRs 01148/01149) shows, e.g., a Declaration of John Leone regarding US 9,124,552 (Ex. 1051) and a Declaration of Jonathan L. Bradford regarding the '028 patent (Ex. 1050). These are expert declaration exhibits, not independent prior-art grounds; I could not verify what role, if any, US9124552 played in the final grounds, and I will not characterize it further.
4. Claim-by-claim § 102 anticipation assessment
Independent claims 1 (method), 8 (device), and 15 (media) are substantively parallel, so the analysis below applies to all three:
| Claim element (claim 1, as published) | Sourcefire 3D System (per PTAB/Fed. Cir. findings) | Anticipation potential |
|---|---|---|
| Receive packet-filtering rules configured to identify packets corresponding to network-threat indicators | Intrusion rules with rule headers (source/dest IPs = threat indicators) | Disclosed — strong |
| Indicators associated with reports from independent network-threat-intelligence providers | Vendor-supplied rule sets; "independent providers" is contested | Weakest point for § 102 single-reference anticipation |
| Receive first and second packets | Sensors receive/analyze traffic | Disclosed |
| Determine first packet satisfies rule based on indicators; apply allow-type operator | Rule match → action (pass/alert) | Disclosed (Board's "responsive to" finding) |
| Communicate information identifying indicators + allowed status | Event/alert messages | Disclosed |
| Receive update; modify operator to block; prevent second packet; communicate prevented status | Rule-update capability; drop action | Disclosed, though Board resolved under § 103 |
Dependent claims (2–7, 9–14, 16–21): These add, among other things, generation of log entries containing information from the rule that identifies the threat indicators and the allow/prevent status; consolidated flow-log entries; DNS-cache resolution; score-based ordering of threats; and interface elements (e.g., "block" options that instruct the device to reconfigure an operator). Sourcefire's event viewer, rule-update UI, and logging functions arguably disclose many of these, but I did not verify claim-by-claim mapping for each dependent claim from the FWD text, so I will not overstate confidence there.
5. Bottom line
- The single most relevant prior art for US10542028 is the Sourcefire 3D System User Guide (NPL) — the PTAB found all 21 claims unpatentable over it (§ 103), and the Federal Circuit affirmed in October 2024. That makes it the closest and most consequential reference; its disclosures map onto essentially every substantive element of claims 1, 8, and 15, and it is the strongest candidate for a § 102 anticipation argument on those claims, subject to the "independent network-threat-intelligence providers" and update/reconfiguration limitations.
- Macaulay (US20150207809A1) is the next most relevant reference, particularly for the intelligence-report/update/score features, but it was used as a combination reference and does not by itself carry the packet-filtering-operator mechanics.
- The adjudicated ground was obviousness (§ 103), not anticipation (§ 102) — no single-reference § 102 anticipation holding exists on this record, so any § 102 assertion would be a new legal argument requiring each limitation to be found in one reference as arranged in the claim.
- Unverified items, stated plainly: the complete examiner "References Cited" list printed on the face of the '028 patent (USPTO record not directly retrievable in my searches); the exact version/edition and publication date of the Sourcefire guide; and the exact title and effective filing date of Macaulay. I have flagged each rather than guessing.
Key sources: PTAB IPR2021-01147 (institution Feb. 10, 2022; FWD Feb. 9, 2023 — https://portal.unifiedpatents.com/ptab/case/IPR2021-01147); Fed. Cir. Case 23-1654, Centripetal Networks, LLC v. Palo Alto Networks, Inc., Oct. 31, 2024 (https://www.courtlistener.com/opinion/[10171832](/patent/10171832)/); IPWatchdog summary (https://ipwatchdog.com/2024/10/31/cafc-affirms-several-ptab-findings-centripetals-network-security-patent-claims-obvious/id=182713/); Vital Law summary (https://www.vitallaw.com/news/patent-fed-cir-obviousness-affirmed-in-computer-network-threat-detection-system-dispute/ipm012297000a16344133acde18cbdb924038); RPX Insight claim text (https://insight.rpxcorp.com/patent/US10542028B2).
Generated 8/30/2026, 6:46:48 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll analyze the obviousness of US 10542028 under 35 U.S.C. § 103. First, I need to identify the prior art references cited during prosecution. The patent text provided does not include the "Prior Art" / "Citations" section, so I'll search for the cited references and any IPR/litigation analyses of this patent.
The search results reveal critical information: this patent (US 10,542,028) was challenged in IPR2021-01147 by Palo Alto Networks, and the PTAB found all challenged claims obvious under § 103 in view of the Sourcefire 3D System User Guide, which the Federal Circuit affirmed on October 31, 2024. Let me dig deeper into the IPR decision and the exact references and rationale.
I now have strong leads. The PTAB in IPR2021-01147 found all challenged claims of US 10,542,028 (the '028 patent, i.e., US10542028) obvious under § 103 over the Sourcefire 3D System User Guide Version 4.10 (alone or with U.S. Patent No. 8,042,149 "Judge"), affirmed by the Federal Circuit on Oct. 31, 2024. Related IPRs used Macaulay (US 2015/0207809) and Maestas (US 9,342,691) in combination with Sourcefire. Let me now get the claim language and the details of the references and motivation analysis.
I have gathered the key prior-art and litigation record. Before presenting the analysis, a note on sourcing: the "Prior Art" (Citations) section of the Google Patents page was not included in the text you supplied, so I reconstructed the operative prior art from the authoritative post-grant record — IPR2021-01147 (Palo Alto Networks v. Centripetal Networks), the PTAB Final Written Decision (2023 WL 1861774, Feb. 9, 2023), and the Federal Circuit affirmance (Centripetal Networks, LLC v. Palo Alto Networks, Inc., Nos. 23-1654/23-1655, decided Oct. 31, 2024) — which is the most current and legally binding § 103 analysis of this exact patent.
Obviousness Analysis of US 10542028 (US 10,542,028 B2) Under 35 U.S.C. § 103
1. The patent and its claims
US 10542028 B2 ("Rule-Based Network-Threat Detection," Centripetal Networks) claims priority to Apr. 17, 2015, and issued Jan. 21, 2020. Independent claim 1 (as reproduced in the IPR2021-01147 record and RPX/PTAB demonstratives) is a method claim requiring, in substance:
- Receiving a plurality of packet-filtering rules configured to identify packets corresponding to network-threat indicators, where the indicators are associated with network-threat-intelligence reports supplied by one or more independent network-threat-intelligence providers;
- Receiving a plurality of packets including first and second packets;
- Responsive to a determination that the first packet satisfies a first rule based on one or more network-threat indicators specified by the rule:
- Applying an operator (an ALLOW-type operator) to the first packet; and
- Communicating information identifying the indicators and data indicating the packet was allowed;
- Receiving an update to at least one rule and modifying an operator to reconfigure the device to prevent future matching packets from continuing;
- Responsive to a determination that the second packet satisfies the (modified) first rule: preventing the second packet and communicating data indicating it was prevented.
The remaining independent claims are a device claim (claim 8) and a non-transitory computer-readable-medium claim, with dependent claims adding logging, scoring, ordering, and interface features (e.g., flow-log consolidation, scores based on number of intelligence providers, geographic information, block-option interfaces).
2. The controlling § 103 record: the claims were already held obvious and that holding was affirmed
This is not a hypothetical analysis. In IPR2021-01147, Palo Alto Networks challenged all claims of the '028 patent for obviousness under § 103 over a single reference — the Sourcefire 3D System User Guide Version 4.10 ("Sourcefire") — alone or in combination with a second reference (identified in the parallel IPR2021-01148 petition as U.S. Patent No. 8,042,149, "Judge", issued Oct. 18, 2011). The PTAB instituted, conducted trial, and in its Final Written Decision (Feb. 9, 2023) found every challenged claim unpatentable under § 103. The Federal Circuit affirmed on Oct. 31, 2024, holding the Board's construction of "responsive to" correct and its obviousness determinations supported by substantial evidence. (Federal Circuit Blog, Oct. 31, 2024; IPWatchdog, Oct. 31, 2024; Lexology/A&O Shearman, Nov. 2024.)
Sourcefire's status as § 102 prior art was itself already settled: in IPR2018-01760 (Cisco) the Board held, and the Federal Circuit affirmed, that the Sourcefire 3D System User Guide Version 4.10 (Mar. 16, 2011, ~2,123 pages) was publicly accessible — distributed on CD-ROM with every 3D System appliance sold from April 2011 through at least March 2013, with no confidentiality obligation — and therefore a printed publication. (Keyhani LLC summary of IPR2018-01760; IPR2021-01148 Petition, Ex. 1004/EX1031.)
3. The primary reference: Sourcefire 3D System User Guide Version 4.10
The Sourcefire 3D System is an enterprise intrusion-prevention/network-security appliance. Per the Board's findings (as summarized by the Federal Circuit):
- The 3D Sensor with Intrusion Prevention System (IPS) is the claimed packet-filtering device.
- Intrusion rules are the claimed packet-filtering rules. Each rule has a rule header (source/destination IP addresses and ports) and a rule-options section (keywords/arguments inspecting packet content). Rules are managed centrally via the Defense Center.
- Rules specify an action/operator: "pass" rules cause traffic to be ignored and allowed to continue (an ALLOW-type operator), "drop" rules cause the packet to be dropped (a BLOCK-type operator), and "alert" rules log an event.
- When a packet matches all conditions of a rule, the system makes a determination that the packet satisfies the rule based on the source/destination IP addresses — which the Board found "are undisputedly 'network-threat indicators'" — optionally in combination with other criteria — and responsive to that determination applies the rule's operator.
- Matching generates intrusion events — log entries that identify the triggering rule, the threat indicators (e.g., Snort rule IDs / CVE IDs), and whether the packet was allowed (pass/alert) or dropped — displayed in the Defense Center's user interface.
- The Defense Center lets an administrator modify a rule's action (e.g., from "alert" to "drop"); the updated rule is pushed to the sensors and applied to subsequent matching packets, which are then dropped and logged.
4. Combination 1 — Sourcefire alone renders claim 1 (and the other independent claims) obvious
The Board found Sourcefire alone discloses every limitation of the independent claims. The element-by-element correspondence is:
| Claim 1 limitation | Sourcefire disclosure |
|---|---|
| Packet-filtering device | 3D Sensor / IPS component |
| Receiving packet-filtering rules to identify packets corresponding to network-threat indicators; indicators from network-threat-intelligence reports/providers | Intrusion rules with headers/options; rule content derived from externally supplied rule sets (Snort/community/third-party threat intelligence), with IP addresses/ports as the indicators |
| Receiving first and second packets | The sensor examines packets in network traffic |
| Determination that first packet satisfies a rule based on the indicators | Rule engine matches a packet against the rule header (IP addresses = network-threat indicators) and any option criteria |
| Applying an ALLOW-type operator | "Pass" (and "alert") rule action lets the packet continue |
| Communicating info identifying the indicators + data indicating allowed | Intrusion-event logging and Defense Center display of the triggered rule/indicators and the pass/alert outcome |
| Receiving an update to a rule; modifying the operator to BLOCK | Administrator edits the rule action (e.g., alert → drop) in the Defense Center, reconfiguring the sensor |
| Responsive to second packet matching: preventing it and communicating that it was prevented | The reconfigured "drop" rule drops the second packet and generates a drop event |
The only genuinely contested limitation was the "responsive to" clause. Centripetal argued "responsive to a determination … based on one or more network-threat indicators" required the applying/communicating steps to be triggered by the network-threat indicators alone. The Board and Federal Circuit rejected that reading: "responsive to" requires a cause-and-effect relationship, but not an exclusive one. Because Sourcefire's rules trigger on IP addresses (network-threat indicators) in combination with other optional criteria, the applying and communicating steps are nonetheless "responsive to" a determination based on the indicators. (Fed. Cir. Op. at 7–10; IPWatchdog, Oct. 31, 2024.) That construction disposed of Centripetal's only non-duplicative validity argument — the Federal Circuit expressly held "the Board had substantial evidence to find that Sourcefire taught the limitation, and its determination of obviousness is correct on that basis."
5. Combination 2 — Sourcefire + Judge (US 8,042,149)
The petition also asserted obviousness over Sourcefire in combination with U.S. Patent No. 8,042,149 ("Judge"). Judge, issued Oct. 18, 2011, is § 102(a)(1)/(a)(2) prior art. The Federal Circuit characterized Judge as "another reference not at issue on appeal," indicating the Board's dispositive holding rested on Sourcefire alone; Judge was available to fill any residual gaps (e.g., network-threat-intelligence-report ingestion or provider-side rule generation) had the Board found Sourcefire lacking. Because the Board found Sourcefire alone sufficient for all claims, the Sourcefire+Judge ground was not the basis of the affirmance, but it remains a valid secondary obviousness ground of record.
6. Dependent-claim combinations — Sourcefire + Macaulay (+ Maestas)
The '028 patent's dependent claims add scoring, ordering, logging, and interface features. The closely related family member US 10,567,413 (same specification) was challenged in IPR2021-01149 on the ground that Sourcefire alone teaches the base system, and:
- Macaulay (US 2015/0207809) — a real-time threat-agent information-sharing system that computes a reputation score for threats explicitly including "the number of cyber threat intelligence sources" that identified the threat — supplies the claimed score based on the number of network-threat-intelligence providers.
- Maestas (US 9,342,691) — which computes an aggregate risk score using geographic origin as a risk factor — supplies dependent-claim limitations requiring scores based on geographic information (claims 3, 13, 18 analogues).
The Board (in the '413 IPR) found these combinations obvious, and the Federal Circuit affirmed — including rejecting Centripetal's teaching-away argument, holding that the inability to bodily incorporate Macaulay into Sourcefire does not establish that Sourcefire taught away from the combination (the Board misstated the Syntex standard but applied the correct rule, making the error harmless). These same references are directly transferable to the '028 patent's dependent claims because the family shares a specification.
7. Motivation to combine — the KSR analysis
The motivation-to-combine findings rest on standard KSR principles (predictable combination of known elements, design choice, and improvement of an existing system):
- Sourcefire alone: The motivation is inherent — Sourcefire is a commercial IPS that already teaches rules, operators, event logging, and UI-driven rule modification. A POSITA (defined in the record as someone with working knowledge of packet-switched networking, firewalls, security policies, protocols/layers, UIs, and customized rules for cyber-attacks) would have been motivated to configure Sourcefire's disclosed features — header-based filtering plus rule options plus "drop" actions — to detect and block known threats such as data exfiltration over HTTP PUT/POST or vulnerable SSL/TLS, with a high expectation of success because Sourcefire explicitly instructs how to combine these components into custom security policies. (IPR2021-01520 petition analysis; IPR2022-01535 petition analysis.)
- Sourcefire + Judge: To the extent any limitation (e.g., receipt of rules generated from external network-threat-intelligence reports supplied by independent providers) was not expressly in Sourcefire, Judge supplies it; combining a threat-intelligence-fed rule source with an existing rule-based IPS is a textbook predictable combination — using known threat-intelligence data to populate the rule criteria of an existing filtering engine — with a reasonable expectation of success.
- Sourcefire + Macaulay (+ Maestas): Sourcefire's manually assigned, static "priority" is a rudimentary ranking; Macaulay teaches a dynamic, multi-source reputation score, which a POSITA would substitute for Sourcefire's static priority to let administrators better prioritize threats — "a straightforward and predictable modification" (IPR2021-01149 petition). Adding Maestas's geographic risk factor is a predictable design choice to refine the multi-factor score. (IPR2021-01149 petition analysis.)
- Secondary considerations did not save the claims: Centripetal's evidence of secondary considerations (commercial success, praise, etc.) was found insufficient to overcome the strong prima facie case; the Board also rejected teaching-away and the CAFC found the teaching-away ruling harmless error at most.
8. Conclusion
Under § 103, US 10542028's claims are obvious as a matter of record. The operative combinations, each found to render the claims unpatentable and each affirmed on appeal, are:
- Sourcefire 3D System User Guide Version 4.10 alone — discloses every limitation of the independent claims (packet-filtering device, network-threat-indicator-based rules, ALLOW operator + communication of indicator/allow data, rule update + operator modification to BLOCK, subsequent prevention + communication), with the "responsive to" limitation properly construed to permit triggering on indicators in combination with other criteria.
- Sourcefire + Judge (US 8,042,149) — the pleaded secondary combination supplying any residual rule-source/network-threat-intelligence-provider teachings.
- Sourcefire + Macaulay (US 2015/0207809), optionally + Maestas (US 9,342,691) — for dependent claims requiring intelligence-provider-count-based scoring and geographic-information-based scoring, as applied to the same specification in the family IPRs.
The motivation to combine in each instance is the predictable improvement of an existing, commercially deployed IPS (Sourcefire) with known techniques (threat-intelligence-fed rules, dynamic multi-source reputation scoring, geographic risk factors), with a reasonable expectation of success — precisely the combination of "known elements" that KSR Int'l Co. v. Teleflex Inc. treats as obvious. The Federal Circuit's Oct. 31, 2024 affirmance (Nos. 23-1654/23-1655) makes this the current, binding ground truth on the § 103 status of US 10542028.
Sources: IPR2021-01147 FWD, 2023 WL 1861774 (Feb. 9, 2023); Centripetal Networks, LLC v. Palo Alto Networks, Inc., Nos. 23-1654, 23-1655 (Fed. Cir. Oct. 31, 2024); IPR2021-01148 Petition (Ex. 1004 Sourcefire v4.10; Ex. 1005 Judge); IPR2021-01149 petition analysis (Sourcefire+Macaulay, +Maestas); IPR2022-01535 petition (Keysight, Sourcefire alone; collateral estoppel from the '722 IPR); IPR2018-01760 (public accessibility of Sourcefire); IPWatchdog (Oct. 31, 2024); Lexology/A&O Shearman (Nov. 5, 2024); Federal Circuit Blog (Oct. 31, 2024); RPX patent record (claim 1 text).
Generated 8/30/2026, 6:46:26 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Centripetal Networks, Inc.
- US 10193917Patent Analysis: US 10193917 B2 Date of Analysis: April 26, 2026 Here is a concise summary of United States Patent 10,193,917, including details from the patent document and recent legal proceedings. --- Patent Details Title: Rule-based…
- US 9917856Here is a concise summary of US Patent 9917856: US Patent 9917856 Title: Rule-based network-threat detection for encrypted communications Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Sean Moore, Douglas M. DiSabello Filing…
- US 10511572US Patent 10511572 (US10511572) is titled "Rule swapping in a packet network." The patent is currently assigned to Centripetal Networks LLC. The inventors are David K. Ahn, Steven Rogers, and Sean Moore. The application was filed on July…
- US 9686193Here is a concise summary of US patent 9686193: US Patent 9686193: Filtering Network Data Transfers Title: Filtering network data transfers Current Assignee: Centripetal Networks LLC Inventor: Sean Moore Filing Date: February 18, 2015 (for…
- US 9203806US Patent 9203806: Rule Swapping in a Packet Network Title: Rule swapping in a packet network Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Steven Rogers, Sean Moore Filing Date: January 11, 2013 Issue Date: December 1, 2015…
- US 9560176Here is a concise summary of US patent 9560176: US Patent 9560176B2 Title: Correlating packets in communications networks Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert…
- US 10284526Verification Note I searched the USPTO/Google Patents records and the Federal Circuit's 2026 dockets for patent number 10284526 (interpreted literally; no similar numbers substituted). I located the authoritative Federal Circuit…
- US 9264370I have the bibliographic data confirmed. The provided patent text doesn't include the claims section, so let me retrieve the actual claim language. Let me retrieve the exact claims text of US9264370 from additional sources. Summary of U.S…
Other patents in Software Technology & Computing Systems (T)
- US 7502897I'll search for authoritative records on this patent number, including litigation dockets, then summarize. US Patent 7,502,897 — Verification Summary Important disambiguation: I searched USPTO/Google Patents and Federal Circuit 2026 docket…
- US 8520251I'll run targeted searches for this specific patent number, including litigation/docket checks. Let me narrow the search specifically to the patent number and assignee. I have the specification and abstract but the fetched text omits the…
- US 7265870I'll search for litigation and docket information on this specific patent, then compile the summary. US Patent 7,265,870 B2 — Analyst Summary Sourcing note: The following is grounded in the Google Patents/USPTO record for US7265870B2…
- US 8817314I'll search for authoritative information on this specific patent number and any 2026 CAFC activity. Now let me pull the actual claim set for this specific patent and check for any 2026 Federal Circuit activity. US 8,817,314 — Search…
- US 8760704I'll search for authoritative information on this patent, including the patent text and any 2026 CAFC docket activity. Let me search for the 2026 CAFC docket activity and the specific claims of this patent. Let me look specifically for…
- US 6995870I'll verify the current status of US 6,995,870 against live sources before summarizing. The CAFC docket search returned nothing on point. Let me try more targeted queries for the claim set and any 2026 appellate activity. Let me try to…
- US 7830546I'll search for current information on this patent, including any CAFC 2026 activity. Let me pull the claim language directly, since the fetched text was truncated before the claims. I have the full claim set and bibliographic data. Let me…
- US 7280251I'll verify the current status of US 7,280,251 against live sources, including any 2026 CAFC dockets. Let me check for any 2026 Federal Circuit activity and litigation status specifically tied to this patent. Let me do a final targeted…
This patent in court (3)
3 tracked lawsuits name US 10542028.