Invalidity dossier

US 10601780

Internet isolation for avoiding internet security threats

Current assignee: Croga Innovations Ltd

Added 9/16/2026, 12:00:16 AM

At a glanceNo PTAB challengesNo litigation on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 1: Derivative works

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for authoritative current information on US patent 10601780, including any 2026 CAFC docket activity.

Let me check specifically for CAFC 2026 docket activity and the reexamination appeal status.

US Patent 10,601,780 — Summary

I searched for U.S. Patent 10,601,780 and for 2026 appellate activity. Findings below; I flag uncertainties explicitly.

Bibliographic data (from the authoritative full text you supplied)

Field Value
Patent number US 10,601,780 B2
Title Internet isolation for avoiding internet security threats
Application no. US 15/910,734
Filing date 2018-03-02 (continuation of US 13/981,896, a §371 national-stage entry of PCT/US2012/023027 filed 2012-01-27, which claims priority to provisional US 61/436,932 filed 2011-01-27)
Priority date 2011-01-27
Issue/grant date 2020-03-24
Inventors Robert B. Hoy; Mark Fenkner; Sean W. Farren
Original assignee L3Harris Technologies Inc.
Current assignee (per Google Patents) Croga Innovations Ltd / L3Harris Technologies Inc.
Anticipated expiration 2032-01-27 (per Google Patents; not a legal conclusion)
Related U.S. publication US 2018/0191684 A1
Family relative US 13/981,896 → US 9,942,198 B2

Assignments recorded: L-3 Communications Corp. (from the inventors) and L3 Technologies, Inc. (from L-3 Communications Corp.) on 2023-05-08; then assigned to Croga Innovations Limited on 2024-01-02 (entries as listed on the patent page).

Abstract (as issued)

A host computer supports a virtual guest system running thereon. The host system has a firewall that prevents it from communicating directly with the Internet, except with predetermined trusted sites. The virtual guest runs on a hypervisor, and comprises primarily a browser allowed to contact the Internet freely via an Internet access connection completely separate from the host connection (e.g., a dedicated network termination point with its own Internet IP address, or tunneling through the host machine architecture). The guest is separated and completely isolated by an internal firewall from the host and cannot access host resources, except it can initiate cut/copy/paste operations and request printing. The host can transfer files to/from a virtual data storage area by manual operator action; no other transfer is permitted.

Independent claims — plain-language overview

Claim 1 (system): A networked computer system with (a) a network; (b) at least one computer system connected to it that has a host system and a virtual system (the virtual system being a separate operating system or a software module running on the computer). An internal firewall separates host from virtual, and a host-based firewall on the computer implements network isolation between the computer and the network; and (c) at least one device (with a processor and memory) implementing a network firewall or web proxy that enforces network isolation between untrusted network destinations and the networked computer system.

Claim 11 (method): A method of network isolation comprising the corresponding steps: providing the network and computer system (host + virtual system); separating the host from the virtual system with an internal firewall; implementing network isolation between computer system and network with a host-based firewall; providing the network firewall/web proxy device; and using that device to isolate untrusted network destinations from the networked computer system.

Dependent-claim themes (claims 2–10, 12–20)

  • Internal firewall blocks host↔virtual data flow absent explicit user input (claims 2, 12).
  • Segregated host vs. virtual memory/storage space (claims 3, 13).
  • Preventing malware from moving laterally to other computers/devices on the network (claims 4, 6, 14, 16).
  • Separate trusted vs. untrusted connections with enforced separation (claims 5, 15).
  • The network firewall/web proxy prevents unauthorized communication to untrusted destinations (claims 7, 17).
  • A dual-policy host-based firewall — one policy when on the home network (host may reach LAN resources; virtual egresses) and another when on a foreign network, blocking host egress but allowing virtual-system egress (claims 8, 18). This tracks the "home vs. roaming" disclosure in the specification.
  • Applications/processes run in the virtual system to reach untrusted destinations (claims 9, 19); applications in the host system reach network devices (claims 10, 20).

Litigation / PTAB history (as reported online, not verified at primary source)

CAFC 2026 docket — not found; explicit caveat

I could not locate any Court of Appeals for the Federal Circuit docket for this patent in 2026 in the searches available to me. If an appeal exists, I did not find authoritative confirmation, and I am not asserting one does or does not.

Important date conflict to flag: One search result (Unified Patents, dated "2026/9/11") states that on September 10, 2026 the PTAB "affirmed-in-part and issued new grounds of rejection" in the ex parte reexamination of 10,601,780. That date is later than the current date you stated (April 26, 2026), so either that report is mis-dated or the timeline is inconsistent. I am reporting it verbatim rather than reconciling it. URL: https://www.unifiedpatents.com/insights/2026/9/11/magnetaratlantic-ip-entity-croga-innovations-firewall-patent-confirmed-invalid-by-ptab

Uncertainty notes

  • Assignee, reexam, and PTAB items come from third-party trackers (Google Patents, Unified Patents, RPX/GreyB) and are not legal conclusions; verify against USPTO PatentCenter/PTAB and PACER/CourtListener.
  • I could not confirm the current claim status (e.g., whether claims stand cancelled/confirmed after the reexam) from a primary USPTO source.
  • I did not independently confirm the exact status notes ("Not Instituted – Merits," "Settlement," etc.) attached to each IPR; they are reported as shown by the trackers.

Would you like me to pull the primary USPTO documents for the reexamination (90/019,638) and the PTAB decisions, or attempt a targeted PACER/CourtListener check for any 2026 Federal Circuit appeal?

Generated 9/16/2026, 12:00:35 AM

Cases on file (0)

Specific litigation cases in our database that name US patent 10601780. The free-form analysis below may also discuss cases beyond this list.

No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll run targeted searches for litigation involving US 10,601,780.

Let me dig into the other district court cases and their current status.

Let me check the litigation portal, the IBM case status, and any 2026/appellate developments.

Bottom line

Yes — litigation involving US 10,601,780 B2 is known and well documented. All of it is by the current owner, Croga Innovations Ltd. (an Atlantic IP Services / Magnetar-affiliated NPE), filed in 2023–2024 against IBM, Cisco, Fortinet, and Amazon Web Services. The patent has also been the target of four IPRs and one Unified Patents ex parte reexamination. Note there is no Palo Alto Networks case on the '780 patent — PAN is only in suit over the '601 patent (Case 2:24-cv-00208), so I exclude it.


District court litigation asserting the '780 patent

# Plaintiff Defendant Jurisdiction / Case No. Filed '780 asserted? Status (as best I can confirm)
1 Croga Innovations Ltd. International Business Machines Corp. E.D. Tex. (Marshall), 2:23-cv-00634-JRG (Judge Rodney Gilstrap) 2023-12-29 Yes (with US 11,178,104) Settled — IBM's IPR2025-00380 terminated on a confidential settlement agreement 2025-06-02; district case resolution not confirmed from a primary source
2 Croga Innovations Ltd. Cisco Systems, Inc. E.D. Tex. (Marshall), 2:24-cv-00065-JRG (lead case) 2024-02-01 Yes (with US 7,738,368 and US 11,223,601) Pending / trial-track. '368 dismissed with prejudice by stipulation (Dec. 30, 2024); joint motion to stay pending IPR denied Apr. 14, 2025; trial set for Nov. 17, 2025. Post-trial outcome not confirmed
3 Croga Innovations Ltd. Fortinet, Inc. E.D. Tex. (Marshall), 2:24-cv-00206-JRG (member case consolidated into lead 2:24-cv-00065) 2024 (exact date not confirmed) Yes — only the '780 patent (asserted claims 11, 13, 14, 20) Pending / trial-track, same Nov. 2025 trial setting as above; outcome not confirmed
4 Croga Innovations Ltd. Amazon Web Services, Inc. W.D. Tex. (Austin), 1:24-cv-00398 (rendered in sources as -ADA, -DII; Judge Robert Pitman entered orders) 2024-04-16 Yes — only the '780 patent (asserted claims 1, 3, 7, 10, 11, 13, 17, 20) Open/pending (trackers list it as "Open"); Rule 12(b)(6) motion to dismiss filed 2024-07-08; claim construction activity through early 2025; resolution not confirmed

Points of interest per case

  • IBM (No. 1): First of the Croga suits (RPX called it "Atlantic IP's Croga Innovations Kicks Off First US Litigation"). Accused instrumentalities: "IBM Wazi Developer versions 1.4, 2.4, 2.5 and 2.6 with IBM Z and IBM LinuxOne platforms, IBM Cloud, IBM Cloud Virtual Servers, and IBM Cloud Bare Metal Servers." Croga served P.R. 4-2 preliminary constructions on Nov. 26, 2024, relying on Dr. Hugh Smith and Dr. Eric Cole.
  • Cisco (No. 2): Accused products are Cisco's Umbrella remote browser isolation (RBI) service (the '780 and '601 patents) and Unified Border Element (CUBE) v14 with compatible Cisco VoIP phones (the '368 patent). The stay denial is Croga Innovations Ltd. v. Cisco Sys., No. 2:24-cv-00065-JRG, 2025 U.S. Dist. LEXIS 71092 (E.D. Tex. Apr. 14, 2025).
  • Fortinet (No. 3): Narrowest '780 case — only claims 11, 13, 14 and 20 asserted.
  • Amazon (No. 4): Accused products are AWS Virtual Private Cloud (VPC), AWS EC2, and AWS Network Firewall (complaint theory: the EC2 hypervisor as the "internal firewall," AWS Network Firewall as the claimed "device," and AWS Nitro Enclaves as an isolated-compute example). Amazon moved to dismiss under Rule 12(b)(6) on 2024-07-08.

Related PTAB proceedings on the '780 patent (not district-court litigation, but directly relevant)

Proceeding Parties Filed Outcome
IPR2024-01196 Cisco Systems, Inc. v. Croga Innovations Ltd. 2024-07-25 Institution denied 2025-02-13 (Fintiv-style discretionary denial); rehearing denied 2025-03-27; petitioner refund of post-institution fee 2025-09-15
IPR2025-00086 Fortinet, Inc. v. Croga Innovations Ltd. 2024-10-24 Institution denied 2025-03-27 (merits), and motion for joinder denied
IPR2025-00380 International Business Machines Corp. v. Croga Innovations Ltd. 2024-12-30 Terminated — settled 2025-06-02 (pre-institution; joint motion to terminate 2025-05-27 with confidential settlement agreement)
IPR2025-00884 Amazon Web Services, Inc. v. Croga Innovations Ltd. 2025-04-17 Discretionary denial (institution decision date shown as 2025-09-03)

Related but not '780 proceedings (other Croga patents): IPR2024-01282 (Cisco, '368 — terminated/settled), IPR2024-01283 (Cisco, '601 — instituted), IPR2024-01421 (PAN, '601 — terminated/settled), IPR2025-00379 (IBM, '11,178,104 — terminated/settled).

Ex parte reexamination 90/019,638 — filed by Unified Patents on 2024-08-28; the Central Reexamination Unit granted the request 2024-11-21, finding substantial new questions of patentability on all challenged claims. Per the E.D. Tex. stay opinion, the Office issued a non-final office action rejecting all claims of the '780 patent on 2025-04-01. URL: https://portal.unifiedpatents.com/exparte/90019638

Also relevant: Unified Patents ran a PATROLL prior-art contest on claim 1 of US 10,601,780.


What I could NOT confirm

  1. The result of the November 2025 E.D. Tex. trial against Cisco and Fortinet, and whether the Fortinet and Cisco '780 claims were resolved by judgment, settlement, or License on Transfer. I did not retrieve a post-trial docket entry.
  2. Whether Croga v. IBM (2:23-cv-00634) was formally dismissed in district court. The June 2, 2025 IPR settlement strongly implies resolution, but I have no primary district-court dismissal order.
  3. The current status of Croga v. Amazon (1:24-cv-00398) beyond early 2025 claim-construction activity.
  4. Any Federal Circuit/Court of Appeals docket for the '780 patent. My searches did not surface a CAFC appeal involving US 10,601,780, and my attempts to run additional targeted litigation-portal searches were truncated. I am not asserting that no appeal exists — only that I did not find one and could not verify. PACER/CourtListener should be checked directly.
  5. I could not load https://portal.unifiedpatents.com/litigation/caselist directly; the case list above is reconstructed from Unified Patents, RPX, Justia, CourtListener, and parties' own filings.

⚠️ Contradiction to flag (consistent with the earlier section)

I again encountered a dated source that post-dates your stated current date of April 26, 2026: a Unified Patents insight page dated 2026-09-11 states that on September 10, 2026 the PTAB "affirmed-in-part and issued new grounds of rejection" in the ex parte reexamination of U.S. Patent 10,601,780 (and that the patent "had been asserted against IBM, Fortinet, and others"). Two further data points also point to a later "today": the full patent text I was given was fetched 2026-09-16, and an IP Verse Croga page is stamped "Last updated on: May 28, 2026." If the true current date is later than April 26, 2026, then claim-level outcomes in the reexam and the district cases may already have changed since the record above. I am reporting these verbatim rather than reconciling them, per the instruction to treat search results as ground truth.

Sources: https://www.unifiedpatents.com/insights/2026/9/11/magnetaratlantic-ip-entity-croga-innovations-firewall-patent-confirmed-invalid-by-ptab · https://law.justia.com/cases/federal/district-courts/texas/txedce/2:2024cv00065/[227640/108](https://assignmentcenter.uspto.gov/search/patent/reelFrameDetail?reelFrame=227640-0108)/ · https://dockets.justia.com/docket/texas/txedce/2:2023cv00634/[226999](/patent/226999) · https://dockets.justia.com/docket/texas/txwdce/1:2024cv00398/1172783402 · https://portal.unifiedpatents.com/ptab/caselist?judges.panel=Kevin+C.+Trock · https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2024-01196 · https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2025-00086 · https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2025-00380 · https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2025-00884

Would you like me to attempt a targeted PACER/CourtListener check for the Nov. 2025 E.D. Tex. judgment and for any Federal Circuit notice of appeal?

Generated 9/16/2026, 12:01:11 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll reconcile the structured ODP data with what web sources show, and pull claim-level outcomes.

PTAB Proceedings — US 10,601,780 B2 ("Internet isolation for avoiding internet security threats")

⚠️ Data-source conflict — flagged up front (read this first)

The structured "PTAB proceedings on file" block in my prompt states that the USPTO Open Data Portal returns no AIA trial proceedings for US 10,601,780. That structured block is wrong, or at minimum badly incomplete, and I am departing from it. Web-sourced public records identify four separate IPR petitions against this exact patent (Pat. No. 10,601,780 B2, App. No. 15/910,734, Tech Center 2400), each with a proceeding number, filing date, assigned panel, and paper-level docket:

  • IPR2024-01196 (Cisco) — filed 2024-07-25
  • IPR2025-00086 (Fortinet) — filed 2024-10-24
  • IPR2025-00380 (IBM) — filed 2024-12-30
  • IPR2025-00884 (Amazon Web Services) — filed 2025-04-17

These are cross-confirmed by four independent trackers (Unified Patents portal, IP Verse/GreyB, RPX Empower, Docket Alarm) and by primary USPTO documents (institution decisions, POPRs, termination orders hosted at ptacts.uspto.gov and in the E.D. Tex. record). The ODP "no proceedings" result is therefore a coverage/indexing gap, not substantive evidence of no activity. Do not rely on the empty structured block. I have not invented any proceeding number.


Proceedings overview

Four AIA trials have been filed against US 10,601,780; none of them reached a Final Written Decision. The breakdown: 2 institution-denied on the merits (Cisco System's IPR2024-01196; Fortinet's IPR2025-00086), 1 discretionarily denied at Director level (Amazon's IPR2025-00884), and 1 settled pre-institution (IBM's IPR2025-00380). Total claims cancelled by the PTAB: zero. Total claims sustained by the PTAB in an FWD: zero — because no FWD exists. Bottom-line defensive posture: no § 315(e)(2) estoppel attaches to anyone, so every prior-art ground remains available to a new defendant; but the IPR channel itself is effectively closed off by the current discretionary-denial regime, and the real threat to this patent is on the ex parte reexamination track, where the examiner has twice rejected all of claims 1–20 and the PTAB, on 2026-09-10, affirmed-in-part and issued new grounds of rejection. Source: https://www.unifiedpatents.com/insights/2026/9/11/magnetaratlantic-ip-entity-croga-innovations-firewall-patent-confirmed-invalid-by-ptab


IPR2024-01196 — Cisco Systems, Inc. v. Croga Innovations Ltd.

  • Type: Inter Partes Review
  • Filed: 2024-07-25
  • Status: Institution Denied (structurally: "Institution Denied"; termination date listed 2025-02-13)
  • Judge panel: Not confirmed from the sources I retrieved. A Panel Change Order issued 2025-03-14, which indicates the original panel was altered. Petitioner counsel: Theodore Foster et al.; Patent Owner counsel: Brett Cooper et al. (BC Law Group). Do not attribute a panel without pulling the decision itself.
  • Petition grounds (claims 1–20 challenged):
    • Ground 1 — § 103 over Delco (US 8,166,474) in view of Adams (US 2010/0077476): claims 1–7, 9–17, 19–20.
    • Ground 2 — § 103 over Delco + Adams + Dadhia (US 7,886,351): claims 8 and 18 (the home/roaming dual-policy claims).
  • Institution decision: Denied 2025-02-13 (Paper 7), on the merits — the panel found Cisco had not shown a reasonable likelihood that Delco teaches or suggests the claimed "internal firewall … configured to separate the host system from the virtual system in the computer system" recited in independent claims 1 and 11. Delco's packet filter 74 was held to filter network traffic for the guest OS, i.e., it performs network isolation, not host-system/virtual-system separation. The Board relied on Delco's Figure 2, which shows two firewalls, neither positioned between the host system and a virtual machine.
  • Final Written Decision: None. Trial was never instituted, so there is no claim-level verdict and no estoppel. Anyone who tells you "claims X–Y of the '780 patent were cancelled in IPR2024-01196" is wrong.
  • Settlement / termination: No. Petitioner requested rehearing 2025-03-14; rehearing denied 2025-03-27 (Paper 8/decision denying request for rehearing). Petitioner then requested refund of the post-institution fee 2025-09-11; refund approved 2025-09-15.
  • Appeal: None found. A § 314(a) institution denial is non-appealable; the only route would be mandamus, and I found no Croga-related Federal Circuit docket.
  • Defensive value: This is the most reusable proceeding for a defendant. The Board's reasoning gives you a ready-made non-infringement/invalidity hook: the '780 patent's novelty argument during prosecution was that it recites three distinct isolators — internal firewall, host-based firewall, and network firewall/web proxy — so a reference disclosing a packet filter or a network appliance does not meet the internal firewall element. Also useful: because institution was denied on the merits (not discretionarily), a district court can give the panel's reasoning its natural persuasive weight without any § 315(e)(2) bar cutting against you.

⚠️ Date discrepancy to flag: Croga's own 2026 filing in the second reexamination refers to the Board's order here as "1/13/2025." Every other source (GreyB, Unified Patents, the district court order) puts it at 2025-02-13. I treat 2025-02-13 as correct and the "1/13/2025" citation as an error in Croga's brief.

Sources: https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2024-01196 · https://ptacts.uspto.gov/ptacts/public-informations/petitions/[1556394](/patent/1556394)/download-documents (Croga POPR, filed 2024-11-20) · https://www.courtlistener.com/opinion/[10379290](/patent/10379290)/croga-innovations-ltd-v-cisco-systems-inc/


IPR2025-00086 — Fortinet, Inc. v. Croga Innovations Ltd.

  • Type: Inter Partes Review (with a Motion for Joinder to IPR2024-01196 under 35 U.S.C. § 315(c) / 37 C.F.R. § 42.122)
  • Filed: 2024-10-24
  • Status: Institution Denied (both the § 314 institution request and the § 315(c) joinder motion were denied; institution decision date 2025-03-27)
  • Judge panel: Terrence W. McMillin, Kevin C. Trock, and Russell E. Cass, Administrative Patent Judges. Opinion authored by APJ McMillin. (Panel confirmed on the face of the decision.)
  • Petition grounds (claims 1–20 challenged) — substantively a near-copy of Cisco's:
    • Ground 1 — § 103 over Delco + Adams: claims 1–7, 9–17, 19–20.
    • Ground 2 — § 103 over Delco + Adams + Dadhia: claims 8 and 18.
    • Additional exhibits interesting to a defendant: Ex. 1005 Delco (US 8,166,474), Ex. 1006 Adams (US 2010/0077476), Ex. 1007 Dadhia (US 7,886,351), Ex. 1008 Marascio (US 2006/0262916), Ex. 1009 McArdle (US 8,468,256), plus a Shenoy declaration.
  • Institution decision: Denied 2025-03-27 (Paper 9). The Board held Fortinet had not demonstrated a reasonable likelihood of prevailing on at least one challenged claim, because Delco fails to teach or suggest the claimed "internal firewall" separating the host system from the virtual system (independent claims 1 and 11). The Board expressly adopted the same reasoning as in IPR2024-01196 and separately denied joinder under § 315(c). Note: the petition was flagged defective on 2024-11-29 and an Erratum issued 2024-12-03.
  • Final Written Decision: None. No institution ⇒ no FWD ⇒ no claim cancelled and no claim confirmed.
  • Settlement / termination: No. Institution denial terminated the proceeding.
  • Appeal: None found.
  • Defensive value: Confirms the merits denial is not a fluke of one panel — two different petitioners (Cisco, Fortinet) using the same Delco-based theory lost on the same element, and the second loss came after Fortinet had the benefit of seeing Cisco's denial. Practically: do not build an IPR petition on Delco/Adams, alone or with Dadhia. The internal firewall limitation is the wall.

⚠️ Date discrepancy to flag: Croga's 2026 brief cites this decision as "3/17/2025" while the case data and the decision's own caption (Paper 9, "PTAB March 27, 2025") show 2025-03-27. I treat 2025-03-27 as correct.

Sources: https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2025-00086 · https://www.docketalarm.com/cases/PTAB/IPR2025-00086/Fortinet_Inc._v._Croga_Innovations_Ltd/ (Decision Denying Institution, 35 U.S.C. § 314; Denying Motion for Joinder, 35 U.S.C. § 315(c); 37 C.F.R. § 42.122)


IPR2025-00884 — Amazon Web Services, Inc. v. Croga Innovations Ltd.

  • Type: Inter Partes Review
  • Filed: 2025-04-17
  • Status: Discretionary Denial (terminated 2025-09-03; Director-level denial, Paper 9)
  • Judge panel: Undetermined. The decision was a Director Discretionary Decision (Paper 9, dated 2025-09-03), not a three-APJ panel opinion. ⚠️ One docket aggregator renders the assigned judge as "Judge Alan D. Albright" — that is obviously a data artifact (Albright is the W.D. Tex. district judge in the parallel Amazon case, not an APJ). Do not rely on it.
  • Petition grounds: A single ground — § 103 over Nazario in view of Ghosh — against claims 1, 3, 7, 10, 11, 13, 17, and 20. Supporting exhibits included Nazario's "Defense and Detection Strategies," Bambos declaration, Cheswick's Firewalls and Internet Security, Rash's Linux Firewalls, Madnick's An Approach to Information System Isolation, and Goldberg's Survey of Virtual Machine Research. This is a different art family from Delco/Adams — the first genuinely new ground aimed at the '780 patent.
  • Institution decision: Denied 2025-09-03, on discretionary grounds. The Director treated the Fintiv factors as largely neutral ("neither favor nor counsel against discretionary denial") and instead denied on the totality/serial-attack rationale: this was "the fourth petition for inter partes review involving the challenged patent"; "an ex parte reexamination has [already] been ordered on the challenged patent"; and "it is not an appropriate use of Office resources to review a patent in two separate, concurrent Office proceedings, especially when the reexamination is in an advanced stage." The Director also flagged roadmapping concerns. Croga's Request for Discretionary Denial was filed 2025-07-21; Amazon's opposition 2025-08-21; POPR 2025-08-20.
  • Final Written Decision: None.
  • Settlement / termination: No settlement — denied and terminated. Amazon requested refund of the $28,125 post-institution fee on 2025-11-14; refund approved 2025-11-24.
  • Appeal: None found. A Director discretionary denial is not directly appealable. Important false-lead to avoid: a widely-circulated Federal Circuit mandamus filing, In re Maplebear Inc. (d/b/a Instacart), No. 26-105 (Fed. Cir.), challenges the USPTO's discretionary-denial framework and surfaced in searches alongside this case — that petition is not by Croga or Amazon and has nothing to do with the '780 patent. Do not cite it as this patent's appeal.
  • Defensive value: Negative for a defendant relying on Nazario/Ghosh at the PTAB — that ground is now the subject of a Director denial and, separately, of a second ex parte reexamination (see 90/015,746 below). But it is a large strategic positive in one respect: the denial is discretionary, not merits-based, so Nazario/Ghosh remains fully available in district court and the § 112(f) / claim-construction fight over "network isolation" is live (Amazon took the position in district court that the two "network isolation" terms in claims 1 and 11 are means-plus-function under § 112 ¶ 6, then allegedly failed to carry that construction into its petition — a waiver-flavored inconsistency Croga exploited).

Sources: https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2025-00884 · https://ptacts.uspto.gov/ptacts/public-informations/petitions/[1557759](/patent/1557759)/download-documents (Amazon opposition to RDD; Amazon refund request, 2025-11-14) · docket entry "Board Director Discretionary Decision: Deny 9" (2025-09-03)


IPR2025-00380 — International Business Machines Corporation v. Croga Innovations Ltd.

  • Type: Inter Partes Review
  • Filed: 2024-12-30
  • Status: Settlement / terminated — captioned "DISMISSAL Due to Settlement Prior To Institution of Trial (35 U.S.C. § 317; 37 C.F.R. § 42.74)"; GreyB status field reads "Terminated-Settled"; termination date 2025-06-02
  • Judge panel: Terrence W. McMillin, Kevin C. Trock, and Russell E. Cass, Administrative Patent Judges (APJ McMillin authored the termination decision). Same panel as IPR2025-00086.
  • Petition grounds (claims 1–20) — again the same theory:
    • Ground 1 — § 103 over Delco + Adams: claims 1–7, 9–17, 19–20.
    • Ground 2 — § 103 over Delco + Adams + Dadhia: claims 8 and 18.
    • IBM conceded in its own petition that its challenge was substantively the same as Cisco's.
  • Institution decision: Never reached. Croga filed a Request/Brief in Support of Discretionary Denial on 2025-04-25, arguing the Delco/Adams art and argument had already been rejected twice on the merits (in IPR2024-01196 and IPR2025-00086), and the Board extended the discretion-briefing deadline (2025-04-24). Before any institution decision, the parties settled.
  • Final Written Decision: None. The Board's Paper 11 (2025-06-02) expressly states: "This Order does not constitute a final written decision pursuant to 35 U.S.C. § 318(a)." It also notes that where trial has not been instituted, "dismissal is more appropriate than termination."
  • Settlement / termination: Joint Motion to Terminate filed 2025-05-27 with a Confidential Settlement Agreement (Ex. 1020) and a joint request to treat it as business confidential information under § 317(b) / 37 C.F.R. § 42.74(c). The Board granted both the dismissal and the confidentiality request; the settlement agreement is to be kept separate from the '780 file and available only to federal agencies on written request or on a showing of good cause. Terms are confidential and are not public. A § 317(b) requirement that all agreements be filed was satisfied by filing Ex. 1020. Petitioner's refund request was approved 2025-07-16. The settlement coincided with a Joint Motion to Stay All Deadlines and Notice of Settlement in Croga v. IBM, 2:23-cv-00634-JRG (E.D. Tex.), Dkt. 49 (2025-04-15) — i.e., the IPR settlement and the IBM district-court resolution moved together, though I could not confirm a formal district-court dismissal order from a primary source.
  • Appeal: None.
  • Defensive value: Mixed. The good news for a defendant: IBM's chosen art (Delco/Adams) is the same failed art as Cisco's and Fortinet's — don't reuse it. The bad news: because the proceeding was dismissed pre-institution, IBM is not estopped under § 315(e)(2) (and never would be — no FWD), so IBM could re-assert that art elsewhere. For a new defendant, this case is mostly a serial-filing precedent: the Board and the Director have now twice counted prior petitions against a later petitioner, which is exactly what killed Amazon's petition.

Sources: https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2025-00380 · Termination Decision (Paper 11, 2025-06-02), IPR2025-00380 · https://portal.unifiedpatents.com/ptab/caselist?judges.panel=Kevin+C.+Trock


Related non-AIA proceedings directly bearing on the same patent

These are not AIA trials, so they are outside the "proceedings overview" count of four, but a defendant must know about them because they are currently the most dangerous dockets for this patent.

Proceeding Requester Filed Status
Ex parte reexam 90/019,638 Unified Patents, LLC (Slater Matsil) 2024-08-28 Reexam granted 2024-11-21 (SNQ found on all challenged claims); examiner rejected claims 1–20 over Thomas and Garge (two office actions; OA dated 2025-08-01); on appeal to the PTAB; PTAB affirmed-in-part and issued new grounds of rejection 2026-09-10
Ex parte reexam 90/015,746 Amazon Web Services (Nazario + Ghosh — a verbatim copy of its denied IPR2025-00884 ground) request dated 2025-12-02 Granted by the CRU; Croga petitioned the Director on 2026-02-06 to suspend the rules and terminate under 35 U.S.C. § 325(d) / In re Vivint, 14 F.4th 1342 (Fed. Cir. 2021); outcome not confirmed
  • The 90/019,638 record is where claims are actually moving: per the E.D. Tex. stay opinion, the Office issued a non-final office action rejecting all '780 claims on 2025-04-01, and Croga's own 2026 petition describes two office actions finding that Thomas anticipates claims 1–20, plus a § 112 written-description rejection of proposed new claims 21–30 for lacking support for "a trusted local area network." Croga argued (and the record shows) the specification contains literal support at 3:15-16, 7:17-20, and 10:54-57, and it took an After-Final Submission on 2025-12-09 and an appeal to the Board.
  • The 2026-09-10 PTAB decision — "affirmed-in-part and issued new grounds of rejection" — is an ex parte appeal decision, not an FWD, and does not cancel claims. Cancellation would require a reexamination certificate. That distinction matters enormously: nothing is dead yet, but the patent is under sustained rejection pressure from a different (Thomas-based) art family than anything the IPR petitioners tried.

⚠️ Internal inconsistency in a source I relied on: Croga's 2026 petition states it "filed its appeal brief … on January 16, 2025" in 90/019,638, yet the last office action it cites is dated 2025-08-01. The appeal brief date is almost certainly 2026-01-16. I am reporting the source verbatim and flagging it rather than silently correcting it.

Sources: https://ipwatchdog.com/wp-content/uploads/2026/03/Petition-to-Terminate-Reexam-90015746-2-6-2026.pdf · https://portal.unifiedpatents.com/exparte/90019638 · https://www.unifiedpatents.com/insights/2024/11/22/magnetaratlantic-ip-entity-croga-innovations-firewall-patent-challenge-instituted


Strategic summary

Claim status of US 10,601,780 — CANCELED / SUSTAINED / UNTESTED.
There are no PTAB-cancelled claims and no PTAB-sustained claims. All four IPRs terminated at or before the institution stage, so claims 1–20 are entirely UNTESTED by any Final Written Decision. What is live: the ex parte reexamination, where the examiner has rejected all of claims 1–20 (over Thomas, with Garge; also characterized as an anticipation rejection) and where the PTAB on 2026-09-10 affirmed-in-part and issued new grounds of rejection. Croga's proposed claims 21–30 drew a § 112 written-description rejection over "trusted local area network." Net: the enforceable claim set is in flux; the asserted sets — claims 11, 13, 14, 20 (Fortinet), claims 1, 3, 7, 10, 11, 13, 17, 20 (Amazon), claims 1–20 via Cisco — have no confirmed validity and no confirmed invalidity. Anyone who tells you "claims 1–5 were cancelled" or "the PTAB upheld the patent" is fabricating; neither happened in an IPR.

Estoppel landscape — the most important point for a defendant.
§ 315(e)(2) estoppel is a nullity here. Estoppel attaches only to a petitioner that obtains a Final Written Decision under § 318(a). Cisco, Fortinet, and Amazon were all denied institution; IBM's petition was dismissed pre-institution with the Board expressly stating the order "does not constitute a final written decision." Therefore none of Delco, Adams, Dadhia, Nazario, or Ghosh is foreclosed to anyone — including, technically, to those same petitioners and their privies. Every prior-art ground they raised, and every ground they reasonably could have raised, is still on the table in district court and in a fresh USPTO challenge. Conversely, Croga is not estoppel-protected on any claim either. The strategic consequence is asymmetric in the defendant's favor: you inherit the benefit of prior panels' reasoning without the burden of anyone's estoppel.

Pattern signals — what has actually worked, and what has not.
(1) Same theory, three times, all failed. Cisco, Fortinet, and IBM all ran Delco + Adams (+ Dadhia), all mapping Delco's packet filter to the "internal firewall." The Board rejected it twice on the merits, holding Delco teaches network packet filtering, not host-to-virtual-machine separation — and the Board specifically grounded that on Delco's own Figure 2 showing no firewall between host and VM. A fourth Delco-based petition is close to self-defeating.
(2) The Director now closes the door on serial petitions. Amazon tried genuinely new art (Nazario/Ghosh) and still lost on totality, because it was the fourth IPR petition and because a reexamination was already "in an advanced stage." Note this is not classic Fintiv — the Director called the Fintiv factors neutral and denied anyway. Under the current regime (Director Squires's 2025-10-17 reclaiming of all institution authority; the 2025-10-17 NPRM proposing categorical bars; "settled expectations" and "roadmapping"), a fifth IPR petition on the '780 patent by a new defendant is very unlikely to be instituted while the two reexaminations are pending.
(3) The reexamination channel is what is actually working — Unified Patents (a defensive aggregator, represented by Slater Matsil and in-house counsel T.J. Murphy and Jessica L.A. Marks) got the reexam granted on 2024-11-21 and, per the 2026-09-10 decision, has now obtained an affirmance-in-part with new grounds of rejection. Amazon, after losing its IPR, simply refiled the same Nazario/Ghosh art as an EPR (90/015,746) — the "IPR denied, refile as reexam" maneuver. Croga is fighting that as an abuse of process under § 325(d) and Vivint.
(4) Croga litigates hard on collateral issues. It has filed discretionary-denial requests in essentially every proceeding, retained Dr. Eric Cole as a declarant across Cisco, Fortinet, and IBM, and has now gone to the Director to kill a reexam. It has also settled twice when the merits turned (IBM) and once pre-institution on a related patent — but it did not settle Cisco, Fortinet, or Amazon on the '780 patent.
(5) Related Croga PTAB activity on other patents (not '780 proceedings, listed only as a pattern signal): IPR2025-00379 (IBM, US 11,178,104 — terminated-settled 2025-06-20), IPR2024-01421 (Palo Alto Networks, US 11,223,601 — terminated-settled), IPR2024-01282 and IPR2024-01283 (Cisco, US 7,736,368 and US 11,223,601). ⚠️ Contradiction to flag: the GreyB summary table lists IPR2024-01283 as "Terminated-Settled," whereas the previously generated litigation section of this analysis states the '601 IPR was instituted with an FWD expected around February 2026 (and the E.D. Tex. stay opinion says the PTAB "granted the institution of the '601 Patent" on 2025-02-13). These cannot both be right. I have not verified which is correct; verify at PTAB E2E before relying on either.


Recommended next steps

If you are a defendant being asserted today, do this in order:

  1. Attack the "internal firewall" element first, and do it in district court, not the PTAB. The Board has twice held that a network-facing packet filter is not an internal firewall separating host from virtual system (IPR2024-01196, Paper 7, 2025-02-13; IPR2025-00086, Paper 9, 2025-03-27) and grounded that on Delco Fig. 2 showing no firewall between the host and the VM. If your accused product's isolation is implemented at the network edge (e.g., a cloud network firewall or a remote-browser service) rather than inside the machine between host OS and guest, that is your non-infringement and your § 103 gap simultaneously. Retrievable at https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2025-00086 and https://www.docketalarm.com/cases/PTAB/IPR2025-00086/.
  2. Do not file a Delco-based IPR. Three petitioners tried; two merits denials and one settlement. It is also now a roadmapping liability: a later petition reusing a rejected theory invites exactly the discretionary denial the Director issued in IPR2025-00884 (2025-09-03).
  3. If you want an IPR at all, expect denial and budget for it. Argue against the settled-expectations/roadmapping/serial-attack rationales affirmatively (the patent issued 2020-03-24 — over six years — which triggers the "settled expectations" factor; and there are already four IPR petitions plus two reexaminations, i.e., six challenges). Any new petition must present art the Office has never seen and must come with a Sotera-type stipulation; Amazon's petition failed even with new art (Nazario/Ghosh).
  4. Ride and support the reexamination track instead. 90/019,638 is the live threat to the patent — the examiner has rejected claims 1–20 over Thomas/Garge, and the PTAB on 2026-09-10 affirmed-in-part and issued new grounds of rejection. Monitor (a) whether the affirmance ripens into an ex parte reexamination certificate cancelling claims, and (b) the still-open 90/015,746 (Amazon's Nazario/Ghosh reexam), where Croga's 2026-02-06 § 325(d)/Vivint termination petition to the Director is pending. If a certificate cancels claims 1–20, the demand letter collapses. Links: https://portal.unifiedpatents.com/exparte/90019638 · https://ipwatchdog.com/wp-content/uploads/2026/03/Petition-to-Terminate-Reexam-90015746-2-6-2026.pdf · https://www.unifiedpatents.com/insights/2026/9/11/magnetaratlantic-ip-entity-croga-innovations-firewall-patent-confirmed-invalid-by-ptab
  5. Weaponize the § 112(f) dispute. Amazon told the W.D. Tex. court that the "network isolation" limitations in claims 1 and 11 are means-plus-function under § 112 ¶ 6 (nonce term "device," function = "implement network isolation between one or more untrusted network destinations and the networked computer system"), then allegedly failed to carry that construction into its petition — the kind of inconsistency the Board punished in Cambridge Mobile Telematics v. Sfara. A well-supported § 112(f) construction narrows the claim to the disclosed structure (Figs. 1–2 and the VPN-termination-point/VPN-conduit hardware at, e.g., 7:7-17 and 9:47-10:4), which is a powerful non-infringement lever against cloud-based network firewalls.
  6. Note the trial-stage math if anything is still live in E.D. Tex. The '780 patent's own IPRs are all over, so there is no institution-deadline/FWD-due-date clock to wait on for claims 1–20. The only PTAB clock that mattered ran on the case the court itself stayed analysis around — and Judge Gilstrap denied the joint stay on 2025-04-14 despite finding that "every asserted claim has a reasonable likelihood of being invalidated" because Croga's interest in timely enforcement and the advanced stage of the case outweighed it (Croga Innovations Ltd. v. Cisco Sys., No. 2:24-cv-00065-JRG, 2025 U.S. Dist. LEXIS 71092 (E.D. Tex. Apr. 14, 2025); https://www.courtlistener.com/opinion/10379290/croga-innovations-ltd-v-cisco-systems-inc/).
  7. Verify at primary sources before filing anything. PTAB E2E: https://ptacts.uspto.gov/ptacts/ ; PTAB Decisions: https://www.uspto.gov/patents/ptab/decisions ; reexam status via USPTO PatentCenter; and PACER/CourtListener for any Federal Circuit appeal — I found no CAFC docket involving US 10,601,780, but I could not exhaustively check, and I am explicitly not asserting that no appeal exists. (And to repeat: In re Maplebear/Instacart, No. 26-105, is a different case — do not conflate it with this patent.)

Nothing in this section is a legal conclusion. All proceeding numbers, dates, panels, and dispositions above are sourced to the cited public pages and USPTO filings; the ODP structured block supplied in my prompt is contradicted by that record and should be treated as erroneous.

Generated 9/16/2026, 12:02:16 AM

Ownership chain (3)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2023-05-08 · Change of Name

    L-3 Communications CorporationL3 Technologies, Inc.

    change of name only

  2. ? · recorded 2024-01-02 · Assignment

    L3 Technologies, Inc.Croga Innovations Limited

    Correspondent: · Lombard Geliebter

    transfer-to-asserter

  3. ? · recorded 2024-01-02 · Assignment

    Farren, Sean W.; Hoy, Robert B.; Fenkner, MarkL-3 Communications Corporation

    employment assignment

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment chain for US 10,601,780, focusing on reel/frame numbers, correspondents, and NPE patterns.

Assignment Record & Ownership Analysis — US 10,601,780 B2

Sourcing caveat up front. I did not obtain a direct, document-level pull of the USPTO Assignment Center pages in this session, and the searches I ran did not return per-link reel/frame numbers. I therefore do not state reel/frame identifiers — inventing them would violate the core constraint. What follows is reconstructed from (a) the Google Patents legal-events record embedded in the authoritative full text you supplied, and (b) a USPTO/PTACTS-filed document in the related file that exposed the post-transfer correspondence of record. Where an element could not be confirmed, I say so explicitly. Verify every conveyance at the Assignment Center by patent number: https://assignmentcenter.uspto.gov/ (mirror: https://assignment.uspto.gov/patent/index.html).


Inventors

Inventor Likely employer at time of filing Basis
Robert B. Hoy L-3 Communications Corporation Named inventor; the original conveyance runs from the inventors to L-3 Communications Corp. (Google Patents legal events: "Assigned to L-3 COMMUNICATIONS CORP. … Assignors: FARREN, SEAN W; HOY, ROBERT B; FENKNER, Mark")
Mark Fenkner L-3 Communications Corporation Same
Sean W. Farren L-3 Communications Corporation Same

Pattern notes / anomalies:

  • All three inventors conveyed at once to a single corporate assignee (L-3 Communications Corp.), consistent with an employer-takes-all employment assignment, not a startup founder split. This is typical of a defense-prime R&D group.
  • Departure-within-12-months is not determinable from assignment records. Assignment data does not record employment end dates, and I found no separate evidence of inventor departures. I am not asserting a fire-sale-precursor pattern here.
  • ⚠️ Indexing anomaly to flag: the Google Patents legal-events record lists the inventors → L-3 Communications Corp. conveyance with a date of 2024-01-02, i.e. the same date as the Croga transfer — roughly 13 years after the 2011 priority filing. This is either (i) a late/confirmatory re-recording of the original employment assignment, or (ii) a Google Patents indexing artifact that conflated a batch of records under one date. I cannot tell which from available sources, and the reel/frame would resolve it. Treat the inventors-to-L-3 link as original and circa 2011–2012 pending confirmation, not as a 2024 event.

Original assignee

  • Assignee of record at issue (2020-03-24): L3Harris Technologies, Inc. (Google Patents "Original Assignee"). The patent issued after the L3–Harris merger closed in June 2019, so the recorded owner at grant carried the post-merger name.
  • Assignee at original filing (2011–2012): L-3 Communications Corporation — the PCT (PCT/US2012/023027) and the §371 national-stage entry (US 13/981,896) were filed under that name.
  • Primary line of business: defense, aerospace, and secure communications — a major U.S. government contractor (historically the Lockheed Martin spinoff; NYSE: LLL pre-merger, now L3Harris Technologies, NYSE: LHX).
  • Current status: Operating. L3Harris is a large, solvent, publicly traded prime. No bankruptcy, no dissolution. (This matters for the fire-sale signal below.)
  • Did they ship a product embodying the claims? Unclear / not confirmed from available sources. The '780 subject matter (VM-based Internet isolation, host/guest firewalling, VPN conduit) sits in L-3/L3Harris's secure-networking and cross-domain-solution business area, and the same R&D group produced a family of related patents (e.g., US 10,558,798; US 10,554,475; US 11,223,601; US 11,178,104). I could not confirm a shipping commercial product that reads on the issued claims. I will not assert one exists.

Assignment timeline

The record contains three recorded conveyance events touching this patent, per the Google Patents legal-events block:

  • 2023-05-08 (recorded 2023-05-08) — Reel/frame not retrieved

    • Conveyance: Change of Name (corporate rebrand; filed as "CHANGE OF NAME (SEE DOCUMENT FOR DETAILS)")
    • Assignor: L-3 Communications Corporation
    • Assignee: L3 Technologies, Inc.
    • Correspondent: not retrieved (would be L-3/L3Harris's own IP counsel, not the Atlantic IP-side correspondent)
    • Context: internal reorganization / change of name only — no change in beneficial ownership; "L-3 Communications Corp." became "L3 Technologies, Inc." (precursor step to the 2019 L3Harris merger identity).
    • Recurrence flag: this is the only non-Atlantic-IP recording in the chain; correspondent did not recur on the later links.
  • 2024-01-02 (recorded 2024-01-02) — Reel/frame not retrieved

    • Conveyance: Assignment of Assignors' Interest ("ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS)")
    • Assignor: L3 Technologies, Inc. (= L3Harris)
    • Assignee: Croga Innovations Limited
    • Correspondent: Atlantic IP c/o Lombard Gelgelter LLP — as recorded in the related file: "Atlantic IP c/o Lombard Geliebter LLP, 1325 Avenue of the Americas, 28th Floor, New York, NY 10019", USPTO Customer Number 199393 (spelling as it appears in the file: Lombard Geliebter LLP). This is the correspondence address of record for the Croga/Atlantic IP portfolio.
      • Recurrence flag: Yes — this same Atlantic IP / Lombard Geliebter correspondence address (Customer No. 199393) is the shared correspondence address used across the Atlantic IP–controlled Croga portfolio, not just this patent. The shell/entity names on individual patents differ, but the recording correspondence runs through the same New York address and customer number.
    • Context: transfer-to-asserter / monetization — sale out of the operating prime into an Irish licensing vehicle administered by Atlantic IP Services Limited. A 37 C.F.R. 3.73(c) statement in the related file was signed 2024-05-01 by Ciaran O'Gara, Director, Croga Innovations Limited, establishing Croga's ownership of record and its authority to prosecute.
    • ⚠️ Timing nuance: the transfer is recorded 2024-01-02, while Croga's first suit (v. IBM, 2:23-cv-00634, E.D. Tex.) was filed 2023-12-29 — i.e., recorded 4 days after the first complaint. That strongly implies the execution date preceded the recordation and that the chain was papered immediately before (or concurrently with) launching the assertion campaign. The execution date should be pulled from the recorded instrument to fix this precisely.
  • 2024-01-02 (recorded 2024-01-02) — Reel/frame not retrieved

    • Conveyance: Assignment of Assignors' Interest
    • Assignor: Farren, Sean W.; Hoy, Robert B.; Fenkner, Mark (the inventors)
    • Assignee: L-3 Communications Corp.
    • Correspondent: not retrieved
    • Context: original employment/confirmatory assignment — likely the original inventor→employer conveyance, showing a 2024-01-02 index date that is almost certainly a recording/indexing artifact (see anomaly note above). Confirm at Assignment Center.

Assignment Center records for this patent: YES — records exist (three events as above). I proceed on that basis, with the reel/frame caveat noted.


Timeline diagram

timeline
    title Ownership of US 10601780
    2011 : Priority filed by L-3 Communications
    2012 : PCT application filed
    2018 : Continuation 15/910734 filed
    2020 : Patent issued to L3Harris
    2023 : L-3 renamed L3 Technologies
         : Croga sues IBM in E D Tex
    2024 : Assigned to Croga Innovations Limited
         : Asserted vs Cisco Fortinet Amazon

NPE / troll-pattern signals

1. Shell-entity transfer — PRESENT.
The patent moved from an operating defense prime (L3 Technologies, Inc. / L3Harris) to Croga Innovations Limited by assignment recorded 2024-01-02. Croga is, per Unified Patents and RPX, "an entity of Atlantic IP Services Limited" — an Irish licensing/monetization firm — and Unified's own case metadata classifies the owner as "NPE (Patent Assertion Entity)." No products in commerce; the entity's function is assertion (it has sued IBM, Cisco, Fortinet, and Amazon on this and sibling patents). Its USPTO correspondence runs to a law-firm address ("Atlantic IP c/o Lombard Geliebter LLP, 1325 Avenue of the Americas, 28th Floor, New York, NY 10019," Customer No. 199393), and its corporate actions are signed by a Director (Ciaran O'Gara) on a 37 CFR 3.73(c) statement. (Named-entity suffix aside, the finding rests on the actual transfer to a licensing-only vehicle + the law-firm correspondence address + the absence of any product.)

2. Known asserter in the chain — PRESENT.
Croga Innovations Limited / Atlantic IP Services Limited is a known, high-frequency NPE plaintiff — the type surfaced on Unified Patents' and RPX's assertion trackers. Unified Patents tags it in the Magnetar Capital and Atlantic IP Services categories ("Magnetar/Atlantic IP entity, Croga Innovations"), and RPX describes it as "a plaintiff tied to Irish monetization firm Atlantic IP Services." It is not on the classic 2010s lists (Acacia, Marathon, Wi-LAN, etc.), but it is a current-generation assertion entity surfaced by Unified/RPX, which satisfies the signal. Assertion history on the '780 patent alone spans four district-court campaigns (2023–2024).

3. Repeat correspondent across the chain — PRESENT (Atlantic-IP side); partially confirmed.
The recurring correspondent is Atlantic IP c/o Lombard Geliebter LLP, 1325 Avenue of the Americas, 28th Floor, New York, NY 10019 — USPTO Customer Number 199393. This correspondence address/customer number recurs across the Atlantic IP–controlled portfolio, i.e. the shell names change but the recording/prosecution correspondence stays with the same New York firm and customer number. Caveat: within this patent's chain I confirmed the Atlantic-IP-side correspondent directly (from the PTACTS-filed document), but I did not retrieve the corresponding attorney/firm on the L-3-side recordings — so the recurrence I can affirm is across the Atlantic IP family, not literally on every link of this one chain. Reel/frame pulls would close that gap.

4. Cascading transfers — NOT PRESENT (in the strict sense).
The chain is operating company → single NPE, not a daisy-chain of LLCs sharing a registered-agent address. However, note the clustering: the change-of-name (2023-05-08), the inventor re-recording and the Croga assignment (both indexed 2024-01-02) all fall inside a ~8-month window, ending at the asserter. Two transfers in <24 months is technically satisfied, but the "chained anonymous LLCs" character of the signal is absent, so I call it not present rather than inflate it.

5. Pre-litigation transfer — PRESENT.
The Croga assignment is recorded 2024-01-02, which is within days of the first suit (IBM, filed 2023-12-29) and immediately before the follow-on suits (Cisco 2:24-cv-00065, Amazon 1:24-cv-00398, Fortinet 2:24-cv-00206, all 2024). Whether measured from the (unretrieved) execution date or the recording date, the transfer is contemporaneous with, and preparatory to, the assertion campaign — the hallmark of a chain arranged to establish clean standing to sue. (Note: it is technically recorded just after, not before, the IBM complaint, which is why the execution date matters; either way, "within 6 months before the first infringement suit" is met on any reasonable reading of the execution date.)

6. Bankruptcy fire-sale — NOT PRESENT.
The transferor, L3Harris Technologies, is a solvent, publicly traded, operating defense contractor (NYSE: LHX). There was no Chapter 7/11 and no court-supervised patent sale. This was a voluntary monetization sale, not a distress liquidation. (Contrast the Kodak/Nortel/Polaroid archetypes.)

7. Privateering — NOT PRESENT (no evidence).
There is no evidence that L3Harris retained a financial interest, back-end license, or assertion-control right in the '780 patent after the 2024 transfer, and no reporting of L3Harris directing Croga's suits against its competitors. Absent a retained-interest document or SEC/EFF/Patent Progress coverage, I do not call this privateering. (The structural fact that a prime sold to a monetizer is real, but structure alone is not the signal.)

8. Defensive aggregator — NOT PRESENT.
The chain ends at an asserting NPE (Croga Innovations Limited), not at RPX, AST, LOT, Unified Patents, or OIN. Note the direction of the Unified Patents involvement: Unified is adverse to this patent — it filed the ex parte reexamination 90/019,638 (2024-08-28) and ran a PATROLL prior-art contest on claim 1 — which is the inverse of the defensive-aggregator signal. No neutralizing assignment occurred.


Verdict

NPE — high confidence.

Three strong signals converge on the same reel/frame chronology: (i) a shell/entity transfer from an operating defense prime (L3 Technologies → Croga Innovations Limited, recorded 2024-01-02) into a licensing-only vehicle that ships no products; (ii) a known asserter in the chain (Croga / Atlantic IP Services Limited, classified by Unified Patents as an NPE/Patent Assertion Entity and described by RPX as an Irish monetization firm), with the recording correspondence running to Atlantic IP c/o Lombard Geliebter LLP, New York, Customer No. 199393; and (iii) a pre-litigation transfer timed to the 2023-12-29 IBM complaint and the 2024 follow-ons against Cisco, Fortinet, and Amazon. The transferor (L3Harris) was solvent and operating, so the bankruptcy and defensive-aggregator signals are affirmatively absent — this is a straight operating-company → NPE monetization sale, not a distress sale and not a defensive neutralization.

Verification links:

Open items to close at the primary source: (1) pull the reel/frame and the execution dates for all three recordings; (2) confirm the inventor→L-3 link's true date (artifacts vs. re-recording); (3) retrieve the correspondent on the L-3-side recordings to complete signal 3 across every link; (4) confirm whether Croga's purchase covered a portfolio (e.g., siblings US 11,178,104 and US 11,223,601) under one instrument, which would further evidence a bulk monetization purchase rather than an isolated patent sale.

Generated 9/16/2026, 12:03:04 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll ground each reference with targeted searches before building the claim-by-claim § 102 analysis.

Good — Delco is well grounded. Now let me ground the remaining petition art and the reexamination art.

I hit the tool-call limit, so I'll build on what's already grounded: the authoritative full text you supplied (which carries the complete face-of-patent citation list), the PTACTS/Board record for Delco, and the IBM petition mapping for Delco/Adams/Dadhia. Where a search returned nothing or I could not verify an element, I say so rather than filling the gap.

One scope note and one flag before the analysis.

Scope note. US 10,601,780 has no "cited by" prior art that was applied in a rejection that stuck — the patent issued with all 20 claims allowed. The face of the patent carries 20 cited patent documents (per the authoritative text: "Citations (20)"). Separately, the references that are actually most relevant in practice are the ones raised in the four IPRs and the two reexaminations — Delco, Adams, Dadhia, Nazario, Ghosh, and (per the reexam reporting) Thomas and Garge — and those were never applied by the examiner. I cover both sets, clearly separated.

Flag (consistent with the earlier sections). Your task header states "Current Date: April 26, 2026." The environment's current date is 2026-09-16, and the fetched patent text is stamped 2026-09-16. I proceed on the record as-is and do not reconcile the dates. Also: my searches for US 2010/0077476 (Adams), US 7,886,351 (Dadhia), the 90/019,638 Thomas/Garge art, and the Nazario/Ghosh details each returned zero or only indirect results. I therefore do not state bibliographic details for those that I could not retrieve — only what the PTACTS record and the prior sections establish.


Prior Art Analysis — US 10,601,780 B2

0. Methodology and the § 102 critical dates that govern everything

The '780 patent is pre-AIA (priority 2011-01-27; PCT filed 2012-01-27). That fixes the two dates that control every citation:

Provision Critical date Effect
pre-AIA § 102(b) 2010-01-27 (one year before priority) Any printed publication or U.S. patent issued before this date is § 102(b) art; not swearing behind it
pre-AIA § 102(a) 2011-01-27 (priority/filing) Art published before this date but not before 2010-01-27 — defeatable by proof of earlier invention
pre-AIA § 102(e) Date the reference application was filed U.S. patents and § 122(b) published applications "by another," filed before the invention date — this is what saves the post-2010 pre-grant publications
Foreign patents (RU) Publication date only No § 102(e) benefit for foreign-origin documents; § 102(a)/(b) by publication date only

Two consequences to keep front of mind:

  1. Four of the 20 cited references were published/granted after 2010-01-27 (US 7,698,442; US 2010/0138829; US 2010/0138830; US 2010/0174811; US 2010/0223613; US 2010/0251329; RU 2406138; US 2012/0023593; US 8,185,642). For each, the § 102 hook is § 102(e) by filing date (U.S. ones) or § 102(a) by publication (RU), which is a materially weaker and more attackable posture.
  2. Anticipation requires a single reference disclosing every element arranged as claimed. Claim 1 and claim 11 each require three distinct isolators — (i) an internal firewall separating host from virtual system, (ii) a host-based firewall on the computer implementing network isolation between computer and network, and (iii) a separate network firewall-or-web-proxy device with processor and memory. The prosecution record (and the PTACTS/IBM petition summaries) confirms that that three-isolator combination was the stated novelty. No single cited reference discloses all three. That is the structural reason nothing on this list anticipated, and it is why the Examiner's citations ended in allowance.

1. The 20 references of record — per-reference detail

Tier 1 — closest single-reference candidates

1. US 2010/0174811 A1 — Microsoft Corporation — "Network isolation and identity management of cloned virtual machines"

  • Filed / published: 2009-01-05 / 2010-07-08
  • § 102 basis: § 102(e) (filed 2009-01-05, before priority). Not § 102(b).
  • Description: Microsoft's cloned-VM management disclosure. It addresses giving each cloned virtual machine its own network isolation and identity so that clones don't collide or cross-contaminate on the network.
  • Potential § 102 mapping: This is the single most textually on-point reference on the face of the patent for the claim-1/claim-11 phrase "network isolation," and for the claim 4 / 6 / 14 / 16 "prevent malware from moving … between the computer system and other devices on the networked computer system" / "lateral communication" limitations. It also touches claim 1(b) (virtual system) and claim 3/13 (segregated memory, insofar as clone identity implies per-VM state separation).
  • Assessment: Can plausibly anticipate the network-isolation dependent claims in isolation, but cannot anticipate claim 1 or 11 — it does not disclose an internal firewall separating host from virtual system on the same machine plus a host-based firewall plus a separate processor/memory network appliance. Best deployed as the § 102(e) anchor on the "network isolation" term, combined with the § 112(b)/(f) indefiniteness attack the previous section identified.

2. RU 2406138 C1 — Корпорация "САМСУНГ ЭЛЕКТРОНИКС Ко., Лтд." (Samsung) — "Security system for virtual computer system" (title rendered as "sytem" in the record; I reproduce the error rather than correct it)

  • Filed / published: 2009-06-18 / 2010-12-10
  • § 102 basis: § 102(a) only (published 2010-12-10, after the 2010-01-27 critical date). No § 102(e) — foreign-origin. Defeatable by an earlier invention date.
  • Description: A security system architecture for a virtual computer system. On its title alone it is a direct conceptual hit on claims 1 and 11 (security + virtual computer system), and on claims 2 / 12 (isolation of the virtual system).
  • Potential § 102 mapping: claims 1, 2, 11, 12 — and, to the extent the "security system" is a separate appliance, claim 1(c)/(e) and claims 7 / 17.
  • Assessment: The highest-upside reference on the list and the highest-risk one. If its full text (Russian) discloses host↔guest separation plus network-facing filtering, it is a genuine anticipation candidate for claims 1–2/11–12. But it is § 102(a)-only and foreign-language — a § 102 anticipation would require a certified translation and an obviousness-style showing to overcome the "arranged as claimed" gaps. Flag: I could not retrieve the RU 2406138 text, so I am reasoning from the title and classification only. This is the first document I would pull.

3. US 2009/0172781 A1 — Fujitsu Limited — "Trusted virtual machine as a client"

  • Filed / published: 2007-12-20 / 2009-07-02
  • § 102 basis: § 102(b) (published 2009-07-02, before 2010-01-27). Clean, unswearable-against art.
  • Description: A trusted virtual machine functioning as a client — i.e., a host with a VM client and a trust boundary between them.
  • Potential § 102 mapping: claim 1(b) (host + virtual system), claim 1(c) (the trust boundary ≈ internal firewall, if implemented as a separation layer), and claims 9 / 10 / 19 / 20 (applications running in the VM vs. host). Also claim 3 / 13 (separate host/VM state).
  • Assessment: Strong § 102(b) art for the virtual-system-on-a-host elements, weak on the firewall architecture — the "trusted VM" concept is about which side is trusted, not about a firewall interposed between host and guest with a single-reference disclosure of the host-based and network-appliance isolators. Best as a § 103 primary reference, not a standalone anticipation of claims 1/11.

4. US 2007/0220187 A1 — Lawrence Kates — "Virus-resistant computer with data interface for filtering data"

  • Filed / published: 2006-03-20 / 2007-09-20
  • § 102 basis: § 102(b).
  • Description: A computer architected to be virus-resistant, with a filtering data interface that screens data before it reaches the protected machine.
  • Potential § 102 mapping: claims 4, 6, 7, 14, 16, 17 (malware containment / preventing movement / preventing unauthorized communication) and claim 1(e) (a filtering device).
  • Assessment: Conceptually the closest result to the patent's purpose, but structurally different — a filtered interface, not a host/guest hypervisor pair with an internal firewall. It would anticipate the anti-malware-movement dependent claims if those are read broadly, but is a poor fit for claim 1/11 because it lacks the virtual-system element entirely. Note that dependent claims can be anticipated individually even where the independent claim is not — so this reference is worth keeping for a claim-by-claim invalidity chart.

Tier 2 — virtualization/hypervisor references (element (b) and (c) coverage)

5. US 2006/0005188 A1 — Microsoft Corporation — "Systems and methods for initializing multiple virtual processors within a single virtual machine"

  • Filed / published: 2004-06-30 / 2006-01-05§ 102(b).
  • Description: Multiple virtual processors within one VM; boot/initialization of a virtualized execution environment.
  • § 102 mapping: claim 1(b) (virtual system as separate OS/software module); claim 3 / 13 (segregated memory) if the virtual processors have isolated address spaces.
  • Assessment: Single-element art only. No anticipation of any independent claim. Supports a § 103 case that virtualization was well known by 2004.

6. US 2006/0070066 A1 — Grobman, Steven L. — "Enabling platform network stack control in a virtualization platform"

  • Filed / published: 2004-09-30 / 2006-03-30§ 102(b).
  • Description: Control of the platform network stack from within a virtualization layer — i.e., the hypervisor mediating network traffic for VMs.
  • § 102 mapping: claim 1(c)/(d) (control of host/guest network paths), claims 5 / 15 (separating first and second communication connections), claims 6 / 16.
  • Assessment: The best-fitted reference on the list for hypervisor-mediated network control, but it is about control/enablement, not about isolation between a host and a guest. § 103 material, not anticipation.

7. US 2008/0028401 A1 — Geisinger, Nile J. — "Software executables having virtual hardware, operating systems, and networks"

  • Filed / published: 2005-08-30 / 2008-01-31§ 102(b).
  • Description: A self-contained software executable that carries its own virtual hardware, OS, and network — essentially a portable VM bundle.
  • § 102 mapping: claim 1(b) and claim 3 / 13; conceptually claims 9 / 19 (application running inside the virtual system).
  • Assessment: Single-element art. No independent-claim anticipation; § 103 support for "virtual system = separate OS or software module."

8. US 2008/0256536 A1 — Zhao, Xiaoming — "Portable secured computing environment for performing online confidential transactions in untrusted computers"

  • Filed / published: 2007-04-11 / 2008-10-16§ 102(b).
  • Description: A secured computing environment (partition/VM) hosted on a machine assumed to be untrusted — the exact "untrusted-host" isolation premise.
  • § 102 mapping: claims 1, 4, 6, 7, 11, 14, 16, 17 — malware confinement and unauthorized-communication prevention — plus claim 2 / 12 if the secure environment is walled off from the host.
  • Assessment: Genuinely relevant to the "malware stays contained" dependent claims. Not an anticipation of claims 1/11: it lacks the dual-firewall-plus-appliance architecture. Strong § 103 reference for the containment objective.

9. US 2008/0201711 A1 — Husain, Syed M. Amir — "Maintaining a Pool of Free Virtual Machines on a Server Computer"

  • Filed / published: 2007-02-15 / 2008-08-21§ 102(b).
  • Description: A pool of pre-provisioned, clean VMs.
  • § 102 mapping: none of the 20 claims recite it. This maps to the specification's "pristine copy / clean slate" refresh disclosure (¶ on hypervisor restoration), which is not claimed.
  • Assessment: No § 102 relevance to the claims. Relevant only to prosecution-history/§ 101 or to a written-description argument about what the applicant considered known. I flag it as a reference that should not be charted against the claims.

10. US 2009/0328038 A1 — Kabushiki Kaisha Toshiba — "Computer System and Device Controlling Method for Computer System"

  • Filed / published: 2008-06-27 / 2009-12-31§ 102(b) (published 2009-12-31, four weeks before the critical date — clean).
  • Description: Computer-system device control, generally in a virtualized/partitioned context.
  • § 102 mapping: claim 1(b); claim 3 / 13 (separate storage) if the disclosure segregates device access by partition.
  • Assessment: Single-element § 102(b) art. No independent-claim anticipation.

11. US 2010/0138829 A1 — Hanquez, Vincent — "Systems and Methods for Optimizing Configuration of a Virtual Machine Running At Least One Process"

  • Filed / published: 2008-12-01 / 2010-06-03§ 102(e) by the 2008-12-01 filing date.
  • Description: VM configuration optimization for VM-hosted processes.
  • § 102 mapping: claim 1(b); claims 9 / 19 (processes running in the virtual system).
  • Assessment: § 102(e) art; no anticipation of any independent claim.

12. US 2010/0138830 A1 — Skytap — "Multitenant hosted virtual machine infrastructure"

  • Filed / published: 2008-05-02 / 2010-06-03§ 102(e) by the 2008-05-02 filing date.
  • Description: Multi-tenant VM hosting with isolation between tenants.
  • § 102 mapping: claims 1(b), 6 / 16 (isolation between machines/tenants), and 8 / 18 (different policies per network/tenant context).
  • Assessment: Good § 102(e) art for the "isolation between entities" theme; not an anticipation of claims 1/11. Useful for claim 6/16.

13. US 2010/0223613 A1 — Schneider, James P. — "Per process virtual machines"

  • Filed / published: 2009-02-27 / 2010-09-02§ 102(e) by the 2009-02-27 filing date.
  • Description: Each process gets its own VM — process-level isolation.
  • § 102 mapping: claim 1(b); claims 9 / 19 (running applications/processes in the virtual system — here, all processes run in VMs).
  • Assessment: Notable because "one process per VM" subsumes putting a browser in a VM. But it discloses no internal firewall/host-based firewall/appliance triad. § 103 material for claims 9/19.

Tier 3 — proxy / whitelist / network-appliance references (element (e) coverage)

14. US 2012/0023593 A1 — Puder, George — "System and method for filtering internet content & blocking undesired websites by secure network appliance"

  • Filed / published: 2010-07-26 / 2012-01-26
  • § 102 basis: § 102(e) by the 2010-07-26 filing date (the publication post-dates the priority date by a year; it cannot be § 102(a)/(b)).
  • Description: A secure network appliance that filters Internet content and blocks undesired websites.
  • § 102 mapping: claim 1(e) and claim 11(e) squarely — "at least one device configured to implement at least one of a network firewall or a web proxy … comprising a processor and a memory configured to implement network isolation between one or more untrusted network destinations and the networked computer system." Also claims 7 / 17 (preventing unauthorized communication with untrusted destinations) and the whitelist concept in claims 5 / 15.
  • Assessment: The cleanest single-reference match to the "device" element of claims 1 and 11. It cannot anticipate the independent claims (no host/guest internal firewall), but it is the reference I would lead with for a § 102 attack on the device element and for the § 112(f) "device" nonce-term fight. This is a high-value reference that appears to have been under-weighted during prosecution.

15. US 2007/0260873 A1 — Hatfalvi, Emil J. — "Systems and methods that provide external network access from a protected network"

  • Filed / published: priority 2001-03-01 / published 2007-11-08§ 102(b) (priority and publication both well before the critical date).
  • Description: Providing external network access from a protected network — proxy/mediated egress, the architectural inverse of "isolate the host and route the guest out."
  • § 102 mapping: claim 1(e) / 11(e) (proxy), claims 5 / 15 (separate first and second communication connections with enforced separation), claims 7 / 17.
  • Assessment: Strong § 102(b) art for the separate-connection architecture. Not an independent-claim anticipation. Excellent § 103 partner for the Puder reference.

16. US 7,698,442 B1 — Voltage Security, Inc. — "Server-based universal resource locator verification service"

  • Filed / granted: 2005-03-03 / 2010-04-13
  • § 102 basis: § 102(e) by the 2005-03-03 filing date. (Grant date 2010-04-13 is after the 2010-01-27 critical date, so no § 102(b) — this is the trap in this reference.)
  • Description: Server-side URL verification — a whitelist-by-verification service.
  • § 102 mapping: claims 1(d)/(e), 7, 11, 17; the "trusted network destinations" concept animating claims 5 / 15.
  • Assessment: § 102(e)-only art for the whitelisting/verification element. No anticipation.

17. US 2010/0251329 A1 — Yottaa, Inc. — "System and method for access management and security protection for network accessible computer services"

  • Filed / published: 2009-03-31 / 2010-09-30§ 102(e) by the 2009-03-31 filing date.
  • Description: Cloud/edge access management and security for network-accessible services.
  • § 102 mapping: claims 1(e), 7, 11, 17 (off-machine security device preventing unauthorized communication).
  • Assessment: § 102(e) art for the device element. No independent-claim anticipation.

18. US 8,185,642 B1 — [Juniper Networks, Inc.](/litigations/by-defendant/Juniper%20Networks%2C%20Inc.) — "Communication policy enforcement in a data network"

  • Filed / granted: 2005-11-18 / 2012-05-22
  • § 102 basis: § 102(e) by the 2005-11-18 filing date (grant date is post-critical, so no § 102(b)).
  • Description: Policy enforcement in a data network — the network/firewall policy layer.
  • § 102 mapping: claims 1(d)/(e), 6 / 16, 11(d)/(e), and especially claims 8 / 18 (per-network policy switching), which is the "home vs. roaming" limitation.
  • Assessment: Good § 102(e) art for policy enforcement and dual-policy firewalling. This is the natural § 103 partner for Dadhia on claims 8/18 (see § 2 below).

Tier 4 — peripheral

19. US 7,478,330 B1 — International Business Machines Corporation — "Systems and methods involving improved web browsing"

  • Filed / granted: 2008-04-30 / 2009-01-13§ 102(b).
  • Description: Improved web browsing methods/systems.
  • § 102 mapping: claims 9 / 19 (application/process running to reach network destinations) and claim 1(e) tangentially.
  • Assessment: No independent-claim anticipation. Note the irony worth surfacing: IBM — the assignee of this very reference's family — is the defendant in Croga's first suit (2:23-cv-00634).

20. US 2002/0069369 A1 — Tremain, Geoffrey Donald — "Method and apparatus for providing computer services"

  • Filed / published: 2000-07-05 / 2002-06-06§ 102(b).
  • Description: Hosted/remote computer-services delivery.
  • § 102 mapping: claim 1(e) (remote service device); claims 9 / 10 / 19 / 20 (which side runs the application).
  • Assessment: The oldest and weakest reference numerically. No independent-claim anticipation.

2. The art the Examiner never applied — this is where the real § 102/§ 103 fight lives

Per the PTACTS record and the IBM petition summary (already analyzed in the PTAB section, not repeated here), the following were the substantive challenges. I give the § 102 relevance and flag every element I could not retrieve.

Reference Full citation Filed / pub. § 102 basis Claims it potentially anticipates
Delco US 8,166,474 B1 — Delco et al. (VMware, Inc.) — "System and methods for implementing network traffic management for virtual and physical machines" filed 2010-04-30 (grant 2012-04-24); priority 2010 § 102(e) at most (grant post-dates priority) claims 1, 3, 5, 6, 10, 13, 15, 16, 20 — maps to elements (a)–(d) but fails (c)
Adams US 2010/0077476 A1 — (Adams) pub. 2010-03-25 § 102(e)/(a), not (b) claims 1(e), 7, 11(e), 17 (processor/memory network appliance)
Dadhia US 7,886,351 B1 — Dadhia et al. — "Network aware firewall" granted 2011-02-08 § 102(e) at most claims 8, 18
Nazario Non-patent literature — "Defense and Detection Strategies" (per the Amazon petition) § 102(b)/(a) if published pre-2011 claims 1, 3, 7, 10, 11, 13, 17, 20 (as raised in IPR2025-00884 / reexam 90/015,746)
Ghosh Non-patent literature (per the Amazon petition) § 102(b)/(a) if published pre-2011 same set as Nazario
Thomas / Garge Not retrieved. Identified in the 90/019,638 reexam as the basis for the rejection of claims 1–20 unknown unknown claims 1–20 (per the reexam record)

The decisive point on Delco — and it applies to the whole § 102 inquiry. The Board held that Delco's packet filter 74 is a filter of packets from an external network and "does not function to separate the host system from the virtual system" (IPR2024-01196, Paper 7, and the same reasoning in IPR2025-00086, Paper 9). Croga's rehearing request argued the Board misread Delco's 3:40–46 ("…including the host operating system and other virtual machines"), and the Board rejected that reading. Net effect: the closest prior art on the planet to element (c) fails as a matter of record. That means:

  • No reference in either set has been shown to anticipate claim 1 or claim 11.
  • No reference has been shown to anticipate any of claims 1–20 in a Final Written Decision — there is no FWD.
  • The only live § 102 findings are in the reexamination, where claims 1–20 stand rejected over Thomas and Garge, with the PTAB reported as having "affirmed-in-part and issued new grounds of rejection" on 2026-09-10. A rejection is not a cancellation — cancellation requires a reexamination certificate. Whether Thomas/Garge is genuine § 102 anticipation or a § 103 obviousness rejection I could not verify; the prior sections report the reexam rejection both as "over Thomas and Garge" and as an "anticipation" rejection. Treat "Thomas anticipates claims 1–20" as reported-but-unverified.

3. Bottom line — ranked § 102 exposure

Genuine single-reference anticipation candidates for the INDEPENDENT claims (1 and 11):

  1. RU 2406138 C1 (Samsung) — title-level match to "security system for virtual computer system"; § 102(a)-only; unverified text. Pull first.
  2. Delco (US 8,166,474) — closest structurally, but judicially found NOT to disclose element (c). Anticipation is foreclosed by the Board's findings unless a court reads Delco differently.

Genuine single-reference anticipation candidates for DEPENDENT claims:
3. US 2010/0174811 A1 (Microsoft) — "network isolation" — claims 4, 6, 14, 16.
4. US 2012/0023593 A1 (Puder) — "secure network appliance" — claim 1(e) / 11(e) and claims 7, 17; strong for the § 112(f) "device" fight.
5. US 2007/0220187 A1 (Kates) — virus-resistant filtering interface — claims 4, 6, 7, 14, 16, 17.
6. US 2009/0172781 A1 (Fujitsu) — trusted VM as client — claims 1(b), 9, 10, 19, 20.
7. US 8,185,642 B1 (Juniper) + Dadhia (US 7,886,351) — claims 8, 18 (dual-policy).

No single reference in either set discloses all three isolators. The independent claims survive on combination, not on any one reference. The realistic invalidity theory is therefore § 103, not § 102 — and the strongest § 103 core is Delco (network traffic management in a VM framework) + Puder or Hatfalvi (network appliance/web proxy) + Juniper or Dadhia (policy enforcement / dual policy), with US 2010/0174811 supplying the literal "network isolation" language. That is a materially different combination from the Delco+Adams(+Dadhia) theory that the Board rejected twice — and it is the only § 103 path that has not already been roadmapped into a discretionary denial.


4. Caveats, corrections, and things I will not assert

  1. I did not retrieve full text for US 2010/0077476 (Adams), US 7,886,351 (Dadhia), RU 2406138, Nazario, Ghosh, Thomas, or Garge. Details for those are drawn from the PTACTS/petition summaries and prior sections, not from the documents themselves. Do not treat the Adams/Dadhia rows as independently bibliographically verified.
  2. Publication dates above are those shown in the authoritative full text's citation table (which renders some as priority dates rather than publication dates — e.g., US 2007/0260873 is listed with "2001-03-01"). Where I state a § 102(b) vs. § 102(e) conclusion from those dates, re-verify at USPTO PatentCenter before relying on it in a filing, because the citation table's date column is not labeled and may mix priority, filing, and publication dates.
  3. "Potentially anticipates" is doing real work in this answer. For every entry above where I say a reference "maps to" a claim, I mean an element-level candidate mapping, not a concluded anticipation. None of these references produced an anticipation rejection that survived prosecution, and the Board has rejected the one closest attempt on the merits.
  4. The § 102(e) references are only as good as the invention date. All pre-AIA § 102(a) and § 102(e) conclusions are defeatable by a Rule 131 showing of earlier invention. § 102(b) references (entries 1, 4, 5, 6, 7, 8, 9, 10, 11, 15, 19, 20) are not.
  5. The date discrepancy continues. If the operative "today" is 2026-09-16 rather than 2026-04-26, the 90/019,638 status and the reported 2026-09-10 PTAB decision are the controlling § 102 developments, and Thomas/Garge may already be closer to a certificate than the record above reflects. Nothing in this section should be relied on without checking the reexamination file history and any reexamination certificate directly.

Nothing here is a legal conclusion. Would you like me to attempt to retrieve the actual texts of RU 2406138 C1 and US 2010/0174811 A1 — the two references with the highest § 102 upside that the record suggests were under-analyzed?

Generated 9/16/2026, 12:04:28 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll ground the key combination references before building the § 103 analysis.

Obviousness Analysis — US 10,601,780 B2 under 35 U.S.C. § 103 (pre-AIA)

Building on the Prior Art section above. That section established which references are available, their § 102 status, and that no single reference discloses all three isolators. This section takes that as given and asks the § 103 question: what combinations would a POSITA have made, and why.


0. Two flags before the analysis (per the instruction to surface contradictions)

(a) Date conflict — carried forward, unresolved. The task header says current date April 26, 2026. The environment says 2026-09-16, the patent text was fetched 2026-09-16, and the prior sections report a 2026-09-10 PTAB decision in reexam 90/019,638. I do not reconcile these. If the operative date is September 2026, the reexamination status (not this § 103 section) is the controlling development.

(b) The Assignment section's open item is now closed — and it corrects an earlier flagged anomaly. The Assignment section said reel/frame numbers were "not retrieved" and flagged as an "indexing anomaly" the appearance of an inventors→L-3 conveyance dated 2024-01-02. The USPTO legal-events record surfaced in this session shows the actual instruments:

Recording Reel/Frame Effective / signing date
Inventors → L-3 Communications Corp. 030951/0649 signing dates 2013-07-12 to 2013-07-29
L-3 Communications Corp. → L3 Technologies, Inc. (change of name) 063564/0207 effective 2016-12-31
L3Harris Technologies / Eagle Technology / L3 Technologies et al.Croga Innovations Limited 066001/0843 effective 2023-09-14

So the "2024-01-02" figure was a recordation/indexing artifact, exactly as the Assignment section suspected, and the Croga transfer's effective date is 2023-09-14 — i.e., ~3.5 months before the first complaint (IBM, 2023-12-29). That strengthens the "pre-litigation transfer" signal but does not change the NPE verdict. I flag it here because it contradicts the earlier section's dates.


1. Legal framework and the construction gate

Governing law. Priority is 2011-01-27, so pre-AIA § 103 applies with the pre-AIA § 102 critical dates already set out. Obviousness is a question of law on Graham's four factual inquiries: scope/content of the prior art, differences from the claims, level of ordinary skill, and secondary considerations. Under KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007), a combination need not be taught by any explicit "TSM" — it is enough that the elements were known, the combination was "obvious to try" with a finite number of identified, predictable solutions, or the combination is "a predictable variation" using a known technique to improve a similar device in the same way (MPEP 2144.03, 2144.04).

POSITA. A person with a bachelor's degree in CS or EE and roughly two to four years of experience in network security, firewalling, and operating-system virtualization as of the 2010–2011 timeframe — i.e., someone who reads Delco, Hatfalvi, Puder, Dadhia, Kates and Juniper as the ordinary literature of the field.

The construction gate. The § 103 case rises or falls on two claim terms, and both were flagged in the earlier sections:

  1. "network isolation" — appears twice in claim 1 (and claim 11) with different scopes: isolation "between the computer system and the network" (host-based firewall), and isolation "between one or more untrusted network destinations and the networked computer system" (the device). Amazon took the position in W.D. Tex. that these are § 112(f) means-plus-function limitations. If so construed, the term narrows to the disclosed structure (hypervisor firewall + VPN conduit + VPN termination point), which helps the patent owner against cloud-based products. A defendant should therefore plead § 103 in the alternative to indefiniteness, not instead of it.
  2. "internal firewall … configured to separate the host system from the virtual system in the computer system" — the element the Board twice found missing from Delco (IPR2024-01196, Paper 7, 2025-02-13; IPR2025-00086, Paper 9, 2025-03-27). This is the swing element for the independent claims, and it is where the combinations below do their work.

Because the claim uses "at least one device configured to implement at least one of a network firewall or a web proxy … comprising a processor and a memory," the device element is broad and easily met by ordinary appliances — which is why the combinations below treat element (c) as the easy element and the internal firewall as the hard one.


2. The structural insight that governs the whole § 103 picture

The previous sections established, and the IBM petition summary in the record confirms, that the patent's asserted novelty is three distinct isolators: the internal firewall, the host-based firewall, and the network firewall/web-proxy device.

  • No single reference in either art set discloses all three, arranged as claimed. That is why nothing anticipated and why the patent issued with all 20 claims allowed.
  • But each of the three was independently known before 2010, in references the Examiner already had of record (Hatfalvi, Puder, Delco-adjacent VM/firewall art, Juniper, Dadhia, Kates) or that the Office had not yet applied (Delco itself).

That is the classic § 103 posture: anticipation fails, obviousness of the combination succeeds if the motivation and predictability are shown. Which they are — and notably, the motivation is supplied in the references themselves, not invented by me. Delco's own background states the problem the '780 patent claims to solve:

"…if a security breach, whether intentional or caused by the inadvertent execution of malware, arises from activity within one of the virtual machines, or from within the host operating system environment, the platform firewall application is unable to prevent the breach from freely spreading between the virtual machines and the host."
— Delco (US 8,166,474), Background

A POSITA reading that sentence in 2010 would immediately look for a firewall between the host and the VM — i.e., the claimed internal firewall. Delco also expressly contemplates the roaming/mobile case the '780 patent claims in claims 8/18:

"…dynamic modification of individual policy rule sets to allow for on-the-fly management changes and automatically recognized changes in the attached networks, which is particularly useful in the case of mobile computer platforms."
— Delco


3. The flagship combination — Hatfalvi + Delco + Puder (+ Dadhia for claims 8/18)

This is the combination I would lead with, and it is materially different from the theory that failed at the PTAB.

3.1 Why Hatfalvi is the missing primary reference

The prior art section ranked Hatfalvi (US 2007/0260873 A1 / US 7,240,193 B2) as merely "strong § 102(b) art for the separate-connection architecture." Having now read the reference, I think that underweights it substantially. Hatfalvi discloses, before the '780 priority date and as § 102(b) art:

  • A protected computer with a browser client module on which "any browser-executed code operates not on the protected computer, but rather on the browser module," where the browser module is "sacrificial" — i.e., infection is contained to the browsing environment (→ claim 1's virtual system; claims 4/6/14/16 malware containment).
  • A browser isolator module interposed between the browser environment and the protected network that "prevents communications between the browser module and the protected network other than those particular authorized messages necessary for the remote operation of the protected computer" (→ the internal firewall separating host from the browsing environment, and claims 2/12's "explicit user input" limit, since only user-driven remote-operation traffic crosses).
  • A second embodiment in which the internet-accessing programs run "on a special virtual machine on the user workstation" that "provides a tunnelled and authenticated communications path from the browser to a border module which then provides access to the Internet" (→ claim 1's virtual system and the specification's VPN-conduit-to-VPN-termination-point architecture; the "border module" is the termination point).
  • Port restrictions — "the specific TCP ports which can be addressed in either direction could be limited to those required by the browser client module" (→ the '780's port 80/443 discussion and claims 5/15's separate enforced connections).
  • Files "initially downloaded onto the browser module" rather than the protected computer (→ claims 3/13 / the file-transfer protocol).

Critically, Hatfalvi's second embodiment affirmatively refutes any teaching-away argument: even though Hatfalvi's first embodiment uses a physically separate browser computer, Hatfalvi itself teaches consolidating the isolated browser onto the user's own workstation as a special virtual machine. A POSITA therefore had express direction to the claimed architecture.

3.2 Element-by-element mapping

Claim 1 element Supplied by Support
(a) a network Delco / Puder Delco Fig. 1 (intranet 22, public network 24); Puder (router/modem)
(b) computer system with host system and virtual system (separate OS or software module) Delco (primary); Hatfalvi 2d embodiment; Geisinger; Fujitsu Delco: host system platform 12 + virtual machines 26/28 under a hypervisor, "host operating system 42"
(c) internal firewall separating host from virtual system Hatfalvi (browser isolator module; special VM + restricted protocol); alt. Fujitsu, Zhao, Microsoft US 2010/0174811 Hatfalvi: "Other communications are generally prohibited" between the browser environment and the protected network
(d) host-based firewall implementing network isolation computer↔network Delco (packet filter application 32; "platform packet filter application") Delco: packet filter application 32 "protect[s] the physical computer system as a single entity"
(e) device with processor/memory implementing network firewall or web proxy, isolating untrusted destinations Puder (squarely); alt. Delco's firewall system 30 + Adams Puder: secure network appliance with proxy server, ports whitelist, physically interposed between router and computer
Claims 4, 6, 14, 16 — no lateral malware movement Hatfalvi (sacrificial, isolator module); Delco ("unable to affect the execution of programs in other virtual machines") both
Claims 5, 15 — separate trusted/untrusted connections, separation enforced Hatfalvi (tunnel vs. protected-network path); Puder Hatfalvi: "two separate routes must be found between endpoints"
Claims 7, 17 — device prevents unauthorized communication Puder Puder claim 1: "passing the request to the Internet only if the requested web address is on the whitelist"
Claims 8, 18 — first policy on the home network, second policy on another network Dadhia (primary); Delco Dadhia: "a firewall keeps two sets of firewall policies locally. The first policy is associated with private (e.g., trusted) networks … The second policy is associated with public (e.g., untrusted) networks"
Claims 9/19, 10/20 — apps/processes in virtual vs. host system Schneider (per-process VMs), Geisinger, Hanquez, Fujitsu each VM runs its own applications; host runs the LAN-facing apps
Claims 3/13 — segregated host/virtual storage Zhao, Fujitsu, Toshiba, Geisinger separate VM memory spaces

3.3 Motivation to combine — articulated as the case would be tried

  1. Same field, same problem, same solution space. All four references address the same problem — preventing internet-borne malicious code from reaching a protected workstation and spreading — and all four sit in network security/virtualization. They are analogous art on any formulation. (Hatfalvi and Delco are both cited on the '780 face of patent; Puder was cited as a § 102(e) reference; Dadhia is Microsoft's "network aware firewall.")

  2. Delco supplies the express motivation for the internal firewall. Delco's background states the precise deficiency the '780 patent purports to solve — the platform firewall cannot stop a breach from "spreading between the virtual machines and the host." A POSITA seeking to fix that would place an isolation boundary between host and VM. Hatfalvi supplies exactly that boundary and its implementation.

  3. The '780 specification's own admissions cut against patentability. The background concedes that "it is possible to use two separate computers, one accessing the Internet and the other connected only with a LAN" and that "other more software-intensive methods of restricting have also been tried." The stated drawback of the two-computer approach is cost ("double cost of equipment") and difficulty transferring legitimate data. The '780's contribution is therefore, on its face, consolidating a known two-machine isolation architecture onto one machine using known virtualization — a KSR "predictable variation" and a design-incentive-driven substitution. That is the strongest single sentence in the obviousness case, and it comes from the patent itself.

  4. Predictable results / known techniques. Running a browser in a hypervisor-isolated VM, filtering packets at a virtual NIC, running a host firewall, and interposing a whitelisting appliance are each standard, and combining them yields nothing more than the expected aggregate of their known benefits (MPEP 2144.04 — arrangement of old elements each performing the same function it was known to perform). There is no asserted criticality, no unexpected synergy, and no comparative data anywhere in the specification.

  5. Reasonable expectation of success. Med-V, VMware, Hyper-V, and Invincea are all named in the '780 specification as available hypervisors; Delco is a VMware patent on exactly the host/VM/host-firewall topology. A POSITA would have had a high expectation of building Hatfalvi's isolating browser on Delco's platform.

  6. No teaching away. Nothing in Delco, Puder, or Dadhia disparages a host/guest isolation boundary. Hatfalvi's first embodiment might superficially be read as preferring a separate physical box — but Hatfalvi's own second embodiment teaches the special VM on the workstation, which closes that door.


4. Secondary and supporting combinations (claim-specific)

Combination A′ — Delco + Puder + Dadhia (the "refined Delco" theory).
For a defendant that wants to stay close to the art the Board has already analyzed: Delco supplies elements (a), (b), (d) and its VM/host packet filters; Puder supplies element (e) (the appliance with processor/memory and whitelist/proxy — squarely better than Adams, which the petitioners used only for "conventional processor and memory" details); Dadhia supplies claims 8/18. This is the same backbone as the failed Delco+Adams(+Dadhia) theory, but it swaps in a reference that reads on the device element rather than merely supplying hardware details, and it drops reliance on Adams. It still needs a reference for the internal firewall — see § 5.

Combination B — Hatfalvi + Kates + Puder (containment-focused).
For claims 4, 6, 7, 14, 16, 17. Hatfalvi supplies containment by design ("sacrificial" browser; isolator module); Kates (US 2007/0220187, virus-resistant computer with a filtering data interface) supplies the anti-malware-movement objective; Puder supplies unauthorized-communication prevention via whitelist. Motivation: Kates and Hatfalvi both state the same objective in their opening paragraphs (arbitrary code from the network must not execute on or spread from the protected machine).

Combination C — RU 2406138 (Samsung) + Puder/Hatfalvi (highest upside, unverified).
If RU 2406138's text discloses host↔guest separation in a "security system for virtual computer system," it becomes a single-reference teaching of element (c) and a powerful § 103 primary, with Puder supplying the appliance. But it is § 102(a)-only (published 2010-12-10, after the 2010-01-27 § 102(b) bar), foreign-language, and I have not retrieved its text — so it is subject to being sworn behind and requires a certified translation. Treat as a second-wave reference, not a lead.

Combination D — Grobman + Microsoft US 2010/0174811 + Delco + Puder (the "hypervisor network control" theory).
For element (c), a POSITA could alternatively read the internal firewall into the hypervisor-mediated network stack: Grobman (US 2006/0070066, "enabling platform network stack control in a virtualization platform") plus Microsoft US 2010/0174811 ("network isolation and identity management of cloned virtual machines," a § 102(e) reference on the '780 face). This gives a second, independent route to element (c) that does not depend on Hatfalvi — useful if Hatfalvi is distinguished on the ground that its isolation is between the browser module and the network rather than between host and VM.

Combination E — for the memory/process dependent claims (3, 9, 10, 13, 19, 20).
Geisinger (US 2008/0028401, VM with its own virtual hardware/OS/network), Schneider (US 2010/0223613, per-process VMs), Hanquez (§ 102(e)), Zhao (US 2008/0256536, secured environment on an untrusted machine), and Fujitsu's Masuoka (US 2009/0172781, "trusted virtual machine as a client," § 102(b)). These are single-element references; they are for the dependent claims only and are best used to show that VM memory segregation and running applications inside the VM were old and well known.


5. Why the PTAB's two merits denials do not control, and what they do cost

This is the most important practical point, and it is where the earlier sections and this one have to be read together.

  • The Board's holdings in IPR2024-01196 (Cisco, Paper 7, 2025-02-13) and IPR2025-00086 (Fortinet, Paper 9, 2025-03-27) were that Delco's packet filter 74 is a network-facing filter and does not separate the host system from the virtual system, relying on Delco's Fig. 2 showing no firewall between host and VM. The Board rejected that element based on Delco alone as the sole internal-firewall reference. IBM's IPR2025-00380 (Delco+Adams+Dadhia) was dismissed pre-institution, so it never got a merits ruling at all.
  • None of that binds a district court, and — because no FWD ever issued — § 315(e)(2) estoppel attaches to nobody. The combinations above use a different reference (Hatfalvi, or Grobman + Microsoft '811) for the internal firewall, which is precisely the gap the Board identified. A court applying Phillips is free to find the limitation met.
  • But note the countervailing reading of Delco, which cuts the other way and is worth testing early: Delco's own specification says the virtual-NIC packet filters let each VM "discretely manage network communications with respect to all external entities, including the host operating system and other virtual machines," and that VMs are "effectively isolated from one another and from the host operating system as a function of the applied virtual machine world context switch," and that filters sit "outside of the nominal application execution space of the guest operating systems" and "within the reserved space of a virtual machine." A court could read that as the claimed internal firewall — the Board read Fig. 2 the other way. That disagreement is a real, live, appealable-quality issue in both directions.
  • What the denials do cost: a fifth IPR petition is unlikely to be instituted. The Director's IPR2025-00884 denial (2025-09-03) was expressly grounded on totality / serial attack — this was "the fourth petition," an ex parte reexam was already "in an advanced stage," and it was "not an appropriate use of Office resources to review a patent in two separate, concurrent Office proceedings." Add the 2020-03-24 issue date (settled expectations) and the two pending reexaminations, and the IPR channel is effectively closed. The § 103 case should therefore be built for the district court and in support of the reexaminations, not for a new IPR.

6. Claim-by-claim § 103 chart (condensed)

Claim Primary refs Secondary/for the element Motivation REOS
1 Hatfalvi (internal firewall/VM browser) + Delco (host/VM + host FW) + Puder (appliance/proxy) Microsoft '811 or Grobman for element (c) alt. Delco states platform FW can't stop host↔VM spread; '780 spec admits two-computer approach was known but costly High — all elements standard; VMware/Microsoft hypervisors commercial
2 / 12 Hatfalvi (only user-authorized remote-operation traffic crosses the isolator) + Delco Zhao; Kates Containment requires no unattended host↔guest data path High
3 / 13 Delco (host OS 42 vs. VM contexts) + Zhao/Geisinger/Toshiba Hanquez VM memory segregation inherent to virtualization High
4 / 14 Hatfalvi (sacrificial; isolator) + Delco Kates Prevent malware from leaving the browsing environment High
5 / 15 Hatfalvi (tunnel vs. protected path) + Delco (per-interface sessions) Grobman Separate trusted/untrusted paths to enforce the boundary High
6 / 16 Delco (VM isolation "from the host operating system"; per-network-interface filters) + Hatfalvi Skytap (tenant isolation) Lateral containment High
7 / 17 Puder (whitelist appliance) + Hatfalvi Juniper (policy enforcement); Voltage Block unauthorized untrusted communication at the appliance High
8 / 18 Dadhia (two policy sets: trusted/private vs. public) + Delco (dynamic policy per attached network; "particularly useful in the case of mobile computer platforms") Juniper US 8,185,642 Laptops roam; policy must follow the network High
9 / 19 Hatfalvi (browser runs in the special VM) + Schneider/Geisinger Hanquez; Fujitsu Browser is the untrusted-content consumer High
10 / 20 Delco (host OS runs on the platform) + Fujitsu Tremain Host-facing applications stay on the host High
11 Same as claim 1, method form Method steps are the practice of claim 1's structure High

7. Objective indicia — what Croga will argue, and why it is weak

Indicia Likely argument Assessment
Long-felt, unmet need Two-computer air-gap was known but costly; the need persisted Weak. Hatfalvi addressed the same need in 2001 and taught the VM-on-workstation fix; Delco's background identified the host↔VM spread problem in 2005. No "failure of others" where the solution was twice published.
Commercial success Licensing/settlement revenue Weak / no nexus. The Assignment section found no confirmed L3Harris product reading on the claims. NPE settlements (IBM IPR2025-00380, PAN on the '601) are weak evidence and carry litigation-avoidance bias, not nexus to a claimed feature.
Industry praise / copying Accused products (Cisco Umbrella RBI, AWS VPC/Network Firewall/Nitro Enclaves) Mixed. Copying can be probative, but here the accused architectures are cloud/network-edge implementations, which the patent owner must argue correspond to the claimed in-machine three-isolator arrangement — a tension with its own § 112(f) narrowing position.
Unexpected results None asserted The specification contains no comparative data, no critical ranges, no surprising synergy. Nothing to weigh.
Examiner allowance over these references The Office cited Hatfalvi, Puder, Kates, Fujitsu, Grobman, Juniper, RU 2406138 and allowed Weak as indicia — office allowance is not a Graham factor. The cited art was listed as background/§ 102(e) references; the record shows no combination rejection was ever made over them. That is an argument for further examination, not for validity — and it is exactly what Unified Patents' reexam 90/019,638 and Amazon's 90/015,746 are testing.

Net: the secondary-considerations record is close to empty, and the one structural admission in the specification (the two-computer approach was known and merely too expensive) affirmatively supports obviousness.


8. Rocks in the road — where the § 103 case is genuinely vulnerable

  1. Element (c) is the whole case. If a court accepts the Board's reading that Delco's VM filters are network-facing, the internal-firewall element must come from Hatfalvi, Grobman/Microsoft '811, Fujitsu, Zhao, or RU 2406138 — and each is distinguishable in some respect (Hatfalvi's isolator is arguably network-facing too; Fujitsu's "trusted VM" is about trust labeling, not firewalling). The combination's strength depends on a court finding that an isolation boundary between two co-resident OS environments on one machine is an "internal firewall," which is common-sense but not textually nailed down by any single reference. This is the same conceptual wall the Board built twice.
  2. § 102 status traps. Puder is § 102(e)-only (US filing 2010-07-26, after the 2010-01-27 § 102(b) date) and is defeatable by a Rule 131 swearing-behind if the applicant establishes an earlier invention date. RU 2406138 is § 102(a)-only and foreign-language. Hatfalvi and Delco are solid (§ 102(b) / § 102(e) by 2005–2007 filings). Build the combination on Hatfalvi + Delco + Dadhia (both § 102(b)) and treat Puder as an enhancement, not a necessity.
  3. The § 112(f) tension. If "network isolation" is means-plus-function and narrows to the disclosed VPN-termination-point structure, the prior art must show that structure — and Hatfalvi's "border module" does, which is why Hatfalvi is the right lead. If instead the term is given its broad ordinary meaning, Puder satisfies it easily. Either construction is workable, which is why the two are paired.
  4. The reexam is the real clock, and a rejection is not a cancellation. Per the record, the examiner rejected all of claims 1–20 over Thomas and Garge in 90/019,638 (two office actions; PTAB reported to have "affirmed-in-part and issued new grounds of rejection" on 2026-09-10), and Croga's proposed claims 21–30 drew a § 112 written-description rejection. Until a reexamination certificate issues, nothing is cancelled. I have not verified the Thomas/Garge references' content or whether the rejection is § 102 or § 103; treat that as reported-but-unverified. If a certificate cancels the claims, this entire § 103 section is moot.
  5. District-court reality. Judge Gilstrap denied the joint stay in Croga v. Cisco, No. 2:24-cv-00065-JRG, 2025 U.S. Dist. LEXIS 71092 (E.D. Tex. Apr. 14, 2025) even while finding "every asserted claim has a reasonable likelihood of being invalidated." A § 103 defense will be tried, not stayed — so the combination must be presented with a POSITA declaration that squarely addresses element (c) and the motivation evidence from Delco's background.

9. Bottom line — ranked § 103 theories

  1. Hatfalvi (US 2007/0260873 / US 7,240,193) + Delco (US 8,166,474) + Puder (US 2012/0023593), + Dadhia (US 7,886,351 / US 8,321,927) for claims 8/18. The best combination: Hatfalvi is § 102(b), teaches the isolated-browser-on-a-VM architecture and the tunnel-to-border-module, and by its own text precludes a teaching-away argument; Delco supplies the host/VM platform and the host-based firewall and supplies the express motivation (host↔VM spread) plus the roaming-policy teaching; Puder supplies the claimed device with processor/memory, whitelist and proxy.
  2. Delco + Dadhia + Puder + Grobman/Microsoft US 2010/0174811 — an alternative route to element (c) via hypervisor-mediated network control, if Hatfalvi is distinguished.
  3. Hatfalvi + Kates + Puder for the containment/malware-movement dependent claims (4, 6, 7, 14, 16, 17), and Hatfalvi + Schneider/Geisinger + Fujitsu for claims 9/10/19/20 and 3/13.
  4. RU 2406138 + Puder/Hatfalvi — highest ceiling, lowest confidence; pull the certified translation before relying on it.

Do not file another Delco + Adams (+ Dadhia) theory. Two panels rejected it on the merits and the Director has now denied a fourth petition on totality. The value of those decisions to a defendant is procedural, not substantive: they confirm the element to attack, they leave every prior-art ground un-estopped, and they show that a new reference must supply the internal firewall — which Hatfalvi does.

Nothing here is a legal conclusion. Every proceeding number, date, and quotation is sourced to the pages and filings cited in the earlier sections and to the primary documents retrieved in this session (Delco at ptacts.uspto.gov pet. 1556845 and sumobrain/freepatentsonline; Dadhia at ptacts.uspto.gov pet. 1556394 and patentsencyclopedia US20110179481; Puder at uspto.report app/20120023593 and freepatentsonline y2012/0023593; Hatfalvi at justia 20070260873 and patentimages US7240193). The Hatfalvi, Fujitsu, Zhao, Kates, Grobman, Juniper, Adams and RU 2406138 mappings remain element-level candidate mappings, not concluded invalidity, and none has ever been adopted by a court or the Board.

Would you like me to (a) attempt a full-text retrieval of RU 2406138 C1 and Fujitsu US 2009/0172781 to firm up element (c), or (b) draft the KSR motivation paragraph and a POSITA declaration outline for the Hatfalvi + Delco + Puder + Dadhia combination?

Generated 9/16/2026, 12:46:40 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

✓ Generated

I'll research the term, adjustment, and family details for US 10,601,780.

Patent Term & Family Analysis — US 10,601,780 B2

Tool-limit note: I hit the search-step ceiling while trying to pull the front-page PTA figure from a primary source (PatentCenter / patentimages). The searches I did run did not return the individual PTA determination for this patent — only generic PTA-methodology material. I therefore give you the framework, the determinable parts, and a bounded range, and I flag explicitly what I could not retrieve. I have not invented a PTA number.


1. Confirmation of the exact patent (no similar-number substitution)

Field Value
Patent US 10,601,780 B2 (not 10,601,780-family lookalikes)
Application 15/910,734
Title Internet isolation for avoiding internet security threats
Filing date 2018-03-02
Grant/publication date 2020-03-24
Pre-grant pub. US 2018/0191684 A1 (2018-07-05)
Inventors Robert B. Hoy; Mark Fenkner; Sean W. Farren
Family ID 46581200

This is the record in the authoritative full text you supplied; I did not substitute any other patent. The TPACTS/GreyB, Unified Patents and Docket Alarm records all confirm the same trio of identifiers — Pat. 10,601,780 / App. 15/910,734 / Tech Center 2400 — so there is no number ambiguity.


2. Patent Term Adjustment (PTA) — 35 U.S.C. § 154(b)

2.1 What is determinable from the record

App. 15/910,734 was filed after 2000-05-29, so § 154(b) PTA applies in principle. Because the '780 is a continuation filed under 35 U.S.C. § 111(a) (see § 4 below), each statutory clock runs from that application's own actual filing date (2018-03-02), not from the 2012 PCT date:

PTA component Measurement date Result
A Delay (§ 154(b)(1)(A)) 14-month date = 2019-05-02 = days from 2019-05-02 to the first § 132 action or Notice of Allowance, whichever first (plus the 4-month response-deadline sub-periods under 37 C.F.R. § 1.703(a)(2)–(6))
B Delay (§ 154(b)(1)(B)) 3-year date = 2021-03-02 0 days. The patent issued 2020-03-24, i.e. ~23 months after the continuation was filed — well inside the three-year window. This is a determinate conclusion.
C Delay (§ 154(b)(1)(C)) 0 days. No interference, no secrecy order, no successful appeal in the '780's own prosecution.
Overlap 0–small, A/B overlap only.

So PTA('780) = A Delay − Applicant Delay, and nothing more.

2.2 Bounded range (my estimate, clearly flagged)

The total pendency of 15/910,734 after the 14-month mark is 2019-05-02 → 2020-03-24 = 327 days. A Delay can never exceed that run. Therefore:

0 ≤ PTA ≤ ~327 days, reduced by any Applicant Delay under 37 C.F.R. § 1.704.

Given (a) the continuation was filed just before the parent issued (a common "quick-issue" continuation pattern), (b) no appeal was taken, and (c) no RCE appears in the visible record, a low-to-modest A Delay (or even 0) is the more likely outcome — but I did not retrieve the actual figure, so I am not asserting one. The number appears on the granted patent's front page under "Patent Term Adjustment" and in the Notice of Allowance PTA determination.

Action to close this gap: pull the PTA determination and the "Patent Term Adjustment" field for 10,601,780 at:

2.3 Terminal-disclaimer cap — a live unknown

Section 154(b)(2)(B) caps PTA at the expiration date specified in any terminal disclaimer. Because the '780 is a continuation of 13/981,896 (US 9,942,198, issued 2018-04-10), and the two share a specification, an obviousness-type double-patenting rejection over the parent is plausible, which would have required a terminal disclaimer. I could not confirm whether a terminal disclaimer was filed in 15/910,734. If one was, the '780's term is capped at the parent's expiration (which is itself 20-year date + the parent's own PTA). This is precisely the In re Cellect fact pattern (which surfaced in my searches only as generic authority, not as data about this patent). Verify a TD at PatentCenter → "Terminal Disclaimer" / prosecution history.


3. Patent Term Extension (PTE) — 35 U.S.C. § 156

Not applicable. Section 156 PTE restores term lost to FDA premarket regulatory review (human drugs, devices, food/color additives, animal drugs, veterinary biologics). US 10,601,780 is a computer/network-security patent (classifications H04L63/02, H04L63/0272, G06F21/53, G06F2009/45587) with no regulated-product approval. There is no PTE and none is available. No FDA-related regulatory-review extension can attach.


4. Continuation and divisional applications

4.1 The '780 is itself a continuation

From the patent's own "Cross Reference to Related Applications" (authoritative text):

"This application is a continuation of U.S. patent application Ser. No. 13/981,896, filed Jul. 29, 2013, which is a National Stage Entry under 35 U.S.C. § 371 of PCT/US2012/023027, filed Jan. 27, 2012, which claims priority from U.S. Provisional Application No. 61/436,932, filed Jan. 27, 2011."

4.2 The '780's parents / priority chain

Link Application Filing date Notes
Provisional 61/436,932 2011-01-27 Earliest priority. Does not count toward the 20-year term.
PCT PCT/US2012/023027WO 2012/103517 A1 2012-01-27 International filing date. Sets the 20-year term.
National stage 13/981,896US 9,942,198 B2 § 371(c) date 2013-07-29; issued 2018-04-10 Parent of the '780
Continuation 15/910,734US 10,601,780 B2 2018-03-02; issued 2020-03-24 The patent at issue

4.3 Continuations of the '780 / divisionals

None on the record. The "Family Applications" listing shows exactly two US family applications — 13/981,896 and 15/910,734 — with no child continuation, CIP, or divisional descending from the '780. The '780 is the terminal application in this chain. No divisional application is present anywhere in the family.

4.4 Related-but-separate L3/L3Harris families (do not confuse)

The "Families Citing this family (91)" are citing documents, not family members. Several are L3/L3Harris patents by the same group on the same subject matter but with their own 2017 priority dates (separate families): e.g., US 10,558,798 and US 10,554,475 ("Sandbox based Internet isolation…"), US 11,240,207 ("Network isolation"), US 11,178,104 ("Network isolation with cloud networks"), US 11,044,233 ("Browser switching system and methods"), US 11,336,619 ("Host process and memory separation"), US 10,992,642 ("Document isolation"), US 11,223,601 ("Network isolation for collaboration software"), US 11,184,323, US 11,550,898, US 11,120,125, US 11,170,096, US 11,374,906, US 11,552,987, US 11,601,467. These are continuations of a different L3 line, not continuations/divisionals of the '780. Asserting otherwise would be an error.


5. Related family members (Family ID 46581200)

Per the "Country Status (5)" block in the authoritative text:

Jurisdiction Document Status reported
US US 9,942,198 B2 (13/981,896) Active (parent)
US US 10,601,780 B2 (15/910,734) Active (the patent at issue)
EP EP 2668608 A4 (EP 12739468.2A) not_active — Withdrawn
WO WO 2012/103517 A1 (PCT/US2012/023027) not_active — Ceased
AU AU 2012211053 A1 (+ a second AU member; count = 2) not confirmed
CA CA 2825811 A1 not confirmed

Consequence for term: the '780's only live parallel protection is the US parent US 9,942,198; the EP application was withdrawn and the PCT ceased, so there is no foreign counterpart term running alongside the US rights in this family.


6. Projected expiration date

Statutory term. 35 U.S.C. § 154(a)(2): 20 years from the US filing date, or, where benefit is claimed under § 120/§ 121/§ 365(c), 20 years from the earliest such application. Because the chain ends at the international filing date 2012-01-27 (a § 371 national stage's filing date is the international filing date, 35 U.S.C. § 363), the '780's base term is:

2012-01-27 + 20 years = 2032-01-27

This matches the "Anticipated expiration: 2032-01-27" field in the authoritative text.

Adjusted expiration (my best bracket):

Component Value
Base 20-year date 2032-01-27
+ PTA (§ 154(b)) 0 to ~327 days (exact figure not retrieved); likely modest
+ PTE (§ 156) None (not applicable)
Cap from terminal disclaimer Unknown — if a TD to US 9,942,198 was filed, the term is capped at the parent's adjusted expiration

Projected expiration (subject to verification): ~2032-01-27, plus a PTA of 0–327 days — i.e., no earlier than 27 Jan 2032 and no later than roughly 19 Dec 2032 on the statutory math alone, absent a terminal disclaimer.

⚠️ Google Patents' "2032-01-27" is a 20-year-date placeholder that does not include PTA. Do not treat it as the final expiration.

Two overriding caveats that can make the term moot:

  1. Pending ex parte reexamination 90/019,638 (Unified Patents; granted 2024-11-21) — per the earlier sections, all of claims 1–20 stand rejected over Thomas/Garge, and the PTAB is reported to have "affirmed-in-part and issued new grounds of rejection" on 2026-09-10. If a reexamination certificate cancels claims 1–20, an expiration date for those claims is meaningless. Note also that a second reexam (90/015,746, Amazon's Nazario/Ghosh art) is pending, with Croga's § 325(d)/Vivint termination petition filed 2026-02-06.
  2. Maintenance fees. Given issuance 2020-03-24, the three windows are 2023-09-24, 2027-09-24, and 2031-09-24 (each with a 6-month grace period). The record reports status "Active," implying the first window was satisfied; the 2027 and 2031 fees are required to keep the patent alive to the projected 2032 expiration.

7. Caveats, uncertainties, and one contradiction

  1. PTA figure not retrieved. I did not obtain the front-page "Patent Term Adjustment" value or the Notice of Allowance determination for 15/910,734. The 0–327-day bracket is derived from statute + the known filing/issue dates, not from the PTA document. This is the single most important item to verify.
  2. Terminal disclaimer unknown. Whether a TD capping the '780 to the parent US 9,942,198 was filed is not confirmed. Given the parent and the continuation share a specification, this is a realistic possibility that would change the adjusted expiration. Check the '780's prosecution history.
  3. The parent's PTA is also unknown. If a TD exists, the cap equals US 9,942,198's adjusted expiration, which itself depends on the '198's PTA (the '198 was pending ~2013-07-29 → 2018-04-10, so it likely carries a substantial B Delay — but I did not retrieve it).
  4. AU/CA member status is unconfirmed; "AU (2)" indicates two Australian family members, one being AU 2012211053 A1.
  5. Possible additional family publication. A PTACTS filing references "Hoy et al. (US 2013/0318594, Pub. Date: Nov. 28, 2013)" as prior art in a related L3 challenge; this is plausibly the pre-grant publication of the parent 13/981,896, but it is not listed in the authoritative text's family/publication block, so I flag it as apparent rather than confirmed.
  6. Date conflict (carried forward, unresolved). The task header says the current date is April 26, 2026; the environment reports 2026-09-20, the fetched patent text is stamped 2026-09-16, and the prior sections report a 2026-09-10 PTAB decision in the reexam. Nothing in this term analysis depends on which date is correct, except that if it is later in 2026, the reexam posture (which can extinguish the claims regardless of expiration math) is the controlling fact. I report the conflict rather than reconcile it.

Bottom line

  • PTA: § 154(b) applies; B Delay and C Delay are determinately 0 because the continuation issued 23 months after its own 2018 filing. A Delay is the only possible component, bounded by 0–327 days; the exact figure was not retrievable in this session. Verify at PatentCenter.
  • PTE: None — not available (no FDA-regulated product; § 156 inapplicable).
  • Continuations: the '780 is a continuation (of 13/981,896US 9,942,198 B2). No continuation or divisional descends from the '780.
  • Family (ID 46581200): US 9,942,198 B2; US 10,601,780 B2; EP 2668608 A4 (withdrawn); WO 2012/103517 A1 (ceased); AU 2012211053 A1 (+1 AU); CA 2825811 A1. Plus provisional 61/436,932 and PCT PCT/US2012/023027.
  • Projected expiration: 27 Jan 2032 + 0–327 days of PTA (≈ 27 Jan 2032 – 19 Dec 2032), subject to any terminal disclaimer cap and, critically, to the outcome of ex parte reexaminations 90/019,638 and 90/015,746, which can cancel the claims outright.

Nothing above is a legal conclusion. The PTA/terminal-disclaimer items are flagged as unverified and should be confirmed against USPTO PatentCenter (App. 15/910,734) and the front page of US 10,601,780 B2 before being relied upon.

Generated 9/20/2026, 6:00:19 PM

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →